Creating a compliance map

Bring requirements, mapped controls, testing results, and issues together to assess compliance coverage and monitor compliance status in real time.

Workflow

Follow these steps to set up and manage your compliance mappings:

  1. Framework setup Create a compliance framework and define the controls your organization needs to meet its regulatory and operational requirements.

    1. Integrate Framework with Projects Import framework controls into Projects so teams can consistently use and test them.

      1. View requirements Create or update requirements and their associated details to manage applicability and track coverage across your organization.

          • Document procedures and walkthrough results.

          • Test control functionality.

          • Identify and document gaps or weaknesses.

  2. Add standards or regulations Import standards or regulations from the Compliance Library, or create custom ones to meet your organization's needs.

  3. View requirements Create or update requirements and their associated details to manage applicability and track coverage across your organization.

  4. Work with linked requirements Link controls to relevant business requirements to demonstrate compliance coverage and simplify audit processes.

  5. Track compliance progress Track the status of each requirement to identify gaps, measure progress, and ensure continuous alignment with compliance goals.

  6. Generate a summary report Export reports in the Excel format to share compliance status with auditors, stakeholders, and leadership.

Note

Some standards and regulations imported into Compliance Maps may be read-only, indicated by a lock icon . This may restrict changes to your standards and regulations. For locked imports from Compliance Maps, you cannot do the following:

  • Edit the standards and regulations, or requirements.

  • Add sub-requirements.

  • Delete requirements.

Add standards or regulations

Add standards or regulations to your compliance map manually, or import available standards and regulations from the Compliance Library.

To view standards and regulations in the Compliance Library, go to:

  1. From the Platform home page (www.diligentoneplatform.com), select the Compliance Maps app to open it.

    If you are already in Diligent One, you can use the left-hand navigation menu to switch to the Compliance Maps app.

  2. Complete any of the following tasks:
    TaskSteps
    Import available standards or regulations
    1. From the Add new dropdown, select Import from Compliance library.
    2. Search and choose the standards or regulations you want to import.

      Note
    3. Select Import.
    4. After the import is complete, select Open. The standards and regulations opens in the side panel, and its top-level requirements appear in the list view.

    5. Skip the steps under Add requirements and proceed to Specify if requirements are applicable and covered.
    Accessing additional standards and regulationsSome standards and regulations display a Contact for access label. Contact your Customer Success Manager to learn how to access these standards and regulations.
    Manually add a standard or regulation
    1. Select Create new.

      The Add standard and regulation side panel opens.

    2. Enter the following information:
      • Title Name the standard or regulation.

        The character limit is 255. The name must be unique.

      • Description (optional) Provide a description of the standard or regulation.
        Note

        Rich text fields cannot exceed 524,288 characters.

    3. Do one of the following: 
      • To add the standard or regulation and close the panel, click Save and Close.

        The standard or regulation is added to the compliance map.

      • To add a requirement to the standard or regulation, click Save and add requirement, and proceed to step 3 of Add requirements.

View and manage standards or regulations

The regulations page lets you view and search requirements within a regulation and see their statuses and associated controls.

To view a regulation, follow these steps from the Compliance Maps home page:

View Steps
High-level details

To view details such as title, description, and source of a regulation, select Show details from the More menu in the Actions column.

Detailed view
  1. Select the standard or regulation name.

  2. On the regulation page, do the following:

  1. Review the list of requirements, their relationships such as number of linked controls and requirements, and their status.

  2. Search for specific requirements within a regulation by entering ID, title, or description.

  3. View requirements descriptions within the overall context of the regulation.

  4. Create subrequirements for a standard or regulation by selecting +Add new sub-requirement.
    When you add subrequirements, they are added to the same hierarchy as the top-level view of a regulation. This ensures the subrequirement is contextualized within the full scope of the regulation and added directly at the requirement level.

  5. Switch between regulations by selecting the switch icon , then choosing the standard or regulation from the list.

  6. Navigate to the requirements details page from the regulations page by selecting the Details button next to a requirement.

View requirements

You can view the requirements from the regulation page. To navigate to the Requirement details page, select the requirement you want to view and then select Details.

Add requirements

Add requirements to populate your compliance map.

  1. From the regulation page, select Details next to a requirement or from the Compliance Maps home page, select a requirement.

  2. In the requirement details page, select + Add new sub-requirement from the More menu.

  3. Enter the following information:
    1. ID Enter the identifier of the requirement.
    2. Title (Optional) Name the requirement.
      Note

      If you do not enter a title, the first 255 characters of the requirement description are used as the title in the tree view.

  4. Do one of the following:

    1. Save and add another Select this option to save the requirement and add another requirement at the same hierarchical level in the tree view.

    2. Save and Close Select this option to save the requirement and close the Add new sub-requirement side panel.

      Note
      • The tree view highlights the new requirement and sorts requirements by ID. If IDs are the same, requirements are sorted by creation date.

      • All requirements are ordered automatically. You cannot configure the order of requirements.

      • The number of requirements added to a standard or regulation appears beside the name of that standard or regulation in the list.

  5. Description Provide a description of the requirement.
    Note

    Rich text fields cannot exceed 524,288 characters.

Uploading evidence for writing rationale

You can upload documents along with a brief explanation (Write rationale) that justifies why the uploaded document is a valid evidence for meeting a specific compliance control or requirement.

  1. From the home page, select the title of the requirement. The Requirement details page opens.
  2. Go to Status section in the Requirement details page.
  3. Select Write rationale to enter a brief explanation about the document. For more information, see View requirements.
  4. In the Upload evidence, select the files to upload or drag and drop your files.

    Note

    • Your file size must be less than 1 GB.

    • The following file types are not supported: application,.aspx,.bat,.cmd,.com,.cpl,.exe,.gadget,.hta.

  5. Select Save and Close.
  6. Select Delete or Download to remove or save documents.

Specify if requirements are applicable and covered

Apply professional judgment to determine and rationalize optimal coverage that is sufficient for the organization.

  1. From the Compliance Maps home page, select the title of the requirement.

    The Requirement details page opens.

  2. In the Status section, from the dropdown list, select one of the following:

    • Not Applicable: Select this option only if the requirement is not applicable for your organization.

    • Applicable - Not Covered: Select this option if the requirement is applicable but not yet covered.

    • Applicable - Covered: Select this option if the requirement is applicable and already covered for your organization.

    Note

    By default, all parent requirements are applicable and not covered. When you create a new sub-requirement, the sub-requirement inherits the Applicable and Covered values from the parent requirement.

  3. (Optional) Select Write rationale to explain why a requirement is marked as applicable, not applicable, covered, or not covered.
    Tip

    You can also copy rationale statements from related requirements. For more information, see View requirements.

Work with linked requirements

Linked requirements helps you identify and connect similar requirements across standards and regulations. By reusing controls already mapped to related requirements, you can save time, avoid duplicate work, and manage compliance mappings more efficiently.

There are two ways you can link requirements:

Linked requirements in bundles from Compliance Library

For standards and regulations with predefined linkages, you can view up to 300 linked requirements and add rationale statements. These linkages are based on industry-approved mappings. For more information, go to Relationships between controls and requirements.

  1. Go to requirement details page, expand the Linked requirements section. The number denotes the total count of requirements currently linked to this section.
  2. You can filter by standards and regulations.
    This shows a list of linked requirements along with their statuses. You can check the regulations related to the new requirement.
  3. Note

    Imported linked requirements are categorized by relationship strength, such as Equivalent, Strong, Medium, or Unlinkable, to indicate the nature of their linkage.

  4. Select a linked requirement.
    A side panel opens displaying the requirement details. The Rationale section displays rationales from linked requirements.
  5. Select Add to include the rationale.
    The new rationale appears in the Rationale section in the requirement details page. 

    If the requirement you are working on already has a rationale statement, the new rationale is appended to the bottom of the existing rationale.

    Tip

    To make further modifications to the rational statement, use Edit rationale option.

  6. Import standards or regulations that contain linked requirements If there are linked requirements that are not imported to your compliance map, do the following:
    1. In the requirements details page, next to the Linked requirements section, select Import Relevant Regulations.

    2. Select the title of an authoritative document to start the import process.

      This takes you to the Compliance library.

Manual linking through search

Link a requirement to any other requirement from other documents in Compliance Maps.

After you link requirements, you can view and reuse controls previously mapped to the linked requirement, saving time and reducing duplicate work.

To link requirements,

  1. From the requirement details page, select Link requirements.
    A side panel opens with the full list of linkable requirements.

  2. Search by requirement ID, title, description, or use filters such as regulation or status. You can also enter a specific keyword to get relevant requirements.

  3. Select Link from the search results or select a requirement.

    1. Select a requirement to open the side panel, where you can view its details, mapped controls, and coverage status. You can also link the requirement from the side panel.

    2. Manually linked requirements appear in the Linked requirements section with the Manually linked label. To remove a link, select Unlink.

    3. For manually linked requirements, you can map controls and add rationale just as you can for requirements linked through imported bundles.

Provide consent to enable Compliance Maps AI features

You must provide your consent and agree to the terms to use the Compliance Maps AI features.
These AI features are disabled by default. As an System Admin, you can enable these AI features by following the steps:
  1. Navigate to Projects > Settings and toggle on the Enable Compliance Maps AI features.
  2. On the Join the Compliance Maps AI features page, select I am interested.
  3. Select the I agree checkbox.
  4. Select Get started.

For more information, go to

Link controls to requirements

Showcase your organization's adherence to specifications relevant to the business by linking controls to requirements. Linked requirements also appear in Control X-Ray and help auditors familiarize themselves with a control based on these requirements.

You can directly link controls to your requirements by using AI Suggestions, by selecting Generate controls with AI and also do a AI version compare.

Note

The maximum number of controls you can link to a single requirement is 300.

To link controls to requirements, follow these steps:

  1. From the Compliance Maps home page, select the title of the requirement.
  2. Select Details.
  3. From the Linked controls dropdown, select Link control. The Link control panel opens.
    Note

    If you do not see Link control, it means that you are viewing an ancestor or descendant of a requirement that cannot be mapped. You must remove existing mappings in the group before you can map additional controls. For more information, see Relationships between controls and requirements.

  4. In the Link control panel, you can do the following:
    1. Search for a control by entering a keyword in the search box.

      You can search for controls by Objective title, Control ID, Control title, or Control description. Search terms are highlighted in the results.

    2. Select Filter to filter controls by frameworks or objectives.

      The search works in combination with any applied filters. If you select a framework or objective filter, and you search for a control, you are only searching within the specified framework or objective.

      • Select the side arrow to expand a framework to view a list of objectives.
      • Select the side arrow next to the objective to view a list of controls.
      • If applicable, select View more to show all frameworks in the Diligent One instance.
    3. Click AI Suggestions to find controls that best match each requirement. AI compares requirement and control descriptions to provide relevant suggestions.
    4. Click Generate controls with AI to select from the list of AI generated available controls to link to your requirements.

      You must provide your consent and agree to the terms to use the Compliance Maps AI features.
      These AI features are disabled by default. To enable them, refer to Provide consent to enable Compliance Maps AI features.
    5. Click Regenerate controls to show more options for AI generated controls.

  5. Select Link beside each control you want to link to the requirement.

View and manage linked requirements

The Linked Control section of the Requirement details page displays the list of linked controls. When you select a linked control, you can perform actions as described in the following table:

Action Steps
View the linked requirements in detail

The following information is displayed in a detailed view as a side panel:

  • Control ID The control identification code.
  • Owner The person responsible for the control.
  • Control title The title of the control.
  • Description Detailed information about the control.
  • Framework The framework where the control is coming from.
  • Testing results Control tests that have passed, failed, and controls that have not yet been tested.
  • Issues An aggregate number of open issues across all project controls linked to the framework control.

    Selecting the issue count link provides a pop-up list of issues. You can select an individual issue to navigate to detailed information.

    Note

    The aggregate issue count is based on all open published issues from active projects that are associated with walkthroughs, test plans, and testing rounds.

Compare Control and Requirement description

When control data is open in the side panel, you can compare the control description with the requirement description by scrolling through both columns side by side. This is essential for initiating compliance work and ensures a clearer understanding of legal requirements.

Update Control weight

To indicate the percentage of the requirement that the control covers, adjust the Control weight.

You can indicate a value between 0 and 100%. The default coverage is 100%.

Navigate to framework

Frameworks

application
  • To navigate to the control in the framework, select the ID link.
  • To navigate to the framework, select the framework link.
Add or remove controls
  • To remove the control association from the requirement, select Unlink.
  • To link additional controls to the requirement, select + Link control.
  • To view a list of controls that have been linked to a single ancestor requirement, or all descendant requirements, and the aggregate number of issues for each control, view the Related controls section.
    • Selecting the control ID link redirects you to the Control page in the applicable framework.
    • Selecting the issue count link provides a pop-up list of issues.

      You can select an individual issue to navigate to detailed information.

Generate controls for requirements

If you cannot find a suitable control by browsing or using AI suggestions, use control generation to create one. This is useful for new or evolving regulatory requirements where existing controls may not be available.

For example, when the General Data Protection Regulation (GDPR) was introduced, organizations needed new controls to address personal data requirements. Control generation helps in similar situations by generating a title and description for a suitable control, saving you time when setting up your compliance framework.

To generate controls:

  1. Select Generate controls with AI. The system automatically generates a list of controls.

  2. Browse the controls list and select a control you want to use.

  3. Review the control, copy its title and description, and paste them into your control library.
    If needed, you can modify the control title or description directly within your control library.

Add controls to Risk Manager

You can add AI-generated controls directly toRisk Manager with a single click, without manually copying control details. Added controls are automatically saved as drafts for your control team to review, manage, and finalize.

To add controls from Compliance Maps to Risk Manager:

  1. Select a control from the list of controls generated by the AI Suggestion service.

  2. Select +Add to Risk Manager.

  3. To review the added controls, select View in Risk Manager from the success message.
    This directly takes you to the relevant control in the Risk Manager app.

    Note

    Controls added to Risk Manager appear in draft mode.

  4. All added controls can be found in the Controls tab, where you can review and manage them according to your organization's policies and procedures.

Link risks from Risk Manager

Link risks from Risk Manager to associate the risks with regulatory requirements. This helps you to understand the risk exposure of specific obligations and escalate or mitigate risks.

To link risks from Risk Manager, follow these steps:

  1. From the Compliance Maps home page, select the title of the requirement.
  2. Select Details.
  3. From the Linked risks from Risk Manager dropdown, select Link risk.
    The Link risk from Risk Manager panel opens.
    Note

    You must be subscribed to Risk Manager and have the reader permissions for risks enabled for you in order to link risks to your requirements.

  4. In the Link risk from Risk Manager panel, you can search for the risk you want to link by entering a keyword in the search box.
  5. Select Link beside each risk you want to link to the requirement.

    It consists of the following details:

    • The title of the risk.
    • The organization unit name.
    • The risk owner's name.
    • The category of the risk.
    • A brief description of the risk.

Link processes from Risk Manager

Link processes from Risk Manager to bring workflows and compliance needs into one clear view. It helps you understand how your processes support compliance and makes managing and tracking requirements easier.

To link processes from Risk Manager, follow these steps:

  1. From the Compliance Maps home page, select the title of the requirement.
  2. Select Details.
  3. From the Linked processes from Risk Manager dropdown, select Link process.
    The Link processes panel opens.
    Note

    You must be subscribed to Risk Manager and have the reader permissions for processes enabled for you in order to link processes to your requirements.

  4. In the Link processes panel, you can search for the process you want to link by entering a keyword in the search box.
  5. Select Link beside each process you want to link to the requirement.

    It consists of the following details:

    • The title of the process.
    • The organization unit name.
    • The process owner's name.
    • A brief description of the process.

Link objectives from Risk Manager

Link objectives from Risk Manager to bring your goals and compliance needs into one clear view. It connects objectives with risks, making it easier to see align, manage compliance, and support better decisions.

To link objectives from Risk Manager, follow these steps:

  1. From the Compliance Maps home page, select the title of the requirement.
  2. Select Details.
  3. From the Linked objectives from Risk Manager dropdown, select Link objective.
    The Link objectives from Risk Manager panel opens.
    Note

    You must be subscribed to Risk Manager and have the reader permissions for objectives enabled for you in order to link objectives to your requirements.

  4. In the Link objectives from Risk Manager panel, you can search for the objective you want to link by entering a keyword in the search box.
  5. Select Link beside each objective you want to link to the requirement.

    It consists of the following details:

    • The title of the objective.
    • The organization unit name.
    • The objective owner's name.
    • A brief description of the objective.

Link assets from Asset Manager

Link assets to requirements to identify related data, systems, and other assets and add operational and technology context to the requirement.

To link assets from Asset Manager, follow these steps:

  1. From the Compliance Maps home page, select the title of the requirement.
  2. Select Details.
  3. From the Linked assets from Asset Manager dropdown, select Link asset.
    The Link assets panel opens.
    Note

    You must be subscribed to Asset Manager and have access to atleast one asset type in order to link assets to your requirements.

  4. In the Link assets panel, you can search for the assets you want to link by entering a keyword in the search box.
  5. Select Link beside each assets you want to link to the requirement.

    It consists of the following details:

    • The name of the asset.
    • A brief description of the asset.
    • The criticality level of the asset.
    • The organization unit name.
    • A category of the asset.
    • A type of the asset.

Link controls from Risk Manager

Link controls from Risk Manager to demonstrate compliance more easily while strengthening integration across the platform.

To link controls from Risk Manager, follow these steps:

  1. From the Compliance Maps home page, select the title of the requirement.
  2. Select Details.
  3. From the Linked controls from Risk Manager dropdown, select Link control.

    The Link controls from Risk Manager panel opens.
    Note

    You must be subscribed to Risk Manager and have the reader permissions for controls enabled for you in order to link controls to your requirements.

  4. In the Link controls from Risk Manager panel, you can search for the risk you want to link by entering a keyword in the search box.
  5. Select Link beside each control you want to link to the requirement.

    It consists of the following details:

    • The title of the control.
    • The organization unit name.
    • The control owner's name.
    • The business owner's name.
    • The design effectiveness.
    • The control effectiveness.
    • A brief description of the control.

Track compliance progress

You can filter the list of requirements to track your compliance progress.

To track compliance progress, go to the Compliance Maps page and complete any of the following tasks:

TaskSelect option or perform actionWhat you see
View all applicable requirements across all regulations and standards.

Applicable

A list of all applicable requirements, whether or not they have been marked as covered.
View requirements that have not been identified as covered.Not covered (Gaps)

A list of applicable requirements that are have not been identified as covered.

View requirements that have been identified as covered.CoveredA list of applicable requirements that have been identified as covered.
View requirements that have been specified as not applicable.Not Applicable

A list of all non-applicable requirements.

Search for requirements.Enter a keyword or phrase in the search box.A list of requirements that match your search term or phrase.

View summary information about a standard, regulation, or requirement, including:

  • the extent to which it is covered or not covered.
  • whether or not it has been identified as covered.
  • whether or not it has been associated with at least one control.
  • the aggregate number of open issues associated with it.
  • the current assurance calculation for a standard, regulation, or requirement.
Consult the Coverage, Covered, Issues, Controls and Assurance columns in the nested tree view.
  • Coverage The percentage of requirements for a standard or regulation that have been identified as covered. Learn how coverage is calculated.
  • Covered An indication ( or ) of whether or not a requirement is covered (based on your identification of the requirement as Covered or Not Covered. Standards and regulations are considered covered when all of their requirements have been identified as covered.
  • Issues An aggregate issue count associated with each standard or regulation, and with the topmost (root) requirements in the tree. Selecting the issue count link provides a popup list of issues. You can select an individual issue to navigate to detailed information.
  • Controls An icon () indicates requirements that have had at least one control linked to them.
  • Assurance A calculation that represents your organization's confidence in requirements being met. Learn how compliance assurance is calculated.

Generate a summary report

Demonstrate your organization's compliance progress by generating a summary report.

  1. Select Compliance Summary Report.
  2. Download the Excel report (.xlsx) to your computer.

    Any applied filters that you apply on the Compliance Maps page are reflected in the report. Each standard/regulation is displayed on a separate worksheet.

    Tip

    Manually created requirements that are indexed alphanumerically in your compliance map may be ordered differently in your Excel report. To achieve the same ordering, you can use the following naming strategy for your requirements:

    • Parent requirement alphabetical ID

      Example A1

    • Sub-requirements alphabetical ID + numerical ID

      Examples A1-01, A1-02, A1-03