Auditwyse by Optywise

Compliance assessment for internal and external audit

Audit evidence, assessed against the criteria it is meant to satisfy.

Auditwyse reads your policy and evidence documents, maps the obligations in them onto NIST 800-53 and ISO 27001 criteria, and produces a control assessment in which every statement cites the passage it came from. Where the evidence does not settle a criterion, the assessment says so, and states what would resolve it.

Assesses against, and reads from

  • NIST SP 800-53
  • ISO/IEC 27001
  • CIS BENCHMARKS
  • AWS SECURITY HUB
  • GUARDDUTY

Beyond checklists. Built for the audit file.

Five stages. Each one writes into a shared knowledge graph that the next stage reads, and every conclusion keeps the citation it was built from.

Stage 01

Compliance knowledge

Obligations and controls are extracted from your policy documents and mapped onto framework criteria. A mapping is accepted only when two independent model families agree on it. Disagreements are left out rather than averaged.

Mapping: Access control policy v3 2 of 2 agree
  1. ✔Obligation 14 → AC-2 Account management
  2. ✔Obligation 14 → A.9.2.1 User registration
  3. –Obligation 19 → AC-6(1) not accepted: one family disagreed
  4. Obligation 20: comparing model families
Cited span: Access rights are reviewed by the asset owner at least quarterly.

From documents to a defensible assessment

Four steps, and a person signs off on the last one.

  1. Ingest

    Policies and evidence are parsed, classified and dated.

  2. Map

    Obligations are linked to framework criteria, only where two models agree.

  3. Assess

    Each control gets a coverage count, reasoning, and citations.

  4. Review

    A named reviewer decides, and the work paper is frozen.

A tool that always answers is easy to build and impossible to defend.

These are product decisions, not gaps waiting to be closed.

What the easy version does

  • Issues an opinion. Output shaped like a verdict, with no qualified person behind it.
  • Guesses when evidence is missing. A gap becomes a fail, or worse, a pass.
  • Reports a compliance percentage. One number that reads as precision the evidence does not support.
  • Asks for write access. Broad cloud permissions to read a handful of findings.

What Auditwyse does instead

  • Does not issue an audit opinion. It prepares and evidences assessments. The opinion stays with a qualified auditor.
  • Does not guess. An unsettled criterion is recorded as could not judge, shown as a neutral state, with what would resolve it.
  • Does not report a percentage. Coverage is counts against a stated denominator.
  • Does not modify your infrastructure. Read only permissions, with the write side of every service explicitly denied in policy.

Data handling

Documents you provide are processed to extract obligations and to assess control evidence. Assessment output is derived from those documents and stored with references back to the specific passages it was built from, so any conclusion can be traced to its source and checked.

Hosting region, subprocessors, and retention periods are set out in the privacy policy.

Contact

Auditwyse is in active development and is not generally available.

If you are evaluating it for an audit programme, or you are an audit firm assessing it on a client's behalf, get in touch and we will walk you through the current state directly rather than through a demo environment.

Email: consulting@optywise.com