TSL GRC emblem

Native support for every major Canadian compliance framework.

Stop mapping controls manually. TSL GRC does it for you.

Controls mapped

Every framework arrives with its controls pre-mapped to TSL GRC's shared control library — no manual crosswalks.

AI policy templates

100% coverage of AI-generated policy templates, ready to tailor to your organization.

Evidence guides

Included with every control, so your team knows exactly what to collect for audit.

Canadian frameworks

AIDA

6 controls

Artificial Intelligence and Data Act (Proposed)

Innovation, Science and Economic Development Canada (ISED)

Explore coverage

CASL

6 controls

Canada's Anti-Spam Legislation (CASL)

Canadian Radio-television and Telecommunications Commission (CRTC)

Explore coverage

CCCS Baseline

7 controls

CCCS - Baseline Cyber Security Controls

Canadian Centre for Cyber Security

Explore coverage

CCSPA

6 controls

Critical Cyber Systems Protection Act (Proposed)

Public Safety Canada

Explore coverage

CIRO

52 controls

CIRO Investment Dealer Rules

Canadian Investment Regulatory Organization

Explore coverage

CPPA

7 controls

Consumer Privacy Protection Act

CPPA

Explore coverage

CyberSecure Canada

7 controls

CyberSecure Canada Certification Program

Standards Council of Canada

Explore coverage

FSRA IT

7 controls

FSRA IT Risk Management Guidance

Financial Services Regulatory Authority of Ontario

Explore coverage

ITSG-33

242 controls

ITSG-33

IT Security Risk Management

Explore coverage

ITSG-33 SECRET MM

179 controls

ITSG-33 Annex 4A Profile 3 (SECRET / Medium / Medium)

Canadian Centre for Cyber Security

Explore coverage

OSFI B-10

6 controls

OSFI Guideline B-10

Third-Party Risk Management

Explore coverage

OSFI B-13

14 controls

OSFI Guideline B-13

Technology and Cyber Risk Management

Explore coverage

OSFI B-15

6 controls

OSFI Guideline B-15

Climate Risk Management

Explore coverage

OSFI E-21

8 controls

OSFI Guideline E-21

Operational Risk Management

Explore coverage

OSFI IS

10 controls

OSFI Integrity and Security Guideline

Integrity and Security Guideline

Explore coverage

PCMLTFA

8 controls

Proceeds of Crime (Money Laundering) and Terrorist Financing Act

FINTRAC

Explore coverage

PHIPA

10 controls

Personal Health Information Protection Act

Ontario Information and Privacy Commissioner

Explore coverage

PIPA (AB)

8 controls

Personal Information Protection Act (Alberta)

Office of the Information and Privacy Commissioner of Alberta

Explore coverage

PIPA (BC)

8 controls

Personal Information Protection Act (British Columbia)

Office of the Information and Privacy Commissioner of BC

Explore coverage

PIPEDA

17 controls

Personal Information Protection and Electronic Documents Act

Office of the Privacy Commissioner of Canada

Explore coverage

QC Law 25

10 controls

Quebec Law 25

Act Respecting the Protection of PI in the Private Sector

Explore coverage

Global & US frameworks

ISO 27001

93 controls

ISO/IEC 27001:2022

Information security management systems

Explore coverage

NIST AI RMF

72 controls

NIST AI RMF

AI Risk Management Framework

Explore coverage

NIST CSF 2.0

106 controls

NIST CSF 2.0

Cybersecurity Framework

Explore coverage

SOC 1

12 controls

SOC 1 / SSAE 18

System and Organization Controls 1

Explore coverage

SOC 2

62 controls

SOC 2

System and Organization Controls 2

Explore coverage

CCPA

18 controls

CCPA

California Consumer Privacy Act

Explore coverage

CJIS

13 controls

CJIS

Criminal Justice Information Services

Explore coverage

CMMC

14 controls

CMMC

Cybersecurity Maturity Model Certification

Explore coverage

CRI Profile

19 controls

CRI Profile

Cyber Risk Institute Profile

Explore coverage

FedRAMP

20 controls

FedRAMP

Federal Risk and Authorization Management Program

Explore coverage

HIPAA

29 controls

HIPAA

Health Insurance Portability and Accountability Act

Explore coverage

HITRUST CSF

14 controls

HITRUST CSF

Health Information Trust Alliance

Explore coverage

NIST 800-171

110 controls

NIST 800-171

Protecting Controlled Unclassified Information

Explore coverage

NIST 800-53

1196 controls

NIST 800-53

Security and Privacy Controls for Info Systems

Explore coverage

SOX ITGC

18 controls

SOX ITGC

Sarbanes-Oxley IT General Controls

Explore coverage

USDP

13 controls

USDP

US Data Privacy

Explore coverage
TSL GRC emblem

Ready to automate your frameworks?

Run a free gap analysis and see exactly which controls TSL GRC already maps for you across Canadian and global frameworks.

Run Gap Analysis Free →