FISMA-Aligned Security Assurance Platform
AIS

One Platform for Risk Assessment,
Control Validation, and Accreditation

AIS manages risk assessments, control validation, findings, evidence, and certification & accreditation outputs in one structured project record.

Designed for

Government AgenciesBanking & Financial ServicesRegulated EnterprisesSecurity Consulting Firms
Security Chat

Control Frameworks. Right There When You Need Them.

Security Chat helps auditors search, interpret, filter, compare, and discuss security controls from supported frameworks and custom catalogues inside AIS. It recognises control IDs, framework names, topic searches, compliance levels, explanation requests, and follow-up questions, so auditors can move from raw control text to practical understanding without leaving the assessment workspace.

  • Look up specific controls by ID, including formats such as AC-2, 16.1.27.C.01, or 5.15
  • Ask for the intention, purpose, rationale, or practical meaning of a control
  • Search controls by topic, such as multi-factor authentication, privileged access, encryption, logging, or incident response
  • Filter controls by framework, chapter, compliance level, or obligation strength where supported
AIS Security Chat querying NZISM chapter 16 controls
AIS Security Chat querying NZISM chapter 16 controls
Risk Analyser

One Structured Record for the Whole Assessment

Every part of the assessment — context, scope, classification, risks, controls, findings, and evidence — lives in one project record. Auditors and reviewers work from the same data. Nothing needs to be copied into a separate document.

  • Controlled workflow status tracks the assessment from start to closure
  • Executive Summary and C&A sections are part of the record and feed directly into exported documents
  • Recertification mode imports prior risks, controls, and findings as a starting point for repeat assessments
AIS Risk Analyser project workspace showing accordion sections and sub-tabs
AIS Risk Analyser project workspace showing accordion sections and sub-tabs
Risk Generator

Start With a Draft, Not a Blank Page

The Risk Generator produces AI-generated risk scenarios from the system context, using the selected control framework and project data already entered. Auditors can review, edit, delete, or add additional risks.

Control Validation

Evidence-Led Control Validation

For each control, auditors record implementation status, supporting evidence, and an effectiveness rating. AIS flags logical inconsistencies before export — for example, a control rated Fully Effective that still has open Critical findings.

  • Integrity Check runs before export and surfaces mismatches between control ratings and open findings
  • Suggest Fix proposes a correction for each integrity warning. The auditor decides whether to accept, change, or dismiss it
  • Reviewers can see exactly why a control received its rating, including linked evidence
AIS Integrity Check showing control consistency warnings with AI-suggested fixes
AIS Integrity Check showing control consistency warnings with AI-suggested fixes
Findings Registry

All Findings. One View.

The Findings Registry shows all findings across every project. Filter by system, auditor, exposure, or classification. Track severity, status, owner, due date, and remediation progress. Overdue items and systemic patterns are visible before they become accreditation problems.

  • Each finding links to its source control, associated risk, and remediation plan
  • Ownership, due dates, and status tracked in the same record — no parallel spreadsheet
  • Add evidence to a finding and let AIS help identify whether it supports the remediation claim, highlights gaps, or needs further review. The auditor remains in control of the final decision
AIS Findings Registry showing cross-project findings with severity, status and owners
AIS Findings Registry showing cross-project findings with severity, status and owners
Attack Path Analysis

Spot Structural Weaknesses

AIS reviews findings for a specific system and helps auditors understand how issues across different security layers may affect the system's real risk position. It highlights related gaps in areas such as access control, identity, monitoring, configuration, resilience, and remediation, helping teams prioritise what to fix first instead of treating every finding in isolation.

Dashboards

Portfolio Visibility for Supervisors and Audit Leads

AIS dashboards turn assessment data into a practical management view for continuous assurance monitoring. Supervisors can see where each project stands, which systems carry the highest risk, which findings are overdue, and which remediation actions need attention before review, accreditation, or certification expiry.

  • Portfolio view of active and closed assessments.
  • Continuous monitoring of risks, findings, remediation status, and assurance progress.
  • Certification and accreditation expiry tracking by system.
  • Risk position by system, project, or assessment.
  • Findings by severity, status, owner, and due date.
  • Management visibility for prioritisation, review readiness, and remediation follow up.
AIS Supervisor Dashboard showing active audits, findings by severity and risk distribution
AIS Supervisor Dashboard showing active audits, findings by severity and risk distribution
Reports & Exports

One Project Record. Multiple Assurance Outputs.

Every report comes from the same project record. No separate templates to maintain, no reformatting between documents. When assessment data changes, it carries through — so senior auditors spend their time on review, not on document preparation.

SRASecurity Risk Assessment
CVPControl Validation Plan
CVAControl Validation Assessment
SRA+CVACombined SRA + CVA
C&ACertification & Accreditation Memo
AI-assisted narrative
ATOAuthority to Operate Memo
AI-assisted narrative
EAEmergency Accreditation Memo
FRPFindings & Remediation Plan
PTSPenetration Testing Scope
AI-assisted narrative
DASHDashboard Report
AIS export panel showing SRA, CVA, C&A Memo, ATO Memo and EA Memo options
AIS export panel showing SRA, CVA, C&A Memo, ATO Memo and EA Memo options
Who AIS Is For

AIS Works Across the Whole Team

Junior & Intermediate Auditors

Guided Through What Good Looks Like

AIS gives auditors practical guidance while they work through controls, evidence, and findings. They can ask how to evaluate a control, what evidence may be expected, whether supplied evidence appears sufficient, and what gaps may need further review. Final judgement remains with the auditor.

  • Ask control interpretation questions in context.
  • Get guidance on expected evidence.
  • Review evidence relevance, completeness, and gaps with AI assistance.
  • Improve consistency before formal review.

Senior Auditors & Reviewers

More Time for What Really Matters

AIS surfaces inconsistent ratings, missing evidence, and integrity issues before documents reach the review stage. Senior review time goes to the substance — not to hunting for problems the platform should have caught.

  • Integrity checks, consistency flags, and score cross-checks run before documents reach review
  • One project record feeds all report types — no template duplication
Who Uses AIS

For Organisations That Run Formal Security Assurance

AIS is for teams where security assurance is a core responsibility, not an occasional exercise.

Government & Public Sector

Government Agencies

AIS supports the NZ government assurance lifecycle — NZISM, PSR, and FISMA-style workflows — with C&A and ATO documentation produced from the same project record as the assessment.

Financial Sector

Banking & Financial Services

Financial institutions need a complete, defensible audit record. AIS documents the evidence behind every control rating, tracks findings ownership and remediation, and supports formal risk governance requirements.

Enterprise

Regulated Enterprises

Enterprise assessment teams running the same assessment type across multiple systems often produce inconsistent results. AIS provides a single structured record per engagement and portfolio visibility across business units.

Consulting

Security Consulting Firms

AIS standardises the assessment methodology across clients, produces all report types from one project record, and reduces the time senior consultants spend on formatting.

AI Governance

Where AI Helps — and Where It Stops

AIS may assist with drafting risk scenarios, evidence review, integrity checks, and narrative sections. It does not make accreditation decisions, accept risk, or change records without auditor control.

AI drafts — auditors decide

Draft risk scenarios, control guidance, and narrative sections come from project data. Every draft is reviewed before entering the record. Nothing is applied automatically.

Scores and ratings come from the record

Risk scores, control ratings, and evidence reflect what auditors recorded — not AI inference.

Auditors control the scores

Likelihood, consequence, and risk scores can be edited directly. Manual entries always take precedence.

Accreditation decisions are yours

Accreditation decisions, risk acceptance, and sign-off rest with authorised personnel. AIS does not recommend whether a system should be accredited.

AIS supports FISMA aligned assurance workflows. It does not guarantee compliance, certification, accreditation, or approval outcomes. All assurance decisions remain with authorised personnel.

Security & Deployment

Runs in Your Environment. Data Stays There.

AIS is intended for organisations that cannot put sensitive security assessment data on a shared cloud service. The platform runs inside your environment — cloud-hosted or on-premises — and assessment data, framework databases, and configuration remain under your control.

Runs in your environment — cloud or on-premises. No shared infrastructure with other customers.

Role-based access control with MFA enforced for all users.

Framework databases and assessment data are stored inside your environment.

Full activity logging across all platform modules and user actions.

AIS is designed to support Microsoft Entra ID SSO, Exchange Online notifications, and SharePoint Online document export — subject to your organisation's configuration and tenant setup.

See AIS in Action

Book a Demo

We will show you the platform in the context of your sector and the type of assessments your team runs. You will see how a project is set up, how risks and controls are managed, and how assessment outputs are produced.

Platform walkthrough tailored to your sector and assessment type
Live demonstration using realistic assessment data
Q&A with the Andean Security Consulting team
Discussion of deployment options, framework support, and integration