Skip to main content
Version: 1.0.0-beta

Custom Frameworks

Beyond built-in frameworks (NCA ECC, PDPL, CSCC), AIIA supports creating custom compliance frameworks for internal policies, industry standards, or regional regulations.

Creating a Custom Framework

  1. Navigate to Compliance → Frameworks → + New Framework
  2. Fill in framework details:
FieldDescriptionRequired
CodeUnique identifier (e.g., INTERNAL-IT-2027)
NameFramework name
Name (AR)Arabic nameOptional
DescriptionFramework purpose and scopeOptional
VersionFramework version number
Issuing BodyWho issued the frameworkOptional
Categoryregulatory, standard, internal

Adding Requirements

Manual Entry

  1. Click + Add Requirement in the framework
  2. Enter the requirement code, title, and description
  3. Set the hierarchy level (domain, subdomain, control)
  4. Repeat for all requirements

Import from CSV

  1. Click Import → CSV
  2. Upload a CSV file with columns: code, title, description, parent_code
  3. Map the CSV columns to framework fields
  4. Review and confirm the import

Hierarchical Structure

Requirements support parent-child relationships:

Domain 1
├── Subdomain 1.1
│ ├── Requirement 1.1.1
│ └── Requirement 1.1.2
└── Subdomain 1.2
└── Requirement 1.2.1

Cross-Framework Mapping

Custom frameworks can be mapped to built-in frameworks:

  • Link custom requirements to NCA ECC, PDPL, or other standards
  • Identify shared controls across frameworks
  • Reduce duplicate compliance work

Versioning

When updating a framework:

  • Create a new version rather than editing the existing one
  • Active assessments continue on their original version
  • New assessments use the latest version

Permissions

ActionManagerCAEAdmin
Create frameworks
Edit frameworks
Import requirements
Delete frameworks
Map controls