Exemplary AIEnterprise
For creatorsDemoBook a demo
Compliance & Risk

Find the controls with nothing behind them.

It is not a question a search box can be asked. Frameworks point at controls, controls need evidence, risks need controls that hold. The links between them live in a spreadsheet. Exemplary AI holds all of it as one graph you can walk.

Talk to us
20+ frameworksEvidence stays on your infrastructureFull audit trail
SOC 2 Type II
CC6.1
CC6.2
CC6.3
CC7.1
CC7.2
CC7.3
CC8.1
CC9.1
CC6.3 · CC8.1 — nothing attached. CC6.1 — evidence predates the review window.Found by walking framework → control → evidence. A search box cannot be asked this.
  1. Framework
  2. Controls
  3. Evidence
  4. Check freshness
  5. Find gaps
  6. Next actions
The mapping gap

Compliance is a mapping problem wearing a document costume.

The artifacts almost always exist, and so does the risk register. What is missing is the structure that connects them to the thing they are supposed to prove.

Evidence exists; the mapping does not.

The exports were pulled and the screenshots were taken. Which clause each one actually satisfies lives in a spreadsheet, or in the head of the person who collected it.

Search cannot answer the real question.

“Which controls have no evidence” is not a keyword. No single document contains the answer — it has to be traversed across three kinds of thing at once.

The risk register lives somewhere else entirely.

Risks sit in one file, the controls meant to mitigate them in another, the issues raised against them in a third. When a control fails, nothing tells you which risks just got worse.

Posture is a point in time.

You knew exactly where you stood the week of the audit. The eleven months in between are a matter of faith, and faith is what findings are made of.

Ask the graph

The same graph answers the auditor and the risk committee.

Posture, evidence, gaps and risk are not four tools bought separately. They are four questions asked of one structure, which is why the answers agree with each other.

Control pathIllustrative
Framework
Control
Pick a framework
Evidence
  •  

The same walk, whichever framework is asking.

Where you stand across the frameworks you are actually held to: not a score, but a live view of which controls are evidenced, which are stale, and which have never had anything attached. Built from the same graph the evidence lives in, so it is current by construction, not by memory.

PostureIllustrative
  • SOC 2 Type IImost controls2 gaps, 1 stale
  • ISO 27001most controls2 unevidenced
  • GDPRall mappedcurrent

A live view of the graph, not a score someone refreshed last quarter.

One audit request

The auditor asks for evidence of your access reviews.

Five steps, and the fifth one is the auditor — because nothing on this page replaces them, and any product that claims otherwise is selling you a finding. The same five steps run for an ISO 27001 clause, a PCI requirement or an Article 30 record; only the framework changes.

  1. Asked

    The request arrives in framework language.

    Not “send me the access reviews” but a criterion reference. The agent resolves it to the controls your organisation has mapped to that criterion.

  2. Traversed

    The graph walks from criterion to artifact.

    Framework → control → evidence, following relationships rather than matching strings. The same walk works the week after you adopt a framework you have never been audited against.

  3. Assembled

    The artifacts come back as a set.

    The quarterly export, the approval record, the policy version in force at the time — each with the date it was collected and the control it was mapped to.

  4. Flagged

    So does what is missing.

    One control in the set has evidence that predates the review window. The agent says so plainly instead of returning three artifacts and letting the fourth be discovered later.

  5. Judged

    The auditor decides whether it is sufficient.

    The platform produced the evidence and the map. Whether it satisfies the criterion is a professional judgement, and it stays one.

What it opens

The second framework costs a fraction of the first.

Evidence mapped once is mapped to everything it satisfies. When a customer contract asks for ISO 27001 on top of SOC 2, you start from the overlap, not a blank collection plan. Because posture is built from the same graph, you can say where coverage stands the day you are asked, not a quarter later.

Say yes to a framework inside a sales cycle rather than a planning cycle.

Answer a customer's security questionnaire from the graph rather than from memory.

Walk into the audit already knowing what the auditor is going to find.

Evidence custody

The evidence of your controls should not need a third party.

There is a particular absurdity in shipping your security evidence to an external processor in order to demonstrate that you control where your data goes.

Evidence never leaves the environment

Exports, screenshots, policies and approval records stay inside your infrastructure. The model comes to them; they are never transmitted out for inference.

One fewer processor to disclose

No external sub-processor means nothing new to add to the register, the DPA or the vendor-risk review — which is usually the longest part of adopting anything here.

The trail is the product

Every retrieval, mapping and change is logged against the user and the artifact. The record of how a conclusion was reached is itself evidence.

SOC 2 Type II, HIPAA, GDPR-ready and ISO 27001 — the frameworks we are held to, and the ones the platform helps you evidence.

SOC 2 Type IIAICPA
HIPAACompliant
GDPRReady
ISO 27001Certified
The structure

Native compliance tools, on a graph.

The structure is the feature here. The Knowledge Graph is not an implementation detail: it is the reason a question about coverage has an answer at all.

Structure
Knowledge Graph entities, relationships and traversal
Native tools
Posture, next actions, control summaries, path traversal
Risk
Risks, issues and third-party assessments as graph entities
Evidence store
Filestore folders, watched sync, upload or API
Reading
OCR and indexing across exports and policy documents
Monitoring
Scheduled automations with full run history
Access
IAM roles and policies — deny overrides allow
Trail
Audit logging across retrieval, mapping and approval
Coverage
20+ compliance frameworks
Deployment
On-premise, private cloud or air-gapped
Go deeper:Knowledge GraphGroupsManagementAnalytics
Common questions

What compliance and risk teams ask first.

See Exemplary AI in action

Book a demo and we'll show you purpose-built agents grounded in your own knowledge — deployed on your infrastructure.

Book a demo
Exemplary AIEnterprise

Agentic AI for the enterprise — installed inside your network.

  • Sovereign deployment
  • Purpose-agnostic agents
Book a demo

Build

  • Agents
  • Model Hub
  • Knowledge Graph
  • File store

Connect

  • Integrations
  • Chatbots
  • Browser Extension

Govern

  • Management
  • Groups
  • Analytics

Company

  • About Us
  • Exemplary for creators
  • Book a demo

Use cases

By industry
  • Healthcare
  • Government
  • Financial services
  • Legal
  • Media
By department
  • Customer Support
  • IT & Engineering
  • Human Resources
  • Finance & Procurement
  • Compliance & Risk

© 2026 Exemplary AI. All rights reserved.

  • SOC 2 Type II
  • HIPAA
  • GDPR-ready
  • ISO 27001