How AI works in Zovos
Zovos uses AI for the language work in a compliance program, such as drafting, mapping, classifying and extracting. It does not use AI to decide anything. Every model output arrives as a proposal with its citations attached, and a named person accepts, disputes, or escalates it before it becomes part of your record. This page explains what the agents do, what grounds their answers, and where you stay in control.
What the agents do
The agents are a closed set. Each one has a defined job, a versioned prompt template, and a run record you can open a year later.
- Policy mapping. This agent crosswalks your policy sections to regulatory citations, with a confidence score on each match.
- Gap analysis. This agent finds obligations with no policy or control covering them. Results land as proposed gaps, never as findings.
- Regulatory monitor. This agent summarizes the impact of a regulatory change and drafts an applicability assessment for your charter.
- Drafter. This agent drafts a policy or procedure grounded in your own library.
- Citation indexer. This agent structures framework citations into paragraph-level references the rest of the product can point at.
- Exam prep. This agent assembles examiner-ready binder items.
- FDL Classifier. This agent sorts the lines of an examiner's first-day letter against your request catalog.
- Mock examiner. This agent writes examiner-voice draft findings for procedures that failed.
- Ad screener. This agent does a UDAAP and advertising first pass that flags trigger terms.
- SOC Reviewer. This agent pulls exceptions, complementary user entity controls, carve-outs, period gaps, and opinion qualifications out of a vendor's SOC 2 report.
- Contract Reviewer. This agent reads an executed vendor contract and proposes its key terms and, for each clause on your required-clause checklist, whether the contract contains it. A proposal that quotes text the contract does not contain is marked ungrounded instead of trusted.
- Horizon Scanner. This agent reads the regulatory updates, enforcement actions and economic data published since its last scan and proposes draft watch items for your emerging-risk register.
- Internal audit drafters. These three agents draft risk-and-control-matrix lines for an engagement, the body of a workpaper from the evidence attached to it, and a finding from the failed items of a sample. An auditor accepts each draft before it becomes part of the engagement.
You meet them in context instead of choosing them from a menu. Examples are remediation guidance on a finding, a policy draft started from a gap, a suggested answer on an inbound due-diligence questionnaire, and the first pass on a marketing review.
What the answers are grounded in
Retrieval runs over two libraries. The first is the regulatory corpus that ships with the product. It holds framework citations, citation paragraphs and regulatory updates, and it is read-only to you. The second library is your own. It holds your policy sections, the text of documents you have uploaded, and drafts in progress. Retrieval never crosses a tenant boundary, and the product enforces that structurally instead of relying on review.
Documents become retrievable on upload. A file is scanned for malware, its text is extracted, and only a clean version is ever indexed. A quarantined file is never read into the index.
Two grounding rules matter more than anything else in this section. First, weak matches are dropped instead of being padded back in, so an empty result is a legitimate answer. The product tells you that nothing in your library supports an answer instead of returning the least-bad match. Second, a citation that does not resolve against the corpus is dropped loudly, with an audit row, instead of being stored as though it were verified. The raw model output is kept verbatim on the run record. Only resolvable citations survive into anything durable.
Nothing binds without a person
Every run comes back banded by confidence. A score above 0.85 is auto-cleared, 0.60 to 0.85 is awaiting review, and below 0.60 is flagged. Auto-cleared is not the same as approved. No agent output binds anything on its own.
The top band carries one extra safeguard. When a run clears on confidence but the untrusted material it read carries instruction-like content, a system note on the run's review trail flags it for human spot-review. The confidence band itself does not change. A confident answer drawn from a document that is trying to steer the model is exactly the answer a person should look at.
The review queue collects everything waiting on a decision. A reviewer accepts, disputes, or escalates, and each of those requires a name and a rationale that is written into the append-only audit trail. Generated gaps stay proposed until someone promotes them. Mock-exam findings are drafts until someone moves them into the real register. Extractions from a SOC report land in proposed fields, and the report's header facts stay blank until a person confirms them. Contract terms and clause findings wait for a person to accept or reject each one, and a draft emerging risk stays a draft until someone accepts it onto the watch list or dismisses it.
Show your work
The run record is immutable. It pins the agent, the model and provider that served it, the prompt template and its version, the resolved prompt, tokens, duration, and a content hash for every input. Re-running reproduces the same inputs verbatim, which is what makes "show me how you got that answer" answerable in front of an examiner long after the template has moved on. Your model governance evidence is assembled from that same telemetry. See Model & AI governance.
Disposition review
Records that reach the end of their lifecycle queue for an explicit decision instead of aging out quietly. A dashboard tile shows what is waiting, a reviewer with the right permission works the queue, and the decision is recorded like any other governed action. A reviewer records an outcome of retain or clear for disposal. Clearing a record destroys nothing, and there is no disposal action in the interface today.
Where we deliberately use no model at all
Where a deterministic answer is possible, the product does not call a model. Absence testing, the mock examiner's procedure checks, shadow-vendor matching, clause review, launch delta and first-day-letter segmentation are all deterministic. The mock examiner copies breaching record identifiers only from query results, never from model output.
There is no statistical analytics engine behind any of it. Model bias testing and fair-lending analysis are evidence-capture and oversight surfaces, and the fair-lending function reports itself unavailable rather than approximating a number it cannot compute. Nothing in the product takes a governance action on its own, and the automation surface deliberately exposes no approval action.
Controls you hold
- Turn AI off. Governance settings carry a processing switch. With it off, every trigger path is refused before any write, for institutions whose policy forbids model processing of their content.
- Cost controls. Agent usage is bounded by a token budget and a cap on concurrent runs, so a runaway job cannot quietly become a bill. Raising either is a conversation with your account team.
- Provenance per run. Each run records which provider actually served it, so governance reads history instead of current configuration.
Your own AI assistant
You can also connect the AI assistant your institution already uses to your workspace over the Zovos connector. It works as you, within your own permissions, and only after an owner turns the connector on. Every tool that reads or changes your data refuses an examiner session.
Over the connector the assistant can show you your own work and your approvals queue, find a record by its ID or title, and read your controls, risks, obligations, findings, key risk indicators, vendors, regulatory updates, exam request lists and policies. It can create a task or comment on a finding or a risk. Each of those is shown as a dry run first and written only when you confirm. It cannot approve, sign off or change a record's status, and it cannot reach fraud cases, SAR decisions or credit risk review. Every tool call is written to your audit trail.
Two of the assistant's tools ask a model for help. One assesses the impact of a regulatory change, and the other drafts answers to a due-diligence questionnaire from your own prior answers. Each of those calls is recorded as an agent run like the ones above, with its citations, its token use and a review band, and neither writes to any of your records. The AI processing switch described above turns them off along with everything else. It also turns off the assistant's policy search, which uses a model to match your question to your policy sections.
The assistant can also search and cite these published docs. We index them for that search and refresh the index as we update the pages. See Connect your AI assistant for setup, and Test controls with your own AI assistant for control tests it can submit for review.
Notes and limits
- We do not run an automated model-quality benchmark. The review queue, with its accepted and disputed decisions, is the evaluation loop today, and we would rather say so than imply a harness we do not have.
- Corpus content is original paraphrase. It is not verbatim regulator text.
- A framework crosswalk is never evidence of certification, including for the AI-management-system framework in the corpus.
- Where inference runs, and the commitment that no customer input or output is used to train foundation models, are stated on our security page.