Client
AI User Manual
What the AI Does (and Does Not Do)
Intended Purpose
The AI features within the FEHA GRC platform serve as a specialized decision-support tool designed to help compliance professionals automate evidence mapping, assess third-party vendor risks, and execute targeted web research. It leverages large language models enriched with curated regulatory knowledge using Retrieval-Augmented Generation (RAG).
Core Boundaries
Every AI output within FEHA GRC is classified strictly as an advisory recommendation. The AI never takes autonomous action on your behalf, nor does it replace professional human expertise and legal counsel.
The AI IS / DOES...

The AI IS NOT / DOES NOT...

Mandatory Rule: Never use AI output as the sole basis for a compliance decision. AI-generated findings, risk scores, and assessments must be reviewed, validated, and approved by a qualified human before any organizational action is taken.
AI Features per Product
The FEHA GRC platform leverages three primary AI capabilities designed to streamline governance, risk, and compliance workflows:
- Control Mapper: Recommends evidence-to-control links using uploaded corporate documentation.
- Policy Generator: Generates specialized compliance policy drafts using company profiles or custom text instructions.
- AI Onboarding: Recommends frameworks, policies, and risks extracted directly from client meeting transcripts.
- Questionnaire Evaluator: Evaluates completed vendor questionnaires to calculate risk ratings and rationales.
- Web Search Query: Sources grounded answers from official vendor domains to complete unanswered assessment items.
Operational Feature Guides
- Control Mapper
- Purpose: Automate the mapping of corporate evidence files to specific framework controls inside the Master Data Management tool.
- Input: Uploaded evidence file (e.g., policy, system screenshot, audit log).
- Output: Recommended evidence-to-control links accompanied by confidence scores.
- How to Use:
- Navigate to Frameworks and select your target compliance framework.
- Under the Evidence Mapping section, upload your compliance document.
- Click Suggest Mapping.
- The AI reads the document, matches the contents against framework control requirements, and returns a suggested mapping list.
- Policy Generator
- Purpose: Generate compliance policy drafts based on your company profile and selected framework.
- Input: Company profile + framework or custom text instructions.
- Output: Policy document draft.
- How to Use:
- Navigate to GuardRisk ➔ Policy Generator.
- Create or select a Policy Group to anchor your organizational scope, industry, and size.
- Click Generate Recommendations to see what policies the AI suggests.
- Select a recommended policy and click Generate Content to draft the full document.
- AI Onboarding
- Purpose: Analyze client onboarding session transcripts and recommend relevant frameworks, policies, and risks from the FEHA global catalog.
- Input: Client meeting transcript file (PDF, DOCX, or TXT).
- Output: Recommended catalog items and frameworks with clear reasoning.
- How to Use:
- Navigate to ➔ Onboarding Sessions.
- Click Upload Transcript and select your transcript file.
- Click Start AI Onboarding Analysis.
- Review the parsed catalog items and automated reasoning statements returned by the system.
- Questionnaire Evaluator
- Purpose: Assess third-party vendor questionnaire responses and suggest automated risk ratings.
- Input: Completed vendor questionnaire.
- Output: Risk scores (Low, Medium, High) accompanied by clear, written rationales.
- How to Use:
- Navigate to Vendor Portals and open a completed vendor questionnaire.
- Click Analyze Answers.
- The AI reads each individual vendor response, evaluates it against compliance best practices, flags weak areas, and calculates the suggested risk score.
- Web Search Query
- Purpose: Query the web (strictly restricted to the vendor's official domain/subdomains) to answer unanswered vendor questionnaire questions.
- Input: Vendor name, official domain URL, and the specific unanswered questions.
- Output: Grounded answers with attached direct citation links (URLs).
- How to Use:
- Navigate to Vendor Portals and open a vendor assessment questionnaire containing incomplete sections.
- Select any unanswered questions you wish to resolve and click Run Web Search.
- Specify the vendor's name and official domain URL (e.g., https://vendor.com).
- The AI executes a targeted search using search grounding, answers the questions based on the vendor's public security pages, and attaches direct citation links.
Human Oversight & Mandatory Checkpoints
All AI outputs are advisory recommendations and require human intervention before being finalized or acted upon.
Checkpoint Matrix
The following checkpoints must be cleared by qualified personnel before moving forward in the workflow:

Universal Evaluation Checklist
When executing any checkpoint review, always assess the output against these parameters:
- Factual Accuracy: Are the cited control IDs, clause numbers, and framework names entirely, correct?
- Hallucination Check: Does the AI reference controls, articles, or sub-requirements that don't actually exist?
- Relevance: Is the output completely specific to the asked framework, or has the AI mixed in unrelated frameworks?
- Completeness: Does the output address all aspects of the evidence or questionnaire question, or are there significant gaps?
System Override Procedures
The FEHA GRC platform operates on the Override Principle: you always have the final say. The AI never takes autonomous action.
- Overriding Control Mapper Suggestions: Click the checkmark icon to approve the suggested link. Click the Edit icon to link the file to a different control ID, or click the Trash icon to discard it completely.
- Overriding Policy Generator drafts: The generated policy is always a draft—manually change any section inside the text editor. Ignore recommendations to create your own topics, or click Generate Content again for a fresh draft.
- Overriding AI Onboarding Decisions: Click the checkbox next to a recommended item and click Apply Selected to approve. Click the edit button on any recommendation to customize the reasoning text before saving, or deselect items to ignore them.
- Overriding Questionnaire Evaluator Scores: Select a alternative risk level from the dropdown in the vendor profile. Enter a mandatory text justification for the override. Click the edit icon to rewrite or clear the AI-suggested rationale.
- Overriding Web Search Query Answers: Adjust the reasoning, modify the returned answer text, or correct/replace the cited URLs manually in the questionnaire editing pane.
What to Report?
When you encounter an AI output that is incorrect, unhelpful, or concerning, navigate to Feedback to submit a star rating (1–5) and a text description. Use the following guide to format your report:

FAQ (Frequently Asked Questions)
Q1: Is my data sent to external AI providers?
A: Yes, document content is sent to a third-party API for processing. However, all PII (names, emails, phone numbers, credit cards, API keys, etc.) is automatically masked before sending. The system does not use API data for training; your original data is processed transiently and discarded after the request completes.
Q2: Can the AI access my company's internal data?
A: Only if you explicitly upload it. The AI has access strictly to: (1) the curated regulatory knowledge base (public frameworks), and (2) documents you upload during your current active session. It cannot access your MySQL database, your other FEHA data, or other companies' data.
Q3: What happens if I accidentally upload a file with sensitive data?
A: The PII masking system (Presidio + 11 custom recognizers) automatically detects and masks 22 types of sensitive data before sending it to the LLM. Your original file is processed transiently and is never stored in the AI system; it is discarded after processing completes.
Q4: Can someone prompt-inject the AI through my documents?
A: The system has robust guardrails that detect 40+ categories of prompt injection patterns in both user inputs and uploaded document content. Malicious content is automatically rejected with a generic error message, and retrieved RAG context is fully sanitized to prevent injection from the knowledge base.
Q5: What file formats can I upload for processing?
A: The platform supports PDF, DOCX, XLSX, XLS, JSON, PNG, JPG, and TIFF. Each file is validated for both its file extension and its magic byte signature to verify the actual file content, not just the name. Files must not exceed the maximum limit of 10 MB per file.
Q6: I got an error saying "inappropriate content detected." What does this mean?
A: Your input triggered the guardrail system. This can happen if your text contains patterns that resemble prompt injection, even unintentionally. Try rephrasing your question, or report it via the Feedback feature if you believe it is a false positive.
Q7: Are my AI interactions logged?
A: Yes. Each AI request logs the model used, message count, input preview, PII entities detected, response preview, and token usage. These logs are strictly used for quality monitoring and incident investigation, and are never shared externally. Observability is provided through Langfuse.
Q8: The onboarding analysis or mapping recommendations are taking a long time to load.
A: For complex operations or automated files analysis, the expected background processing time is 30-120 seconds depending on file count and overall layout volume. Check your job status indicator. If persistent, contact your system administrator to check the AI Services container health.
Key Reporting & Support Contact
In accordance with your privacy and data processing frameworks, any suspected model bias, security concerns, or data processing violations can be directed to the Privacy Contact / Data Protection Representatives:
- DPO Team: Henry Kevin Marcelino Ratu & Ryan Yosedie
- Email: privacy@feha.io