The Platform

One Project Record. Every Assurance Output.

Risks, controls, evidence, findings, and accreditation outputs in one structured record per engagement. The data stays consistent. The audit trail holds. AI-assisted assurance, human-led decisions.

Security Chat

Control Frameworks. Right There When You Need Them.

Security Chat helps auditors search, interpret, filter, compare, and discuss security controls from supported frameworks and custom catalogues inside AIS. It recognises control IDs, framework names, topic searches, compliance levels, explanation requests, and follow-up questions, so auditors can move from raw control text to practical understanding without leaving the assessment workspace.

  • Look up specific controls by ID, including formats such as AC-2, 16.1.27.C.01, or 5.15
  • Ask for the intention, purpose, rationale, or practical meaning of a control
  • Search controls by topic, such as multi-factor authentication, privileged access, encryption, logging, or incident response
  • Filter controls by framework, chapter, compliance level, or obligation strength where supported
  • AIS supports built-in and custom control frameworks, allowing assessments to align with your organisation's policies, standards, and regulatory requirements.
AIS Security Chat querying NZISM chapter 16 controls
AIS Security Chat querying NZISM chapter 16 controls
Risk Analyser

One Structured Record for the Whole Assessment

Every part of the assessment lives in one project record: context, scope, classification, risks, controls, findings, and evidence. Auditors and reviewers work from the same data. Nothing needs to be copied into a separate document.

  • Controlled workflow status tracks the assessment from start to closure
  • Executive Summary and C&A sections are part of the record and feed directly into exported documents
  • Recertification mode imports prior risks, controls, and findings as a starting point for repeat assessments
AIS Risk Analyser project workspace showing accordion sections and sub-tabs
AIS Risk Analyser project workspace showing accordion sections and sub-tabs
Risk Generator

Start With a Draft, Not a Blank Page

The Risk Generator produces AI-generated risk scenarios from the system context, using the selected control framework and project data already entered. Auditors can review, edit, delete, or add additional risks.

Control Validation

Evidence-Led Control Validation

For each control, auditors record implementation status, supporting evidence, and an effectiveness rating. AIS flags logical inconsistencies before export, for example a control rated Fully Effective that still has open Critical findings.

  • Integrity Check runs before export and surfaces mismatches between control ratings and open findings
  • Suggest Fix proposes a correction for each integrity warning. The auditor decides whether to accept, change, or dismiss it
  • Reviewers can see exactly why a control received its rating, including linked evidence
AIS Integrity Check showing control consistency warnings with AI-suggested fixes
AIS Integrity Check showing control consistency warnings with AI-suggested fixes
Pentest Report Ingest

Bring Penetration Test Results Into the Record

Import third-party penetration test reports (PDF or DOCX) directly into an audit project. AIS extracts candidate technical findings and observations, maps them to the project's control catalogue, and places every candidate in a review queue. Nothing enters the official record without explicit auditor acceptance.

  • AI-assisted extraction of technical findings and observations, capped and schema-validated
  • Built-in prompt-injection screening treats report content as untrusted, and suspicious content is flagged for the auditor
  • Review queue with accept, edit, or reject per candidate. Accepted items become tracked TF findings with retest notes
  • Imported findings flow into the Findings Registry, integrity checks, and reports like any other finding
Evidence Collector

Evidence Arrives by Itself. Auditors Stay in Control.

Evidence providers drop files into a dedicated SharePoint folder per project. AIS detects new files and new versions automatically, and the assigned auditor decides what happens next: AI analysis proposes control mappings with justification and confidence, and only an explicit auditor confirmation imports the file as standard, immutable AIS evidence.

  • SharePoint drop-folder per project, so nobody chases evidence through email threads
  • Vision-capable AI analyses documents, spreadsheets, and diagrams and proposes control mappings. Proposals only, never automatic imports
  • Fail-closed security validation and strict content limits before any file is analysed
  • Imported evidence is an immutable snapshot with full audit events. Later source changes are flagged as new versions for review
Findings Registry

All Findings. One View.

The Findings Registry shows all findings across every project. Filter by system, auditor, exposure, or classification. Track severity, status, owner, due date, and remediation progress. Overdue items and systemic patterns are visible before they become accreditation problems.

  • Each finding links to its source control, associated risk, and remediation plan
  • Ownership, due dates, and status tracked in the same record, with no parallel spreadsheet
  • Add evidence to a finding and let AIS help identify whether it supports the remediation claim, highlights gaps, or needs further review. The auditor remains in control of the final decision
AIS Findings Registry showing cross-project findings with severity, status and owners
AIS Findings Registry showing cross-project findings with severity, status and owners
Attack Path Analysis

Spot Structural Weaknesses

AIS reviews findings for a specific system and helps auditors understand how issues across different security layers may affect the system's real risk position. It highlights related gaps in areas such as access control, identity, monitoring, configuration, resilience, and remediation, helping teams prioritise what to fix first instead of treating every finding in isolation.

Review Gates

No Closure Without Independent Sign-Off

Every audit passes through formal review gates before it can be finalised. At each stage the work moves from in progress to under review, and only advances once an independent reviewer has signed it off.

  • Gate 1: Security Risk Assessment review
  • Gate 2: Control Validation Assessment review
  • Gate 3: Final review before closure
  • The assigned reviewer is notified at each gate, checks the work, and passes the gate to let the audit continue
Audit Flexibility

Per-Audit Control Databases and Risk Matrices

Not every engagement uses the same catalogue or the same risk appetite. Admin-gated feature flags allow a non-default control database to be selected at project creation, and the risk matrix to be tailored per project, without affecting platform-wide defaults.

  • Per-audit control database selection, locked permanently after project creation for a defensible baseline
  • Per-project 5×5 risk matrix overrides, editable while the audit is active and locked at closure
  • Every change is confirmed, attributed, and written to the audit log
Dashboards

Portfolio Visibility for Supervisors and Audit Leads

AIS dashboards turn assessment data into a practical management view for continuous assurance monitoring. Supervisors can see where each project stands, which systems carry the highest risk, which findings are overdue, and which remediation actions need attention before review, accreditation, or certification expiry.

  • Portfolio view of active and closed assessments.
  • Continuous monitoring of risks, findings, remediation status, and assurance progress.
  • Certification and accreditation expiry tracking by system.
  • Risk position by system, project, or assessment.
  • Findings by severity, status, owner, and due date.
  • Management visibility for prioritisation, review readiness, and remediation follow up.
AIS Supervisor Dashboard showing active audits, findings by severity and risk distribution
AIS Supervisor Dashboard showing active audits, findings by severity and risk distribution
Reports & Exports

One Project Record. Multiple Assurance Outputs.

Every report comes from the same project record. No separate templates to maintain, no reformatting between documents. When assessment data changes, it carries through, so senior auditors spend their time on review, not on document preparation.

SRASecurity Risk Assessment
CVPControl Validation Plan
CVAControl Validation Assessment
SRA+CVACombined SRA + CVA
C&ACertification & Accreditation Memo
AI-assisted narrative
ATOAuthority to Operate Memo
AI-assisted narrative
EAEmergency Accreditation Memo
FRPFindings & Remediation Plan
PTSPenetration Testing Scope
AI-assisted narrative
DASHDashboard Report

All documents are produced by a unified block-based export engine. Every report is a composition of the same named sections, so output stays consistent across document types and custom report compositions are supported.

AIS export panel showing SRA, CVA, C&A Memo, ATO Memo and EA Memo options
AIS export panel showing SRA, CVA, C&A Memo, ATO Memo and EA Memo options
Who AIS Is For

AIS Works Across the Whole Team

Junior & Intermediate Auditors

Guided Through What Good Looks Like

AIS gives auditors practical guidance while they work through controls, evidence, and findings. They can ask how to evaluate a control, what evidence may be expected, whether supplied evidence appears sufficient, and what gaps may need further review. Final judgement remains with the auditor.

  • Ask control interpretation questions in context.
  • Get guidance on expected evidence.
  • Review evidence relevance, completeness, and gaps with AI assistance.
  • Improve consistency before formal review.

Senior Auditors & Reviewers

More Time for What Really Matters

AIS surfaces inconsistent ratings, missing evidence, and integrity issues before documents reach the review stage. Senior review time goes to the substance, not to hunting for problems the platform should have caught.

  • Integrity checks, consistency flags, and score cross-checks run before documents reach review
  • One project record feeds all report types, with no template duplication
Who Uses AIS

For Organisations That Run Formal Security Assurance

AIS is for teams where security assurance is a core responsibility, not an occasional exercise.

Government & Public Sector

Government Agencies

AIS supports the NZ government assurance lifecycle across NZISM, PSR, and FISMA-style workflows, with C&A and ATO documentation produced from the same project record as the assessment.

Financial Sector

Banking & Financial Services

Financial institutions need a complete, defensible audit record. AIS documents the evidence behind every control rating, tracks findings ownership and remediation, and supports formal risk governance requirements.

Enterprise

Regulated Enterprises

Enterprise assessment teams running the same assessment type across multiple systems often produce inconsistent results. AIS provides a single structured record per engagement and portfolio visibility across business units.

Consulting

Security Consulting Firms

AIS standardises the assessment methodology across clients, produces all report types from one project record, and reduces the time senior consultants spend on formatting.

See It on Your Frameworks

A 30-minute walkthrough tailored to your sector and the assessments your team runs.