Skip to content

AI Feature Inventory

A complete list of the AI-assisted capabilities in OrviQ, and the governance around each.

Every entry follows the same pattern: AI produces something non-authoritative; a person with a different permission adopts it or does not.


Regulatory and compliance

CapabilityTriggerProducesGeneration permissionAdoption
Regulatory change classificationA source sweep detects a changeA summary and suggested classification on the change eventreg_intel.sweepHuman triage, reg_intel.triage
Smart ExtractA person runs the wizard on a documentCandidate requirements with source text and provenancelibrary.smart_extractHuman review and publication
Applicability rationaleA person requests a draft on an applicability recordDraft justification wording, and a suggested statuscompliance.read plus AI entitlementHuman sets the status; approval by compliance.validate
Requirement assurance rationaleA person requests a draft on a requirement reviewDraft review rationaleai.use plus AI entitlementHuman review sign-off, assurance.review

Controls and assurance

CapabilityTriggerProducesGeneration permissionAdoption
Control discoveryA person searches for candidate controlsA ranked list — creates nothingmapping.discoverNot applicable
AI mapping proposalA person runs a comparison passMappings in proposed status with relationship, rationale and confidencemapping.ai_proposemapping.review
Control extractionA control source document is ingestedCandidate controls with confidence bands and source lineagecontrol_source.ingestcontrol_source.publish
Design adequacy checkA person runs the check on an approved mappingA draft recommendation onlyadequacy.runadequacy.submit, then adequacy.review
Expected evidence suggestionGenerated from an approved adequacy assessmentRecommended expected-evidence requirementsexpected_evidence.ai_suggestexpected_evidence.accept

Risk and remediation

CapabilityTriggerProducesGeneration permissionAdoption
Exception justificationA person requests a draftDraft justification wordingai.use plus AI entitlementHuman submits; exception.approve decides

Audit and inspections

CapabilityTriggerProducesGeneration permissionAdoption
Audit assistanceA person requests it during fieldworkDraft procedures, workpaper summaries, draft finding wordingaudit.ai_assistHuman authorship; audit.engagement_review
Inspection candidate extractionA person runs extraction on an examination reportCandidate observations with source location and confidenceinspection.extractinspection.canonicalize
Inspection response draftA person requests a draftDraft response wordinginspection.ai_assistinspection.signoff

Resilience

CapabilityTriggerProducesGeneration permissionAdoption
Scenario generationA person requests itDraft exercise scenariosbcm.ai_assistHuman authorship; bcm.exercise_signoff
BIA impact suggestionsA person requests itDraft impact assessmentsbcm.ai_assistHuman authorship; bcm.bia_approve
Gap analysis draftA person requests itDraft gap narrativebcm.ai_assistHuman authorship

Incidents

CapabilityTriggerProducesGeneration permissionAdoption
Incident summaryA person requests itDraft executive summaryincident.ai_assistHuman authorship
Classification suggestionA person requests itSuggested classification with reasoning and an advisory noticeincident.ai_assistincident.manage sets it
Investigation questionsA person requests itStructured inquiry prompts, five-whys and timelineincident.ai_assistHuman investigation
Root-cause hypothesesA person requests itCandidate causes across process, control, human and technical factorsincident.ai_assistincident.investigate records the cause
Lessons learned draftA person requests itPreventive recommendationsincident.ai_assistHuman authorship

The Assistant

CapabilityTriggerProducesGeneration permissionAdoption
OrviQ AssistantA person asks a questionAn answer with citations, grounded in product knowledge and permitted tenant dataai.use plus AI entitlementNot applicable — the Assistant takes no governed action

See the Assistant section for detail.


What is not AI

For completeness, these are deterministic and involve no model:

  • Indicator evaluation and result status
  • Control effectiveness derivation
  • Requirement satisfaction derivation
  • Evidence coverage calculation
  • Freshness evaluation
  • Policy comparison
  • Historical reconstruction
  • Business reference generation

Failure and fallback behaviour

When an AI provider is unavailable or unconfigured:

CapabilityBehaviour
Smart ExtractThe extraction job records an error with a code; the session shows failed. Requirements can still be imported or authored manually
Change classificationThe event appears without a summary and is fully triageable
Mapping proposalUnavailable. Manual proposal is unaffected
Adequacy checkUnavailable. Manual adequacy assessment is unaffected
Advisory draftsUnavailable. All records can be authored manually
AssistantUnavailable

No governed workflow depends on AI availability

Every approval chain, every register, every determination and every report works with AI entirely disabled.

This is worth verifying during evaluation: turn the AI entitlement off and confirm the platform still runs your compliance programme. It does.

See AI Provider Diagnostics.


OrviQ Enterprise Governance, Risk & Compliance Platform