21% of SSAE 18 you already have
AML/CTF Act 2006 (Australia) already covers about 21% of SSAE 18, leaving
53 of 67 controls as genuinely new work.
Already covered 5
Likely covered 9
New work 53
What is genuinely new work
Nothing in AML/CTF Act 2006 (Australia) reaches these. This is the list to scope.
SSAE-01Common Attestation Concepts (AT-C 105)
SSAE-02Examination Engagements (AT-C 205)
SSAE-03Review Engagements (AT-C 210)
SSAE-04Agreed-Upon Procedures (AT-C 215)
SSAE-05SOC 1 Engagements (AT-C 320)
SSAE-06SOC 2 Engagements (AT-C 205 with TSC)
SSAE-07SOC 3 General Use Reports
SSAE-08Preconditions for Attestation Engagement
SSAE-09Independence and Ethics
SSAE-10Engagement Risk Assessment
SSAE-11Materiality in Attestation
SSAE-12Written Representations
SSAE-13Other Information in Reports
SSAE-14Reporting on Pro Forma Financial Information (AT-C 310)
SSAE-15Reporting on Compliance (AT-C 315)
SSAE-16Examinations of Prospective Financial Information (AT-C 305)
SSAE-17Engagement Documentation
SSAE-18Quality Management at Firm and Engagement Level
SSAE-19Modifications to the Standard Report
SSAE-20Use by Specified Parties and Restricted Distribution
SSAE18-A1.2A1.2 - Environmental Protections and Recovery
SSAE18-A1.3A1.3 - Recovery Plan Testing
SSAE18-C1.1C1.1 - Confidential Information Identification
SSAE18-C1.2C1.2 - Confidential Information Disposal
SSAE18-CC1.1CC1.1 - COSO Principle 1: Integrity and Ethical Values
SSAE18-CC1.2CC1.2 - COSO Principle 2: Board Independence and Oversight
SSAE18-CC1.3CC1.3 - COSO Principle 3: Management Structure and Authority
SSAE18-CC1.4CC1.4 - COSO Principle 4: Commitment to Competence
SSAE18-CC1.5CC1.5 - COSO Principle 5: Accountability
SSAE18-CC2.1CC2.1 - COSO Principle 13: Quality Information
SSAE18-CC2.2CC2.2 - COSO Principle 14: Internal Communication
SSAE18-CC2.3CC2.3 - COSO Principle 15: External Communication
SSAE18-CC3.3CC3.3 - COSO Principle 8: Fraud Risk Assessment
SSAE18-CC5.1CC5.1 - COSO Principle 10: Control Activity Selection
SSAE18-CC5.2CC5.2 - COSO Principle 11: Technology General Controls
SSAE18-CC5.3CC5.3 - COSO Principle 12: Control Activity Policies
SSAE18-CC6.1CC6.1 - Logical Access Security Software
SSAE18-CC6.3CC6.3 - Access Removal
SSAE18-CC6.4CC6.4 - Physical Access Restrictions
SSAE18-CC6.5CC6.5 - Logical Access to Protected Assets
SSAE18-CC6.6CC6.6 - External Threats and Security Measures
SSAE18-CC6.7CC6.7 - Data Transmission Restrictions
SSAE18-CC6.8CC6.8 - Unauthorized Software Prevention
SSAE18-CC7.1CC7.1 - Infrastructure and Software Monitoring
SSAE18-CC7.2CC7.2 - Anomaly Monitoring in Operations
SSAE18-CC7.3CC7.3 - Security Event Evaluation
SSAE18-CC9.1CC9.1 - Risk Mitigation Activities
SSAE18-PI1.2PI1.2 - System Processing Completeness and Accuracy
SSAE18-PI1.3PI1.3 - Processing Error Handling
SSAE18-SOC1-01Control Environment
SSAE18-SOC1-03Information and Communication
SSAE18-SOC1-04Monitoring Activities
SSAE18-SOC1-05Control Activities for Financial Processing
Show the 14 you already have
SSAE18-CC3.1CC3.1 - COSO Principle 6: Risk Identification
SSAE18-CC3.2CC3.2 - COSO Principle 7: Risk Analysis
SSAE18-CC6.2CC6.2 - New User Registration and Authorization
SSAE18-CC9.2CC9.2 - Vendor and Business Partner Risk Management
SSAE18-SOC1-02Risk Assessment
SSAE18-A1.1A1.1 - Availability Commitments and Requirements
SSAE18-CC3.4CC3.4 - COSO Principle 9: Change Management
SSAE18-CC7.4CC7.4 - Incident Response
SSAE18-CC7.5CC7.5 - Incident Recovery
SSAE18-CC8.1CC8.1 - Infrastructure and Software Change Management
SSAE18-P1.1P1.1 - Privacy Notice
SSAE18-P1.2P1.2 - Choice and Consent
SSAE18-PI1.1PI1.1 - Processing Integrity Definition
SSAE18-SOC1-06Transaction Processing Controls
How this is calculated
Already covered means a mapping runs from a control in AML/CTF Act 2006 (Australia) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition