---
title: "POST /audit/frameworks"
method: POST
path: "/audit/frameworks"
---

# POST /audit/frameworks

`POST /audit/frameworks`

Creates a framework with one or more controls. A framework is a collection of controls that you can use to evaluate your backup practices. By using pre-built customizable controls to define your policies, you can evaluate whether your backup practices comply with your policies and which resources are not yet in compliance.

## Request body

- object
  - `FrameworkName` string, required — The unique name of the framework. The name must be between 1 and 256 characters, starting with a letter, and consisting of letters (a-z, A-Z), numbers (0-9), and underscores (_).
  - `FrameworkDescription` string — An optional description of the framework with a maximum of 1,024 characters.
  - `FrameworkControls` FrameworkControl[], required — A list of the controls that make up the framework. Each control in the list has a name, input parameters, and scope.
    - `ControlName` string, required — The name of a control. This name is between 1 and 256 characters.
    - `ControlInputParameters` ControlInputParameter[] — A list of <code>ParameterName</code> and <code>ParameterValue</code> pairs.
      - `ParameterName` string — The name of a parameter, for example, <code>BackupPlanFrequency</code>.
      - `ParameterValue` string — The value of parameter, for example, <code>hourly</code>.
    - `ControlScope` object — The scope of a control. The control scope defines what the control will evaluate. Three examples of control scopes are: a specific backup plan, all backup plans with a specific tag, or all backup plans. For more information, see <a href="aws-backup/latest/devguide/API_ControlScope.html"> <code>ControlScope</code>.</a>
      - `ComplianceResourceIds` String[] — The ID of the only Amazon Web Services resource that you want your control scope to contain.
      - `ComplianceResourceTypes` ARN[] — Describes whether the control scope includes one or more types of resources, such as <code>EFS</code> or <code>RDS</code>.
      - `Tags` object — The tag key-value pair applied to those Amazon Web Services resources that you want to trigger an evaluation for a rule. A maximum of one key-value pair can be provided. The tag value is optional, but it cannot be an empty string. The structure to assign a tag is: <code>[{"Key":"string","Value":"string"}]</code>.
  - `IdempotencyToken` string — A customer-chosen string that you can use to distinguish between otherwise identical calls to <code>CreateFrameworkInput</code>. Retrying a successful request with the same idempotency token results in a success message with no action taken.
  - `FrameworkTags` object — Metadata that you can assign to help organize the frameworks that you create. Each tag is a key-value pair.

## Response `200`

Success

- CreateFrameworkOutput
  - `FrameworkName` string — The unique name of the framework. The name must be between 1 and 256 characters, starting with a letter, and consisting of letters (a-z, A-Z), numbers (0-9), and underscores (_).
  - `FrameworkArn` string — An Amazon Resource Name (ARN) that uniquely identifies a resource. The format of the ARN depends on the resource type.

## Other responses

- `480` — AlreadyExistsException
- `481` — LimitExceededException
- `482` — InvalidParameterValueException
- `483` — MissingParameterValueException
- `484` — ServiceUnavailableException

---

[API](https://skmtc.net/aws/apis/backup.md) · [All operations](https://skmtc.net/aws/apis/backup/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/aws/backup/versions/386d8a5f8871/schema)
