Compliance frameworks

The Compliance area gathers every framework your organisation answers to onto one screen and lets you work down to the individual control that still has nothing behind it.

A framework is a published set of requirements you measure yourself against — ISO 22301, DORA, GDPR. Each breaks into controls. You link policies, procedures, evidence (the proof a control works) and risks to those controls, and those links are all Aegis reads. One detail decides the headline number: a control counts as covered only when at least one linked evidence item is still inside its valid-until date. A control with only a policy, a procedure or a risk linked is partial, not covered.

Switching a framework on does not move your coverage

A newly enabled framework arrives with every control at Not Started and nothing linked to it. That is why the demonstration organisation below reads 0% overall coverage: only 4 of its 3944 controls have current evidence behind them. Coverage rises as you link work to controls, and falls back as that evidence expires.

Who uses it

What's on this screen

Open Compliance from the left menu to land on /compliance. The header reads Compliance over the line "Track control coverage and implementation status across compliance frameworks", with three buttons on the right: Gap Triage (AI), Coverage Triage (AI) and Export. Below run five numbers — Overall Coverage, Total Controls, Covered, Compliant and Overdue Evidence — counting only frameworks that are both enabled and applicable to your organisation. Coverage is green from 80%, yellow from 60%, amber below.

Under the Frameworks heading is a grid of cards, four to a row, each giving the framework name, its percentage, a progress bar and a line such as "2 compliant of 121". The seeded tenant opens with BSI C5:2020, CCPA / CPRA, CMMC 2.0 and CyberFundamentals Framework, and runs on alphabetically below the fold. Only enabled frameworks appear: switching one off removes its card and its entry in the framework filter rather than greying it out. A framework your organisation profile marks as not applicable stays on the grid but is dimmed, shows in place of a percentage and carries a short "not applicable" line. The NIS2 card additionally carries an Essential, Important, Basic or Small badge, taken from your NIS2 classification.

Scroll on to Control Requirements — the controls table, with search, framework, status and owner-group filters above it (a domain filter joins them when the controls on show are grouped that way, and CyberFundamentals adds its own) and columns for Control ID, Description, Framework, Evidence, Procedures, Progress, Status, Owner group and X-Framework. Saved AI insights and Action items from AI close the page.

Reading your position and filtering to one framework

  1. Read Overall Coverage first — the share of controls carrying at least one linked evidence item that is still inside its valid-until date. The four numbers beside it break that down.
  2. Scan the Frameworks grid to see where the work is concentrated. A card at 0% has no control with current evidence behind it yet.
  3. Select a card, say DORA, to filter the table below to that framework. The card gains a highlighted border, the heading becomes Frameworks (click to clear filter) and the table heading reads Control Requirements - DORA. Select it again to clear the filter.
  4. Select Gap Triage (AI). The Control Gap Smart Triage window explains what it will do, then waits for you to press Run Gap Triage.
  5. Select Coverage Triage (AI) for the sister action, which looks at controls with nothing linked at all rather than at open gaps.
  6. Select Export to open Export Compliance Data: a format (JSON, CSV, PDF, OSCAL SSP or OSCAL AR), a scope (All Frameworks, Single Framework or Executive Summary) and which details to include. The file downloads in your browser.
The Compliance overview — coverage numbers, framework cards and the AI and export actions. /compliance.
The Compliance overview — coverage numbers, framework cards and the AI and export actions. /compliance.

Working a single control

The controls table is where coverage is earned. Selecting a row opens a window headed with the control's reference and title: its requirements, its current status, everything linked to it, and any unresolved gaps and active implementation blockers Aegis has recorded.

  1. Filter the table to the work in hand: search matches control text, and the framework, status and owner-group filters narrow it further. Unmapped controls sit at Not Started with empty counts.
  2. Select the row. The control window opens over the page.
  3. With Manager rights or above, work the requirements listed inside the control: each carries a small status control you set to Not Started, In Progress or Complete. You do not set the control's own status by hand. Aegis derives it from the requirements and any unresolved gaps — every requirement Complete and no gap open gives Compliant; every requirement Complete with a gap still open gives Non-Compliant; any requirement In Progress gives In Progress; otherwise it stays Not Started.
  4. If that recalculation changes the control's status and the control has equivalents in other frameworks, a Cross-Framework Sync window asks whether to carry the new status across. You confirm or decline; it never happens silently.
  5. Select AI Implementation Proposal in the footer to have Aegis draft a plan for that control. Read it, edit it, apply the parts that fit; nothing is applied until you say so.
  6. Close the window. The row reflects the new status. Ticking rows in the table raises a bar with Export CSV on it, which downloads only that selection.

The DORA page

DORA (the EU's Digital Operational Resilience Act, Regulation 2022/2554) has its own page at /compliance/dora because it asks for a register of information, not only control statuses. A DORA Readiness bar sits under the header — 25% in the capture, with the note "Complete all four areas to achieve full readiness". Each area has a card: DORA Profile (Configured, with Edit), ICT Assets, Third-Party Providers and Resilience Tests, the last three at 0 here. Navigation cards repeat those registers with their article references.

  1. Select AI Register Readiness. Aegis scores your Register of Information against DORA Article 28(3), then lists the gaps found, each tied to an article, with three to five next steps.
  2. Select Edit on the DORA Profile card to open the profile setup window — entity type (the one required field), category, sector, proportionality tier, competent authority and the applicable-since and last-assessment dates. Save, and the card reads Configured and the readiness bar moves. With no profile yet the button reads Configure; without the DORA update permission there is no button at all.
  3. Read the Saved AI insights panel. Kept runs appear with their date and a confidence badge — the capture holds one saved on 15 July 2026 at "Medium Confidence 57%", reporting that the register cannot be scoped without a configured profile. Show more expands the full text.
  4. Select Create action item to turn a recommendation into tracked work, or Edit and Delete to amend or remove the insight.
  5. Check Action items from AI at the foot. Until you create one, it says there are none and points you back to Create action item.
The DORA landing page — readiness bar, profile and register cards, and one saved AI insight. /compliance/dora.
The DORA landing page — readiness bar, profile and register cards, and one saved AI insight. /compliance/dora.

The EU AI Act page

/compliance/eu-ai-act is the entry point for Regulation 2024/1689. Four numbers follow the header — Total Systems, High Risk, Conformity Passed and FRIA Required — all 0 here, because nothing has been registered. Four navigation cards lead to the registers: AI Systems, Technical Documentation (Annex IV), Transparency Notices (Article 50) and Prohibited Practices Check (Article 5).

  1. Select AI Inventory Readiness. Aegis scores your registered systems on prohibited practices, classification, risk management and data governance, fundamental-rights impact assessment, conformity and registration, tying each gap it finds to an article. With an empty inventory it says exactly that — it does not invent systems, so register them first through AI Systems.
  2. Whatever you keep from a run lands in Saved AI insights. Until then the panel says no insights have been saved yet and tells you to use Save as record.
  3. Action items from AI behaves as it does on the DORA page: empty until you turn a recommendation into a tracked item.
The EU AI Act landing page with an empty inventory and both AI panels unused. /compliance/eu-ai-act.
The EU AI Act landing page with an empty inventory and both AI panels unused. /compliance/eu-ai-act.

The other compliance pages

Page Route What it does
Cross-framework /compliance/cross-framework Shows where the same requirement appears in more than one framework.
Deduplication /compliance/deduplication AI-assisted matching of equivalent controls; you accept or reject each suggestion.
Mock Audit /compliance/mock-audit Practice audit runs with AI-generated questions and a readiness score. Licence-gated.
CyFun maturity /compliance/cyfun/maturity Scores CyberFundamentals controls against your target level.
ISO 42001 /compliance/iso-42001 The AI management system control set. Needs Contributor rights and its own framework entitlement. Early — see below.

The AI assist

Five AI actions live here — Gap Triage (AI), Coverage Triage (AI), the two readiness runs and AI Implementation Proposal. All behave the same way: they read what is recorded, produce a written briefing, and leave the decision to a person. None changes a control, status or mapping on its own.

Gap triage ranks open gaps by severity and control importance — the ranking itself is deterministic, not generated — and sequences them into a 90-day sprint and a 12-month horizon. Coverage triage looks instead at controls with nothing linked at all. Any run can be kept with Save as record and turned into an action item; every AI action is logged and counts against your tenant's AI credits.

Tips and limits

Where this connects

Close gaps by linking work from Policies, Procedures and Evidence, and by recording treatment in Risks. Control Mapping, CyFun Maturity and Mock Audit cover the sub-pages listed above; DORA Compliance and EU AI Act go further into the two framework pages. Audit readiness turns this picture into a checklist, and what you act on is tracked in Action items.