Suspect a breach? Report it immediately — response within 1 hour.Report an incident

UCM Unified Control Mapping

A single control set, where every control is traced to every regulatory requirement it satisfies — implementing once what must be demonstrated many times over.

Multi-jurisdictional compliance

Principle

An organization operating across several markets — Morocco, the rest of Africa, the Gulf, Europe — is simultaneously subject to several regulatory and normative frameworks that overlap substantially in substance, yet are never worded the same way. Treating each framework separately means processing the same technical control several times under different wordings.

UCM establishes a single control set. Every control in this set is traced to every regulatory requirement it satisfies, framework by framework. An organization implements a control once and demonstrates compliance to as many frameworks as that control actually covers.

Mechanism

UCM is built and maintained in five steps.

01

Inventory of applicable frameworks

The regulatory and normative frameworks applicable to the client are identified based on the markets it operates in, its industry, and its regulatory exposure.

02

Construction of the unified control set

A set of technical and organizational controls is defined, structured independently of the wording specific to each framework.

03

Control-to-requirement traceability

Each control in the set is explicitly linked to every regulatory requirement it satisfies, framework by framework, in a named correspondence matrix.

04

Unified evidence registry

Each piece of evidence — configuration, log, procedure, attestation — is collected once and attached to every control and framework it documents.

05

Per-framework compliance dashboard

Compliance status is reported framework by framework from the same control set, enabling continuous steering rather than a one-off exercise.

Frameworks covered

The UCM control set is traced to the following frameworks, depending on the client's regulatory exposure:

ISO/IEC 27001:2022Law 05-20 & DNSSILaw 09-08GDPRNIS2DORANESA / UAE IANCA ECC-2:2024SAMA CSFPCI DSS v4.0SOC 2IEC 62443

Measurable benefit

By consolidating controls that overlap across frameworks, UCM reduces the number of controls to implement compared to treating each framework separately, and reduces the audit burden carried by the client: a single piece of evidence serves several frameworks instead of being reconstituted for each one.

Deliverables

  • Named correspondence matrix, control by control
  • Unified evidence registry
  • Per-framework compliance dashboard

UCM and the compliance practice

UCM is the mechanism behind our Compliance & GRC service for any organization subject to several frameworks. The detail of each individually covered framework — requirements, deadlines, sanctions — is available on the Compliance hub.

Map your frameworks with UCM

Whether your organization is subject to a single framework or a combination across markets, UCM structures the approach to avoid duplicated effort.