Reuse one control spine. State where the mappings stop.
Ansvar uses NIST SP 800-53 Rev 5 as a canonical spine. Framework requirements attach as sourced links with provenance, and a link becomes a coverage claim only after its relationship has been reviewed and approved. Where an authored mapping does not exist, the library returns no result. The current coverage boundary is documented below.
A framework tag can only ever say “related”
A flat framework tag says only that a control touches a framework. That label throws away the two things an assessor needs from a mapping.
It cannot say how much. A flat tag asserts relatedness and nothing more. It cannot tell you whether the control is equivalent to the requirement, a strict subset that leaves a residual gap, a superset with margin, or a partial overlap. Coverage analysis, gap reports and audit defensibility all rest on exactly that distinction.
It cannot be checked. A tag asserts a mapping but carries no way to verify it. Checking that a control satisfies a requirement means reading the requirement — and copying licensed text into a product to make that possible is both a licensing problem and a drift hazard, because the copy goes stale against its source.
Five relationships, read control-to-requirement
Each edge records one of five relationships. Four carry a coverage consequence; related-to records an informative link and claims nothing.
| Relationship | What it means | What it counts as |
|---|---|---|
equivalent | Control scope and requirement demand are the same | Covered |
superset-of | The control does more than the requirement asks | Covered, with margin |
subset-of | The control does less than the requirement demands | Partial — a residual gap is recorded |
intersects-with | Scopes overlap partially in both directions | Partial — a residual gap is recorded |
related-to | An informative link between the two | Nothing — navigation only |
Every edge also carries its rationale, confidence, provenance and review state. Where a control falls short, the residual gap is written down and becomes visible work rather than hiding behind a green tag.
One control, any framework that asks
Nothing in the model is specific to the four below. A framework joins by registering its requirements and mapping them onto the spine — adding one is a mapping exercise, not a second control set to implement. Here is what IR-4 reaches today, with the relationship recorded on each edge.
related-to except the identity mapping: authoritative for relatedness, and navigable, but not yet a coverage claim. That is the distinction the table above exists to keep.We store the pointer; the text comes from its source
A mapping is a claim. Turning it into evidence means fetching the requirement itself, at the moment you ask, under the entitlements you hold.
A requirement record in the library is an identifier, a short factual title where licensing permits one, and a citation descriptor that says how to resolve it. There is no licensed clause text in the library, and none is paraphrased. For ISO/IEC 27001 and 27002, BSI C5:2020 and the French RGS, records carry identifiers and pointers only — and for ISO, not even titles as a set. BSI C5:2026, published under a licence that permits verbatim reuse with attribution, may also carry short factual titles.
When your agent needs the words, the library hands back the citation descriptor and the gateway resolves the requirement from the corpus that grounds it, checking your entitlement first. Standards you have licensed through the ISO standards add-on resolve as clause text; regulations resolve from the served law corpora with their own citation and licence. The mapping layer never becomes a stale second copy of somebody else's standard.
Coverage grows as fast as review, and no faster
Our covered counts are low today, and the reason is the same one that makes them quotable.
The NIST-published crosswalks we ingest are untyped. NIST's CSF 2.0 to 800-53 mapping carries no set-theory field; the 800-53 to ISO 27001 workbook puts that vocabulary on a legend sheet and types none of its rows; the 800-171 traceability is plain back-matter. They enter the library as related-to — authoritative for relatedness, claiming nothing about coverage.
Typing an edge is judgement work done by a qualified person, and an agent may propose a typing but never approve its own. Ingested links therefore add nothing to covered counts until someone reviews and types them, and proposed typings never count. Outside the generated 800-53 identity map, a covered count means an approved set-theory mapping stands behind it.
Where that leaves us today. Outside the generated 800-53 identity map, external coverage is zero. ISO 27001, CSF 2.0 and 800-171 are connected through the spine by approved related-to links you can navigate and cite — that is the crosswalk in the worked example below. NIS2, DORA and the Cyber Resilience Act are registered as resolvable, citable requirements, but no mappings have been authored for them yet: the library serves none and claims none. Ask it for one of those crosswalks today and it returns nothing, rather than a confident answer it cannot defend.
A real run, not a diagram
A captured production session: one ISO 27001 control walked through the spine and out into CSF 2.0, with the provenance of every hop.
Read the captured run — ISO/IEC 27001:2022 Annex A.5.26 lands on IR-4 in the spine, then on 24 CSF 2.0 subcategories spanning detection, response, recovery and improvement, each edge traced to the NIST mapping row it came from, and each path returned as a navigation link rather than a coverage claim.
Or connect your own client and ask it directly:
Using Ansvar, crosswalk ISO 27001 Annex A.5.26 to NIST CSF 2.0 through the canonical control spine and show the provenance of each hop.
Using Ansvar, show me the canonical control behind incident handling and everything it maps to, with the relationship type on each edge.
Questions teams ask first
If your question is not here, email us — every message gets a human answer.
What is a canonical control?
One control in a single set that your organisation implements and evidences once, independent of the framework asking about it. Ansvar's spine is NIST SP 800-53 Rev 5, a public-domain US government control set, organised under the CSF 2.0 functions, with a defined path for Ansvar-authored extensions where a requirement falls outside it. Frameworks then attach to that set as mappings rather than as separate control lists, so evidence you attach to a control is reused everywhere it maps instead of being rebuilt per audit.
Do you store the ISO 27001 or BSI C5 clause text?
No — identifiers, a resolvable citation, and short factual titles only where the licence permits them. When your agent needs the words, the gateway resolves them from the licensed source under your own entitlements, so what you read is never a stale copy. The section above sets out which frameworks allow titles and which do not.
Why does a framework show zero covered controls?
Because no one has typed those mappings yet, and Ansvar does not count untyped ones. The NIST-published crosswalks we ingest carry no set-theory relationship, so they enter as links that claim nothing until a person reviews and types them. Outside the generated 800-53 identity map, a covered count needs that review — the section above shows where it stands today.
Which plan includes the control library?
Team and Company. For authenticated Team and Company workspaces, the seven control-library tools appear in your connected AI client alongside the law and standards corpora. Anyone can read the worked example linked from this page without signing in.
Put it in front of your own controls
The control library is available on Team and Company plans, through the AI client your team already uses.