Start with a bounded task

Choose a task with an explicit input and a reviewable output: summarize a document, prepare assessment notes, or identify missing information. Define the scope and the person responsible for reviewing the result before running the task.

Keep the source attached

A proposed finding should identify the document or record that supports it and explain the reasoning. If the source is missing, outdated, or outside the assessment scope, the proposal should state that limitation. Confidence is not a substitute for evidence.

Separate preparation from authority

Permission to read evidence does not imply permission to change a risk score, accept a risk, or publish a report. Define permitted actions for each task. Require an authorized reviewer to make decisions that commit the organization.

Make human review practical

Show the original record, the proposed change, and its supporting sources together. Let the reviewer accept, amend, or reject the proposal. Record the review outcome and rationale so the next reviewer can understand what happened.

Evaluate the complete workflow

Assess the quality of the output and the effort needed to review it. Include incomplete evidence, contradictory documents, and changes in scope in your evaluation. Stop or narrow the workflow when reviewers cannot reliably establish the basis for a proposal.

Apply the approach in FokusRM

FokusRM connects risk records, treatment decisions, controls, and evidence. Audit Agent supports document-based framework assessments and report exports. Review assessment outputs and use the platform's decision workflow for treatment approvals. The wider agent operating model described here remains a methodology rather than a promise of autonomous operations.

Back to resources