{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","contextIds":["ctrl:aiuc-1:A004","ctrl:aiuc-1:A005","ctrl:aiuc-1:E001","ctrl:aiuc-1:E002","ctrl:aiuc-1:E003","ctrl:aiuc-1:E006","ctrl:aiuc-1:E012","ctrl:aiuc-1:E016","ctrl:ccpa:CCPA-1798.140","ctrl:cobit-2019:APO09","ctrl:cobit-2019:APO10","ctrl:cobit-2019:APO14","ctrl:cobit-2019:BAI09","ctrl:cobit-2019:BAI10","ctrl:cobit-2019:DSS04","ctrl:coso-erm:E15","ctrl:coso-ic:P15","ctrl:coso-ic:P5","ctrl:coso-ic:P9","ctrl:dora:DORA-Art28-44","ctrl:eu-ai-act:AIA-Art13","ctrl:eu-ai-act:AIA-Art16","ctrl:eu-ai-act:AIA-Art20","ctrl:eu-ai-act:AIA-Art21-22","ctrl:eu-ai-act:AIA-Art23-25","ctrl:eu-ai-act:AIA-Art26","ctrl:eu-ai-act:AIA-Art43","ctrl:eu-ai-act:AIA-Art47-49","ctrl:eu-ai-act:AIA-Art50","ctrl:eu-ai-act:AIA-Art53","ctrl:eu-ai-act:AIA-Art55","ctrl:eu-ai-act:AIA-Art73","ctrl:gdpr:GDPR-Art28","ctrl:gdpr:GDPR-Art44-49","ctrl:hipaa:HIPAA-164.314","ctrl:iia-2024:Principle 11","ctrl:iia-2024:Principle 12","ctrl:iia-2024:Std 11.1","ctrl:iia-2024:Std 11.2","ctrl:iia-2024:Std 12.1"],"directIds":[],"kind":"bundle","metadata":"/assets/agent_metadata.5c7612c9c5b0b455.json","name":"Third-Party / Supply-Chain Risk","next":"/assets/agent_topics-third-party-supply-chain-risk-2.3b0a4a929e303c61.json","page":1,"pageSize":40,"records":[{"attributes":{"category":"technical","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Protect IP & trade secrets","details":{"automation":"hybrid","control_category":"technical","control_id":"A004","control_type":"preventive","domains":["AI Governance","Data Protection & Privacy"],"framework":"aiuc-1","group":"Data & Privacy","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":5,"source_pages":null,"source_url":"https://www.aiuc-1.com/data-and-privacy/protect-ip-trade-secrets"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-a004-0955d43a.html","id":"ctrl:aiuc-1:A004","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AA004","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/data-and-privacy/protect-ip-trade-secrets","title":"A004 — Protect IP & trade secrets","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-a004-0955d43a.1017c974af4b43d0.json"},{"attributes":{"category":"technical","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Prevent cross-customer data exposure","details":{"automation":"automated","control_category":"technical","control_id":"A005","control_type":"preventive","domains":["AI Governance","Data Protection & Privacy"],"framework":"aiuc-1","group":"Data & Privacy","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":5,"source_pages":null,"source_url":"https://www.aiuc-1.com/data-and-privacy/prevent-cross-customer-data-exposure"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-a005-12903764.html","id":"ctrl:aiuc-1:A005","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AA005","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/data-and-privacy/prevent-cross-customer-data-exposure","title":"A005 — Prevent cross-customer data exposure","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-a005-12903764.f738ac844492303a.json"},{"attributes":{"category":"administrative","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"AI failure plan for security breaches","details":{"automation":"manual","control_category":"administrative","control_id":"E001","control_type":"preventive","domains":["AI Governance","Governance, Policy & Oversight"],"framework":"aiuc-1","group":"Accountability","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":5,"source_pages":null,"source_url":"https://www.aiuc-1.com/accountability/ai-failure-plan-for-security-breaches"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-e001-ec2a2db9.html","id":"ctrl:aiuc-1:E001","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AE001","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/accountability/ai-failure-plan-for-security-breaches","title":"E001 — AI failure plan for security breaches","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-e001-ec2a2db9.9b30235a7d4d4cfe.json"},{"attributes":{"category":"administrative","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"AI failure plan for harmful outputs","details":{"automation":"manual","control_category":"administrative","control_id":"E002","control_type":"preventive","domains":["AI Governance","Governance, Policy & Oversight"],"framework":"aiuc-1","group":"Accountability","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":5,"source_pages":null,"source_url":"https://www.aiuc-1.com/accountability/ai-failure-plan-for-harmful-outputs"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-e002-aa262146.html","id":"ctrl:aiuc-1:E002","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AE002","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/accountability/ai-failure-plan-for-harmful-outputs","title":"E002 — AI failure plan for harmful outputs","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-e002-aa262146.76084dbfb29721e5.json"},{"attributes":{"category":"administrative","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"AI failure plan for hallucinations","details":{"automation":"manual","control_category":"administrative","control_id":"E003","control_type":"preventive","domains":["AI Governance","Governance, Policy & Oversight"],"framework":"aiuc-1","group":"Accountability","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":5,"source_pages":null,"source_url":"https://www.aiuc-1.com/accountability/ai-failure-plan-for-hallucinations"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-e003-2e1c73ec.html","id":"ctrl:aiuc-1:E003","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AE003","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/accountability/ai-failure-plan-for-hallucinations","title":"E003 — AI failure plan for hallucinations","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-e003-2e1c73ec.1024f9b71bf6bb30.json"},{"attributes":{"category":"administrative","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Conduct vendor due diligence","details":{"automation":"manual","control_category":"administrative","control_id":"E006","control_type":"preventive","domains":["AI Governance","Governance, Policy & Oversight"],"framework":"aiuc-1","group":"Accountability","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":5,"source_pages":null,"source_url":"https://www.aiuc-1.com/accountability/conduct-vendor-due-diligence"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-e006-362f564d.html","id":"ctrl:aiuc-1:E006","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AE006","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/accountability/conduct-vendor-due-diligence","title":"E006 — Conduct vendor due diligence","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-e006-362f564d.11bc436f4b4c62cc.json"},{"attributes":{"category":"administrative","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Document regulatory compliance","details":{"automation":"manual","control_category":"administrative","control_id":"E012","control_type":"preventive","domains":["AI Governance","Governance, Policy & Oversight"],"framework":"aiuc-1","group":"Accountability","key_control":false,"requirement_frequency":"Every 6 months","requirement_status":"mandatory","risk_count":3,"source_pages":null,"source_url":"https://www.aiuc-1.com/accountability/document-regulatory-compliance"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-e012-78a3be53.html","id":"ctrl:aiuc-1:E012","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AE012","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/accountability/document-regulatory-compliance","title":"E012 — Document regulatory compliance","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-e012-78a3be53.10961e879e61170f.json"},{"attributes":{"category":"technical","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Implement AI disclosure mechanisms","details":{"automation":"automated","control_category":"technical","control_id":"E016","control_type":"preventive","domains":["AI Governance","Governance, Policy & Oversight"],"framework":"aiuc-1","group":"Accountability","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":6,"source_pages":null,"source_url":"https://www.aiuc-1.com/accountability/implement-ai-disclosure-mechanisms"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-e016-8f16478c.html","id":"ctrl:aiuc-1:E016","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AE016","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/accountability/implement-ai-disclosure-mechanisms","title":"E016 — Implement AI disclosure mechanisms","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-e016-8f16478c.20ff782c5cc3bf1d.json"},{"attributes":{"category":"administrative","framework":"ccpa","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/ccpa/","description":"Service-provider and contractor contract requirements","details":{"automation":"manual","control_category":"administrative","control_id":"CCPA-1798.140","control_type":"preventive","domains":["Data Protection & Privacy","Compliance, Audit & Assurance","Governance, Policy & Oversight"],"framework":"ccpa","group":"CCPA/CPRA (California Consumer Privacy)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-ccpa-ccpa-1798-140-775f9cfa.html","id":"ctrl:ccpa:CCPA-1798.140","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Accpa%3ACCPA-1798.140","sourceIds":["ccpa"],"sourceUrl":null,"title":"CCPA-1798.140 — Service-provider and contractor contract requirements","type":"control","url":"/assets/agent_record-ctrl-ccpa-ccpa-1798-140-775f9cfa.b5ef741dc3aa2c1d.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Service Agreements","details":{"automation":"manual","control_category":"administrative","control_id":"APO09","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Human Resources / Personnel Security","Third-Party / Supply-Chain Risk","Asset Management & Inventory"],"framework":"cobit-2019","group":"Align, Plan and Organize","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":8,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-apo09-2d1f48e2.html","id":"ctrl:cobit-2019:APO09","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3AAPO09","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"APO09 — Managed Service Agreements","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-apo09-2d1f48e2.633991f774128f82.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Vendors","details":{"automation":"manual","control_category":"administrative","control_id":"APO10","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Human Resources / Personnel Security","Third-Party / Supply-Chain Risk","Asset Management & Inventory"],"framework":"cobit-2019","group":"Align, Plan and Organize","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":8,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-apo10-2c3cb0dc.html","id":"ctrl:cobit-2019:APO10","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3AAPO10","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"APO10 — Managed Vendors","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-apo10-2c3cb0dc.c8d0cf0279298206.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Data","details":{"automation":"manual","control_category":"administrative","control_id":"APO14","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Human Resources / Personnel Security","Third-Party / Supply-Chain Risk","Asset Management & Inventory"],"framework":"cobit-2019","group":"Align, Plan and Organize","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-apo14-ab650d02.html","id":"ctrl:cobit-2019:APO14","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3AAPO14","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"APO14 — Managed Data","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-apo14-ab650d02.5061680c52a84d2d.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Assets","details":{"automation":"hybrid","control_category":"administrative","control_id":"BAI09","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security","Secure Configuration & Change Management","Asset Management & Inventory","Business Continuity & Disaster Recovery"],"framework":"cobit-2019","group":"Build, Acquire and Implement","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-bai09-09a008c3.html","id":"ctrl:cobit-2019:BAI09","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ABAI09","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"BAI09 — Managed Assets","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-bai09-09a008c3.269925ad628c54e8.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Configuration","details":{"automation":"hybrid","control_category":"administrative","control_id":"BAI10","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security","Secure Configuration & Change Management","Asset Management & Inventory","Business Continuity & Disaster Recovery"],"framework":"cobit-2019","group":"Build, Acquire and Implement","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":7,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-bai10-40479176.html","id":"ctrl:cobit-2019:BAI10","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ABAI10","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"BAI10 — Managed Configuration","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-bai10-40479176.0dd8cba1e3a97830.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Continuity","details":{"automation":"hybrid","control_category":"administrative","control_id":"DSS04","control_type":"corrective","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"cobit-2019","group":"Deliver, Service and Support","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-dss04-2d611bca.html","id":"ctrl:cobit-2019:DSS04","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ADSS04","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"DSS04 — Managed Continuity","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-dss04-2d611bca.f6686538c00a9f08.json"},{"attributes":{"category":"administrative","framework":"coso-erm","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/coso-erm/","description":"Assesses Substantial Change","details":{"automation":"manual","control_category":"administrative","control_id":"E15","control_type":"detective","domains":["Risk Assessment & Management","Compliance, Audit & Assurance","Governance, Policy & Oversight"],"framework":"coso-erm","group":"Review & Revision","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-coso-erm-e15-7207b4fa.html","id":"ctrl:coso-erm:E15","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acoso-erm%3AE15","sourceIds":["coso-erm"],"sourceUrl":null,"title":"E15 — Assesses Substantial Change","type":"control","url":"/assets/agent_record-ctrl-coso-erm-e15-7207b4fa.105d0e569f4c2702.json"},{"attributes":{"category":"administrative","framework":"coso-ic","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/coso-ic/","description":"The organization communicates with external parties regarding matters affecting the functioning of internal control.","details":{"automation":"manual","control_category":"administrative","control_id":"P15","control_type":"preventive","domains":["Compliance, Audit & Assurance","Financial Reporting Controls (SOX)"],"framework":"coso-ic","group":"Information & Communication","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-coso-ic-p15-04537dd0.html","id":"ctrl:coso-ic:P15","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acoso-ic%3AP15","sourceIds":["coso-ic"],"sourceUrl":null,"title":"P15 — The organization communicates with external parties regarding matters affecting the functioning of internal control.","type":"control","url":"/assets/agent_record-ctrl-coso-ic-p15-04537dd0.cd4963c320fdfc50.json"},{"attributes":{"category":"administrative","framework":"coso-ic","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/coso-ic/","description":"The organization holds individuals accountable for their internal control responsibilities in the pursuit of objectives.","details":{"automation":"manual","control_category":"administrative","control_id":"P5","control_type":"preventive","domains":["Governance, Policy & Oversight","Human Resources / Personnel Security"],"framework":"coso-ic","group":"Control Environment","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-coso-ic-p5-7f62f522.html","id":"ctrl:coso-ic:P5","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acoso-ic%3AP5","sourceIds":["coso-ic"],"sourceUrl":null,"title":"P5 — The organization holds individuals accountable for their internal control responsibilities in the pursuit of objectives.","type":"control","url":"/assets/agent_record-ctrl-coso-ic-p5-7f62f522.36791ace8dd5f10f.json"},{"attributes":{"category":"administrative","framework":"coso-ic","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/coso-ic/","description":"The organization identifies and assesses changes that could significantly impact the system of internal control.","details":{"automation":"manual","control_category":"administrative","control_id":"P9","control_type":"preventive","domains":["Risk Assessment & Management","Third-Party / Supply-Chain Risk"],"framework":"coso-ic","group":"Risk Assessment","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-coso-ic-p9-8a96cb71.html","id":"ctrl:coso-ic:P9","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acoso-ic%3AP9","sourceIds":["coso-ic"],"sourceUrl":null,"title":"P9 — The organization identifies and assesses changes that could significantly impact the system of internal control.","type":"control","url":"/assets/agent_record-ctrl-coso-ic-p9-8a96cb71.983a56d89d3d016f.json"},{"attributes":{"category":"administrative","framework":"dora","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/dora/","description":"Managing of ICT third-party risk","details":{"automation":"manual","control_category":"administrative","control_id":"DORA-Art28-44","control_type":"preventive","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Third-Party / Supply-Chain Risk","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"dora","group":"EU DORA (Digital Operational Resilience Act)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":8,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-dora-dora-art28-44-d3e89c89.html","id":"ctrl:dora:DORA-Art28-44","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Adora%3ADORA-Art28-44","sourceIds":["dora"],"sourceUrl":null,"title":"DORA-Art28-44 — Managing of ICT third-party risk","type":"control","url":"/assets/agent_record-ctrl-dora-dora-art28-44-d3e89c89.a71563b64de05293.json"},{"attributes":{"category":"administrative","framework":"eu-ai-act","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/eu-ai-act/","description":"Transparency and provision of information to deployers (high-risk)","details":{"automation":"manual","control_category":"administrative","control_id":"AIA-Art13","control_type":"preventive","domains":["AI Governance","Risk Assessment & Management","Governance, Policy & Oversight"],"framework":"eu-ai-act","group":"EU AI Act","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-eu-ai-act-aia-art13-bee2028e.html","id":"ctrl:eu-ai-act:AIA-Art13","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aeu-ai-act%3AAIA-Art13","sourceIds":["eu-ai-act"],"sourceUrl":null,"title":"AIA-Art13 — Transparency and provision of information to deployers (high-risk)","type":"control","url":"/assets/agent_record-ctrl-eu-ai-act-aia-art13-bee2028e.38dfba7e31c5462c.json"},{"attributes":{"category":"administrative","framework":"eu-ai-act","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/eu-ai-act/","description":"Obligations of providers of high-risk AI systems","details":{"automation":"manual","control_category":"administrative","control_id":"AIA-Art16","control_type":"preventive","domains":["AI Governance","Risk Assessment & Management","Governance, Policy & Oversight"],"framework":"eu-ai-act","group":"EU AI Act","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-eu-ai-act-aia-art16-63a82efa.html","id":"ctrl:eu-ai-act:AIA-Art16","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aeu-ai-act%3AAIA-Art16","sourceIds":["eu-ai-act"],"sourceUrl":null,"title":"AIA-Art16 — Obligations of providers of high-risk AI systems","type":"control","url":"/assets/agent_record-ctrl-eu-ai-act-aia-art16-63a82efa.e1abdb71d13c21b8.json"},{"attributes":{"category":"administrative","framework":"eu-ai-act","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/eu-ai-act/","description":"Corrective actions and duty of information for non-conforming high-risk AI systems","details":{"automation":"manual","control_category":"administrative","control_id":"AIA-Art20","control_type":"corrective","domains":["AI Governance","Risk Assessment & Management","Governance, Policy & Oversight"],"framework":"eu-ai-act","group":"EU AI Act","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-eu-ai-act-aia-art20-ee657bfd.html","id":"ctrl:eu-ai-act:AIA-Art20","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aeu-ai-act%3AAIA-Art20","sourceIds":["eu-ai-act"],"sourceUrl":null,"title":"AIA-Art20 — Corrective actions and duty of information for non-conforming high-risk AI systems","type":"control","url":"/assets/agent_record-ctrl-eu-ai-act-aia-art20-ee657bfd.2b32d1feedba9e5b.json"},{"attributes":{"category":"administrative","framework":"eu-ai-act","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/eu-ai-act/","description":"Cooperation with competent authorities; authorised representatives of non-EU providers","details":{"automation":"manual","control_category":"administrative","control_id":"AIA-Art21-22","control_type":"preventive","domains":["AI Governance","Risk Assessment & Management","Governance, Policy & Oversight"],"framework":"eu-ai-act","group":"EU AI Act","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-eu-ai-act-aia-art21-22-eb4ae796.html","id":"ctrl:eu-ai-act:AIA-Art21-22","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aeu-ai-act%3AAIA-Art21-22","sourceIds":["eu-ai-act"],"sourceUrl":null,"title":"AIA-Art21-22 — Cooperation with competent authorities; authorised representatives of non-EU providers","type":"control","url":"/assets/agent_record-ctrl-eu-ai-act-aia-art21-22-eb4ae796.b50f01834920c071.json"},{"attributes":{"category":"administrative","framework":"eu-ai-act","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/eu-ai-act/","description":"Obligations of importers and distributors; responsibilities along the AI value chain","details":{"automation":"manual","control_category":"administrative","control_id":"AIA-Art23-25","control_type":"preventive","domains":["AI Governance","Risk Assessment & Management","Governance, Policy & Oversight"],"framework":"eu-ai-act","group":"EU AI Act","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-eu-ai-act-aia-art23-25-05f2196c.html","id":"ctrl:eu-ai-act:AIA-Art23-25","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aeu-ai-act%3AAIA-Art23-25","sourceIds":["eu-ai-act"],"sourceUrl":null,"title":"AIA-Art23-25 — Obligations of importers and distributors; responsibilities along the AI value chain","type":"control","url":"/assets/agent_record-ctrl-eu-ai-act-aia-art23-25-05f2196c.d5b607a27471cdf8.json"},{"attributes":{"category":"administrative","framework":"eu-ai-act","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/eu-ai-act/","description":"Obligations of deployers of high-risk AI systems","details":{"automation":"manual","control_category":"administrative","control_id":"AIA-Art26","control_type":"preventive","domains":["AI Governance","Risk Assessment & Management","Governance, Policy & Oversight"],"framework":"eu-ai-act","group":"EU AI Act","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-eu-ai-act-aia-art26-600eb687.html","id":"ctrl:eu-ai-act:AIA-Art26","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aeu-ai-act%3AAIA-Art26","sourceIds":["eu-ai-act"],"sourceUrl":null,"title":"AIA-Art26 — Obligations of deployers of high-risk AI systems","type":"control","url":"/assets/agent_record-ctrl-eu-ai-act-aia-art26-600eb687.ed2fb2c45d19ebad.json"},{"attributes":{"category":"administrative","framework":"eu-ai-act","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/eu-ai-act/","description":"Conformity assessment of high-risk AI systems","details":{"automation":"manual","control_category":"administrative","control_id":"AIA-Art43","control_type":"preventive","domains":["AI Governance","Risk Assessment & Management","Governance, Policy & Oversight"],"framework":"eu-ai-act","group":"EU AI Act","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-eu-ai-act-aia-art43-00b4ae7a.html","id":"ctrl:eu-ai-act:AIA-Art43","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aeu-ai-act%3AAIA-Art43","sourceIds":["eu-ai-act"],"sourceUrl":null,"title":"AIA-Art43 — Conformity assessment of high-risk AI systems","type":"control","url":"/assets/agent_record-ctrl-eu-ai-act-aia-art43-00b4ae7a.a3ba609f30fba42e.json"},{"attributes":{"category":"administrative","framework":"eu-ai-act","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/eu-ai-act/","description":"EU declaration of conformity, CE marking and registration in the EU database","details":{"automation":"manual","control_category":"administrative","control_id":"AIA-Art47-49","control_type":"preventive","domains":["AI Governance","Risk Assessment & Management","Governance, Policy & Oversight"],"framework":"eu-ai-act","group":"EU AI Act","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-eu-ai-act-aia-art47-49-48da9c43.html","id":"ctrl:eu-ai-act:AIA-Art47-49","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aeu-ai-act%3AAIA-Art47-49","sourceIds":["eu-ai-act"],"sourceUrl":null,"title":"AIA-Art47-49 — EU declaration of conformity, CE marking and registration in the EU database","type":"control","url":"/assets/agent_record-ctrl-eu-ai-act-aia-art47-49-48da9c43.37ead2d90babf03e.json"},{"attributes":{"category":"administrative","framework":"eu-ai-act","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/eu-ai-act/","description":"Transparency obligations for certain AI systems (deepfakes, chatbots, emotion recognition)","details":{"automation":"manual","control_category":"administrative","control_id":"AIA-Art50","control_type":"preventive","domains":["AI Governance","Risk Assessment & Management","Governance, Policy & Oversight"],"framework":"eu-ai-act","group":"EU AI Act","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-eu-ai-act-aia-art50-a9da90b0.html","id":"ctrl:eu-ai-act:AIA-Art50","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aeu-ai-act%3AAIA-Art50","sourceIds":["eu-ai-act"],"sourceUrl":null,"title":"AIA-Art50 — Transparency obligations for certain AI systems (deepfakes, chatbots, emotion recognition)","type":"control","url":"/assets/agent_record-ctrl-eu-ai-act-aia-art50-a9da90b0.c360412f3dca787b.json"},{"attributes":{"category":"administrative","framework":"eu-ai-act","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/eu-ai-act/","description":"Obligations for providers of general-purpose AI (GPAI) models","details":{"automation":"manual","control_category":"administrative","control_id":"AIA-Art53","control_type":"preventive","domains":["AI Governance","Risk Assessment & Management","Governance, Policy & Oversight"],"framework":"eu-ai-act","group":"EU AI Act","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-eu-ai-act-aia-art53-fd785909.html","id":"ctrl:eu-ai-act:AIA-Art53","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aeu-ai-act%3AAIA-Art53","sourceIds":["eu-ai-act"],"sourceUrl":null,"title":"AIA-Art53 — Obligations for providers of general-purpose AI (GPAI) models","type":"control","url":"/assets/agent_record-ctrl-eu-ai-act-aia-art53-fd785909.bb957c663fdc95e5.json"},{"attributes":{"category":"administrative","framework":"eu-ai-act","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/eu-ai-act/","description":"Obligations for GPAI models with systemic risk","details":{"automation":"manual","control_category":"administrative","control_id":"AIA-Art55","control_type":"preventive","domains":["AI Governance","Risk Assessment & Management","Governance, Policy & Oversight"],"framework":"eu-ai-act","group":"EU AI Act","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-eu-ai-act-aia-art55-53ccdfc5.html","id":"ctrl:eu-ai-act:AIA-Art55","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aeu-ai-act%3AAIA-Art55","sourceIds":["eu-ai-act"],"sourceUrl":null,"title":"AIA-Art55 — Obligations for GPAI models with systemic risk","type":"control","url":"/assets/agent_record-ctrl-eu-ai-act-aia-art55-53ccdfc5.055acf00c96e3812.json"},{"attributes":{"category":"administrative","framework":"eu-ai-act","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/eu-ai-act/","description":"Reporting of serious incidents (providers; deployers inform providers)","details":{"automation":"manual","control_category":"administrative","control_id":"AIA-Art73","control_type":"corrective","domains":["AI Governance","Risk Assessment & Management","Governance, Policy & Oversight"],"framework":"eu-ai-act","group":"EU AI Act","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-eu-ai-act-aia-art73-60a07514.html","id":"ctrl:eu-ai-act:AIA-Art73","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aeu-ai-act%3AAIA-Art73","sourceIds":["eu-ai-act"],"sourceUrl":null,"title":"AIA-Art73 — Reporting of serious incidents (providers; deployers inform providers)","type":"control","url":"/assets/agent_record-ctrl-eu-ai-act-aia-art73-60a07514.839e7b578da88477.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"Processor obligations and data processing agreements","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art28","control_type":"preventive","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art28-e21fee94.html","id":"ctrl:gdpr:GDPR-Art28","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art28","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art28 — Processor obligations and data processing agreements","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art28-e21fee94.5ea41d93b9f5d85d.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"International transfers of personal data","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art44-49","control_type":"preventive","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art44-49-8ad28202.html","id":"ctrl:gdpr:GDPR-Art44-49","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art44-49","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art44-49 — International transfers of personal data","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art44-49-8ad28202.5b6cd8ca6d1807c9.json"},{"attributes":{"category":"administrative","framework":"hipaa","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/hipaa/","description":"Organizational requirements (business associate contracts, group health plan requirements)","details":{"automation":"manual","control_category":"administrative","control_id":"HIPAA-164.314","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Access Control & Identity Management","Physical & Environmental Security","Logging, Monitoring & Detection","Business Continuity & Disaster Recovery","Third-Party / Supply-Chain Risk","Data Protection & Privacy"],"framework":"hipaa","group":"HIPAA Security Rule","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-hipaa-hipaa-164-314-0b44ffa8.html","id":"ctrl:hipaa:HIPAA-164.314","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Ahipaa%3AHIPAA-164.314","sourceIds":["hipaa"],"sourceUrl":null,"title":"HIPAA-164.314 — Organizational requirements (business associate contracts, group health plan requirements)","type":"control","url":"/assets/agent_record-ctrl-hipaa-hipaa-164-314-0b44ffa8.99cd944bf9558eae.json"},{"attributes":{"category":"administrative","framework":"iia-2024","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-2024/","description":"Communicate Effectively","details":{"automation":"manual","control_category":"administrative","control_id":"Principle 11","control_type":"preventive","domains":["Compliance, Audit & Assurance","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"iia-2024","group":"Domain IV — Managing the Internal Audit Function","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iia-2024-principle-11-9a00dcd8.html","id":"ctrl:iia-2024:Principle 11","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-2024%3APrinciple+11","sourceIds":["iia-2024"],"sourceUrl":null,"title":"Principle 11 — Communicate Effectively","type":"control","url":"/assets/agent_record-ctrl-iia-2024-principle-11-9a00dcd8.3ee343f37f020ae3.json"},{"attributes":{"category":"administrative","framework":"iia-2024","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-2024/","description":"Enhance Quality","details":{"automation":"manual","control_category":"administrative","control_id":"Principle 12","control_type":"detective","domains":["Compliance, Audit & Assurance","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"iia-2024","group":"Domain IV — Managing the Internal Audit Function","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iia-2024-principle-12-ef0f1834.html","id":"ctrl:iia-2024:Principle 12","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-2024%3APrinciple+12","sourceIds":["iia-2024"],"sourceUrl":null,"title":"Principle 12 — Enhance Quality","type":"control","url":"/assets/agent_record-ctrl-iia-2024-principle-12-ef0f1834.cfae2cd589424cae.json"},{"attributes":{"category":"administrative","framework":"iia-2024","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-2024/","description":"Building Relationships and Communicating with Stakeholders","details":{"automation":"manual","control_category":"administrative","control_id":"Std 11.1","control_type":"preventive","domains":["Compliance, Audit & Assurance","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"iia-2024","group":"Domain IV — Managing the Internal Audit Function","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iia-2024-std-11-1-ae43870c.html","id":"ctrl:iia-2024:Std 11.1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-2024%3AStd+11.1","sourceIds":["iia-2024"],"sourceUrl":null,"title":"Std 11.1 — Building Relationships and Communicating with Stakeholders","type":"control","url":"/assets/agent_record-ctrl-iia-2024-std-11-1-ae43870c.30c92ce46abb789a.json"},{"attributes":{"category":"administrative","framework":"iia-2024","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-2024/","description":"Effective Communication","details":{"automation":"manual","control_category":"administrative","control_id":"Std 11.2","control_type":"preventive","domains":["Compliance, Audit & Assurance","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"iia-2024","group":"Domain IV — Managing the Internal Audit Function","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iia-2024-std-11-2-36c386cb.html","id":"ctrl:iia-2024:Std 11.2","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-2024%3AStd+11.2","sourceIds":["iia-2024"],"sourceUrl":null,"title":"Std 11.2 — Effective Communication","type":"control","url":"/assets/agent_record-ctrl-iia-2024-std-11-2-36c386cb.80f6cf7c808bb2b6.json"},{"attributes":{"category":"administrative","framework":"iia-2024","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-2024/","description":"Internal Quality Assessment","details":{"automation":"manual","control_category":"administrative","control_id":"Std 12.1","control_type":"detective","domains":["Compliance, Audit & Assurance","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"iia-2024","group":"Domain IV — Managing the Internal Audit Function","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iia-2024-std-12-1-5f2fe558.html","id":"ctrl:iia-2024:Std 12.1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-2024%3AStd+12.1","sourceIds":["iia-2024"],"sourceUrl":null,"title":"Std 12.1 — Internal Quality Assessment","type":"control","url":"/assets/agent_record-ctrl-iia-2024-std-12-1-5f2fe558.b1a8e274b5d70c2d.json"}],"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0120d17e0da51c637ec6d208b44f68806054b442bf381ab2a3bf290cbfe22a17","properties":{"control_id":"AIA-Art13","coverage":"full","delta":null,"framework":"eu-ai-act","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2024/1689"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-10-f53dd533.json","sourceId":"uc:UC-AI-10","targetDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art13-bee2028e.json","targetId":"ctrl:eu-ai-act:AIA-Art13","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:05f47708636fcc22888663483542bc3e8693875eea819fc13c46fbd1ba60f18f","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-apo09-2d1f48e2.json","sourceId":"ctrl:cobit-2019:APO09","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:071946c7f47bc974a5dad8a15a71bae0ed4c9fa115558049369b03248c1b5562","properties":{"control_id":"HIPAA-164.314","coverage":"partial","delta":"group health plan document requirements (164.314(b)) fall outside vendor/BA contracting","framework":"hipaa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"45 CFR Parts 160/164 (Security, Privacy, Breach Notification)"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-314-0b44ffa8.json","targetId":"ctrl:hipaa:HIPAA-164.314","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:08901f92f139567733352fa9c46f6b8381406d516a043727a779bb251a871be5","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-coso-ic-p5-7f62f522.json","sourceId":"ctrl:coso-ic:P5","targetDetailPath":"/data/v1/records/std-coso-ic-3f80f565.json","targetId":"std:coso-ic","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0be2c34465b299c94ca6af1affeb773f61d4e88ba0a1046a45cab8dd13a7a1aa","properties":{"control_id":"P9","coverage":"full","delta":null,"framework":"coso-ic","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2013"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-11-3f5d23ea.json","sourceId":"uc:UC-RISK-11","targetDetailPath":"/data/v1/records/ctrl-coso-ic-p9-8a96cb71.json","targetId":"ctrl:coso-ic:P9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0e01a91c505dc9722946c2e57191c233c7313b629f4f2666e36fdb9e39c37ef8","properties":{"control_id":"AIA-Art16","coverage":"partial","delta":"substantive QMS, conformity-assessment, CE-marking, and EU-database-registration duties are not yet covered by a dedicated unified control - an acknowledged coverage gap in the AI Governance domain","framework":"eu-ai-act","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2024/1689"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-13-2ce71d80.json","sourceId":"uc:UC-AI-13","targetDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art16-63a82efa.json","targetId":"ctrl:eu-ai-act:AIA-Art16","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1034a1bf8aadb88c03724051eb8a21ece1a44c8b14c592c16dc9039e08476a12","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art44-49-8ad28202.json","sourceId":"ctrl:gdpr:GDPR-Art44-49","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:108a3809a1bac8bc7cb9df10dcb04af91bb4cceb5fd8086da8cbfc0011a122c9","properties":{"control_id":"E15","coverage":"full","delta":null,"framework":"coso-erm","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-11-3f5d23ea.json","sourceId":"uc:UC-RISK-11","targetDetailPath":"/data/v1/records/ctrl-coso-erm-e15-7207b4fa.json","targetId":"ctrl:coso-erm:E15","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:151c6358382dbbca56287fa96b5e2f91eda2817b774910275f3b508306cd9bfe","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-a005-12903764.json","sourceId":"ctrl:aiuc-1:A005","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1a49d4c807a940c6b50891663e057143621fdcb4c30dac1e95db5edeb937ec62","properties":{"control_id":"E001","coverage":"partial","delta":"a pre-approved failure plan for AI security breaches with containment, rollback, and customer-notification steps","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-11-7112e573.json","sourceId":"uc:UC-AI-11","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-e001-ec2a2db9.json","targetId":"ctrl:aiuc-1:E001","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1b152ffafabbccfd351468403eaa09760ac35c82f3c4a5b5892a3443464569d8","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art13-bee2028e.json","sourceId":"ctrl:eu-ai-act:AIA-Art13","targetDetailPath":"/data/v1/records/std-eu-ai-act-54986689.json","targetId":"std:eu-ai-act","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1d432230ecd3d2a598a5a0d08362e5568163137ad9ad1a09b7f538785887a862","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-2024-std-11-2-36c386cb.json","sourceId":"ctrl:iia-2024:Std 11.2","targetDetailPath":"/data/v1/records/std-iia-2024-1687734b.json","targetId":"std:iia-2024","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1e1e41b81cfaa99a6c07c8879250c2bf86a8ce054be57cf89dc659bd1c1d76e9","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-2024-principle-12-ef0f1834.json","sourceId":"ctrl:iia-2024:Principle 12","targetDetailPath":"/data/v1/records/std-iia-2024-1687734b.json","targetId":"std:iia-2024","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:206e737c385ca53fe82d7ba6df4799fc9a0c3e70df649c5f972de37fdfe26c05","properties":{"control_id":"AIA-Art23-25","coverage":"partial","delta":"importer and distributor verification duties and the conditions under which a distributor, importer, or deployer becomes a provider","framework":"eu-ai-act","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2024/1689"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-13-2ce71d80.json","sourceId":"uc:UC-AI-13","targetDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art23-25-05f2196c.json","targetId":"ctrl:eu-ai-act:AIA-Art23-25","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2106f7a91c88cd5dc7e2734eb94ee9491fdc036b430053d96b3c746a35a4a4c9","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art20-ee657bfd.json","sourceId":"ctrl:eu-ai-act:AIA-Art20","targetDetailPath":"/data/v1/records/std-eu-ai-act-54986689.json","targetId":"std:eu-ai-act","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:266413b704059cefdeb68ba76808b5444e25095d835aa595a43d1476260b7d3e","properties":{"control_id":"BAI10","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-06-c1afc713.json","sourceId":"uc:UC-SDLC-06","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai10-40479176.json","targetId":"ctrl:cobit-2019:BAI10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:28274a8c3f9ad8a2d885158f58bafbdd313754cb0dbeeb773d63bcdd96809e76","properties":{"control_id":"Std 11.2","coverage":"partial","delta":"Requires communications be accurate, objective, clear, concise, constructive, complete, and timely","framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-18-7ab55995.json","sourceId":"uc:UC-AUDIT-18","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-11-2-36c386cb.json","targetId":"ctrl:iia-2024:Std 11.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:28cbc076c691c4481111652ba581b69d65bc7b35b4c1947853f1515157a6896e","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-dss04-2d611bca.json","sourceId":"ctrl:cobit-2019:DSS04","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2e1a500f18d0e2b83e81106ed2f4fbf92860977b1a8e6661d8bc8b375f5e1366","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-140-775f9cfa.json","sourceId":"ctrl:ccpa:CCPA-1798.140","targetDetailPath":"/data/v1/records/std-ccpa-55f3fd20.json","targetId":"std:ccpa","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2e1dd368ab61117184f962a4423da9347a8dc7bd50f9574314804ebded1af983","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-dora-dora-art28-44-d3e89c89.json","sourceId":"ctrl:dora:DORA-Art28-44","targetDetailPath":"/data/v1/records/std-dora-95cf939d.json","targetId":"std:dora","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:35eebd189f1575ee338fadccdde6be2f9eded242acad4ddcb3aa02c74807db27","properties":{"control_id":"BAI09","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-12-08ce2fc7.json","sourceId":"uc:UC-SDLC-12","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai09-09a008c3.json","targetId":"ctrl:cobit-2019:BAI09","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:39dff700e2a0bbdef624f431f6804954b71d44876cada877e7f382362a2cddea","properties":{"control_id":"APO14","coverage":"partial","delta":"operational data management - data-management strategy, business glossary/metadata, data-quality profiling and cleansing, archiving/backup - beyond governance policy and oversight bodies","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-20-4a468c1a.json","sourceId":"uc:UC-GOV-20","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-apo14-ab650d02.json","targetId":"ctrl:cobit-2019:APO14","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3c72b18e584a203354850963f832b1486e3dd1fd1d8d8f25bc3788de37bc8493","properties":{"control_id":"AIA-Art47-49","coverage":"partial","delta":"drawing up the declaration of conformity, affixing the marking, and registering the system in the public database before placing on the market","framework":"eu-ai-act","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2024/1689"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-13-2ce71d80.json","sourceId":"uc:UC-AI-13","targetDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art47-49-48da9c43.json","targetId":"ctrl:eu-ai-act:AIA-Art47-49","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:400f70c551f11263d174c3150339cb30cd22c365dcf230821bec670279b89c6e","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-coso-ic-p15-04537dd0.json","sourceId":"ctrl:coso-ic:P15","targetDetailPath":"/data/v1/records/std-coso-ic-3f80f565.json","targetId":"std:coso-ic","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:43a819bc0f51c24d97dc540a9b8b9b7cbb8e4e9ef3dd7300c1e5d8199e19fb01","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art43-00b4ae7a.json","sourceId":"ctrl:eu-ai-act:AIA-Art43","targetDetailPath":"/data/v1/records/std-eu-ai-act-54986689.json","targetId":"std:eu-ai-act","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:46649b5491420104088389b6488bcc81c25e0f04301e1b993c9c416d4ab952b2","properties":{"control_id":"GDPR-Art44-49","coverage":"full","delta":null,"framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","sourceId":"uc:UC-DATA-11","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art44-49-8ad28202.json","targetId":"ctrl:gdpr:GDPR-Art44-49","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:471a0896837a1f88972d37d8fd39f0416f1f5b99c225e8bb2df05e7110265338","properties":{"control_id":"AIA-Art26","coverage":"partial","delta":"operational oversight, monitoring, and log-retention duties evidenced via dedicated controls","framework":"eu-ai-act","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2024/1689"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-13-2ce71d80.json","sourceId":"uc:UC-AI-13","targetDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art26-600eb687.json","targetId":"ctrl:eu-ai-act:AIA-Art26","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:522d28aed24ab32fe41449ac950acc152ef604cf0a9e3b0e0aee1ab0b91027e2","properties":{"control_id":"P5","coverage":"full","delta":null,"framework":"coso-ic","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2013"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-07-2a8998f7.json","sourceId":"uc:UC-GOV-07","targetDetailPath":"/data/v1/records/ctrl-coso-ic-p5-7f62f522.json","targetId":"ctrl:coso-ic:P5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5809c10d79dbe0dab9da26811957d1943c0288a7eb8249ba7af1c187dcba466a","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-2024-std-11-1-ae43870c.json","sourceId":"ctrl:iia-2024:Std 11.1","targetDetailPath":"/data/v1/records/std-iia-2024-1687734b.json","targetId":"std:iia-2024","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:621d04b1a2deeaf39ec2c83a5dfdbfa03e8cdcda00b1b7506875d8e238a2c65e","properties":{"control_id":"E003","coverage":"partial","delta":"a pre-approved failure plan for hallucination incidents with containment, rollback, and customer-notification steps","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-11-7112e573.json","sourceId":"uc:UC-AI-11","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-e003-2e1c73ec.json","targetId":"ctrl:aiuc-1:E003","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:639af74f867207985c0d330720da0b18bcbac5a07f9e93504c9405e222505aca","properties":{"control_id":"A005","coverage":"partial","delta":"tenant isolation inside AI systems: retrieval indexes, memory, fine-tuning data, and caches segregated so one customer's data cannot surface in another customer's outputs","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","sourceId":"uc:UC-DATA-11","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-a005-12903764.json","targetId":"ctrl:aiuc-1:A005","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:66c476cbded0770a1dfb5dac88dbddc813fd47b5a6cffddb59a967f1f0fe2087","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-bai10-40479176.json","sourceId":"ctrl:cobit-2019:BAI10","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6c1846fb9812d3a66dd47cb08fabc59bc2947d21d3b9398e0ec8166b1e2f5445","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-a004-0955d43a.json","sourceId":"ctrl:aiuc-1:A004","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7843c3f12abcbdae8c0226c23f8a2d755a402c4d56140aecef697acc9b4fe5df","properties":{"control_id":"DSS04","coverage":"partial","delta":"continuity testing, training, and post-incident review satisfied by companion controls","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-01-428f23d3.json","sourceId":"uc:UC-BCDR-01","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-dss04-2d611bca.json","targetId":"ctrl:cobit-2019:DSS04","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7844c6b31cbd1d768f2a3e54adc373869a072b6ecb9c2ae94226209800315bfe","properties":{"control_id":"Principle 11","coverage":"partial","delta":"Principle 11 also spans communication quality, results reporting, errors, risk-acceptance escalation (11.2-11.5)","framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-18-7ab55995.json","sourceId":"uc:UC-AUDIT-18","targetDetailPath":"/data/v1/records/ctrl-iia-2024-principle-11-9a00dcd8.json","targetId":"ctrl:iia-2024:Principle 11","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7a773fb1e78534dc51329b05ae6a49c568389eee53a7cead548ae2dae672337f","properties":{"control_id":"AIA-Art53","coverage":"full","delta":null,"framework":"eu-ai-act","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2024/1689"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-15-eb9589c6.json","sourceId":"uc:UC-AI-15","targetDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art53-fd785909.json","targetId":"ctrl:eu-ai-act:AIA-Art53","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7d34e04ad1579e310269ee941e2a5c6a7cac485064e493b51c90fee6778eed55","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-2024-principle-11-9a00dcd8.json","sourceId":"ctrl:iia-2024:Principle 11","targetDetailPath":"/data/v1/records/std-iia-2024-1687734b.json","targetId":"std:iia-2024","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8971794847ccd5035c53cd286df2473e21d22b664f87028844a75bd655b59b86","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art28-e21fee94.json","sourceId":"ctrl:gdpr:GDPR-Art28","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:98e288190a80f4b9684f719b462f304e3ad2604643cf30159ec607b9f18aa498","properties":{"control_id":"A004","coverage":"partial","delta":"leakage of intellectual property and confidential information through AI system outputs, requiring model-output safeguards beyond network and channel flow controls","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","sourceId":"uc:UC-DATA-11","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-a004-0955d43a.json","targetId":"ctrl:aiuc-1:A004","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9d6b9b606b485c90a839a57bafe230a44e306f127a95e429e71bf0c9216880aa","properties":{"control_id":"P15","coverage":"partial","delta":"entity-wide external channels (whistleblower, customers, suppliers) beyond assurance stakeholders","framework":"coso-ic","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2013"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-18-7ab55995.json","sourceId":"uc:UC-AUDIT-18","targetDetailPath":"/data/v1/records/ctrl-coso-ic-p15-04537dd0.json","targetId":"ctrl:coso-ic:P15","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9e823c9b9f8f190d5ccca5bbd11e0fa9f642ec650887926835ab9dd785a79abd","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-e016-8f16478c.json","sourceId":"ctrl:aiuc-1:E016","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9fa3d3c91726a4a890c2543bd8ae26001b16207ec017301c6e58893cd622b8a6","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-bai09-09a008c3.json","sourceId":"ctrl:cobit-2019:BAI09","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a1176b69934bb7a2a9b58a8902bddd8d43154c94593f024b32399d5563c800e9","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art47-49-48da9c43.json","sourceId":"ctrl:eu-ai-act:AIA-Art47-49","targetDetailPath":"/data/v1/records/std-eu-ai-act-54986689.json","targetId":"std:eu-ai-act","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a1bb1621ad1c51d063f6e33db96e516aadea16e66c6f3ad15bdb3abc0f0ba182","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-314-0b44ffa8.json","sourceId":"ctrl:hipaa:HIPAA-164.314","targetDetailPath":"/data/v1/records/std-hipaa-a825d271.json","targetId":"std:hipaa","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:aca06ef120dabb82430a487ed877679a3ae107279b2f22a40b97fa0609e4626e","properties":{"control_id":"AIA-Art43","coverage":"partial","delta":"execution of the applicable conformity assessment procedure (internal control or notified body) before placing the system on the market","framework":"eu-ai-act","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2024/1689"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-13-2ce71d80.json","sourceId":"uc:UC-AI-13","targetDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art43-00b4ae7a.json","targetId":"ctrl:eu-ai-act:AIA-Art43","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:adbaa4bf87a505a87b022653888d959ad0ec5b716ebd2383be39e0601fb3b967","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-e002-aa262146.json","sourceId":"ctrl:aiuc-1:E002","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:af6ab2d5251cdc7bb47cb1c14e6b98ada5789c922c2183d0f20d3eebe9bcec52","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art26-600eb687.json","sourceId":"ctrl:eu-ai-act:AIA-Art26","targetDetailPath":"/data/v1/records/std-eu-ai-act-54986689.json","targetId":"std:eu-ai-act","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b1ed9c27194ee1313187f33bdc2bd3453ff18132e9501be428ba167899a52497","properties":{"control_id":"Std 11.1","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-18-7ab55995.json","sourceId":"uc:UC-AUDIT-18","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-11-1-ae43870c.json","targetId":"ctrl:iia-2024:Std 11.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b28ea7bff8a7a69df01a6a4d9b3d714b1e0a06a3413cb514b0e7aa17e4b438dd","properties":{"control_id":"AIA-Art55","coverage":"full","delta":null,"framework":"eu-ai-act","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2024/1689"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-15-eb9589c6.json","sourceId":"uc:UC-AI-15","targetDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art55-53ccdfc5.json","targetId":"ctrl:eu-ai-act:AIA-Art55","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b48d208fc579b8bfaf3f263db5da6c421457ede838fd19c511096175349f2716","properties":{"control_id":"APO10","coverage":"partial","delta":"day-to-day vendor performance monitoring and contract administration","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-apo10-2c3cb0dc.json","targetId":"ctrl:cobit-2019:APO10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b9234cf242770d990321cf2b835603cab23434062235ee36dff7aa0ee556cc7f","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-e003-2e1c73ec.json","sourceId":"ctrl:aiuc-1:E003","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b942e1c5dad608655084fe8b0a63671d65b2e2b08497f85ac6f1be23fd85e28a","properties":{"control_id":"GDPR-Art28","coverage":"full","delta":null,"framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art28-e21fee94.json","targetId":"ctrl:gdpr:GDPR-Art28","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bc558ad8ff092d5a9e10eae1b515809838d780083b7ba00c51f9a09147dac950","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-e012-78a3be53.json","sourceId":"ctrl:aiuc-1:E012","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bcca9a04811547af6f8efe99349fd908107c33b0cb3a58e430301295776d80db","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art21-22-eb4ae796.json","sourceId":"ctrl:eu-ai-act:AIA-Art21-22","targetDetailPath":"/data/v1/records/std-eu-ai-act-54986689.json","targetId":"std:eu-ai-act","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c155012acf013e8a1e3c96c8c7765103fb5c190959a137a8a6cc41a1a4350970","properties":{"control_id":"CCPA-1798.140","coverage":"full","delta":null,"framework":"ccpa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"CCPA (2018) as amended by CPRA (2020)"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-140-775f9cfa.json","targetId":"ctrl:ccpa:CCPA-1798.140","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c3593c35718fb6895e0619e1721925c1cf835b3ceaa054ed46d8cb3be1d5e67d","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-2024-std-12-1-5f2fe558.json","sourceId":"ctrl:iia-2024:Std 12.1","targetDetailPath":"/data/v1/records/std-iia-2024-1687734b.json","targetId":"std:iia-2024","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c3af86201b362726dcf731b480743ed527971d2ee9164ddbdda693ec766a6961","properties":{"control_id":"E012","coverage":"partial","delta":"semiannual documentation of the AI system's regulatory compliance posture and obligations register shared with customers","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-13-2ce71d80.json","sourceId":"uc:UC-AI-13","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-e012-78a3be53.json","targetId":"ctrl:aiuc-1:E012","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c6a95e75741b7912283c6c65a39aa1b75da07ed6faf729a70e32129d65986800","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art50-a9da90b0.json","sourceId":"ctrl:eu-ai-act:AIA-Art50","targetDetailPath":"/data/v1/records/std-eu-ai-act-54986689.json","targetId":"std:eu-ai-act","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c75fc9df42a3d842da0c4a5bd5b70b9d1de6b03a36c073443137ebd0079c518f","properties":{"control_id":"AIA-Art73","coverage":"full","delta":null,"framework":"eu-ai-act","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2024/1689"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-11-7112e573.json","sourceId":"uc:UC-AI-11","targetDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art73-60a07514.json","targetId":"ctrl:eu-ai-act:AIA-Art73","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cb331171f2173812819b3693734a404afeb336920f1e8b5f4e994f54618b914a","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art55-53ccdfc5.json","sourceId":"ctrl:eu-ai-act:AIA-Art55","targetDetailPath":"/data/v1/records/std-eu-ai-act-54986689.json","targetId":"std:eu-ai-act","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cdfc2f9413fd140a562df49ea5eaba903ae055b65fcccc3e24492dd8521dfca7","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art73-60a07514.json","sourceId":"ctrl:eu-ai-act:AIA-Art73","targetDetailPath":"/data/v1/records/std-eu-ai-act-54986689.json","targetId":"std:eu-ai-act","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d29cfe9b4c6815e2799060bccba899163305433b1c550706a1ffaf8800b89fab","properties":{"control_id":"AIA-Art50","coverage":"partial","delta":"informing persons exposed to emotion-recognition/biometric-categorisation systems omitted","framework":"eu-ai-act","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2024/1689"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-10-f53dd533.json","sourceId":"uc:UC-AI-10","targetDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art50-a9da90b0.json","targetId":"ctrl:eu-ai-act:AIA-Art50","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d30ef7fd2bbb90d2d22640fe778b901d09a3b65df04eb887c2b165df9dec0ab5","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-e006-362f564d.json","sourceId":"ctrl:aiuc-1:E006","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d48739629f27ebf74e1abf8e7ac546403e3835cefc31839403687da5212a0e56","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-apo10-2c3cb0dc.json","sourceId":"ctrl:cobit-2019:APO10","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:da75d8c9c435b8098e7b7df946476f108ce707a0769015d95cddc2f60e660ccb","properties":{"control_id":"AIA-Art21-22","coverage":"partial","delta":"cooperation with competent authorities on request and appointment of an authorised representative for providers established outside the jurisdiction","framework":"eu-ai-act","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2024/1689"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-13-2ce71d80.json","sourceId":"uc:UC-AI-13","targetDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art21-22-eb4ae796.json","targetId":"ctrl:eu-ai-act:AIA-Art21-22","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dadba8095e99ffd7e92198bac506ab1dd4ad19cf0bb742d44e096f3eba524948","properties":{"control_id":"E006","coverage":"partial","delta":"assess foundation and upstream model providers against explicit data-handling, PII-control, security, and compliance criteria, and retain the due-diligence evidence","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-14-cc67739e.json","sourceId":"uc:UC-AI-14","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-e006-362f564d.json","targetId":"ctrl:aiuc-1:E006","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:db5f4ea733e0e68a13d0d5ee1bee8da00daecc29d4afbdbb597aba4a4e159533","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-coso-ic-p9-8a96cb71.json","sourceId":"ctrl:coso-ic:P9","targetDetailPath":"/data/v1/records/std-coso-ic-3f80f565.json","targetId":"std:coso-ic","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dc36b697ee08e8cd25e67f4a055985ad077d734872f6d447b525f2a50133c1cb","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-e001-ec2a2db9.json","sourceId":"ctrl:aiuc-1:E001","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ddfda65f8336bc6775be4832e673415b701ff608b644a5db420ccb847c330e14","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art23-25-05f2196c.json","sourceId":"ctrl:eu-ai-act:AIA-Art23-25","targetDetailPath":"/data/v1/records/std-eu-ai-act-54986689.json","targetId":"std:eu-ai-act","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e038a96012a85371ad6163ae4988cdbf381186e6eb53bddd760aa75bb71d5d01","properties":{"control_id":"AIA-Art20","coverage":"partial","delta":"provider-side corrective action (withdrawal, disabling, recall) of non-conforming systems and information to distributors, deployers, and authorities","framework":"eu-ai-act","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2024/1689"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-11-7112e573.json","sourceId":"uc:UC-AI-11","targetDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art20-ee657bfd.json","targetId":"ctrl:eu-ai-act:AIA-Art20","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e28a72f4b0cd6f80510c81151daed71ede3c024dbdbf8b1557894ebece808997","properties":{"control_id":"Principle 12","coverage":"partial","delta":"engagement-level performance oversight and improvement (Std 12.3) satisfied by the documentation-and-supervision companion control","framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-19-a0f61a19.json","sourceId":"uc:UC-AUDIT-19","targetDetailPath":"/data/v1/records/ctrl-iia-2024-principle-12-ef0f1834.json","targetId":"ctrl:iia-2024:Principle 12","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e78e6d8318dddee9a06047c187236305d89bfc8b8d1dd425132f1ec1ac0247cf","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-coso-erm-e15-7207b4fa.json","sourceId":"ctrl:coso-erm:E15","targetDetailPath":"/data/v1/records/std-coso-erm-7265cc54.json","targetId":"std:coso-erm","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e9ed37a16a9eea24ac6ab97a2867655eac5951640e5418829fc171db5167e1b6","properties":{"control_id":"Std 12.1","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-19-a0f61a19.json","sourceId":"uc:UC-AUDIT-19","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-12-1-5f2fe558.json","targetId":"ctrl:iia-2024:Std 12.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eb2763c24ae0bb6b3625b11233e6e45a9a11273627780a51ee50b96a9c66f2a8","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-apo14-ab650d02.json","sourceId":"ctrl:cobit-2019:APO14","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f28fb81c662abb1546d2c57a369268caa3464e3e177354b5f7aa9d1b65f8836c","properties":{"control_id":"E002","coverage":"partial","delta":"a pre-approved failure plan for harmful outputs with containment, rollback, and customer-notification steps","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-11-7112e573.json","sourceId":"uc:UC-AI-11","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-e002-aa262146.json","targetId":"ctrl:aiuc-1:E002","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f2e2e7b72bc628ac1dc26cf6544d63f62633d9a1276598c3474fe2e52c916f16","properties":{"control_id":"DORA-Art28-44","coverage":"partial","delta":"DORA-specific regulator obligations (register of information format, competent-authority/Lead Overseer interactions) beyond the general third-party program","framework":"dora","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2022/2554"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-dora-dora-art28-44-d3e89c89.json","targetId":"ctrl:dora:DORA-Art28-44","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f3af93bd09f148bca3812d692cfd5d7444b8022fddc026684a5a5e383fb497a5","properties":{"control_id":"E016","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-10-f53dd533.json","sourceId":"uc:UC-AI-10","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-e016-8f16478c.json","targetId":"ctrl:aiuc-1:E016","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f55bf4e1aca81ca451d41d4da594182561ebd78192b68d970d53f115d62848f4","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art16-63a82efa.json","sourceId":"ctrl:eu-ai-act:AIA-Art16","targetDetailPath":"/data/v1/records/std-eu-ai-act-54986689.json","targetId":"std:eu-ai-act","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fa1e03375b19113343f4dead8c7384d2ce6473a62a0177095daa5a8303d69ee2","properties":{"control_id":"APO09","coverage":"partial","delta":"service catalog definition and SLA lifecycle management","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-apo09-2d1f48e2.json","targetId":"ctrl:cobit-2019:APO09","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fe56eb4296e68785198e7c151a8fb322b26fc4012b56da65d167ea60058e3e1f","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art53-fd785909.json","sourceId":"ctrl:eu-ai-act:AIA-Art53","targetDetailPath":"/data/v1/records/std-eu-ai-act-54986689.json","targetId":"std:eu-ai-act","type":"belongs_to"}],"schemaVersion":1,"scope":"topics","total":275}
