Feature · Library

Fifty-four frameworks, one crosswalk.

Prudential and consumer frameworks, federal and state, are mapped once, reused everywhere, and extended without re-implementation.

SectionLibrary
UpdatedOctober 2026
Frameworks
54
in the corpus
Citations
754
indexed
Crosswalks
Map once
reuse everywhere
Obligation coverage · framework → citation → policy → control
FFIEC92%
BSA / AML100%
CRA64%
UDAAP78%
SOC 288%
NIST CSF 2.071%
Illustrative product preview. It does not show tenant data.
01 · Frameworks & crosswalks

The framework library

Fifty-four frameworks ship in the corpus, from prudential exams to consumer regs to the newest AI standards.

  • 01The corpus covers FFIEC, BSA/AML, GLBA, and the Reg alphabet (E, Z, B, DD, CC, F, O, W, GG).
  • 02It covers CRA, HMDA, RESPA, FCRA, UDAAP, OFAC, TPRM, and MRM (2026 revised guidance).
  • 03It covers SOC 2, PCI, NIST 800-53, CSF 2.0 and AI-RMF, ISO 27001 and 42001, CRI, COSO, SOX, and FDICIA.
  • 04It also covers IIA GIAS 2024, NYDFS 500 and 504, CCPA, and the Colorado AI Act.
02 · Frameworks & crosswalks

Coverage graph

The Coverage graph traces framework → citation → policy → control, so you can see the line from a rule to the thing that satisfies it (CoverageGraph).

  • 01It is a D3 graph rather than a static export.
  • 02Follow any framework down to the controls that cover it.
  • 03A citation’s coverage drawer lists the same ground in other frameworks: the citations reached through the control objectives mapped to both.
03 · Frameworks & crosswalks

Obligation-coverage scorecard

Obligation coverage turns the graph into a scorecard that shows what share of a framework’s obligations you actually cover (ObligationCoverage).

  • 01Coverage is computed per framework from the mapping, so nobody self-attests it.
04 · Frameworks & crosswalks

Gap report

The Gap report surfaces what is unmapped or thin, with the Gap Analysis agent proposing where the gaps are (GapReport, gap_analysis).

  • 01Framework and control gaps show up in one place.
  • 02The agent proposes each gap and a person confirms it.
05 · Frameworks & crosswalks

Bring your own framework

Add a framework and crosswalk it to what you already have. Imported control content and SCF crosswalks do the heavy lifting (ContentLibrary).

  • 01Map a control once and reuse it across every crosswalked framework.
  • 02Import control content and reconcile it in the Content library.
The corpus

All 54 frameworks.

Consumer Compliance
  • Regulation E / EFTA
  • Regulation Z / TILA
  • Community Reinvestment Act
  • Small Business Lending (Reg B)
  • UDAAP (Dodd-Frank §§1031/1036)
  • ECOA / Regulation B
  • Truth in Savings / Reg DD
  • Funds Availability / Reg CC
  • FCRA / Reg V + FACTA Red Flags
  • HMDA / Regulation C
  • RESPA / Regulation X
  • Flood Disaster Protection Act
  • Fair Housing Act
  • Servicemember Protections (SCRA + MLA)
  • FDCPA / Regulation F
  • E-SIGN Act
  • Marketing Comms (TCPA + CAN-SPAM)
  • Federal Benefit Garnishment
  • Homeowners Protection Act (PMI)
  • SAFE Act / Reg G & H (NMLS)
Financial Crime
  • BSA / AML
  • OFAC Sanctions Compliance
  • NYDFS Part 504 TM & Filtering
Prudential
  • NCUA (12 CFR Chapter VII)
  • Third-Party Risk Management
  • Model Risk Management
  • Insider Lending / Regulation O
  • Affiliate Transactions / Reg W
  • Interagency Safety & Soundness Standards
  • Liquidity Risk Management
Cyber & Tech
  • FFIEC IT Examination Handbook
  • GLBA (Reg P + Safeguards)
  • NIST SP 800-53 Rev. 5
  • CIS Critical Security Controls v8.1
  • CRI Profile v2.2
  • NIST Cybersecurity Framework 2.0
  • NYDFS Cybersecurity (23 NYCRR 500)
  • FFIEC Business Continuity Management
  • SOC 2 Trust Services Criteria
  • PCI DSS v4.0.1
  • ISO/IEC 27001:2022
AI
  • Financial Services AI RMF
  • NIST AI RMF + GenAI Profile
  • ISO/IEC 42001:2023 AI Management System
  • Colorado AI Act
  • Multistate AI Deployer Duties (Composite)
Audit & Privacy
  • COSO Internal Control: Integrated Framework
  • FDICIA Part 363 Annual Audit & ICFR
  • SOX ICFR (§302/404, AS 2201)
  • IIA Global Internal Audit Standards
  • CCPA/CPRA + CPPA Regulations
  • Multistate Consumer Privacy (Composite)
Payments
  • Nacha Operating Rules: ACH Oversight & Audit
  • UIGEA / Regulation GG
Proof points

Grounded in shipped behaviour.

  • The seed corpus holds 54 frameworks: FFIEC, BSA/AML, GLBA, the Reg alphabet, CRA, HMDA, RESPA, FCRA, UDAAP, OFAC, TPRM, MRM, NYDFS 500/504, SOC 2, PCI, NIST 800-53 / CSF 2.0 / AI-RMF, ISO 27001/42001, CRI, COSO, SOX, FDICIA, IIA GIAS 2024, CCPA, and the Colorado AI Act.
  • 754 indexed citations link each obligation to its source paragraph.
  • The Coverage graph traces framework → citation → policy → control. The Gap report surfaces what is unmapped.
  • Frameworks include 2024–2026 revisions: MRM 2026, IIA GIAS 2024, NIST CSF 2.0, and the Colorado AI Act.

Counts come from the platform's regulatory corpus, connector registry, and seed template library at release. See the documentation for the current values.

FAQ

Questions, answered first.

Can I add my own framework?
Yes. Bring your own and crosswalk it to what you already have. Imported control content and SCF crosswalks in the Content library map it to your existing controls.
Do I have to map the same control twice?
No. Map a control once and it is reused across every framework it crosswalks to. That is the point of mapping once and reusing everywhere.
What is the difference between the Coverage graph and Obligation coverage?
The Coverage graph is the framework → citation → policy → control map. Obligation coverage is the scorecard of how much of a framework you actually cover.
How current are the frameworks?
They include recent revisions such as the 2026 MRM interagency guidance, IIA GIAS 2024, NIST CSF 2.0, and the Colorado AI Act.

See frameworks & crosswalks on your library.

Bring your controls, a policy, and one regulator paragraph that gives you trouble. We target two-week onboarding.