CIAO Standard v1.0

CIAO COMMONS — STANDARD
C-AO/STD/001:2026 PUBLIC
CIAO Standard v1.0
The Common Information Assurance Oversight Standard
Date Issued  1 January 2026
Review Date  1 January 2027
Cite as: CIAO Standard. (2026). CIAO Standard v1.0. v1.1. C-AO/STD/001:2026. www.c-ao.com
🟢 Commons — Visible to all members

A Standard for Implementing Standards — A Governance Meta-Standard for Multi-Framework Assurance

1. Architectural Position Statement

CIAO — Common Information Assurance Oversight — is a governance meta-standard that sits architecturally above conventional security and compliance frameworks. It does not replace ISO 27001, NIST CSF, SOC 2, GDPR, POPIA, or any other established standard. It governs them collectively, providing the coordination layer that has been absent from the compliance ecosystem.

The compliance landscape is fragmented by design. Every framework defines its own control catalogue, documentation requirements, audit process, and terminology. Organisations operating under multiple simultaneous obligations — which is now the rule, not the exception — are forced to maintain parallel compliance systems: duplicated policies, duplicated evidence, duplicated audit preparation. The cost is not only financial. It is governance capacity, leadership attention, and institutional resilience.

CIAO addresses the architectural gap that no existing framework has formally occupied: multi-framework assurance orchestration. Through a formal control equivalence taxonomy, a unified governance model, and a structured implementation architecture, CIAO enables organisations to achieve audit-readiness across multiple frameworks simultaneously, from a single governance posture.

Formal Definition: CIAO is a framework-agnostic governance meta-standard that maps, coordinates and operationalises the overlapping requirements of established international compliance frameworks — enabling organisations to achieve multi-framework assurance through a single, structured governance posture.

🔵 Core — Core membership and above
🔒 Core membership required — Core membership required to access the full architectural detail of the CIAO Standard.  Login  or become a member →

🟡 Essential — Essential membership and above
🔒 Essential membership required — Essential membership required to access the CIAO governance architecture in full.  Login  or become a member →

2. The CIAO 5-Layer Governance Architecture

CIAO operates at the apex of a five-layer governance architecture. Layers 1 through 3 are occupied by existing frameworks and control systems. CIAO formally governs Layers 4 and 5 — the coordination and oversight layers that have historically been left unoccupied.

LayerNameDescriptionOccupied By
LAYER 5Assurance OversightMeta-standard authority — governs the entire compliance architectureCIAO
LAYER 4Framework CoordinationISO 27001 / NIST CSF / SOC 2 / GDPR / POPIA mappings and equivalenceCIAO
LAYER 3Unified Control LibraryNormalised control taxonomy (CIAO GOV series)CIAO + Frameworks
LAYER 2Policy & Evidence SystemOperational governance documentationOrganisation
LAYER 1Operational ControlsTechnical and organisational controlsOrganisation

This architecture resolves the structural problem that existing frameworks have not addressed: each operates within its own layer, defining controls, risk processes, or governance principles for a single regime. None provides the coordination mechanism required when multiple regimes must be satisfied simultaneously. CIAO occupies the apex — Layer 5 — as the assurance oversight model that governs the entire stack.

🟠 Professional — Professional membership and above
🔒 Professional membership required — Professional membership required for framework cross-references and heatmap detail.  Login  or become a member →

What CIAO Is Not

CIAO is not a control framework — it does not define technical security controls or replace ISO 27001 Annex A, NIST CSF control families, or SOC 2 Trust Services Criteria. CIAO is not a risk framework — it does not define risk assessment methodology or risk treatment processes. CIAO is not a compliance checklist — compliance checklists are point-in-time artefacts; CIAO provides the governance infrastructure for continuous, multi-framework assurance.

What CIAO Is

CIAO is a governance meta-standard. It defines: the architectural relationship between compliance frameworks; a unified control equivalence taxonomy (the CIAO GOV series); the assurance lifecycle for multi-framework audit readiness; and the governance infrastructure through which organisations operationalise compliance across regimes without duplication.


3. CIAO Control Equivalence Taxonomy — GOV Seed Table

The Control Equivalence Taxonomy is the architectural heart of CIAO. Each CIAO GOV control represents a unified governance obligation that spans multiple frameworks simultaneously. This public seed table (GOV-001 to GOV-015) is licensed under CC BY-SA 4.0 as part of the CIAO Commons tier. The full GOV taxonomy (GOV-001 to GOV-050+), sector-specific overlays, and cross-framework evidence mapping workbooks are available in CIAO Essentials and above.

All references are to current published versions: ISO/IEC 27001:2022, NIST CSF 2.0, South African POPIA (Act 4 of 2013), AICPA SOC 2 Trust Services Criteria (2022), and EU GDPR 2016/679.

Protected Framework This framework is protected under CC BY-NC-ND 4.0patent pending. See Multitier Licensing.
CIAO IDDomainControl NameISO 27001:2022NIST CSF 2.0POPIASOC 2GDPR
GOV-001GovernanceInformation Governance PolicyA.5.1GV.PO-01S.19CC1.1Art.24
GOV-002GovernanceRoles & ResponsibilitiesA.5.2GV.RR-01S.55CC1.3Art.37–39
GOV-003RiskRisk Assessment & TreatmentCl.6.1.2GV.RM-01S.19CC3.1–3.2Art.32, 35
GOV-004AssetsAsset Classification & ManagementA.5.9–5.12ID.AMS.14CC6.1Art.30
GOV-005AccessAccess Control GovernanceA.5.15–5.18PR.AAS.19CC6.1–6.3Art.32
GOV-006IncidentsIncident Management OversightA.5.24–5.27RS.CO, RS.ANS.22CC7.3–7.5Art.33–34
GOV-007ContinuityBusiness Continuity GovernanceA.5.29–5.30RC.RP, RC.COS.19A1.2–A1.3Art.32
GOV-008Supply ChainThird-Party & Supply Chain OversightA.5.19–5.22GV.SCS.21CC9.2Art.28
GOV-009ComplianceCompliance Monitoring & ReportingA.5.35–5.36GV.OCS.51CC4.1–4.2Art.30, 83
GOV-010PrivacyData Protection & Privacy GovernanceA.5.34GV.POCond.1–8P1–P8Art.5–11
GOV-011PeopleSecurity Awareness & Training GovernanceA.6.3PR.ATS.19CC1.4, CC2.2Art.39(1)(b)
GOV-012ChangeChange Management GovernanceA.8.32PR.IP-03S.19CC8.1Art.25
GOV-013AuditAudit & Assurance OversightA.5.35, A.8.34ID.IMS.55CC4.1–4.2Art.39
GOV-014ThreatsVulnerability & Threat GovernanceA.8.8ID.RA, DE.CMS.19CC7.1–7.2Art.32
GOV-015ArchitectureInformation Architecture & ClassificationA.5.12–5.13ID.AM-05S.14CC6.1Art.5(1)(f)
CIAO GOV Seed Table v1.0 — Licensed CC BY-SA 4.0 — Full taxonomy (GOV-001 to GOV-050+) available in Essentials tier and above

4. CIAO Positioned Against Existing Governance Approaches

CIAO occupies a structural category that existing governance approaches do not fill. The table below clarifies CIAO’s unique niche within the broader governance landscape.

ApproachWhat It DefinesWhat It Does Not DefineCIAO Relationship
ISO 27001 / 27002Information security controls and management systemCross-framework coordination or assurance orchestrationCIAO Layer 4 maps ISO controls into unified GOV taxonomy
NIST CSF 2.0Cybersecurity risk governance functionsMulti-framework compliance coordinationCIAO Layer 4 aligns NIST functions to equivalent CIAO controls
ISACA COBITEnterprise governance principlesDetailed control mapping or compliance orchestrationCIAO complements COBIT governance principles at Layer 5
GDPR / POPIARegulatory obligations for data protectionTechnical control definitions or cross-framework mappingCIAO GOV-010 consolidates privacy obligations across regimes
CIAO StandardMulti-framework assurance orchestration at governance levelIndividual control implementation (by design)The meta-standard that governs all frameworks simultaneously

5. Open Principles

CIAO’s foundation is built on disruptive Open Principles that challenge spiralling bureaucracy and compliance costs:


6. The CIAO Assurance Lifecycle

The CIAO assurance lifecycle defines the process through which organisations move from framework fragmentation to unified multi-framework audit readiness:

#PhaseActionOutput
01DefineEstablish the unified CIAO GOV control taxonomy relevant to the organisation’s applicable frameworksScoped CIAO control register
02MapMap organisational frameworks to CIAO control equivalence classes — identify overlaps, gaps, and consolidated obligationsCross-framework equivalence map
03ImplementDevelop and deploy operational policies and governance documentation against the unified CIAO control registerCIAO-aligned policy library
04CollectGather compliance evidence against CIAO controls — evidence reused across all mapped frameworks simultaneouslyUnified evidence repository
05ValidateValidate assurance coverage against each applicable framework using CIAO equivalence mappingsMulti-framework assurance report
06DemonstratePresent audit-ready documentation to auditors and regulators — single governance posture satisfying multiple frameworksAudit readiness package

7. Membership Tier Content Architecture

For the canonical detailed treatment of tier content depth and the artefact ladder (Manual → Operating Policy Framework → Enterprise Control Framework → Sub-Policies → Processes → Procedures → Implementation artefacts), see Standard Architecture & Tier Content Depth.

The CIAO membership model is designed as a governance maturity ladder. Each tier provides everything included in all tiers below it. The Commons tier is permanently free and publicly accessible — it constitutes the open standard layer of CIAO.

TierAccessContent Included
COMMONSFreeCIAO Architecture (5-Layer Model), Open Principles, CIAO Glossary, GOV Seed Table (GOV-001 to GOV-015), Framework Comparison Overview
COREEntry Paid3 enterprise-grade policies + Framework Mapping Starter Pack (full GOV-001 to GOV-015 detail)
ESSENTIALS€9910 policies + Information Management System structure + Full GOV Taxonomy GOV-001 to GOV-050
PROFESSIONAL€99930 policies + Cross-framework evidence mapping workbooks + Multi-user access + Operational framework templates
ENTERPRISE€9,999Full CIAO suite + Unlimited users + Sector-specific overlays (Financial, Health, Public Sector) + Dedicated secure environment
CONGLOMERATEBespokeEverything in Enterprise + White-label subdomain portal + Custom logo + Multi-entity governance architecture

Licensed under Creative Commons CC BY-SA 4.0. CIAO Standard v1.0 — March 2026 — www.c-ao.com

⚫ Enterprise & Conglomerate — Implementation artifacts
🔒 Enterprise membership required — Enterprise membership required for procedures, templates and work instructions.  Login  or become a member →

Enterprise and Conglomerate implementation content will be added here — procedures, templates, and work instructions aligned to this document.

● LIVE CONTENT  ·  Verified 15 May 2026 at 09:52 UTC  ·  Version 1.1  ·  Always current at c-ao.com  ·  © CIAO Standard Secretariat 2026