Framework Settings
Enable, configure, and manage compliance frameworks.
Framework Settings
Framework settings control which compliance frameworks are active and how they're configured for your organization.
Framework settings require admin access. Contact your organization admin if you don't have access.
Accessing Framework Settings
Go to Settings
Click Settings in the sidebar.
Click "Frameworks"
Opens framework configuration.
Enabled Frameworks
Viewing Enabled Frameworks
See which frameworks are currently active:
- Framework name and version
- Enable/disable toggle
- Configuration status
- Last analysis date
Available Frameworks
PartnerAlly supports:
| Framework | Description |
|---|---|
| SOC 2 | Trust Service Criteria |
| ISO 27001 | Information Security Management |
| HIPAA | Healthcare data protection |
| GDPR | EU data protection |
| PCI DSS | Payment card security |
| AML/BSA | Anti-money laundering |
| NIST CSF | Cybersecurity framework |
| SOX | Financial controls |
Enabling a Framework
Find the Framework
Locate in the available frameworks list.
Click "Enable"
Toggle or click enable button.
Configure Options
Set framework-specific options.
Confirm
Framework is now active.
What Happens When You Enable
- Framework controls are loaded
- Existing documents are re-analyzed
- New gaps may be identified
- Framework appears in filters and reports
Disabling a Framework
Before Disabling
Consider:
- Existing gaps for this framework
- Active workflows linked to it
- Reporting and metrics impact
- Audit implications
Disabling Process
Find the Framework
Locate in enabled frameworks.
Click "Disable"
Toggle or click disable.
Confirm Action
Acknowledge the impact.
Framework Deactivated
Controls are hidden (not deleted).
After Disabling
- Framework gaps are hidden (not deleted)
- No new gaps are created for this framework
- Existing data is preserved
- Can re-enable anytime
Disabling a framework hides but doesn't delete data. Re-enable to see historical gaps and evidence.
Framework Configuration
SOC 2 Configuration
| Option | Description |
|---|---|
| Trust Service Criteria | Select which TSC to include |
| Points of Focus | Include detailed points of focus |
| Type | Type I or Type II focus |
ISO 27001 Configuration
| Option | Description |
|---|---|
| Version | 2013 or 2022 |
| Annex A Scope | Which control domains to include |
| SoA Support | Statement of Applicability integration |
HIPAA Configuration
| Option | Description |
|---|---|
| Rule Focus | Privacy, Security, or Both |
| Entity Type | Covered Entity or Business Associate |
| Safeguards | Which safeguard categories |
Other Frameworks
Each framework has specific configuration options. Review when enabling.
Control Customization
Adding Custom Controls
If your organization has additional requirements:
- Open framework settings
- Click "Custom Controls"
- Add control details
- Map to existing controls if applicable
Excluding Controls
Mark controls as not applicable:
- Find the control
- Click "Not Applicable"
- Document the reason
- Control excluded from analysis
Control Mapping
Link controls across frameworks:
- See related controls
- Identify overlaps
- Reduce duplicate work
Framework Versions
Version Management
When frameworks update:
- New version becomes available
- Existing version continues working
- Transition at your pace
Upgrading Versions
Review Changes
See what's new in the version.
Plan Transition
Identify impact on your program.
Enable New Version
Activate the new version.
Migrate
Transition gaps and evidence.
Framework Analysis
Triggering Re-Analysis
Re-analyze documents against frameworks:
- Go to Framework Settings
- Select framework
- Click "Re-analyze Documents"
- All documents are re-analyzed
Analysis Scope
Control what's analyzed:
- All documents
- Documents updated since last analysis
- Specific document types
Best Practices
Framework Selection
Choose frameworks based on:
- Customer requirements
- Regulatory obligations
- Industry standards
- Business goals
Phased Enablement
Start with primary frameworks:
- Enable most critical first
- Build compliance foundation
- Add additional frameworks
- Manage workload growth
Regular Review
Review framework settings:
- Quarterly for configuration
- Annually for relevance
- When regulations change
- When business changes
Common Questions
How many frameworks should I enable?
Depends on your needs:
- Start with 1-3 primary frameworks
- Add more as capacity allows
- Quality over quantity
Will enabling more frameworks create more gaps?
Yes. Each framework brings additional controls. More frameworks = more potential gaps initially.
Can I use custom frameworks?
Contact support for custom framework needs. Standard frameworks are available by default.
How do framework updates affect my data?
When frameworks update:
- Existing data is preserved
- New controls may create new gaps
- Transition is managed
Next Steps
- Notifications - Configure framework alerts
- Integrations - Connect tools
- Admin - Manage organization