
AI now drafts policies, assembles evidence and answers security questionnaires, and auditors accept AI-assisted work when a named human attests to it. The deeper change is that compliance has acquired a new object. With ISO/IEC 42001 certifiable since December 2023, the AI you use to comply is also something you must govern.
What compliance work does AI do well today?
AI is genuinely good at three compliance jobs: drafting documents, mapping controls between frameworks, and answering security questionnaires from an existing evidence base. Those three share a property. The source of truth already exists somewhere, and the AI is transforming it rather than inventing it.
Drafting is the most visible win. A first-draft information security policy scoped to your actual stack used to mean a consultant's template and a fortnight of edits. Now it takes an afternoon of review. The draft is rarely right, but it is a competent starting point, and starting points were most of the cost.
Mapping is the quieter one. If you hold ISO 27001 and a customer asks for SOC 2, someone has to work out which of your existing controls satisfy which criteria in the new framework. That used to be days of spreadsheet work by whoever knew both standards. AI does a credible first pass in minutes. A human then checks the edge cases instead of building the whole matrix by hand.
Questionnaires are where founders feel it most. A 300-question security questionnaire from an enterprise prospect used to stall a deal for weeks. AI that retrieves answers from your approved answer library (previous responses plus current policies) can produce a reviewable draft in an hour. The keyword is retrieves. It works because the answers already exist and were checked once by a person.
What do auditors accept?
Auditors accept AI-assisted policies and evidence when a named human has reviewed the material and attests to it. Published audit-body statements converge on the same position: the method of production is not the audit question. Accountability is.
An auditor has never cared whether your access control policy was typed or adapted from a template. They care whether it describes what you actually do, and whether the person who owns it can answer questions about it in interview. AI drafting changes none of that. What carries audit weight is the attestation itself: a named person and a review date.
In practice this means keeping review records alongside AI-assisted documents. When the auditor samples your policies and asks the owner what a clause means, "the tool wrote it" is not an answer that survives the interview. "I reviewed it in March, and that clause covers our contractor offboarding" is. The bar has not moved. The work of clearing it has shifted from writing to reviewing.
The corollary is worth stating plainly. An unreviewed AI-generated document is not evidence of anything. It is a liability with formatting.
What breaks when you over-automate?
Three failure modes account for most AI-related compliance damage: hallucinated controls, unowned policies, and evidence nobody read. All come from the same mistake, which is treating generation as the finish line rather than the starting gun.
Hallucinated controls are the sharpest risk. Ask a general-purpose model to describe your encryption practices and it will describe encryption practices. Plausible ones. Possibly not yours. If that answer goes into a questionnaire, you have made a false representation to a customer. If it goes into a policy, you are now non-conformant against your own document: a generated policy that promises quarterly access reviews you never run is a finding waiting for its audit.
Unowned policies are subtler. AI makes it cheap to produce a complete policy suite in a week, so teams do, and end up with a shelf of documents no individual has actually read, let alone owns. The first auditor interview exposes this immediately. A policy without an owner who can speak to it is worse than a gap, because a gap is honest.
Evidence nobody read completes the set. Automated collection can pull screenshots and log exports into an audit folder continuously, which feels like progress. If no human reviews the pile, contradictions ship straight to the auditor: the exported user list that still includes the contractor your offboarding policy says was removed, or the backup log that quietly stopped in April. Automation raised the volume of documentation. Your review capacity is now the constraint, and pretending otherwise is how clean-looking programmes fail messy audits.
How does AI become a compliance object itself?
The AI you use has itself become something to govern. ISO/IEC 42001, the management system standard for AI, has been certifiable since December 2023, which means "how do you manage your AI?" now has a formal, auditable answer.
You do not need certification to feel the pull. Enterprise questionnaires increasingly include an AI section asking what models you use and what data they touch. If AI drafts your policies and answers your questionnaires, then your compliance tooling needs a named owner and a risk assessment of its own, and customers who ask deserve a straight answer about it. The loop closes. The system that helps you comply is in scope for the compliance it helps produce.
Australia has signalled the same direction locally. The Department of Industry, Science and Resources published the Voluntary AI Safety Standard in September 2024, a set of voluntary guardrails for organisations deploying AI. Voluntary is the operative word, for now. The standard reads as a preview of where Australian regulation is heading, and an organisation that adopts the guardrails early is doing what early ISO 27001 adopters did. They built the muscle before any obligation arrived.
The practical starting point is unglamorous: a register of where AI is used in your organisation and what data each use touches, with a named owner for every entry. ISO 42001 starts by asking for that list, and so does the DISR standard. Your customers' questionnaires are getting there too.
Keeping that thread straight is register work: which documents were AI-assisted, and which named person attested to each. That is the kind of record Zavior is built to hold.
Frequently asked questions
Will auditors accept AI-written policies?
Yes, provided a named human has reviewed the policy and attests to it. Audit bodies assess whether the document reflects reality and whether its owner can speak to it in interview, not how the first draft was produced. An AI-drafted policy with no accountable reviewer will fail; a reviewed one is treated like any other.
Can AI answer security questionnaires safely?
Yes, when it retrieves answers from an approved and current answer library and a human reviews the output before it is sent. It becomes unsafe when the model generates answers from general knowledge, because it will confidently describe controls you do not operate. A questionnaire answer is a representation to a customer, so the pre-send review is non-negotiable.
Does using AI create new compliance obligations?
Increasingly, yes. ISO/IEC 42001 has made AI governance certifiable since December 2023, and Australia's Voluntary AI Safety Standard (September 2024) signals where local regulation is heading. Customers already ask about AI use in due diligence, so at minimum you need a register of the AI systems you use and the data they touch, with a named owner for each.
Zavior · Cyber Security
AI can draft the policy and answer the questionnaire, but it cannot run the controls those documents promise. Zavior does the security work most Australian SMEs keep deferring, then hands you a cyber hygiene report you can put in front of a board or a big customer. When something looks wrong, a real person is watching.
Book a free 30-minute business assessment →This is general information, not legal advice.