Every framework you answer to, decoded.
What each regulation is, who it applies to, and the exact evidence auditors expect — maintained as living requirements, not PDFs gathering dust.
01 Food safety
5 frameworksFSMA 204
FDA’s traceability rule: keep and produce lot-level records for high-risk foods within 24 hours.
HACCP
The preventive food-safety system behind almost every food regulation: identify hazards, control them at critical points, prove it.
SQF
The GFSI scheme most demanded by North American retailers — with supplier documentation woven through every module.
BRCGS
The GFSI scheme with the strictest supplier-approval clauses — Issue 9 makes raw-material risk assessment explicit.
ISO 22000
The international FSMS standard combining HACCP with management-system discipline across the supply chain.
02 Pharma & life sciences
2 frameworksGMP · 21 CFR 211
FDA’s current Good Manufacturing Practice: every component, supplier and test result documented and defensible.
21 CFR Part 11
The FDA rule that makes electronic compliance records trustworthy: audit trails, access control, signature integrity.
03 ESG & trade
3 frameworksUFLPA
US customs law with a rebuttable presumption: prove your supply chain is forced-labor-free, or your goods don’t enter.
EUDR
Sell cattle, cocoa, coffee, palm oil, rubber, soy or wood products into the EU? You now owe plot-level geolocation proof.
CSRD / CSDDD
The EU’s twin sustainability regimes turn your supplier relationships into reportable, auditable data.
04 Quality management
1 framework05 Security & privacy
5 frameworksISO 27001
The international ISMS standard — and the supplier-security clauses your enterprise customers audit you against.
SOC 2
The de-facto North American security attestation — vendor management evidence is sampled in every Type II audit.
GDPR
EU data protection law — Article 28 makes you accountable for every processor in your chain.
HIPAA
US health-data law — every vendor touching PHI needs a BAA and documented oversight.
NIST CSF
The US cybersecurity framework — CSF 2.0 elevates supply-chain risk management into the new Govern function.
Not PDFs gathering dust — clauses that stay current.
Every framework in this library is maintained inside ComplianceFlow as structured requirements. When a regulation changes, your mapping changes with it.
Decoded in plain English
Each clause is rewritten as what it actually asks of you and your suppliers — no legal archaeology required.
Mapped to evidence
Every requirement is tied to the exact documents auditors sample: COAs, audit trails, supplier assessments.
Synced on change
Regulatory updates are tracked and your requirement mapping is refreshed — so the library you read is the one you’re audited against.
Your frameworks, mapped to your suppliers.
Public standards, customer specifications and internal policies live side-by-side — every clause tied to the supplier evidence that proves it.