Skip to content

Working with frameworks

A framework is the standard or regulation you’re working against — ISO 9001 (quality), ISO 14001 (environment), ISO 27001 (information security), GDPR, and more in the catalogue. Regnora maintains each one centrally as its full set of requirements, so you don’t import the standard text or keep it up to date yourself. This guide covers how a framework is structured inside Regnora, how to enable one in a project, and how to request one that isn’t catalogued yet.

Open a framework and you see its requirements laid out as a tree that mirrors the published standard — chapters, sections, articles, paragraphs, annexes, clauses, controls, and so on, nested the way the document itself is. A table of contents alongside the tree lets you jump around a large standard quickly.

This structure is what everything else hangs off: gap analyses assess against these requirements, and the project profile attributes a framework asks for are tied to the same requirements.

Manage: Library frameworks · Enabled in this project

To bring a framework into a project, you enable it. On the project’s Frameworks page, select Add framework, pick the one you want from the list, and select Enable. That creates an adoption — your project’s own instance of that framework, against which you’ll evidence requirements and run gap analyses.

Enabling is about tracking, not access. The assistant, revisions and custom agents can read and search every framework in the library, plus your organisation’s own submitted frameworks, whether or not the project has enabled it — enabling marks the frameworks the project is assessed against and puts them first when you ask about “our frameworks”. Starting a gap analysis against a framework enables it for the project automatically.

Enabling is reversible. You can disable an adoption at any time without losing data, and re-enable it later. Because each adoption is project-scoped, the same framework enabled in two projects stays completely independent — an ISO 27001 adoption for your own ISMS doesn’t get mixed up with one you’re running for a client.

A project can have several frameworks enabled at once — common when one engagement spans, say, ISO 27001 and GDPR. They all assess against the same evidence base in the project. Overlapping requirements aren’t deduplicated; each framework is evaluated on its own terms.

The Framework library is the central catalogue of everything Regnora supports. You enable frameworks for a project from that project’s Frameworks page, but you browse the full set here. It has two tabs:

  • Catalogue — every supported framework, which you can filter (for example, EU, ISO, or Other) and which is grouped into categories like EU regulations and ISO standards.
  • Your submissions — frameworks you’ve requested that aren’t in the catalogue yet, with their current status.

Select one or more frameworks in the Catalogue and choose Read to open them, side by side if you picked several, or Compare to set two against each other. Every framework on screen shows what the library knows about it above its text.

A comparison is available when Regnora has curated one for the pair — either two editions of the same standard (ISO 9001:2015 against ISO 9001:2025) or two different standards crosswalked against each other. It opens on the later framework’s text with the changes redlined over it, and can also be read as a list, side by side, as a heatmap or as a diagram.

Comparisons are built from correspondences: one reviewed link per pair of requirements, each carrying two fields.

  • Relation describes what happened to the requirement: unchanged, editorial (wording only), narrowed (it now covers fewer cases), broadened (more), relocated (same obligation, different place), split (one became several), merged (several became one), added (no counterpart on the earlier side), removed (none on the later side).
  • Materiality is the field that decides whether you have to redo work: none, editorial (the wording moved but your existing evidence still discharges it), or substantive (evidence collected against the earlier requirement may no longer hold).

Only correspondences Regnora has reviewed and accepted are shown. A framework’s clause text is shown only where your organization holds a reading grant for it, since publishers license their text.

Framework comparisons are an experimental feature, enabled per organization by your Regnora contact.

Where a requirement cites another provision — “pursuant to Article 32”, “Directive 95/46/EC” — the citation is a link that opens the cited requirement or framework in the library. Hover over it to preview the cited text. Links stay within Regnora; a citation of something that isn’t in your library is shown as plain text.

The useful questions about a framework are often narrowing ones — “only the substantive changes”, “just clause 8”, “what does it say about competence”, “how do ISO 27001 and GDPR relate on incident reporting”. Select Explore with Assistant while reading to open the Assistant with the frameworks on screen already named in the message; add your question and send it.

The Assistant answers in the conversation and shows what it is talking about in the pane beside it, using the same reader as the library: the comparison narrowed to the slice you asked about, the clauses it cites, or a concept graph of how requirements from different frameworks connect. Ask a follow-up and the pane narrows with it. Every figure in the pane is counted from the rows it shows, so the numbers and the text beside them can never disagree. Links the Assistant draws in a concept graph that no curator has reviewed are shown apart from curated correspondences, and it says so.

You can also ask the Assistant about frameworks from any chat — it recognises the question and brings the pane up on its own.

Requesting a framework that isn’t catalogued

Section titled “Requesting a framework that isn’t catalogued”

If the standard you need isn’t listed, you can submit it from the library. A submission captures the framework’s name, publisher, version, and a description, with optional notes and a file. Submitted frameworks are processed by Regnora before they become enableable — you’ll see them under Your submissions with a processing status until they’re ready. While a submission is still processing it won’t appear in the Add framework picker; it shows up there automatically once its requirements are in place, so there’s nothing to re-submit if you don’t see it right away.

Manage: Library frameworks · Enabled in this project