Request a scoping call Contact
← Research

An AI-drafted control profile describes your documents, not your controls

An AI-drafted control profile is bounded by its source evidence. Distinguish policy, self-report, observations and test results, then review source mappings and evidence gaps before using the profile for an assurance decision.

Governance / Conceptual study
Trace the evidence.
  1. Sources
  2. Evidence links
  3. Decision record

Keep sources linked to the record used for review. The diagram does not represent automatic approval.

Drafting a current-state control profile involves mapping records to framework outcomes. AI can assist with that work, but a populated table does not establish that every control operates or is effective. The assessment owner needs to know which source supports each row and what kind of evidence it supplies.

Consistent prose can make rows with different evidence look equally authoritative. Require an explicit evidence classification so the reviewer does not have to infer confidence from wording.

Review the profile’s evidence mappings and gaps alongside its conclusions. A model can organise supplied evidence, including reports of observation and testing. It does not independently establish events absent from those sources or validate every claim they contain.

What NIST actually published

NIST released the initial public draft of SP 1353 on 19 August 2026, with comments invited until 15 October. It illustrates AI-assisted governance review and current- and target-state profiling using fictional inputs. The announcement presents it as a drafting aid.

The guide requires source-grounded output and qualified review. Its examples are illustrative, not a prescribed assurance methodology. The organisation remains responsible for checking scope, inputs and results.

The current-state prompt also asks for an evidence-gap note, including outcomes with thin support and rows based on documented process rather than observed practice.

Use that distinction in the review brief. The drafting method and the assurance decision require different evidence.

Why the table cannot say more than the folder

Classify the basis for each control statement. Policy, documented procedure, observed practice and tested effectiveness answer different questions. All may be recorded in documents, but their presence and reliability need to be checked.

illustrative fixture

Separate the draft from the control evidence

Swipe or scroll for the full diagram →

The evidence stops before the proposed applicationObserved finding connects to an inference. A dashed boundary separates that inference from the untested application.ObservedInferenceUntested application
The evidence stops before the proposed applicationObserved finding and inference appear above a dashed boundary. The untested application remains below it.Observed findingInferenceUntestedapplication

A complete profile needs checked source mappings and explicit gaps.

Observed
NIST’s draft illustrates source-grounded profiling with qualified review and an evidence-gap note.
Inference
Classify supplied policies, self-reports, observations and test records, and validate consequential mappings.
Evidence boundary
A generated row does not independently repeat a test, observe current operation or establish that every gap was found.

Representative method for this article, not a measured deployment result.

A complete profile needs checked source mappings and explicit gaps. Evidence boundary: A generated row does not independently repeat a test, observe current operation or establish that every gap was found.

Reviewed 2026-10-02

A source portfolio can include audit findings, penetration-test reports and operational observations as well as policies. A model may summarise those records, but it has not repeated the tests or observed the current service itself. Retain the source, date and tested scope, and identify when further validation is needed.

Interview notes add reported practice. Distinguish a practitioner’s description from a reviewer’s direct observation or a recorded test result. All can be useful, but they carry different limits and should not be silently treated as equivalent proof.

A human assessor has the same duty to make evidence strength explicit. Tone is an unreliable substitute: confident wording can accompany weak support, and cautious wording can accompany strong findings. Use a classification and source locator that another reviewer can inspect.

Uniform language can make a profile easier to compare. It also makes explicit evidence labels more useful when rows rest on different foundations. Review both the claims and their source links instead of judging assurance strength through prose style.

The gap register should expose missing evidence, conflicts and limits to current applicability. Validate it rather than assuming the model found every omission. Supported rows also need sampling because a confident mapping can be incorrect.

What to require back

Resource the validation separately from drafting. Sample consequential conclusions and source mappings, investigate thin rows and inspect the service where necessary. Reading the table remains useful, but reading alone cannot establish that a described control operates.

Define review and release conditions for each profile version. A rapidly regenerated table still needs checked sources, a current gap register and approval for its intended audience. Preserve the prompt, input list and review record so a later reader can understand the evidence boundary.

What this does not claim

None of this says the approach is wrong or that NIST has overstated it. The draft is explicit that its use cases are illustrative rather than an assurance method, and the point here is drawn from its own instructions rather than against them. Nor is it a claim that a document-fed profile is unusable — a faster first draft with an honest gap register is better than a slow first draft without one.

It is also not a statement about anyone’s regulatory position. The Inference Institute does not certify organisations against ISO/IEC 42001, the NIST AI RMF or anything else, and a profile produced this way is evidence of readiness at best. Where a framework position carries legal or contractual weight, that interpretation stays with your counsel and your assessor.

The assessment owner should accept a profile with traceable claims, classified evidence and unresolved gaps. Decide which conclusions are demonstrated and which require further observation or testing. A useful draft supports that judgement without presenting document completeness as control effectiveness.

Filed under · Governance · NIST · Evidence · Assurance Inference Institute · 02 Oct 2026 (updated)

Bring us the question

Reading this because it is on your desk right now?

That is the conversation we are best at. Thirty minutes, a written summary, no obligation.