Use AI-powered suggestions to map policies to controls, reduce manual effort, and keep compliance mappings accurate and up to date.
Mapping controls to policies is critical for maintaining compliance, but it can also be one of the most time-consuming parts of managing a GRC program.
To improve accuracy and reduce manual work, Drata provides AI-powered control suggestions.
This feature helps you identify the most relevant controls for a policy based on its content and workspace context.
How AI control suggestions work
When a policy is approved or published, Drata’s AI analyzes the policy content and generates a list of recommended controls to map to that policy.
Suggestions are based on:
The policy text
The controls available in the selected workspace
Existing control mappings (already mapped controls are excluded)
What’s included
AI-powered control suggestions can include both standard and custom controls.
This feature is supported for all policy types, including:
Template policies
Custom policies
External policies
Prerequisites
To use AI-powered control suggestions, the following requirements must be met:
AI must be enabled for your organization. Go to AI settings to turn it on.
The policy must be approved or published.
The policy must:
Be written in English
Contain at least 450 words
Required Drata Roles: Admin, Guest Administrator, Information Security Lead, Policy Manager, or Control Manager.
You must have permission to view and map controls. Read-only roles cannot use this feature.
View and manage AI control suggestions
To review suggestions:
Open a policy.
Navigate to the Controls tab under mapped controls.
Once the policy is approved or published, suggested controls appear automatically.
Use the ellipsis menu to:
Map all suggested controls
Ignore all suggestions
Regenerate suggestions
Ignored suggestions are hidden in the current version of the policy. If suggestions are regenerated in the future, previously ignored controls may reappear.
AI-powered control suggestions status
You may see one of the following states:
Generating suggestions
AI is analyzing the policy content.Suggestions available
One or more controls are recommended and ready for review.No suggestions found
This can occur if:The policy is too short
The policy is not in English
The policy is still in Draft or Needs approval
No relevant controls were identified
AI is not enabled
Your role does not allow control mapping
Current limitations and important notes
If you're using workspaces, AI-powered control suggestions are only available in the New Experience.