Frameworks

Compliance Without Limits

Whether your organization works to one standard or several, AuditAndy provides a unified workspace to manage them together. Coverage differs by framework: some are supported with a complete requirement catalogue from the authoritative publisher, while others are supported as reference coverage, where AuditAndy manages your programme without reproducing the published standard. Each framework states its own coverage in the app before you activate it. Instead of learning different software, maintaining duplicate documentation, or reinventing processes, your team uses one intelligent system powered by AuditAndy AI.

From quality management and cybersecurity to privacy, governance, and sustainability, AuditAndy helps organizations implement, maintain, and continuously improve compliance with confidence.

Why AuditAndy?

Most compliance software focuses on a single standard. Modern organizations rarely do.

  • A defense supplier may work to CMMC 2.0, NIST SP 800-171, and NIST CSF 2.0 at the same time.
  • A healthcare organization may need HIPAA, GDPR, and NIST CSF 2.0.
  • A financial services firm may need GLBA, the FTC Red Flags Rule, and NIST SP 800-53.

AuditAndy manages them all from one intelligent platform.

One Platform. Multiple Frameworks.

Shared Documentation

Create policies, procedures, forms, and records once, then reuse them across multiple standards where applicable.

Unified Audits

Conduct one internal audit that can satisfy requirements across multiple frameworks.

AI Guidance

Ask AuditAndy questions in plain English and receive framework-specific guidance instantly.

Cross-Framework Visibility

Monitor the health of every compliance program from one dashboard instead of switching between multiple systems.

Ask AuditAndy Anything

Get framework-specific answers and generate compliance artifacts in seconds.

What does NIST CSF 2.0 expect for access control?
Create an OSHA forklift inspection checklist.
Summarise the evidence usually expected for 800-171 03.01.01.
What documentation is required for HIPAA risk assessments?
Framework Coverage

What AuditAndy holds for each framework

Support depth varies by framework. Some frameworks include AuditAndy guidance, evidence expectations and assessment procedures for every requirement; others hold the publisher's complete requirement set; others are available as reference catalogues for organising your programme. Each framework states its own coverage in the app before you activate it.

Guided support

Guided support

AuditAndy holds the publisher's complete requirement set plus AuditAndy implementation guidance, evidence expectations and assessment procedures for every requirement. Guided assessment review is available end to end.

Cybersecurity

  • NIST Cybersecurity Framework 2.0
  • NIST SP 800-171 (CUI protection)
  • CMMC 2.0
Supported

Supported catalogue

AuditAndy holds the complete requirement set from the authoritative publisher, and you can run requirements, evidence, assessments, gaps, remediation, audits and reports against it. Requirement-level AuditAndy guidance is not yet written for these frameworks.

Cybersecurity

  • NIST SP 800-53 Rev. 5

Privacy & healthcare

  • HIPAA (Privacy, Security, Breach Notification)
  • GDPR
  • CCPA / CPRA

Financial services

  • GLBA (Safeguards, Privacy, Regulation P)
  • FTC Red Flags Rule

Workplace safety

  • OSHA 29 CFR 1910 (General Industry)
  • OSHA 29 CFR 1926 (Construction)

Life sciences

  • FDA 21 CFR Part 211 (cGMP for finished pharmaceuticals)
Reference catalogue

Reference catalogue

AuditAndy helps you organise a programme for these frameworks, but the catalogue held here does not reproduce the published standard — many are copyrighted and we do not republish them. Coverage figures describe your workspace, not the standard.

Quality & manufacturing

  • ISO 9001
  • AS9100
  • IATF 16949
  • ISO 13485
  • ISO 22000
  • FDA 21 CFR Part 820

Information security

  • ISO/IEC 27001
  • ISO/IEC 27017
  • ISO/IEC 27018
  • ISO/IEC 27701
  • SOC 2
  • PCI DSS
  • CIS Critical Security Controls
  • CIS Benchmarks

Privacy & healthcare

  • PIPEDA

Environment, health & safety

  • ISO 14001
  • ISO 45001
  • ISO 50001

Governance & resilience

  • ISO 22301
  • ISO 31000
  • ISO 55001
  • ISO/IEC 20000
  • ITIL
  • COBIT
  • COSO Internal Control
  • COSO Enterprise Risk Management

Sustainability reporting

  • CSRD
  • GRI Standards
  • SASB Standards
  • TCFD

AuditAndy organises requirements, evidence, assessments, gaps, remediation and reports so your team can prepare for an audit. AuditAndy does not issue, guarantee or determine certification, conformity or regulatory compliance — your auditor, certification body or regulator does.

AI-Powered

AuditAndy AI Across Your Frameworks

AuditAndy AI works across the frameworks you activate, drafting and explaining as you go. People make every compliance determination — AuditAndy never records a verdict on your behalf.

AuditAndy can help you:

  • Explain complex requirements in plain English
  • Compare requirements between frameworks you have activated
  • Draft policies and procedures for your team to review
  • Draft work instructions and forms
  • Build audit checklists
  • Suggest corrective actions
  • Point out requirements with no evidence attached
  • Answer employee compliance questions
  • Organize evidence and assessment work for audit preparation
  • Summarise the current state of your compliance records

AuditAndy AI Assistant

Drafting help, available any time

What does NIST CSF 2.0 expect for access control?
AuditAndy pulls the requirement text you have activated, explains it in plain language, points to the evidence usually expected, and can draft a policy or checklist for your team to review and approve.

Designed to Scale With Your Organization

Whether you're implementing your first certification or managing enterprise-wide compliance across multiple business units, AuditAndy grows with your organization.

Start with one framework, then add others as your programme grows. Requirements, evidence, assessments, and reports stay in the same workspace, so you don't rebuild your documentation each time.

Benefits of a Unified Compliance Platform

Traditional Approach
AuditAndy
Multiple software systems
One unified platform
Duplicate documentation
Shared documentation across frameworks
Manual gap analysis
AI-powered recommendations
Separate audit programs
Integrated audit management
Multiple dashboards
One executive dashboard
Consultant-dependent
AI guidance available 24/7
Spreadsheet tracking
Automated workflows and reporting

Looking for a Specific Framework?

These frameworks have the deepest coverage today. Every framework states its own coverage in the app before you activate it.

NIST Cybersecurity Framework 2.0NIST SP 800-171 (CUI protection)CMMC 2.0NIST SP 800-53 Rev. 5HIPAA (Privacy, Security, Breach Notification)GDPRCCPA / CPRAGLBA (Safeguards, Privacy, Regulation P)FTC Red Flags RuleOSHA 29 CFR 1910 (General Industry)

Ready to see your frameworks in one place?

Activate the standards that matter to your organization and start building a unified compliance program today.

Simplify compliance across your frameworks

Join organizations using AuditAndy to manage quality, security, privacy, and governance standards in one intelligent workspace.