59% of ISO 39001:2012 you already have
ISO 30401 already covers about 59% of ISO 39001:2012, leaving
69 of 168 controls as genuinely new work.
Already covered 3
Likely covered 96
New work 69
What is genuinely new work
Nothing in ISO 30401 reaches these. This is the list to scope.
ISO-22313-4.1Understanding the organization and its context
ISO-22313-4.2Understanding the needs and expectations of interested parties
ISO-22313-4.3Determining the scope of the BCMS
ISO-22313-4.4Business continuity management system
ISO-22313-6.2Business continuity objectives and plans to achieve them
ISO-22313-6.3Planning changes to the BCMS
ISO-22313-8.3Business continuity strategies and solutions
ISO-22313-8.4Business continuity plans and procedures
ISO-22313-8.5Exercise programme
ISO-37002-4.1Understanding the organization and its context
ISO-37002-4.2Understanding the needs and expectations of interested parties
ISO-37002-4.3Determining the scope of the whistleblowing management system
ISO-37002-4.4Whistleblowing management system
ISO-37002-5.2Whistleblowing policy
ISO-37002-6.2Whistleblowing management system objectives and planning
ISO-39001-4.1Understanding the organization and its context
ISO-39001-4.2Understanding the needs and expectations of interested parties
ISO-39001-4.3Determining the scope of the RTS management system
ISO-39001-4.4RTS management system
ISO-39001-6.2RTS performance factors
ISO-39001-6.3RTS objectives and planning to achieve them
ISO-39001-8.2Emergency preparedness and response
ISO-41001-4.2Understanding the needs and expectations of interested parties
ISO-41001-4.4Facility management system
ISO-41001-5.2Facility management policy
ISO-41001-6.2Facility management objectives and planning to achieve them
ISO-41001-6.3Planning of changes
ISO-41001-7.6Organizational knowledge
ISO-41001-8.2Coordination with stakeholders
ISO-41001-8.3Integration of services
ISO-50001-4.1Understanding the organization and its context
ISO-50001-4.2Understanding the needs and expectations of interested parties
ISO-50001-4.3Determining the scope of the EnMS
ISO-50001-4.4Energy management system
ISO-50001-5.2Energy policy
ISO-50001-6.2Objectives, energy targets and planning to achieve them
ISO-50001-6.3Energy review
ISO-50001-6.4Energy performance indicators (EnPIs)
ISO-50001-6.5Energy baseline (EnB)
ISO-50001-6.6Planning for the collection of energy data
ISO-50001-9.2Evaluation of compliance with legal and other requirements
ISO-56002-4.1Understanding the organization and its context
ISO-56002-4.2Understanding the needs and expectations of interested parties
ISO-56002-4.4Establishing the innovation management system
ISO-56002-5.2Innovation policy
ISO-56002-5.3Innovation vision and strategy
ISO-56002-5.5Organizational culture
ISO-56002-6.2Innovation objectives and planning to achieve them
ISO-56002-6.3Organizational structures
ISO-56002-6.4Innovation portfolios
ISO-56002-7.6Tools and methods
ISO-56002-7.7Strategic intelligence management
ISO-56002-7.8Intellectual property management
ISO39001-4.1Understanding the Organization and Its Context
ISO39001-4.2Needs and Expectations of Interested Parties
ISO39001-4.4RTS Management System
ISO39001-6.2RTS Performance Factors
ISO39001-6.2.PostCrashPost-Crash Response
ISO39001-6.2.SafeRoadUsersSafe Road Users
ISO39001-6.2.SafeRoadsSafe Roads and Roadsides
ISO39001-6.2.SafeSpeedsSafe Speeds
ISO39001-6.2.SafeVehiclesSafe Vehicles
ISO39001-6.3RTS Objectives and Planning
ISO39001-7.4Communication and Coordination
ISO39001-8.2Emergency Preparedness and Response
ISO39001-9.1.CrashCrash and Other RTS Incident Investigation
Show the 99 you already have
ISO-39001-10.1Nonconformity and corrective action
ISO-41001-10.1Nonconformity and corrective action
ISO-56002-10.2Deviation, nonconformity and corrective action
ISO-22313-10.1Nonconformity and corrective action
ISO-22313-10.2Continual improvement
ISO-22313-5.1Leadership and commitment
ISO-22313-5.3Organizational roles, responsibilities and authorities
ISO-22313-6.1Actions to address risks and opportunities
ISO-22313-7.4Communication
ISO-22313-7.5Documented information
ISO-22313-8.1Operational planning and control
ISO-22313-8.2Business impact analysis and risk assessment
ISO-22313-9.1Monitoring, measurement, analysis and evaluation
ISO-22313-9.2Internal audit
ISO-22313-9.3Management review
ISO-37002-10.1Nonconformity and corrective action
ISO-37002-10.2Continual improvement
ISO-37002-5.1Leadership and commitment
ISO-37002-5.3Organizational roles, responsibilities and authorities
ISO-37002-6.1Actions to address risks and opportunities
ISO-37002-7.3Awareness and training
ISO-37002-7.4Communication
ISO-37002-7.5Documented information
ISO-37002-9.1Monitoring, measurement, analysis and evaluation
ISO-37002-9.2Internal audit
ISO-37002-9.3Management review
ISO-39001-10.2Continual improvement
ISO-39001-5.1Leadership and commitment
ISO-39001-5.3Organizational roles, responsibilities and authorities
ISO-39001-6.1Actions to address risks and opportunities
ISO-39001-7.4Communication
ISO-39001-7.5Documented information
ISO-39001-8.1Operational planning and control
ISO-39001-9.1Monitoring, measurement, analysis and evaluation
ISO-39001-9.2Internal audit
ISO-39001-9.3Management review
ISO-41001-10.2Continual improvement
ISO-41001-4.1Understanding the organization and its context
ISO-41001-4.3Determining the scope of the FM management system
ISO-41001-5.1Leadership and commitment
ISO-41001-5.3Organizational roles, responsibilities and authorities
ISO-41001-6.1Actions to address risks and opportunities
ISO-41001-7.4Communication
ISO-41001-7.5Documented information
ISO-41001-8.1Operational planning and control
ISO-41001-8.4Control of outsourced processes and services
ISO-41001-9.1Monitoring, measurement, analysis and evaluation
ISO-41001-9.2Internal audit
ISO-41001-9.3Management review
ISO-50001-10.1Nonconformity and corrective action
ISO-50001-10.2Continual improvement
ISO-50001-5.1Leadership and commitment
ISO-50001-5.3Organizational roles, responsibilities and authorities
ISO-50001-6.1Actions to address risks and opportunities
ISO-50001-7.4Communication
ISO-50001-7.5Documented information
ISO-50001-8.1Operational planning and control
ISO-50001-9.1Monitoring, measurement, analysis and evaluation of energy performance
ISO-50001-9.3Internal audit
ISO-50001-9.4Management review
ISO-56002-10.3Continual improvement
ISO-56002-4.3Determining the scope of the innovation management system
ISO-56002-5.1Leadership and commitment
ISO-56002-5.4Organizational roles, responsibilities and authorities
ISO-56002-6.1Actions to address opportunities and risks
ISO-56002-7.4Communication
ISO-56002-7.5Documented information
ISO-56002-9.1Monitoring, measurement, analysis and evaluation
ISO-56002-9.2Internal audit
ISO-56002-9.3Management review
ISO39001-10.1Nonconformity and Corrective Action
ISO39001-10.2Continual Improvement
ISO39001-5.1Leadership and Commitment
ISO39001-7.5Documented Information
ISO39001-8.1Operational Planning and Control
ISO39001-9.1Monitoring, Measurement, Analysis, and Evaluation
ISO39001-9.2Internal Audit
ISO39001-9.3Management Review
How this is calculated
Already covered means a mapping runs from a control in ISO 30401 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition