AI Assistance for Controls
Enterprise Feature
AI Assistance for Controls is available exclusively in OpenGRC Enterprise. Learn more about Enterprise.
OpenGRC Enterprise adds an AI Assistant to every control, available from the control's detail page. It helps close the gap between what a control requires and what your organization already has in place, by suggesting implementations to map or create, and by assessing whether your existing implementations actually meet the control.
Overview
The AI Assistant helps organizations:
- Get concrete implementation guidance -- policies, processes, and technical measures -- for satisfying a specific control
- Discover existing implementations in their library that could be mapped to the control
- Surface work they may already be doing that isn't documented as a formal implementation yet
- Get an AI-generated assessment of whether their mapped implementations meet the control's requirements
How It Works
Click AI Assistant on a control's detail page to choose one of two actions: Suggest Implementations or Assess Implementations.
Suggest Implementations
Suggest Implementations reviews the control and your organization's existing implementation library, then returns three things:
- Implementation Guidance -- general recommendations for meeting the control, grouped into Policies, Processes, and Technical Implementations
- Suggested Implementations -- existing implementations from your library that could satisfy the control, each with a relevance rating (e.g. High or Medium relevance) and a short explanation of why it applies. Review each suggestion and click the checkmark to approve it or the X to reject it -- nothing is mapped to the control until you approve it
- New Implementations to Consider -- implementations that don't exist in your library yet, but that your organization may already be doing without documenting. Click + to create one (it's added to your implementation library as Not Implemented and mapped to this control) or X to dismiss it
Assess Implementations
Assess Implementations reviews the implementations currently mapped to the control and returns:
- Conclusion -- a summary determination, such as "Meets Requirements"
- Justification -- an explanation of why the mapped implementations do or don't satisfy the control
- Recommendations -- suggested next steps to strengthen or close gaps in coverage
Every AI Assistant response includes a disclaimer that it was generated by AI and should be reviewed for accuracy before use.
Best Practices
- Run Suggest Implementations before building a control from scratch -- it's often faster to review and approve suggestions than to write implementations manually
- Review relevance ratings critically -- treat High relevance suggestions as a strong starting point, but confirm they reflect what your organization actually does
- Use New Implementations to Consider to close documentation gaps -- it's a fast way to formally document work your team is already doing
- Re-run Assess Implementations after mapping new implementations -- to confirm the control's requirements are now met
- Treat AI output as a draft, not a final answer -- always review the justification and recommendations before relying on them for an audit
Permissions
- The AI Assistant is available to any user who can edit the control, subject to your organization's AI usage settings
- AI Assistant actions consume AI tokens, which count against your organization's AI quota. Monitor usage in Settings > AI