What we tell people who ask whether AI belongs in compliance work
The honest answer is that it belongs in the reading and nowhere near the deciding. Here is where we draw that line and why we draw it there.
Read the articleMost teams prepare for the wrong conversation. A regulator is not testing whether you are perfect. They are testing whether you know where you stand and can show your working.

There is a particular kind of nervousness that arrives a few weeks before a regulatory engagement. It is usually spent on the wrong thing.
Teams polish. They tidy the register, soften the language on the open items, and rehearse the answers that make things sound settled. It is completely understandable, and it is close to the worst possible preparation, because the thing being assessed is not whether you are in good shape. It is whether you have an honest and current picture of your own position.
Those are different tests, and only one of them is winnable.
When an assessor asks about a control, they are rarely interested in the control on its own. They are working out three things.
Do you know what your actual state is. Do you know how you got there. Can somebody here account for the decisions that were taken.
An organisation with eleven open gaps, each with an owner, a date and a reason, reads as being in control. An organisation with two open gaps and no explanation for how the other forty closed reads as one that has not looked carefully. The second one has the better numbers and the worse position, and experienced assessors can tell the difference within an hour.
Nobody has ever been penalised for having a gap they understood. The trouble starts with the gap that surprised everyone in the room.
The evidence exists but cannot be produced. Somebody did the work. The proof is in a folder, in a chat thread, or in the head of a person who is on leave. From the assessor's side, that is indistinguishable from the work not having happened.
Closure with nothing behind it. An item was marked complete because a project ended, not because anybody verified the outcome. The follow up question is always the same. Who confirmed this, and what did they look at.
The document and the practice have drifted apart. The policy says quarterly. The team does it monthly, which is better, but the record says quarterly and the evidence shows monthly. Now you are explaining a discrepancy instead of a strength.
Ownership that evaporated. A control belongs to a role that no longer exists, or to somebody who changed teams eighteen months ago. Nobody noticed because nothing in the process was watching for it.
Run the exercise on yourself, honestly, a month out.
Pick ten controls at random. Not the ten you feel good about. Random. For each, try to answer four questions without contacting the owner.
Whatever you cannot answer is what the assessment will find, and you have just found it first, which is an enormously better position. Fixing four of those in a month is real progress. Rehearsing better answers for all ten is not.
The instinct is to keep difficulty out of the record. It is the wrong instinct.
A known gap, written down, with an owner and a target date and a note explaining why it is not resolved yet, is evidence of governance working. The same gap, unrecorded, discovered by somebody else, is evidence of governance failing. The gap is identical. The record is what differs, and the record is the entire subject of the assessment.
This is one of the reasons we build the way we do. In CyberNexus, a control does not close because a task finished. It closes against evidence that a named reviewer accepted, and the history of how it got there stays attached. Not because it is elegant, but because the alternative leaves you unable to answer the one question that matters most, which is who decided.
If you are building a programme from a standing start, the NIST Cybersecurity Framework is a reasonable structure for the conversation with leadership, and ISO/IEC 27001 is the common reference where certification is the goal. The UK National Cyber Security Centre publishes some of the plainest written guidance available anywhere, and it is worth reading even where its jurisdiction does not apply to you.
Where an organisation answers to more than one of these at once, the duplication becomes the dominant cost, which is the problem ControlGraph exists to hold.
Go in knowing your own position better than the person assessing it. Be able to show your working. Do not hide the open items, own them.
An assessor who believes you know where you stand will spend the day confirming it. One who suspects you do not will spend the day finding out, and that is a much longer day for everyone.
Whether you know your own position, how you got there, and whether somebody can account for the decisions taken. Not perfection. An organisation with eleven understood gaps reads better than one with two gaps and no explanation for how the rest closed.
Yes, with an owner, a date and a reason. A known gap written down is evidence of governance working. The same gap unrecorded and discovered by somebody else is evidence of governance failing, and the gap itself is identical.
Run it on yourself a month early. Pick ten controls at random, not the ten you feel good about, and try to answer what is in place, what proves it, who confirmed it and what would tell you if it stopped being true, without contacting the owner.
Evidence that exists but cannot be produced. Somebody did the work and the proof is in a folder, a chat thread or the head of a person on leave. From the assessor's side that is indistinguishable from the work not having happened.

The honest answer is that it belongs in the reading and nowhere near the deciding. Here is where we draw that line and why we draw it there.
Read the article
They are not competing standards and you are not really choosing between them. One is a certifiable management system, the other is a way of describing where you stand. Here is how to tell which you need first.
Read the article
The phrase is used to sell dashboards. What it really describes is a change in when evidence is produced, and that change is the only part that matters.
Read the articleIf this raises a question about your own compliance position or your security operations, the quickest route is a direct conversation.