Appearance
Crosswalk Import
Where to find it: Controls & Assurance, then Control Crosswalk (/crosswalk), then Import.
Crosswalk Import brings an externally prepared mapping dataset into OrviQ. It is how you load a common controls framework crosswalk, a regulator-published mapping, a consultant's deliverable, or a mapping set migrated from a previous platform.
What import is
Import takes a prepared dataset of obligation-to-control relationships and creates a corresponding mapping record for each row.
Every imported mapping enters as proposed.
Import is not automatic compliance, and cannot be
An import creates proposals. It does not:
- Approve anything
- Change any compliance position
- Create evidence
- Assert that the mapped controls exist in your organisation, operate, or work
An imported dataset of 3,000 rows produces 3,000 items awaiting review. Reviewing them is the work; importing them is the file handling.
This is the single most important thing to understand about the feature, and the reason it is safe to offer at all. A platform where import could write approved mappings would let a spreadsheet declare an organisation compliant with a standard.
Import versus AI suggestion
These are different mechanisms and are frequently confused.
| Crosswalk Import | AI Mapping Suggestion | |
|---|---|---|
| Input | A prepared external dataset | Your control register plus an obligation |
| Produced by | An external party or catalogue | An AI comparison pass over your own controls |
| Mapping source | imported, curated, scf, regulator, framework_crosswalk | ai_suggested |
| Provenance recorded | Source catalogue and version | AI provider, model, prompt version, confidence |
| Entry status | proposed | proposed |
| Permission | mapping.import | mapping.ai_propose plus the AI entitlement |
Both produce proposals. Both require independent approval. See AI Mapping Suggestions.
There is no autonomous discovery scanner
OrviQ does not run a continuous background process that discovers and creates mappings on its own. Mappings enter through a person, an import, or an explicitly triggered AI proposal run. If you have seen that capability described elsewhere, it is not what this platform does.
When to import
| Situation | Import is a good fit |
|---|---|
| Adopting a second framework that overlaps a first | Yes — a framework-to-framework crosswalk saves substantial analysis |
| Loading a common controls framework baseline | Yes |
| Migrating mappings from a previous platform | Yes |
| Loading a regulator-published mapping | Yes |
| Your own controls mapped by your own team | No — propose them in the application, where the rationale is captured naturally |
How to import
- Prepare the dataset. Each row needs the source obligation, the target control, and ideally the relationship type and a rationale.
- Confirm the identifiers resolve. Rows referencing obligations or controls that do not exist in your tenant cannot be mapped.
- Open the Control Crosswalk and select Import.
- Provide the mapping source and source version. This is your provenance record — "curated catalogue v2.4, imported March 2026" is worth writing.
- Run the import. Rows become
proposedmappings. - Review. This is the substantive step.
Requires mapping.import.
Reviewing an import well
A large import is a review workload, and reviewing it badly is worse than not importing at all — it produces a register full of approved mappings nobody examined.
Prioritise by obligation, not by row. Group the proposals by the obligation they address and review each obligation's full mapping set together. You cannot judge whether a mapping is subset without seeing what else is mapped alongside it.
Check the relationship type first. Catalogue crosswalks are frequently generous, marking as equivalent relationships that are honestly subset or intersection. Adjusting these on review is the highest-value thing a reviewer does.
Check the control is really yours. A catalogue row may map to a reference control that resembles one of yours but is not the same thing. Origin classification helps here — see Control Register.
Add rationale. Imported rows often carry only a source reference. Writing why the relationship holds is what turns a catalogue claim into your organisation's assertion.
Reject freely. A rejected import row is not a failure. It is a recorded conclusion that the external dataset did not fit your organisation, which is exactly what independent review is for.
Do not bulk-approve. If the volume makes review infeasible, import a subset. An unreviewed backlog of proposals is honest; a bulk-approved crosswalk nobody read is not.
Permissions
| Action | Permission |
|---|---|
| Import crosswalk mappings | mapping.import |
| Review and approve imported proposals | mapping.review |
| Export crosswalk datasets | mapping.export |
Example
A bank adopting a second information security framework already holds an approved crosswalk for its first.
It imports a published framework-to-framework crosswalk: 1,204 rows, mapping source framework_crosswalk, source version recorded.
Review over six weeks, by two analysts and one approver:
| Outcome | Count | Notes |
|---|---|---|
| Approved as imported | 612 | Relationship type and target both sound |
| Approved after adjustment | 341 | Mostly equivalent reduced to subset or intersection |
| Rejected | 187 | Mapped to reference controls the bank does not operate |
Recorded as no_match | 64 | Plausible-looking but not addressing the objective |
Outcome: 953 approved mappings for six weeks of review, against an estimated four to five months to build the same crosswalk from scratch — and 341 of them carry a more honest relationship type than the published catalogue asserted.
That last number is the argument for review. The import saved months. The review is what made the result true.
Troubleshooting
"Rows failed to import." The obligation or control identifier did not resolve in your tenant. Load the framework and the controls first.
"Import created nothing for some rows." An active mapping already exists for that obligation and control pair. Adjust the existing mapping rather than importing a second.
"Imported mappings are not in the Statement of Applicability." They are proposed. Only approved mappings appear.
"The import is enormous and review will take months." Import in slices — one framework domain at a time, or the obligations you are actually assessing this cycle. Proposals awaiting review are visible in the crosswalk statistics, so an outstanding backlog is never invisible.
"Import is unavailable." Requires mapping.import and the control_assurance entitlement.