Framework Workbench · Agentic Controls Mapping
Framework Mapper
Automated discovery of regulatory updates across NIST, CIS, ISO, NIS2 and EU regulation — parsed, structured into canonical controls, mapped to the internal control framework with traceable lineage, and kept current by a continuous-monitoring agent.
Frameworks Tracked
0
▲2 Q2
Requirements
0
▲49 WoW
Controls Mapped
0
▲30 WoW
Coverage
0%
▲1 WoW
Open Gaps
0
▼2 WoW
Pending Review
0
Latest Intake · EU AI Act (2024/1689)
Intake Run · eur-lex.europa.eucomplete
- New release detected09:12:04DiscoveryRegulation (EU) 2024/1689 · eur-lex feed · corrigendum OJ L series
- Document parsed09:12:31ParsingPDF · 144 pp → 412 segments · article citations preserved
- Requirements normalized09:13:02Structuring68 canonical requirements · stable IDs AIACT-001…068
- Persisted to Framework DB09:13:20Structuringpostgres: 68 rows · embeddings indexed → pgvector
- Crosswalked to ICF09:14:05Mapping41 of 68 mapped · 12 lineage overlaps (GDPR · ISO 27001)
- Fit to org context09:14:48Applicabilitydeployer profile · EU region · 23 obligations in scope
- Gaps published09:15:12Gaps7 new gaps (3 high) · routed to Recommendation agent
fully automated · no human touch3m 08s
Relevant For You · Applicability23 / 68
DeployerEU RegionHigh-Risk UseNot a Provider
- Art. 4gapAI literacy for staff operating AI systemsno matching control
- Art. 26(2)gapAssign human oversight for high-risk AI useno matching control
- Art. 26(6)partialRetain automatically generated logs ≥ 6 monthsICF-LM-05
- Art. 26(7)partialInform workers before deploying high-risk AIICF-HR-03
- Art. 50coveredTransparency for chatbots & synthetic contentICF-DP-09
- Art. 72coveredPost-market monitoring cooperation (deployer)ICF-IR-08
45 provider-only obligations excluded from scope
New Gaps · From This Release7
- HIGH3–5 wksAI literacy programme for operators of AI systemsorigin Art. 4
- HIGH2–4 wksHuman-oversight roles for high-risk AI deploymentsorigin Art. 26(2)
- HIGH4–6 wksFundamental-rights impact assessment procedureorigin Art. 27
- MED1–2 wks6-month retention for high-risk AI system logsorigin Art. 26(6)
- MED1 wkWorker notification prior to high-risk AI useorigin Art. 26(7)
+ 2 low-severity gaps5 control drafts ready ↓
Agent Pipeline
Discovery
12 sources watched
Parsing
NIS2 · 214 segments
Structuring
canonical IDs assigned
Mapping
crosswalk → ICF
Validation
34 in review
Applicability
Gaps & Findings
Recommendation
Reporting
Monitoring
Agent Swarms
Agent Swarm · Framework Intakesources → segments → canonical controls
Framework Discoverydone
Source & version detection
- ·Monitor subscriptions
- ·Register sources
- ·Detect new releases
12 sources · 2 new releases
Document Parsingdone
Raw document extraction
- ·Parse PDF / DOCX / XLSX / HTML
- ·Segment contents
- ·Preserve citations
214 segments · citations kept
Control Structuringdone
Canonical control creation
- ·Extract domains
- ·Normalize requirements
- ·Assign stable IDs
1,847 requirements structured
Harmonization & QAcross-framework alignment · human-in-the-loop
Control Mappingactive
Cross-framework alignment
- ·Map to internal taxonomy
- ·Identify overlaps
- ·Trace lineage
1,412 mapped · 88 overlaps
Validationactive
Quality & governance checks
- ·Flag duplicates
- ·Score confidence
- ·Route exceptions
34 routed to human review
Assessment Swarmfit to org context → gaps → drafted controls
Applicabilityactive
Fit to org context
- ·Match sector / region
- ·Evaluate triggers
- ·Prioritize controls
GxP scope · 3 regions
Gaps & Findingsqueued
Internal comparison
- ·Compare expected vs current
- ·Classify gaps
- ·Assign severity
43 open gaps
Recommendationqueued
Internal improvement action
- ·Draft missing controls
- ·Suggest control language
- ·Estimate effort
9 drafts pending
Delivery & Lifecycleanalyst consumption · continuous reassessment
Reporting & Chatqueued
Analyst consumption
- ·Answer with citations
- ·Generate reports
- ·Support ad-hoc search
128 Q&A sessions
Continuous Monitoringactive
Lifecycle management
- ·Watch source changes
- ·Trigger reassessments
- ·Maintain history
next sweep in 04:12
Framework Registry
| Framework▾ | Version | Requirements▾ | Mapped▾ | Gaps▾ | Last Sync | Status |
|---|---|---|---|---|---|---|
NIST CSFnist.gov | 2.0 | 106 | 100% | 3 | 02 Jul 2026 | synced |
NIST SP 800-53nist.gov | Rev 5 | 1,189 | 84% | 18 | 28 Jun 2026 | synced |
ISO/IEC 27001iso.org | 2022 | 93 | 100% | 2 | 24 Jun 2026 | synced |
CIS Controlscisecurity.org | v8.1 | 153 | 92% | 6 | 30 Jun 2026 | review |
NIS2 Directiveeur-lex.europa.eu | EU 2022/2555 | 214 | 46% | 11 | 14 Jul 2026 | mapping |
EU DORAeur-lex.europa.eu | 2022/2554 | 64 | 71% | 3 | 11 Jul 2026 | mapping |
EU AI Acteur-lex.europa.eu | 2024/1689 | 68 | 60% | 7 | 14 Jul 2026 | new release |
Harmonization & Gaps
Requirements · Mapping Status
76%
Coverage- Mapped141276%
- Review17810%
- Unmapped25714%
Open Gaps · By DomainGAPS
- Incident Reporting & Notification11NIS2 · DORA
- Supply Chain / Third-Party9800-53 · CSF
- Resilience Testing7DORA
- Access Control & PAM6CIS · ISO
- Logging & Monitoring5800-53
- Data Protection (GxP)5ISO · GxP
Agent Activity10
- 14:02:11[DISCOVERY]eur-lex feed: NIS2 implementing act rev detected (v2024-07)
- 14:02:19[PARSING]parse_pdf(nis2_implementing_act.pdf) → 214 segments, citations preserved
- 14:02:40[STRUCTURING]normalized 41 requirements → assigned IDs NIS2-IR-001…041
- 14:03:02[MAPPING]crosswalk NIS2-IR-004 → ICF-IR-12 (lineage: 800-53 IR-6)
- 14:03:05[MAPPING]overlap detected: NIS2-IR-004 ≈ DORA Art.19 — merged lineage
- 14:03:18[VALIDATION]confidence 0.63 < 0.75 threshold → routed to human review
- 14:03:29[APPLICABILITY]NIS2 Art.23 applies: essential entity, EU region, GxP unaffected
- 14:03:44[GAPS]expected control ICF-IR-24 (24h notification) not found — severity H
- 14:04:01[RECOMMEND]drafted control language for ICF-IR-24 · est. effort M (2–4 wks)
- 14:04:10[MONITORING]reassessment scheduled for CIS v8.1 delta (3 changed safeguards)
Requirement → Control Traceability
| Requirement ID | External Obligation | Internal Control | Confidence▾ | Status▾ |
|---|---|---|---|---|
| NIS2-IR-004 | Notify CSIRT of significant incidents within 24 hoursNIS2 | ICF-IR-12 | 0.91 | validated |
| DORA-19.1 | Classify ICT-related incidents by materiality thresholdsDORA | ICF-IR-08 | 0.87 | validated |
| CSF-GV.SC-06 | Due diligence prior to supplier relationshipNIST CSF | ICF-TP-03 | 0.63 | in review |
| NIS2-IR-009 | Final incident report within one month of notificationNIS2 | — | — | gap |
| 800-53-AC-6(7) | Review privileges of privileged users periodically800-53 | ICF-AC-17 | 0.94 | validated |
| CIS-8.11 | Conduct audit log reviews on a weekly basis or moreCIS v8.1 | ICF-LM-05 | 0.71 | in review |
| DORA-24.2 | Threat-led penetration testing every 3 yearsDORA | — | — | gap |
Drafted Controls
Missing Controls · Drafted by Recommendation Agent5
- HIGHest. 2–4 wks24-hour early-warning notification procedure to national CSIRTICF-IR-24 · origin NIS2 Art.23
- HIGHest. 6–8 wksThreat-led penetration testing programme (TLPT) on critical functionsICF-RT-07 · origin DORA Art.26
- MEDest. 3–5 wksRegister of ICT third-party contractual arrangementsICF-TP-11 · origin DORA Art.28
- MEDest. 1–2 wksWeekly privileged-session log review with documented sign-offICF-LM-09 · origin CIS 8.11
- LOWest. 1 wkGxP audit-trail retention policy alignment (21 CFR Part 11)ICF-DP-15 · origin GxP baseline
High-Level Architecture
Framework Sources
NIST · EU · NIS2 · CIS · Tavily
Orchestrator
FastAPI · MCP · task routing
Agent Swarms
intake · QA · assessment
Framework DB
Postgres · pgvector RAG
GRC Platform
ServiceNow sync
Model Garden
self-host + frontier API