Coverage maps draw the relationships that power the crosswalk as flows: which controls mitigate which risks, which policies cover which framework requirements, and which platform checks evidence which clauses. Every map ends in a decision list, so the picture is not the point - the next action is. Open them from Coverage maps in the Work section of the sidebar.
Risks to controls, policies to frameworks, and the decision lists that come out of them. (63 seconds)
Reading a map
Sources sit in the left column, targets in the right. The width of a ribbon is the number of relationships it carries: a control that mitigates nine risks draws a wider band than one that mitigates one. Each node carries a small status dot:
- In place (green) - the control is effective, the policy approved, the check passing.
- Needs attention (amber) - partially implemented, in review, or rated poor.
- Gap (red) - not implemented, failing, or nothing behind the node at all.
- Not evaluated (grey) - no assessment or scan yet.
Click a node to open the record behind it. Hover a ribbon to see what it represents, for example "3 risks mitigated" or "11 requirements covered". Where relationships stop, a grey node collects the gap: No control for risks without a control, No policy for requirements without a policy. On a phone the same map is shown as a list, one source per row with its status and the targets it reaches.
Risks to controls

The first map takes every active risk in the register and draws it to the controls linked to it, then on to the frameworks whose requirements those controls satisfy. Switch between By category (Cyber, Operational, Third-Party and so on) and Individual risks. The caption above the map states the numbers plainly: how many risks are active, how many have at least one control, and how many controls carry that mitigation.
The decision list underneath is ordered by what matters most:
| Finding | What it means | Action |
|---|---|---|
| Weak control | A control rated poor or partially effective that several risks depend on. Listed first, with the number of risks behind it. | Strengthen |
| Unmitigated risk | A risk with a high or critical residual rating and no control at all. | Add a control |
| Single control | A high residual risk resting on exactly one control - one failure away from being unmitigated. | Add a second control |
Policies to frameworks

The second map draws each policy to the frameworks whose requirements it is mapped to. Each framework node reports its own gap - "12 of 93 requirements without a policy" or "Every requirement has a policy" - and the framework chips above the map narrow it to one framework, where the right column becomes that framework's individual requirements. Frameworks with no policy mapped at all are not drawn; their gap is stated in the decision list instead.
The decision list ranks the frameworks with the largest policy gaps first, then the policies waiting for approval together with the number of requirements approving each one would cover:
- Uncovered framework - "x of y requirements have no policy behind them". Action: Map or write policies.
- Unapproved policy - a policy in draft or review; approving it covers the stated number of requirements. Action: Approve.
Platform maps
When Azure / Microsoft 365 or Google Workspace is connected, the page gains a tab per platform. These maps draw the platform's checks to the framework requirements they evidence, with failing checks in red. The decision list ranks failing checks by the number of requirements they affect ("Affects 14 requirements across 6 frameworks") and names the action: fix the setting in the tenant, or enable a check the scanner skipped. The same map lives on the Map tab of each platform section.