home/roleplay/master-controls-mapper

Master Controls Mapper

GPTClaudeGemini··997 copies·updated 2026-07-14
master-controls-mapper.prompt
# 08. Master Controls Mapper

**Domain:** Compliance
**Level:** Practitioner

## Use Case

Map controls between any two GRC frameworks, standards, or regulations. Identifies which controls satisfy multiple frameworks simultaneously, where gaps exist, and where one framework's controls exceed another's requirements. Eliminates the duplication of effort that comes from managing each framework independently.

## Variables

| Variable | What to Enter | Example |
|----------|--------------|---------|
| `[FRAMEWORK_A]` | The primary or source framework | e.g. ISO 27001:2022 Annex A, ISO 42001:2023 Annex A, NIST CSF 2.0, SOC 2 Trust Service Criteria |
| `[FRAMEWORK_B]` | The secondary or target framework to map to | e.g. EU AI Act (Articles 9-17), NIST AI RMF 1.0, GDPR, ISO 31000, FCA SYSC, DORA |
| `[MAPPING_SCOPE]` | Which specific sections or control domains to map | e.g. All controls, ISO 27001 A.8 Technological Controls only, ISO 42001 Annex A.6-A.9 (AI system lifecycle), NIST CSF Govern and Identify functions |
| `[ORGANISATION_CONTEXT]` | How your organisation currently uses these frameworks | e.g. ISO 27001 certified (primary), preparing for EU AI Act compliance (target); or both frameworks being adopted simultaneously |
| `[MAPPING_PURPOSE]` | Why this mapping is needed | e.g. Avoid duplicating controls for two certifications, identify where one framework satisfies another, build an integrated control set, respond to regulatory request |

## The Prompt

Copy everything below this line. Replace all `[VARIABLES]` with your specific information. Paste into Claude, GPT-4o, Gemini, or any capable LLM.

---

when to use it

Community prompt sourced from the open-source GitHub repo KunalCyber/GRC-Prompts-Library (MIT). A "Master Controls Mapper" style prompt — adapt the placeholders and specifics to your task. Imported as-is and not independently retested here, so check the output before relying on it.

tags

roleplaycommunitygeneral

source

KunalCyber/GRC-Prompts-Library · MIT