Custom Control Mapping Agent is now available for all

SEPTEMBER 02, 2026

Drata AICompliance AutomationEnterprise GRC

Why it matters

Custom controls are often central to a compliance program, especially for organizations managing proprietary requirements, multiple frameworks, or controls outside Drata’s native library. Mapping those controls to the rest of the program has historically required a significant amount of manual review.

A GRC practitioner may need to understand each control’s purpose and scope, then determine which framework requirements, monitoring tests, evidence, policies, and risks it should connect to. That work becomes difficult to complete consistently when a program includes hundreds of controls.

Custom Control Mapping Agent helps teams get started faster. The Agent analyzes custom controls and recommends relevant GRC object mappings. Teams can review the suggestions, validate whether they support each control, and decide which mappings to apply.

This helps compliance teams spend less time on repetitive matching work and more time improving coverage, closing gaps, and preparing their programs for audits.

What’s new

  • Import brand-new custom controls in bulk through CSV or add them individually from the AI Recommendations experience.
  • Select existing custom controls and start an AI-assisted object mapping analysis for those controls.
  • Receive recommendations for relevant framework requirements, monitoring tests, evidence, policies, and risks.
  • Review recommendations in a centralized workspace with the custom control details, suggested object, confidence level, and rationale.
  • Use the rationale to understand the DCF control similarity that informed each recommendation.
  • Open a suggested GRC object to validate its purpose, scope, and coverage before taking action.
  • Map recommendations individually, map all recommendations for a custom control when appropriate, or dismiss recommendations that are not relevant.
  • Search and filter recommendations so teams can work through large control sets at their own pace.
  • See accepted mappings reflected on the corresponding object pages and the custom control’s details immediately.

How it works

From the Recommendations page, choose Controls and import or create custom controls. Submitting the import automatically generates recommendations for those controls.

You can also select existing custom controls from Compliance > Controls and choose Recommend Objects to start the mapping workflow for a subset of controls.

Once the analysis is complete:

  • Open Recommendations > Controls to review the suggestions.
  • Compare each recommendation with the control’s purpose, scope, and expected outcome.
  • Select Map or Dismiss for individual recommendations.
  • Select Map all when all recommendations for a control are relevant.

Callouts and notes

  • Recommendations help teams start their review faster, but they do not replace compliance judgment. Validate each suggestion before accepting it.
  • Custom Control Mapping Agent does not map a custom control to a DCF or convert a custom control into a DCF. It recommends downstream GRC objects, with related DCF similarity shown as part of the rationale.
  • Selecting Map is the only way to apply a recommendation to the live compliance program. Nothing is auto-approved on your behalf.
  • The feature respects AI enablement and existing role-based access controls. Users only see and action the recommendation types they are permitted to access.

Get started

Read the AI-Assisted Custom Control Mapping to GRC Objects guide to learn how to import or select custom controls, review recommendations, and apply mappings.


Chart Your Course

Navigate to new worlds of trust with Drata.