Set up with AI turns ten questions about your business into a first draft of your risk register, Key Risk Indicators, third parties, ICT assets and first actions. Nothing is written until you have read the draft and ticked what to keep, so an empty Risk Management module becomes a working starting point in a few minutes instead of a blank page you have to fill from memory.

The Set up with AI page with the ten questions answered for a managed IT services provider
The ten questions, answered for a managed IT services provider - shown with sample data.
ℹ️
Open it from Risk Management › Risk Register or KRIs while they are still empty (the empty state links to it), from the Set up with AI quick action on the Overview page while the register is empty, or directly at /risk/ai-setup. It is part of the Professional and Enterprise plans and needs a role that can edit the GRC registers.

Which model does the work

If your organisation has entered its own API key under Settings › AI (Claude, ChatGPT or DeepSeek), that provider is used and there is no limit on runs. Without a key, Venvera's own model does the work and each organisation gets three runs a day; the page shows how many are left. Your answers, the organisation profile from Settings and the list of enabled frameworks are sent to the model once per run. Nothing else in your tenant is sent.

The ten questions

The page counts how many required answers are still missing; Generate the draft runs once they are all in. Generation takes 20 to 60 seconds and the page updates by itself.

QuestionWhat it is used for
What does the company do?Two or three sentences on what you sell, to whom and how it is delivered. This is the main input for the risk names and descriptions.
SectorThe closest match drives the risk and KRI selection; a payment institution and a SaaS company get different drafts.
Countries of operationWhere you are licensed, sell or host data. The first country also becomes the head office country if the organisation has no legal entity yet.
HeadcountRough size is enough; it gives the model a sense of scale.
Who are your customers?Businesses, consumers, financial institutions or the public sector. Pick all that apply.
Data you holdDrives the data protection and payment risks.
Core systems and platformsEverything you run or depend on. These become ICT assets and the technology risks.
Critical third partiesProviders a one-day outage would hurt. Named providers become entries in the third-party register.
Known issues, incidents or deadlinesAudit findings, incidents and regulator deadlines. They feed the first actions and the risks that relate to them.
Risk appetiteSets how the residual ratings are judged.

Reviewing the draft

The draft review with the Risks tab open, each risk ticked, with its ratings and framework references
Reviewing the drafted risks before applying - shown with sample data.

The draft opens in five tabs: Risks, KRIs, Third parties, ICT assets and First actions. Every item starts ticked. Untick anything that does not fit, click a name or a rating to edit it before it is created, and read the Why line under each item for the reasoning the model gave. Select all and Clear work per tab. Apply N selected creates the ticked items in one go; Discard draft throws the whole draft away and creates nothing.

The KRIs tab of the draft review showing direction, frequency and the green, yellow and red thresholds
Drafted KRIs with their threshold bands - shown with sample data.

Each KRI comes with a direction (lower is better or higher is better), a frequency, a unit and three threshold bands. The bands are written as adjoining green, yellow and red ranges, so a measurement always lands in exactly one band. Where a KRI matches the built-in catalogue, the catalogue reference is kept in its notes.

What gets created

RegisterWhat the draft writes
Risk registerRisks numbered on from your last reference (R-001, R-002 and so on) with category, department, inherent and residual rating, control effectiveness and the framework clauses they map to. The model's rationale is appended to the description.
KRIsActive KRIs numbered KRI-1 onwards with direction, frequency and three threshold bands; the unit and any catalogue reference sit in the notes.
Third partiesProviders with type, criticality and country. The notes say the entry was drafted by AI setup and ask you to confirm the legal entity, LEI and contract.
ICT assetsActive assets with type, criticality, environment, management model and data classification.
First actionsOpen tasks with a priority and, where relevant, a framework, flagged as auto-generated so you can tell them apart from your own.

Risks and KRIs must belong to a legal entity. If the organisation has none yet, the wizard creates a head office entity named after the organisation, in the first country you selected; you can rename it later.

⚠️
What the wizard never does. It does not mark any control as implemented or effective, does not attach evidence, does not set owners and does not change anything that already exists. Everything it creates is a draft for a person to confirm. Set owners and check ratings as you go through the registers, and treat the first board report after a run as a review exercise rather than a statement of fact.

Running it again

You can run the wizard as often as your plan allows. A second run adds items alongside the existing ones and changes nothing that is already there; it does not read the registers first, so untick anything they already cover before applying. Reference numbers continue from the last one in use.

Permissions

Starting a run needs the right to edit the GRC registers. Each tab is then written under its own permission: third parties need third-party risk editing, ICT assets need risk management editing and first actions need task editing. If your role lacks one of them, that tab is skipped and reported, never silently, and the other tabs go through.

Privacy and audit trail

Every run is recorded with who started it, which provider and model answered, the answers, the draft and the id of every row it created, so a set can be reviewed or removed later. Both the generation and the apply appear in the audit trail. With your own key, your provider's data terms apply; with Venvera's model, the answers go to OpenAI's API under Venvera's account.