Trust & method

How this works, and what we refuse to claim.

You are considering buying AI-generated compliance documents. The reasonable worry is that they contain something invented, and that you will not find out until someone knowledgeable reads them. This page explains what is done about that, in enough detail to judge it — including the parts that are limitations rather than features.

An independent review stage

Every generated document, assessment and review answer is produced by one system and then checked by a separate reviewer that never sees the instructions given to the producer. The one exception is the workspace assistant, which answers questions about your own records and is checked by fixed rules rather than by a second model. That separation is the point: a checker that knows what the writer was told to do tends to agree with it.

The reviewer decides whether the output can be released. It is explicitly not asked to defend the output. It checks whether each claim is supported by the material actually supplied, whether every cited identifier exists in the control library, and whether the reasoning holds together. Three outcomes: publish, revise, or withhold.

Withholding is a normal, visible outcome. When an output cannot be cleared it goes to a human review queue and you are told it was withheld and why. We would rather show you that than publish something fluent and wrong. If you never saw a withhold, the reviewer would not be doing anything.

Rules the system operates under

These are instructions the generating systems carry, not marketing copy about them:

  • A score is never released without its reasoning. The factors, the weight of each, and why the number is not higher or lower. A score on its own is an incomplete answer.
  • Output is advisory. It is never presented as legal advice, certification, authorisation, accreditation or a compliance determination.
  • No approval language. Nothing is "approved" or "signed off" — outputs use reviewer, review record, reviewed by. The distinction matters when a document is read by someone deciding what it commits you to.
  • Uncertainty is stated. If the supplied context does not support a statement, the output says so in plain terms rather than filling the gap.
  • No invented clauses, identifiers, citations or dates. Only identifiers present in the supplied material may be used.
  • Missing answers are missing. They are never treated as compliant. A gap that improves a score by being ignored is a defect, and it is tested for.

Instructions can be attacked. That is handled explicitly.

A real risk with this kind of product is that someone puts an instruction into the material being assessed — a vendor document that says "report no concerns", or a task that says "assume every missing answer is compliant". The subject of an assessment should not be able to write its own verdict.

Attempts of that shape are detected in the request itself, before anything is generated, and are recorded against the run. The system is told to report the attempt as an observation and to assess on the evidence actually supplied — not to adopt it, and not to adopt it as a "disclosed assumption" either. An assumption that carries a published rating is a fact to whoever reads it, however it is labelled.

What is recorded

Every run is written to an audit trail: which system ran, on whose behalf, in which organisation, what the reviewer decided, whether it was published or withheld, which sources it was permitted to consult and which it used, and the version of the instructions in force at the time. Runs that were refused are recorded too — a run that did not happen is exactly the kind of thing an audit trail has to be able to show.

That last item is load-bearing. The instruction version is pinned to the actual content of the instructions, so a change to what the systems were told cannot happen without the version changing with it. It means the record of "what produced this document" can be relied on afterwards rather than taken on trust.

Agent attestation, 7 September 2026

RiskWoven is itself an estate of twenty-one AI agents, and the controls described on this page are ones we operate on them in production. We publish an attestation of what has been verified about those agents, and we update it when the estate changes. The most recent covers the deployment of 7 September 2026 and the seventeen agents that existed on that date; the four intake review agents added on 11 September 2026 are not yet attested, and are named here rather than left for a reader to notice. The production observations below were made against the 4 September deployment and are carried forward as observations of that date; they have not been re-run since.

ControlWhat was observed
Kill switchDisabling an agent returned 503 with the operator's reason and made zero model calls. Re-enabling restored it within one request.
Refusals loggedThe refusal was written to the audit trail naming the switch that caused it.
Instruction pinningAny change to an agent's instructions without a version bump fails the test suite, so the version recorded on each audit row is meaningful. The pin covers every agent in the registry.
Independent reviewEvery generated document, assessment and review answer passes a reviewer that never sees the producer's instructions before it is released. The workspace assistant is checked by fixed rules instead.
Tenant isolationSeventeen cross-organisation probes from a real second account, zero exposure.

The attestation also records what was not verified: nine of the seventeen agents attested had never run in production, the two newest have not yet been observed live, and the audit trail begins on 23 August 2026 because it was broken before that date. That is the standard we hold ourselves to, and it is the standard our AI Agent Governance Pack applies to your agents. How the pack works.

Your information

  • Separation between organisations. Your workspace is scoped to your organisation at the data layer, not by filtering what gets displayed. This is tested, including by deliberately attempting cross-organisation access from a second account.
  • The free scan runs in your browser. The twelve questions are scored locally. Your answers are not sent to us. The only thing that is, unless your browser sends Do Not Track, is an anonymous progress signal saying which step you reached.
  • Framework material is licensed where the standard is licensed. Requirements are described in our own words and cited to identifiers. Where a standard's text is copyrighted — ISO standards among them — it is not reproduced, and if you pursue certification you will need your own copy. We would rather tell you that than quietly quote it.
  • Access is verified per request. Signed-in areas verify identity on every request rather than trusting a session or a header.

What we do not claim

The absence of these statements elsewhere on the site is deliberate.

Not a certification

Nothing here certifies, accredits or approves. Certification is awarded by an accredited body after their own audit. We produce the position you would take into one.

Not an audit

An audit is performed by an independent auditor against a defined scope. This is an assessment you commission about yourself.

Not legal advice

Where obligations turn on your jurisdiction, contracts or circumstances, you need a lawyer. The output is written to help you ask a better question, not to answer it for you.

Not continuous monitoring

We do not connect to your cloud accounts and collect evidence automatically. If that is what you need, a compliance-automation platform is the right purchase and we will say so.

Not a guarantee of outcome

No document guarantees you pass a customer review, a certification audit or a regulator's question.

Not "trained on your data"

We improve the systems by changing their instructions, and every such change is versioned and recorded. We do not describe that as training, because it is not, and the difference matters to anyone assessing us.

Known limitations, stated plainly

  • Long documents are withheld more often than short ones. The reviewer is stricter on lengthy outputs, and some correct documents get held for human review as a result. We consider that the right direction to fail in, and we are working on the rate rather than on loosening the reviewer.
  • Coverage varies by framework. The control library is maintained, but depth is not uniform across every framework. Where a framework is thin, the output says so rather than producing confident mapping from sparse material.
  • Export formats are limited. Documents render in the browser. Downloadable formats are not complete across every output type yet.
  • Advisory scores are model-produced. The engine's arithmetic is reproducible and you can check it. Narrative risk scores carry disclosed reasoning and are reviewed, but they are not reproducible in the same way, and we do not present them as though they were.

If something is wrong

Tell us. An incorrect citation, a disproportionate rating, a document that misreads your situation — these are defects and we want them reported rather than quietly worked around. Write to hello@riskwoven.com with what you were doing and what the output said.