Record which clauses each control satisfies and how much of each it carries, accept the catalogue's proposals, and confirm or reject suggestions before they count.
A mapping records that one of your controls satisfies one clause of a standard, and how much of that clause it carries. Mappings are what the Satisfies column in the library, the Framework coverage view and the Statement of Applicability are built from. Only confirmed mappings count as coverage or appear in the Statement of Applicability. A mapping is a claim you make to an auditor. It says nothing about whether the control works; that comes from testing.
Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control from the Library in Controls. Select the Requirements tab.
Task | What you need |
|---|---|
See a control's mappings and the catalogue's proposals | View controls ( |
Create, change, confirm or remove a mapping, including accepting catalogue proposals and assistant suggestions and running Suggest mappings from the catalogue | Manage Requirements ( |
Admins can do all of these. People without Manage Requirements see the mappings but not the buttons that change them. See create roles and choose their permissions.
Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control from the Library in Controls. Select the Requirements tab.
Open a control and select the Requirements tab. The panel is titled What this control satisfies and lists every clause the control is mapped to, with its Coverage and State.
Source | How it arrives | State when it arrives |
|---|---|---|
You map it by hand | You choose the clause on the control and give a rationale. | Confirmed |
The control catalogue | A control adopted from a pack carries the clauses its authors wrote it for. You accept them on the control or in the library. | Confirmed once accepted |
Suggest mappings from the catalogue | Run for one standard from its Framework coverage view. | Unconfirmed, shown as Awaiting review |
Adopting a standard | When your organisation adopts a standard, the mappings of the packs that come with it are added as suggestions. | Unconfirmed |
The Controls Assistant | The assistant proposes a mapping with its reasoning when you ask it to. | Unconfirmed |
Unconfirmed suggestions, whether from the catalogue or the assistant, do not count as coverage and stay out of the Statement of Applicability until someone confirms them.
A control can be mapped to a clause only once. Existing mappings are never overwritten by a later proposal or suggestion pass, so a coverage choice you have made stays as you left it.
Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control from the Library in Controls. Select the Requirements tab.
Coverage is reported word for word in the Statement of Applicability, so claim Primary only where this control really is the main way the clause is met.
Coverage | Use it when | Effect in Framework coverage |
|---|---|---|
Primary | This control substantially satisfies the clause on its own. | A clause with a confirmed primary control can read Covered. |
Supporting | The control contributes, alongside the controls that carry the clause. | A clause with only confirmed supporting or partial controls reads No primary control. |
Partial | The control covers only part of the clause, and something else must cover the rest. | As for Supporting. |
A clause is often met by several controls together: for example, one control for approving new access, one for the quarterly review and one for removing leavers.
Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control from the Library in Controls. Select the Requirements tab.
Open the control from the library and select Requirements.
Choose the action to add a mapping.
Choose the standard, then the clause. The clause text is shown so you can check that you have the right one.
Choose the coverage: Primary, Supporting or Partial. It defaults to Primary; change it if the control does not carry the clause on its own.
Write the rationale: why this control satisfies this clause. Up to 4,000 characters. This is what an auditor reads when the mapping is questioned, so refer to what the control actually does.
Save. The mapping appears in the table as Confirmed, recorded in your name.
If the clause you need is not offered, check that the standard is adopted and the clause exists in its requirement list. See manage requirements.
Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control from the Library in Controls. Select the Requirements tab.
When the catalogue maps a control to clauses you have not accepted, the Requirements tab shows ComplyTrain maps this control to 1 clause (or to several clauses). Each proposal shows the standard code, clause code, the catalogue's coverage and the clause text.
Read each proposed clause and its coverage.
Choose Accept this mapping (or Accept these mappings). The mappings are added as Confirmed.
Adjust the Coverage of any row that does not match how you operate the control.
To accept proposals for many controls at once, use the library. A banner reads ComplyTrain proposes a number of mappings across a number of controls; choose Accept all to accept them for the controls on the current page. Or select controls with their checkboxes and choose Accept in the selection bar (it shows the number proposed). The library's Satisfies column shows how many mappings are still proposed for each control.
If you later remove an accepted mapping, the catalogue proposes it again. Remove it again, or leave it proposed, if it does not apply to you.
Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control from the Library in Controls. Select the Requirements tab.
A suggestion that nobody has reviewed shows a Confirm button instead of the Confirmed badge. In the library's Satisfies column, its clause shows the tooltip "not yet confirmed by anyone here".
Read the clause text and, for an assistant suggestion, its rationale.
Set the Coverage you stand behind. An assistant suggestion does not decide coverage for you.
Choose Confirm. The mapping becomes yours and is recorded in your name. Or choose Remove if the control does not satisfy the clause.
Until it is confirmed, a suggestion counts as Awaiting review in Framework coverage rather than as coverage, and it is left out of the Statement of Applicability.
Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control from the Library in Controls. Select the Requirements tab.
Coverage: choose a different value in the row's Coverage list. It is saved straight away.
Rationale: open the mapping and edit its rationale when the way you operate the control changes.
Remove: choose Remove on the row. The clause no longer counts this control, and the change shows in Framework coverage and in the next Statement of Applicability draft.
A retired control's mappings stay in the record but no longer count as coverage.
Product location: /qms/controls/standards/{standardId}/coverage (fallback: /qms/controls). Open Framework coverage from the standard, or choose the standard in the Library's Standard filter and select Framework coverage.
From a standard, open its Framework coverage view. The tiles show Clauses with no control, Awaiting review and Clauses in this standard. Use Show to list Clauses with no control, Awaiting review or Every clause.
Choose Suggest mappings from the catalogue to add suggestions for the controls you have adopted. The result reads, for example, 12 new suggestions added. Then open each control named in the Controls column and confirm or remove its suggestions as described above. See framework coverage and the Controls overview.
Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control from the Library in Controls. Select the Requirements tab.
Library: the Satisfies column shows a pill for each mapped clause. Selecting a pill opens that clause in the standard's scope list.
Standard scope list in QMS: each clause shows the controls mapped to it, linked to the control.
Framework coverage: the clause's status moves between No control, Awaiting review, No primary control, Covered and Excluded.
Statement of Applicability: the next draft or rebuild lists the control against each clause it has a confirmed mapping to, with its coverage. A control marked Partly applicable still applies and is shown as Partly applicable. See prepare, approve and sign a Statement of Applicability.
A mapping does not create work, schedule tests or affect a risk score.
Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control from the Library in Controls. Select the Requirements tab.
Your organisation has written its own control, AC-07 Quarterly access review: each quarter the system owner reviews who has access to production systems and removes anyone who no longer needs it.
Open AC-07, then Requirements. It shows This control is not mapped to any requirement yet. and nothing is proposed, because you wrote the control yourself.
Map it to clause A.5.18 Access rights with coverage Primary. Rationale: "Quarterly review of every production account against the joiners, movers and leavers list; access that is no longer needed is removed and the removal recorded."
Map it to A.5.15 Access control with coverage Supporting, because the access control policy is carried by a separate control.
Map it to A.8.2 Privileged access rights with coverage Partial, because the review covers privileged accounts on production systems only.
Open the standard's Framework coverage view. A.5.18 now reads Covered; A.8.2 reads No primary control until a control for privileged access on other systems is mapped as primary.
The mappings appear in the next Statement of Applicability draft. Whether AC-07 actually works is shown on its Tests tab once it has been tested; see test a control and get it signed off.