AI Document Analysis is a tool that automatically reviews compliance and evidence documents you upload, such as SOC 2 reports, ISO 27001 certificates, or pen test results, and answers a set of questions about the document's content. Instead of manually reading through a lengthy report to find specific details, you let the AI extract the answers for you, helping you spot gaps between what a vendor claims in a questionnaire and what their supporting documents actually show. Each answer is grounded in the document and, when available, includes a Reference line noting the page number(s) it was drawn from, so you can go straight to the source and verify it.
You'll find this tool under Communication > AI Document Analysis in the top navigation.
Default document types
AI Document Analysis supports common document types by default, including:
- Access Control Policy
- Business Continuity / Disaster Recovery Plan
- HIPAA Business Associate Agreement (BAA)
- Incident Response Plan
- Information Security Policy
- ISO 27001 Certificate
- Penetration Test Report
- Risk Management Policy / Assessment
- SOC 2 Type 2 Report
Choosing the type that best matches your file improves the accuracy of the template questions and the AI's answers. If none of these fit, select Add new document type during setup to create a custom type with your own questions.
How to use AI Document Analysis
- From the top navigation, go to Communication > AI Document Analysis.
- Click the Select evidence dropdown. The My Documents window opens showing documents already added to your Evidence Locker under the "AI Document Analysis" category.
- To add a new document, either:
- Click Add Document inside this window to upload one directly, or
-
Go to Evidence Locker separately, add the evidence, and set its Category to "AI Document Analysis."
Note: Only PDF files (limit of 50MB per file) are supported for analysis. The PDF must contain selectable text; scanned or image-only PDFs aren't processed. Password-protected or corrupted PDFs can't be analyzed. Files uploaded through the tool are saved to the Evidence Locker.
- Select the document you want to analyze from the list.
- Choose a document type from the dropdown that appears once evidence is selected (for example, SOC 2 Type 2 or ISO 27001 Certificate). You can also select Add new document type to create a custom one with your own questions; check "Save this document type and questions for future use" if you want it available next time.
- Review the question set for the selected document type. You can edit existing questions or add/remove your own. Changes save automatically.
- Click Analyze Document.
After you click Analyze Document, the summary includes an answer to each question (with a reference to where it was found in the document, when available) and an overall summary of findings. Use the Download PDF or Download CSV buttons to export the results.
Tips
- Choosing the correct document type improves the accuracy of the questions and the AI's answers.
- Analysis can take a few minutes, especially for larger documents.
- If you tag a document with the "AI Document Analysis" category directly in Evidence Locker, confirm it's a PDF before running analysis; other file types can be tagged but won't produce reliable results.
- Saved custom document types and their question sets are reusable, so you only need to set them up once per document type.