Skip to content

Design Adequacy

An approved mapping says a control is intended to address an obligation. Design adequacy asks a harder question: if that control operated exactly as written, would the obligation actually be discharged?


Why it is a separate assessment

A mapping can be approved and still be inadequate by design.

Obligation: "Access to production systems shall be reviewed at least quarterly and revoked promptly on change of role or termination."

Mapped control: "An annual access review is performed for all production systems."

Mapping: approved, relationship subset.

The mapping is correct — the control does address part of the obligation. Design adequacy is where you record that annual is not quarterly, and that role change and termination are not covered at all.

Without this assessment, the gap lives only in the head of whoever approved the mapping.


The flow


The AI check

Running the AI design adequacy check produces a draft recommendation — never an assessment, and never an approved one.

AI doesAI does not
Read the obligation and the mapped controlDecide adequacy
Identify apparent gaps between themSubmit anything
Draft a recommendationApprove anything
Record its provenanceChange any compliance position

Requires adequacy.run and the AI entitlement.

The AI recommends; the human review decision is authoritative

An unsubmitted draft has no governance status. It is a starting point for the person who will own the assessment, and nothing more.


Submission and review

A person edits the draft, submits it (adequacy.submit), and an independent reviewer approves or rejects it (adequacy.review).

The reviewer cannot be the submitter. This is the same maker-checker rule that governs mappings, exceptions, applicability decisions and every other governed judgement in the platform.


What an adequacy assessment produces

An approved assessment records whether the mapping is adequate by design and, where it is not, what is missing.

That output feeds directly into expected evidence: an approved adequacy assessment is the natural source of AI-suggested expected-evidence requirements, because it has already articulated what the control needs to demonstrate.


When to run design adequacy

SituationWorth running?
A newly approved equivalent mapping on a material obligationYes
A subset or intersection mappingYes — the gap is already known; record it properly
Preparing for certification or a regulatory inspectionYes, across the applicable set
A related or no_match mappingNo — there is no design claim to assess
Routinely across thousands of mappingsNo — target it at material obligations

Permissions

ActionPermissionEntitlement
View adequacy assessments and historyadequacy.readcontrol_assurance
Run the AI adequacy checkadequacy.runai_risk_intelligence
Submit a draft for reviewadequacy.submitcontrol_assurance
Approve or reject a submitted assessmentadequacy.reviewcontrol_assurance

Example

Obligation: "The institution shall encrypt personal data at rest using industry-standard algorithms and shall manage encryption keys under dual control."

Mapped control: CTL-2026-0031 — Data at Rest Encryption. "All databases containing personal data are encrypted at rest using AES-256." Mapping approved as subset.

AI draft recommendation: "The control addresses the encryption algorithm requirement. It does not address key management under dual control. No key custody, rotation or dual-control provision is described."

Analyst edit: the analyst confirms the gap and adds that key management is performed by the cloud provider's managed key service, whose dual-control properties are governed under a separate control that is not currently mapped to this obligation.

Review: the Compliance Manager approves the assessment and adds a required action — map CTL-2026-0058 Key Management to the same obligation as supporting.

Outcome: two mappings now address the obligation, and the expected evidence set includes both encryption configuration and key custody attestation.

The AI found the gap. The analyst explained why it existed. The reviewer decided what to do about it. Each did the part they are suited to.


Troubleshooting

"The AI check is unavailable." Requires adequacy.run and the AI entitlement. Manual adequacy assessment does not need AI.

"I cannot review my own assessment." Correct. Segregation of duties applies.

"Adequacy assessment did not change requirement satisfaction." It does not. Adequacy is a judgement about design. Satisfaction depends on evidence, coverage and effectiveness. See Separation Principles.

"The AI draft is wrong." Edit it. It is a draft, and you own the submitted assessment.


OrviQ Enterprise Governance, Risk & Compliance Platform