Risk Assessment FAQ

u

Which frameworks can I become compliant with using the platform?

The risk domains covered in the platform cover a waide array of frameworks, like NIST, ISO 27001 and CMMC. As the platform grows, more framework-specific modules will be added.

u

Does completing the assessment equal an audit?

Our platform is built around the concept of pre-audition, allowing for the discovery of gaps in accordance with the selected framework in scope. Though not an audit itself, it is extremely useful in the preparation of external audits.

u

Who can use the platform?

Anybody from your IT team can easily complete the assessment. Although the platform covers critical areas, everything is explained in a simple and direct manner.

u

Is Passerum using AI in its platform?

Yes. We have AI mechanisms on the backend that validate your answers and create recommendations based on your gaps in accordance with your industry.

u

How can I sign up for the platform?

On the upper menu, you can purchase access to the platform for 3 months or a year. Once the payment is approved, an access token will be sent to the email used for signing up.

u

What kind of platform support does Passerum offer?

We can help you troubleshoot any issue you run into with the platform, and we can also assist by resolving the questions that may come up when completing the assessment.

AI Services FAQ

u

How does the AI risk audit work?

We review your deployed AI agents or GenAI workflows, evaluate risk factors like bias exposure and unsafe outputs, and deliver a structured report with recommended controls and governance actions.

u

Do you access datasets during your audit?

No. The focus of our audit is on the interaction layer and how bias can occur based on user interaction. 

u

Can you help with AI strategy implementation?

Absolutely! We help companies implement AI in their business operations and become AI-enabled companies. We create implementation plans with goals set for the 30-day, 90-day, and year milestones.

u

What technical requirement is needed for completing an audit?

The only requirement is a user with the same level of access that a regular user would have. We audit the system at the same level where we are addressing the bias.

u

What is the on-boarding process?

We start with a 30-minute meeting where we talk about your organization, and how you are using AI. Understanding your company and its context allows us to define the scope. We will then send a proposal, and upon payment, we will begin.

u

Why do I need to audit my AI systems?

AI is a great leverage for most businesses, and it is moving much faster than regulatory bodies can. Auditing your AI today prepares you for the mandatory requirements that will be defined in the near future.

General FAQ

u

How does Passerum identify vulnerabilities?

We use a structured assessment approach to identify likely exposure points, misconfigurations, and control gaps. The goal is practical prioritization: what to address first and why.

u

How does Passerum ensure data privacy?

We minimize data collection, use secure handling practices, and keep scope focused on what’s necessary to deliver results. Specific data handling details are confirmed during scoping.

u

Does Passerum provide compliance reporting?

We can map findings to common control areas and provide documentation support. If you have a specific compliance goal, we’ll tailor deliverables during scoping.

u

Is Passerum suitable for businesses without a cybersecurity team?

Yes. Passerum is designed for SMBs with IT teams that need clear risk visibility and prioritization without building a full security function.

u

Can Passerum integrate with existing IT systems?

Yes. Our approach is designed to work with common SMB environments and tools. During the discovery call, we confirm what’s in scope and what data is needed.

u

How often should we revisit our risk posture?

Most SMBs revisit risk posture quarterly and after major changes (new systems, cloud migrations, new vendors, or AI deployments). We can recommend a cadence during your consultation.