Skip to content.
A woman in a pink shirt sits at a desk holding glasses and smiling at the camera. Behind her, a man works at a table with a laptop displaying a chart. The office setting is bright and modern.

Agentic AI: Can it transform compliance?

When we introduced Nira, NAVEX’s new agentic AI experience for NAVEX One, one thing became clear almost immediately – people weren’t just interested in what the technology could do. They wanted to know how it works, how it’s governed, how it protects their data and where we’re headed next. 

Those are exactly the conversations we hoped to have. 

AI is evolving quickly, showing great potential to help people make better decisions, uncover risks sooner and spend more time on work that requires human judgment. That’s the philosophy behind Nira. We designed it to connect data across compliance workflows while keeping people firmly in control through governance, transparency and human oversight. 

During our recent webinar, attendees asked thoughtful questions about security, implementation, AI governance and the roadmap ahead. We’ve collected some of the most common questions below, with lightly edited answers for clarity. 

Getting started with Nira

If we’re already EthicsPoint customers, will AI automatically be added to the platform? 

It depends on the AI capability. Features like AI-assisted summarization and AI-Suggested Related Cases are not enabled by default and must be activated by your organization. Nira for Analytics is enabled by default for eligible customers, with the option to disable it at any time based on your organization’s needs. Your NAVEX representative can help you understand which AI capabilities are available and how to enable them. 

Is there an AI reporting experience we can enable? 

Yes. Nira for Analytics is available as a natural-language reporting experience built into NAVEX’s analytics capabilities, starting with incident and benchmarking data. You’ll be able to ask questions in plain language and receive governed, data-backed answers, reports and insights almost instantly. 

How Nira fits into NAVEX One

What is Nira?

Nira is NAVEX’s AI-powered compliance intelligence, powering a growing set of AI experiences that help customers work smarter by finding answers faster, uncovering insights and working with greater confidence. 

How does Nira work with PolicyTech, and how is it different from the existing AI search experience?

Think of Nira as the umbrella AI capability across NAVEX solutions going forward. As a reflection of that, the PolicyTech search and chat experience you have today will be upgraded with a new and improved experience in August and fall under the Nira name. It’s not a separate tool. Rather, it will be one consistent AI experience across NAVEX One, with the existing PolicyTech experience getting a significant upgrade. 

What integrations and APIs does NAVEX support?

We already have a strong set of APIs, which work in our whistleblowing and case management system, and APIs are very much part of where we’re headed as a platform. Rather than give a partial answer because every environment is different, the best approach is to connect with one of our Solutions Engineers. They can walk through what’s available today, what’s planned and what’s coming, along with best practices for your specific needs.

Building AI you can trust

How does NAVEX protect customer data and ensure AI is secure? 

Customer data is never used to train AI models. That’s not a setting or a toggle – it’s a blanket policy across the platform. Your data is only ever used to deliver your own results, never to train or improve the underlying models. 

The choice you do have is whether to turn AI features on at all. Once enabled, security starts with the foundation. Nira runs on Microsoft Azure OpenAI as well as AWS Bedrock, so you’re inheriting the security posture of two of the most trusted names in enterprise cloud. On top of that, we add our own controls, including PII masking where appropriate, access restrictions, full audit logging and a human always in the loop before anything happens. It’s enterprise-grade security by design, not an afterthought. 

Do you see fewer hallucinations because of the compliance context? 

Yes. It’s a combination of things. The AI is grounded in your actual case and policy data instead of general knowledge. We also run evaluations using an LLM-as-judge approach to continuously test quality, and we use subagent orchestration – breaking tasks into smaller, where appropriate specialized steps instead of asking one model to do everything. That helps reduce drift and improve consistency. 

What observability does Nira provide? 

Every AI action is logged in an invocation database to provide a full audit trail. We run an LLM-as-judge process to continuously check output quality, and we track model versioning so we always know what produced what. It’s an area we’re continuing to mature, but the foundation – auditability and quality monitoring – is already in place. 

How NAVEX approaches AI 

How does NAVEX choose AI models while keeping the platform current and efficient? 

We match the model to the task. Simpler requests use lighter, more efficient models, and only the more complex work uses the heavier ones. Moving to AWS Bedrock gives us that flexibility, along with shared infrastructure, so we’re not rebuilding the same thing for every new feature. 

It also means we’re not locked into one vendor or one model. As new models become available, we can evaluate and adopt the best option for each task. Keeping pace with AI advances isn’t a one-time project – it’s built into the platform. 

How does Nira support compliance in regulated industries like financial services? 

Financial services is a core vertical for us, and the design already leans into what regulated industries expect – full audit trails, human review before any action and data that’s never used to train models. For anything specific to your regulatory framework, we’d recommend talking directly with your NAVEX team so we can address your particular requirements. 

What’s coming next 

Will AI recommend policy updates based on investigation findings? 

That’s not live today, but it’s on our roadmap because it’s a real gap customers have identified. The direction is to get much more specific than simply recommending a policy update. We want to identify the exact policy – and eventually the specific section – that’s affected, and ultimately suggest language based on the trend driving the recommendation. 

Our plan is to take the same approach with regulatory changes by identifying which policies are impacted and recommending updates there as well. A human will always make the final decision before any policy changes are made. 

How NAVEX connects intelligence using AI 

AI is most valuable when it helps compliance teams connect information, uncover insights and spend more time applying their expertise. That’s the approach behind NAVEX One. 

By bringing together Whistleblowing & Incident Management, Policy & Procedure Management, Ethics & Compliance Training, Risk & Governance and other connected risk and compliance solutions, NAVEX helps organizations put AI to work in practical ways while maintaining the governance, transparency and human oversight needed to build trust and support better decision-making.