Skip to content
Compliance · frameworks

Compliance frameworks and what a receipt maps evidence to.

One line for every regime a regulated firm asks about, including the ones Déjà does not map. SOC 2, NYDFS Part 500 and ISO 27001 each have a page listing every control Déjà's control table tracks, with the receipt types that map evidence to each.

For compliance, risk and internal audit teams mapping evidence to a control matrix.

01 · Regimes

Every regime, and where Déjà stands.

A receipt maps evidence to a control, never the whole of it: the rest of each control is tested outside Déjà. These pages are about the frameworks your firm is examined against. Déjà's own controls and attestation status are on Security & trust.

  • SOC 2Maps evidence to

    Common criteria of the 2017 Trust Services Criteria. Every other criterion is evidenced outside Déjà.

    SOC 2 controls · 7 of 33 listed have a receipt type

  • NYDFS Part 500Maps evidence to

    23 NYCRR Part 500, as amended in November 2023. Every other section is evidenced outside Déjà.

    NYDFS Part 500 controls · 2 of 16 listed have a receipt type

  • ISO 27001Maps evidence to

    ISO/IEC 27001:2022 Annex A: incident management planning and change management.

    ISO 27001 controls · 2 of 2 listed have a receipt type

  • HIPAAMaps evidence to

    The Security Rule's administrative safeguards, 45 CFR 164.308.

    No page of its own yet. Its controls are listed under For auditors.

  • DORAOwner's view only

    Shown on your own Frameworks page in Déjà's own numbering until counsel has reviewed the regulation's references, and left out of the auditor's evidence pack until then. Data is held in the US only today.

  • SR 11-7Owner's view only

    Shown on your own Frameworks page in Déjà's own numbering until counsel has reviewed the guidance's references, and left out of the auditor's evidence pack until then.

  • SOX ITGCNot mapped

    Not mapped. Supports change-management evidence through SOC 2 CC8.1, and through the ServiceNow change record a deploy ran under, which is shown beside the receipt. [Awaiting owner: counsel review of the SOX change-management wording]

  • SEC / FINRANot mapped

    Not mapped. No control in Déjà's table names an SEC or FINRA rule.

  • FCANot mapped

    Not mapped. No control in Déjà's table names an FCA rule, and data is held in the US only.

  • PCI DSSNot mapped

    Not mapped. No control in Déjà's table names a PCI DSS requirement.

  • NIST CSFNot mapped

    Not mapped. No control in Déjà's table names a NIST CSF function or category.

  • FedRAMPNot mapped

    Not mapped, and Déjà holds no FedRAMP authorisation.

A regime marked owner's view only is shown on your own Frameworks page in Déjà's numbering until counsel has reviewed the standard's references. It has no public page and is left out of an auditor's evidence pack until then.

02 · Limits

What Déjà does not do for you.

Determine root cause
An attribution receipt (R1) records the change Déjà's scoring tied a failure to, and the score it reached. That is evidence for an investigation, not its finding.
Certify a control
A receipt maps evidence to a control. Whether the control is designed and operating effectively is the auditor's opinion, and the rest of each control is tested outside Déjà.
Attest
Déjà issues no attestation report or audit opinion about your firm. Déjà's own attestation status is on Security & trust.

Déjà supplies a record of what connected systems reported and what changed. It does not determine root cause, file regulatory reports, or discharge any obligation under any regime: those remain with your named accountable individuals.

Walk the list with us, control by control.

Bring your control matrix. We will say which rows a receipt maps evidence to, and which ones it does not.