Controls
Connect every obligation to something the business actually does.
Coverage is not a percentage on a slide. It is a set of named bindings between a requirement, a policy, a control, a process, an owner, and the evidence that proves the control operated.
Regulatory requirements
248
Mapped
211
Partially mapped
24
Unmapped
13
Coverage matrix
Requirement to evidence, in one row.
Coverage matrix · 248 requirements
| Requirement | Policy | Control | Process | Evidence | Coverage |
|---|---|---|---|---|---|
R-1182 Customer data retention | Data Governance Policy | C-2047 Automated retention | Customer offboarding | Retention logs | Partially mapped |
R-0914 Third-party materiality register | Outsourcing Policy | C-1180 Vendor register review | Vendor onboarding | Register export | Mapped |
R-1204 Automated decision transparency | — | — | Credit decisioning | — | Unmapped |
R-0771 Incident notification window | Incident Response Policy | C-3310 Notification workflow | Incident management | Notification records | Mapped |
R-1052 Records of processing purposes | Privacy Policy | C-2051 Purpose register | Data intake | Purpose register | Partially mapped |
R-1233 Model oversight documentation | Model Risk Policy | — | Model approval | — | Unmapped |
Select a row to inspect the binding
Control detail
Traceable, defensible, owned.
Each control view carries the requirement it satisfies, the systems in scope, the evidence collected, and the accountable owner.
Control C-2047
Needs review
Requirement
Customer data retention
Policy
Data Governance Policy
Process
Customer Offboarding
Systems
CRM / Data Warehouse
Evidence
Retention logs
Owner
Data Governance
Status
Needs review
Last attested
18 Jun 2026
Coverage74%
Evidence drill-down
12 sources
- VerifiedRetention log export — CRMCollected 01 Sep 2026
- VerifiedRetention log export — WarehouseCollected 01 Sep 2026
- MissingSupport archive rule setNot configured
- VerifiedPolicy attestation — Data GovernanceSigned 18 Jun 2026
- PartialDeletion job run historyPartial coverage
Request access
Build compliance into the operating layer of the business.
Regulus gives compliance, legal, risk, and operational teams a continuously updated view of how regulatory requirements affect the organization.
- Deployment
- Enterprise, single-tenant
- Stage
- Seed — early enterprise deployments
- Sources monitored
- Regulators, standards, guidance
- Traceability
- Requirement to evidence
Access requestReviewed manually