The unit of work is the control
A framework requirement is a sentence; a control is a thing that can be tested: “privileged accounts are reviewed quarterly and the review is signed”. CCM works at that level. For each control it states what evidence proves it, how fresh that evidence must be, who reviews it and what happens when it fails. A hundred well-specified controls monitored this way cover several frameworks at once, because the requirement sentences map onto them.
Automated where possible, honest where not
A CCM program that claims full automation is usually claiming coverage it does not have. Identity, cloud configuration and endpoint controls can be tested from connectors; a training completion, a supplier contract clause or a board approval cannot. The workable model mixes both: automated tests where a source exists, evidence upload with AI-assisted validation and human review elsewhere, and a single status vocabulary so a reader never has to ask which kind of proof sits behind a green.
What it feeds
Control status is the input that makes the rest of the GRC honest. The residual score of a risk inherits from the status of its controls; a KRI can count controls whose evidence has aged; the compliance view of a framework is the sum of its mapped controls’ status on the day it is read. CCM is therefore less a reporting feature than the source of truth the register, the indicators and the audit all read from.