How AI answers are grounded
SolveGRC's AI does not answer from general knowledge. It answers from your knowledge — the documents, evidence, approved answers, and control records in your own tenant. Everything it drafts is an argument built out of your material, with a citation back to the exact source. That is the whole point: an answer you can hand to a customer or an auditor has to be defensible, and an answer with no traceable source is not defensible.
Where an answer comes from
When the AI drafts a questionnaire answer, a control narrative, or a summary, it works in three moves:
The corpus in step one is your material — the documents, evidence, and approved answers in your tenant — not the open internet.
- Retrieve. It searches your corpus for the passages most relevant to the question. It is reading your policies and evidence, not the open internet.
- Draft. It writes an answer using only what it retrieved, and tells you how confident it is.
- Cite. Each claim carries a pointer to the source passage it came from, so you can open the original and check it yourself.
Why a human still approves it
A drafted answer is a proposal, not a fact. Nothing the AI writes counts as your position until a person on your team reviews and approves it. Approval is where the answer becomes real: only then does it register as reusable evidence, prefill future questionnaires, or appear in an export. This is deliberate — it keeps a human accountable for every claim that leaves your organization, and it means the AI can be helpful without being trusted blindly.
Why it sometimes refuses — and why that is good
If the AI cannot find grounding for a question in your corpus, it says so instead of inventing an answer. A refusal is a signal, not a failure: it usually means you are missing a document or a piece of evidence that a real answer would need. The same instinct shows up as a flagged weak spot — the AI marking a part of its own draft as thin, so your reviewer looks there first.
An answer machine that confidently fills every blank is dangerous in compliance. One that refuses when it lacks proof, and points at what is missing, is doing its job.
What this means for you
- Feed the corpus. The AI is only as good as what you have given it. The more of your real policies, evidence, and approved answers live in SolveGRC, the richer and better-cited its drafts.
- Check the citation, not just the prose. The fastest way to trust or correct a draft is to open its source and read the passage it cited.
- Treat refusals as a to-do list. When the AI won't answer, it is usually telling you where a gap is.
You can see every source the AI used and every answer it produced. What stays internal is how it decides which passages to retrieve and how it phrases a draft — the retrieval and prompting machinery. You get the grounded result and the receipts; the recipe stays in the platform.
Related
- How evidence quality and freshness work — the corpus the AI cites is only as strong as the evidence in it.
- Review and approve — the human gate, step by step.