Compliance frameworks

The Compliance area puts every framework your organisation answers to on one screen, then lets you open any single control to see what still stands between it and coverage.

A framework is a published set of requirements you measure yourself against, such as DORA, GDPR or ISO 22301. Each framework breaks into controls. You link policies, procedures, risks and evidence (the proof a control works) to those controls, and Aegis reads only those links. One rule decides the headline number: a control counts as covered when at least one linked evidence item is approved and still inside its valid-until date. A control with only a policy, a procedure or a risk linked is partial, not covered.

Who uses it

What's on this screen

Open Compliance in the left menu to reach /compliance. The header reads Compliance above the line "Track control coverage and implementation status across compliance frameworks". Three buttons sit on the right: Gap Triage (AI), Coverage Triage (AI) and the dark Export button.

Below the header are five figures: Overall Coverage, Total Controls, Covered, Compliant and Overdue Evidence. They count only frameworks that are both enabled and applicable. In the capture, 23 of 4,951 controls are covered, which rounds down to 0%, and none is yet Compliant. Coverage shows green from 80%, yellow from 60% and orange below.

Under Frameworks is an alphabetical grid of cards, four to a row. Each gives the framework name, its percentage, a progress bar and a line such as "0 compliant of 56". The ESRS card carries a yellow Newer edition badge. A framework your organisation profile marks as not applicable stays on the grid with a dashed border, a Not applicable to your organization label and — in place of a percentage.

Below the captured area come Control Requirements (the filterable controls table), Saved AI insights and Action items from AI.

Working from the overview

  1. Select Gap Triage (AI). The Control Gap Smart Triage window opens and waits for Run Gap Triage. It ranks open gaps into a 90-day sprint and a 12-month horizon.
  2. Select Coverage Triage (AI). Its window looks at controls with nothing linked at all and suggests where to start.
  3. Select Export. The Export Compliance Data window asks for a format (JSON, CSV, PDF, OSCAL SSP or OSCAL AR) and a scope. Confirm, and the file downloads.
  4. Read Overall Coverage: the share of controls with approved, current evidence. Compliant, by contrast, counts controls whose own status is Compliant.
  5. Select a card, for example DORA. The card gains a highlighted border, the heading changes to Frameworks (click to clear filter), and the controls table below shows only DORA controls. Select the card again to clear the filter.
  6. Hover over the Newer edition badge on a card such as ESRS. A tooltip names the edition that supersedes the one Aegis ships.
The Compliance overview: AI and export actions, the five headline figures and the framework cards — /compliance.
The Compliance overview: AI and export actions, the five headline figures and the framework cards — /compliance.

Opening a control

Scroll to Control Requirements, narrow the table with the search box and filters, then select a row. A window opens, headed with the control's reference and title, here ISO27001-4.3, with the framework and a status badge (Not Started) beneath.

  1. Read the Applicability panel. For most controls a Manager can tick "This control is not applicable", which removes it from coverage. ISO management-system clauses 4 to 10 are mandatory, so here the panel says it "cannot be marked not applicable".
  2. Record your reasoning in Justification (optional), then save. For a Contributor, as here, the field is read-only and has no save button.
  3. Check Organization-defined parameters: values the framework leaves to you, which flow into exports. Here the catalogue defines none.
  4. Look at Owner group. A yellow No owner assigned badge means nobody owns the control yet. Implementation progress below reads 0%.
  5. Select Close. The window closes and the table row reflects any saved change.
A mandatory ISO management-system clause, which cannot be marked not applicable — /compliance.
A mandatory ISO management-system clause, which cannot be marked not applicable — /compliance.

Moving a control forward

This needs Manager rights. Further down the same window are a Maturity panel and the requirements, each with a status of Not Started, In Progress or Complete.

The DORA page

DORA (the EU's Digital Operational Resilience Act) has its own page at /compliance/dora. A DORA Readiness bar under the header shows 50%, with the note "Complete all four areas to achieve full readiness". Four figure cards follow: DORA Profile (Configured, with Edit), ICT Assets 0, Third-Party Providers 0 and Resilience Tests 3. Below them, navigation cards open each register, with its DORA article.

  1. Select AI Register Readiness. Aegis scores your Register of Information against DORA Article 28(3) and lists gaps and next steps. You decide which to act on.
  2. Select Edit on the DORA Profile card. The profile window opens; only entity type is required. Save, and the readiness bar updates. With no profile yet, the button reads Configure.
  3. Read Saved AI insights. The capture holds one run saved on 15 July 2026 at Medium Confidence 57%. Its Legacy record badge means it was saved before AI runs were recorded, so its origin cannot be verified. Show more expands the full text.
  4. Select Create action item to turn a recommendation into tracked work. It then appears under Action items from AI at the foot of the page.
  5. Use Edit to amend the insight's text, or Delete to remove it.
The DORA landing page: readiness bar, profile and register cards, and one saved AI insight — /compliance/dora.
The DORA landing page: readiness bar, profile and register cards, and one saved AI insight — /compliance/dora.
A saved insight is a snapshot, not a live reading

The insight in the capture says the register "cannot be scoped without a configured profile", yet the profile card now reads Configured. Saved insights record what was true when the run happened. Run AI Register Readiness again after you change the register, and delete insights that no longer apply.

The EU AI Act page

/compliance/eu-ai-act is the entry point for the EU AI Act (Regulation 2024/1689). Five figures follow the header: Total Systems 9, High Risk 1, Conformity Passed 0, FRIA Required 1 (FRIA is a fundamental-rights impact assessment) and Reassessment Required 0. Four navigation cards lead to AI Systems, Technical Documentation (Annex IV), Transparency Obligations (Article 50) and Prohibited Practices Check (Article 5).

  1. Select AI Inventory Readiness. Aegis scores your registered AI systems on prohibited practices, classification, FRIA, conformity and registration, tying each gap to an article. With an empty inventory it says so and does not invent systems, so register them first through AI Systems.
  2. Read Saved AI insights. Until you keep a run, it says "No AI insights saved yet. Run an AI action and choose 'Save as record' to keep it here."
  3. Read Action items from AI. It stays empty until you use Create action item inside an AI result, exactly as on the DORA page.
The EU AI Act landing page with nine registered systems and both AI panels still empty — /compliance/eu-ai-act.
The EU AI Act landing page with nine registered systems and both AI panels still empty — /compliance/eu-ai-act.

The AI assist

All five AI actions in this area read what is recorded, write a briefing, and leave the decision to a person. None changes a control, status or mapping by itself. The gap triage ranking comes from fixed rules, not from AI. Keep any run with Save as record. Every AI action is logged and uses your organisation's AI credits.

Tips and limits

Where this connects

Close gaps by linking work from Policies, Procedures and Evidence, and by recording treatment in Risks. Control Mapping, CyFun Maturity and Mock Audit cover the related sub-pages. DORA Compliance and EU AI Act go deeper into the two framework pages. Audit readiness turns this picture into a checklist, and the work you take on is tracked in Action items.