Mapping & Derivation Methodology

CIAO COMMONS — METHODOLOGY
C-AO/STD/MDM/001:2026 PUBLIC
Mapping & Derivation Methodology
The Four-Layer Harmonisation Method — From Standards Portfolio to Living Alignment
Date Issued  11 June 2026
Review Date  11 June 2027
Cite as: CIAO Standard. (2026). Mapping & Derivation Methodology. v1.0. C-AO/STD/MDM/001:2026. www.c-ao.com
🟢 Commons — Public

1. Purpose & Position

This document is the canonical reader-facing statement of the harmonisation method behind the CIAO Standard. The Constitution declares that CIAO operates as an architectural layer above existing standards, laws, and frameworks; this page explains how that layer is made. The method proceeds in four layers, each feeding the next: your organisation’s standards portfolio (Layer 1), clause-level mapping (Layer 2), harmonisation (Layer 3), and the learning engine that deepens with every standard onboarded (Layer 4).

The method is proprietary intellectual property of the CIAO Standard’s corporate steward (patent pending). What follows describes what the method does and how its outputs reach you as a member; the implementing mechanism of Layer 4 is proprietary and is not published.

2. Layer 1 — Your Standards Portfolio

Every organisation is bound by its own set of source standards — jurisdictional, industry, contractual, and voluntary. You select your applicable standards on your member profile, and CIAO content aligns to that portfolio through the Dynamic Selection Engine. You remain in control: your portfolio is yours to amend at any time. A forthcoming Pre-Selection Questionnaire will help you arrive at your portfolio by considering both the standards imposed on your organisation directly and those that reach you through your suppliers, customers, and regulators. A periodic reassessment cycle will prompt you to revisit the portfolio as your organisation and its threat landscape evolve.

3. Layer 2 — Clause-Level Mapping

All standards and laws decompose into clauses under sections. CIAO maps at the clause level, in two directions. Forward: for each CIAO policy, the editorial process identifies the relevant clauses of each registered source standard and attributes every policy statement to its sources. Reverse: for each source standard, the editorial process verifies that every clause the standard expects is covered somewhere in the CIAO policy body, so that gaps are found and closed. The reverse check repeats at every editorial change and whenever a source standard issues a new version.

4. Layer 3 — Harmonisation

Where clauses from different standards pursue the same control objective, CIAO harmonises them: the strictest common position is written as a single coherent CIAO statement, and reference chips attribute that statement to every source standard that converges on it. Where one standard carries a unique constraint beyond the harmonised position, that constraint remains visible as its own statement, attributed to its specific source — it is never dissolved into the harmonised text. Every harmonisation decision is recorded with its rationale, creating an auditable editorial trail. You see one clear sentence; the chips show you which of your standards stand behind it.

5. Layer 4 — The Learning Engine

Beneath the harmonised text sits the deepest layer of the method: the engine learns from each onboarded standard. Every harmonisation decision enriches an underlying proprietary structure, and that enrichment compounds — each new standard onboards faster and maps more completely than the last, because the method has already learned the territory it covers. This is what makes CIAO a living standard rather than a static mapping: the more the Standard engages, the deeper its alignment becomes. The implementing mechanism of this layer is proprietary intellectual property (patent pending) and is not published; its outputs reach you through the harmonised statements, the reference chips, and the Dynamic Selection Engine.

6. Source-Text Discipline

CIAO never reproduces the text of any source standard. Mappings are expressed as clause references only; you consult your organisation’s own authorised copy of each standard for the clause text. What an operating system is to the applications that run on it — interoperability above the licensed parts, never duplication of them — the CIAO Standard is to its source standards. This discipline is declared in the Constitution and governs every page of CIAO content.

7. Method Governance

Validity is non-negotiable: where a CIAO statement maps directly to a registered source standard, the mapping reflects what the standard requires. Editorial deliberation concerns positioning — which CIAO policy hosts a statement, and whether overlapping policies should consolidate — and is reviewed by the Panel of Advisors. When a source standard issues a new version, a cross-reference integrity gate re-examines every affected mapping, repeats the reverse check, and revisits harmonisation where the new edition has materially shifted. The Canonical Source Standards Register defines which source standards the method may engage.

● LIVE CONTENT  ·  Verified 19 June 2026 at 08:19 UTC  ·  Version 1.0  ·  Always current at c-ao.com  ·  © CIAO Standard Secretariat 2026