Validate your mappings against the Apeiris corpus
Send us your control-to-framework mappings. We validate each one against the open Apeiris corpus and return a private report: which mappings we agree with, which extend our coverage, which look mis-cited, and — the part partners find most useful — what your set is missing.
This is a white-glove pilot: we run the analysis and hand you the report directly. It is an analysis aid, not an audit or certification.
Two kinds of rows, in one file.
Crosswalks
Your own mapping of an Apeiris control to a framework requirement — “we think control X corresponds to Article Y of framework Z.”
Trust-votes
Your assessment of one of our existing mappings — “your mapping of control X to requirement Y should be graded differently.”
You don't need to cover everything — send the subset you care about (a single framework, a domain, or a full set up to ~2,000 rows). Browse control identifiers at Domains & controls or the Knowledge Graph.
CSV or JSON. Start from a template.
Use CSV (easiest from a spreadsheet or GRC export) or JSON. Download a ready-to-edit template:
Crosswalk fields
| Column | Req. | Allowed values / notes |
|---|---|---|
| kind | ✔ | crosswalk |
| control_ref | ✔ | The Apeiris control URI: apeiris://<domain>/controls/<ID> (e.g. apeiris://security/controls/IA-01). |
| framework | ✔ | The framework you're citing (e.g. eu_ai_act, iso_42001, nist_ai_rmf, owasp_aisvs). A name we can resolve is fine. |
| requirement_id | ✔ | The exact clause/article id (e.g. Article 15, A.6.2.2). It must be a real citation — we verify it against the framework's primary text. |
| fit | ✔ | direct · supporting · partial · adjacent |
| relation | — | satisfies (a binding obligation) · equivalent_to (a control in another standard) · defends_against (a threat) · informs (guidance) |
| normative_force | — | binding-law · regulation · supervisory-guidance · certification-standard · voluntary-standard · industry-framework · best-practice · informative-reference |
| mapping_confidence | — | high · medium · low |
| rationale | ✔ | One sentence on why the mapping holds. An unexplained mapping can't be reviewed. |
Trust-vote fields
| Column | Req. | Allowed values / notes |
|---|---|---|
| kind | ✔ | vote |
| mapping_ref | ✔ | The specific Apeiris mapping: apeiris://<domain>/controls/<ID>/frameworks/<framework>/<requirement_id> |
| verdict | ✔ | direct · partial · supporting · adjacent (it holds at that strength) · conflicting (you dispute it) · invalid (the cited id doesn't support it) |
| confidence | ✔ | high · medium · low |
| rationale | ✔ | One sentence on why. |
CSV must be UTF-8; wrap any value containing a comma or quote in double-quotes. Leave optional columns blank if unused. Do not include secrets, credentials, personal data, or client-identifying information in any field — send only the mappings themselves.
Example — crosswalk CSV
kind,control_ref,framework,requirement_id,fit,relation,normative_force,mapping_confidence,rationale crosswalk,apeiris://security/controls/IA-01,eu_ai_act,Article 15,partial,satisfies,binding-law,medium,"Per-agent distinct identity contributes to the Article 15 obligation but does not by itself satisfy it." crosswalk,apeiris://identity/controls/II-01,nist_ai_rmf,GOVERN 1.2,supporting,informs,voluntary-standard,medium,"An agent identity registry supports the accountability structures in GOVERN 1.2."
A private report — a verdict per row, plus a gap pass.
| Verdict | Meaning |
|---|---|
| agrees | The corpus already carries this mapping at the same strength (any fit difference is noted). |
| conflicting | The corpus maps it materially differently — we show both sides. |
| extends-corpus | Your citation checks out and the corpus doesn't have it — you found a gap in our coverage. |
| invalid | The cited requirement id doesn't hold up against the framework's primary text (a likely mis-citation). |
| unverifiable | We haven't yet ingested that framework's primary text, so we can't machine-confirm the citation this round. |
For trust-votes, we report whether your vote agrees with or disputes our mapping. And across your whole set, a “what you're missing” pass: the Apeiris controls, evidence requirements, and framework obligations relevant to what you submitted that your set doesn't yet cover.
Private by default.
Private. Your file and the report stay between us. They are never published, added to a public page, or shared with another party.
The corpus is never edited from your upload. Where your mappings disagree with ours, they become candidate findings we review — your submission never changes the published corpus on its own.
Verify us back. Everything we cite resolves to a public Apeiris control URI you can check yourself, and every published artifact is independently verifiable.
Ready to submit?
Prepare your .csv or .json and send it to your Apeiris contact via the secure channel we set up with you. Not in the pilot yet? Get in touch and we'll arrange a secure drop before you send anything.
The self-serve, authenticated web workspace — upload in the browser, saved reports, your own gap dashboard — is on our roadmap. This page covers the white-glove pilot available today.