One Project Record. Every Assurance Output.
Risks, controls, evidence, findings, and accreditation outputs in one structured record per engagement. The data stays consistent. The audit trail holds. AI-assisted assurance, human-led decisions.
Control Frameworks. Right There When You Need Them.
Security Chat helps auditors search, interpret, filter, compare, and discuss security controls from supported frameworks and custom catalogues inside AIS. It recognises control IDs, framework names, topic searches, compliance levels, explanation requests, and follow-up questions, so auditors can move from raw control text to practical understanding without leaving the assessment workspace.
- Look up specific controls by ID, including formats such as AC-2, 16.1.27.C.01, or 5.15
- Ask for the intention, purpose, rationale, or practical meaning of a control
- Search controls by topic, such as multi-factor authentication, privileged access, encryption, logging, or incident response
- Filter controls by framework, chapter, compliance level, or obligation strength where supported
- AIS supports built-in and custom control frameworks, allowing assessments to align with your organisation's policies, standards, and regulatory requirements.
One Structured Record for the Whole Assessment
Every part of the assessment lives in one project record: context, scope, classification, risks, controls, findings, and evidence. Auditors and reviewers work from the same data. Nothing needs to be copied into a separate document.
- Controlled workflow status tracks the assessment from start to closure
- Executive Summary and C&A sections are part of the record and feed directly into exported documents
- Recertification mode imports prior risks, controls, and findings as a starting point for repeat assessments
Evidence-Led Control Validation
For each control, auditors record implementation status, supporting evidence, and an effectiveness rating. AIS flags logical inconsistencies before export, for example a control rated Fully Effective that still has open Critical findings.
- Integrity Check runs before export and surfaces mismatches between control ratings and open findings
- Suggest Fix proposes a correction for each integrity warning. The auditor decides whether to accept, change, or dismiss it
- Reviewers can see exactly why a control received its rating, including linked evidence
Bring Penetration Test Results Into the Record
Import third-party penetration test reports (PDF or DOCX) directly into an audit project. AIS extracts candidate technical findings and observations, maps them to the project's control catalogue, and places every candidate in a review queue. Nothing enters the official record without explicit auditor acceptance.
- AI-assisted extraction of technical findings and observations, capped and schema-validated
- Built-in prompt-injection screening treats report content as untrusted, and suspicious content is flagged for the auditor
- Review queue with accept, edit, or reject per candidate. Accepted items become tracked TF findings with retest notes
- Imported findings flow into the Findings Registry, integrity checks, and reports like any other finding
Evidence Arrives by Itself. Auditors Stay in Control.
Evidence providers drop files into a dedicated SharePoint folder per project. AIS detects new files and new versions automatically, and the assigned auditor decides what happens next: AI analysis proposes control mappings with justification and confidence, and only an explicit auditor confirmation imports the file as standard, immutable AIS evidence.
- SharePoint drop-folder per project, so nobody chases evidence through email threads
- Vision-capable AI analyses documents, spreadsheets, and diagrams and proposes control mappings. Proposals only, never automatic imports
- Fail-closed security validation and strict content limits before any file is analysed
- Imported evidence is an immutable snapshot with full audit events. Later source changes are flagged as new versions for review
All Findings. One View.
The Findings Registry shows all findings across every project. Filter by system, auditor, exposure, or classification. Track severity, status, owner, due date, and remediation progress. Overdue items and systemic patterns are visible before they become accreditation problems.
- Each finding links to its source control, associated risk, and remediation plan
- Ownership, due dates, and status tracked in the same record, with no parallel spreadsheet
- Add evidence to a finding and let AIS help identify whether it supports the remediation claim, highlights gaps, or needs further review. The auditor remains in control of the final decision
Spot Structural Weaknesses
AIS reviews findings for a specific system and helps auditors understand how issues across different security layers may affect the system's real risk position. It highlights related gaps in areas such as access control, identity, monitoring, configuration, resilience, and remediation, helping teams prioritise what to fix first instead of treating every finding in isolation.
No Closure Without Independent Sign-Off
Every audit passes through formal review gates before it can be finalised. At each stage the work moves from in progress to under review, and only advances once an independent reviewer has signed it off.
- Gate 1: Security Risk Assessment review
- Gate 2: Control Validation Assessment review
- Gate 3: Final review before closure
- The assigned reviewer is notified at each gate, checks the work, and passes the gate to let the audit continue
Per-Audit Control Databases and Risk Matrices
Not every engagement uses the same catalogue or the same risk appetite. Admin-gated feature flags allow a non-default control database to be selected at project creation, and the risk matrix to be tailored per project, without affecting platform-wide defaults.
- Per-audit control database selection, locked permanently after project creation for a defensible baseline
- Per-project 5×5 risk matrix overrides, editable while the audit is active and locked at closure
- Every change is confirmed, attributed, and written to the audit log
Portfolio Visibility for Supervisors and Audit Leads
AIS dashboards turn assessment data into a practical management view for continuous assurance monitoring. Supervisors can see where each project stands, which systems carry the highest risk, which findings are overdue, and which remediation actions need attention before review, accreditation, or certification expiry.
- Portfolio view of active and closed assessments.
- Continuous monitoring of risks, findings, remediation status, and assurance progress.
- Certification and accreditation expiry tracking by system.
- Risk position by system, project, or assessment.
- Findings by severity, status, owner, and due date.
- Management visibility for prioritisation, review readiness, and remediation follow up.
One Project Record. Multiple Assurance Outputs.
Every report comes from the same project record. No separate templates to maintain, no reformatting between documents. When assessment data changes, it carries through, so senior auditors spend their time on review, not on document preparation.
All documents are produced by a unified block-based export engine. Every report is a composition of the same named sections, so output stays consistent across document types and custom report compositions are supported.
AIS Works Across the Whole Team
Junior & Intermediate Auditors
Guided Through What Good Looks Like
AIS gives auditors practical guidance while they work through controls, evidence, and findings. They can ask how to evaluate a control, what evidence may be expected, whether supplied evidence appears sufficient, and what gaps may need further review. Final judgement remains with the auditor.
- Ask control interpretation questions in context.
- Get guidance on expected evidence.
- Review evidence relevance, completeness, and gaps with AI assistance.
- Improve consistency before formal review.
Senior Auditors & Reviewers
More Time for What Really Matters
AIS surfaces inconsistent ratings, missing evidence, and integrity issues before documents reach the review stage. Senior review time goes to the substance, not to hunting for problems the platform should have caught.
- Integrity checks, consistency flags, and score cross-checks run before documents reach review
- One project record feeds all report types, with no template duplication
For Organisations That Run Formal Security Assurance
AIS is for teams where security assurance is a core responsibility, not an occasional exercise.
Government & Public Sector
Government Agencies
AIS supports the NZ government assurance lifecycle across NZISM, PSR, and FISMA-style workflows, with C&A and ATO documentation produced from the same project record as the assessment.
Financial Sector
Banking & Financial Services
Financial institutions need a complete, defensible audit record. AIS documents the evidence behind every control rating, tracks findings ownership and remediation, and supports formal risk governance requirements.
Enterprise
Regulated Enterprises
Enterprise assessment teams running the same assessment type across multiple systems often produce inconsistent results. AIS provides a single structured record per engagement and portfolio visibility across business units.
Consulting
Security Consulting Firms
AIS standardises the assessment methodology across clients, produces all report types from one project record, and reduces the time senior consultants spend on formatting.
See It on Your Frameworks
A 30-minute walkthrough tailored to your sector and the assessments your team runs.





