Reads the file your customer sent
CAIQ, SIG Lite, VSA and the spreadsheet a customer wrote themselves. .xlsx, .csv and pasted text. The question column is found by reading the header, so you are not mapping columns before you can start.
Governance, Risk & Compliance
A customer sends a 250-row spreadsheet and a deal stops moving until somebody fills it in. SemperWise One imports the file, answers what you have already answered, and shows you exactly which rows still need a human — with the control and the dated artefact behind every claim.
Answer libraries are not new. Every compliance platform has one: you answer a question once, and the next questionnaire that asks it gets the same text back. That part is genuinely useful and we do it too — import the file your customer sent, and the rows you have answered before fill themselves in, however differently they are phrased this time.
What almost nobody does is keep the library honest. A security answer is a claim about a control, and controls stop working. The access review that ran last March is not evidence in month fourteen. The penetration test you cited expired. The encryption standard changed. In most answer libraries none of that is visible: the text sits there, still confident, still filling questionnaires, quietly asserting something that stopped being true.
So we bind every answer to the evidence that makes it true. When that evidence expires, the answer stops filling questionnaires by itself and comes back to you with the reason attached. It is not deleted and not hidden — it is simply no longer allowed to speak for you unattended. That is the difference between an answer library and a library of things that used to be true.
Coverage
Import, fill, review, export — with the receipts carried the whole way.
CAIQ, SIG Lite, VSA and the spreadsheet a customer wrote themselves. .xlsx, .csv and pasted text. The question column is found by reading the header, so you are not mapping columns before you can start.
A local, deterministic match on the meaning-bearing words, so "do you encrypt customer data at rest" finds your answer whether they asked it that way or asked about industry-standard algorithms at rest.
Each answer carries the framework clause and the dated evidence behind it. Those travel into the export as a "Backed by" column your customer can actually check.
When the evidence behind an approved answer expires, that answer stops auto-filling and the row is handed back with the expiry date named. Nothing re-asserts a control that quietly lapsed.
Where the library has nothing, the drafting pass is grounded in your real control state and told to answer "no" or "partial" where that is the truth. A questionnaire answer is a contractual representation; an AI that flatters you is worse than no AI.
Everything the fill produces is a draft. A person approves each one, and their name is recorded against it. Answers that came from the model are excluded from bulk approval on purpose — nobody has read them yet.
Every answer you approve lands in the library with its citations, folded into the existing entry when the same question was asked in different words. The second questionnaire costs a fraction of the first.
Approach
Four steps, and only one of them is yours.
Upload the spreadsheet, or paste the questions from the email. Sections and the customer's own reference numbers are carried across so your response lines up with their sheet.
The library answers what it can. The result is itemised rather than totalled — how many came from your approved answers, how many were drafted, how many were held back as stale, how many nobody can answer honestly.
You read the drafts. The rows that need you are marked, and the ones that are fine are visibly fine. Approving an answer puts your name on it and teaches the library.
A CSV with your responses and the control reference and dated evidence behind each one. Send it back, or paste it into the customer's own template.
Deliverables
The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.
Exported with your answers, your short yes/partial/no column, and the citations behind each claim.
Your approved answers, each bound to a control and an artefact, ready for the next customer who asks.
Which of your standing answers have outlived their evidence — which is, in practice, a list of controls that stopped being evidenced.
Who approved which answer and when, because "who told the customer that?" is a question that eventually gets asked.
Is this for you?
If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.
Book a scoping callHow we work
The same engagement model applies to every piece of work we take on, so you always know what happens next.
A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.
Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.
Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.
One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.
A walkthrough call with your engineers. We answer questions on the fix, not just the finding.
A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.
Questions
The questions clients actually ask during scoping. If yours is not here, ask it directly.
CAIQ, SIG Lite, VSA and any customer-written spreadsheet, as .xlsx, .csv or .tsv — plus pasted text for the short lists that arrive in the body of an email. The question column is detected from the header rather than assumed, so a sheet with a title block above it and a column called "Consensus Assessment Questions" works without configuration.
No. Everything the fill produces is a draft, and a person approves every answer before it goes anywhere. Answers drafted by the model are deliberately excluded from bulk approval, because a bulk-approve button over text nobody has read is how a company ends up warranting something untrue.
When you approve an answer you can attach the control it rests on and the evidence artefact that proves it. Evidence in SemperWise One carries a collection date and an expiry. When that expiry passes, the answer is marked stale: it stays in your library, but it will not fill a new questionnaire until the evidence is re-collected or you re-approve it deliberately. The row comes back to you with the expiry date named.
Yes, and it is worth knowing why that works. The matching is local and deterministic — no embeddings, no vector database, no external call — so your own approved answers fill questionnaires with the AI layer switched off entirely. The model only drafts the rows your library has never seen.
On our hosted platform the drafting pass sends the question and your control state to the model provider. On an on-premises or private-cloud deployment you can point the AI layer at a model inside your own network, or turn it off and use the library alone. The library, the citations and the evidence never leave your tenant either way.
Two ways that matter. Theirs produce text; ours produces text with a control reference and a dated artefact attached, carried into the export so the recipient can verify it rather than take it on trust. And theirs have no concept of an answer going out of date — ours stops using an answer the day the evidence behind it expires.
Next step
A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.