About ControlMapper
Problem Statement: Regulatory requirements, standards, and customer assurance expectations are changing quickly, and Governance, Risk and Compliance practitioners often need to assess whether existing control libraries still cover new or updated obligations. This requires mapping a regulatory requirement or custom control against an existing set of controls, identifying the closest matches, and determining whether the existing controls need to be updated to meet the new requirements.
Objective: ControlMapper is designed to help users map Custom Controls to an existing Control Library. It achieves this by looking for the most similar combinations using both keyword (word overlap) and semantic (words with similar meaning) algorithms. The solution does not map the controls, rather it helps users to identify similar controls and users are the ones to do the mapping.
Key Features
- Protects privacy: Matching calculations happen locally in your browser. Browser Local LLM keeps gap analysis on your device.
- Speeds up initial mapping: Instead of manually scanning a control library, users upload a regulatory/custom control set and a control library. ControlMapper ranks likely matches using keyword and semantic similarity.
- Supports human review rather than replacing it: The solution does not auto-approve mappings. It gives candidate matches, scores, and text side by side so the practitioner remains the decision-maker.
- Highlights possible gaps: The LLM gap analysis can compare a custom requirement against a candidate control and list requirements present in the custom control but missing from the control library.
- Works with spreadsheets: We recognise that many GRC teams operate in Excel. ControlMapper allows users to download into Excel anytime during the process.
How to Use
- Upload Data: Navigate to the Upload tab. Upload your Control Library and Custom Controls data (Excel format). Select which columns contain the IDs and Descriptions. The "Descriptions" column is used for similarity matching.
- Local Semantic Matching Go to Settings and click Load semantic model now when you want semantic comparison. Initial model download will require a bit of time (30 seconds to 1 min). Model used: all-MiniLM-L6-v2. If Github source is blocked, download the model separately from Github repo and save it in the same folder as the solution.
- Map Controls: Navigate to the Mapping tab to view similar controls. You can customize the number of top matches to manually review. Once you have decided on the control to map, click on Map.
- Configure LLM Gap Analysis (Optional): Go to the Settings tab, enable AI Gap Analysis, then either load the Browser Local LLM or select a cloud/provider LLM and enter the required API key. You can also customize the gap-analysis prompts here. Once configured, use Trigger LLM Analysis to compare two controls, or use Group Analysis to compare multiple mapped Control Library controls against one Custom Control.
- Export: You can click the Download Results button to export everything to Excel at any point in the process. You can choose to do the AI Analysis in the Solution then do the Mapping in Excel if it is easier.
Demo Data
Load a small SOC 2 control library and ISO 27001 governance set to try the mapping workflow.
1. Control Library
EmptyUpload Control Library (Excel format).
2. Custom Controls
EmptyUpload Custom Controls (e.g., CPS 234).
| # | Regulation / Custom Control | Keyword % | Semantics % |
Weighted Avg % |
ID | Control Library Text |
Trigger LLM Analysis |
LLM Gap Analysis | Mapped? | Grouped Analysis |
|---|---|---|---|---|---|---|---|---|---|---|
| Load files in Upload tab first | ||||||||||