Security & privacy assessment platform

Better assessments.
Less busywork.

AIS connects risks, evidence, reviews and reports in one platform. Give seniors more time for judgement, help juniors work with guidance, and keep your assessment outputs consistent.

Data sovereignty.Your environment.Your control.
THE ASSESSMENT, CONNECTED 01 — AIS
One assessment recordA shared foundation for the whole team
Risks
Controls
Evidence
SR
Ready for a more focused reviewLinked evidence. Visible findings. Consistent ratings.
SRACVAC&AATO

Security workflow illustration

Privacy has its own workspace.From threshold assessment to a full PIA.
AI-ASSISTED ANALYSISHUMAN-LED DECISIONS
BUILT FOR TEAMS THAT
RUN FORMAL ASSESSMENTS

Government

Financial services

Regulated enterprises

Security consultancies

The work behind the work

Your team should be assessing risk.
Not reconciling spreadsheets.

01 / SENIOR CAPACITY

Stop rebuilding
the same report.

Generate assessment documents from recorded data. Put senior expertise into challenging the conclusions and reviewing the evidence.

Less preparation and rework
02 / TEAM CAPABILITY

Make the next
step clearer.

Give junior staff control guidance, draft validation plans and structured reviewer feedback inside the assessment workflow.

Support while the work happens
03 / REPORT CONSISTENCY

Tell one story
across every output.

Use the same assessment record for risks, control ratings, findings and reports. Flag contradictions before they reach the reader.

One source, consistent outputs

How it works

From the first question
to the final report.

One platform. Two dedicated assessment workflows. Evidence, review and reporting stay connected.

  1. 01

    Scope the system

    Record context, boundaries and the applicable control framework.

  2. 02

    Assess & validate

    Develop risks, plan control tests and record supporting evidence.

  3. 03

    Review the work

    Resolve integrity issues and reviewer comments in context.

  4. 04

    Generate reports

    Produce assessment reports and accreditation memos from the record.

  5. 05

    Follow through

    Track findings, remediation and the next assessment cycle.

Explore Risk Analyser

Make expertise go further

Good people.
Better use of their time.

Less effort moving information around. More support for the work that needs a person.

FOR SENIOR REVIEWERS

Review the judgement.
Spend less time fixing the document.

Senior time disappears into reconciling ratings, chasing evidence and correcting the same issues across several reports.

AIS links risks, controls, findings and evidence, flags inconsistencies and keeps reviewer comments with the work. Reports are generated from that assessment record.

  • Identify conflicting ratings before final review
  • Review the evidence behind an assessment
  • Resolve comments in context, with a review trail
INSIDE AIS Product view
AIS Integrity Check highlighting inconsistent ratings and findings
AIS Integrity Check highlighting inconsistent ratings and findings

AIS product screen

Less reconciliation. More time for professional judgement.

Your frameworks. Your methodology.

Recognised standards.
Your organisation’s own controls.

Work with built-in frameworks or bring your own control catalogues. Use dedicated security and privacy workflows, with standard outputs and custom report templates.

SECURITY ASSURANCE

Risk Analyser

Connect system context, risks, control validation and findings through to accreditation documentation.

  • Evidence-led control assessments
  • Integrity checks and reviewer feedback
  • Standard reports and reusable custom templates
Explore security assessments
Risk Analyser workspace with risks, controls and assessment context
Risk Analyser workspace with risks, controls and assessment context

AIS product screen

PRIVACY ASSURANCE NEW

Privacy Analyser

Start with a threshold assessment and progress to a full PIA where needed, keeping the privacy record connected.

  • Business questionnaires in Word and Excel
  • Privacy risks, principles and evidence
  • PTA and PIA reports from one record
Explore privacy assessments
Privacy Analyser showing the threshold determination and assessment tabs
Privacy Analyser showing the threshold determination and assessment tabs

AIS product screen

YOUR FRAMEWORKS, IN CONTEXT

NZISM

NIST SP 800-53

ISO/IEC 27002

PSR

Privacy Act 2020

Your own catalogues

Continuous assurance & remediation

The assessment ends.
The follow-through continues.

For assurance leads, system owners and remediation teams. Keep findings visible, accountable and moving towards resolution.

FINDINGS REGISTRY

Track every finding
through to remediation.

Bring findings from assessments into a shared register. See who owns each action, when it is due and what still needs attention, without maintaining a parallel spreadsheet.

  • Track severity, status, ownership and due dates
  • Follow remediation progress and overdue actions
  • Keep the source control, risk and evidence in context
Full product screen. Click to enlarge.
Complete AIS Findings Registry showing finding ownership, status and remediation tracking
Complete AIS Findings Registry showing finding ownership, status and remediation tracking

Full product screen. Click to enlarge.

DASHBOARDS

See the portfolio.
Prioritise the next action.

Bring assessment progress, risk positions and findings into a management view. Focus follow-up where work is overdue, reviews need attention or accreditation is approaching expiry.

  • Monitor assessment and remediation progress
  • See findings by severity, status and owner
  • Track certification and accreditation expiry by system
Full product screen. Click to enlarge.
Complete AIS Supervisor Dashboard showing assessment progress, findings and risk distribution
Complete AIS Supervisor Dashboard showing assessment progress, findings and risk distribution

Full product screen. Click to enlarge.

Continuous oversight of recorded findings and actions, beyond the assessment report.

See the management view

Privacy findings enter the shared registry when the privacy assessment closes. Visibility follows the permissions configured for each user.

Consistency by design

One source of truth.
Your reports. Your templates.

Standard outputs when you need them. Custom templates when your organisation needs something different.

Generate risk assessments, validation plans, accreditation memos, remediation plans and management reports from the same project record. Privacy assessments produce their own PTA and PIA reports.

Build once. Reuse across the team.

Choose and arrange report sections, start from an official preset, and share approved templates. Required sections in accreditation presets remain protected.

Custom templates are available where enabled. Each assessment has its own record and report set. Regenerate exports to reflect updates.

Explore reports & templates
Security assessment record

Context · Risks · Evidence · Findings · Review

GENERATE FROM THE SAME RECORD
SRASecurity Risk Assessment
CVP / CVAControl validation & combined reports
C&A / ATOAccreditation & authorisation memos
EAEmergency Accreditation Memo
FRP / PTSRemediation plan & pentest scope
DashboardManagement reporting

Data sovereignty, by design

Your assessment data stays under your control.

For government and organisations handling sensitive information: deploy AIS in your own environment, choose your hosting location and retain control of assessment records. Locally hosted AI supports a deployment without external AI processing.

Data sovereignty & deployment

A short look inside AIS

Start with context.
See a risk draft take shape.

Watch the Security Risk Generator in action. Give the team a starting point for risk development, then apply professional judgement to review and refine the draft.

More short product demos

AI-generated risks are drafts. The assessor reviews what belongs in the assessment record.

Built from the auditor’s chair

We know where
the hours go.

AIS is built by Andean Security Consulting, a New Zealand consultancy that runs formal security assessments. It grew out of the same work your team does: testing controls, reviewing evidence, reconciling findings and preparing documents.

The goal is practical: help capable people deliver clear, consistent, reviewable assessments with less administrative effort.

Meet the practitioners behind AIS

See it with your team

Bring your assessment.
We’ll show you the workflow.

A 30-minute walkthrough tailored to your frameworks, your team and the work you need to deliver.