Yes, a large part of it can. Data collection, evidence review, risk scoring, monitoring and alerting are all well suited to automation, and AI can now read security documents and complete assessments that people once did by hand. Human judgment still matters for setting risk appetite and deciding how to treat the highest-risk findings, but the repetitive work no longer needs to be manual.
