Framework overlap

Does Azure Security Benchmark cover French Sapin II Law (Law No. 2016-1691)?

You hold Azure Security Benchmark and have been told to do French Sapin II Law (Law No. 2016-1691). Here is how much overlaps, control by control.

29% of French Sapin II Law (Law No. 2016-1691) you already have

Azure Security Benchmark already covers about 29% of French Sapin II Law (Law No. 2016-1691), leaving 10 of 14 controls as genuinely new work.

Already covered 3 Likely covered 1 New work 10

What is genuinely new work

Nothing in Azure Security Benchmark reaches these. This is the list to scope.

Sapin2-AFA-Inspection-Sanctions
Agence Francaise Anticorruption (AFA) Inspection Powers and Sanctions
Sapin2-Art17-Scope-Program
Article 17 - 8-Pillar Anti-Corruption Compliance Program Scope and Applicability
Sapin2-CJIP-Settlements
Convention Judiciaire d'Interet Public (CJIP) - Deferred Prosecution Agreement
Sapin2-Coordination-FCPA-UKBA-ISO37001
Coordination with FCPA, UK Bribery Act, ISO 37001, OECD Anti-Bribery Convention and UNCAC
Sapin2-HATVP-Lobbying
HATVP Lobbying Register, Public Officials Transparency and EU Coordination
Sapin2-Pillar2-Whistleblowing-Waserman
Pillar 2 - Internal Whistleblowing System (Waserman Reform 2022)
Sapin2-Pillar5-Accounting-Controls
Pillar 5 - Accounting Control Procedures (Specific Anti-Corruption Controls)
Sapin2-Pillar6-Training
Pillar 6 - Anti-Corruption Training Program
Sapin2-Pillar8-Internal-Monitoring
Pillar 8 - Internal Monitoring and Continuous Improvement
Sapin2-Status-Waserman-CSDDD-AI
Sapin II Status, Waserman Whistleblower Reform 2022, CSDDD Coordination and 2024-2025 Pipeline
Show the 4 you already have
Sapin2-Pillar1-Code-of-Conduct
Pillar 1 - Anti-Corruption Code of Conduct
Sapin2-Pillar3-Risk-Mapping
Pillar 3 - Corruption Risk Mapping (Cartographie des Risques)
Sapin2-Pillar4-ThirdParty-DueDiligence
Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)
Sapin2-Pillar7-Disciplinary-Regime
Pillar 7 - Disciplinary Regime for Anti-Corruption Violations

How this is calculated

Already covered means a mapping runs from a control in Azure Security Benchmark to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition