Skip to content

AI Advisory Drafting

Several modules offer AI drafting of narrative content. They behave identically, so they are documented together.


The capabilities

ModuleCapabilityProduces
IncidentsIncident summaryA draft executive summary from incident context
Classification suggestionA suggested classification with reasoning and an advisory notice
Investigation questionsStructured inquiry prompts, five-whys and timeline
Root-cause hypothesesCandidate causes across process, control, human and technical factors
Lessons learnedPreventive recommendations for post-incident review
AuditAudit assistanceDraft procedures, workpaper summaries, draft finding wording
InspectionsResponse draftDraft regulatory response wording
ResilienceScenario generationDraft exercise scenarios
BIA impact suggestionsDraft impact assessments
Gap analysisDraft gap narrative
RiskException justificationDraft justification wording

The shared behaviour

All of them:

  • Are triggered explicitly by a person, never on a schedule or an event
  • Produce a draft, never a record
  • Carry full provenance — provider, model, prompt version
  • Never modify an authoritative record
  • Require a separate permission to adopt the output

AI suggestions never autonomously modify authoritative records

Drafting an incident summary does not update the incident. Suggesting a classification does not set it. Drafting a response does not submit it. Hypothesising a root cause does not record it.

In every case a person reads the draft, decides what is true, and writes the record.


Which are actually worth using

Honest assessment, because these vary considerably in value.

Genuinely useful

Investigation questions. A structured prompt set at the start of an incident investigation costs nothing and reliably surfaces the question nobody thought to ask. It does not need to be right; it needs to be prompting.

Root-cause hypotheses. Same reasoning. Candidate causes across process, control, human and technical factors counteract the natural tendency to stop at the first plausible explanation — usually "human error", which is a description rather than a cause.

Audit procedure drafting. Given a clear objective, a draft test programme is a reasonable starting structure that an auditor then makes specific and testable.

Useful with heavy editing

Incident summaries. The structure is helpful. The content needs verification against the timeline, and executive summaries carry consequences that generated prose should not.

Exception justifications. A draft gives the shape. The substance — why this control cannot be met, what compensates, when it resolves — comes from the requester.

Response drafts. Given what a regulatory response is, expect to rewrite most of it. Starting from a structured draft that already references the right findings and actions still saves real time.

Use with care

Classification suggestions. Heuristic. Category is usually reasonable; severity and reportability are judgements the model cannot make. It never assesses reportability at all.

BIA impact suggestions. These touch recovery objectives, which are executive determinations about acceptable customer harm. The draft can structure the impact categories; the numbers are yours.

Lessons learned. Generated recommendations tend toward the generic. A lessons-learned section that reads like it could apply to any incident teaches nothing.


Using a draft well

Treat it as a first draft, not a first opinion. Read it for structure and completeness, not for conclusions.

Verify every fact. Drafts are generated from the context recorded so far. A thin record produces confident-sounding content built on very little.

Rewrite the openings. Generated first paragraphs are the most recognisable part of AI prose, and the part a reader judges the document by.

Delete what does not apply. A draft covering five contributing factors when your incident had two is not thorough; it is noise.

Never submit one unread. For a regulatory response in particular, the submitted document is a formal representation to a supervisor.


Permissions

CapabilityGeneration permissionAdoption
Incident drafting, all fiveincident.ai_assistincident.manage or incident.investigate
Audit assistanceaudit.ai_assistaudit.engagement_execute, reviewed under audit.engagement_review
Inspection response draftinspection.ai_assistinspection.signoff
Resilience draftingbcm.ai_assistThe relevant bcm.* manage or approve permission
Exception justificationai.use plus the AI entitlementexception.create, approved under exception.approve

Each requires the relevant module entitlement, and most require the AI entitlement.


Example

Incident INC-2026-0014 — investigation questions.

The Head of Payments Operations requested investigation questions two hours into the incident. The model returned eleven prompts. Nine were obvious to anyone doing the job.

Two were not:

"Was the failed batch's error message distinguishable from a 'not submitted' state, and what did the operator's runbook instruct at that point?"

"Did the duplicate detection control's threshold cover the full value range of the duplicated transactions?"

Both became contributing factors in the final investigation. The second became finding FND-2026-0156 — the detection threshold was set above the value of 14 of the duplicates, which is why those 14 were released.

This is what advisory AI is for

The model did not investigate anything, did not know the threshold value, and did not identify a finding. It asked whether someone had checked. Nobody had.

That is a modest contribution, and it is a real one.


Troubleshooting

"AI assistance is unavailable." Requires the module's AI permission and the relevant entitlement. All records can be authored manually.

"Drafts are generic." They draw on the context recorded so far. Write the narrative and timeline first, then request the draft.

"The draft contains something that did not happen." Delete it. The draft is not a record and has no standing.

"A classification suggestion was applied." It cannot be. Check who set the classification.


OrviQ Enterprise Governance, Risk & Compliance Platform