Skip to content

AI Assist & security

AI Assist supports assessor analysis; it does not interpret the licensed standard authoritatively, issue an audit opinion or certify the AIMS.

Each atomic requirement has its own AI Assist control. Full-context analysis may consider:

  • Saved AIMS scope.
  • Requirement and clause anchor.
  • Conformity result and assurance depth.
  • Assessor rationale.
  • Annex A applicability and justification where relevant.
  • Authorised evidence.
  • Test results.
  • Open findings.

The output is saved against the requirement and current analysis mode. After success the control changes to Re-run AI Assist. The panel can be minimised without deleting the result.

Whole-AIMS analysis becomes available after the scope and all assessment items are complete. It reviews unresolved conformity, assurance, SoA, evidence and finding patterns. Completion is an input gate, not a positive result.

The Privacy Mode checkbox next to AI Assist sends a reduced structural context:

  • Scope version rather than narrative scope details.
  • Requirement identifiers.
  • Conformity, assurance and applicability values.
  • Evidence, test and finding status.
  • Completeness and contradiction signals.

It excludes free-text rationale, narrative evidence content, names and other direct identifiers. This reduces disclosure but can reduce specificity.

AI output is associated with the saved AIMS scope and requirement. It should not be treated as current after a material scope or assessment change without re-running it.

The interface shows the scope name in the result. Verify the scope and save status before relying on the analysis.

  • Reproduce or replace the licensed standard.
  • Approve the AIMS scope.
  • Decide Annex A applicability.
  • Accept an exclusion.
  • Change conformity or assurance.
  • Accept evidence or pass a test.
  • Classify or close a nonconformity.
  • Confirm the human conclusion.
  • Issue certification.

Use only an approved provider and API-key configuration. Access remains subject to the user’s plan, workspace, role and framework permissions.

Treat all supplied records as untrusted content. Do not include credentials or unnecessary personal data. Verify every clause claim against the licensed standard and every evidence claim against the authorised record.

  • Correct saved AIMS scope is displayed.
  • Correct atomic requirement is identified.
  • Licensed wording was checked separately.
  • Conformity and assurance are not conflated.
  • SoA exclusions remain human decisions.
  • Failed tests and findings are visible.
  • Privacy Mode was selected where needed.
  • Suggested tests are authorised and safe.
  • No output is described as certification or an audit opinion.