Skip to content
AI & Security

AI-powered Cyber Essentials assessment: what Fig Group does differently

How AI-assisted assessment workflows can support triage and feedback, the boundaries they must respect, and why Fig Group’s certification decision remains with a human assessor.

an abstract image of a sphere with dots and l

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

9 min read

Share

Section 01

AI-powered Cyber Essentials assessment: what Fig Group does differently

Standfirst

Fig Group publishes a six-working-hour Basic turnaround guarantee for qualifying compliant submissions. An IASME-licensed human assessor makes the certification decision. The workflow below illustrates AI-assisted assessment design; it is not a measured production benchmark or confirmation of a particular model deployment.

6 working hours

Conditional Basic certification guarantee

AI-augmented

Triage, gap detection, and feedback drafting

Human-assessed

Authorised assessor accountable for the assessment

In this articleWhat the AI doesWhat the AI doesn't doWhy the assessor decides

Section 02

What the AI is doing

An AI-assisted assessment workflow can identify patterns in self-assessment evidence and prepare material for human review. Before using it with customer submissions, confirm the approved processing environment, model providers, access controls and retention terms. Fig Group’s privacy notice and subprocessor information are the starting points for processing enquiries; this illustrative workflow does not create a separate data-location or third-party-processing promise. Four useful applications are:

Submission triage

As a self-assessment arrives, the workflow can classify answers against the requirements applicable to that account and flag possible inconsistencies for an assessor. New applications from 27 April 2026 use v3.3; applications started earlier may continue under v3.2. Actual question count, triage time and clarification rate depend on the account and submission and require operational records before they are presented as measured outcomes.

Gap detection against v3.3

The workflow checks answers against the applicable account version. For v3.3, cloud-service authentication must use MFA; security updates for high or critical vulnerabilities must be installed within 14 days of release when a fix is available. BYOD and cloud-service scope need to be described accurately. A phrase such as "MFA for most users" or "monthly patching" prompts a check of actual coverage, severity and release dates; the assessor decides whether an answer fails a mandatory criterion.

Feedback generation

Instead of a generic correction request, an AI-assisted workflow can draft a specific feedback paragraph: what the answer says, the relevant requirement, the evidence to clarify and the control to verify before resubmission. A human assessor must check each draft before it reaches the customer. Feedback must describe the actual environment and required remediation, not supply a convenient answer that masks a failing control.

Cross-reference checking

Where a customer has supplied a previous submission for renewal, the workflow can flag differences for assessor review. Useful checks include the 14-day security-update rule where applicable, supported software, firewall posture on in-scope remote-worker endpoints and the actual technical boundary used for BYOD. A privately owned home router used only to provide internet access is normally outside the organisation's scope; an organisation-owned or managed router may be in scope. Product-specific settings such as Windows AutoRun or Defender tamper protection are possible security checks, not universal Cyber Essentials pass criteria by name.

Section 03

What the AI is not doing

Not issuing the certificate

An authorised human assessor reviews the evidence and determines the assessment outcome under the scheme rules. Fig Compliance Ltd issues the certificate after a successful assessment. AI-generated analysis and drafts do not replace that accountability.

Not making edge-case judgements

Some submissions contain genuine ambiguity: a non-standard network topology, an unusual SaaS architecture, a scope boundary that is not cleanly in or out. The AI flags these to a human assessor rather than attempting to resolve them. The assessor makes the judgement call, documents the reasoning, and records the decision on the submission.

Not reading unsubmitted evidence

In this illustrative workflow, AI should be restricted to authorised assessment evidence; actual access and processing must be checked against the approved implementation. If the assessor needs to see a screenshot of the admin console or a policy document, the assessor should request it through the agreed secure channel and review the attachment.

Not auto-correcting customer submissions

If the AI detects a problem, it generates feedback - the customer fixes the submission, not the AI. The control narrative is the customer's, not Fig Group's.

Section 04

Why this delivers the 6-hour SLA

Submission quality, assessor capacity, clarification and remediation can all affect elapsed time. Fig Group's published six-working-hour Basic guarantee applies to a complete, compliant submission received before the stated cutoff, subject to its terms.

An illustrative workflow would route a morning submission to an assessor promptly, with possible issues already highlighted. The assessor still checks the answers and may return questions or feedback. This illustration is not a measured processing trace or a promise of a particular decision time.

Compare providers' written clocks using the same submission quality, cutoff and business-day assumptions. A market average or explanation of other providers' queues requires comparable provider records.

Section 05

The failure modes AI catches best

These are illustrative review prompts, not counts from an authenticated cohort:

1. MFA appears partial. Check every in-scope cloud-service user and the actual sign-in method.

2. Patching is described as monthly. Check release dates and whether high or critical vulnerabilities were fixed within 14 days when fixes were available.

3. BYOD is governed only by a policy. Check the technical controls and whether the chosen scope is accurate.

4. A remote worker uses a home router. Distinguish a privately owned internet-only router, normally outside scope, from an organisation-owned or managed device that may be in scope; check the endpoint firewall.

5. Cloud services are listed without their access controls. Check service and account scope, including MFA.

An assessor must verify the relevant facts and decide the result. No fixed detection time or frequency is implied.

Section 06

Customer trust and the IASME rules

IASME's scheme rules require that assessments are performed by named licensed assessors. Fig Group operates entirely within these rules: the AI is a tool the assessor uses, not a replacement for the assessor. Every certificate carries an IASME-licensed assessor's name. Every contentious judgement is documented by a human. The AI speeds up the parts that can be safely sped up - triage, gap detection, feedback drafting - and leaves the judgement to humans.

Any statement about IASME consultation or approval of a particular AI pipeline needs the relevant correspondence and scope. The assessor remains accountable for decisions under the applicable scheme rules.

Section 07

What comes next

Two specific extensions of the AI pipeline are in development in 2026:

1. Structured evidence validation. A proposed Plus workflow could organise device sampling evidence for the technical assessor. It cannot replace the specified tests or the assessor's judgement.

2. Renewal pre-population. A proposed renewal workflow could show prior answers and flag differences against the applicable account version. The customer must review the full current submission; there is no fixed 20-question renewal route.

Neither extension changes the core model: human assessor accountability, AI assistance, IASME scheme compliance.

Section 08

Bottom line

AI-assisted triage can help an assessor prioritise complete submissions and draft useful feedback. The published Basic guarantee still depends on the stated intake conditions and a successful human assessment; this article does not claim measured queue reduction or an automatically approved certificate.

Get Cyber Essentials certified in 6 hours | Read about the 6-hour guarantee | See pricing

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group's built-in AI automates security operations and compliance analysis across your stack.

Request a demo

Related solutions

Continue exploring Fig Group