Skip to main content

Framework Mapping Agent: AI-Assisted Control Mapping for Custom Frameworks

The Framework Mapping Agent uses AI to recommend control mappings when you bring a custom or unsupported compliance framework into Drata. Instead of manually reading every requirement and matching it to a control yourself, you upload your framework and the Agent suggests mappings — pulling from the DCF controls already active in your workspace, your own custom controls, and the full DCF control library.

Each recommendation comes with a confidence indicator, so you know which suggestions are safe to accept quickly and which deserve a closer look. You stay in control the whole time — nothing is added to your compliance program until you accept it.

This is especially useful when you're onboarding a framework Drata doesn't natively support, such as a regional regulation, an industry-specific standard, or a proprietary framework requested by a customer or auditor.


Prerequisites

  • Custom Framework add-on required: Your organization must have the Custom Framework add-on. There is no additional cost to use the Agent's mapping recommendations.

  • RBAC roles: Admin, Compliance Manager, GRC Lead, Control Manager

  • Workspace awareness: This feature is workspace-aware.


What can I do here?

Import your framework and generate recommendations

  • From the custom framework creation flow, upload a CSV of your framework's requirements.

  • Once the framework is created, Drata automatically generates control mapping recommendations for each requirement.

  • Recommendations are drawn from three sources: DCF controls already active in your workspace, custom controls you've created, and the broader DCF control library — not just the small set of controls provisioned to your account.

Review AI-suggested mappings

  • Open the review queue to see every requirement awaiting a decision.

  • Select a requirement to see its details alongside the suggested control(s) and a confidence indicator for each suggestion.

  • Accept a suggestion to map it to your program, or dismiss it if it isn't a good match.

  • The queue shows loading, empty, and completed states, and you can filter it to focus on what's left to review.

  • Your progress is saved as you go, so you can leave the review and pick up where you left off.

Review low or medium-confidence or unmatched requirements

  • Some requirements won't have a strong match — the Agent will flag these as low or medium-confidence or leave them unmatched rather than force a guess.

  • For these, search the existing controls directly or create a new custom control, then map the requirement to it yourself.

Apply bulk decisions

  • Apply multiple recommendations at once for a single requirements and accept or dismiss them together instead of reviewing one at a time.

  • Bulk actions are reflected immediately in your review progress.


Use cases / Best practices

Onboarding a framework Drata doesn't support natively

If a customer, auditor, or regulator asks you to demonstrate compliance with a framework outside Drata's standard library — a regional regulation, a sector-specific standard, or an internal proprietary framework — upload it as a custom framework and let the Agent generate a starting set of mappings instead of matching every requirement by hand.

Let confidence guide your review effort

Treat confidence indicators as a prioritization tool: spend your review time on lower-confidence and unmatched requirements, and move quickly through high-confidence suggestions that clearly match an existing control.

You're always the final decision-maker

Accepting a recommendation is the only way it's applied to your live compliance program. If a suggestion doesn't reflect your control environment accurately, dismiss it and map the requirement manually — nothing is auto-approved on your behalf.

Pick up where you left off

Large frameworks can mean dozens or hundreds of requirements to review. You don't need to finish in one sitting — the review queue preserves your progress, so you can return and continue later.

Did this answer your question?