25% of SSAE 18 you already have
UK Gambling Commission already covers about 25% of SSAE 18, leaving
50 of 67 controls as genuinely new work.
Already covered 0
Likely covered 17
New work 50
No control in UK Gambling Commission
maps directly to one in SSAE 18. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in UK Gambling Commission reaches these. This is the list to scope.
SSAE-01Common Attestation Concepts (AT-C 105)
SSAE-02Examination Engagements (AT-C 205)
SSAE-03Review Engagements (AT-C 210)
SSAE-04Agreed-Upon Procedures (AT-C 215)
SSAE-05SOC 1 Engagements (AT-C 320)
SSAE-06SOC 2 Engagements (AT-C 205 with TSC)
SSAE-07SOC 3 General Use Reports
SSAE-08Preconditions for Attestation Engagement
SSAE-09Independence and Ethics
SSAE-10Engagement Risk Assessment
SSAE-11Materiality in Attestation
SSAE-12Written Representations
SSAE-13Other Information in Reports
SSAE-14Reporting on Pro Forma Financial Information (AT-C 310)
SSAE-15Reporting on Compliance (AT-C 315)
SSAE-16Examinations of Prospective Financial Information (AT-C 305)
SSAE-17Engagement Documentation
SSAE-18Quality Management at Firm and Engagement Level
SSAE-19Modifications to the Standard Report
SSAE-20Use by Specified Parties and Restricted Distribution
SSAE18-C1.1C1.1 - Confidential Information Identification
SSAE18-C1.2C1.2 - Confidential Information Disposal
SSAE18-CC1.1CC1.1 - COSO Principle 1: Integrity and Ethical Values
SSAE18-CC1.2CC1.2 - COSO Principle 2: Board Independence and Oversight
SSAE18-CC1.3CC1.3 - COSO Principle 3: Management Structure and Authority
SSAE18-CC1.4CC1.4 - COSO Principle 4: Commitment to Competence
SSAE18-CC1.5CC1.5 - COSO Principle 5: Accountability
SSAE18-CC2.1CC2.1 - COSO Principle 13: Quality Information
SSAE18-CC2.2CC2.2 - COSO Principle 14: Internal Communication
SSAE18-CC2.3CC2.3 - COSO Principle 15: External Communication
SSAE18-CC3.3CC3.3 - COSO Principle 8: Fraud Risk Assessment
SSAE18-CC5.1CC5.1 - COSO Principle 10: Control Activity Selection
SSAE18-CC5.2CC5.2 - COSO Principle 11: Technology General Controls
SSAE18-CC5.3CC5.3 - COSO Principle 12: Control Activity Policies
SSAE18-CC6.1CC6.1 - Logical Access Security Software
SSAE18-CC6.3CC6.3 - Access Removal
SSAE18-CC6.5CC6.5 - Logical Access to Protected Assets
SSAE18-CC6.6CC6.6 - External Threats and Security Measures
SSAE18-CC6.7CC6.7 - Data Transmission Restrictions
SSAE18-CC6.8CC6.8 - Unauthorized Software Prevention
SSAE18-CC7.1CC7.1 - Infrastructure and Software Monitoring
SSAE18-CC7.2CC7.2 - Anomaly Monitoring in Operations
SSAE18-CC7.3CC7.3 - Security Event Evaluation
SSAE18-CC9.1CC9.1 - Risk Mitigation Activities
SSAE18-PI1.2PI1.2 - System Processing Completeness and Accuracy
SSAE18-PI1.3PI1.3 - Processing Error Handling
SSAE18-SOC1-01Control Environment
SSAE18-SOC1-03Information and Communication
SSAE18-SOC1-04Monitoring Activities
SSAE18-SOC1-05Control Activities for Financial Processing
Show the 17 you already have
SSAE18-A1.1A1.1 - Availability Commitments and Requirements
SSAE18-A1.2A1.2 - Environmental Protections and Recovery
SSAE18-A1.3A1.3 - Recovery Plan Testing
SSAE18-CC3.1CC3.1 - COSO Principle 6: Risk Identification
SSAE18-CC3.2CC3.2 - COSO Principle 7: Risk Analysis
SSAE18-CC3.4CC3.4 - COSO Principle 9: Change Management
SSAE18-CC6.2CC6.2 - New User Registration and Authorization
SSAE18-CC6.4CC6.4 - Physical Access Restrictions
SSAE18-CC7.4CC7.4 - Incident Response
SSAE18-CC7.5CC7.5 - Incident Recovery
SSAE18-CC8.1CC8.1 - Infrastructure and Software Change Management
SSAE18-CC9.2CC9.2 - Vendor and Business Partner Risk Management
SSAE18-P1.1P1.1 - Privacy Notice
SSAE18-P1.2P1.2 - Choice and Consent
SSAE18-PI1.1PI1.1 - Processing Integrity Definition
SSAE18-SOC1-02Risk Assessment
SSAE18-SOC1-06Transaction Processing Controls
How this is calculated
Already covered means a mapping runs from a control in UK Gambling Commission to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition