Compliance Glossary for Confluence

What does the requirements mapper do?

The requirements mapper links recorded internal evidence to supported catalog requirements and shows current recorded readiness and gaps. It helps teams organize evidence by control or requirement. It does not decide legal applicability, certify compliance, or prove that a mapped record is sufficient. Qualified owners must review every mapping and gap.

Last verified against production v6 · 26 September 2026

At a glance

InputActionOutputLimit
Supported requirement catalogSelect the relevant framework viewRequirement listCatalog content is not legal advice
Internal evidence referenceMap it to a requirementRecorded evidence relationshipA link does not prove sufficiency
Missing or incomplete evidencePreserve the gap stateReadiness signalTeams own remediation and applicability
Custom control needSave supported custom contextOrganization-specific mappingGovernance and review remain external

How it works

  1. Open Requirements Mapper.
  2. Select the supported catalog or custom context.
  3. Review each requirement.
  4. Attach the relevant recorded evidence.
  5. Keep missing or incomplete items visible.
  6. Have qualified owners review applicability and sufficiency.

Example

A security team maps its incident terminology evidence to one control requirement. The mapper shows that evidence is recorded, while a separate requirement remains incomplete. Leadership sees the documented posture without receiving a certification claim.

What this does not mean

Mapping is organizational evidence management. It is not a legal interpretation, audit opinion, certification, or guarantee of regulatory compliance. Catalog updates and applicability decisions require qualified review.

Related questions

Next step

Use the mapper to expose gaps, then have control owners evaluate sufficiency.

View on Atlassian Marketplace
Verification basis: production v6 code, tests, manifest, and operations guidance. Verified 26 September 2026.