ISO/IEC 17020 accredited inspection body · Cleared facility (FCL)
Home / AssessIQ

AI-native assessment platform

AssessIQ

The assessment execution platform for FedRAMP, FISMA, DoD SRG, NIST SP 800-171 and FedRAMP 20x engagements. Built by assessors, for the assessment firm.

What it is

The assessor keeps the judgment. The platform removes the reading.

AssessIQ reads a system’s evidence corpus, drafts every Examine, Interview and Test write-up in plain assessor language, flags discrepancies across sources, and runs adversarial quality control before the assessor signs.

What it does not do is conclude. Every determination stays with the assessor, procedure by procedure. Assessor edits are locked, so refreshed draft text lands beside your words rather than over them. What comes out of the schedule is the reading, matching and drafting time, which is where the hours actually go.

We built it because we run assessments ourselves. It is in production on live engagements now.

Estimated time saved per engagement
  • 30%FedRAMP Low
  • 35%FedRAMP Moderate
  • 40%FedRAMP High
  • 42%High with a large SSP corpus

Estimated assessor-labor savings against a conventional assessment of the same scope. The advantage grows with the size of the evidence corpus. Assessor review time is unchanged by design.

What it does

Three jobs, run in order, on every engagement.

01

Reads the evidence

  • SSPs, policies, procedures, transcripts, artifacts and screenshots
  • Documents auto-classified by type and scope
  • Per-control evidence pulled from hundreds of pages, with no manual highlight-and-quote
02

Drafts the assessment

  • Examine, Interview and Test write-ups per procedure, determination first
  • Plain assessor language, one house style
  • Evidence requests and interview questions tailored to the corpus
03

Catches errors before delivery

  • Dual-pass adversarial QC on every write-up
  • Discrepancy findings across SSP, interview and test sources
  • Delivery Manager sampling and a tamper-evident audit trail

At a glance

What runs on the platform today.

10Framework configurations
5,262Catalog procedures built in
5,252Curated asks and questions
12Deliverable outputs
Frameworks
  • FedRAMP (NIST 800-53 Rev 5)
  • NIST 800-53 Rev 5 and FISMA
  • NIST SP 800-171 (130 requirements)
  • DoD Cloud SRG (IL4, IL5, IL6)
  • NIST 800-172 and CSF 2.0
  • FedRAMP 20x (Key Security Indicators)
Deliverables
  • SAR and SAP (Word)
  • SRTM, POA&M, RET (Excel)
  • SPRS score sheets
  • Evidence request list and interview bank
  • KSI OSCAL, KSI summary, 20x package
  • Raw assessment workbook
Access & control
  • Four roles with 19 granular permissions
  • Super Admin, Admin, Delivery Manager, Assessor
  • Company-scoped tenant isolation
  • MFA, passkeys and SSO through Entra ID, Okta or Google Workspace

Time recovered

One assessor, one month: 120 of 160 hours back.

Modelled on a NIST 800-53 Rev 5 Moderate baseline of 175 procedures in a 160-hour month, at a five-minute blended review per procedure. The assessor reads each drafted write-up against its cited evidence, then signs or adjusts.

ASSESSOR HOURS PER STAGE, ONE ASSESSOR MONTH Read the package31h8hMap the evidence23h2hWork the interviews16h4hWrite the results58h15hChase inconsistencies8h3hQC the work12h4hAssemble deliverables12h4hCONVENTIONALWITH ASSESSIQ
Assessor hours by stage, conventional against AssessIQ.

A planning model, stated so it can be checked. It is not a time study. Tool processing runs unattended and is not assessor time.

120 hrsRecovered per assessor month
3 of 4Working hours come back
55 14Minutes per procedure, all-in
11.3 minOne five-document evidence delivery

Stage by stage

Where the 120 hours come from.

StageThe workConventionalWith AssessIQSaved
Read the packageTool reads, classifies and maps the corpus; assessor reads per-control summaries31 h8 h23 h
Map the evidenceTool matches artifacts to procedures; assessor spot checks23 h2 h21 h
Work the interviewsTool works transcripts and notes; assessor confirms attribution16 h4 h12 h
Write the resultsTool drafts all 175 write-ups; assessor reviews and signs each58 h15 h43 h
Chase inconsistenciesTool flags cross-source conflicts; assessor adjudicates8 h3 h5 h
QC the workTool runs dual-pass quality check; assessor rules on flags12 h4 h8 h
Assemble deliverablesTool builds SAR, risk table and requirements matrix; assessor reviews12 h4 h8 h
The 160-hour month160 h40 h120 h

Hours are assessor hours. Engagement cadence (standups, briefs, coordination) rides outside both columns. The firm’s independent quality review under its own accreditation sits on top of both and is neither compressed nor counted.

Delivery calendar

A Moderate analysis phase inside 14 business days.

Agencies emulating FedRAMP 20x expect assessment calendars measured in days and weeks, not months. This is a document-based Rev 5 analysis phase meeting that expectation. The ambition is calendar speed rather than feature parity.

Three assessors on dedicated assignment, about 89% loaded. At a ten-minute review the window runs about 17 days. The same dedicated team conventionally needs about 50 business days.

EXECUTE TO DELIVERED RESULTS: NIST MODERATE, THREE ASSESSORS Conventionally about 50 business days for the same dedicated team Before the clockPreparation: corpus stagedDay 1Intake, classification, mapping, drafting run unattendedDays 2–11Per-procedure corroboration across three assessorsDays 12–14QC flags cleared; SAR and matrices reviewed
Execute to delivered results, on the same stage model.

Scale

The saved share holds at every baseline.

ANALYSIS-PHASE HOURS BY BASELINE Estimated; three quarters recovered at every baseline Low966 procedures883 h221 h662 HOURS RECOVEREDModerate1303 procedures1191 h298 h893 HOURS RECOVEREDHigh1463 procedures1338 h334 h1004 HOURS RECOVERED
Analysis-phase hours by baseline, at the same per-procedure pace.

Three quarters recovered at every baseline, so deeper reviews save more hours in absolute terms.

Measured, not modelled

Document analysis times from a live engagement corpus.

Wall-clock times from intake to control-mapped output, recorded by the platform. None of it is assessor time. Processing starts on upload and runs unattended inside the tenant’s selected AI data path.

DocumentPagesTool timeOutput
System access review export1,8192.7 min125 control-mapped evidence pulls
Vulnerability scan evidence export5,8300.6 minIndexed to the scan evidence workflow
Continuous monitoring workbook1382.8 min26 control-mapped evidence pulls
Security program policy214.3 min47 control-mapped evidence pulls
Asset inventory record10.9 min3 control-mapped evidence pulls
One measured delivery7,80911.3 minRead, classified and processed, unattended

Framework coverage

One workflow across every framework you run.

FrameworkCatalogScope tiersDeliverables
FedRAMP (NIST 800-53 Rev 5)2,176 proceduresLow / Moderate / HighSAR, SAP, SRTM, POA&M, RET, raw
NIST 800-53 Rev 5 (non-FedRAMP)2,761 native proceduresLow / Moderate / HighSAR, SRTM, POA&M, raw
FISMANative NIST catalogLow / Moderate / HighSAR, SRTM, POA&M, raw
DoD Cloud Computing SRG800-53 master + 10 GRRsIL4 Mod / IL4 High / IL5 / IL6SAR, SRTM, POA&M, RET, raw
NIST SP 800-171 Rev 3130 requirementsFCI / CUI / CUI EnhancedAssessment report, SPRS, POA&M, raw
NIST SP 800-172Enhanced requirementsEnhancedAssessment report, POA&M, raw
NIST CSF 2.0185 outcomesAll functionsAssessment report, raw
FedRAMP 20x (Key Security Indicators)FRMR-synced KSIsKSIKSI OSCAL, KSI summary, 20x package

Security and trust

Your content stays inside the data path you choose.

You select an authorized AI data path per tenant and per engagement. Content stays inside it on every call, and bring-your-own-model credentials are supported.

Data pathModel familiesUse
Google Vertex AIClaude, GeminiSovereign lane; Assured Workloads for regulated engagements
AWS BedrockClaudeSovereign lane; GovCloud available
Azure AI FoundryGPT-5 familyBoundary lane for FedRAMP High and DoD IL2 tenants
  • Tenant isolation enforced on every query, with roles and granular permissions
  • MFA, passkeys and SSO through Entra ID, Okta or Google Workspace
  • Tamper-evident audit trail, encrypted secrets and a web application firewall
  • Per-tenant AI spend guardrails with alert and hard-stop thresholds, and a guardrail pause never changes an assessment result
  • Continuous security scanning of the platform, mapped to NIST 800-53 controls
  • Runs in Azure Commercial East, a FedRAMP High platform-authorized region

The line we do not cross

What stays with the assessor.

  • Every determination, signed procedure by procedure
  • Interview conduct and professional judgment
  • Sampling depth and evidence sufficiency calls
  • Final wording, with assessor edits locked rather than overwritten
  • Where the dual-pass QC disagrees with itself, the question defers to a human

Tell us what the contract requires. We’ll tell you what it takes.

A 30-minute scoping call is usually enough to size the gap, name the deliverables and give you a realistic date for authorization.