New NXDD AI assurance technology

Meet NXDD ISMate.

Your AI teammate for ISO/IEC 27001:2022. Build the ISMS, connect risks and controls, prepare evidence, support internal audit and drive continual improvement — with humans approving every important decision.

Human-governed AI Evidence traceability Flexible deployment
AI
ISMate Readiness AgentIllustrative workspace · Human approval enabled
ACTIVE
82%READINESS
ISMS requirements88%
Evidence health76%
Risk treatment69%
Audit preparedness81%
DRAFTEDStatement of Applicability
REVIEWEvidence Request Pack
PRIORITY7 Improvement Actions
Explainable recommendationsSource, owner and rationale retained
ISMS operating intelligenceFrom context to management review
ReadinessGuided implementation across ISMS requirements
Risk & SoAConnected risk, treatment and applicability workflow
EvidenceMapped, reviewed and time-aware assurance records
ImprovementFindings, actions, management decisions and closure
Product overview

An ISMS teammate — not another static checklist.

NXDD ISMate is a human-governed AI agent designed to support the establishment, implementation, maintenance and continual improvement of an information security management system.

It turns business context, risks, assets, policies, controls, evidence, audit findings and management decisions into one connected operating model.

The agent drafts, recommends and explains. Accountable people review and approve before content is published or decisions are finalized.

The shift ISMate is built for

Manual readiness workSpreadsheets, repeated interviews and disconnected documents.
Guided implementationStructured prompts, ownership, tasks and review-ready artifacts.
Evidence foldersStatic files with unclear currency, scope and control relevance.
Living evidence graphEvidence linked to controls, owners, audits, risks and review dates.
Audit-cycle scrambleLate requests, missing proof and reactive corrective actions.
Continuous preparednessReadiness signals, findings, actions and management visibility.
Brand proposition

Build the ISMS. Prove the evidence. Improve continuously.

The ISMate brand combines ISMS discipline with the idea of a capable teammate: always available to structure the work, explain the requirement and prepare the next action.

AI-guided. Human-approved.

ISMate accelerates work without removing accountability. Every material output is traceable, reviewable and subject to assigned approval.

Recommendations grounded in approved organizational context and evidence.
Review queues for policies, risks, SoA decisions, findings and reports.
Audit trail of sources, changes, decisions and responsible owners.

One agent. Multiple stakeholder views.

CISOs see posture; ISMS managers see implementation; risk owners see actions; auditors see traceable evidence; executives see decisions and improvement.

CISO and management dashboard
ISMS implementation workspace
Internal audit and findings workflow
Business-owner tasks and evidence requests
Core capabilities

Everything needed to move from readiness to a sustainable ISMS.

Modular capabilities connect requirements, risks, controls, artifacts, evidence, audit and continual improvement.

01

ISMS Readiness Agent

Scope, context, interested parties, requirements, gaps, priorities and implementation roadmap.

02

Risk & Treatment Agent

Risk scenarios, scoring, treatment decisions, residual risk, acceptance and monitoring.

03

Statement of Applicability Agent

Control applicability, justification, implementation status, ownership and evidence linkage.

04

Policy & Procedure Agent

Draft, review and maintain policies, procedures, standards, registers and operating instructions.

05

Evidence Intelligence

Request, collect, classify, map, validate, approve and monitor evidence currency.

06

Internal Audit Agent

Audit planning, interviews, sampling, workpapers, findings, corrective actions and reporting.

07

Management Review Agent

Prepare agenda, metrics, incidents, risk updates, audit results, decisions and action tracking.

08

Continual Improvement Engine

Prioritize findings, corrective actions, lessons learned, owners, due dates and closure proof.

ISMS lifecycle coverage

Support across the management-system lifecycle.

ISMate organizes the work from organizational context and leadership through planning, operation, evaluation and improvement.

4ContextScope, parties, needs
5LeadershipPolicy, roles, commitment
6PlanningRisk, objectives, change
7SupportResources, awareness, documents
8OperationRisk process and controls
9EvaluationMonitoring, audit, review
10ImprovementNonconformity and CAPA
Interactive workflow

One agent, four operating modes.

Switch between implementation, assurance, audit and improvement views.

Build the ISMS with structured guidance.

ISMate interprets requirements in the context of your organization, prepares draft artifacts and routes work to assigned owners.

1
UnderstandLoad scope, context, assets, stakeholders and current documentation.
2
AssessIdentify gaps and prioritize implementation activities.
3
GeneratePrepare draft policies, registers, plans and task packs.
Implementation WorkspaceHUMAN REVIEW ON
4
Confirm ISMS scope boundariesAssigned: ISMS Manager · Source: Context Workshop
REVIEW
6
Approve risk assessment methodologyAssigned: CISO · Draft prepared by ISMate
DRAFT
7
Publish competence and awareness planAssigned: HR + ISMS · Evidence checklist attached
READY

Turn evidence into continuous assurance.

Evidence is connected to controls, risks, owners and review cycles so the team can see what is current, weak or missing.

1
RequestSend role-based evidence requests with due dates and guidance.
2
ValidateCheck completeness, period, source, scope and control relevance.
3
MonitorTrack expiry, changes, exceptions and control-effectiveness indicators.
Evidence Health76% CURRENT
A.5
Supplier security review records6 current · 2 expiring · 1 missing owner
ACTION
A.6
Security-awareness completionCurrent · approved · mapped to people controls
VALID
A.8
Privileged-access reviewLatest review requires owner attestation
PENDING

Prepare audits with traceable workpapers.

ISMate supports planning, interview questions, sampling, evidence packs, findings and report preparation.

1
PlanSet scope, criteria, schedule, auditor and sampling approach.
2
ExecuteRun interviews, collect evidence and document objective results.
3
ReportPrepare findings, root cause, corrective action and closure workflow.
Internal Audit Pack81% PREPARED
Q
Leadership interview guide12 questions linked to requirements and prior decisions
READY
E
Sample evidence bundleAccess review, incident testing and supplier records
REVIEW
F
Finding classification reviewHuman auditor confirmation required
DRAFT

Convert findings into measurable improvement.

Prioritize corrective action based on risk, recurrence, root cause, ownership and management commitments.

1
AnalyzeStructure root cause, impact and recurring issue patterns.
2
PrioritizeRecommend actions based on risk, dependency and due date.
3
VerifyCollect closure evidence and confirm effectiveness after implementation.
Improvement Engine7 PRIORITY ACTIONS
1
Strengthen evidence ownershipRecurring gap across access, supplier and backup evidence
HIGH
2
Standardize risk acceptanceManagement approval workflow and expiry required
PLAN
3
Validate corrective-action effectivenessPost-implementation review scheduled
TRACKED
Artifact intelligence

Draft the working documents — keep the decisions human.

ISMate accelerates the first draft and maintains the relationship between artifacts, controls, evidence, owners and approvals.

01 · GOVERNANCE

ISMS Scope & Context

Boundaries, interfaces, interested parties, requirements and documented exclusions.

02 · RISK

Risk Register & Treatment Plan

Risk scenarios, scoring, controls, action owners, due dates and residual-risk review.

03 · APPLICABILITY

Statement of Applicability

Control decisions, justification, status, owner, implementation notes and evidence references.

04 · DOCUMENTATION

Policy & Procedure Library

Policies, procedures, standards, registers, plans and controlled version history.

05 · ASSURANCE

Evidence Request Packs

Role-based requests, required period, acceptance criteria, review and expiry.

06 · AUDIT

Internal Audit Workpapers

Audit plan, checklist, interviews, samples, objective evidence, findings and reports.

07 · LEADERSHIP

Management Review Pack

Performance, risks, incidents, audits, changes, resources, decisions and actions.

08 · IMPROVEMENT

Corrective Action Register

Nonconformities, root cause, action plan, ownership, verification and effectiveness.

EVIDENCE
GRAPH
Controlsrequirements and applicability
Auditssamples, workpapers and findings
Riskstreatment and residual risk
Actionsowners, SLA and closure
Policiesversions and approvals
Assets & Ownersscope and accountability
Evidence intelligence

A living source of proof.

Instead of storing evidence as isolated files, ISMate connects each record to the requirement it supports, the control being operated, the owner responsible, the audit using it and the review date that keeps it current.

Evidence acceptance criteria and required time period
Source, owner, approver and collection method
Control, risk, asset, policy and audit relationships
Expiry, revalidation, exception and change triggers
Exportable audit and management assurance packs
Standards and ecosystem

ISO 27001 focused. Enterprise connected.

The product is designed around ISO/IEC 27001:2022 readiness and can connect with supporting security, cloud, privacy and resilience practices.

Primary focus

ISO/IEC 27001:2022ISMS requirementsRisk treatmentStatement of ApplicabilityInternal auditManagement review

Supporting practices

ISO/IEC 27002:2022ISO 31000ISO 22301ISO/IEC 27017ISO/IEC 27018NIST CSF

Enterprise integrations

NXDD GRCNXDD VerityITSMIAMSIEM / EDRVulnerability ManagementM365 / SharePoint
Responsible AI

Safe by design. Governed in operation.

ISMate supports people who remain accountable for the ISMS. It does not replace professional judgment, independent audit or certification decisions.

01

Human approval

Policies, risks, SoA decisions, findings and management outputs follow assigned review and approval.

02

Source traceability

Recommendations identify their supporting evidence, context, requirement and rationale.

03

Role-based access

Users see only the ISMS information and actions authorized for their role.

04

Data protection

Customer data stays within the approved deployment boundary and governed processing model.

05

Quality controls

Templates, validation rules, review queues and audit logs reduce unsupported or inconsistent output.

06

Clear limitations

ISMate provides implementation and assurance support, not certification, accreditation or legal advice.

Deployment and data ownership

Your ISMS. Your data. Your operating model.

Flexible options support regulated environments, regional residency needs and different maturity levels.

01 · SOVEREIGN

On-Premises

Designed for highly regulated environments requiring maximum control over infrastructure, identity, data and integrations.

02 · FLEXIBLE

Private / Public Cloud

Deploy in the customer-selected cloud and region with enterprise security, integration and resilience controls.

03 · RAPID

SaaS

Accelerate time-to-value through a managed environment with configurable governance, roles and evidence workflows.

Start your ISMS journey

Give your ISO 27001 program an intelligent teammate.

Book a focused session to review your scope, current maturity, audit timeline, evidence model, deployment needs and the ISMate modules that fit.

Personalized walkthrough Readiness use cases Deployment discussion

Request an ISMate demo