Regulatory mapping

Linking each regulatory obligation to the entities, processes, policies and controls that discharge it, so coverage and gaps become visible.

Regulatory mapping is the practice of linking each regulatory obligation to the parts of the organization it affects and to the policies, processes and controls that discharge it. The result answers two audit questions at once: for any rule, what do we do about it, and for any control, which obligations does it exist to meet? ISO 37301:2021 clause 4.5 asks organizations to identify their compliance obligations and assess their impact on operations; mapping is how that assessment is recorded in a form someone can test.

A mapping usually runs in layers. Obligations are extracted from the source text at clause level and recorded in an obligations register. Each obligation is linked to the legal entities, business lines, products and jurisdictions it applies to, then to the owning function, and finally to the policy sections and control IDs that satisfy it. An obligation with no mapped control is an open gap; a control with no mapped obligation may be redundant or undocumented.

The term has a second, related meaning: crosswalks between frameworks, showing how one regulation's requirements correspond to another standard's controls. NIST's National Online Informative References (OLIR) Program is a public example, publishing standardized relationships between elements of NIST frameworks and other documents. Framework crosswalks save effort when several regimes ask for similar controls, but they do not replace mapping each obligation to the controls a specific organization actually runs.

Maps decay when rules change. Each new or amended obligation that comes out of regulatory change management should trigger a check of its mappings, and a regulatory change impact assessment is where that check is documented. Mapping is also where the cost of compliance becomes visible: a regulation such as DORA breaks into dozens of obligation rows, each needing an owner and a control.

The mapped-controls field of our regulatory obligations register template is regulatory mapping in table form.

This entry is general information, not legal advice.

Sources

  1. ISO 37301:2021 Compliance management systems accessed 30 Sep 2026
  2. NIST, National Online Informative References (OLIR) Program accessed 30 Sep 2026

Know which changes apply to your business.

RegWatch reads the regulators you choose and explains every change it surfaces.

Book a demo