πŸ“– User Guide

Everything you need to run a world-class audit programme.

AssurAI is the The Agentic GRC Platform built by ex-Big 4 practitioners. This guide covers every feature β€” from creating your first workpaper to running 5 AI agents in sequence.

Version 3.0 β€” September 2026
Modules 8 GRC modules
AI Tools 320+ AI tools
Frameworks 25+ supported
What's New
New Features Guide
The latest additions to AssurAI β€” from full-population testing and the testing plan executor to real-time collaboration, MFA and the Enterprise API. Each feature below includes a quick step-by-step.

πŸ§ͺ Full Population Testing

Test every transaction in your population, not just a sample. Upload a CSV/Excel and define your test attribute; AI evaluates every row and produces a decision log.

1

Go to Engagement β†’ Population Testing AI

2

Upload your population CSV/Excel (up to 50,000 rows)

3

Enter the control name and test attribute (what makes a row pass/fail)

4

Click Start Testing β€” AI processes rows in batches with a live progress bar

5

Review exceptions highlighted in red, download decision log as CSV

6

Click Save as Workpaper to save to your engagement file

πŸ“‘ Testing Plan Executor

Upload your existing audit testing plan; AI follows it step by step against uploaded evidence.

1

Go to Engagement β†’ Plan Executor

2

Upload your testing plan (.docx, .pdf, or .txt)

3

Review the AI-parsed test procedures

4

Upload your evidence files (CSV, Excel, PDF)

5

Click Execute Plan β€” AI works through each step

6

Review results and save complete workpaper

πŸ“‹ Auto Decision Logs

Every Evidence Intelligence test automatically generates a structured decision log traceable to specific data points.

1

Go to AI Tools β†’ Evidence Intelligence

2

Upload documents and run Classify or Test

3

Decision log appears automatically below results

4

Click Download Decision Log for CSV export

5

Click Save Decision Log to store in Supabase

πŸ•΅οΈ Fraud Risk Assessment

Generate fraud risk assessments per ISA 240 for any business process.

1

Go to Engagement β†’ Fraud Risk

2

Select the process (Revenue, AP, Payroll, etc.)

3

Enter company context (size, industry, key systems)

4

Click Generate Assessment

5

Review top 10 fraud schemes with likelihood/impact ratings

6

Save as workpaper or export

πŸ“ Management Action Plans

Track management responses to findings with owners, target dates, closure evidence.

1

Go to Engagement β†’ Action Plans

2

All open findings are listed automatically

3

For each finding toggle Agreed/Disagreed, enter response, assign owner, set target date

4

Click Submit β€” email notification sent to auditor

5

Auditor clicks Re-test to mark finding closed

πŸ“‘ Regulatory Change Monitor

Automatic weekly scan of PCAOB, IIA, SEC, ISACA, FRC, FASB.

1

Go to Risk & Monitoring β†’ Regulatory Monitor

2

Page loads and AI scans for latest updates automatically

3

Review feed: source, date, summary, impact (High/Medium/Low), affected modules

4

Mark items as Reviewed or Action Required

5

Action Required items create notifications in your platform

πŸ“ Industry Benchmarking

Compare your GRC metrics against anonymized industry medians.

1

Go to Reporting β†’ Benchmarking

2

Your metrics are pulled automatically from Supabase

3

Green = better than industry median, Red = below median

4

Click Share with Board to generate a PDF summary

πŸ“† Resource Planning

Gantt-style engagement timeline with team capacity and deadline tracker.

1

Go to Platform β†’ Resource Planning

2

View all active projects on the Gantt timeline

3

Click a project bar to edit dates, status, lead email

4

Click + New Engagement to create an engagement

5

Click a team member row to edit weekly capacity

6

Use ✏️ Edit and βœ“ Mark Complete on deadline rows

πŸ” MFA Setup

Add two-factor authentication using Google Authenticator or Authy.

1

Go to Settings β†’ Enable MFA

2

Scan the QR code with your authenticator app

3

Enter the 6-digit code to confirm

4

MFA is now active

πŸ”Œ Enterprise API

REST API access to integrate AssurAI data into your own dashboards.

1

Go to Platform β†’ API Docs

2

Click Generate API Key in Settings

3

Use the key in the Authorization header: Bearer <key>

4

Endpoints: GET /api/v1/projects, /findings, /controls, /workpapers, /kris

5

Rate limit: 1000 requests/hour per key

πŸ‘₯ Real-time Collaboration

Live comments and presence indicators on workpapers.

1

Open any workpaper in Workflow

2

See who else is viewing (presence indicator)

3

Scroll to the bottom for the comment thread

4

Type @ to mention a teammate

5

Comments trigger email notifications to preparer/reviewer

πŸ“₯ Excel Export

Export workpapers, findings, controls, evidence requests to formatted Excel.

1

Go to Workpapers, Findings, Controls, or Evidence Requests

2

Click πŸ“₯ Export to Excel

3

Choose template: Standard, Big 4, or PCAOB

4

File downloads as AssurAI_[Page]_[Date].xlsx


Section 1
Platform Overview
AssurAI is a complete The Agentic GRC Platform covering 8 modules β€” SOX, Internal Audit, Risk & ERM, Compliance, BCM, Financial Intelligence, BSA/AML & FDICIA, and Fund Compliance β€” all in one place, powered by AI.
πŸ›‘οΈ

SOX & ICFR

Full Section 404 workflow β€” scoping, RCM, control testing, deficiency classification, PCAOB workpapers.

πŸ“‹

Internal Audit

IIA Standards-aligned engagement management β€” planning, fieldwork, findings, board reporting.

πŸ“ˆ

Risk & ERM

COSO ERM framework β€” risk register, heat maps, KRI monitoring, scenario analysis, board packs.

βš–οΈ

Compliance

Multi-framework compliance β€” SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS, cross-framework mapping.

πŸ›‘οΈ

BCM & Resilience

ISO 22301 aligned β€” BIA, recovery planning, tabletop exercises, crisis communications.

πŸ’°

Financial Intelligence

Benford's Law, JE review, revenue recognition, reconciliation testing, going concern.

🏦

BSA/AML & FDICIA

Bank Secrecy Act compliance β€” AML programme assessment, SAR workflows, FDICIA internal controls testing.

πŸ“Š

Fund Compliance

Investment fund compliance β€” SEC/CFTC reporting, fund audit support, regulatory filing checklists.

πŸ’‘

New to AssurAI? Start by opening a module (e.g. SOX & ICFR), clicking "+ New Engagement", and running the Guided Project Wizard. It will walk you through every step of the engagement.

Section 3
Engagements
Every engagement in AssurAI is organised as a Project. Projects keep your workpapers, findings, controls, risks and evidence together.
1

Create an engagement

Open any module page and click "+ New Engagement". Give it a name (e.g. "SOX FY2026") and description. The project appears in your dashboard and in the module's left panel.

2

Select a project

On pages like Risk Assessment, Executive Dashboard and Compliance Calendar, use the project dropdown at the top right to load data for a specific engagement.

3

View all projects

Go to /projects to see all active engagements across all modules, with phase progress and status.


Section 4 β€” Core Workflow
Workpapers
AssurAI workpapers are structured audit documents with a defined anatomy and a formal sign-off workflow β€” from preparation through to locked and signed off.

πŸ“‹ Workpaper Structure

Every workpaper has six mandatory sections matching Big 4 and IIA standards:

  • Objective β€” What are you testing and why?
  • Scope & Population β€” What period, what data, any exclusions?
  • Test Procedures β€” Step-by-step procedures performed
  • Evidence Reference β€” What evidence supports the conclusion (EV-01, EV-02...)
  • Exceptions Noted β€” Any control failures or anomalies found
  • Conclusion β€” Effective / Ineffective / Not Applicable

✍️ Sign-Off Workflow

Every workpaper moves through a four-stage approval process:

Draft β†’ In Review β†’ Approved β†’ πŸ”’ Signed Off
  • Draft β€” Preparer is working on it. Can be edited.
  • In Review β€” Submitted to reviewer. Preparer clicks "Submit for Review β†’"
  • Approved β€” Reviewer has approved content. Senior reviewer clicks "Approve"
  • Signed Off β€” Final lock. No further edits. PCAOB/IIA aligned.
1

Create a workpaper

Go to /workflow and click "+ New Workpaper". Fill in the Reference (e.g. WP-SOX-001), select a project, and complete all six structured sections.

2

Save as draft

Click "Save Draft" to save progress without submitting. You can return and edit at any time while in Draft status.

3

Submit for review

Click "Submit for Review β†’" when complete. Status moves to In Review. The reviewer will be notified by email if notifications are configured.

4

View and export

Click "View" on any workpaper to see the full structured content. Click "Export PDF" to generate a print-ready workpaper with sign-off blocks.

πŸ’‘

AI shortcut: Run any AI tool from a module page to generate workpaper content automatically. Copy the output into the Test Procedures and Conclusion fields.

Section 5
Findings & Remediation
Findings are documented using the IIA 5C framework and tracked through a formal remediation workflow from identification to verified closure.

⚠️ IIA 5C Finding Structure

  • Condition β€” What IS β€” the issue found (factual, specific)
  • Criteria β€” What SHOULD BE β€” the policy, standard or control requirement
  • Cause β€” Root cause β€” WHY it happened
  • Consequence / Effect β€” Financial, operational or compliance impact
  • Corrective Action / Recommendation β€” Specific, actionable steps

πŸ”„ Remediation Workflow

Open β†’ In Progress β†’ Remediated β†’ βœ“ Verified Closed
  • Open β€” Finding logged, awaiting management response
  • In Progress β€” Management has acknowledged and is remediating
  • Remediated β€” Management confirms fix is complete. Evidence provided.
  • Verified Closed β€” Auditor re-tested and confirmed control now operating effectively
  • Overdue β€” Due date has passed and finding remains open (auto-flagged in red)

πŸ“„ Exporting Findings

Click "Export Report" in the top right of the Findings page to generate a formatted findings summary report β€” suitable for management or audit committee presentation. Filter by status, severity or module before exporting.

πŸ“§

Email alerts: When a finding becomes overdue, AssurAI automatically sends an email alert to the remediation owner. Alerts are also sent 3 days before the due date as a reminder.

Section 6
Control Library
The Control Library is your centralised repository of all controls across all modules and frameworks. Controls can be linked to risks, workpapers and findings.

πŸ—‚οΈ Control Attributes

  • Control ID β€” Unique identifier (e.g. SOX-JE-001)
  • Control Type β€” Preventive or Detective
  • Frequency β€” Daily, Weekly, Monthly, Quarterly, Annual, Transaction-level
  • Automated / Manual β€” System-enforced or human-performed
  • SOX Key β€” Flagged if it's a key control for Section 404
  • Test Result β€” Effective, Ineffective, or Not Tested
  • Related Modules β€” Which GRC modules this control applies to
Section 7
Testing
The Testing page manages test cases and executions β€” sampling, evidence collection and results recording for each control in scope.

πŸ”¬ Test Case vs Test Execution

  • Test Case β€” The test design: what to test, how, sample size, evidence required
  • Test Execution β€” The result of running the test: Pass, Fail, or Pass with Exceptions
πŸ’‘

AI-powered testing: Use the ITGC Testing Agent or Control Testing tool from any module to auto-generate test procedures, sample sizes and documentation guidance for any control.


Section 9 β€” AI Features
AI Agents (50+)
AI Agents execute complete multi-step workflows autonomously. Each agent takes a description of your situation and produces workpaper-ready output β€” not just a chatbot response.

🎯 SOX & ICFR Agents

πŸ“

SOX Scoping Agent

Identifies FSLIs, calculates materiality, produces scoping memo

πŸ”

Deficiency Assessment Agent

Classifies CD/SD/MW, drafts management letter language

πŸ“‹

RCM Builder Agent

Builds complete Risk and Control Matrix for any process

πŸ“Š

IPE Validator Agent

Tests completeness and accuracy of reports controls rely on

πŸ”

ITGC Testing Agent

Builds test procedures for all 4 ITGC domains

πŸ”„

Rollforward Agent

Rolls prior year SOX programme forward with updated scope

πŸ“‹ Internal Audit Agents

πŸ“‹

Audit Planning Agent

Risk-based audit plan with timing, hours and team assignments

✍️

Engagement Letter Agent

IIA-standard engagement letter ready to send

πŸ“

Finding Writer Agent

Complete IIA 5C finding in professional audit language

πŸ•΅οΈ

Fraud Risk Agent

Fraud scenarios, fraud triangle, ISA 240 test procedures

πŸ›οΈ

Audit Committee Report Agent

Board-ready AC pack with programme status and findings

🌐

Audit Universe Agent

Risk-scored audit universe with 3-year coverage plan

🌑️ Risk & ERM Agents

πŸ“Š

Risk Assessment Agent

Complete risk register with heat map and KRI recommendations

🌑️

Risk Register Agent

20+ risks identified, scored, controls mapped, COSO aligned

🎭

Scenario Analysis Agent

Base / Adverse / Severe / Catastrophic scenarios modelled

🏒

Third-Party Risk Agent

Vendor scorecard across 5 risk dimensions

πŸ“ˆ

KRI Monitoring Agent

5 KRIs per risk with G/A/R thresholds and owners

πŸ’‘

How to run an agent: Go to /ai-agents, find the agent you need, click "β–Ά Run", describe your situation in the text box, and the agent produces complete output. All agents are available at all plan levels unless marked Professional+.

Section 10
AI Agent Pipeline
The Agent Pipeline runs 5 specialist agents in sequence β€” from intake through reporting β€” delivering a complete documented audit workflow in minutes. Output saves directly to your engagement file as workpapers.

πŸ”„ How the Pipeline Works

1

Select your module

Choose SOX & ICFR, Internal Audit, Risk & ERM, Compliance, BCM, or Financial Intelligence.

2

Select a project

Use the dropdown to choose which engagement the output will be saved to.

3

Describe your engagement

Write a description of your company, situation and key areas of concern. The more detail, the better the output.

4

Click Run

Watch 5 agents run in sequence. Each agent's output feeds the next, building cumulatively on context.

5

Save to engagement

Click "πŸ’Ύ Save to Engagement File" β€” all 5 outputs are saved as draft workpapers in your selected project, ready for review.

⚠️

AI-generated content should always be reviewed by a qualified professional before reliance. The pipeline produces a strong first draft β€” not a finished deliverable without review.

Section 11
Evidence Intelligence
Upload any document dump β€” screenshots, emails, access lists, reconciliations β€” and AssurAI classifies each document, maps it to the right control, executes the test procedure, and generates a Big 4-quality workpaper.
1

Drop your documents

Upload any file type β€” CSV, Excel, PDF, screenshots, emails. AI parses and classifies each automatically.

2

AI executes the test

The AI follows your audit procedure step by step, testing each control attribute against the evidence provided.

3

Get a workpaper

Every conclusion is linked to specific evidence. One click generates a formatted, sign-off-ready workpaper with full evidence traceability.


Section 12 β€” Modules
8 GRC Modules
Each module is a complete, specialised GRC environment with its own AI tools, wizards, workpaper templates, calculators and workflow tools.
ModuleAI ToolsFrameworksKey Features
πŸ›‘οΈ SOX & ICFR24 toolsPCAOB AS 2201Scoping, RCM, materiality, ITGC, deficiency classification
πŸ“‹ Internal Audit22 toolsIIA IPPFEngagement planning, fieldwork, findings, board reporting
πŸ“ˆ Risk & ERM23 toolsCOSO ERM Β· ISO 31000Risk register, heat maps, KRIs, scenario analysis, board packs
βš–οΈ Compliance16 toolsSOC 2 Β· GDPR Β· ISO 27001 Β· HIPAA Β· PCIGap assessments, policy drafting, certification campaigns
πŸ›‘οΈ BCM & Resilience15 toolsISO 22301 Β· NISTBIA, recovery plans, tabletop exercises, crisis comms
πŸ’° Financial Intelligence15 toolsASC 606 Β· GAAPBenford's Law, JE review, reconciliation, going concern
🏦 BSA/AML & FDICIA12 toolsBSA · FinCEN · FDICIAAML programme assessment, SAR workflows, FDICIA internal controls, CDD testing
πŸ“Š Fund Compliance10 toolsSEC Β· CFTC Β· AIFMDFund audit support, regulatory filing checklists, investor reporting, compliance calendar
πŸ’‘

Guided Project Wizard: Every module has a guided step-by-step wizard (yellow banner at the top of the tools panel). Click it to get a structured workflow from planning through reporting.

Section 13
SOX & ICFR Module
The SOX module covers the complete Section 404 compliance workflow aligned to PCAOB AS 2201.

πŸ›‘οΈ Key SOX Tools

  • Scoping & FSLI β€” Materiality calculation, FSLI identification, scope documentation
  • RCM Builder β€” Risk and Control Matrix for any business process
  • Control Testing β€” Test procedure design, population and sample guidance
  • Deficiency Analyzer β€” CD / Significant Deficiency / Material Weakness classification
  • ITGC Testing β€” User access, change management, backup, privileged access
  • SoD Analyzer β€” Segregation of duties conflict identification
  • IPE Assessment β€” Information Produced by Entity testing
  • Y/Y Rollforward β€” Prior year programme rollforward
  • SOX Certifications β€” Sub-certification management (/sox-certifications)
Section 14
Risk & ERM Module
Enterprise Risk Management aligned to COSO ERM 2017 and ISO 31000 β€” from risk identification through board reporting.

πŸ“ˆ Risk Assessment Page (/risk-assessment)

A dedicated risk management workspace with:

  • Risk Heat Map β€” Visual 5Γ—5 likelihood Γ— impact grid with your risks plotted as dots
  • Risk Register β€” Full register with filtering by rating and status
  • Risk by Category β€” Bar chart showing risk distribution across categories
  • + Add Risk β€” Log any risk with full scoring, ownership and treatment status

🌑️ Risk Module Tools (23)

  • AI Tools (16) β€” KRI Dashboard, Third-Party Risk, Emerging Risk Radar, Bow-Tie Analysis, Risk Heat Map Builder, COSO ERM Assessment, Risk Register Builder, Risk Scoring Model, Residual Risk Analyzer, Scenario Analysis, Risk Treatment Plan, KRI Designer, Board Risk Report, Regulatory Change Monitor, Cyber Risk Assessment, FAIR Cyber Risk Model
  • Calculators (2) β€” Monte Carlo Simulator, Risk Quantification Calculator
  • Templates (3) β€” ERM Framework Builder, Risk Appetite Tool, Risk Taxonomy Designer
  • Workflow (2) β€” Risk Review Workflow, Risk Committee Pack
Section 15
Compliance Module
Multi-framework compliance management β€” test once and satisfy 25 frameworks simultaneously using the Cross Assurance Engine.

βš–οΈ Supported Frameworks

SOC 2 Type II Β· ISO 27001 Β· GDPR Β· HIPAA Β· PCI DSS v4.0 Β· CCPA Β· AML Β· ESG Β· NIST CSF Β· ISO 22301 Β· SOX Β· FedRAMP Β· DORA Β· and 12 more


Section 16 β€” Reporting
Executive Dashboard
The Executive Dashboard (/executive-dashboard) provides real-time audit programme status for CAEs and CFOs β€” live KPIs, charts and overdue item tracking.

πŸ“Š Dashboard KPIs

  • Total Controls β€” Controls in scope for the selected project
  • Controls Tested % β€” Percentage of controls with completed test executions
  • Open Exceptions β€” Active findings not yet remediated or closed
  • High/Critical Risks β€” Risks rated High or Critical in the risk register
  • Days to Completion β€” Set in project settings

Select a project from the dropdown to load live data. Click Refresh to update.

⚑ Real-time KPI Strip

A persistent banner at the top of the Executive Dashboard shows live cross-engagement totals β€” open findings, controls tested today, overdue remediations, and KRI breaches β€” updated in real time without a page refresh.

πŸ”— Integration Canvas

The Integration Canvas (/integration-canvas) provides a visual data-flow map of every connected system β€” showing how data moves from your source systems (Okta, Azure AD, GitHub, AWS, Jira, Slack) into AssurAI modules in real time.

  • Live connection status β€” green/amber/red for each integration
  • Data volume indicators β€” records synced, last sync timestamp
  • One-click re-sync β€” trigger a manual pull from any source
  • AI mapping suggestions β€” AI recommends which controls each data source should feed

πŸ“Œ Customisable Shortcuts

The dashboard shortcut bar supports 200+ pinnable tools. Click the Edit Shortcuts button to browse the full library by module and drag tools into your personal shortcut bar. Your configuration is saved per user.

Section 17
Audit Trail
The Audit Trail (/audit-trail) is an immutable log of every action taken on the platform β€” who did what, when, and on which record. Required by PCAOB AS 2201 and IIA Standards.

πŸ” What's Logged

  • Workpaper created, edited, submitted for review, approved, signed off
  • Finding created, status changed, remediated, verified closed
  • Control tested, result recorded
  • Project created or modified
  • AI Agent Pipeline output saved to engagement

πŸ“₯ Exporting the Audit Trail

Click "Export CSV" to download the complete audit trail. Filter by entity type, action, actor or date range before exporting to narrow the output. The CSV is suitable for external auditor review.

πŸ”’

Immutable: Audit trail entries cannot be modified or deleted β€” not even by administrators. Every entry is timestamped and attributed to a specific user email.

Section 18
Compliance Calendar
The Compliance Calendar (/compliance-calendar) tracks all audit deadlines, control testing windows, sign-off dates and regulatory filing dates in one visual calendar.

πŸ“… Using the Calendar

  • Select a project from the dropdown to load its deadlines
  • Click + Add Deadline to log a new deadline with owner, category and reminder setting
  • Colour coding β€” Red = overdue, Amber = due within 7 days, Blue = upcoming
  • Upcoming Deadlines panel (right side) β€” sorted list with days remaining
  • Alerts β€” Red banner for overdue, amber banner for items due within 7 days
Section 19
Exporting Reports
Every major page in AssurAI has export capability β€” workpapers, findings reports, audit trail, and board-ready packs.
πŸ“‹

Workpaper Export

Click "Export PDF" on any workpaper. Generates a print-ready document with sign-off blocks, evidence references and all structured sections.

⚠️

Findings Report

Click "Export Report" on the Findings page. Generates a formatted findings summary with severity ratings, status, recommendations and management responses.

πŸ”

Audit Trail CSV

Click "Export CSV" on the Audit Trail page. Complete immutable log suitable for external auditor review.

πŸ–¨οΈ

Print Any Page

Every page has a print button or is print-optimised. Use Cmd+P (Mac) or Ctrl+P (Windows) for a clean printed version.


Section 20 β€” Platform
Continuous Monitoring
Continuous Monitoring (/continuous-monitoring) runs automated checks on your control environment 24/7 β€” flagging exceptions without waiting for the quarterly review cycle.

πŸ”΄ Pre-configured Monitors

  • User Access Review β€” SOX ITGC Β· Daily
  • Journal Entry Anomalies β€” SOX Financial Β· Daily
  • Change Management β€” SOX ITGC Β· Weekly
  • Segregation of Duties β€” SOX Controls Β· Weekly
  • Vendor Payment Anomalies β€” Fraud/AP Β· Daily
  • Privileged Access Monitoring β€” Cybersecurity Β· Hourly

Click "+ Add Monitor" to create custom monitors. Click "β–Ά Run" to test on-demand.

Section 21
Cross Assurance Engine
Test once. Satisfy 25 frameworks. The Cross Assurance Engine maps any control simultaneously to SOX, SOC 2, ISO 27001, NIST CSF, GDPR, HIPAA, PCI DSS and 18 more.

πŸ”— How Cross Assurance Works

1

Describe your control

Go to /cross-assurance and describe the control you want to map β€” or select from your control library.

2

AI maps to all frameworks

The engine identifies every applicable clause, requirement or control objective across 25 frameworks that your control satisfies.

3

Calculate savings

See estimated audit hour savings from eliminating duplicate testing across frameworks. Typical savings: 40–60% of testing hours.

Section 22
Settings & Customisation
The Settings page (/settings) is organised into seven tabs β€” covering your profile, integrations, AI provider, notifications, team management, security, and branding.

πŸ‘€ Profile

Update your name, email, job title, and avatar. Change your password or configure Single Sign-On (SSO) for your organisation.

πŸ”Œ Integrations

Connect AssurAI to your existing tech stack. Available integrations include:

  • Identity β€” Okta, Azure AD, Google Workspace
  • Dev & Cloud β€” GitHub, GitLab, AWS, Azure, GCP
  • ITSM β€” Jira, ServiceNow, Linear
  • Comms β€” Slack, Microsoft Teams
  • GRC β€” ServiceNow GRC, Archer, MetricStream

Each integration has a connection wizard β€” click Connect, authorise via OAuth or API key, and configure which modules receive the data feed.

πŸ€– AI Provider

AssurAI defaults to Claude (Anthropic). In this tab you can switch your organisation's AI provider or bring your own API key:

  • Claude (Anthropic) β€” default, recommended for audit-quality output
  • GPT-4o (OpenAI) β€” paste your OpenAI API key
  • Gemini (Google) β€” connect via Google AI Studio key
  • Azure OpenAI β€” use your enterprise Azure endpoint

πŸ”” Notifications

Configure email and in-app alerts per event type:

  • Finding overdue β€” email to owner + CAE at day 7, 14, 30
  • Workpaper submitted for review β€” email to assigned reviewer
  • KRI threshold breach β€” email to Risk Manager and CRO
  • Regulatory monitor alert β€” weekly digest or immediate push

πŸ‘₯ Team

Invite team members, assign roles (Admin, Manager, Preparer, Viewer), and manage module-level access permissions. Admins can deactivate users and transfer ownership of engagements.

πŸ” Security

  • MFA β€” Enable TOTP-based two-factor authentication (Google Authenticator / Authy)
  • SSO β€” SAML 2.0 / OIDC for enterprise identity providers
  • API Keys β€” Generate and revoke keys for the Enterprise REST API (1,000 req/hr)
  • Session timeout β€” Configure idle session expiry (15 min to 8 hrs)
  • IP Allowlisting β€” Restrict platform access to approved IP ranges

🎨 Brand

Upload your organisation's logo and set primary brand colours. These appear on exported PDFs, workpaper covers, board portal reports, and the PBC Portal client-facing pages. White-labelling is available on Enterprise plans.

πŸ’‘

Excel Add-in: Run AI-powered audit tests directly inside Microsoft Excel. Download from /excel-addin or the Microsoft AppSource. Select any data range, choose a test (JE review, Benford's Law, user access), and get PCAOB-aligned findings written back to your sheet.

Section 23
Integration Canvas
The Integration Canvas (/integration-canvas) is a visual data-flow mapper that shows how every connected system feeds into AssurAI in real time β€” making it easy to diagnose gaps and verify evidence pipelines.

πŸ—ΊοΈ What the Canvas Shows

  • Source nodes β€” each connected system (Okta, GitHub, Azure AD, Jira, AWS, Slack, etc.) appears as a labelled node on the left
  • Module nodes β€” each AssurAI module appears on the right; arrows connect data flows between source and module
  • Connection health β€” green (live), amber (degraded), red (disconnected) status on every arrow
  • Last sync β€” hover any arrow to see the timestamp and record count of the last successful pull

⚑ AI Mapping Suggestions

When you connect a new integration, AssurAI's AI analyses the data schema and recommends which controls, test procedures, and modules should consume it β€” saving setup time and reducing the risk of missing evidence sources.

1

Go to /integration-canvas and click + Add Integration

2

Select your system (or use Generic REST connector)

3

Authorise via OAuth or paste your API key

4

Review AI mapping suggestions β€” approve or adjust

5

Click Activate β€” data begins flowing within seconds

πŸ’‘

New in September 2026: The Integration Canvas now supports bi-directional flows β€” findings and remediation status can be pushed back to Jira or ServiceNow automatically, keeping your ITSM tickets in sync.