Product

Letting AI review the evidence, without breaking your audit

April 16, 2026 · 9 min read

A document review engine maps each report to the control it evidences, checks currency and scope, and extracts real findings. Here is how it works, and the lines it will not cross.


Reading vendor evidence properly is slow, and slowness is why evidence often goes unread. A SOC 2 report gets a glance at the cover page and a tick; a penetration-test report is filed without anyone checking whether the critical findings were fixed. AI can read these documents properly and at scale. The question that matters is how to do that without introducing findings you cannot defend to an auditor.

Map first, then review

The engine never reviews a document in a vacuum. It first maps the file to the specific control it is meant to evidence, then reviews it only against that control's validation checks and red flags. A cloud-configuration procedure is judged on hardening baselines and patch SLAs; an access-control policy is judged on its access-control requirements. This is the single most important design choice, because it is what stops the review from inventing irrelevant observations. A review that is not anchored to a control will find generic 'gaps' in any document, which is noise, not assurance.

When evidence is provided against a control the vendor explicitly claimed, the mapping is not guessed at all: the review is pinned to that exact control's rubric. When a document is uploaded loosely, the engine ranks the most likely controls and reviews against the best match, flagging low-confidence cases for a human.

Go beyond 'does it exist'

Existence is a weak test. What matters is whether the evidence actually supports the control:

The lines the engine will not cross

Trust in an automated reviewer comes from its restraint as much as its capability. The rules are deliberately conservative:

Where the human stays in the loop

The engine's job is to do the slow reading and produce a defensible, control-anchored verdict with the evidence quoted. The reviewer's job is to make the risk decision: accept, request more, or flag for remediation. That division of labour is what keeps the audit intact. The AI makes the evidence legible and consistent; the accountable human makes the call.

Live review is the Enterprise step

Watching the engine read a report in real time, highlighting evidence as it maps to open questions and pre-filling answers with a quoted excerpt and a confidence score, is available on the Enterprise plan alongside the conversational copilot. The underlying review engine, though, backs every plan. It is how each claimed control earns a defensible verdict rather than a checkbox.

See it in your own portfolio

Full question bank, both portals, and transparent launch pricing by vendor volume.

See launch pricing

Keep reading

Frameworks

SEBI CSCRF, explained for vendor risk teams

The Cybersecurity and Cyber Resilience Framework changed what SEBI-regulated entities must prove about their t

Fundamentals

What is third-party risk management? A 2026 primer

Inherent risk, control maturity, residual risk: the three numbers every TPRM program runs on, why the order ma

Frameworks

RBI outsourcing directions: a vendor-by-vendor checklist

How to translate the RBI Master Directions on IT outsourcing into criticality ratings, questionnaire depth, co