// tool reference · Governance & Advisory
AI Compliance Mapper Pro
Map your security posture to SOC 2, ISO 27001, Japan APPI and GDPR with per-control gap analysis and readiness scores.
What it does
Maps your controls across ISO 27001, SOC 2, PCI DSS, GDPR and NIST CSF, and surfaces the overlaps — so one control can satisfy several frameworks instead of being implemented five times.
When to use it
- Preparing for an audit; deciding what a new framework actually adds.
Inputs
Field names are the actual form parameters, verified against source.
| Field | Type | Required | Notes |
|---|---|---|---|
| posture | textarea | required | Your current controls / posture. |
| fw | select | optional | Target framework. |
What you get back
A control map with overlaps and gaps.
Worked example
Input
posture = MFA everywhere, encrypted backups, quarterly access review, central logging with 90-day retention. fw = SOC 2
Output (abridged)
CONTROL MAP -- 4 controls satisfy 11 requirements MFA everywhere SOC 2 CC6.1 | ISO 27001 A.5.17 | PCI DSS 8.4 | NIST CSF PR.AA-03 One control, four frameworks. Evidence once, cite four times. Encrypted backups SOC 2 A1.2 | ISO A.8.13 | PCI 9.4.1 GAP: none of these are satisfied by an UNTESTED backup. SOC 2 A1.3 wants restoration testing -- you did not mention it. Quarterly access review SOC 2 CC6.2/CC6.3 | ISO A.5.18 | PCI 7.2.4 Central logging, 90d SOC 2 CC7.2 | ISO A.8.15 | NIST DE.AE-03 GAP: PCI DSS 10.5.1 requires 12 months (3 immediately available). If PCI is in scope, 90 days FAILS. TOP GAPS: (1) backup restoration testing (2) log retention vs PCI
How it works
AI mapping against framework structure.
Limits
Read live from the platform configuration.
| Rate limit | 4 requests / 10 minutes |
Limitations — what it does not do
Advisory mapping, not an audit opinion. Framework interpretation varies by auditor and scope. Use it to find overlap and obvious gaps -- not to declare compliance.
Privacy
Your posture description is sent to the AI provider.
Standards
ISO 27001SOC 2PCI DSSGDPRNIST CSF