Help & User Guide

Everything you need to run an audit on AssurAI

From your first login to AI-powered evidence testing — this guide walks your Internal Audit team through every part of the platform. Use the search on the left to jump to any topic.

Quick Start

New to AssurAI? These three steps take you end-to-end — from your first uploaded document to a saved workpaper — in a few minutes.

Upload your first document to Evidence Intelligence. Open Evidence Intelligence, drop in an invoice or control document, and let the AI classify and assess it.
Run your first AI Agent Pipeline. Open the AI Agent Pipeline, pick a module, and watch five specialist agents collaborate to produce a full analysis — complete with a colour-coded risk dashboard.
Create your first workpaper. From any AI output click Save as Workpaper, then open Workpapers to edit, submit and sign it off.

🚀 New User? Start Here

Welcome to the Internal Audit team. Your organisation is already set up — your engagements, team and workpapers are waiting for you. Follow these seven steps on your first day.

Log in with your company Google account. Go to getassurai.com/login.html and click Continue with Google. Use your @bloomenergy.com address — no separate password to remember.
Land on your Dashboard. You'll see your organisation's engagements, open findings and key metrics. Everything here is private to your organisation.
Open an engagement. Click any engagement to open its Engagement File — the home base for that audit.
Browse the Workpapers. Open the Workpapers view to see what's already been prepared, submitted or approved.
Try Evidence Intelligence. Upload an invoice or a control document and let the AI classify it and assess its adequacy.
Run an AI Agent. Open Fraud Risk Assessment and run an assessment for a process such as Procure-to-Pay.
Save the result to your engagement. Click Save as Workpaper on the AI output and file it into the right engagement — then find it under Workpapers.
💡 Pro tip for auditors
Do the full loop once on a low-stakes control before your real fieldwork. Running one agent end-to-end — from prompt to a saved draft workpaper — is the fastest way to understand how the whole platform fits together.

🔑 Logging In

AssurAI uses Google Single Sign-On (SSO). You sign in with your company Google Workspace account — there is no separate AssurAI password.

Go to getassurai.com/login.htmlContinue with Google → choose your @bloomenergy.com account

How to use it

Click Continue with Google and pick your company account.
On first login you're automatically placed in your organisation (matched by your email domain) and taken to the Dashboard.
💡 Pro tip
Bookmark getassurai.com/dashboard.html once you're in. After your first SSO sign-in, that link takes you straight to your work.
⚠️ Common confusion
If you don't see your engagements after logging in, you may have signed in with a personal Google account instead of your @bloomenergy.com account. Sign out and sign back in with your company account.

📁 Projects & Engagements

An engagement (also called a project) is a single audit — for example "FY2026 Internal Audit — Procurement Process". It holds the engagement's workpapers, findings, controls, evidence and team. The Engagement File is its home page.

Sidebar → Dashboard → click an engagement → Engagement File

Understanding phases

Each engagement moves through phases. The current phase is shown on the engagement card and at the top of the Engagement File:

Planning Fieldwork Review Reporting Closed

How to use it

From the Dashboard, click an engagement to open its Engagement File.
Use the tabs/sections to move between Workpapers, Findings, Controls and Evidence for that engagement.
For SOX engagements, switch between By Phase and By Process (O2C, P2P, R2R, H2R, ITGC) to view work the way you plan it.
Use the Export button to produce a PDF of the engagement file.
💡 Pro tip for auditors
Keep one engagement per audit per year (e.g. FY2026 SOX — ITGC Review). It keeps your workpapers, findings and evidence cleanly separated for the file and for rollforward next year.

📄 Workpapers

A workpaper documents a piece of audit work — a walkthrough, a test of a control, or an analysis. Workpapers move through a sign-off lifecycle and are locked once approved.

Sidebar → Workpapers (or open an engagement → Workpapers)

The workpaper lifecycle

DraftSubmitted for reviewReviewedApproved & locked

How to use it

Create a workpaper directly, or save one from any AI agent (see Save to Engagement). It starts as a Draft.
Edit the draft — add the procedure performed, the population, results and your conclusion.
Submit for review when ready. The reviewer is notified.
The reviewer approves (which locks the workpaper) or returns it with review comments for you to clear.
⚠️ Important
Approving a workpaper locks it. To make further changes, the reviewer must re-open it — this preserves the integrity of the signed-off audit file.
💡 Pro tip for auditors
Clear every review note before re-submitting. A clean review trail (note raised → cleared → approved) is exactly what a quality reviewer or external inspector expects to see.

⚠️ Findings

A finding is an issue or control deficiency you've identified. AssurAI captures findings using the standard condition / criteria / cause / effect / recommendation structure and tracks them through to closure.

Sidebar → Findings (or open an engagement → Findings)

Severity levels

Critical Significant Moderate Observation

Finding lifecycle

Identified / OpenIn ProgressRemediatedVerified / Closed

How to use it

Log a finding — give it a title, severity, owner and the affected module/process.
Add the condition, criteria, cause, effect and your recommendation.
Capture management's response and a remediation owner and due date (see Management Action Plans).
When remediation is complete, verify the evidence and move the finding to Closed.
💡 Pro tip for auditors
Link the finding back to the workpaper that supports it. When the audit committee asks "what's the evidence for this issue?", you can answer in one click.

📥 Evidence & PBC Requests

"PBC" (Prepared By Client) requests let you ask control owners and process owners for evidence. AssurAI sends a secure link — the recipient uploads files without needing an AssurAI login.

Sidebar → Evidence Manager / PBC Portal

How to use it

Create a request — describe the evidence you need and choose the recipient (the control or process owner).
AssurAI emails the owner a secure upload link. They open it, upload their documents and submit — no login required.
The evidence flows back into the engagement, ready to test with Evidence Intelligence.
Outstanding requests send automatic escalating reminders and can escalate to the owner's manager if overdue.
💡 Pro tip for auditors
Be specific in the request ("Q3 user access listing for SAP S/4HANA, exported on the review date") — precise asks get the right evidence first time and cut down on back-and-forth.

🛡️ Controls

The control library holds the controls in scope for an engagement — their description, owner, frequency, whether they're a key control, and their current test status.

Sidebar → Controls (or open an engagement → Controls)

How to use it

Review the controls in scope and confirm which are key controls (the ones that must be tested).
Track each control's test status — Not Started, In Progress, Passed, or Exception.
Link controls to the workpapers that test them and to any findings raised.
💡 Pro tip for auditors
Filter to key controls first. For SOX, that's where your testing effort and the external auditor's reliance are concentrated.

🧪 Testing & Sampling

AssurAI supports the full testing workflow — design the test, select a sample (or test the whole population), perform the test against evidence, and record a PCAOB-style conclusion.

Open a control / workpaper → Run Test · or Sidebar → Sampling Engine / Population Testing AI

How to use it

Design the test — define the control objective, attribute(s) and the procedure.
Select a sample using the Sampling Engine (MUS or attribute sampling) — or test the entire population with Population Testing AI (up to 50,000 rows).
Perform the test — the AI evaluates each item against the attributes and flags exceptions with a decision log.
Record your conclusion — the AI proposes a PCAOB-style conclusion; you, the auditor, make the final judgement.
⚠️ The auditor concludes — not the AI
The AI proposes conclusions and highlights exceptions. You make the professional judgement and own the final conclusion in the workpaper.
💡 Pro tip for auditors
For high-volume, low-judgement controls (e.g. three-way match), run full Population Testing instead of a sample — you get 100% coverage and a defensible decision log for every exception.

Evidence Intelligence

Upload any audit document — PDF, Excel, Word or CSV — and the AI reads it, classifies it, evaluates it and maps it to your controls automatically, while detecting the type of testing required. It works across all six modules — SOX & ICFR, Internal Audit, Risk & ERM, Compliance, BCM & Resilience and Financial Intelligence — and MRC testing evaluates all five PCAOB attributes automatically.

Sidebar → AI ToolsEvidence Intelligence

Three testing modes — detected automatically

🔬
MRC testing
Detects Management Review Controls and evaluates 5 attributes. See the MRC section.
📊
IPE testing
Tests the completeness and accuracy of Information Produced by the Entity (reports, listings, queries).
📄
Standard evidence
Evaluates relevance, reliability and sufficiency against the control objective.
🧾
Decision log
Every AI judgement is traced to specific data points for a fully auditable trail.

How to use it

Upload or paste your evidence — PDF, Excel, Word, CSV, image or screenshot.
Click Classify Evidence with AI. The AI detects whether this is an MRC, IPE or standard evidence situation and runs the right test.
Review the adequacy rating, attribute-by-attribute analysis, any missing-attribute warnings and the suggested test procedures.
Save as Workpaper to file the analysis into your engagement (see Save to Engagement).
💡 Pro tip for auditors
When you upload a report or query result, tell the AI what the report should contain. It sharpens the IPE completeness-and-accuracy assessment.

🔬 MRC Testing (Management Review Controls)

Management Review Controls are some of the hardest controls to test — and AssurAI tests them automatically. This section explains what an MRC is, how the AI evaluates it, and why it matters.

What is an MRC — and why is it hard?

A Management Review Control is a control where a person reviews something and acts on it — for example a CFO reviewing a monthly variance analysis, or a controller reviewing a reconciliation. They're hard to test because a signature alone proves nothing: you have to evidence that the review had the right precision, rigour and follow-up, not just that someone signed off.

How Evidence AI detects an MRC

When you upload review evidence (a variance analysis, a reconciliation review, a board pack with annotations), AssurAI recognises the MRC pattern and switches into MRC mode — then evaluates the review against five attributes.

The 5-attribute evaluation framework

1 · Performance
Was the review actually performed — with evidence of the reviewer engaging with the data (not just a signature)?
2 · Competence
Did the reviewer have the authority and expertise to perform the review effectively?
3 · Timeliness
Was the review performed on time — within the period and before the related reporting deadline?
4 · Effectiveness
Was the review at the right level of precision — did it identify and challenge the items it should have (e.g. variances over threshold)?
5 · Documentation
Is there sufficient documentation of the review, the questions raised and how they were resolved?

Worked example — a CFO variance analysis

You upload the monthly P&L variance analysis the CFO reviewed. The AI evaluates: did the CFO investigate variances above the threshold (effectiveness/precision)? Are there review notes, questions or annotations showing engagement (performance)? Was it reviewed before the close deadline (timeliness)? Is the CFO the appropriate reviewer (competence)? Is the review documented well enough to re-perform (documentation)? You get a rating per attribute plus the gaps to follow up.

⚠️ Why this matters — PCAOB AS 2201
For MRCs, regulators (PCAOB AS 2201) expect evidence of the precision of the review — that it operates at a level that would catch a material misstatement. A sign-off without evidence of investigation is the classic MRC deficiency. AssurAI's 5-attribute test is built around exactly this expectation.
💡 Pro tip for auditors
Upload the actual review document — the marked-up variance analysis with the reviewer's notes and questions — not just the sign-off sheet. The sign-off proves someone approved it; the marked-up document proves the review had precision. The AI can only assess what you give it.

🤖 AI Agents

AI Agents are specialist tools — each one is an expert at a single audit task. There are 20+ agents; pick the one that matches your work, give it data, and it runs the analysis with Big-4-grade prompts built in.

Sidebar → AI Agents

The specialist agents

How to use any agent

Open the agent from the AI Agents page.
Provide its input — upload a file, paste data, or describe the process/scope.
Run the agent and review its structured output, exceptions and decision log.
Click Save as Workpaper to file the output into your engagement (see Save to Engagement).
💡 Pro tip for auditors
Every agent output is a starting point, not a conclusion. Read the decision log, sanity-check a few items yourself, then add your own judgement before you submit the workpaper for review.

🔗 Agent Pipeline

Five specialist agents collaborate in sequence — each one builds on the output of the last — to complete a multi-step audit procedure autonomously. It's available for SOX & ICFR, Internal Audit, Risk & ERM, Compliance, BCM & Resilience and Financial Intelligence. Outputs save directly to your engagement file, and you can export the result as PDF, Word or PowerPoint.

Sidebar → AI AgentsAgent Pipeline

How to use it

Pick a module and provide the starting input, then run the pipeline — the five agents execute in turn, each feeding the next.
Review the combined output. For Risk & ERM, the pipeline auto-renders a colour-coded risk dashboard — a 5×5 heat map, a risk register and key-metric cards.
Save the result to your engagement, and export any agent output or the full report as PDF, Word or PowerPoint.
💡 Pro tip for auditors
Start with a two-agent chain before building longer pipelines. It's easier to review the hand-off between two steps and confirm the logic holds.

📊 Data Analytics

12 pre-built use cases turn raw data into audit-ready findings. Upload your own CSV or Excel to run a live AI analysis, or explore any use case instantly with built-in sample data — no upload required.

Sidebar → AI ToolsData Analytics

The 12 use cases

JE Anomalies Vendor Payments UAR Payroll Three-Way Match Revenue Expense IT Change Access Provisioning Bank Reconciliation Fixed Assets Contract Review

How to use it

Pick a use case and click Run Analysis — with no upload it returns realistic sample KPIs, severity-rated findings and an audit-language narrative immediately, marked with a "Using sample data" badge.
To analyse your own data, upload a CSV or Excel file and run the same use case against it for a live AI analysis.
Review the findings and save the analysis to your engagement as a workpaper.
💡 Pro tip for auditors
Use sample mode to learn what each analysis produces before fieldwork, then upload your real population to run it for the engagement. The output format is identical — only the data changes.

🔀 Flowchart Builder

Describe a process in plain English and the Flowchart Builder generates a visual swimlane diagram — plus a full process narrative and a risk-and-control matrix, all generated automatically — in one click.

Sidebar → Flowchart Builder

How to use it

Pick a template (Procure-to-Pay, Payroll, Order-to-Cash…) or describe your process.
Generate the swimlane diagram, narrative and risk/control matrix.
Refine the description and regenerate; then save it to your engagement as a walkthrough workpaper.
Export the flowchart as SVG, PNG, PDF or Visio (.vsdx) — open the Visio file directly in Microsoft Visio or draw.io for further editing.
💡 Pro tip for auditors
Use it at the start of a walkthrough to draft the process map, then confirm and correct it live with the process owner. It turns a blank page into a 5-minute review.

🔌 Integrations

Connect AssurAI to your source systems to pull data straight into the platform for automated testing. The Integrations Hub is where you set up and manage every connection.

Sidebar → Integrations · or visit integrations-hub.html

Live connectors

How to use it

Open the Integrations Hub and choose a connector — Workday Financials or BlackLine.
Complete the connection setup and field mapping, then import GL or reconciliation data for automated testing — or use sample-data mode to explore with no credentials required.
Run MRC testing on the imported data and save the results to your engagement.
💡 Pro tip for auditors
The Hub also previews SAP, NetSuite, ServiceNow, Dynamics 365, Okta and Workiva. Start with sample-data mode to see exactly what each import looks like before you involve IT for credentials.

💾 Save to Engagement

Every AI agent output can be filed directly into an engagement as a workpaper. This is what keeps your AI analysis organised inside the audit file instead of scattered across downloads — and it's available on all 20+ agents.

Why it matters

An AI result is only useful in an audit if it lands in the right place in the file, with the right context, ready to review and sign off. Save to Engagement does exactly that — one click turns an agent output into a draft workpaper in the correct engagement.

How to use it — the 5-level hierarchy

Click Save as Workpaper on any AI result and choose, top to bottom:

1 · Module
SOX & ICFR, Internal Audit, Risk & ERM, or Compliance.
2 · Engagement
The specific audit/project this belongs to.
3 · Business Process
O2C, P2P, R2R, H2R, ITGC… (especially important for SOX).
4 · Section
Where in the engagement file the workpaper sits.
5 · Workpaper Type
Walkthrough, Test of Operating Effectiveness, Analysis, etc.
On any AI agent result, click Save as Workpaper.
Work down the five levels — Module → Engagement → Business Process → Section → Workpaper Type.
Choose Save as Draft (or Save & Submit for Review). The output is filed as a workpaper in the chosen engagement.
Go to Workpapers to find it — then edit, submit for review, and approve it like any other workpaper.
💡 Pro tip for auditors
For SOX work, always pick the correct Business Process (O2C / P2P / R2R / H2R / ITGC). It's what lets the engagement file group everything By Process and gives the external auditor a clean, navigable file.
Where does the saved workpaper go?
Straight into the Workpapers list for the engagement you selected, as a Draft. Nothing is auto-approved — you review and sign it off.

🗂️ Engagement Modules

AssurAI organises work into modules. Your engagements live inside the module that matches the type of work.

📋
SOX & ICFR
SOX compliance, ITGC testing, and 302/906 certifications — organised by business process.
🔎
Internal Audit
Full audit lifecycle — planning, fieldwork, findings and reporting.
📊
Risk & ERM
Risk assessment, risk register and continuous monitoring.
⚖️
Compliance
Regulatory compliance tracking and mapping across frameworks.
💡 Pro tip for the Internal Audit team
Your day-to-day home is the Internal Audit module, but you'll dip into SOX & ICFR whenever you test ITGCs or controls relied on for financial reporting.

📊 Reporting & Monitoring

Stay on top of risk and tell the story to leadership — these tools turn your audit work into monitoring signals and board-ready reporting.

How to use them

Check the KRI Monitor for any amber/red breaches before status meetings.
Scan the Regulatory Monitor weekly for standards changes that affect your controls.
Use the Audit Universe to prioritise next year's plan by risk.
Generate the Audit Committee Report when you need a board pack — then review and tailor it.
💡 Pro tip for auditors
Generate the Audit Committee Report a few days before the meeting and edit the narrative. The AI gives you a strong 90% draft; your judgement makes the last 10% land with the committee.

🧰 Platform Features

Supporting tools that run across all your engagements.

SOX Certifications
302/906 certification cycles and certifier management — create a new cycle and track sign-offs.
📐
Benchmarking
Compare your performance and GRC metrics against industry peers.
📆
Resource Planning
Team utilisation, capacity (RAG) and budget tracking with a Gantt timeline.
⏱️
Time Tracker
Log time against engagements with budget-vs-actual reporting.
🧾
Audit Trail
A complete, tamper-evident history of every action taken in the platform.
💡 Pro tip for auditors
Log time as you go in the Time Tracker. Accurate budget-vs-actual data is gold when you're scoping next year's engagement and defending your resourcing.

📅 Audit Planning & Tracking

Plan engagements visually, track hours against budget, and manage external auditor document requests — the tools that keep an engagement on schedule and on budget.

💡 Pro tip for auditors
Build the Gantt plan first, then track time against the same phases — the budget-vs-actual variance tells you early when an engagement is drifting.

📊 Benchmarking & Analytics

See how your audit program compares to industry peers, and roll multiple entities up into a single consolidated view of your group.

💡 Pro tip for auditors
Use the Benchmarking Dashboard before planning season — knowing where your cycle time or coverage sits against peers helps you make the case for resourcing.

🔔 Notifications

Decide exactly which email alerts you receive and how often — so the right things reach you without the noise.

How to use it

Open Notification Settings and toggle which of the 13 notification types you want — covering findings, controls, certifications and the weekly digest.
Choose your email frequency — Immediate, Daily Digest or Weekly Only.
💡 Pro tip for auditors
Set findings-overdue and SOX-cert-due to Immediate and put everything else on the Daily Digest — you stay on top of deadlines without a flooded inbox.

💼 Management & Stakeholder Portals

AssurAI provides purpose-built portals for stakeholders outside the audit team — so management, external auditors and the CAE can interact with the audit process without needing a full platform account.

How management responses work

Open a finding and use the Send to Management action to generate a secure, token-authenticated link.
Management receives the link by email, opens it in any browser — no login needed — and submits their response, remediation plan and target date.
The audit team is notified instantly and the response is recorded against the finding.
💡 Pro tip for auditors
Complete the Independence Declaration before every engagement, not just at onboarding — IIA Standard 1130 requires pre-engagement sign-off each time. Download the PDF as your evidence of independence.

🔐 Security & Compliance

AssurAI is built for enterprise audit teams who need to know exactly how their data is protected and what compliance frameworks the platform meets.

🔐
SOC 2 Trust Center
Full security and compliance documentation — encryption, infrastructure, access control, data residency and regulatory alignment.
🛡️
Data Encryption
Data encrypted at rest and in transit using AES-256 and TLS 1.2+.
⚖️
GDPR & CCPA
AssurAI is GDPR and CCPA compliant. A Data Processing Agreement (DPA) is available on request.
📋
Standards Alignment
Platform design aligns to IIA Standards, PCAOB AS 2201 and SOX requirements.
💡 For procurement and InfoSec teams
Share the Trust Center with your security and legal teams during vendor assessment. DPA requests can be sent to shakeel@getassurai.com.

Audit Efficiency Tools

Purpose-built tools that reduce administrative overhead — carry prior-year work forward, track how long issues have been open, automate follow-up scheduling and log time accurately against engagements.

Carry-Forward Workpapers
Copy any prior-year workpaper to a new engagement period in one click — objectives, procedures and conclusions carry over as a Draft with a CF reference.
📊
Issue Aging Reports
Aging Analysis tab on the findings page — four color-coded buckets (0–30, 31–60, 61–90, 90+ days) with a full aging table sorted by days open.
📅
Follow-Up Scheduling
Auto-prompts to schedule a follow-up when a finding is marked Remediated — assign an auditor, set a verification date and track via the Follow-Up Due filter.
⏱️
Real Time Tracking
Log hours against engagements with date, activity and notes — saved to Supabase. Resource planning shows budgeted vs actual hours with configurable capacity targets.

How to use Carry-Forward Workpapers

Open the workpaper list for the prior-year engagement.
Click Carry Forward on any workpaper row and choose the target engagement period.
The new workpaper is created as a Draft with a CF reference — update the procedures and conclusions for the current year, then submit for review.
💡 Pro tip for auditors
Use Issue Aging to prioritise your follow-up effort — focus on the 61–90 day and 90+ buckets first. Those are the issues most likely to slip into the next audit cycle unremediated.

🎯 AI-Powered Testing Tools

AssurAI's AI testing tools automate the time-consuming, mechanical parts of audit fieldwork — classifying evidence, evaluating controls, documenting walkthroughs, and reconciling datasets — while keeping every professional conclusion in your hands.

MRC Deterministic Testing

Management Review Controls require consistent evaluation against PCAOB AS 2201's five attributes. AssurAI runs MRC testing at temperature=0 — the same evidence always produces the same conclusion.

💡 Results are consistent
Temperature=0 means the same evidence always produces the same evaluation. The AI cites the exact text from your document for every attribute conclusion — if the evidence is not present, it states NOT FOUND rather than fabricating.
Evidence Intelligence → upload document → Run MRC Test → review 5-attribute table → edit conclusion → print workpaper
Upload your evidence document to Evidence Intelligence.
Click Run MRC Test — the AI evaluates all five PCAOB AS 2201 attributes (Precision, Investigation, Frequency, Preparer Competence, Documentation) with an exact evidence quote for each.
Review the 5-attribute table. Each row shows: attribute, result (PASS/FAIL), confidence (HIGH/MEDIUM/LOW), and the exact evidence quote.
Review and edit the AI auditor conclusion, then sign off — your name and timestamp are added to the workpaper.
Click Print Workpaper to produce a Big 4 formatted PDF for your engagement file.

RCM Auto-Reader

If you already have a Risk Control Matrix in Excel, PDF, Word, or CSV, you do not need to re-enter it manually. Upload it and the AI extracts every control automatically.

RCM Reader → upload RCM file → review extracted controls → add to library
Go to RCM Reader and upload your existing RCM file (any format — no template required).
Review the extracted controls — the AI identifies control ID, name, description, process, frequency, control type, and owner.
Select the controls you want to import and click Add to Control Library — or generate an evidence request list from them directly.

Walkthrough AI

From meeting notes to a structured workpaper in minutes. Paste your walkthrough interview notes and the AI builds the narrative, flowchart, and control list.

Walkthrough AI → paste meeting notes → review narrative + flowchart → save to engagement
Go to Walkthrough AI and paste your meeting notes or interview transcript.
The AI generates: a structured process narrative, an SVG flowchart of the process, a list of controls identified, and key risk points.
Review and edit, then click Save to Engagement to file it as a workpaper.

Reconciliation AI

Upload two datasets — GL and bank statement, intercompany accounts, AR/AP — and the AI matches transactions, identifies exceptions, and generates a complete reconciliation workpaper.

Reconciliation AI → upload Dataset A and B → review matched/unmatched/exceptions → export workpaper
Go to Reconciliation AI and upload your two datasets.
The AI matches records, identifies unmatched items, and classifies exceptions with a likely cause for each.
Review the exception detail, add your conclusions, and export the full reconciliation workpaper.

Prior Year Workpaper Ingestion

Stop copy-pasting prior year workpapers. Upload the PDF or Word file and the AI reads the structure, objectives, procedures, and conclusions — then creates a new Draft with [PY] markers ready for this year.

Open any workpaper and click Import Prior Year, then upload the prior year PDF or Word file.
The AI creates a new Draft workpaper pre-populated with prior year content, with [PY] markers wherever current-year updates are needed.
Work through the [PY] markers, updating objectives, procedures, and conclusions for the current year — then submit for review.

📎 Evidence Intelligence & Management

Evidence Intelligence is the intake layer for all your audit evidence. Every document you upload is classified, authenticated, matched to controls, and hashed — before a human has read it.

Uploading documents for classification

Evidence IntelligenceUpload Document → AI classifies automatically

Supported formats: PDF, Excel (.xlsx), Word (.docx), CSV, images (PNG/JPG), screenshots.

Understanding the classification output

After upload, the AI returns a structured classification covering:

Module
Which GRC module this evidence applies to (SOX, Internal Audit, Risk, Compliance)
Evidence type
What kind of document it is (Management Review, Approval, Report, Log, Certificate)
PCAOB assertions
Which PCAOB AS 2201 assertions the evidence supports
Adequacy
Whether the document is sufficient to support a control conclusion

Missing evidence alerts

After classification, AssurAI runs a coverage check across your uploaded evidence. If any key MRC attribute lacks supporting evidence, a Missing Evidence Alert appears before you run the test — so you can collect the missing document before testing rather than discovering the gap in the workpaper.

⚠️ Act on missing evidence alerts before testing
If an attribute shows NOT FOUND during MRC testing, the AI will document it as absent — it will not fabricate evidence. Collecting missing evidence before testing saves you a re-run.

Evidence auto-matching

Classified documents are automatically matched to controls in your library based on content analysis. High/Medium confidence matches appear on the control's evidence panel — click to accept the link in one click.

Cryptographic evidence hashing

Every uploaded document receives a SHA-256 integrity certificate — a unique digital fingerprint at the moment of upload, timestamped and linked to the uploader's identity. If the file is ever modified, the hash will not match. Download the Evidence Integrity Certificate from the document detail page to include in your audit file.

Redboxed evidence packages

Evidence Intelligence → document → Generate Redboxed Package

The AI identifies the exact text passages that support each PCAOB attribute conclusion and highlights them in Big 4 style. Download a print-ready PDF with all redboxed passages and the attribute mapping table.

💡 Pro tip for SOX teams
Attach the redboxed evidence package to your MRC workpaper before submitting for external audit review — it significantly reduces back-and-forth with the external audit team.

🚀 For Pre-IPO Companies

Building your SOX program before IPO is the single most cost-effective decision a pre-IPO CFO can make. Retrofitting SOX controls after IPO — with external auditors already on the clock — costs 3–5× more than building it right from the start.

Why start SOX-ready from day one

External auditors will test your controls for the first time in your IPO year. If you have documented, tested controls with evidence files already built in AssurAI, the audit is straightforward. If you are building controls in parallel with the audit, expect material weaknesses, audit delays, and significantly higher fees.

AI-native tools change the economics. A two-person finance team can build a SOX-compliant control environment in 90 days using AssurAI — at a fraction of traditional consulting costs.

Your first 90 days

Month 1: Build your control library. Upload your draft RCM using RCM Auto-Reader — the AI extracts every control, no template required. Add your key SOX processes: Revenue, Procure-to-Pay, Financial Close, Payroll, ITGC. Set owners and frequencies.
Month 2: Document processes and test key controls. Use Walkthrough AI to document each process — paste your interview notes, get a narrative and flowchart. Run MRC Testing on your highest-risk controls and generate Big 4 workpapers.
Month 3: Remediate gaps and produce the external auditor readiness report. Review findings from your MRC tests, remediate control deficiencies, and generate your external auditor readiness package — workpapers, evidence files, and findings log.

Key features for pre-IPO teams

💡 External auditor readiness tip
Your external auditors will ask for your RCM, walkthrough documentation, and evidence files for key controls. If these are all in AssurAI, you can export everything in Big 4 format in one step — saving weeks of preparation time.

→ View the full Pre-IPO Guide

📨 Getting Help

Need a hand or want to see more? We're here to help you get the most out of AssurAI.

💡 The fastest way to get unstuck
Email shakeel@getassurai.com with a screenshot and the engagement you're working in — that context lets us answer in one reply.

Frequently Asked Questions

Can multiple team members work on the same engagement?
Yes — all team members in your organisation see the same engagements and workpapers, and can collaborate in real time with comments and presence.
Is my data secure?
Yes — your data is isolated to your organisation. Other organisations cannot see your data. Access is enforced at the database level by row-level security.
Can I export workpapers?
Yes — use the Export button on the Engagement File page to export to PDF. AI tools can also export to Big 4, PCAOB or standard Excel templates.
How do I add a new team member?
Contact your AssurAI admin, or email support@getassurai.com.
What file types can Evidence Intelligence analyse?
PDF, Excel (.xlsx), Word (.docx), CSV, images (PNG, JPG) and screenshots.
Does the AI make the audit conclusion for me?
No — the AI provides analysis and observations. The auditor makes all professional judgements and conclusions. AssurAI is there to do the heavy lifting, not to sign your name.
What standards does AssurAI align to?
PCAOB AS 2201, IIA Standards (2024 edition), ISA 240, ISA 500, and SOX Sections 302 and 906.
Still stuck? Email us at support@getassurai.com — we're happy to help.

← Back to platform