Diwo
Provenance · Custom control matrix

Bring your own control matrix.

You built your own controls in a spreadsheet? Import them as-is. Provenance evidences your matrix against your live estate — control by control.
Your framework gets proven, not ours — and each control maps to the standards your auditor reads: NIST AI RMF, ISO 42001, the EU AI Act.
Control registerIMPORTED · your matrix
SUP-03Hallucinated depsevidenced
SCM-02Review disciplineevidenced
AGT-04Agent authoritypartial
GOV-01Governance reviewattested
The fit

“We built our own” isn’t an objection — it’s the fit.

The most governed teams already keep a controls spreadsheet. Provenance doesn’t ask them to abandon it — it turns that spreadsheet into live, evidenced governance in three steps.

01

Import your matrix

Upload the Excel control register your team already maintains. Provenance parses every control and stores it as your own framework — no re-keying.

02

Evaluate against the estate

Each control runs a deterministic binding over observed facts — authorship, reviews, dependencies, agent configs — and returns evidenced, partial, or flagged.

03

Prove it, sealed

Flags, evidence, and human attestations render into one framework-mapped report — sealed, timestamped, and verifiable on any date.

A worked example

Follow one control, end to end.

One row from your spreadsheet — imported as-is, evidenced against your live estate, then frozen into the sealed report.

① Imported · your Excel
Control
Description · frameworks
SCM-02
Human review on AI-authored mergesNIST PW.7 · ISO A.6

Your row, exactly as it sits in the spreadsheet your team maintains.

② Evidenced · from your estate
SCM-02partial

22 of 25 AI-PRs to Tier-1 repos had a recorded human review — 3 did not.

NIST PW.7 · ISO A.6 · derived

Evaluated against the live estate — an observed fact, not a claim.

③ Sealed · in the report
AI-Code Risk Briefing
SCM-02included
sha256 sealed · verified

Frozen into the framework-mapped report — verifiable on any date.

The honesty gate

Derived from your estate — not declared on a form.

A questionnaire records what someone said. Provenance records what actually happened. The overlay is computed per request from observed facts and never persisted as a claim — and a manual “evidenced” with no evidence behind it is rejected. Where a control needs a human, the attestation is a dated, signed decision — evidence of the sign-off, not a ticked box.

Declared

“Yes, we review AI-authored changes.” — a box ticked in a spreadsheet, unverifiable months later.

Derived

“25 AI-authored PRs merged to Tier-1 repos with a recorded human review; 3 without — here they are.” — observed from the estate, reproducible on any date.

One decision, every framework

Maps to the standards your auditor reads.

Each control in your matrix carries a crosswalk, so one recorded decision shows where it counts across frameworks — no re-work per standard.

Evaluated built-in

EU AI Act and NIST AI RMF — status derived directly from your estate.

Mapped (crosswalk)

ISO 42001, NIST SSDF, OWASP, CIS — one decision, shown where it counts. “Maps to,” never “certifies.”

Frequently asked

The questions teams ask.

What is a custom control matrix?

It's the set of controls your organization is actually measured against — often a spreadsheet your security, risk, or audit team already maintains. Instead of forcing you onto a vendor's fixed framework, Provenance lets you import that matrix as-is and treats each of your controls as a first-class governance object it can evidence against your estate.

How do I import my controls?

Upload your control register as an Excel workbook. Provenance parses each control — its id, name, description, and any framework mappings you've already recorded — and stores it as your tenant's own framework. Re-importing updates in place, so your matrix stays the source of truth as it evolves. No re-keying, no forcing your controls into someone else's taxonomy.

Does Provenance use an LLM to decide whether a control passes?

No. Each control is bound to a deterministic evaluator that reads observed facts from your estate — authorship, review records, dependency manifests, agent-config files — and returns a status (evidenced, partial, awaiting scope, flagged). This is 'evidence then report,' the opposite of a 'classify then derive' approach that asks a model to judge compliance. Deterministic bindings mean the same estate produces the same verdict every time.

Can I just mark a control as 'evidenced' myself?

Not silently — that's the honesty gate. Provenance will reject a manual 'evidenced' status that isn't backed by observed evidence; the estate overlay is computed per request and never persisted as a claim. Where a control genuinely needs human sign-off (a policy attestation, for example), that attestation is recorded as an explicit, dated human decision with a note — evidence of the sign-off, not a box someone quietly ticked.

Which frameworks does it map to — and which does it evaluate?

Provenance evaluates two frameworks built in — the EU AI Act and NIST AI RMF — meaning it derives their status from your estate directly. For other standards (ISO/IEC 42001, NIST SSDF, OWASP, CIS), each control carries a crosswalk mapping so one recorded decision shows where it counts across the standards your auditor reads. The distinction is deliberate and honest: 'evaluated' for the two packs, 'maps to' for the crosswalk — never 'certified.'

Has anyone actually run this on a real matrix?

Yes. We imported a real enterprise security-controls matrix (an Excel workbook) and evidenced it, control by control, against a live multi-repository estate — flags, evidence, and attestations rendered into a single sealed, framework-mapped report. Re-import updates the register in place; the report can be re-generated and its seal verified at any time.

See it on your estate

See your evidence this afternoon.

Connect your first repo in minutes — read-only, no credit card, no sales call. Your Provenance Score, your blind spots, and your first board-ready briefing, from your own estate.