AI Features
The Adversarial platform uses AI large language models (LLMs) to automate risk and incident management and streamline communications. AI features are available across four areas: the Risk Register, risk import from documents, the Incident Register, and Governance Reporting.
Overview
Section titled “Overview”A key AI feature of the Adversarial platform is AI Scoring within the risk and incident modules. AI Scoring is a robust, repeatable scoring process that produces consistent results across source-agnostic risks and incidents. It applies the same logic whether an entry arrives through an automated integration, a bulk CSV import, or manual entry, so a risk or incident is evaluated the same way regardless of where it came from.
| Feature | What AI does |
|---|---|
| Risk Register Scoring | Assesses likelihood and impact per the RAMP, explains rationale, identifies associated threat objectives |
| Risk Import from Documents | Extracts proposed risks from an uploaded narrative document for human review before anything is added to the register |
| Incident Register Scoring | Proposes incident severity per the CIRP, explains rationale, identifies associated threat objectives |
| Governance Reporting | Constructs narrative summaries and explanations of risk and incident data for executive and Board reporting |
Risk Register Scoring
Section titled “Risk Register Scoring”When risks are brought into the register — whether through automated API integrations, bulk CSV imports, or manual entry — AI can be applied individually or in bulk to:
- Assess likelihood and impact ratings
- Memorialize the rationale behind the conclusions
- Discern the threat objectives potentially associated with the risks
To conduct this processing, the AI reads the available risk details together with the Risk Assessment Management Procedure (RAMP) and your organization’s profile — the name and description set at Settings > Company. The RAMP provides the scoring framework; the organization profile supplies the customer-specific context.
When AI scoring is turned on for a risk integration, scoring is refreshed automatically whenever the source tool updates the description of an existing risk — keeping likelihood, impact, and rationale current as findings evolve. For integration-sourced records, capture any new details in the Comments section rather than editing the Description field — the next sync from the source tool overwrites Description edits. If you adjust the scoring of one of these entries manually, record why in the record’s reasoning fields.
Risk Import from Documents
Section titled “Risk Import from Documents”Import via AI on the risk register turns a narrative document — a pen-test report, an audit memo, a vendor assessment — into proposed risks. The AI reads the uploaded document and, for each candidate risk, drafts a title, description, class, initially reported urgency, source, and discovered date, along with a rationale and the verbatim passage of the document it was drawn from.
The AI only proposes; a person disposes. Every proposal is reviewed side-by-side with the source document, can be edited or discarded, and nothing reaches the register until you approve the import. See Creating Risks for the workflow.
Incident Register Scoring
Section titled “Incident Register Scoring”Incident scoring follows a similar approach. The AI reads the available incident details together with the Cyber Incident Response Procedure (CIRP), which defines the severity levels, and your organization’s Cybersecurity Policy, which determines what counts as authorized activity, to:
- Propose incident severity per the CIRP
- Explain the rationale for the proposed severity
- Assign the relevant threat objectives, always at strong correlation for incidents — on risks the AI uses low or strong as the evidence warrants — and only when the record has none set already
Severity reasoning is persisted in the incident record, providing a permanent audit trail of the AI’s scoring rationale.
When AI scoring is turned on for an incident integration, scoring is refreshed automatically whenever the source tool updates the description of an existing incident. Incidents whose severity is set directly by the source — for example, a GreyMatter incident closed with a benign close code — keep that severity and are not re-scored. The same guidance applies as for risks: capture new details for integration-sourced records in Comments, since the next sync overwrites Description edits.
Governance Reporting
Section titled “Governance Reporting”Several elements of governance reporting use AI to construct narrative summaries and explanations of included data:
- Executive summary — Takes threat profile data, risk metadata, and incident metadata from the reporting period to identify themes, patterns, and changes. The AI produces section summaries for threats, risks, incidents, and compliance, along with a notice rating indicating which areas require attention.
- Risk management slide — Uses similar prompts to construct a summary of remediation agility.
- Incident management slide — Constructs a summary of detection and containment for the selected severities.
Every count these narratives state is computed by the platform for the reporting period and supplied to the AI as a named figure — the AI writes the prose around the numbers but does not produce the numbers. Each figure the narrative cites is listed on the report’s References slide with a link that opens the register filtered to exactly those records, so any statement in a report can be checked against the live data. See Where the numbers come from.
Embedded fields
Section titled “Embedded fields”The quality of AI scoring depends on the detail captured in each entry. The table below shows which fields are used for each register:
| Field | Risk Register | Incident Register |
|---|---|---|
| Title | Yes | Yes |
| Description | Yes | Yes |
| Comments | Yes | Yes |
| Initially Reported Urgency (IRU) | Yes | — |
Threat Objectives are not an input to scoring — the AI assigns them as an output of the scoring run.
Data handling and privacy
Section titled “Data handling and privacy”AI scoring is currently routed to Adversarial’s commercial OpenAI account by default. The ability to train models or otherwise share customer data with OpenAI is explicitly disabled. Documents uploaded to the AI risk import are handled under the same posture: the extracted text is used to produce the import proposals and is not used for model training.
The procedural documents that guide AI outputs (the RAMP, CIRP, and Cybersecurity Policy) are available for review in the Compliance module. They provide more deterministic outcomes on risk and incident scoring than most manual team processes in practice.