Appearance
Design Adequacy
An approved mapping says a control is intended to address an obligation. Design adequacy asks a harder question: if that control operated exactly as written, would the obligation actually be discharged?
Why it is a separate assessment
A mapping can be approved and still be inadequate by design.
Obligation: "Access to production systems shall be reviewed at least quarterly and revoked promptly on change of role or termination."
Mapped control: "An annual access review is performed for all production systems."
Mapping: approved, relationship
subset.
The mapping is correct — the control does address part of the obligation. Design adequacy is where you record that annual is not quarterly, and that role change and termination are not covered at all.
Without this assessment, the gap lives only in the head of whoever approved the mapping.
The flow
The AI check
Running the AI design adequacy check produces a draft recommendation — never an assessment, and never an approved one.
| AI does | AI does not |
|---|---|
| Read the obligation and the mapped control | Decide adequacy |
| Identify apparent gaps between them | Submit anything |
| Draft a recommendation | Approve anything |
| Record its provenance | Change any compliance position |
Requires adequacy.run and the AI entitlement.
The AI recommends; the human review decision is authoritative
An unsubmitted draft has no governance status. It is a starting point for the person who will own the assessment, and nothing more.
Submission and review
A person edits the draft, submits it (adequacy.submit), and an independent reviewer approves or rejects it (adequacy.review).
The reviewer cannot be the submitter. This is the same maker-checker rule that governs mappings, exceptions, applicability decisions and every other governed judgement in the platform.
What an adequacy assessment produces
An approved assessment records whether the mapping is adequate by design and, where it is not, what is missing.
That output feeds directly into expected evidence: an approved adequacy assessment is the natural source of AI-suggested expected-evidence requirements, because it has already articulated what the control needs to demonstrate.
When to run design adequacy
| Situation | Worth running? |
|---|---|
A newly approved equivalent mapping on a material obligation | Yes |
A subset or intersection mapping | Yes — the gap is already known; record it properly |
| Preparing for certification or a regulatory inspection | Yes, across the applicable set |
A related or no_match mapping | No — there is no design claim to assess |
| Routinely across thousands of mappings | No — target it at material obligations |
Permissions
| Action | Permission | Entitlement |
|---|---|---|
| View adequacy assessments and history | adequacy.read | control_assurance |
| Run the AI adequacy check | adequacy.run | ai_risk_intelligence |
| Submit a draft for review | adequacy.submit | control_assurance |
| Approve or reject a submitted assessment | adequacy.review | control_assurance |
Example
Obligation: "The institution shall encrypt personal data at rest using industry-standard algorithms and shall manage encryption keys under dual control."
Mapped control: CTL-2026-0031 — Data at Rest Encryption. "All databases containing personal data are encrypted at rest using AES-256." Mapping approved as subset.
AI draft recommendation: "The control addresses the encryption algorithm requirement. It does not address key management under dual control. No key custody, rotation or dual-control provision is described."
Analyst edit: the analyst confirms the gap and adds that key management is performed by the cloud provider's managed key service, whose dual-control properties are governed under a separate control that is not currently mapped to this obligation.
Review: the Compliance Manager approves the assessment and adds a required action — map CTL-2026-0058 Key Management to the same obligation as supporting.
Outcome: two mappings now address the obligation, and the expected evidence set includes both encryption configuration and key custody attestation.
The AI found the gap. The analyst explained why it existed. The reviewer decided what to do about it. Each did the part they are suited to.
Troubleshooting
"The AI check is unavailable." Requires adequacy.run and the AI entitlement. Manual adequacy assessment does not need AI.
"I cannot review my own assessment." Correct. Segregation of duties applies.
"Adequacy assessment did not change requirement satisfaction." It does not. Adequacy is a judgement about design. Satisfaction depends on evidence, coverage and effectiveness. See Separation Principles.
"The AI draft is wrong." Edit it. It is a draft, and you own the submitted assessment.