Framework overlap

Does ISO 27043 cover ISO 37001?

You hold ISO 27043 and have been told to do ISO 37001. Here is how much overlaps, control by control.

5% of ISO 37001 you already have

ISO 27043 already covers about 5% of ISO 37001, leaving 40 of 42 controls as genuinely new work.

Already covered 0 Likely covered 2 New work 40

No control in ISO 27043 maps directly to one in ISO 37001. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in ISO 27043 reaches these. This is the list to scope.

ISO37001-01
Quality policy and objectives
ISO37001-02
Leadership commitment to quality
ISO37001-03
Risk-based thinking and planning
ISO37001-04
Resource management for quality
ISO37001-05
Organizational roles and responsibilities
ISO37001-06
Operational planning and control
ISO37001-07
Requirements for products and services
ISO37001-08
Design and development controls
ISO37001-09
Control of externally provided processes
ISO37001-10
Production and service provision controls
ISO37001-10.2
Nonconformity and Corrective Action
ISO37001-11
Monitoring, measurement, and analysis
ISO37001-12
Internal audit program
ISO37001-13
Management review process
ISO37001-14
Customer satisfaction measurement
ISO37001-16
Continual improvement methodology
ISO37001-17
Corrective and preventive actions
ISO37001-4.1
Understanding the Organization and Its Context
ISO37001-4.2
Interested Parties
ISO37001-4.3
Scope of the ABMS
ISO37001-4.5
Bribery Risk Assessment
ISO37001-5.1.1
Governing Body Leadership
ISO37001-5.1.2
Top Management Leadership
ISO37001-5.2
Anti-Bribery Policy
ISO37001-5.3.2
Anti-Bribery Compliance Function
ISO37001-7.2.1
Employee Competence
ISO37001-7.2.2.1
Employee Due Diligence
ISO37001-7.3
Anti-Bribery Awareness and Training
ISO37001-8.10
Investigating and Dealing with Bribery
ISO37001-8.2
Business Associate Due Diligence
ISO37001-8.3
Financial Controls
ISO37001-8.4
Non-Financial Controls
ISO37001-8.5
Anti-Bribery Commitments by Controlled Parties
ISO37001-8.6
Commitments to Anti-Bribery by Business Associates
ISO37001-8.7
Gifts, Hospitality, Donations, Sponsorships
ISO37001-8.8
Managing Inadequate Anti-Bribery Controls
ISO37001-8.9
Raising Concerns
ISO37001-9.1
Monitoring, Measurement, Analysis, Evaluation
ISO37001-9.2
Internal Audit of ABMS
ISO37001-9.3
Management Review
Show the 2 you already have
ISO37001-15
Nonconformity and corrective action
ISO37001-18
Innovation and change management

How this is calculated

Already covered means a mapping runs from a control in ISO 27043 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition