Appearance
AI Feature Inventory
A complete list of the AI-assisted capabilities in OrviQ, and the governance around each.
Every entry follows the same pattern: AI produces something non-authoritative; a person with a different permission adopts it or does not.
Regulatory and compliance
| Capability | Trigger | Produces | Generation permission | Adoption |
|---|---|---|---|---|
| Regulatory change classification | A source sweep detects a change | A summary and suggested classification on the change event | reg_intel.sweep | Human triage, reg_intel.triage |
| Smart Extract | A person runs the wizard on a document | Candidate requirements with source text and provenance | library.smart_extract | Human review and publication |
| Applicability rationale | A person requests a draft on an applicability record | Draft justification wording, and a suggested status | compliance.read plus AI entitlement | Human sets the status; approval by compliance.validate |
| Requirement assurance rationale | A person requests a draft on a requirement review | Draft review rationale | ai.use plus AI entitlement | Human review sign-off, assurance.review |
Controls and assurance
| Capability | Trigger | Produces | Generation permission | Adoption |
|---|---|---|---|---|
| Control discovery | A person searches for candidate controls | A ranked list — creates nothing | mapping.discover | Not applicable |
| AI mapping proposal | A person runs a comparison pass | Mappings in proposed status with relationship, rationale and confidence | mapping.ai_propose | mapping.review |
| Control extraction | A control source document is ingested | Candidate controls with confidence bands and source lineage | control_source.ingest | control_source.publish |
| Design adequacy check | A person runs the check on an approved mapping | A draft recommendation only | adequacy.run | adequacy.submit, then adequacy.review |
| Expected evidence suggestion | Generated from an approved adequacy assessment | Recommended expected-evidence requirements | expected_evidence.ai_suggest | expected_evidence.accept |
Risk and remediation
| Capability | Trigger | Produces | Generation permission | Adoption |
|---|---|---|---|---|
| Exception justification | A person requests a draft | Draft justification wording | ai.use plus AI entitlement | Human submits; exception.approve decides |
Audit and inspections
| Capability | Trigger | Produces | Generation permission | Adoption |
|---|---|---|---|---|
| Audit assistance | A person requests it during fieldwork | Draft procedures, workpaper summaries, draft finding wording | audit.ai_assist | Human authorship; audit.engagement_review |
| Inspection candidate extraction | A person runs extraction on an examination report | Candidate observations with source location and confidence | inspection.extract | inspection.canonicalize |
| Inspection response draft | A person requests a draft | Draft response wording | inspection.ai_assist | inspection.signoff |
Resilience
| Capability | Trigger | Produces | Generation permission | Adoption |
|---|---|---|---|---|
| Scenario generation | A person requests it | Draft exercise scenarios | bcm.ai_assist | Human authorship; bcm.exercise_signoff |
| BIA impact suggestions | A person requests it | Draft impact assessments | bcm.ai_assist | Human authorship; bcm.bia_approve |
| Gap analysis draft | A person requests it | Draft gap narrative | bcm.ai_assist | Human authorship |
Incidents
| Capability | Trigger | Produces | Generation permission | Adoption |
|---|---|---|---|---|
| Incident summary | A person requests it | Draft executive summary | incident.ai_assist | Human authorship |
| Classification suggestion | A person requests it | Suggested classification with reasoning and an advisory notice | incident.ai_assist | incident.manage sets it |
| Investigation questions | A person requests it | Structured inquiry prompts, five-whys and timeline | incident.ai_assist | Human investigation |
| Root-cause hypotheses | A person requests it | Candidate causes across process, control, human and technical factors | incident.ai_assist | incident.investigate records the cause |
| Lessons learned draft | A person requests it | Preventive recommendations | incident.ai_assist | Human authorship |
The Assistant
| Capability | Trigger | Produces | Generation permission | Adoption |
|---|---|---|---|---|
| OrviQ Assistant | A person asks a question | An answer with citations, grounded in product knowledge and permitted tenant data | ai.use plus AI entitlement | Not applicable — the Assistant takes no governed action |
See the Assistant section for detail.
What is not AI
For completeness, these are deterministic and involve no model:
- Indicator evaluation and result status
- Control effectiveness derivation
- Requirement satisfaction derivation
- Evidence coverage calculation
- Freshness evaluation
- Policy comparison
- Historical reconstruction
- Business reference generation
Failure and fallback behaviour
When an AI provider is unavailable or unconfigured:
| Capability | Behaviour |
|---|---|
| Smart Extract | The extraction job records an error with a code; the session shows failed. Requirements can still be imported or authored manually |
| Change classification | The event appears without a summary and is fully triageable |
| Mapping proposal | Unavailable. Manual proposal is unaffected |
| Adequacy check | Unavailable. Manual adequacy assessment is unaffected |
| Advisory drafts | Unavailable. All records can be authored manually |
| Assistant | Unavailable |
No governed workflow depends on AI availability
Every approval chain, every register, every determination and every report works with AI entirely disabled.
This is worth verifying during evaluation: turn the AI entitlement off and confirm the platform still runs your compliance programme. It does.