19 Compliance Frameworks

AI Compliance
Chatbot

Your 24/7 compliance expert. Get instant, contextual answers to compliance questions across all 19 supported standards including ISO 27001, ISO 27701, ISO 27017, ISO 27018, GDPR, SOC 2, Cyber Essentials, and IASME certifications. Powered by Claude AI.

19
Compliance Frameworks
200+
Topic Areas Covered
24/7
Availability
Claude
AI Engine

Intelligent Assistance

Compliance Guidance at Your Fingertips

Ask complex compliance questions in natural language and receive detailed, framework-specific guidance with control references and implementation recommendations.

Natural Language

Ask Anything

Ask questions in plain English. No need to know specific control numbers or clause references. The chatbot understands context and provides relevant, detailed answers.

Example: "What do I need to do for access control under ISO 27001?"

Multi-Turn

Contextual Conversations

Follow-up questions maintain context. Dive deeper into topics without repeating background information. The chatbot remembers your conversation history.

Example: "Can you explain that in more detail?" or "How does this apply to cloud services?"

Expert Knowledge

Precise Control References

Responses include specific control numbers, clause references, and cross-framework mappings. Get audit-ready information for documentation and evidence.

Example: Response includes "ISO 27001 A.5.15, A.8.3" with implementation guidance.

Secure

Private & Confidential

Conversations are stored securely within your organization. No data is shared externally. Multi-tenant isolation ensures complete privacy.

Features: Persistent conversation history, conversation export, full audit trail.

Comprehensive Coverage

19 Compliance Frameworks

Deep expertise across all major compliance standards including cloud security, privacy management, and UK certifications. Switch between frameworks seamlessly or ask cross-framework questions.

ISO 27001:2022

Information Security Management System

Context of Organization

Stakeholder analysis, ISMS scope, information security context

Leadership & Commitment

Security policy, roles, organizational authority

Planning & Risk

Risk assessment methodology, treatment plans, objectives

Support & Awareness

Resources, competence, communication, documentation

Operations

Operational planning, risk treatment implementation

Annex A Controls

All 93 controls across 4 themes: Organization, People, Physical, Technical

ISO 42001:2023

AI Management System

AI System Lifecycle

Development, deployment, monitoring, decommissioning

AI Risk Management

AI-specific risks, bias detection, model governance

Data Governance

Training data quality, data lineage, bias in datasets

Responsible AI

Ethics, transparency, explainability, human oversight

Impact Assessment

Societal impact, environmental considerations, stakeholder analysis

Third-Party AI

Vendor AI systems, API integrations, supply chain

GDPR / UK GDPR

General Data Protection Regulation

Data Subject Rights

Access, rectification, erasure, portability, objection

Lawful Basis

Consent, contract, legal obligation, vital interests, legitimate interests

Data Processing

Records of processing, international transfers, processors

DPIAs

Data Protection Impact Assessments, high-risk processing

Breach Notification

72-hour notification, breach documentation, regulator reporting

Technical Measures

Encryption, pseudonymization, security controls

SOC 2

Trust Services Criteria

Security (CC)

Common criteria, logical/physical access, system operations

Availability (A)

System uptime, disaster recovery, capacity planning

Processing Integrity (PI)

Complete, valid, accurate, timely processing

Confidentiality (C)

Information classification, encryption, data protection

Privacy (P)

Notice, choice, access, disclosure, security

Control Environment

Governance, risk assessment, monitoring activities

PCI DSS 4.0

Payment Card Industry Data Security Standard

Network Security

Firewalls, network segmentation, secure configurations

Cardholder Data

Storage protection, encryption, data retention

Vulnerability Mgmt

Anti-malware, secure development, patching

Access Control

Need-to-know, unique IDs, authentication

Monitoring & Testing

Logging, IDS, penetration testing, vulnerability scans

Security Policies

Policies, procedures, awareness training

NIST CSF 2.0

Cybersecurity Framework

Govern (GV)

Strategy, roles, policies, oversight, supply chain

Identify (ID)

Asset management, risk assessment, improvement

Protect (PR)

Identity management, awareness, data security

Detect (DE)

Continuous monitoring, adverse event analysis

Respond (RS)

Incident management, analysis, mitigation, reporting

Recover (RC)

Recovery planning, execution, communications

Extended ISO Coverage

ISO 27017:2015

Cloud Security Controls - Guidelines for information security in cloud services including shared responsibility, multi-tenancy, and virtual machine security.

ISO 27018:2019

Cloud Privacy Protection - PII protection in public cloud environments with privacy-specific requirements for cloud service providers.

ISO 27701:2019

Privacy Information Management - PIMS extension supporting GDPR compliance for both PII controllers and processors.

UK Cyber Certifications

Cyber Essentials 2023

UK Government cyber certification with five technical controls: firewalls, secure configuration, access control, malware protection, and security updates.

Cyber Essentials Plus 2023

Enhanced UK certification with independent technical verification including vulnerability scanning and configuration review.

IASME Cyber Assurance 2023

Governance-based cyber security incorporating Cyber Essentials Plus with additional risk management and incident response controls.

IASME DCC 2023

Data Compliance Certification for SMEs demonstrating GDPR compliance with practical, accessible requirements.

IASME MSP 2024

Managed Service Provider certification addressing unique security challenges of managing multiple client IT environments.

Simple to Use

How the AI Chatbot Works

1

Select Your Framework

Choose from ISO 27001, ISO 42001, GDPR, SOC 2, PCI DSS 4.0, or NIST CSF 2.0. The chatbot tailors responses to your selected framework's specific requirements and terminology.

2

Ask Your Question

Type your compliance question in natural language. Ask about requirements, implementation guidance, control mappings, evidence needs, or audit preparation tips.

3

Get Expert Answers

Receive detailed responses with specific control references, implementation recommendations, and cross-framework mappings. Responses are formatted in markdown for easy reading.

4

Continue the Conversation

Ask follow-up questions to dive deeper. The chatbot maintains context throughout your conversation, enabling natural back-and-forth dialogue on complex topics.

Get Inspired

Example Questions You Can Ask

Here are some real-world questions the AI Chatbot can help you with.

ISO 27001

"What are the requirements for access control under ISO 27001:2022 Annex A?"

ISO 42001

"How do I document AI system lifecycle processes for ISO 42001 compliance?"

GDPR

"When is a Data Protection Impact Assessment required under GDPR?"

SOC 2

"What evidence do I need to demonstrate CC6.1 - Logical Access Security?"

PCI DSS

"What are the encryption requirements for cardholder data at rest in PCI DSS 4.0?"

NIST CSF

"How do I implement continuous monitoring as per NIST CSF 2.0 Detect function?"

Under the Hood

Technical Capabilities

Claude AI Engine

Powered by Anthropic's Claude API for accurate, nuanced responses with deep compliance knowledge.

Persistent Conversations

All conversations are saved and can be continued later. Full history available for reference and audit.

Markdown Formatting

Responses rendered in rich markdown with headers, lists, code blocks, and tables for clarity.

Multi-Tenant Security

Complete data isolation between organizations. Conversations never shared across tenants.

Real-Time Streaming

Responses stream in real-time for immediate feedback. No waiting for complete responses.

Framework-Specific Prompts

Custom system prompts for each framework ensure accurate, contextual responses.

Ready to Ask Your First Question?

Get instant compliance guidance across 19 frameworks. No more searching through documentation or waiting for consultant responses.

Launch Chatbot View All Features