Back to Frameworks

ISO 37301:2021

International
v2021
7 domains
47 controls
Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

Clause 6 – ISO 37301:2021

3 controls
Controls in the Clause 6 – ISO 37301:2021 domain of ISO 37301:20213 controls
CodeTitle
iso-37301-2021::6.1Actions to address risks and opportunities
iso-37301-2021::6.2Compliance objectives and planning to achieve them
iso-37301-2021::6.3Planning of changes

Context of the organization – ISO 37301:2021

6 controls
Controls in the Context of the organization – ISO 37301:2021 domain of ISO 37301:20216 controls
CodeTitle
iso-37301-2021::4.1Understanding the organization and its context
iso-37301-2021::4.2Understanding the needs and expectations of interested parties
iso-37301-2021::4.3Determining the scope of the compliance management system
iso-37301-2021::4.4Compliance management system
iso-37301-2021::4.5Compliance obligations
iso-37301-2021::4.6Compliance risk assessment

Improvement – ISO 37301:2021

2 controls
Controls in the Improvement – ISO 37301:2021 domain of ISO 37301:20212 controls
CodeTitle
iso-37301-2021::10.1Continual improvement
iso-37301-2021::10.2Nonconformity and corrective action

Leadership – ISO 37301:2021

8 controls
Controls in the Leadership – ISO 37301:2021 domain of ISO 37301:20218 controls
CodeTitle
iso-37301-2021::5.1Leadership and commitment
iso-37301-2021::5.1.1Governing body and top management
iso-37301-2021::5.1.2Compliance culture
iso-37301-2021::5.1.3Compliance governance
iso-37301-2021::5.2Compliance policy
iso-37301-2021::5.3Roles, responsibilities and authorities
iso-37301-2021::5.3.2Compliance function
iso-37301-2021::5.3.4Personnel

Operation – ISO 37301:2021

4 controls
Controls in the Operation – ISO 37301:2021 domain of ISO 37301:20214 controls
CodeTitle
iso-37301-2021::8.1Operational planning and control
iso-37301-2021::8.2Establishing controls and procedures
iso-37301-2021::8.3Raising concerns
iso-37301-2021::8.4Investigation processes

Performance evaluation – ISO 37301:2021

13 controls
Controls in the Performance evaluation – ISO 37301:2021 domain of ISO 37301:202113 controls
CodeTitle
iso-37301-2021::9.1Monitoring, measurement, analysis and evaluation
iso-37301-2021::9.1.1General
iso-37301-2021::9.1.2Sources of feedback on compliance performance
iso-37301-2021::9.1.3Development of indicators
iso-37301-2021::9.1.4Compliance reporting
iso-37301-2021::9.1.5Record-keeping
iso-37301-2021::9.2Internal audit
iso-37301-2021::9.2.1General
iso-37301-2021::9.2.2Internal audit programme
iso-37301-2021::9.3Management review
iso-37301-2021::9.3.1General
iso-37301-2021::9.3.2Management review inputs
iso-37301-2021::9.3.3Management review results

Support – ISO 37301:2021

11 controls
Controls in the Support – ISO 37301:2021 domain of ISO 37301:202111 controls
CodeTitle
iso-37301-2021::7.1Resources
iso-37301-2021::7.2Competence
iso-37301-2021::7.2.1General
iso-37301-2021::7.2.2Employment process
iso-37301-2021::7.2.3Training
iso-37301-2021::7.3Awareness
iso-37301-2021::7.4Communication
iso-37301-2021::7.5Documented information
iso-37301-2021::7.5.1General
iso-37301-2021::7.5.2Creating and updating documented information
iso-37301-2021::7.5.3Control of documented information

Your Compliance Coverage

If you comply with ISO 37301:2021, you already cover:

Maps to 87 other frameworks

47 total controls
ISO 27701:2019
38 source controls mapped|37 target controls covered
81%
ISO 9001:2015
36 source controls mapped|36 target controls covered
77%
ISO 37001:2016
35 source controls mapped|34 target controls covered
74%
ISO 22000:2018
33 source controls mapped|32 target controls covered
70%
ISO 14001:2015
31 source controls mapped|30 target controls covered
66%
ISO 45001:2018
30 source controls mapped|30 target controls covered
64%
ISO/IEC 42001:2023
29 source controls mapped|28 target controls covered
62%
ISO 22301:2019
29 source controls mapped|26 target controls covered
62%
ISO 50001:2018 - Energy Management Systems
27 source controls mapped|28 target controls covered
57%
ISO 55001:2014
23 source controls mapped|21 target controls covered
49%
ISO 37301
22 source controls mapped|22 target controls covered
47%
ISO 19011:2018
21 source controls mapped|33 target controls covered
45%
ISO 14004:2016
21 source controls mapped|14 target controls covered
45%
ISO 39001:2012 - Road Traffic Safety Management
18 source controls mapped|83 target controls covered
38%
ISO 41001:2018 - Facility Management Systems
17 source controls mapped|84 target controls covered
36%
ISO 56002
17 source controls mapped|80 target controls covered
36%
ISO 22313:2020 - Guidance on Business Continuity Management Systems
17 source controls mapped|74 target controls covered
36%
ISO 27001:2022
17 source controls mapped|15 target controls covered
36%
ISO 37002:2021 - Whistleblowing Management Systems
16 source controls mapped|77 target controls covered
34%
ISO/IEC 27003:2017
16 source controls mapped|35 target controls covered
34%
AS9100D - Aerospace Quality Management System
16 source controls mapped|24 target controls covered
34%
ISO 9001
15 source controls mapped|14 target controls covered
32%
ISO 22000
14 source controls mapped|11 target controls covered
30%
ISO 30401
13 source controls mapped|13 target controls covered
28%
ISO 45001
13 source controls mapped|10 target controls covered
28%
ISO 55001
13 source controls mapped|13 target controls covered
28%
ISO/IEC TR 24028:2020
13 source controls mapped|2 target controls covered
28%
ISO 13485:2016
11 source controls mapped|4 target controls covered
23%
ISO 31000:2018
9 source controls mapped|5 target controls covered
19%
ISO 37001
8 source controls mapped|8 target controls covered
17%
ASIS SPC.1-2009 - Organizational Resilience Standard
8 source controls mapped|7 target controls covered
17%
ISO/IEC 25012:2008 - Data Quality Model
8 source controls mapped|2 target controls covered
17%
ISO/IEC 27010:2015
8 source controls mapped|1 target controls covered
17%
ISO 28001:2007 Supply Chain Security Management
7 source controls mapped|4 target controls covered
15%
ISO 27005:2022
7 source controls mapped|7 target controls covered
15%
ISO/IEC 27031:2011
7 source controls mapped|4 target controls covered
15%
ISO/IEC 38500:2024
7 source controls mapped|21 target controls covered
15%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
6 source controls mapped|12 target controls covered
13%
ISO/IEC 23894:2023
5 source controls mapped|10 target controls covered
11%
ISO 19011
3 source controls mapped|3 target controls covered
6%
ISO 10006:2003
3 source controls mapped|3 target controls covered
6%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
3 source controls mapped|3 target controls covered
6%
ISO 22320:2018
3 source controls mapped|4 target controls covered
6%
ISO/IEC 27701:2019
3 source controls mapped|3 target controls covered
6%
BS 65000:2014 - Guidance on Organizational Resilience
2 source controls mapped|2 target controls covered
4%
ISO 20400:2017 - Sustainable Procurement
2 source controls mapped|2 target controls covered
4%
ISO 31000
2 source controls mapped|2 target controls covered
4%
APRA CPS 220 Risk Management
2 source controls mapped|1 target controls covered
4%
CSA STAR (Security, Trust, Assurance, and Risk)
1 source controls mapped|1 target controls covered
2%
ITIL 4
1 source controls mapped|1 target controls covered
2%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
1 source controls mapped|1 target controls covered
2%
ISO/IEC 17025:2017 - General Requirements for Testing and Calibration
1 source controls mapped|1 target controls covered
2%
2%
EU Digital Markets Act
1 source controls mapped|1 target controls covered
2%
Digital Services Act (DSA) - Regulation (EU) 2022/2065
1 source controls mapped|1 target controls covered
2%
ISO/IEC 27050 - Electronic Discovery (Parts 1-4)
1 source controls mapped|1 target controls covered
2%
NFPA 1600 - Standard on Continuity, Emergency, and Crisis Management
1 source controls mapped|1 target controls covered
2%
NIST SP 800-128
1 source controls mapped|1 target controls covered
2%
AML/CTF Act 2006 (Australia)
1 source controls mapped|1 target controls covered
2%
Canada's Anti-Spam Legislation (CASL)
1 source controls mapped|1 target controls covered
2%
EU AI Act
1 source controls mapped|1 target controls covered
2%
EASA Part-IS - Information Security in Aviation
1 source controls mapped|1 target controls covered
2%
Union Customs Code (UCC) - Regulation (EU) No 952/2013
1 source controls mapped|1 target controls covered
2%
Canada Artificial Intelligence and Data Act (AIDA)
1 source controls mapped|1 target controls covered
2%
ISAE 3402 - Assurance Reports on Controls at a Service Organisation
1 source controls mapped|1 target controls covered
2%
ISO/IEC 29147:2018
1 source controls mapped|2 target controls covered
2%
ISO 22318
1 source controls mapped|2 target controls covered
2%
FFIEC IT Examination Handbook
1 source controls mapped|1 target controls covered
2%
NIST SP 800-183
1 source controls mapped|2 target controls covered
2%
PCI P2PE
1 source controls mapped|1 target controls covered
2%
ISO 22317
1 source controls mapped|1 target controls covered
2%
NSA Guidance for Transition to Quantum-Resistant Cryptography
1 source controls mapped|1 target controls covered
2%
PCI SSF
1 source controls mapped|1 target controls covered
2%
UK Bribery Act 2010
1 source controls mapped|1 target controls covered
2%
ISO 22316
1 source controls mapped|1 target controls covered
2%
NIST SP 1800-32
1 source controls mapped|1 target controls covered
2%
ISO/IEC 30111:2019
1 source controls mapped|1 target controls covered
2%
ISO 26000:2010
1 source controls mapped|1 target controls covered
2%
APRA CPS 230 Operational Risk Management
1 source controls mapped|1 target controls covered
2%
Brazil AI Framework
1 source controls mapped|1 target controls covered
2%
PCI PIN Security
1 source controls mapped|1 target controls covered
2%
ISO/IEC 27004:2016
1 source controls mapped|1 target controls covered
2%
OWASP ASVS
1 source controls mapped|1 target controls covered
2%
ISO 10007:2017
1 source controls mapped|1 target controls covered
2%

Frequently Asked Questions

What is ISO 37301:2021?

ISO 37301:2021 is a compliance framework from International with 7 domains and 47 controls. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does ISO 37301:2021 have?

ISO 37301:2021 has 47 controls organised across 7 domains. The largest domains are Performance evaluation – ISO 37301:2021 (13 controls), Support – ISO 37301:2021 (11 controls), Leadership – ISO 37301:2021 (8 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does ISO 37301:2021 map to?

ISO 37301:2021 maps to 87 other compliance frameworks. The top mapping partners are ISO 27701:2019 (81% coverage), ISO 9001:2015 (77% coverage), ISO 37001:2016 (74% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with ISO 37301:2021 compliance?

Start your ISO 37301:2021 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 37301:2021 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 47 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required