Skip to main content

AI Features

ConcertoGRC integrates AI throughout the platform to accelerate compliance work -- analyzing documents, suggesting remediation plans, drafting policies, mapping evidence, and generating reports. AI assists but never replaces human judgment; all AI-generated content is presented as suggestions for your review.

See AI Model Cards for detailed governance controls, guardrails, and safeguards for each AI capability.

Feature Catalog

ConcertoGRC includes 36 AI-powered features across four categories. Each feature can be individually enabled or disabled, and administrators can configure models and prompt templates per feature.

Orchestrator

FeatureDescriptionDefault Model
Orchestrator QueriesConversational AI for status lookups, complex reasoning, actions, reports, and compliance guidance. Streaming responses.Claude Sonnet 4.5

Auto-Suggest

FeatureDescriptionDefault Model
EmbeddingsVector similarity search across controls, evidence, and policies for intelligent mapping suggestionsTitan Embeddings V2
Explanations"Why?" explanations for suggested mappings between controls, evidence, and other recordsClaude Haiku 4.5
Migration Field MappingColumn-to-field mapping suggestions during data migration wizard importsClaude Haiku 4.5

Analysis

FeatureDescriptionDefault Model
Vendor URL DiscoveryAuto-discovers vendor website, trust center, and privacy policy URLsClaude Haiku 4.5
Vendor Due DiligenceAnalyzes vendor questionnaire responses and generates risk assessmentsClaude Sonnet 4.5
Vendor Legal ReviewAnalyzes vendor documents through a legal lens -- privacy, terms of service, data processing, and regulatory concernsClaude Sonnet 4.5
Questionnaire ReviewAI-assisted review and scoring of questionnaire responsesClaude Sonnet 4.5
Risk RemediationGenerates remediation plans and treatment suggestions for identified risksClaude Haiku 4.5
Document AnalysisAnalyzes uploaded documents for compliance evidence and completenessClaude Sonnet 4.5
Evidence MappingMaps evidence artifacts to framework controlsClaude Haiku 4.5
Evidence ReviewReviews evidence artifacts against control requirements for external audit assessmentsClaude Sonnet 4.5
Task PrioritizationCompliance-aware rationale for dashboard task priority rankingsClaude Haiku 4.5
Security AnalysisAnalyzes network security group rules for misconfigurations and compliance risksClaude Haiku 4.5
Infrastructure RemediationGenerates step-by-step remediation guidance with AWS CLI commands for infrastructure findingsClaude Haiku 4.5
Transcript AnalyserParses compliance meeting transcripts into categorized, actionable suggestionsClaude Sonnet 4.5
Commitment ExtractionExtracts security and compliance commitments from customer contracts with source-clause traceabilityClaude Sonnet 4.5
Contract Text OCRText extraction from contract documents using AWS Textract for scanned/image-based PDFsTextract
PIA Gap AnalysisIdentifies privacy regulation compliance gaps across GDPR, CCPA, and ISO 27701Claude Sonnet 4.5
Scan Finding AnalysisPlain-language explanation of vulnerability scan findings with impact assessment and remediation guidanceClaude Haiku 4.5

Generation

FeatureDescriptionDefault Model
Policy DraftingGenerates or reviews policy documents based on framework requirements. Streaming.Claude Sonnet 4.5
Report NarrativeDrafts executive summaries and compliance report narratives. Streaming.Claude Sonnet 4.5
Initiative Status UpdateGenerates concise status updates for initiatives based on description and supporting tasksClaude Haiku 4.5
AI Generate (General)General-purpose generation via the prompt template systemClaude Sonnet 4.5
Policy Variable SuggestionsAnalyzes policy template content and suggests where text should be replaced with template variablesClaude Haiku 4.5
Evidence Gap SuggestionDrafts evidence requests for framework controls that lack evidence mappingsClaude Haiku 4.5
Activity GenerationDrafts recurring activity definitions for framework controls without activity mappingsClaude Haiku 4.5
Assessment Finding GenerationAI-assisted drafting of formal assessment findings from auditor descriptionsClaude Haiku 4.5
BIA Environment ImportGenerates BIA records from environment descriptions with vendor/risk/dependency linkingClaude Sonnet 4.5
Risk Register GenerationGenerates risk register records from environment descriptions with framework control mappingClaude Sonnet 4.5
AI WorkspaceGeneral-purpose AI assistant with document upload, analysis, and streaming chatClaude Sonnet 4.5
PIA Section DraftingDrafts responses for privacy impact assessment sections given vendor contextClaude Sonnet 4.5
Training Content GenerationGenerates complete training modules with slides, quizzes, scenarios, and artifactsClaude Sonnet 4.5
Infrastructure Diagram -- AI GenerateGenerates network infrastructure diagrams from text descriptions. Streaming.Claude Sonnet 4.5
Infrastructure Diagram -- ImportExtracts infrastructure components from uploaded PDF or image diagrams and reconstructs as a canvasClaude Sonnet 4.5
Customer Notification DraftAI-generated customer notification drafts personalized to tier, contractual language, and incident detailsClaude Sonnet 4.5

AI Workspace

The AI Workspace provides a conversational interface for compliance queries, document analysis, and data lookups with streaming responses. Upload documents for analysis, ask questions about your compliance program, and get help with any task.

AI Workspace chat interface

Conversations are saved automatically and can be resumed later. The workspace supports file uploads for document analysis and provides context-aware responses based on your organization's data.

Models

ModelProviderUse Cases
Claude Sonnet 4.5Anthropic via AWS BedrockComplex analysis, document review, detailed generation, streaming tasks
Claude Haiku 4.5Anthropic via AWS BedrockHigh-volume field suggestions, quick mappings, lightweight analysis
Claude Sonnet 4Anthropic via AWS BedrockAvailable alternative for complex tasks
Claude Opus 4.6Anthropic via AWS BedrockHighest quality for critical assessments and board-level reports
Titan Embeddings V2AmazonVector embeddings for similarity search across compliance records

All AI processing is performed via Amazon Bedrock within AWS. Your data is not used to train AI models and is not retained by the model provider beyond the request lifecycle.

Transparency and Human Oversight

  • All AI-generated content is clearly marked with the ConcertoGRC AI icon
  • The platform never auto-applies AI suggestions without human confirmation
  • You always have the opportunity to review, edit, or discard AI output before it affects any record
  • Every AI invocation is logged with full audit trail (input, output, model, user, timestamp)
  • AI features can be globally enabled or disabled per organization
  • Access can be restricted to platform operators only or opened to all users

Configuration

Administrators can configure AI behavior from Settings → AI. Each feature is represented as a card showing the feature name, description, assigned model, and current status.

AI feature configuration cards in Settings

Configuration options include:

  • Enable/disable individual features with toggle switches
  • Model selection per feature (where multiple models are supported)
  • Prompt templates with {{variable}} placeholders populated from record fields
  • Inference settings -- max tokens and temperature overrides per feature
  • Category filtering -- filter by Orchestrator, Auto-Suggest, Analysis, or Generation

Tenant administrators can view feature configurations and, when permitted, customize prompt templates for their organization while inheriting platform defaults.

See AI Configuration for detailed setup instructions.