π§ͺ Full Population Testing
Test every transaction in your population, not just a sample. Upload a CSV/Excel and define your test attribute; AI evaluates every row and produces a decision log.
Go to Engagement β Population Testing AI
Upload your population CSV/Excel (up to 50,000 rows)
Enter the control name and test attribute (what makes a row pass/fail)
Click Start Testing β AI processes rows in batches with a live progress bar
Review exceptions highlighted in red, download decision log as CSV
Click Save as Workpaper to save to your engagement file
π Testing Plan Executor
Upload your existing audit testing plan; AI follows it step by step against uploaded evidence.
Go to Engagement β Plan Executor
Upload your testing plan (.docx, .pdf, or .txt)
Review the AI-parsed test procedures
Upload your evidence files (CSV, Excel, PDF)
Click Execute Plan β AI works through each step
Review results and save complete workpaper
π Auto Decision Logs
Every Evidence Intelligence test automatically generates a structured decision log traceable to specific data points.
Go to AI Tools β Evidence Intelligence
Upload documents and run Classify or Test
Decision log appears automatically below results
Click Download Decision Log for CSV export
Click Save Decision Log to store in Supabase
π΅οΈ Fraud Risk Assessment
Generate fraud risk assessments per ISA 240 for any business process.
Go to Engagement β Fraud Risk
Select the process (Revenue, AP, Payroll, etc.)
Enter company context (size, industry, key systems)
Click Generate Assessment
Review top 10 fraud schemes with likelihood/impact ratings
Save as workpaper or export
π Management Action Plans
Track management responses to findings with owners, target dates, closure evidence.
Go to Engagement β Action Plans
All open findings are listed automatically
For each finding toggle Agreed/Disagreed, enter response, assign owner, set target date
Click Submit β email notification sent to auditor
Auditor clicks Re-test to mark finding closed
π‘ Regulatory Change Monitor
Automatic weekly scan of PCAOB, IIA, SEC, ISACA, FRC, FASB.
Go to Risk & Monitoring β Regulatory Monitor
Page loads and AI scans for latest updates automatically
Review feed: source, date, summary, impact (High/Medium/Low), affected modules
Mark items as Reviewed or Action Required
Action Required items create notifications in your platform
π Industry Benchmarking
Compare your GRC metrics against anonymized industry medians.
Go to Reporting β Benchmarking
Your metrics are pulled automatically from Supabase
Green = better than industry median, Red = below median
Click Share with Board to generate a PDF summary
π Resource Planning
Gantt-style engagement timeline with team capacity and deadline tracker.
Go to Platform β Resource Planning
View all active projects on the Gantt timeline
Click a project bar to edit dates, status, lead email
Click + New Engagement to create an engagement
Click a team member row to edit weekly capacity
Use βοΈ Edit and β Mark Complete on deadline rows
π MFA Setup
Add two-factor authentication using Google Authenticator or Authy.
Go to Settings β Enable MFA
Scan the QR code with your authenticator app
Enter the 6-digit code to confirm
MFA is now active
π Enterprise API
REST API access to integrate AssurAI data into your own dashboards.
Go to Platform β API Docs
Click Generate API Key in Settings
Use the key in the Authorization header: Bearer <key>
Endpoints: GET /api/v1/projects, /findings, /controls, /workpapers, /kris
Rate limit: 1000 requests/hour per key
π₯ Real-time Collaboration
Live comments and presence indicators on workpapers.
Open any workpaper in Workflow
See who else is viewing (presence indicator)
Scroll to the bottom for the comment thread
Type @ to mention a teammate
Comments trigger email notifications to preparer/reviewer
π₯ Excel Export
Export workpapers, findings, controls, evidence requests to formatted Excel.
Go to Workpapers, Findings, Controls, or Evidence Requests
Click π₯ Export to Excel
Choose template: Standard, Big 4, or PCAOB
File downloads as AssurAI_[Page]_[Date].xlsx
SOX & ICFR
Full Section 404 workflow β scoping, RCM, control testing, deficiency classification, PCAOB workpapers.
Internal Audit
IIA Standards-aligned engagement management β planning, fieldwork, findings, board reporting.
Risk & ERM
COSO ERM framework β risk register, heat maps, KRI monitoring, scenario analysis, board packs.
Compliance
Multi-framework compliance β SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS, cross-framework mapping.
BCM & Resilience
ISO 22301 aligned β BIA, recovery planning, tabletop exercises, crisis communications.
Financial Intelligence
Benford's Law, JE review, revenue recognition, reconciliation testing, going concern.
BSA/AML & FDICIA
Bank Secrecy Act compliance β AML programme assessment, SAR workflows, FDICIA internal controls testing.
Fund Compliance
Investment fund compliance β SEC/CFTC reporting, fund audit support, regulatory filing checklists.
New to AssurAI? Start by opening a module (e.g. SOX & ICFR), clicking "+ New Engagement", and running the Guided Project Wizard. It will walk you through every step of the engagement.
Create an engagement
Open any module page and click "+ New Engagement". Give it a name (e.g. "SOX FY2026") and description. The project appears in your dashboard and in the module's left panel.
Select a project
On pages like Risk Assessment, Executive Dashboard and Compliance Calendar, use the project dropdown at the top right to load data for a specific engagement.
View all projects
Go to /projects to see all active engagements across all modules, with phase progress and status.
π Workpaper Structure
Every workpaper has six mandatory sections matching Big 4 and IIA standards:
- Objective β What are you testing and why?
- Scope & Population β What period, what data, any exclusions?
- Test Procedures β Step-by-step procedures performed
- Evidence Reference β What evidence supports the conclusion (EV-01, EV-02...)
- Exceptions Noted β Any control failures or anomalies found
- Conclusion β Effective / Ineffective / Not Applicable
βοΈ Sign-Off Workflow
Every workpaper moves through a four-stage approval process:
- Draft β Preparer is working on it. Can be edited.
- In Review β Submitted to reviewer. Preparer clicks "Submit for Review β"
- Approved β Reviewer has approved content. Senior reviewer clicks "Approve"
- Signed Off β Final lock. No further edits. PCAOB/IIA aligned.
Create a workpaper
Go to /workflow and click "+ New Workpaper". Fill in the Reference (e.g. WP-SOX-001), select a project, and complete all six structured sections.
Save as draft
Click "Save Draft" to save progress without submitting. You can return and edit at any time while in Draft status.
Submit for review
Click "Submit for Review β" when complete. Status moves to In Review. The reviewer will be notified by email if notifications are configured.
View and export
Click "View" on any workpaper to see the full structured content. Click "Export PDF" to generate a print-ready workpaper with sign-off blocks.
AI shortcut: Run any AI tool from a module page to generate workpaper content automatically. Copy the output into the Test Procedures and Conclusion fields.
β οΈ IIA 5C Finding Structure
- Condition β What IS β the issue found (factual, specific)
- Criteria β What SHOULD BE β the policy, standard or control requirement
- Cause β Root cause β WHY it happened
- Consequence / Effect β Financial, operational or compliance impact
- Corrective Action / Recommendation β Specific, actionable steps
π Remediation Workflow
- Open β Finding logged, awaiting management response
- In Progress β Management has acknowledged and is remediating
- Remediated β Management confirms fix is complete. Evidence provided.
- Verified Closed β Auditor re-tested and confirmed control now operating effectively
- Overdue β Due date has passed and finding remains open (auto-flagged in red)
π Exporting Findings
Click "Export Report" in the top right of the Findings page to generate a formatted findings summary report β suitable for management or audit committee presentation. Filter by status, severity or module before exporting.
Email alerts: When a finding becomes overdue, AssurAI automatically sends an email alert to the remediation owner. Alerts are also sent 3 days before the due date as a reminder.
ποΈ Control Attributes
- Control ID β Unique identifier (e.g. SOX-JE-001)
- Control Type β Preventive or Detective
- Frequency β Daily, Weekly, Monthly, Quarterly, Annual, Transaction-level
- Automated / Manual β System-enforced or human-performed
- SOX Key β Flagged if it's a key control for Section 404
- Test Result β Effective, Ineffective, or Not Tested
- Related Modules β Which GRC modules this control applies to
π¬ Test Case vs Test Execution
- Test Case β The test design: what to test, how, sample size, evidence required
- Test Execution β The result of running the test: Pass, Fail, or Pass with Exceptions
AI-powered testing: Use the ITGC Testing Agent or Control Testing tool from any module to auto-generate test procedures, sample sizes and documentation guidance for any control.
π― SOX & ICFR Agents
SOX Scoping Agent
Identifies FSLIs, calculates materiality, produces scoping memo
Deficiency Assessment Agent
Classifies CD/SD/MW, drafts management letter language
RCM Builder Agent
Builds complete Risk and Control Matrix for any process
IPE Validator Agent
Tests completeness and accuracy of reports controls rely on
ITGC Testing Agent
Builds test procedures for all 4 ITGC domains
Rollforward Agent
Rolls prior year SOX programme forward with updated scope
π Internal Audit Agents
Audit Planning Agent
Risk-based audit plan with timing, hours and team assignments
Engagement Letter Agent
IIA-standard engagement letter ready to send
Finding Writer Agent
Complete IIA 5C finding in professional audit language
Fraud Risk Agent
Fraud scenarios, fraud triangle, ISA 240 test procedures
Audit Committee Report Agent
Board-ready AC pack with programme status and findings
Audit Universe Agent
Risk-scored audit universe with 3-year coverage plan
π‘οΈ Risk & ERM Agents
Risk Assessment Agent
Complete risk register with heat map and KRI recommendations
Risk Register Agent
20+ risks identified, scored, controls mapped, COSO aligned
Scenario Analysis Agent
Base / Adverse / Severe / Catastrophic scenarios modelled
Third-Party Risk Agent
Vendor scorecard across 5 risk dimensions
KRI Monitoring Agent
5 KRIs per risk with G/A/R thresholds and owners
How to run an agent: Go to /ai-agents, find the agent you need, click "βΆ Run", describe your situation in the text box, and the agent produces complete output. All agents are available at all plan levels unless marked Professional+.
π How the Pipeline Works
Select your module
Choose SOX & ICFR, Internal Audit, Risk & ERM, Compliance, BCM, or Financial Intelligence.
Select a project
Use the dropdown to choose which engagement the output will be saved to.
Describe your engagement
Write a description of your company, situation and key areas of concern. The more detail, the better the output.
Click Run
Watch 5 agents run in sequence. Each agent's output feeds the next, building cumulatively on context.
Save to engagement
Click "πΎ Save to Engagement File" β all 5 outputs are saved as draft workpapers in your selected project, ready for review.
AI-generated content should always be reviewed by a qualified professional before reliance. The pipeline produces a strong first draft β not a finished deliverable without review.
Drop your documents
Upload any file type β CSV, Excel, PDF, screenshots, emails. AI parses and classifies each automatically.
AI executes the test
The AI follows your audit procedure step by step, testing each control attribute against the evidence provided.
Get a workpaper
Every conclusion is linked to specific evidence. One click generates a formatted, sign-off-ready workpaper with full evidence traceability.
| Module | AI Tools | Frameworks | Key Features |
|---|---|---|---|
| π‘οΈ SOX & ICFR | 24 tools | PCAOB AS 2201 | Scoping, RCM, materiality, ITGC, deficiency classification |
| π Internal Audit | 22 tools | IIA IPPF | Engagement planning, fieldwork, findings, board reporting |
| π Risk & ERM | 23 tools | COSO ERM Β· ISO 31000 | Risk register, heat maps, KRIs, scenario analysis, board packs |
| βοΈ Compliance | 16 tools | SOC 2 Β· GDPR Β· ISO 27001 Β· HIPAA Β· PCI | Gap assessments, policy drafting, certification campaigns |
| π‘οΈ BCM & Resilience | 15 tools | ISO 22301 Β· NIST | BIA, recovery plans, tabletop exercises, crisis comms |
| π° Financial Intelligence | 15 tools | ASC 606 Β· GAAP | Benford's Law, JE review, reconciliation, going concern |
| π¦ BSA/AML & FDICIA | 12 tools | BSA Β· FinCEN Β· FDICIA | AML programme assessment, SAR workflows, FDICIA internal controls, CDD testing |
| π Fund Compliance | 10 tools | SEC Β· CFTC Β· AIFMD | Fund audit support, regulatory filing checklists, investor reporting, compliance calendar |
Guided Project Wizard: Every module has a guided step-by-step wizard (yellow banner at the top of the tools panel). Click it to get a structured workflow from planning through reporting.
π‘οΈ Key SOX Tools
- Scoping & FSLI β Materiality calculation, FSLI identification, scope documentation
- RCM Builder β Risk and Control Matrix for any business process
- Control Testing β Test procedure design, population and sample guidance
- Deficiency Analyzer β CD / Significant Deficiency / Material Weakness classification
- ITGC Testing β User access, change management, backup, privileged access
- SoD Analyzer β Segregation of duties conflict identification
- IPE Assessment β Information Produced by Entity testing
- Y/Y Rollforward β Prior year programme rollforward
- SOX Certifications β Sub-certification management (/sox-certifications)
π Risk Assessment Page (/risk-assessment)
A dedicated risk management workspace with:
- Risk Heat Map β Visual 5Γ5 likelihood Γ impact grid with your risks plotted as dots
- Risk Register β Full register with filtering by rating and status
- Risk by Category β Bar chart showing risk distribution across categories
- + Add Risk β Log any risk with full scoring, ownership and treatment status
π‘οΈ Risk Module Tools (23)
- AI Tools (16) β KRI Dashboard, Third-Party Risk, Emerging Risk Radar, Bow-Tie Analysis, Risk Heat Map Builder, COSO ERM Assessment, Risk Register Builder, Risk Scoring Model, Residual Risk Analyzer, Scenario Analysis, Risk Treatment Plan, KRI Designer, Board Risk Report, Regulatory Change Monitor, Cyber Risk Assessment, FAIR Cyber Risk Model
- Calculators (2) β Monte Carlo Simulator, Risk Quantification Calculator
- Templates (3) β ERM Framework Builder, Risk Appetite Tool, Risk Taxonomy Designer
- Workflow (2) β Risk Review Workflow, Risk Committee Pack
βοΈ Supported Frameworks
SOC 2 Type II Β· ISO 27001 Β· GDPR Β· HIPAA Β· PCI DSS v4.0 Β· CCPA Β· AML Β· ESG Β· NIST CSF Β· ISO 22301 Β· SOX Β· FedRAMP Β· DORA Β· and 12 more
π Dashboard KPIs
- Total Controls β Controls in scope for the selected project
- Controls Tested % β Percentage of controls with completed test executions
- Open Exceptions β Active findings not yet remediated or closed
- High/Critical Risks β Risks rated High or Critical in the risk register
- Days to Completion β Set in project settings
Select a project from the dropdown to load live data. Click Refresh to update.
β‘ Real-time KPI Strip
A persistent banner at the top of the Executive Dashboard shows live cross-engagement totals β open findings, controls tested today, overdue remediations, and KRI breaches β updated in real time without a page refresh.
π Integration Canvas
The Integration Canvas (/integration-canvas) provides a visual data-flow map of every connected system β showing how data moves from your source systems (Okta, Azure AD, GitHub, AWS, Jira, Slack) into AssurAI modules in real time.
- Live connection status β green/amber/red for each integration
- Data volume indicators β records synced, last sync timestamp
- One-click re-sync β trigger a manual pull from any source
- AI mapping suggestions β AI recommends which controls each data source should feed
π Customisable Shortcuts
The dashboard shortcut bar supports 200+ pinnable tools. Click the Edit Shortcuts button to browse the full library by module and drag tools into your personal shortcut bar. Your configuration is saved per user.
π What's Logged
- Workpaper created, edited, submitted for review, approved, signed off
- Finding created, status changed, remediated, verified closed
- Control tested, result recorded
- Project created or modified
- AI Agent Pipeline output saved to engagement
π₯ Exporting the Audit Trail
Click "Export CSV" to download the complete audit trail. Filter by entity type, action, actor or date range before exporting to narrow the output. The CSV is suitable for external auditor review.
Immutable: Audit trail entries cannot be modified or deleted β not even by administrators. Every entry is timestamped and attributed to a specific user email.
π Using the Calendar
- Select a project from the dropdown to load its deadlines
- Click + Add Deadline to log a new deadline with owner, category and reminder setting
- Colour coding β Red = overdue, Amber = due within 7 days, Blue = upcoming
- Upcoming Deadlines panel (right side) β sorted list with days remaining
- Alerts β Red banner for overdue, amber banner for items due within 7 days
Workpaper Export
Click "Export PDF" on any workpaper. Generates a print-ready document with sign-off blocks, evidence references and all structured sections.
Findings Report
Click "Export Report" on the Findings page. Generates a formatted findings summary with severity ratings, status, recommendations and management responses.
Audit Trail CSV
Click "Export CSV" on the Audit Trail page. Complete immutable log suitable for external auditor review.
Print Any Page
Every page has a print button or is print-optimised. Use Cmd+P (Mac) or Ctrl+P (Windows) for a clean printed version.
π΄ Pre-configured Monitors
- User Access Review β SOX ITGC Β· Daily
- Journal Entry Anomalies β SOX Financial Β· Daily
- Change Management β SOX ITGC Β· Weekly
- Segregation of Duties β SOX Controls Β· Weekly
- Vendor Payment Anomalies β Fraud/AP Β· Daily
- Privileged Access Monitoring β Cybersecurity Β· Hourly
Click "+ Add Monitor" to create custom monitors. Click "βΆ Run" to test on-demand.
π How Cross Assurance Works
Describe your control
Go to /cross-assurance and describe the control you want to map β or select from your control library.
AI maps to all frameworks
The engine identifies every applicable clause, requirement or control objective across 25 frameworks that your control satisfies.
Calculate savings
See estimated audit hour savings from eliminating duplicate testing across frameworks. Typical savings: 40β60% of testing hours.
π€ Profile
Update your name, email, job title, and avatar. Change your password or configure Single Sign-On (SSO) for your organisation.
π Integrations
Connect AssurAI to your existing tech stack. Available integrations include:
- Identity β Okta, Azure AD, Google Workspace
- Dev & Cloud β GitHub, GitLab, AWS, Azure, GCP
- ITSM β Jira, ServiceNow, Linear
- Comms β Slack, Microsoft Teams
- GRC β ServiceNow GRC, Archer, MetricStream
Each integration has a connection wizard β click Connect, authorise via OAuth or API key, and configure which modules receive the data feed.
π€ AI Provider
AssurAI defaults to Claude (Anthropic). In this tab you can switch your organisation's AI provider or bring your own API key:
- Claude (Anthropic) β default, recommended for audit-quality output
- GPT-4o (OpenAI) β paste your OpenAI API key
- Gemini (Google) β connect via Google AI Studio key
- Azure OpenAI β use your enterprise Azure endpoint
π Notifications
Configure email and in-app alerts per event type:
- Finding overdue β email to owner + CAE at day 7, 14, 30
- Workpaper submitted for review β email to assigned reviewer
- KRI threshold breach β email to Risk Manager and CRO
- Regulatory monitor alert β weekly digest or immediate push
π₯ Team
Invite team members, assign roles (Admin, Manager, Preparer, Viewer), and manage module-level access permissions. Admins can deactivate users and transfer ownership of engagements.
π Security
- MFA β Enable TOTP-based two-factor authentication (Google Authenticator / Authy)
- SSO β SAML 2.0 / OIDC for enterprise identity providers
- API Keys β Generate and revoke keys for the Enterprise REST API (1,000 req/hr)
- Session timeout β Configure idle session expiry (15 min to 8 hrs)
- IP Allowlisting β Restrict platform access to approved IP ranges
π¨ Brand
Upload your organisation's logo and set primary brand colours. These appear on exported PDFs, workpaper covers, board portal reports, and the PBC Portal client-facing pages. White-labelling is available on Enterprise plans.
Excel Add-in: Run AI-powered audit tests directly inside Microsoft Excel. Download from /excel-addin or the Microsoft AppSource. Select any data range, choose a test (JE review, Benford's Law, user access), and get PCAOB-aligned findings written back to your sheet.
πΊοΈ What the Canvas Shows
- Source nodes β each connected system (Okta, GitHub, Azure AD, Jira, AWS, Slack, etc.) appears as a labelled node on the left
- Module nodes β each AssurAI module appears on the right; arrows connect data flows between source and module
- Connection health β green (live), amber (degraded), red (disconnected) status on every arrow
- Last sync β hover any arrow to see the timestamp and record count of the last successful pull
β‘ AI Mapping Suggestions
When you connect a new integration, AssurAI's AI analyses the data schema and recommends which controls, test procedures, and modules should consume it β saving setup time and reducing the risk of missing evidence sources.
Go to /integration-canvas and click + Add Integration
Select your system (or use Generic REST connector)
Authorise via OAuth or paste your API key
Review AI mapping suggestions β approve or adjust
Click Activate β data begins flowing within seconds
New in September 2026: The Integration Canvas now supports bi-directional flows β findings and remediation status can be pushed back to Jira or ServiceNow automatically, keeping your ITSM tickets in sync.