AI Compliance Engine
How the Nexxis AI engine analyses your environment, generates compliance findings, and produces natural-language explanations.
5 min readUpdated 2026-02-01
AIenginefindingsanalysis
Overview
The Nexxis AI Compliance Engine is the core of the platform. It combines rule-based control evaluation with large language model (LLM) analysis to produce human-readable compliance findings, recommendations, and risk explanations.
How It Works
1. Evidence Collection
Nexxis collects evidence from your connected integrations (cloud providers, identity providers, code repositories).2. Control Evaluation
Each control is evaluated against a set of rules. The rule engine checks:- Configuration values (e.g., "Is MFA enabled?")
- Presence of required artefacts (e.g., "Is a backup policy document uploaded?")
- Historical events (e.g., "Have all patches been applied within 30 days?")
3. AI Analysis
For findings, the AI engine:- Generates a plain-English explanation of what's wrong and why it matters
- Proposes a specific remediation tailored to your environment
- Estimates the risk impact if left unresolved
- Cross-references against known attack patterns to contextualise the risk
4. Report Generation
Findings, recommendations, and evidence are compiled into structured reports suitable for internal teams and external auditors.AI Quality
Nexxis uses AI responses that are:
- Grounded in your actual evidence — no hallucinated findings
- Framework-specific — language matches the framework you're targeting (e.g., SOC 2 Trust Service Criteria language)
- Reviewable — every AI-generated finding links to the underlying evidence
Customising AI Behaviour
You can tune the AI engine per project:
- Verbosity: Concise (1-sentence) vs. Detailed (full paragraph) explanations
- Tone: Technical (for security engineers) vs. Executive (for board-level reporting)
- Risk Appetite: Adjust the risk scoring to reflect your organisation's tolerance