Set up with AI turns ten questions about your business into a first draft of your risk register, Key Risk Indicators, third parties, ICT assets and first actions. Nothing is written until you have read the draft and ticked what to keep, so an empty Risk Management module becomes a working starting point in a few minutes instead of a blank page you have to fill from memory.

Which model does the work
If your organisation has entered its own API key under Settings › AI (Claude, ChatGPT or DeepSeek), that provider is used and there is no limit on runs. Without a key, Venvera's own model does the work and each organisation gets three runs a day; the page shows how many are left. Your answers, the organisation profile from Settings and the list of enabled frameworks are sent to the model once per run. Nothing else in your tenant is sent.
The ten questions
The page counts how many required answers are still missing; Generate the draft runs once they are all in. Generation takes 20 to 60 seconds and the page updates by itself.
| Question | What it is used for |
|---|---|
| What does the company do? | Two or three sentences on what you sell, to whom and how it is delivered. This is the main input for the risk names and descriptions. |
| Sector | The closest match drives the risk and KRI selection; a payment institution and a SaaS company get different drafts. |
| Countries of operation | Where you are licensed, sell or host data. The first country also becomes the head office country if the organisation has no legal entity yet. |
| Headcount | Rough size is enough; it gives the model a sense of scale. |
| Who are your customers? | Businesses, consumers, financial institutions or the public sector. Pick all that apply. |
| Data you hold | Drives the data protection and payment risks. |
| Core systems and platforms | Everything you run or depend on. These become ICT assets and the technology risks. |
| Critical third parties | Providers a one-day outage would hurt. Named providers become entries in the third-party register. |
| Known issues, incidents or deadlines | Audit findings, incidents and regulator deadlines. They feed the first actions and the risks that relate to them. |
| Risk appetite | Sets how the residual ratings are judged. |
Reviewing the draft

The draft opens in five tabs: Risks, KRIs, Third parties, ICT assets and First actions. Every item starts ticked. Untick anything that does not fit, click a name or a rating to edit it before it is created, and read the Why line under each item for the reasoning the model gave. Select all and Clear work per tab. Apply N selected creates the ticked items in one go; Discard draft throws the whole draft away and creates nothing.

Each KRI comes with a direction (lower is better or higher is better), a frequency, a unit and three threshold bands. The bands are written as adjoining green, yellow and red ranges, so a measurement always lands in exactly one band. Where a KRI matches the built-in catalogue, the catalogue reference is kept in its notes.
What gets created
| Register | What the draft writes |
|---|---|
| Risk register | Risks numbered on from your last reference (R-001, R-002 and so on) with category, department, inherent and residual rating, control effectiveness and the framework clauses they map to. The model's rationale is appended to the description. |
| KRIs | Active KRIs numbered KRI-1 onwards with direction, frequency and three threshold bands; the unit and any catalogue reference sit in the notes. |
| Third parties | Providers with type, criticality and country. The notes say the entry was drafted by AI setup and ask you to confirm the legal entity, LEI and contract. |
| ICT assets | Active assets with type, criticality, environment, management model and data classification. |
| First actions | Open tasks with a priority and, where relevant, a framework, flagged as auto-generated so you can tell them apart from your own. |
Risks and KRIs must belong to a legal entity. If the organisation has none yet, the wizard creates a head office entity named after the organisation, in the first country you selected; you can rename it later.
Running it again
You can run the wizard as often as your plan allows. A second run adds items alongside the existing ones and changes nothing that is already there; it does not read the registers first, so untick anything they already cover before applying. Reference numbers continue from the last one in use.
Permissions
Starting a run needs the right to edit the GRC registers. Each tab is then written under its own permission: third parties need third-party risk editing, ICT assets need risk management editing and first actions need task editing. If your role lacks one of them, that tab is skipped and reported, never silently, and the other tabs go through.
Privacy and audit trail
Every run is recorded with who started it, which provider and model answered, the answers, the draft and the id of every row it created, so a set can be reviewed or removed later. Both the generation and the apply appear in the audit trail. With your own key, your provider's data terms apply; with Venvera's model, the answers go to OpenAI's API under Venvera's account.