One Platform for Risk Assessment,
Control Validation, and Accreditation
AIS manages risk assessments, control validation, findings, evidence, and certification & accreditation outputs in one structured project record.
Built by practitioners who run NZISM assessments.
Designed for
The Whole Audit in One Workspace
From risk scoring to the final export. Click any screen to take a closer look.
Assurance Dashboards
A Different Take on AI for Risk & Assurance
Assurance teams lose time every day across spreadsheets, scattered documents, and repetitive reporting. AIS lets skilled people spend their time on judgement, not formatting, and lifts the quality of every output.
Strengthens auditors, never replaces them
AI drafts risk scenarios, reviews evidence, and flags inconsistencies. Every draft is reviewed by an auditor before it enters the record, and every audit passes independent review gates before closure. AI-assisted assurance. Human-led decisions.
Your data stays home
AIS runs in your environment, on-premises or in your own cloud, and can use locally hosted AI models. No external AI services required, no shared infrastructure. Built for New Zealand data sovereignty.
One record. Every assurance output.
Risks, controls, evidence, and findings live in one project record that produces every output: SRA, CVA, C&A, ATO, and more. Senior time goes to judgement, not formatting.
One Project Record. Every Assurance Output.
Most assessment teams work across spreadsheets, Word templates, and email threads, producing a different set of documents each time. AIS consolidates risks, controls, findings, evidence, and accreditation outputs into one structured project record per engagement. The data stays consistent. The audit trail holds.
Security Chat
Query and consult NZISM, NIST SP 800-53, ISO 27002, PSR, Privacy Act IPPs, and custom catalogues directly from the platform.
Risk Analyser
The core audit workspace: context, scope, risks, controls, findings, and evidence in one project record.
Risk Generator
AI-generated draft risk scenarios from project context and selected frameworks. Every draft is auditor-reviewed before entering the record.
Control Validation
Record implementation status and evidence per control. Integrity checks flag inconsistencies before export.
Findings Registry
All findings across every project in one view: ownership, status, due dates, and remediation progress.
Attack Path Analysis
Highlights possible relationships between findings, control gaps, and exposure to support senior auditor review.
Dashboards
Current view of audit completion, findings by severity, and risk positions across the portfolio.
Pentest Report Ingest
Import third-party penetration test reports. AI extracts candidate findings; every one is reviewed and accepted by an auditor before entering the record.
Evidence Collector
SharePoint drop-folder for evidence providers. AIS detects new files, AI proposes control mappings, and the auditor confirms every import.
Reports & Exports
SRA, CVA, C&A Memo, ATO Memo, EA Memo, and Findings Plans, all from the same assessment data.
Where AI Helps, and Where It Stops
AIS may assist with drafting risk scenarios, evidence review, integrity checks, and narrative sections. It does not make accreditation decisions, accept risk, or change records without auditor control.
AI drafts, auditors decide
Draft risk scenarios, control guidance, and narrative sections come from project data. Every draft is reviewed before entering the record. Nothing is applied automatically.
Scores and ratings come from the record
Risk scores, control ratings, and evidence reflect what auditors recorded, not AI inference.
Auditors control the scores
Likelihood, consequence, and risk scores can be edited directly. Manual entries always take precedence.
Accreditation decisions are yours
Accreditation decisions, risk acceptance, and sign-off rest with authorised personnel. AIS does not recommend whether a system should be accredited.
AIS supports FISMA aligned assurance workflows. It does not guarantee compliance, certification, accreditation, or approval outcomes. All assurance decisions remain with authorised personnel.
Runs in Your Environment. Data Stays There.
AIS is intended for organisations that cannot put sensitive security assessment data on a shared cloud service. The platform runs inside your environment, cloud-hosted or on-premises, and assessment data, framework databases, and configuration remain under your control.
Runs in your environment, cloud or on-premises. No shared infrastructure with other customers.
Role-based access control with MFA enforced for all users.
Framework databases and assessment data are stored inside your environment.
Full activity logging across all platform modules and user actions.
AIS is designed to support Microsoft Entra ID SSO, Exchange Online notifications, and SharePoint Online document export, subject to your organisation's configuration and tenant setup.
Built From the Auditor's Chair
AIS is developed by Andean Security Consulting, a New Zealand security consultancy that runs formal security assessments for government and regulated organisations. We built AIS because we lived the problem: senior audit time buried in spreadsheets, reformatting, and chasing inconsistencies instead of exercising judgement.
Every workflow in AIS, from risk development to the final ATO memo, mirrors how real NZISM, PSR and FISMA-aligned engagements are actually run.
Meet Andean Security Consulting10+ years
dedicated to security audits and assurance
6 years
running NZISM, PSR and C&A engagements for New Zealand government and regulated organisations
Talk Directly to the People Who Built AIS
Start wherever suits you: a quick question, a walkthrough, or a free guided pilot running a real assessment in your own environment.