Skip to content

AI Assistant

AI for GRC and ISMS: automate compliance work with agents

KaitoSec supports the current record with drafts, summaries and mappings. Sources remain visible and changes require approval from an accountable person.

Where friction starts today

Compliance work is mostly routine, and it still eats your week

Most of a security and compliance programme is not hard, it is just relentless. Classifying a new asset, drafting a questionnaire answer you have written ten times before, writing the justification for a control, chasing the next review. None of it needs deep thought, all of it needs doing, and it quietly consumes the people who should be working on the decisions that actually matter.

Bolting a chatbot onto the side does not fix this. A general assistant that knows nothing about your asset register, your risks or your open controls just produces confident text you then have to check. What helps is support on the actual record: a draft with visible sources and approval by the accountable person. That reduces writing and searching without handing assessment, decisions or governance to a model.

One data model

What KaitoSec AI takes on

KaitoSec AI works on the selected record and keeps the links to requirements, risks, controls and evidence intact.

A change in this module is written to the shared data model, which the other modules read immediately.

This module

AI Assistant

Shared data model

One asset, one risk, one control, one piece of evidence

  • Risk ManagementCurrent at once
  • Business ContinuityCurrent at once
  • Asset ManagementCurrent at once

Entry to evidence

Traceability and human-in-the-loop control

Sources, changes and approvals remain visible. KaitoSec AI can prepare work, but an accountable person reviews and approves every change to the workspace.

One change writes its previous value, its owner and its date, and surfaces in the management report, the audit evidence and the customer questionnaire.

One change

A risk is re-assessed

Written with it

  • Previous value and version
  • Person responsible
  • Date and reason

Where it surfaces

  • Management report
  • Audit evidence
  • Customer questionnaire

Simple or expert

Departments decide. The audit reads the method.

One switch per person, the same data. Simple mode shows what needs deciding. Expert mode opens SoA references, risk links and the audit trail.

KaitoSec AI and modes

Simple mode

What to do
Request review reports for the six critical service providers.
Why
Your customers ask for it, and NIS2 requires it for the supply chain.
What is enough
File the report against the contract and renew it once a year.

Expert mode

Control
A.5.19 supplier due diligence · applicability justified in the SoA
Risk
Linked to R-042 · residual risk accepted, review date set
Evidence
Treatment plan with owner and date, evidence signed, audit trail complete

KaitoSec AI

AI agents steer your workspace for continuous resilience.

The agents work on a world model of over 5,000 entities: from governance through ISMS, BCMS, DSMS, AIMS and TPRM down to the operative MITRE ATT&CK tactics. They prioritise, keep registers and evidence current and propose the next step.

Before anything counts, a network of practitioners reviews it. Decisions stay with people.

Compliance routine is the starting point. Security and resilience are the goal.

See KaitoSec AI
Four layers of the world model: governance, the five management systems, measures and evidence, operative MITRE ATT&CK tactics.

The world model

Governance

Policies · roles · approvals

Management systems

ISMS · BCMS · DSMS · AIMS · TPRM

Measures and evidence

Registers · tasks · audit packs

Operational tactics

MITRE ATT&CK

Derive policies and controls from requirements

Applicable requirements and current workspace context become policy and control drafts for professional review.

01

Support in the professional context

Every domain, from risk to AI governance, keeps its own logic. KaitoSec AI prepares; accountable people review and decide.

02

Keep sources and input data visible

Suggestions refer to the selected record and the information available there. This makes it possible to review what a summary, mapping or recommendation is based on.

03

Start with a reviewable draft

First drafts of risk treatments, BC plans, policy sections, vendor responses and audit answers are produced from workspace context, not generic templates. Review, adjust, publish, with every approval logged for governance.

04

Reachable from anywhere with one shortcut

Cmd+J opens KaitoSec AI on any record. Cmd+K runs a global search across assets, risks, controls, policies, vendors, incidents and BC plans. The shortcut works the same on every page and brings KaitoSec AI to the current record with one keystroke.

Assess risks and collect evidence

Summarise risk context, prepare treatment options, identify missing evidence and assign follow-up work without separating the result from its source record.

01

Prepare gap analysis for professional review

Upload a framework assessment or describe the current state. KaitoSec AI maps the input to the selected framework and prepares potential gaps across ISMS, BCMS, DSMS and AIMS for review.

02

Contextual summaries on the record

Select a risk, asset, vendor, policy or AI system and summarise status, related findings and missing context. The accountable person reviews the result before it is used further.

03

Simple Mode and Expert Mode side by side

Simple Mode walks new users through a guided flow with the next action surfaced for them. Expert Mode opens the full depth of the platform for the ISB, the risk owner or the auditor. Both modes run on the same platform, switchable per user or per session.

04

Domain Lens for multi-entity organisations

Filter the entire workspace to one scope: a tenant, a site, a standard, a single management system. The lens narrows risk views, evidence packages and reports without rebuilding the data model, and works for multi-entity organisations from day one.

05

Prepare recurring drafts under control

KaitoSec AI can prepare SoA justifications, questionnaire responses, asset classifications or exercise scenarios. No workspace change takes place without human approval.

Data protection and hosting in Germany

KaitoSec is developed and hosted in Germany. AI use remains bounded by documented data sources, configured infrastructure and human approval for workspace changes.

How does AI help build an ISMS?

AI agents in KaitoSec import existing registers and documents, check them against the methodology (for example, the six phases of BSI IT-Grundschutz), identify gaps and turn them into tasks with an owner and due date.

Does AI make decisions in the compliance process?

No. AI agents prepare the work; people decide. Every suggestion remains under human oversight, is reasoned and traceable, and only takes effect after approval. See ISO 42001 for the governance model.

Is using AI in the ISMS GDPR-compliant?

AI use in KaitoSec is GDPR-compliant: hosting remains in Germany, customer data is not used for model training and the agent retains the user's permissions. Details are available under Integrations.

Can our own AI assistants access KaitoSec?

Yes. Your own AI assistants can access KaitoSec through the MCP server and documented API. They read and write registers, risks and evidence directly instead of parsing PDF exports, using least-privilege scopes.

Which tasks do the KaitoSec agents take on?

KaitoSec agents handle data import and mapping, completeness checks, suggestions for risk assessments, deriving controls from requirements, collecting and assigning evidence, and preparing audit responses.

AI management under ISO 42001 and the EU AI Act

Use the same traceable records for your AI inventory, risk work and governance under ISO 42001 and the EU AI Act.