The Control Mapping Engine is the intelligence layer that transforms a collection of documents into an audit-ready evidence package. Its job is to answer the question every auditor asks: "Show me the evidence that this control is operating effectively." Without mapping, evidence is just a pile of files. With mapping, it becomes a structured demonstration of compliance.
The engine supports five control frameworks out of the box — SOC 2, ISO 27001, PCI DSS, HIPAA, and GDPR — with an extensible mapping architecture that accommodates any control set the organization needs to demonstrate.
The mapping process operates in three phases:
Phase 1: Control Registration. The organization loads its control set into the platform — either by selecting from pre-built framework templates or by importing a custom control catalogue. Each control is registered with its ID, description, framework reference, testing frequency, and evidence requirements. For example, SOC 2 CC6.1 ("The entity implements logical access security software, infrastructure, and architectures") requires evidence including access-review records, firewall configurations, network diagrams, and user-access policies.
Phase 2: Evidence-to-Control Mapping. As documents enter the system — policies from the policy manager, screenshots from the engineering team, reports from cloud providers, certificates from training platforms — the classification agent assigns each document a type, a date, and a source. The mapping agent then analyses each document against the registered controls and proposes connections: "This quarterly access review report appears to satisfy the access-review requirement for CC6.1. Map it?" A compliance analyst confirms or adjusts the mapping with a single click. Over time, the mapping agent learns the organization's evidence patterns and achieves >90% auto-mapping accuracy.
Phase 3: Gap Analysis. Once evidence is mapped, the engine produces a gap analysis: which controls have sufficient evidence, which have partial evidence, and which have none. The gap report includes specific recommendations — "You need a firewall configuration document dated within the last 6 months" — and estimated effort to close each gap. A control-readiness score (0-100%) provides an at-a-glance measure of audit preparedness.
The engine also manages evidence freshness. SOC 2 requires evidence of ongoing control operation, not just point-in-time documentation. The engine tracks when each piece of evidence was last collected, flags evidence approaching expiration, and triggers re-collection workflows. A control supported by a policy reviewed 13 months ago when the requirement is annual review gets flagged as stale, and the policy owner receives an automated review request.
The blueprint includes the complete control-to-evidence mapping specification for all five frameworks, the gap-analysis algorithm, and the freshness-tracking system — plus an extensible control-framework schema that organizations can use to add custom frameworks or industry-specific standards (FedRAMP, NIST, CMMC, etc.).