AI-powered Cyber Essentials assessment: what Fig Group does differently
How AI-assisted assessment workflows can support triage and feedback, the boundaries they must respect, and why Fig Group’s certification decision remains with a human assessor.

Section 01
AI-powered Cyber Essentials assessment: what Fig Group does differently
Standfirst
Fig Group publishes a six-working-hour Basic turnaround guarantee for qualifying compliant submissions. An IASME-licensed human assessor makes the certification decision. The workflow below illustrates AI-assisted assessment design; it is not a measured production benchmark or confirmation of a particular model deployment.
6 working hours
Conditional Basic certification guarantee
AI-augmented
Triage, gap detection, and feedback drafting
Human-assessed
Authorised assessor accountable for the assessment
Section 02
What the AI is doing
An AI-assisted assessment workflow can identify patterns in self-assessment evidence and prepare material for human review. Before using it with customer submissions, confirm the approved processing environment, model providers, access controls and retention terms. Fig Group’s privacy notice and subprocessor information are the starting points for processing enquiries; this illustrative workflow does not create a separate data-location or third-party-processing promise. Four useful applications are:
Submission triage
As a self-assessment arrives, the workflow can classify answers against the requirements applicable to that account and flag possible inconsistencies for an assessor. New applications from 27 April 2026 use v3.3; applications started earlier may continue under v3.2. Actual question count, triage time and clarification rate depend on the account and submission and require operational records before they are presented as measured outcomes.
Gap detection against v3.3
The workflow checks answers against the applicable account version. For v3.3, cloud-service authentication must use MFA; security updates for high or critical vulnerabilities must be installed within 14 days of release when a fix is available. BYOD and cloud-service scope need to be described accurately. A phrase such as "MFA for most users" or "monthly patching" prompts a check of actual coverage, severity and release dates; the assessor decides whether an answer fails a mandatory criterion.
Feedback generation
Instead of a generic correction request, an AI-assisted workflow can draft a specific feedback paragraph: what the answer says, the relevant requirement, the evidence to clarify and the control to verify before resubmission. A human assessor must check each draft before it reaches the customer. Feedback must describe the actual environment and required remediation, not supply a convenient answer that masks a failing control.
Cross-reference checking
Where a customer has supplied a previous submission for renewal, the workflow can flag differences for assessor review. Useful checks include the 14-day security-update rule where applicable, supported software, firewall posture on in-scope remote-worker endpoints and the actual technical boundary used for BYOD. A privately owned home router used only to provide internet access is normally outside the organisation's scope; an organisation-owned or managed router may be in scope. Product-specific settings such as Windows AutoRun or Defender tamper protection are possible security checks, not universal Cyber Essentials pass criteria by name.
Section 03
What the AI is not doing
Not issuing the certificate
An authorised human assessor reviews the evidence and determines the assessment outcome under the scheme rules. Fig Compliance Ltd issues the certificate after a successful assessment. AI-generated analysis and drafts do not replace that accountability.
Not making edge-case judgements
Some submissions contain genuine ambiguity: a non-standard network topology, an unusual SaaS architecture, a scope boundary that is not cleanly in or out. The AI flags these to a human assessor rather than attempting to resolve them. The assessor makes the judgement call, documents the reasoning, and records the decision on the submission.
Not reading unsubmitted evidence
In this illustrative workflow, AI should be restricted to authorised assessment evidence; actual access and processing must be checked against the approved implementation. If the assessor needs to see a screenshot of the admin console or a policy document, the assessor should request it through the agreed secure channel and review the attachment.
Not auto-correcting customer submissions
If the AI detects a problem, it generates feedback - the customer fixes the submission, not the AI. The control narrative is the customer's, not Fig Group's.
Section 04
Why this delivers the 6-hour SLA
Submission quality, assessor capacity, clarification and remediation can all affect elapsed time. Fig Group's published six-working-hour Basic guarantee applies to a complete, compliant submission received before the stated cutoff, subject to its terms.
An illustrative workflow would route a morning submission to an assessor promptly, with possible issues already highlighted. The assessor still checks the answers and may return questions or feedback. This illustration is not a measured processing trace or a promise of a particular decision time.
Compare providers' written clocks using the same submission quality, cutoff and business-day assumptions. A market average or explanation of other providers' queues requires comparable provider records.
Section 05
The failure modes AI catches best
These are illustrative review prompts, not counts from an authenticated cohort:
1. MFA appears partial. Check every in-scope cloud-service user and the actual sign-in method.
2. Patching is described as monthly. Check release dates and whether high or critical vulnerabilities were fixed within 14 days when fixes were available.
3. BYOD is governed only by a policy. Check the technical controls and whether the chosen scope is accurate.
4. A remote worker uses a home router. Distinguish a privately owned internet-only router, normally outside scope, from an organisation-owned or managed device that may be in scope; check the endpoint firewall.
5. Cloud services are listed without their access controls. Check service and account scope, including MFA.
An assessor must verify the relevant facts and decide the result. No fixed detection time or frequency is implied.
Section 06
Customer trust and the IASME rules
IASME's scheme rules require that assessments are performed by named licensed assessors. Fig Group operates entirely within these rules: the AI is a tool the assessor uses, not a replacement for the assessor. Every certificate carries an IASME-licensed assessor's name. Every contentious judgement is documented by a human. The AI speeds up the parts that can be safely sped up - triage, gap detection, feedback drafting - and leaves the judgement to humans.
Any statement about IASME consultation or approval of a particular AI pipeline needs the relevant correspondence and scope. The assessor remains accountable for decisions under the applicable scheme rules.
Section 07
What comes next
Two specific extensions of the AI pipeline are in development in 2026:
1. Structured evidence validation. A proposed Plus workflow could organise device sampling evidence for the technical assessor. It cannot replace the specified tests or the assessor's judgement.
2. Renewal pre-population. A proposed renewal workflow could show prior answers and flag differences against the applicable account version. The customer must review the full current submission; there is no fixed 20-question renewal route.
Neither extension changes the core model: human assessor accountability, AI assistance, IASME scheme compliance.
Section 08
Bottom line
AI-assisted triage can help an assessor prioritise complete submissions and draft useful feedback. The published Basic guarantee still depends on the stated intake conditions and a successful human assessment; this article does not claim measured queue reduction or an automatically approved certificate.
Get Cyber Essentials certified in 6 hours | Read about the 6-hour guarantee | See pricing
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group's built-in AI automates security operations and compliance analysis across your stack.
Request a demoRelated solutions
Continue exploring Fig Group
Related guides
Continue reading
Compliance
within 6 working hours, Guaranteed: How Fig Group's AI-Powered Platform Delivers the UK's Fastest Cyber Essentials Certification
Fig Group’s AI-assisted certification proposition and qualifying six-working-hour Basic guarantee, with human decision authority and clear readiness limits.
Read articleCompliance
Cyber Essentials within 6 working hours - Guaranteed. Here Is What That Actually Means.
What Fig Group’s qualifying six-working-hour Basic guarantee means: complete compliant submission, UK business-day cutoff, feedback and separate Plus timing.
Read articleTechnical Guides
Why Same-Day Cyber Essentials Is Possible: Workflow and Readiness
How preparation, structured workflows and human assessment support same-day Cyber Essentials, with the current guarantee conditions and evolving technical requirements.
Read article

