CYBER · PRIVACY · DIGITAL TRUSTPowered by Falconry360 Book a working session

Home/Falconry360/FalconryX

The intelligence layer

FalconryX

The governed intelligence layer inside Falconry360. Eight agents that draft, map, check and chase — and a design principle that none of them decide anything.

WHAT IT IS
Assistive agents embedded in Falconry360
WHAT IT IS NOT
An autonomous decision-maker
GOVERNED UNDER
ISO/IEC 42001 management system structures
CONTROL
Disabled at tenant level if you prefer

Automation in a compliance platform is itself a governance question

So we treat it as one, and we expect you to hold us to it.

Every organisation we work with is being sold AI. Very few are being told what happens when it is wrong. In a system that holds your control evidence, your risk register and your regulatory position, that is not an acceptable gap — a confidently wrong control mapping is worse than no mapping, because it will be believed.

FalconryX is built on the assumption that it will sometimes be wrong. Every agent produces a proposal, a draft or a flag. A named person accepts it. The acceptance is recorded with the inputs, the model version and the approver, and retained alongside the artefact it produced.

That is not caution for its own sake. It is what makes the output usable as evidence.

The agents

Each works inside your tenant, on your control library, against your regulatory perimeter. None of them operates across tenants, and none trains on your data.

Regulatory Change Agent

Draft, human-approved

Reads a published change from an authority you answer to, works out which of your controls, policies and obligations it touches, and drafts the impact assessment with owners already named.

  • Monitors NCA, SAMA, SDAIA, CBUAE, CBO, NCSA, CBB, CITRA, ICO, FCA and the standards bodies
  • Produces a diff against the version of the requirement you last assessed
  • Routes to the accountable owner with a due date, not to a shared mailbox
  • Flags where wording has diverged enough that one control test will no longer satisfy both regimes

Nothing publishes to your control library until a named owner approves the assessment.

Control Mapping Agent

Draft, human-approved

Proposes how a newly loaded framework or market pack maps onto the control set you already operate, so adding a jurisdiction is a mapping exercise rather than a second programme.

  • Suggests many-to-many mappings with a confidence position and the reasoning behind each
  • Identifies controls that would satisfy several regimes from a single test
  • Separates genuine equivalence from superficial similarity, and says which is which
  • Highlights obligations with no matching control — the gaps worth knowing about early

Mappings are proposals. A control owner accepts, amends or rejects each one.

Evidence Agent

Assistive, continuous

Checks what has been submitted against what the control actually requires, and returns what is missing before an auditor does.

  • Reads evidence against the control's stated requirement, not just its presence
  • Detects stale evidence, wrong period, wrong system, wrong scope
  • Chases the owner on the schedule, with escalation when it ages
  • Distinguishes machine-collected evidence from asserted evidence in every pack

It can reject evidence as incomplete. It cannot accept evidence as sufficient — that is a human decision.

Scenario Calibration Agent

Draft, human-approved

Proposes Open FAIR parameters for a loss scenario from your incident history, asset criticality and comparable sector loss data — then argues with the estimators when a range looks wrong.

  • Suggests minimum, most likely and maximum for each factor, with the evidence for each
  • Flags estimates that sit outside what the supporting evidence will bear
  • Surfaces where the group is converging too quickly, which usually means anchoring
  • Re-runs affected scenarios when a control changes or an incident is recorded

The calibrated estimators set the numbers. The agent supplies the starting position and the challenge.

Third-Party Agent

Assistive, continuous

Runs the supplier assessment cycle that otherwise consumes a team: tiering, questionnaires, evidence review, clause tracking and reassessment scheduling.

  • Tiers new suppliers from contract, data exposure and service dependency
  • Reviews returned questionnaires and marks the answers that do not match the evidence supplied
  • Tracks clause expiry, right-to-audit position and sub-processor change notifications
  • Recalculates portfolio concentration whenever the supplier master changes

Supplier risk acceptance and offboarding decisions stay with the contract owner.

Narrative Agent

Draft, human-approved

Writes the first draft of a board paper, a post-incident review, a regulator response or a customer security questionnaire — from the live record, with every figure traceable.

  • Assembles board packs on the committee's cadence from current platform data
  • Drafts post-incident reviews from the incident timeline and the controls it exercised
  • Answers customer due-diligence questionnaires from your control and evidence base
  • Writes in your organisation's register of terms, not in vendor language

Nothing reaches a board, a regulator or a customer without a named person approving it.

Privacy Operations Agent

Assistive, continuous

Keeps the privacy record current across several regimes at once — the work that decays fastest when it is done by hand.

  • Proposes records of processing entries from system and integration discovery
  • Triages DPIA triggers from the change pipeline before deployment, not after
  • Applies the governing regime's clock and conditions to each rights request
  • Maintains the transfer register as systems, suppliers and hosting positions change

The DPO approves every assessment and every response to a data subject or a regulator.

Resilience Agent

Assistive, continuous

Watches the dependency picture behind your important business services and tells you when it has quietly moved.

  • Recalculates single points of failure when the asset or supplier master changes
  • Flags services drifting toward their impact tolerance before a test does
  • Proposes severe but plausible scenarios drawn from the same library used for quantification
  • Tracks plan currency and exercise overdue positions against the agreed schedule

Impact tolerances and recovery strategies are approved by the service owner and the board.

What it looks like in a working week

Six situations our clients actually hit, and what changes when the agents are running.

A new NCA control release lands

The Regulatory Change Agent produces the diff, the affected control list and a draft impact assessment within the working day. The security team spends its time on the four controls that genuinely changed rather than on reading 200 pages to find them.

A Saudi bank adds a UK subsidiary

The Control Mapping Agent proposes how the existing SAMA-aligned control set maps to UK GDPR, the NCSC CAF and FCA operational resilience expectations — and flags the dozen obligations with no current control behind them.

Examination notice arrives with three weeks' notice

The Evidence Agent has been chasing on schedule all year, so the gap is small. The Narrative Agent assembles the response pack to the regulator's own request structure.

The board asks what a ransomware event would cost

The Scenario Calibration Agent proposes parameters from your incident history and sector data. Your estimators challenge and set them. The curve is on a slide by the end of the week, with the assumptions attached.

A critical supplier is acquired

The Third-Party Agent reopens the assessment, flags the sub-processor change, surfaces the clauses that need renegotiating, and recalculates the concentration position across the portfolio.

An enterprise customer sends a 340-question security questionnaire

The Narrative Agent drafts the answers from your live control and evidence base. What used to take a fortnight of a senior engineer's time becomes a review.

How it is governed

The same ISO/IEC 42001 structures we help clients put around their own AI adoption.

Human approval on every consequential output
No control mapping, risk rating, evidence acceptance, regulatory response or board paper takes effect on agent output alone. Approval is recorded against a named person with a timestamp.
Full traceability
Every generated output records its inputs, the model version, the prompt context and the approver, and is retained with the artefact it produced. If a regulator asks how a position was reached two years ago, the answer exists.
Tenant isolation
Agents operate inside a single tenant. Client data is not used to train shared models and is not visible across tenants. Processing location follows the residency position agreed for your tenant — including in-Kingdom for Saudi clients.
Stated limits
We publish what each agent can and cannot do, including the classes of error it is prone to. A vendor that will not tell you how its AI fails has not tested it properly.
Opt-out
FalconryX can be disabled at tenant level, per agent. Falconry360 functions without it; the drafting becomes manual. Several clients start this way and enable agents one at a time.
Audit of the layer itself
The agent layer is in scope for the same control testing and assurance as the rest of the platform, and we will share the results under due diligence.

On the word "agent". We use it to mean a bounded task performer with a defined input, a defined output and a defined approver — not an autonomous system that pursues goals across your estate. If a vendor is offering the second thing for governance work, ask them who signs the regulatory filing.

Securing your AI, not only using ours

The governance you apply to FalconryX is the governance you need for your own AI.

Most organisations across the Gulf now have AI in the estate that arrived without a procurement decision — embedded in a vendor product, enabled by default, or adopted by a team that saw the productivity case. The governance question is not whether to allow it. It is whether you can list it.

  • AI inventory. What is deployed, by whom, on what data, with what human oversight — including the features that arrived inside something you already bought.
  • Use-case impact assessment. Purpose, affected parties, data, model provenance, failure modes and oversight, assessed before deployment rather than after an incident.
  • ISO/IEC 42001 management system. Policy, roles, objectives, controls and internal audit, structured so the AI management system shares evidence with the ISMS rather than duplicating it.
  • Model and change governance. Version control, evaluation records, approval and monitoring for drift in the outcomes that matter.
  • Third-party AI. Vendor AI capability assessed as part of supplier due diligence, because your exposure includes their model choices.

How this fits a transformation programme

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.