Compliance

ISO Clause Mapping Tool

Map business processes to ISO 27001 Annex A controls.

Last reviewed by the Radiatus Cloud team

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

Map your processes to ISO 27001 controls

ISO 27001’s Annex A lists security controls, and connecting them to your actual business processes is central to implementation. This tool maps business processes to the relevant Annex A controls, so you can see which controls each process needs.

Why mapping processes to controls matters

Controls exist to protect something, and that something is your business processes and the assets they use. Mapping each process to the Annex A controls that apply to it grounds the abstract control list in your real operations, showing which controls each part of the business needs and, conversely, whether any process is inadequately controlled. This is how ISO implementation moves from a generic checklist to a programme fitted to your organisation, and it produces the traceability between processes, risks and controls that the standard and auditors expect.

A tool, not legal advice

This is a practical aid, not legal advice, and regulations change and vary by circumstance. Confirm your obligations with a qualified professional before relying on any assessment or generated document. It runs entirely in your browser, so nothing you enter is uploaded, which matters when the input describes your compliance posture.

Related tools

Frequently Asked Questions

What is Annex A?

The list of security controls in ISO 27001, covering areas from access control to cryptography, which organisations select from based on their risks.

Why map processes to controls?

Because controls exist to protect business processes and their assets. Mapping grounds the abstract control list in your real operations and shows what each process needs.

What does the mapping reveal?

Which controls each process requires, and whether any process is inadequately controlled, producing the traceability the standard expects.

Does every process need every control?

No. Each process needs the controls relevant to its risks. Mapping shows which apply where rather than treating all controls as universal.

Is my input uploaded?

No. The tool runs entirely in your browser.

Privacy & Security

Mapping done locally.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.