One Platform for Risk Assessment,
Control Validation, and Accreditation
AIS manages risk assessments, control validation, findings, evidence, and certification & accreditation outputs in one structured project record.
Designed for
One Project Record. Every Assurance Output.
Most assessment teams work across spreadsheets, Word templates, and email threads, producing a different set of documents each time. AIS consolidates risks, controls, findings, evidence, and accreditation outputs into one structured project record per engagement. The data stays consistent. The audit trail holds.
Security Chat
Query and consult NZISM, NIST SP 800-53, ISO 27002, PSR, Privacy Act IPPs, and custom catalogues directly from the platform.
Risk Analyser
The core audit workspace — context, scope, risks, controls, findings, and evidence in one project record.
Risk Generator
AI-generated draft risk scenarios from project context and selected frameworks. Every draft is auditor-reviewed before entering the record.
Control Validation
Record implementation status and evidence per control. Integrity checks flag inconsistencies before export.
Findings Registry
All findings across every project in one view — ownership, status, due dates, and remediation progress.
Attack Path Analysis
Highlights possible relationships between findings, control gaps, and exposure to support senior auditor review.
Dashboards
Current view of audit completion, findings by severity, and risk positions across the portfolio.
Reports & Exports
SRA, CVA, C&A Memo, ATO Memo, EA Memo, and Findings Plans — all from the same assessment data.
Control Frameworks. Right There When You Need Them.
Security Chat helps auditors search, interpret, filter, compare, and discuss security controls from supported frameworks and custom catalogues inside AIS. It recognises control IDs, framework names, topic searches, compliance levels, explanation requests, and follow-up questions, so auditors can move from raw control text to practical understanding without leaving the assessment workspace.
- Look up specific controls by ID, including formats such as AC-2, 16.1.27.C.01, or 5.15
- Ask for the intention, purpose, rationale, or practical meaning of a control
- Search controls by topic, such as multi-factor authentication, privileged access, encryption, logging, or incident response
- Filter controls by framework, chapter, compliance level, or obligation strength where supported
One Structured Record for the Whole Assessment
Every part of the assessment — context, scope, classification, risks, controls, findings, and evidence — lives in one project record. Auditors and reviewers work from the same data. Nothing needs to be copied into a separate document.
- Controlled workflow status tracks the assessment from start to closure
- Executive Summary and C&A sections are part of the record and feed directly into exported documents
- Recertification mode imports prior risks, controls, and findings as a starting point for repeat assessments
Evidence-Led Control Validation
For each control, auditors record implementation status, supporting evidence, and an effectiveness rating. AIS flags logical inconsistencies before export — for example, a control rated Fully Effective that still has open Critical findings.
- Integrity Check runs before export and surfaces mismatches between control ratings and open findings
- Suggest Fix proposes a correction for each integrity warning. The auditor decides whether to accept, change, or dismiss it
- Reviewers can see exactly why a control received its rating, including linked evidence
All Findings. One View.
The Findings Registry shows all findings across every project. Filter by system, auditor, exposure, or classification. Track severity, status, owner, due date, and remediation progress. Overdue items and systemic patterns are visible before they become accreditation problems.
- Each finding links to its source control, associated risk, and remediation plan
- Ownership, due dates, and status tracked in the same record — no parallel spreadsheet
- Add evidence to a finding and let AIS help identify whether it supports the remediation claim, highlights gaps, or needs further review. The auditor remains in control of the final decision
Spot Structural Weaknesses
AIS reviews findings for a specific system and helps auditors understand how issues across different security layers may affect the system's real risk position. It highlights related gaps in areas such as access control, identity, monitoring, configuration, resilience, and remediation, helping teams prioritise what to fix first instead of treating every finding in isolation.
Portfolio Visibility for Supervisors and Audit Leads
AIS dashboards turn assessment data into a practical management view for continuous assurance monitoring. Supervisors can see where each project stands, which systems carry the highest risk, which findings are overdue, and which remediation actions need attention before review, accreditation, or certification expiry.
- Portfolio view of active and closed assessments.
- Continuous monitoring of risks, findings, remediation status, and assurance progress.
- Certification and accreditation expiry tracking by system.
- Risk position by system, project, or assessment.
- Findings by severity, status, owner, and due date.
- Management visibility for prioritisation, review readiness, and remediation follow up.
One Project Record. Multiple Assurance Outputs.
Every report comes from the same project record. No separate templates to maintain, no reformatting between documents. When assessment data changes, it carries through — so senior auditors spend their time on review, not on document preparation.
AIS Works Across the Whole Team
Junior & Intermediate Auditors
Guided Through What Good Looks Like
AIS gives auditors practical guidance while they work through controls, evidence, and findings. They can ask how to evaluate a control, what evidence may be expected, whether supplied evidence appears sufficient, and what gaps may need further review. Final judgement remains with the auditor.
- Ask control interpretation questions in context.
- Get guidance on expected evidence.
- Review evidence relevance, completeness, and gaps with AI assistance.
- Improve consistency before formal review.
Senior Auditors & Reviewers
More Time for What Really Matters
AIS surfaces inconsistent ratings, missing evidence, and integrity issues before documents reach the review stage. Senior review time goes to the substance — not to hunting for problems the platform should have caught.
- Integrity checks, consistency flags, and score cross-checks run before documents reach review
- One project record feeds all report types — no template duplication
For Organisations That Run Formal Security Assurance
AIS is for teams where security assurance is a core responsibility, not an occasional exercise.
Government & Public Sector
Government Agencies
AIS supports the NZ government assurance lifecycle — NZISM, PSR, and FISMA-style workflows — with C&A and ATO documentation produced from the same project record as the assessment.
Financial Sector
Banking & Financial Services
Financial institutions need a complete, defensible audit record. AIS documents the evidence behind every control rating, tracks findings ownership and remediation, and supports formal risk governance requirements.
Enterprise
Regulated Enterprises
Enterprise assessment teams running the same assessment type across multiple systems often produce inconsistent results. AIS provides a single structured record per engagement and portfolio visibility across business units.
Consulting
Security Consulting Firms
AIS standardises the assessment methodology across clients, produces all report types from one project record, and reduces the time senior consultants spend on formatting.
Where AI Helps — and Where It Stops
AIS may assist with drafting risk scenarios, evidence review, integrity checks, and narrative sections. It does not make accreditation decisions, accept risk, or change records without auditor control.
AI drafts — auditors decide
Draft risk scenarios, control guidance, and narrative sections come from project data. Every draft is reviewed before entering the record. Nothing is applied automatically.
Scores and ratings come from the record
Risk scores, control ratings, and evidence reflect what auditors recorded — not AI inference.
Auditors control the scores
Likelihood, consequence, and risk scores can be edited directly. Manual entries always take precedence.
Accreditation decisions are yours
Accreditation decisions, risk acceptance, and sign-off rest with authorised personnel. AIS does not recommend whether a system should be accredited.
AIS supports FISMA aligned assurance workflows. It does not guarantee compliance, certification, accreditation, or approval outcomes. All assurance decisions remain with authorised personnel.
Runs in Your Environment. Data Stays There.
AIS is intended for organisations that cannot put sensitive security assessment data on a shared cloud service. The platform runs inside your environment — cloud-hosted or on-premises — and assessment data, framework databases, and configuration remain under your control.
Runs in your environment — cloud or on-premises. No shared infrastructure with other customers.
Role-based access control with MFA enforced for all users.
Framework databases and assessment data are stored inside your environment.
Full activity logging across all platform modules and user actions.
AIS is designed to support Microsoft Entra ID SSO, Exchange Online notifications, and SharePoint Online document export — subject to your organisation's configuration and tenant setup.
Book a Demo
We will show you the platform in the context of your sector and the type of assessments your team runs. You will see how a project is set up, how risks and controls are managed, and how assessment outputs are produced.





