Compliance frameworks and what a receipt maps evidence to.
One line for every regime a regulated firm asks about, including the ones Déjà does not map. SOC 2, NYDFS Part 500 and ISO 27001 each have a page listing every control Déjà's control table tracks, with the receipt types that map evidence to each.
For compliance, risk and internal audit teams mapping evidence to a control matrix.
Every regime, and where Déjà stands.
A receipt maps evidence to a control, never the whole of it: the rest of each control is tested outside Déjà. These pages are about the frameworks your firm is examined against. Déjà's own controls and attestation status are on Security & trust.
- SOC 2Maps evidence to
Common criteria of the 2017 Trust Services Criteria. Every other criterion is evidenced outside Déjà.
SOC 2 controls · 7 of 33 listed have a receipt type
- NYDFS Part 500Maps evidence to
23 NYCRR Part 500, as amended in November 2023. Every other section is evidenced outside Déjà.
NYDFS Part 500 controls · 2 of 16 listed have a receipt type
- ISO 27001Maps evidence to
ISO/IEC 27001:2022 Annex A: incident management planning and change management.
ISO 27001 controls · 2 of 2 listed have a receipt type
- HIPAAMaps evidence to
The Security Rule's administrative safeguards, 45 CFR 164.308.
No page of its own yet. Its controls are listed under For auditors.
- DORAOwner's view only
Shown on your own Frameworks page in Déjà's own numbering until counsel has reviewed the regulation's references, and left out of the auditor's evidence pack until then. Data is held in the US only today.
- SR 11-7Owner's view only
Shown on your own Frameworks page in Déjà's own numbering until counsel has reviewed the guidance's references, and left out of the auditor's evidence pack until then.
- SOX ITGCNot mapped
Not mapped. Supports change-management evidence through SOC 2 CC8.1, and through the ServiceNow change record a deploy ran under, which is shown beside the receipt. [Awaiting owner: counsel review of the SOX change-management wording]
- SEC / FINRANot mapped
Not mapped. No control in Déjà's table names an SEC or FINRA rule.
- FCANot mapped
Not mapped. No control in Déjà's table names an FCA rule, and data is held in the US only.
- PCI DSSNot mapped
Not mapped. No control in Déjà's table names a PCI DSS requirement.
- NIST CSFNot mapped
Not mapped. No control in Déjà's table names a NIST CSF function or category.
- FedRAMPNot mapped
Not mapped, and Déjà holds no FedRAMP authorisation.
A regime marked owner's view only is shown on your own Frameworks page in Déjà's numbering until counsel has reviewed the standard's references. It has no public page and is left out of an auditor's evidence pack until then.
What Déjà does not do for you.
- Determine root cause
- An attribution receipt (R1) records the change Déjà's scoring tied a failure to, and the score it reached. That is evidence for an investigation, not its finding.
- Certify a control
- A receipt maps evidence to a control. Whether the control is designed and operating effectively is the auditor's opinion, and the rest of each control is tested outside Déjà.
- Attest
- Déjà issues no attestation report or audit opinion about your firm. Déjà's own attestation status is on Security & trust.
Déjà supplies a record of what connected systems reported and what changed. It does not determine root cause, file regulatory reports, or discharge any obligation under any regime: those remain with your named accountable individuals.
Walk the list with us, control by control.
Bring your control matrix. We will say which rows a receipt maps evidence to, and which ones it does not.