Risk assessment performed and repeated
Risks to objectives are identified and assessed on a defined cadence and on material change.
DTCF normalises what an organization must achieve into 10 objectives across 10 families, then maps each to the frameworks practitioners face. Mappings are graded: fully addressed, partially addressed, or deliberately absent with the reason recorded. An empty cell is a finding about the framework, not a gap in your programme.
DTCF 2026.1 · published 10 Sep 2026 · CC BY 4.0 · free to use with attribution
Risks to objectives are identified and assessed on a defined cadence and on material change.
Risks are recorded with inherent and residual judgement, an owner, a treatment decision and a review date.
People receive role-relevant training on joining and at a defined cadence, and completion is evidenced.
Security-relevant events are logged, retained and reviewed, with alerts that reach a person who acts.
Security requirements, review and testing are part of how software is built and released.
Reportable incidents are assessed and notified to regulators and affected people within the applicable deadlines.
AI and automated decision systems in use are inventoried with purpose, owner, data and risk classification.
AI systems are assessed for harm, bias, robustness and transparency before use, and the assessment is revisited on change.
People affected by automated decisions are told, and a competent person can intervene.
Evidence shows what was done, by whom and when, and is kept for the period the obligation requires.
First edition. Objectives are normalised statements of what an organization must achieve. Mappings are graded: full, partial, or a recorded absence with the reason it is absent. An empty cell is a finding about the framework, not about the objective.
Framework names and references are the property of their publishers. DTCF is an independent mapping and is not endorsed by them. Corrections are welcome through the contact form and are published in the edition changelog.