How Regurai measures framework coverage.
Regurai maps framework requirements to governance controls and supporting evidence to identify coverage, gaps and the actions required. Coverage is an operational indicator of that mapping — never a statement of compliance.
An indicator of mapping strength, not a compliance verdict.
Coverage represents the proportion of the framework requirements held in Regurai that are mapped to governance controls, weighted by the strength of that mapping. A fully covered requirement counts once; a partially covered requirement counts as one half; a gap counts as zero.
Coverage % = ((Covered × 1) + (Partially covered × 0.5)) ÷ Total requirements in scope × 100
Important
Framework coverage is an operational mapping and assurance indicator, not a legal determination of compliance or certification. Applicability, implementation and compliance remain the responsibility of the organisation.
Four coverage states, each with a defined meaning.
Covered
Mapped Regurai controls address the requirement across its aspects. Coverage of the mapping — not confirmation that the control operates effectively in your organisation.
Partially covered
One or more mapped controls address some, but not all, aspects of the requirement. Further mapping or evidence is required.
Gap — not yet covered
No control is currently mapped to the requirement, so no coverage can be evidenced. Treated as a gap requiring action.
Waived / not applicable
The requirement has been recorded as not applicable or formally waived, with the decision retained in the change history.
A framework is only useful once it reaches an owner.
Regurai turns regulatory and governance frameworks into connected requirements, controls, evidence, gaps and actions.
- Framework
- Requirement
- Control
- Evidence
- Gap
- Action
- Owner
- Assurance
Ten steps, in the order the platform performs them.
Framework ingestion
A framework is registered with its short code, full name, jurisdiction, version and official source reference. Frameworks can be added by an administrator; nothing is inferred automatically.
Requirement normalisation
Each framework is broken into individually addressable requirements, each with a stable reference code, title, source text, category and named owner.
Control mapping
Governance controls are mapped to requirements. A requirement with no mapped control is a gap; a requirement with a single mapped control is partially covered; a requirement addressed across multiple mapped controls is covered.
Mapping strength
Mapping strength is the weight applied in the calculation: covered counts as 1, partially covered as 0.5, a gap as 0. Waived requirements are recorded with their justification and retained in the change history.
Coverage calculation
Coverage % = ((Covered × 1) + (Partially covered × 0.5)) ÷ Total requirements in scope × 100
Gap identification
Requirements that are not fully covered are surfaced as gaps with the affected category, the responsible owner and a suggested remediation. Suggestions are proposals for human review; they are accepted or rejected by a named person.
Action assignment
An accepted gap becomes an action with an owner and an effort estimate, so that coverage moves from an observation to a piece of work someone is accountable for.
Review and assurance
Attestations run on a defined frequency with a named attester. Every coverage change, mapping, decision and attestation is written to a tamper-evident change history that can be verified on demand.
Mapped against the authoritative source in each jurisdiction.
Referencing a framework does not imply endorsement by, or affiliation with, the issuing body.
International
- ISO/IEC 27001:2022Information security management systemsOfficial source
- ISO/IEC 42001:2023Artificial intelligence management systemOfficial source
European Union
- EU AI Act (2024/1689)Harmonised rules on artificial intelligenceOfficial source
- GDPR (2016/679)General Data Protection RegulationOfficial source
- DORA (2022/2554)Digital Operational Resilience ActOfficial source
United Kingdom
- FCA HandbookFinancial Conduct Authority HandbookOfficial source
- PRA SS1/23Model risk management principles for banksOfficial source
United States
- NIST CSF 2.0Cybersecurity FrameworkOfficial source
- NIST AI RMF 1.0AI Risk Management FrameworkOfficial source
What Regurai provides, and what remains yours.
Regurai provides
- Normalised framework requirements with named owners
- Control mappings and the strength of each mapping
- Gap identification with suggested remediation for human decision
- Actions, attestations and a tamper-evident change history
Your organisation remains responsible for
- Determining which frameworks and requirements apply to it
- Implementing and operating the controls
- The sufficiency and accuracy of the evidence held
- Any assertion of regulatory compliance or certification
Related: Governance & compliance and Audit & evidence.
