Disclaimer: Independent educational project. Not affiliated with GoRico. Built by Kaushal Khodifad. Data from public sources; figures are estimates.return to portfolio
Disclaimer: Independent educational project. Not affiliated with GoRico.
TechCorp Solutions
3 Active Programs
TC

AMCF Control Mapping

Accorian Multi-Compliance Framework - map a control once, demonstrate compliance many times.

Map Once, Comply Many

The real GORICO platform uses Accorian's Multi-Compliance Framework (AMCF) to map a single common control to requirements across SOC 2, ISO 27001, HIPAA and more. This demo reconstructs that idea on a synthetic library: every figure below is computed live from 30 common controls and 99 control mappings in the demo data layer.

30 common controls
satisfy 99 framework requirements
30

Common Controls

99

Framework Mappings

3

Frameworks Covered

57-70%

Evidence Reuse / Effort Saved

What "map once" is worth per audit cycle

illustrative - set your own
~320h

conservative: 40 duplicate implementations avoided(direct-equivalence mappings only)

up to ~552h

generous: 69 avoided(counts partial/related matches too)

Math: running SOC 2 + ISO 27001 + HIPAA as separate programs means implementing and evidencing all 99 framework-specific controls; the common-control library implements 30 once. Avoided work = mappings − common controls, shown as a conservative-to-generous range because partial matches still need incremental effort. Control counts are computed from the demo mapping table; the hours figure is your assumption, not a claim.

FullPartial
AMCF CodeControl TitleCategorySOC 2ISO 27001HIPAA
AMCF-AC-001Access Control PolicyAccess Control
CC6.1
A.5.15
164.312(a)(1)
AMCF-AC-002User Registration and DeprovisioningAccess Control
CC6.2
A.5.15
164.308(a)(3)
AMCF-AC-003Privileged Access ManagementAccess Control
CC6.3
A.8.2
164.312(a)(1)
AMCF-AC-004Multi-Factor AuthenticationAccess Control
CC6.1
A.8.5
164.312(d)
AMCF-AC-005Access Review and RecertificationAccess Control
CC6.3
A.5.15
164.308(a)(4)
AMCF-RA-001Risk Assessment ProcessRisk Assessment
CC3.1CC3.2
A.5.12
164.308(a)(1)
AMCF-RA-002Risk Treatment PlanningRisk Assessment
CC9.1
A.5.29
164.308(a)(1)
AMCF-RA-003Fraud Risk AssessmentRisk Assessment
CC3.3
A.5.7
164.308(a)(1)
AMCF-IR-001Incident Response PlanIncident Response
CC7.3CC7.4
A.5.24
164.308(a)(6)
AMCF-IR-002Incident Detection and AnalysisIncident Response
CC7.1CC7.2
A.5.25
164.308(a)(6)
AMCF-IR-003Incident Communication and ReportingIncident Response
CC2.3
A.5.26
164.308(a)(6)
AMCF-AT-001Security Awareness ProgramAwareness & Training
CC1.4
A.6.3
164.308(a)(5)
AMCF-AT-002Role-Based Security TrainingAwareness & Training
CC1.4
A.6.3
164.308(a)(5)
AMCF-CM-001Change Management ProcessChange Management
CC8.1
A.8.32
164.308(a)(8)
AMCF-CM-002Separation of EnvironmentsChange Management
CC8.1
A.8.31
164.312(c)(1)
AMCF-DP-001Data Classification and HandlingData Protection
CC6.7
A.5.12
164.312(c)(1)
AMCF-DP-002Encryption at Rest and in TransitData Protection
CC6.1
A.8.24
164.312(e)(1)164.312(a)(1)
AMCF-DP-003Data Retention and DisposalData Protection
CC6.5
A.7.10
164.310(d)(1)
AMCF-ML-001Security Monitoring and LoggingMonitoring & Logging
CC7.1CC7.2
A.8.15A.8.16
164.312(b)
AMCF-ML-002Audit Log Protection and ReviewMonitoring & Logging
CC4.1
A.8.15
164.312(b)
AMCF-BC-001Business Continuity PlanningBusiness Continuity
CC9.1
A.5.30
164.308(a)(7)
AMCF-BC-002Backup and RecoveryBusiness Continuity
CC7.5
A.5.29
164.308(a)(7)
AMCF-PS-001Physical Access ControlsPhysical Security
CC6.4
A.7.1A.7.2
164.310(a)(1)
AMCF-PS-002Media and Equipment SecurityPhysical Security
CC6.5
A.7.10
164.310(d)(1)
AMCF-GP-001Information Security PolicyGovernance & Policy
CC1.1CC5.3
A.5.1
164.308(a)(1)
AMCF-GP-002Roles and ResponsibilitiesGovernance & Policy
CC1.3
A.5.2
164.308(a)(2)
AMCF-GP-003Compliance MonitoringGovernance & Policy
CC4.1CC4.2
A.5.36
164.308(a)(8)
AMCF-VM-001Vulnerability Scanning and RemediationVulnerability Management
CC7.1
A.8.8
164.308(a)(1)
AMCF-VM-002Malware ProtectionVulnerability Management
CC6.8
A.8.7
164.308(a)(5)
AMCF-VN-001Third-Party Risk ManagementVendor Management
CC9.2
A.5.23
164.308(a)(4)

Synthetic demonstration data. AMCF (Accorian Multi-Compliance Framework) and GORICO are products of Accorian; this is an independent educational reconstruction, not the live platform. Framework requirement counts above are computed from the demo control-mapping table, not asserted. Reuse methodology: the low end (57%) counts only the 70 direct (full-equivalence) mappings as avoided work; the high end (70%) counts all 99 mappings, including partial/related matches that still need incremental framework-specific effort.

↑ Independent educational project by Kaushal Khodifad. GoRico is a real company in the GRC & compliance automation space; this design and the underlying prototype were built by Kaushal as a portfolio study. Not affiliated with, endorsed by, or representative of GoRico's actual product. Data is from public sources. Figures are estimates.

Return to portfolioOpen the live demo