Skip to content

Framework Compliance & Gap Analysis

Upload and map regulatory frameworks to your internal policies to find coverage gaps.

FRWhat it is
FR2Upload and map frameworks to find gaps
FR3Manage a regulation and its amendments over time
FR4Verify policies cover a new regulation
FR5Compare regulations to surface overlaps
FR6Classify each obligation as mandatory or optional
FR7Periodic (annual) NIST / ISO 27001 gap analysis
FR7-ITSCMDedicated ITSCM / continuity gap analysis

FR2 · Adopting a regulation

1

Upload your company policies into the Document Hub.

The AXA XL compliance dashboard with the Documents Hub and Risk Exposure widget.
Your compliance home — the Documents Hub is where your policies live.
2

Open the regulation library.

The Library tab of the Regulatory Drawer, listing regulations with Import buttons.
The Library — regulations you can adopt into your organization.
3

If the framework is already there, click Adopt.

Demo — adopting a regulation from the Regulatory Drawer.
4

If it is not there, click Upload and add the PDF/DOCX.

The Upload Regulation dialog: choose a regulation, set region scope, upload the primary text.
Not in the library? Upload your own regulation document instead.
Demo — uploading a regulation / evidence document.
5

Click Generate Questions / Analyze.

6

Click Analyze All, and the system checks your policies against the rules.

Demo — the dashboard widgets after analysis.

Which frameworks (FR2 list). The capability is framework-agnostic — any of these can be adopted from the library or uploaded as a document:

  • Americas — ITAR/EAR, EO 14117, CFIUS LOA, SACA, HIPAA, NYDFS Part 500, Delaware Insurance Act, California CCPA, CPRA, Illinois BIPA, Connecticut Data Security, Connecticut Data Privacy, FINRA / GLBA, Louisiana Cyber Regulation (US); OSFI B-13, Quebec ICT RMF, QCCPA, PIPEDA (Canada); BMA Solvency Assessment, BMA Risk Management Assessment (Bermuda); SUSEP 638, Brazil LGPD (Brazil).
  • Europe — SWIFT, AXA GO Security Requirements, Airbus/Thales Contract Requirements (FR), EU DORA, EU GDPR, EIOPA Solvency II, EU FIDA, UK FCA / PRA, UK Cyber Essentials, Lloyd’s MS 311, UK Data Protection Act, Switzerland FINMA Notices, Central Bank of Ireland (CBI).
  • National under EU — Ireland, France, Germany, Italy, Spain.
  • APAC — Australia CPS 234, Australia CPS 230, and further APAC regulations.

FR3 · Manage a regulation and its amendments

1

Open an adopted regulation to see its detail drawer.

The DORA detail drawer: 6 amendments, 192 questions with 63 answered and 129 missing, Period Annual 2026, History Approved.
The regulation drawer — amendments, question progress, review period, and approval history in one place.
2

Review the amendments attached to the regulation.

3

Add, update, or re-scope the regulation as its text changes.

Demo — managing regulations and their amendments.
4

Use the History / approval status to track its review state.

FR4 · Verify policies cover a new regulation

1

Make sure your policies are in the Document Hub.

2

Upload the new regulation.

3

Generate questions.

A regulation's detail view: progress and answered/missing counters, Questions / Evidence / Activity tabs.
Each regulation becomes a set of questions with answered / missing status.
4

Run Analyze All.

5

Anything left Unanswered is not covered by your current policies.

The DORA drawer showing 63 answered and 129 missing questions.
The answered / missing counters show exactly what your policies do and do not cover.

FR5 · Compare regulations to surface overlaps

1

Adopt more than one related regulation.

2

Open Obligations or the Compliance Map.

3

Check shared obligations / Conflicts.

4

In a workspace, use Chat with Regulation to ask the AI to compare regulations.

The regulation drawer with a Chat with Regulation action.
Chat with Regulation lets you ask the AI where two regulations overlap.

FR6 · Classify each obligation as mandatory or optional

1

Open the regulation’s Response Canvas.

2

For each response, set its classification to Mandatory or Optional.

The Response Canvas for UK_GDPR with a Mandatory / Optional dropdown open on a response.
Each obligation carries a Mandatory / Optional classification you can set in the Canvas.
3

Use the classification to prioritise which gaps to close first.

FR7 · Periodic NIST / ISO 27001 gap analysis

1

Adopt NIST or ISO 27001 (or upload the PDF).

2

Keep policies in the Document Hub.

3

Set the review Period (for example, Annual 2026).

The regulation drawer showing Period Annual 2026 and an Approved history state.
Set the regulation’s review Period so the gap analysis repeats on schedule.
4

Run Analyze All.

5

Review Unanswered gaps.

6

Export the result, and repeat every year.

FR7-ITSCM · Dedicated ITSCM / continuity gap analysis