AI agents that draft, map and check. People still decide.
- Organisational context
- Policy drafting
- Control mapping
- Policy review
- Implementation checks
- Operation checks
Why agents, and not a template pack
What the agents do
Identify organisational context
Your sector, size, systems, data types, customers and the laws that reach you. This is the ISO 27001 Clause 4.1 and 4.2 work, and everything downstream depends on it.
Create policies
Policies drafted from that context rather than from a shelf. A firm holding Ontario health data gets different wording from a fintech selling into the United States.
Map policies to controls
Every clause tied to the controls it supports, and every control tied to the framework requirements it answers. Write once, satisfy each framework that asks.
Review policies
Policies drift. The agents re-read them when your systems, headcount, products or frameworks change, and flag the clauses that no longer describe the business.
Verify implementation
Does the control exist as designed? The agents check configuration in your cloud, identity, code and device tooling against what the control says.
Verify operation
Did the control run, on schedule, with a record? A control that exists but did not operate is the exception an auditor writes up in a SOC 2 Type 2 report.