Coverage maps draw the relationships that power the crosswalk as flows: which controls mitigate which risks, which policies cover which framework requirements, and which platform checks evidence which clauses. Every map ends in a decision list, so the picture is not the point - the next action is. Open them from Coverage maps in the Work section of the sidebar.

Risks to controls, policies to frameworks, and the decision lists that come out of them. (63 seconds)

Reading a map

Sources sit in the left column, targets in the right. The width of a ribbon is the number of relationships it carries: a control that mitigates nine risks draws a wider band than one that mitigates one. Each node carries a small status dot:

  • In place (green) - the control is effective, the policy approved, the check passing.
  • Needs attention (amber) - partially implemented, in review, or rated poor.
  • Gap (red) - not implemented, failing, or nothing behind the node at all.
  • Not evaluated (grey) - no assessment or scan yet.

Click a node to open the record behind it. Hover a ribbon to see what it represents, for example "3 risks mitigated" or "11 requirements covered". Where relationships stop, a grey node collects the gap: No control for risks without a control, No policy for requirements without a policy. On a phone the same map is shown as a list, one source per row with its status and the targets it reaches.

Risks to controls

Venvera coverage map flowing risk categories to the controls that mitigate them, each control marked with its effectiveness
Risks to controls, grouped by category - shown with sample data.

The first map takes every active risk in the register and draws it to the controls linked to it, then on to the frameworks whose requirements those controls satisfy. Switch between By category (Cyber, Operational, Third-Party and so on) and Individual risks. The caption above the map states the numbers plainly: how many risks are active, how many have at least one control, and how many controls carry that mitigation.

The decision list underneath is ordered by what matters most:

FindingWhat it meansAction
Weak controlA control rated poor or partially effective that several risks depend on. Listed first, with the number of risks behind it.Strengthen
Unmitigated riskA risk with a high or critical residual rating and no control at all.Add a control
Single controlA high residual risk resting on exactly one control - one failure away from being unmitigated.Add a second control

Policies to frameworks

Venvera coverage map flowing policies to the frameworks whose requirements they cover, with framework chips to filter and a gap node for requirements without a policy
Policies to frameworks - shown with sample data.

The second map draws each policy to the frameworks whose requirements it is mapped to. Each framework node reports its own gap - "12 of 93 requirements without a policy" or "Every requirement has a policy" - and the framework chips above the map narrow it to one framework, where the right column becomes that framework's individual requirements. Frameworks with no policy mapped at all are not drawn; their gap is stated in the decision list instead.

The decision list ranks the frameworks with the largest policy gaps first, then the policies waiting for approval together with the number of requirements approving each one would cover:

  • Uncovered framework - "x of y requirements have no policy behind them". Action: Map or write policies.
  • Unapproved policy - a policy in draft or review; approving it covers the stated number of requirements. Action: Approve.

Platform maps

When Azure / Microsoft 365 or Google Workspace is connected, the page gains a tab per platform. These maps draw the platform's checks to the framework requirements they evidence, with failing checks in red. The decision list ranks failing checks by the number of requirements they affect ("Affects 14 requirements across 6 frameworks") and names the action: fix the setting in the tenant, or enable a check the scanner skipped. The same map lives on the Map tab of each platform section.

💡
Use the maps in review meetings. "Which three things would move the most requirements?" is answered by the top of a decision list, and the ribbons show the reviewer why without a spreadsheet.
ℹ️
Permissions follow the underlying data: grc.view for the risks map, policies.view for the policies map and integrations.view for the platform maps. A user without one of them simply does not see that tab.