Graphletter Logo
    Graphletter
    TryGitHub (opens in new tab)

    Research

    Open questions and active work in automated compliance analysis. These research directions inform the system's development and represent areas where the approach is still evolving.

    Control Graph Modeling

    Active

    Modeling relationships between SCF controls, assessment objectives, and cross-framework mappings as a navigable graph structure.

    • SCF 2026.1.1 normalization across 79+ frameworks.
    • Hierarchical domain → control → objective → evidence relationships.
    • Cross-framework traceability — one evidence base, many framework views.
    • Graph-based gap propagation: a gap on one control surfaces across every framework it maps to.

    Evidence Confidence Scoring

    Active

    Developing reliable confidence metrics for LLM-based evidence assessment against compliance controls.

    • Per-objective confidence as a 0.0–1.0 score, bucketed into low / medium / high for display.
    • Low model temperatures (0.1–0.2) to keep assessments consistent across runs.
    • Open question: how well does model-reported confidence track human-auditor agreement?

    Cross-Framework Mapping Accuracy

    Planned

    Measuring and improving the accuracy of automated control mappings between regulatory frameworks.

    • SCF provides curated mappings; evaluating completeness and correctness.
    • Identifying mapping gaps where SCF coverage is thin.
    • Comparing AI-generated mappings against SCF reference mappings.
    • Framework version tracking and mapping drift detection.

    Continuous Monitoring

    Planned

    Moving from point-in-time assessment to continuous compliance posture tracking.

    • Evidence expiry and re-assessment triggers.
    • Detecting when framework updates invalidate prior assessments.
    • Integration points for automated evidence collection.
    • Compliance drift scoring over time.

    Want to discuss?

    Open an issue or a discussion on GitHub — we're happy to compare notes on compliance automation.

    Open a discussion
    Graphletter · MIT-licensed · © 2026
    FrameworksResearchPrivacyTermsSecurityGitHub (opens in new tab)