Fifty-four frameworks, one crosswalk.
Prudential and consumer frameworks, federal and state, are mapped once, reused everywhere, and extended without re-implementation.
The framework library
Fifty-four frameworks ship in the corpus, from prudential exams to consumer regs to the newest AI standards.
- 01The corpus covers FFIEC, BSA/AML, GLBA, and the Reg alphabet (E, Z, B, DD, CC, F, O, W, GG).
- 02It covers CRA, HMDA, RESPA, FCRA, UDAAP, OFAC, TPRM, and MRM (2026 revised guidance).
- 03It covers SOC 2, PCI, NIST 800-53, CSF 2.0 and AI-RMF, ISO 27001 and 42001, CRI, COSO, SOX, and FDICIA.
- 04It also covers IIA GIAS 2024, NYDFS 500 and 504, CCPA, and the Colorado AI Act.
Coverage graph
The Coverage graph traces framework → citation → policy → control, so you can see the line from a rule to the thing that satisfies it (CoverageGraph).
- 01It is a D3 graph rather than a static export.
- 02Follow any framework down to the controls that cover it.
- 03A citation’s coverage drawer lists the same ground in other frameworks: the citations reached through the control objectives mapped to both.
Obligation-coverage scorecard
Obligation coverage turns the graph into a scorecard that shows what share of a framework’s obligations you actually cover (ObligationCoverage).
- 01Coverage is computed per framework from the mapping, so nobody self-attests it.
Gap report
The Gap report surfaces what is unmapped or thin, with the Gap Analysis agent proposing where the gaps are (GapReport, gap_analysis).
- 01Framework and control gaps show up in one place.
- 02The agent proposes each gap and a person confirms it.
Bring your own framework
Add a framework and crosswalk it to what you already have. Imported control content and SCF crosswalks do the heavy lifting (ContentLibrary).
- 01Map a control once and reuse it across every crosswalked framework.
- 02Import control content and reconcile it in the Content library.
All 54 frameworks.
- Regulation E / EFTA
- Regulation Z / TILA
- Community Reinvestment Act
- Small Business Lending (Reg B)
- UDAAP (Dodd-Frank §§1031/1036)
- ECOA / Regulation B
- Truth in Savings / Reg DD
- Funds Availability / Reg CC
- FCRA / Reg V + FACTA Red Flags
- HMDA / Regulation C
- RESPA / Regulation X
- Flood Disaster Protection Act
- Fair Housing Act
- Servicemember Protections (SCRA + MLA)
- FDCPA / Regulation F
- E-SIGN Act
- Marketing Comms (TCPA + CAN-SPAM)
- Federal Benefit Garnishment
- Homeowners Protection Act (PMI)
- SAFE Act / Reg G & H (NMLS)
- BSA / AML
- OFAC Sanctions Compliance
- NYDFS Part 504 TM & Filtering
- NCUA (12 CFR Chapter VII)
- Third-Party Risk Management
- Model Risk Management
- Insider Lending / Regulation O
- Affiliate Transactions / Reg W
- Interagency Safety & Soundness Standards
- Liquidity Risk Management
- FFIEC IT Examination Handbook
- GLBA (Reg P + Safeguards)
- NIST SP 800-53 Rev. 5
- CIS Critical Security Controls v8.1
- CRI Profile v2.2
- NIST Cybersecurity Framework 2.0
- NYDFS Cybersecurity (23 NYCRR 500)
- FFIEC Business Continuity Management
- SOC 2 Trust Services Criteria
- PCI DSS v4.0.1
- ISO/IEC 27001:2022
- Financial Services AI RMF
- NIST AI RMF + GenAI Profile
- ISO/IEC 42001:2023 AI Management System
- Colorado AI Act
- Multistate AI Deployer Duties (Composite)
- COSO Internal Control: Integrated Framework
- FDICIA Part 363 Annual Audit & ICFR
- SOX ICFR (§302/404, AS 2201)
- IIA Global Internal Audit Standards
- CCPA/CPRA + CPPA Regulations
- Multistate Consumer Privacy (Composite)
- Nacha Operating Rules: ACH Oversight & Audit
- UIGEA / Regulation GG
Grounded in shipped behaviour.
- The seed corpus holds 54 frameworks: FFIEC, BSA/AML, GLBA, the Reg alphabet, CRA, HMDA, RESPA, FCRA, UDAAP, OFAC, TPRM, MRM, NYDFS 500/504, SOC 2, PCI, NIST 800-53 / CSF 2.0 / AI-RMF, ISO 27001/42001, CRI, COSO, SOX, FDICIA, IIA GIAS 2024, CCPA, and the Colorado AI Act.
- 754 indexed citations link each obligation to its source paragraph.
- The Coverage graph traces framework → citation → policy → control. The Gap report surfaces what is unmapped.
- Frameworks include 2024–2026 revisions: MRM 2026, IIA GIAS 2024, NIST CSF 2.0, and the Colorado AI Act.
Counts come from the platform's regulatory corpus, connector registry, and seed template library at release. See the documentation for the current values.
Questions, answered first.
- Can I add my own framework?
- Yes. Bring your own and crosswalk it to what you already have. Imported control content and SCF crosswalks in the Content library map it to your existing controls.
- Do I have to map the same control twice?
- No. Map a control once and it is reused across every framework it crosswalks to. That is the point of mapping once and reusing everywhere.
- What is the difference between the Coverage graph and Obligation coverage?
- The Coverage graph is the framework → citation → policy → control map. Obligation coverage is the scorecard of how much of a framework you actually cover.
- How current are the frameworks?
- They include recent revisions such as the 2026 MRM interagency guidance, IIA GIAS 2024, NIST CSF 2.0, and the Colorado AI Act.
See frameworks & crosswalks on your library.
Bring your controls, a policy, and one regulator paragraph that gives you trouble. We target two-week onboarding.