Changelog
What's New in AssurAI
Product updates, new features and improvements.
25 August 2026 Latest
๐Ÿš€ 4 Competitive Gap Closers โ€” Policy Management, Data Privacy, Audit Universe & BCM Depth
๐Ÿ“œ
Policy Management

Full policy lifecycle management with AI-assisted drafting, version control, attestation campaigns, and approval workflows. Policy owners can assign attestation deadlines, track completion rates, and auto-escalate overdue sign-offs. AI drafter generates policy drafts from control frameworks in seconds.

๐Ÿ”’
Data Privacy (GDPR / CCPA)

Comprehensive privacy compliance module covering Records of Processing Activities (ROPA), Data Subject Request (DSR) tracking with SLA timers, privacy incident management, and an AI-guided Privacy Impact Assessment (PIA) wizard. Covers GDPR, CCPA, PIPEDA, and PDPA frameworks.

๐Ÿ—‚๏ธ
Audit Universe โ€” Annual Plan & Coverage Analytics

Audit Universe now includes a quarterly Gantt-style Annual Plan view, Coverage Analytics dashboard with Chart.js bar charts, and an AI Planner agent that generates a risk-based annual plan automatically. Drag entities across quarters, export the plan, and track HC Coverage % and budgeted hours in real time.

๐Ÿ›ก๏ธ
BCM โ€” BIA Manager & Tabletop Exercise Manager

Business Continuity Management now includes a full BIA Manager to capture RTO, RPO, MTPD, and financial impact per business process, and a Tabletop Exercise Manager with AI-generated scenario scripts. Run ransomware, pandemic, or supply-chain exercises with guided injects, participant roles, and AI-produced after-action reports.

25 August 2026
๐Ÿค Channel Partner Audit โ€” AI-Powered Auditing for Distributors, Resellers & Agents
๐Ÿค
Channel Partner Audit Module

AI-powered auditing for distributors, resellers, agents and licensees. 8 agentic AI agents covering FCPA screening, royalty testing, revenue leakage detection, contract compliance and due diligence. Fully integrated into the Internal Audit module โ€” workpapers save to existing engagement files, findings to the shared findings table.

โš–๏ธ
FCPA / Anti-Corruption AI

Assess FCPA and UK Bribery Act exposure automatically. AI evaluates jurisdiction risk, government official interactions, commission reasonableness, and generates a complete anti-corruption workpaper with escalation protocol.

๐Ÿ’ฐ
Royalty & Revenue Leakage Detection

12-vector revenue leakage analysis covering channel stuffing, unauthorized discounts, return manipulation, grey market indicators, and more. Royalty calculation testing workpaper with sampling methodology included.

๐Ÿ“Š
Partner Risk Registry & Analytics

Centralized partner registry with AI risk scoring (0-100 across 4 dimensions), 3ร—3 risk matrix, overdue audit tracking, revenue-at-risk calculations, and audit coverage analytics. Risk scores updated automatically by AI.

23 August 2026
โš™๏ธ ABC Testing Engine โ€” AI-Powered Automated Control Testing
โš™๏ธ
ABC Testing Engine

The first AI-powered automated control testing platform. Connect to your ERP โ€” AssurAI pulls the automated control configuration, AI reviews the logic for design gaps, traces a sample transaction end-to-end, and generates a PCAOB AS 2201 workpaper. In minutes.

๐Ÿ”ท
SAP ยท Oracle ยท NetSuite ยท Workday ยท Salesforce

14 pre-built automated control templates across P2P, O2C, R2R, Payroll, and Inventory. Live ERP configuration pulls via API with configuration hash tracking and change detection.

๐Ÿ“„
PCAOB AS 2201 Workpaper Generator

Six-section professional workpapers with design adequacy, configuration evidence, AI assessment, transaction trace, and integrated conclusion โ€” auto-saved to the engagement binder.

๐Ÿ”ด
Configuration Change Monitoring

Subscribe to configuration changes per control. When AssurAI detects a change during scheduled pulls, it emails the audit team, flags the workpaper for re-testing, and shows a diff of what changed.

21 August 2026
๐Ÿ—บ๏ธ Integration Canvas โ€” Visual No-Code API Connector Builder
๐Ÿ”—
Visual API Integration Canvas
Drag-and-drop integration builder: visually connect source systems (Okta, GitHub, AWS IAM, Azure AD, Supabase, Cloudflare) to AssurAI modules via an SVG bezier canvas. Map fields with drag-and-drop chips, schedule automated pulls (daily/weekly/monthly), and set per-connection actions including exception alerts and Slack notifications.
๐Ÿค–
AI Auto-Field Mapping
One-click Auto-Map uses Claude to intelligently map source fields to destination fields by name similarity and data type โ€” saving hours of manual configuration. Includes a test preview showing sample values for each mapped field.
๐Ÿ“ก
Custom REST API & Webhook Receiver
Add any REST API in 4 steps: enter credentials, point to an endpoint, auto-discover fields, test, and save to canvas. Webhook receiver endpoint at /.netlify/functions/webhook-receiver accepts real-time push events from any system with org-level key validation.
20 August 2026
โšก SOX Evidence Collector โ€” Automatic ITGC Evidence from 6 Live Connectors
NewAutomatic ITGC evidence collection from Okta, GitHub, AWS IAM, Azure AD, Supabase & Cloudflare โ€” maps to 24 SOX controls with PCAOB AS 2201-aligned workpaper generation
NewABC/MBC business process control testing via ERP file upload + AI analysis; continuous SOX monitoring with configurable frequency and alert thresholds
19 August 2026
๐Ÿ›ก๏ธ Module 08: Trust & Security Compliance โ€” SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS
๐Ÿ›ก๏ธ
Trust & Security Module Hub
New Module 08 landing page with links to all 11 Trust & Security tools. Full binder layout with progress bars, chip grid, and quick links to SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, Policy Library, Questionnaire AI, Personnel Security, Trust Portal, Subprocessor Registry, and Compliance Dashboard.
๐Ÿ”
SOC 2 Readiness Tracker โ€” 64 Trust Service Criteria
Track readiness against all 64 AICPA Trust Service Criteria across 5 categories (CC, A, C, PI, P). Dynamic circular gauge, per-criterion status tracking, AI guidance per criterion, evidence locker with SHA-256 tamper detection, gap assessment, and 8-milestone readiness timeline. Supabase-backed with org isolation.
๐Ÿ“‹
Policy Library โ€” 40 AI-Generated Templates
40 security and compliance policy templates across 5 categories (Security, Privacy, HR, IT, Compliance). AI policy generator tailored to your industry and company size. Annual attestation workflow tracks who has signed which policy. Policies save to Supabase with approval dates and review schedules.
๐Ÿค–
Security Questionnaire AI โ€” Auto-Answer Any Questionnaire
Upload or paste any customer/vendor security questionnaire. AI reads your security posture knowledge base and drafts answers automatically. Supports SIG Lite, CAIQ, VSA, and custom questionnaires. Shows confidence levels (High/Medium/Review Required) and estimated hours saved.
๐Ÿ‘ฅ
Personnel Security โ€” Onboarding, Training & Offboarding
Manage security onboarding checklists (10 items per employee), annual security training completion, offboarding procedures with critical access revocation alerts (red badge if access not revoked within 1 day of termination), and quarterly access reviews.
๐ŸŒ
Trust Portal โ€” Public Security Page Builder
Build your organisation's public trust page (like trust.vanta.com) directly in AssurAI. Shows certification status, security overview, downloadable policies, AI & data handling, subprocessors table, and AI trust chatbot. Public mode requires no auth โ€” share getassurai.com/trust/{org-slug} with prospects.
๐Ÿ”
ISO 27001:2022 Readiness โ€” 93 Controls, Statement of Applicability
Gap assessment across all 93 ISO 27001:2022 controls across 4 themes (Organisational, People, Physical, Technological). CMMI-style maturity scoring (1-5), auto-generated Statement of Applicability, AI gap report with certification roadmap.
๐Ÿ‡ช๐Ÿ‡บ
GDPR Compliance โ€” ROPA, DSARs, Breach Register
Records of Processing Activities (ROPA) with AI-assisted entry generation, Data Subject Access Request tracker with 30-day countdown, Data Processing Agreement tracker, personal data breach register with 72-hour DPA notification countdown, and AI tools for Privacy Notices, LIA, and DPIA.
๐Ÿ”’
PCI DSS v4.0 Readiness โ€” 12 Requirements, CDE Mapper
Track readiness against all 12 PCI DSS v4.0 requirements with SAQ type selector (A/A-EP/B/B-IP/C/C-VT/D/ROC). Cardholder Data Environment (CDE) scope mapper shows in-scope vs out-of-scope systems. AI gap report generates remediation roadmap.
๐Ÿข
Subprocessor Registry โ€” Vendor Data Processing Tracker
Track all subprocessors and vendors who process customer data. Pre-populated with AssurAI's own subprocessors (Anthropic, Supabase, Netlify, Cloudflare, Brevo) as a demo. Public toggle controls what appears on your Trust Portal. Export as CSV or PDF.
๐Ÿ“Š
Compliance Dashboard โ€” Unified Framework View
Control centre across all compliance frameworks: SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, India IFC, and Sharia. Framework status grid, upcoming deadlines calendar, control heat map by category and framework, evidence expiry tracker (90-day alerts), and AI board report generator.
๐Ÿค–
4 New Trust & Security Agents: SCOUT-2, PETRA, QUINN, PIPA
SCOUT-2 assesses SOC 2 readiness across all 64 criteria. PETRA drafts board-ready security policies in minutes. QUINN auto-answers customer security questionnaires from your security posture. PIPA conducts GDPR Data Protection Impact Assessments (Article 35 compliant).
16 August 2026
Annotated Evidence Export (4 File Types), Full Archer GRC Integration & More
๐Ÿ“Ž
Annotated Evidence Export โ€” 4 File Types
Evidence AI now exports annotated evidence files automatically โ€” PDF files get audit overlay with tick marks, exception flags and annotation page; Excel/CSV files get 3-sheet annotated workbook (Annotated Data, Audit Summary, Exceptions Only); Word/DOCX files get 3-page annotated PDF report (Cover + Conclusion, Exhibit Table, Exceptions Detail). File type detected automatically.
๐Ÿน
Full Archer GRC Integration
Native RSA Archer REST API integration โ€” findings, workpapers and action plans push directly into your Archer instance. New Archer Settings page for connection config, field mapping and test push. Push All to Archer bulk button on findings page. Activate with your Archer instance URL and credentials.
๐Ÿ’พ
Evidence AI โ€” Save as Workpaper
After Evidence AI analyses your evidence and produces a workpaper, click Save to store it directly to Supabase workpapers table with one click. Project picker modal lets you assign to any engagement. Redirects to workpapers page with new entry highlighted.
๐Ÿ”‘
Agent Pipeline โ€” Auth Warning Banner
AI Agent Pipeline now checks authentication on page load and shows a clear amber warning banner with Re-login link and Refresh Session button if session has expired โ€” eliminates silent 401 failures mid-pipeline.
15 August 2026 Previous
Sharia Audit Module, File Upload for All AI Agents & Agent Pipeline Enhanced
๐Ÿ•Œ
Sharia Audit & Governance Module
Complete Sharia audit framework inside Compliance module โ€” 25 AI tools, AAOIFI GSIFI/SS 1-62/FAS, IFSB-10, OIC Fiqh Academy, 8 regional regulators, full Islamic product universe, income purification, zakat computation, fatwa library, SSB governance structure.
๐Ÿ“Ž
File Upload for All AI Agents
Every AI agent now accepts PDF, DOCX, XLSX, CSV and TXT file uploads โ€” upload real evidence, workpapers or data and the agent analyses it directly.
๐Ÿ“‹
Co-Pilot Pro PDF Analysis
Upload any PDF document โ€” prior year workpapers, evidence files, policies โ€” and Co-Pilot Pro reads and analyses it with suggested prompts and PBC generation.
๐Ÿ”€
Walkthrough AI โ€” Interview Upload
Upload walkthrough interview notes as TXT file and Walkthrough AI generates the full Big 4 narrative, process flowchart and control matrix.
๐Ÿค–
AI Agent Pipeline โ€” Enhanced
Agent pipeline now uses AssurAI Agent with 16,000 token output โ€” longer, more complete audit plans with no truncation. File upload supported.
12 August 2026 Previous
14 Live Integrations, Mobile Approvals & BI Connector
๐Ÿ”Œ
12 Live Integrations โ€” Connect with Demo Fallback
Connect AssurAI to BlackLine, Workday, SAP, NetSuite, ServiceNow, Okta, RSA Archer, Diligent HighBond, MetricStream, Onspring, Dynamics 365, and more โ€” all with instant demo mode that works without credentials.
๐Ÿ“ฑ
Mobile Approvals โ€” Approve from any device
Approve findings, workpapers, and SOX certifications from any mobile device with one tap. Includes digital signature capture, push notification setup, QR code access, and offline queue support.
๐Ÿ“Š
BI Connector โ€” Export to Power BI, Tableau, Looker & Qlik (2027)
Pre-built AssurAI data models and connection strings for Power BI, Tableau, Looker, and Qlik. Download schemas, generate connection strings, and preview sample dashboards. Full launch in 2027 โ€” join the waitlist now.
11 August 2026
Custom AI Playbook Builder, Vendor SOC 2 Analyzer, Policy Framework Analyzer & More
๐ŸŽฎ
Custom AI Playbook Builder
Build your own multi-agent AI pipelines with custom steps, scheduling and automated execution. Define up to 8 sequential agent steps with custom roles, input sources and output formats. Run on demand or schedule daily, weekly, monthly or quarterly.
๐Ÿ“‹
Third-Party Assurance Report Analysis
Upload vendor SOC 2, SOC 1 or ISO 27001 reports โ€” AI identifies key findings, exceptions and your complementary control obligations (CUECs). Risk score gauge, trust service criteria coverage table, subservice organizations, and one-click Word export.
๐Ÿ”
Policy vs Framework Analyzer
Check any policy against SOX, SOC 2, ISO 27001, HIPAA, NIST CSF, GDPR, PCI DSS and CMMC. AI identifies coverage gaps with percentage scores per framework, top 5 critical gaps highlighted, and a downloadable gap report.
๐Ÿ“
Questionnaire Auto-Answer โ€” Source Citations
Security questionnaire answers now sourced from your actual control library and policies first, with source citations per answer. Green badge for Control Library sources, amber for Policy Hub, grey for AI Generated. Export all Q&A as a formatted Word document ready to send.
โฐ
CCM Scheduler
Schedule continuous control monitoring rules to run daily, weekly, monthly or quarterly with automatic email notifications. Schedule badge on each rule card shows next run date. Overdue rules auto-trigger on page load.
7 August 2026 Previous
AI Audit Trail, Workpaper Timer, Compliance Score Dashboard & More
๐Ÿค–
AI Audit Trail
Complete AI decision log per workpaper โ€” every AI annotation, finding, and confidence score recorded. "Generate AI Decision Log" produces a PCAOB-ready summary of all AI decisions made during the audit engagement. Export as PDF.
๐Ÿ“Š
Compliance Score Dashboard Widget
Real-time overall compliance health score (0โ€“100) on the dashboard. Circular gauge coloured green/amber/red, with breakdown across Controls, Findings, and Workpapers. Calculated live from your Supabase data.
โฑ๏ธ
Workpaper Timer โ€” Time Tracking
Track time spent per workpaper with a built-in timer. Start and stop the timer directly in the workpaper detail header. Logged time persists and demonstrates ROI: "This workpaper took 12 minutes with AI."
๐Ÿ“‚
Prior Year Comparison
Compare current year workpapers against prior year side-by-side. AI highlights unchanged sections, modified procedures, sample size changes, and new exceptions vs prior year. "Rollforward" copies prior year content as the starting point.
๐Ÿ’ฐ
LP Distribution Waterfall Calculator
Model carried interest and LP distributions in the Fund LP Portal. Enter invested capital, portfolio value, hurdle rate, and carry %. View the 5-step waterfall with colour-coded bars, IRR estimate, and generate an ILPA-format distribution notice.
โšก
HIPAA Breach Impact Calculator
Real-time breach impact calculator in the HIPAA module. Enter number of individuals affected and instantly see OCR fine estimates, class action risk rating, and required notification obligations.
๐Ÿ“…
Joint Commission Survey Countdown
Prominent countdown to next triennial accreditation survey window at the top of the Joint Commission page. Shows years, months, days remaining with real-time readiness indicator.
๐Ÿ†
Portfolio GRC Score Calculator
AI-powered GRC score (0โ€“100) for each portfolio company in the Fund Portfolio Monitor. Assess SOC 2, ISO 27001, GDPR, internal audit programme, and board oversight โ€” get a score plus 3 recommended actions per company.
๐Ÿงน
AI Assistant Enhanced NL Queries
Ask the AI Assistant "show me all critical findings", "what controls are ineffective", "which workpapers need review", "how many exceptions this quarter", "show me the JE control" and more. Results appear as inline lists with module links.
August 2026
AI Audit Judgment, Auto Evidence Chase & Full Population Testing
๐Ÿค–
AI Audit Judgment โ€” PCAOB Standard
Render formal PCAOB-compliant audit judgments per control with confidence scoring, PCAOB classification (No Deficiency / Control Deficiency / Significant Deficiency / Material Weakness) and sign-off recommendations. Every judgment is documented with rationale that survives PCAOB review.
๐Ÿ“ฌ
Automated Evidence Chase
Auto-chase overdue evidence requests with Day 1 reminder, Day 3 second reminder, and Day 7 management escalation. Full chase history tracked per request. Enable per-request with the auto-chase toggle, or run all overdue at once with the "๐Ÿค– Auto-Chase" button.
๐Ÿ“ฆ
Full Population Testing
Test 100% of your control population instead of a sample. Enable "Full Population Testing" when creating a test to set sample size equal to population size. Eliminates sampling risk and shows a "100% COVERAGE" badge on test cards.
๐Ÿ”ฅ
Complex Control Templates
Pre-built test templates for complex controls: Bad Debt Reserve (Management Review), Revenue Cut-Off Testing, Management Review of Financial Statements, IPE Validation, and Segregation of Duties analysis. Available in the Test Library under ๐Ÿ”ฅ Complex Controls.
โœ‰๏ธ
Exception Correspondence
AI drafts professional control owner correspondence for every finding in Findings. Click "Draft Correspondence" on any finding card โ€” AI generates a professional, factual email ready to send. "Notify All Owners" sends correspondence across all open findings in one click.
๐Ÿ“ฌ
Control Owner Portal
A dedicated portal for control owners to upload evidence without needing an AssurAI login. Generate a unique owner link from any evidence request card โ€” owners click the link, drag-and-drop their files, and submit. Replaces email attachments entirely.
August 2026
Healthcare & Fund Compliance โ€” Phase 2
๐Ÿฅ
Staff Training Tracker
Track mandatory HIPAA, compliance and clinical training completion across your workforce. Automated reminders, completion reports and Joint Commission readiness with 10 pre-built training categories.
โš ๏ธ
Incident Reporting & Patient Safety
Report, track and analyse compliance incidents, near-misses and adverse events. AI-powered root cause analysis with automatic regulatory reporting obligation identification (HHS, Joint Commission, state health departments).
๐Ÿ“‹
Policy Management & Staff Attestation
Manage compliance policies, track review cycles and collect staff attestations. AI reviews draft policies for regulatory alignment. Full attestation tracking with automated reminders.
๐Ÿฆบ
OSHA Healthcare Compliance
Track compliance with 5 key OSHA healthcare standards: Bloodborne Pathogens, Hazard Communication, Workplace Violence Prevention, Respiratory Protection and OSHA 300 recordkeeping. AI self-inspection guidance.
โญ
CMS Star Ratings & EMTALA Compliance
CMS Hospital Compare star ratings integration with AI benchmarking analysis. Full EMTALA compliance checklist with AI risk assessment for ED compliance gaps.
๐Ÿ’Š
340B Drug Pricing Compliance
340B programme eligibility tracking, diversion prevention controls, duplicate discount prevention and HRSA audit readiness assessment. AI-powered risk scoring for contract pharmacy arrangements.
๐Ÿ’ฐ
Expense Misallocation Detection
AI-powered expense allocation audit โ€” upload fund expense reports and AI identifies misallocated expenses with SEC enforcement risk scoring. Generates compliance memos with remediation priorities.
๐Ÿ’ผ
Multi-Fund Consolidated View
Group portfolio companies by fund with consolidated GRC scores, weighted average scoring and cross-fund framework coverage. Add and manage multiple funds with vintage year and commitment tracking.
๐Ÿ“‹
ILPA Reporting Templates
Download ILPA Principles 3.0 compliant Excel templates: Fee Template, Capital Call Template, Distribution Notice and Quarterly Report โ€” all with standard ILPA column headers and formula cells.
๐Ÿ“ˆ
GIPS Compliance Tracker
CFA Institute Global Investment Performance Standards compliance โ€” composite management, annual requirements checklist and AI review of GIPS-compliant presentations for required disclosures.
๐Ÿ›๏ธ
SEC EDGAR Integration
Pull Form ADV filings directly from SEC EDGAR using the public API. Enter your CRD number to fetch registration data, last amendment date and next filing deadline. Monitor for new filings automatically.
August 2026 NEW FEATURE
Fund & Healthcare Compliance Agent Pipelines โ€” Board-ready CCO reports in 90 seconds
๐Ÿค–
6-Agent Fund Compliance Assessment
A 6-agent AI pipeline runs sequentially on any fund type (Hedge Fund, PE, VC) โ€” covering Regulatory Profile, Investment Adviser Compliance, AML/KYC, Portfolio & Operational Compliance, ESG & Reporting, and a final CCO Board Report with overall compliance score, risk rating, critical findings and compliance calendar. Exports to Word and PowerPoint.
๐Ÿฅ
7-Agent Healthcare Compliance Assessment
A 7-agent AI pipeline assesses any healthcare organisation type (hospital, health system, health plan, digital health, pharma) โ€” covering Regulatory Frameworks, HIPAA Security & Privacy, Accreditation & Survey Readiness, OIG Fraud Risk, Cybersecurity & HITRUST, Revenue Cycle Compliance, and a CCO Board Report with scorecard across all domains. Exports to Word and PowerPoint. The only GRC platform with autonomous multi-agent compliance assessment for investment managers and healthcare organisations.
August 2026 NEW MODULE
Healthcare Compliance โ€” Purpose-built for Hospital Systems and Health Networks
๐Ÿฅ
Healthcare Compliance Module
9-module compliance suite purpose-built for healthcare compliance officers and internal audit teams. Covers HIPAA Privacy & Security, Joint Commission & CMS readiness, OIG Work Plan tracking, HITRUST CSF assessment, Revenue Cycle compliance, 21 CFR Part 11 & GxP, ESG & Community Benefit reporting, and Healthcare Vendor & Supply Chain Risk.
๐Ÿ”’
HIPAA Privacy & Security โ€” Annual risk analysis, BAA tracker, breach workflow
Comprehensive HIPAA compliance module covering annual Security Rule risk analysis (per 45 CFR 164.308(a)(1)), Business Associate Agreement tracking with expiry alerts, breach notification workflow with regulatory routing (HHS/media/individual), and workforce training completion tracker.
๐Ÿ›ก๏ธ
HITRUST CSF Assessment โ€” AI gap analysis across all 19 domains in 2 minutes
Upload security policies and evidence documents โ€” AI assesses all 19 HITRUST CSF domains, scores maturity (0โ€“5), identifies gaps, and generates a certification roadmap for e1, i1 or r2 assessment types. Includes evidence collection tracker and milestone planning.
๐Ÿ’Š
Revenue Cycle Compliance โ€” AI anomaly detection across full claims population
Upload claims data for AI-powered full-population analysis: Benford's Law statistical testing, duplicate claim detection, CPT code upcoding patterns, modifier misuse, and place-of-service errors. Includes pre-built coding audit programmes for E&M, surgical procedures, ICD-10, DRG and APC validation.
August 2026 NEW MODULE
Fund & Investment Manager Compliance โ€” Purpose-built for PE, VC and Hedge Funds
๐Ÿ’ผ
Fund & Investment Manager Compliance Module
9-module compliance suite purpose-built for investment managers and their portfolio companies. Covers SEC/FCA regulatory tracking, portfolio-wide GRC monitoring, AI-powered due diligence assessments, ESG/ISSB reporting, LP reporting portal, investment adviser compliance, AML/KYC and management company internal audit.
๐Ÿข
Portfolio GRC Monitor โ€” Single view across all portfolio companies
Fund compliance teams can now track GRC health across all portfolio companies in one dashboard. Red/amber/green status per company per framework (SOX, SOC 2, ISO 27001, GDPR, ESG). AI-generated portfolio intelligence highlights at-risk companies and time-sensitive issues.
๐Ÿ”
AI Due Diligence Assessment โ€” Compliance memo in 2 minutes
Upload target company documents and AI runs 6 sequential compliance analysis agents: company risk profile, framework assessment, financial controls, data privacy/cybersecurity, red flags identification, and a professional DD memo generation. Outputs overall risk rating, maturity scores per framework, conditions precedent list, and post-close action plan.
๐ŸŒฑ
ESG & ISSB Reporting โ€” ISSB S1/S2, SFDR, TCFD compliant
Collect E/S/G metrics across all portfolio companies, generate AI ESG scores with SFDR Article 6/8/9 classification, and produce LP-ready ESG reports. Covers ISSB S1/S2, SFDR, GRI Standards, TCFD and SEC Climate Rules.
August 2026 NEW
Major Platform Upgrade โ€” 10 Enterprise Gaps Closed โ€” August 2026
๐Ÿ“
Permanent File Storage โ€” Evidence files now stored in Supabase Storage
Evidence files uploaded via Evidence Intelligence are now permanently stored in Supabase Storage with cryptographic path isolation per organisation. Each file receives a permanent public URL and metadata record (file_name, type, size, control linkage) in the evidence_files table. Version control tracks re-uploads of the same filename.
๐Ÿ‘ฅ
Real-Time Collaboration โ€” See who's viewing workpapers live
Workpaper pages now show live presence indicators โ€” coloured avatar bubbles showing which team members are viewing or editing each workpaper. Powered by Supabase Realtime channels with per-workpaper presence tracking. Section locking broadcasts prevent concurrent edits.
๐Ÿ”
Enterprise SSO โ€” Okta, Azure AD, Google Workspace
The login page now includes an Enterprise SSO section. Enter your company email and AssurAI detects whether your domain has SAML 2.0 or OIDC SSO configured. SSO domain mapping is configured per organisation in org_settings. Supports Okta, Azure Active Directory, and Google Workspace via Supabase's native SAML SSO feature.
๐Ÿ“œ
Immutable Audit Trail โ€” Auto-logged changes across all key tables
Database triggers now automatically log every INSERT, UPDATE, and DELETE across workpapers, findings, controls, control_tests, and issues into the audit_trail table. Each entry captures: table name, record ID, action, before/after values (JSONB), changed_by user, org_id, timestamp, and IP address. The trigger function is fault-tolerant โ€” audit failures never block the main operation.
๐Ÿ“ฑ
Mobile PWA โ€” Install AssurAI as a home screen app
AssurAI is now a Progressive Web App. A manifest.json enables "Add to Home Screen" on iOS and Android. The new Mobile Approvals page lets reviewers approve or return workpapers with large tap targets optimised for phones. The service worker (v10) caches key pages for offline access. Install prompt auto-appears on mobile browsers.
๐Ÿ“ง
Email Notifications โ€” Overdue alerts, review reminders, daily digest
The Automations engine now sends professionally formatted email notifications via Resend for: overdue Critical/Significant findings (30+ days), workpapers stuck in review (5+ days), overdue evidence requests, and new significant findings. Templates include deep-links back to the platform. Notification preferences configurable per organisation in org_settings.
๐Ÿ’ฌ
Natural Language Queries โ€” Ask the AI assistant data questions
The AI assistant (โœจ button) now detects data queries and answers them directly from your Supabase data. Ask "Show me all critical findings overdue" or "How many workpapers are in review?" and the assistant queries the relevant table, applies filters, and returns a formatted summary โ€” without requiring any manual navigation.
๐Ÿข
Vendor Portal โ€” External questionnaire portal for TPRM
A public-facing vendor portal (vendor-portal.html) lets third parties complete security questionnaires without a platform login. Auditors generate a unique access token and email it to the vendor; the vendor visits the portal, completes the 4-section questionnaire (Company Info, Security Controls, Compliance Certifications, Sub-processors), and submits. Responses are stored against the vendor_assessments record and the requesting auditor is notified.
๐Ÿ“„
Microsoft Office Export โ€” Word download from workpaper cards
Every workpaper card now has a ๐Ÿ“„ Word button that downloads the full workpaper as a .doc file โ€” including objective, scope, procedures, evidence trail, exceptions, conclusion, and sign-off blocks formatted for Microsoft Word. A ๐Ÿ“Š Excel button deep-links to the Excel add-in with the workpaper pre-loaded.
โš™๏ธ
Automation Rules Engine โ€” 4 pre-built rules with dry-run testing
The automations engine now has a real backend (run-automations.js). Four rules run on schedule: escalate critical overdue findings, remind workpaper reviewers, chase overdue evidence requests, and alert on new significant findings. A dry_run mode shows how many records would be affected without sending emails. Execution logged in automations_log table.
August 2026 NEW
Advisory Services, Framework Library Exports & Evidence Intelligence โ€” August 2026
๐Ÿค
AssurAI Advisory Launched โ€” 28 named services across 7 practice areas
AssurAI Advisory delivers fixed-fee professional services across SOX & ICFR, Internal Audit, Cybersecurity, Risk & Compliance, TPRM, Financial Intelligence, and Cross-Assurance. All engagements include a 25โ€“50% cost savings guarantee versus Big 4 and mid-tier firms. Service menu includes scoping workshops, control design, gap assessments, readiness reviews, co-sourcing, and regulatory advisory. Book a free 30-min consultation directly from the advisory page.
๐Ÿ“š
Framework Library โ€” File upload for gap assessments + PowerPoint / Word / Excel export
The Framework Library now accepts file uploads (PDF, DOCX, XLSX, CSV) as input for AI gap assessments. After AI analysis, export results as a branded PowerPoint deck, a structured Word report, or an Excel workbook โ€” ready to share with clients and management with no additional formatting needed. Covers 25+ frameworks including SOC 2, ISO 27001, NIST CSF, PCI DSS, HIPAA, and CIS Controls.
๐ŸŽฏ
Project Mode โ€” PowerPoint and Word export for all 6 project types
Every Project Mode pipeline (Cyber Maturity, SOC 2 Readiness, ISO 27001, TPRM, Internal Audit, Fraud Risk) now exports a fully-structured PowerPoint presentation and Word report directly from agent results โ€” including executive summary, gap analysis, risk ratings, and recommended roadmap. Replaces $40โ€“120K deliverable preparation time.
๐Ÿ”ฌ
Evidence Intelligence โ€” Suggested Controls matching + Attach to control
After AI classification, Evidence Intelligence now surfaces a ๐ŸŽฏ Suggested Controls panel showing the top matching controls from your library. Click ๐Ÿ“Ž Attach to control to create a link in the evidence_control_links table โ€” building a traceable evidence-to-control map automatically from uploaded documents.
๐ŸŒ
25+ data sources โ€” CrowdStrike, Qualys, Splunk, Workday and more
Evidence Intelligence now displays 25+ named data sources in the source selector, including CrowdStrike Falcon, Qualys VMDR, Splunk SIEM, Workday, ServiceNow, Okta, AWS IAM, Azure AD, GitHub, Google Workspace, Jira, Confluence, Microsoft 365, Salesforce, SAP, Oracle ERP, Netsuite, Veeva, Proofpoint, Rapid7 InsightVM, Tenable.io, SentinelOne, Crowdstrike Spotlight, and Custom REST connectors. Each source has a branded icon and description.
July 2026
10 Strategic Platform Improvements โ€” July 2026
๐Ÿ 
Clean home launcher โ€” module chicklets replace the busy dashboard.
The app home page is now a focused launcher with a welcome header, a 3ร—2 grid of module chicklets (SOX & ICFR, Internal Audit, Risk & ERM, Compliance, BCM & Resilience, Financial Intel), and a personalised quick-launch bar.
๐Ÿ“Š
Customisable dashboard โ€” drag-and-drop widgets, choose what you see.
A new /dashboard page lets you build your own view from 8 widget types: Recent Activity, Findings by Severity, Workpaper Status, Deadlines, AI Insights, KRI Status, My Assignments, and Team Workload. Drag to reorder, add or remove with one click.
โœ๏ธ
Personalised quick launch โ€” pick your 8 favourite shortcuts.
The home page quick-launch bar is fully customisable. Choose up to 8 shortcuts from every page in the platform, organised by section. Your selection is saved locally and persists across sessions.
๐Ÿ—‚๏ธ
Collapsible Sidebar
The platform sidebar now collapses to an icon-only strip, giving more horizontal space for workpapers and analysis panels. Click the chevron or use the collapse button โ€” preference persists across sessions.
๐Ÿ“ค
Coexistence Exports โ€” Cross-Platform Workpaper Export
Export any workpaper directly to your existing GRC platform (JSON, Word/Excel, or CSV) with one click from the workpaper toolbar. Use AssurAI's AI alongside your existing platform โ€” no rip-and-replace required.
๐ŸŽฏ
Project Mode Launcher
Select a project type (cyber maturity, SOC 2 readiness, ISO 27001 gap analysis, TPRM, internal audit, fraud risk) and AssurAI pre-configures modules, loads template workpapers, and generates your PBC evidence list automatically. Replaces $40โ€“120K contractor engagements with a subscription feature.
๐Ÿค–
Bring Your Own LLM (BYOLLM)
Switch the AI model powering your workpapers and analysis from Anthropic Claude to OpenAI GPT-4o, Google Gemini Pro, or Azure OpenAI in Settings โ†’ AI Provider. API keys stay in your browser โ€” never sent to AssurAI servers. The provider badge in the sidebar header updates in real time.
๐Ÿ’ณ
Project Licence Pricing
New $999 flat-fee Project Licence: 90-day full-platform access for up to 5 users โ€” no annual commitment. Designed for single engagements (SOX readiness, cyber assessment, audit co-sourcing). Upgradeable to a full subscription with fee credit applied to month one.
๐Ÿงฉ
Custom Module Builder
Build your own GRC modules with a 3-column builder: set module name, icon, description and access level; add up to 10 workflow steps (Data Collection, AI Analysis, Review, Sign-off) with custom AI prompts; preview live in the sidebar. Modules are stored in Supabase and appear in the nav automatically.
๐Ÿ‘‹
Personalised Onboarding Flow
New 3-step onboarding wizard shown to first-time users: role selection โ†’ first project type โ†’ team size. On completion, the platform opens the most relevant module automatically (SOX, Audit, Risk, Compliance, Cyber, or Vendor Risk). Skippable at any step.
July 2026 NEW
Competitive Feature Release โ€” 6 New Capabilities โ€” July 2026
๐Ÿค
Third-Party Risk Management (TPRM)
Full vendor risk module โ€” register vendors with criticality, contract dates, and SOC 2 expiry; AI-powered risk assessments that return a risk score, key risks, recommended actions, and due diligence questions; risk distribution dashboard; auto-saves assessments to vendor record. Closes the gap with Vanta's paid TPRM add-on โ€” included in AssurAI at no extra cost.
๐Ÿ“
AI Questionnaire Auto-Answer
Paste or upload a security questionnaire (.txt/.csv) and AI auto-answers all questions using your persisted knowledge base. Batch processing with progress bar, confidence ratings (High / Medium / Low), inline editing, and one-click CSV export. Covers due diligence, vendor security questionnaires, and RFP security sections โ€” a capability absent from Vanta and most competing platforms.
๐Ÿ”—
Regulatory Change โ†’ Control Mapping
Each regulatory change card now has a "Map to My Controls" button. AI analyses the regulatory change against your live control library, identifies impacted controls, rates impact (High / Medium / Low), and recommends specific actions. Results are saveable to workpapers with a single click (ref format: REG-MAP-[timestamp]).
๐Ÿ”Œ
Evidence Connectors
Generic REST connector to pull evidence from any system with an API (URL + optional bearer token). Preview fetched content before importing. Imported evidence is queued directly in Evidence Intelligence. Evidence schedules let you define recurring pulls. Coming Q3 2026: native connectors for Okta, AWS IAM, Azure AD, GitHub, and Google Workspace.
โš™๏ธ
CCM AI Rule Templates + Anomaly Review
Six pre-built AI detection rule templates (terminated user with active access, JE outside business hours, duplicate vendor payment, payment just under approval threshold, dormant account activity, privileged access change without ticket). Each monitoring alert now has an "AI Anomaly Review" button that returns likely cause, false positive probability, recommended investigation steps, and suggested disposition.
๐Ÿ›ก๏ธ
SOC 2 / ISO 27001 Framework Mapper
Track readiness against all 33+ SOC 2 Trust Services Criteria (CC1โ€“CC9 + A1) and 45+ ISO 27001:2022 Annex A controls. Each criterion has a status dropdown (Not Started / In Progress / Implemented / Not Applicable), evidence notes, and owner field โ€” all auto-saved to Supabase. Overall readiness percentage with per-section progress bars. "AI Gap Analysis" button generates a readiness score, critical gaps, quick wins, remediation roadmap, and estimated timeline.
๐Ÿ›ก๏ธ
Framework Mapper enhanced โ€” 10 new frameworks
Framework Mapper now covers 12 frameworks: NIST CSF 2.0 (6 functions), NIST SP 800-53 Rev 5 (20 control families), PCI DSS v4.0 (12 requirements), HIPAA Security Rule (17 safeguard standards), GDPR (10 key articles), COBIT 2019 (15 governance objectives), CIS Controls v8 (18 controls), FedRAMP, DORA (5 pillars) and IIA Standards 2024. New features: file upload for gap analysis (attach policies, audit reports, pen tests โ€” AI incorporates them), expandable criterion rows showing description, guidance notes and evidence examples, per-criterion evidence file attachment, last-updated timestamps, status summary chips, bulk "Mark N/A" per section, Export to Excel (CSV), import prior assessment, and copy summary to clipboard. Gap analysis now returns a rich report with critical gaps table (ref, risk level, recommended action, effort, timeline), quick wins cards, strengths section, remediation roadmap by phase, and numbered next steps.
๐Ÿ”
Module-Based Access Control
Org admins can now restrict team members to specific GRC modules โ€” SOX only, ERM only, read-only observer, and more. An interactive access matrix (Full / Read Only / None) per module is managed from the Team page. One-click role presets for common audit team structures: Internal Auditor, Risk Manager, Compliance Officer, SOX Team, and Read Only Observer. Users with no access to a module see an access-denied page; read-only users see a banner and action buttons are hidden automatically across the platform.
July 2026 NEW
Evidence Intelligence + Annotation โ€” July 2026
๐Ÿ”ฌ
Evidence Intelligence + Annotation
AI Evidence Annotation Trail is now automatically generated after every test run. Each uploaded document receives a structured annotation card covering procedures performed, key findings, exceptions noted, and a reliability rating (High / Moderate / Low). A consolidated evidence trail summarises overall sufficiency, compliance gaps, and recommended additional procedures. Fully compliant with PCAOB AS 1215 and IIA GIAS 2024 Standard 14.1. One-click workpaper creation links the full annotation trail to the workpaper file.
๐Ÿ“„
Evidence Annotator Workpaper Mode
Open any workpaper's evidence directly in the Annotator with AI auto-annotations pre-loaded. The evidence queue shows all documents attached to the workpaper. Click any document to view AI-generated tick marks (โœ“), pins (๐Ÿ“Œ), and exceptions (โœ—) overlaid on the document. Annotations are saved back to the workpaper evidence trail for auditor review and sign-off.
July 2026
AI Evidence Annotation Trail โ€” July 2026
๐Ÿ“‹
AI Evidence Annotation Trail & Workpaper Linking
After AI analysis completes in Evidence Intelligence, generate a structured per-document annotation trail compliant with PCAOB AS 1215, IIA GIAS 2024 Standard 14.1, and ISA 230. Each document receives a full annotation card (type, procedures performed, key findings, exceptions, conclusion, reliability assessment). A consolidated trail summarises overall reliability, evidence sufficiency, and recommended additional procedures. All fields are editable inline. Save directly to an existing workpaper or create a new one โ€” the annotation trail is linked and viewable from Workflow with a ๐Ÿ“Ž Evidence Trail badge.
July 2026 NEW
Agent AI Expansion โ€” July 2026
๐Ÿ“Ž
Document Attachment in Agent Pipeline
Attach up to 10 files (PDF, DOCX, XLSX, CSV, TXT, PNG, JPG) directly to your Agent Pipeline run. PDFs and images are passed as native content blocks to Claude; text files are prepended as context. Drag-and-drop supported with a total size indicator.
๐Ÿง 
Persistent Pipeline Memory
The Agent Pipeline now remembers your last 5 runs. Each run is automatically summarised and stored locally. On subsequent runs, Co-Pilot builds on prior analysis rather than starting from scratch โ€” surfaced via an in-page context banner with one-click history clear.
๐Ÿ”—
Cross-Module AI Orchestration
Select 2โ€“6 GRC modules and run a coordinated AI analysis across them simultaneously. The AI orchestrator surfaces patterns, gaps, and interdependencies invisible when viewing modules in isolation โ€” presented in four collapsible sections with export to text.
๐Ÿ“„
Policy & Document Ingestion Hub
Import policies from any source โ€” paste a URL, paste text directly, or upload files. Extracted content is stored in your Policy Library and can be used to review workpapers, check compliance gaps, feed the Agent Pipeline, or generate test procedures โ€” all in one click.
July 2026 NEW
AI-Powered Features โ€” July 2026
๐Ÿง 
Predictive Risk AI
AI-powered escalation predictions across your full risk register. Identifies the top 3 risks most likely to escalate in the next 90 days with confidence scoring and recommended actions.
๐Ÿค
Co-Pilot Pro
Context-aware AI assistant with full knowledge of your active engagement, open findings, risks, and workpapers. Answers audit questions, drafts workpapers and findings, and suggests procedures.
๐Ÿ“Š
Enhanced Executive Dashboard
Board-level reporting with live KPIs, findings trend chart, 5ร—5 risk heatmap, engagement progress, and AI-generated executive insights panel.
๐Ÿ”„
Real-time Collaboration
Live presence indicators show who else is viewing or editing. Instant toast notifications when team members update workpapers or change finding status.
๐Ÿ“‹
IA Audit Programme Builder
AI-generated risk-based audit procedures inside Internal Audit engagement files. Generate 10โ€“15 specific procedures from your audit objective with one click.
June 2026 AI Intelligence Features NEW
AI Intelligence Features โ€” June 2026
๐ŸŽฏ
Deterministic AI MRC Testing
MRC evaluations now run at temperature=0 โ€” the same evidence always produces the same conclusion. Every attribute evaluation cites the exact text from your uploaded document. No hallucinations. Full audit trail.
๐Ÿ“‹
Big 4 MRC Workpaper Format
MRC test results now render as a full 6-section Big 4 workpaper โ€” header, 5-attribute evaluation table with evidence quotes and pass/fail verdicts, missing evidence alerts, AI auditor conclusion, editable sign-off fields, and print-ready format.
๐Ÿ“Š
Missing Evidence Alerts
After Evidence Intelligence classifies your documents, an automatic coverage check identifies which key MRC attributes are present and which are missing โ€” before you run the test.
๐Ÿ“Š
RCM Auto-Reader
Upload your existing Risk Control Matrix in any format โ€” Excel, PDF, Word, or CSV. AI extracts every control automatically with no template required. Add directly to your control library or generate evidence request lists.
๐Ÿ”—
Evidence Auto-Matching
Classified documents are automatically matched to controls in your library based on content analysis. High/Medium confidence matching with one-click linking.
๐Ÿ“‚
Prior Year Workpaper Ingestion
Upload any prior year workpaper โ€” PDF or Word. AI reads the structure, objectives, procedures, and conclusions, then creates a new Draft workpaper pre-populated with [PY] markers for this year.
๐ŸŽค
Walkthrough AI
Paste your walkthrough meeting notes โ€” AI generates a structured process narrative, SVG flowchart, list of controls identified, and risk points. Meeting to workpaper in minutes.
๐Ÿ”ด
Redboxed Evidence Packages
AI identifies the exact passages in your evidence documents that support each PCAOB attribute conclusion and highlights them Big 4 style. Download a print-ready redboxed evidence package.
๐Ÿ”
Evidence Authenticity Check
Every uploaded document is automatically scanned for authenticity indicators โ€” inconsistent formatting, suspicious dates, round-number patterns, and AI-generated text signatures.
๐Ÿข
Enterprise Deployment Options
AssurAI now offers VPC and on-premise deployment for organisations with strict data governance requirements. SSO/SAML, SCIM, custom SLAs, and dedicated tenants available.
๐Ÿ”„
Reconciliation AI
Upload two datasets โ€” GL and bank statement, intercompany balances, AR/AP โ€” and AI matches, identifies exceptions, explains likely causes, and generates a complete reconciliation workpaper.
๐Ÿ“‹
Big 4 Compatibility
AssurAI workpapers are now explicitly formatted to Big 4 standards โ€” accepted by external audit teams without reformatting. PCAOB AS 2201 aligned throughout.
๐Ÿฆ
BSA/AML Compliance Module
New compliance module covering Bank Secrecy Act and Anti-Money Laundering requirements โ€” risk assessment, SAR review assistance, CIP/KYC testing, and AML program assessment.
๐Ÿš€
Pre-IPO Landing Page
Dedicated guidance for companies building their SOX program before IPO โ€” scoping, control framework, gap analysis, and external auditor readiness. AI-native from day one.
๐Ÿ”
Cryptographic Evidence Hashing
Every uploaded document receives a SHA-256 integrity certificate โ€” timestamped proof that evidence has not been altered since collection. Download the certificate for your audit file.
๐Ÿ“ˆ
Year-over-Year Intelligence
AI analyses your historical audit data to surface repeat findings, control effectiveness trends, testing efficiency improvements, and suggested focus areas for the current year.
June 2026 Competitive AI Features
Competitive AI Features โ€” June 2026
๐ŸŽค
Walkthrough AI
Paste walkthrough meeting notes โ€” AI generates process narrative, flowchart, and identifies controls automatically. Big 4 standard workpaper output.
๐Ÿ”ด
Redboxed Evidence Packages
Big 4 standard redboxing โ€” AI identifies exact text passages that support each PCAOB attribute conclusion. Downloadable printable package.
๐Ÿ”
Evidence Authenticity Check
AI-powered detection of potentially forged or AI-generated documents. Flags suspicious patterns including weekend dates, round numbers, and copy-paste artifacts.
๐Ÿ”
Cryptographic Evidence Hashing
SHA-256 cryptographic certificates for every uploaded document. Printable integrity certificate proves evidence has not been altered since upload.
๐Ÿ”„
Reconciliation AI
Upload two datasets โ€” AI matches transactions, identifies exceptions, and generates audit-ready reconciliation workpapers with exception analysis.
๐Ÿ“ˆ
Year-over-Year Intelligence
AI insights from your prior year audit history โ€” repeat findings, control effectiveness trends, and testing efficiency metrics.
๐Ÿฆ
BSA/AML Compliance Module
New module for Bank Secrecy Act and AML compliance โ€” risk assessment, SAR review, CIP/KYC testing, transaction monitoring, and AML program assessment.
๐Ÿš€
Pre-IPO SOX Landing Page
Dedicated page for pre-IPO companies building their SOX program. AI-native from day one โ€” cut Big 4 readiness costs by 70%.
๐Ÿข
Enterprise Deployment Options
VPC and on-premise deployment options for large organizations. SSO/SAML, SCIM, dedicated tenant, custom SLAs, and white-labeling.
June 2026 โ€” Update 5 Just shipped
Risk Dashboards, Instant Analytics, Exports & Integrations
๐ŸŽฏ
Enterprise Risk Dashboard (ERM Agent Pipeline)
The ERM Agent Pipeline now automatically visualises risk-scoring output as a colour-coded dashboard โ€” a 5ร—5 risk heat map with numbered risk badges plotted by likelihood and impact, a risk register table with coloured severity badges (Critical / High / Medium / Low) and key-metric cards (Total Risks, Critical, High, Avg Risk Score). It auto-renders from Agent 2 output with no manual steps, and Agent 5 (Board Report) shows the same visual dashboard.
๐Ÿ“Š
Data Analytics โ€” Instant Sample Data
All 12 pre-built analytics use cases now demo instantly without uploading data โ€” click Run Analysis on any use case to see realistic KPIs, severity-rated findings and audit-language narrative immediately. Covers JE Anomalies, Vendor Payments, UAR, Payroll, Three-Way Match, Revenue, Expense, IT Change, Access Provisioning, Bank Reconciliation, Fixed Assets and Contract Review. A "Using sample data" badge clearly marks illustrative output; upload real data to run live AI analysis.
๐Ÿ“ค
Agent Pipeline Exports (PDF, Word, PowerPoint)
Export any individual agent output or the full pipeline report. PDF gives a clean, print-formatted report with all tables and dashboards; Word (.doc) preserves tables, the risk register and severity badges; PowerPoint (.pptx) is a real downloadable file with one slide per agent, navy headers and risk-register bullets. Export buttons appear on each agent output after completion.
๐Ÿ”€
Flowchart Builder Improvements
Full narrative, risks and controls now render correctly after generation. Export to Visio (.vsdx) downloads flowcharts as genuine Visio files for editing in Microsoft Visio or draw.io, and a more robust JSON parser handles truncated API responses gracefully.
โšก
Evidence Intelligence โ€” More Reliable Classification
Classification now retries automatically on timeout โ€” showing "Analysingโ€ฆ (retrying)" instead of an error โ€” which significantly reduces classification failures during high-load periods.
๐Ÿ”Œ
Workday & BlackLine Integrations
A new Integrations Hub brings live connections to Workday Financials (full connection setup, GL data import with risk flagging, field mapping and MRC testing) and BlackLine (reconciliation data import, close calendar and MRC testing from recon data). Sample-data mode lets you explore without credentials. Eight integrations are shown: Workday, BlackLine, SAP, NetSuite, ServiceNow, Dynamics 365, Okta and RSA Archer.
๐Ÿ›๏ธ
Auditor Portal โ€” Enterprise Redesign
A complete visual redesign of the external auditor portal โ€” a navy app shell with a 64px header bar, a 280px sidebar with firm avatar, icon navigation and permission chips, an engagement hero card with a Planning โ†’ Fieldwork โ†’ Review โ†’ Complete progress tracker, workpaper cards with hover effects and colour-coded status badges, and finding cards with severity-driven left borders.
๐Ÿ”
Trial & Billing Infrastructure
A 14-day free trial is now enforced automatically, with a colour-coded trial countdown banner in the dashboard navigation, automatic emails at 3 days remaining and on expiry, upgrade prompts and a locked-account flow โ€” all backed by full Stripe payment integration.
๐Ÿ“Š
Benchmarking Dashboard
Compare your audit program against industry peers across six key metrics โ€” audit cycle time, control coverage, findings per audit, remediation rate, cost efficiency and risk coverage โ€” with four CSS comparison charts pitting your program against the industry average. Pick your sector (Technology, Financial Services, Healthcare, Manufacturing, Retail, Energy or Professional Services); benchmarks are based on IIA CBOK 2024.
๐Ÿ””
Notification Settings
Configure exactly which email alerts you receive across 13 notification types โ€” findings overdue, control untested, SOX cert due, weekly digest and more โ€” and choose your email frequency: Immediate, Daily Digest or Weekly Only.
๐Ÿ“…
Audit Planner โ€” Gantt Chart
A visual Gantt chart for audit engagement planning with colour-coded phases โ€” Planning (navy), Fieldwork (blue) and Reporting (amber). Click any task to edit its details, owner, status and notes, add tasks dynamically (stored in localStorage), and use the today line plus print/export support.
โฑ๏ธ
Time Tracking & Reports
Track audit hours by engagement, team member and activity with a quick time-entry form and weekly timesheet view. Three report tabs โ€” By Engagement, By Team Member and By Activity โ€” give hours-vs-budget tracking with variance analysis, plus CSV and PDF export.
๐Ÿ“ฅ
PBC Request Tracker
Manage external auditor document requests (Prepared By Client) with 15 sample requests, colour-coded status badges and a full filter bar (status, category, priority, auditor). Upload via a drag-and-drop modal and track submission dates and overdue items.
๐Ÿข
Multi-Entity Support
A consolidated view across all entities in your group โ€” an entity comparison table with risk colour coding, individual entity drill-down views, an Add Entity modal and a risk-aggregation chart by severity.
๐Ÿ’ผ
Management Response Portal
A standalone token-authenticated portal for management to view and respond to findings โ€” no AssurAI account needed. Management receives a secure link via email, submits their response, remediation plan and target date, and the audit team is notified instantly.
๐Ÿ”
SOC 2 Trust Center
A public security and trust page for enterprise procurement teams โ€” covering encryption, infrastructure, access control and data residency. Includes GDPR, CCPA, IIA Standards and PCAOB compliance documentation, with DPA available on request.
โ†ฉ
Carry-Forward Workpapers
Copy any workpaper to a new engagement period with one click โ€” carrying forward objectives, procedures and prior year conclusions. The new workpaper is created as a Draft with a CF reference, available on every workpaper row in the workpaper list.
๐Ÿ“Š
Issue Aging Reports
An Aging Analysis tab on the findings page โ€” four aging buckets: 0โ€“30 days (green), 31โ€“60 (amber), 61โ€“90 (red) and 90+ (dark red) โ€” plus a full aging table sorted by days open descending. Zero additional API calls: uses existing findings data.
๐Ÿ›ก๏ธ
Independence Declaration
A formal IIA Standard 1130 pre-engagement independence declaration โ€” six conflict-of-interest questions with Yes/No answers, an impairment warning and CAE approval workflow if a conflict is identified, a digital signature with reference number saved to Supabase, and PDF download support.
๐Ÿ“…
Follow-Up Audit Scheduling
Auto-prompts to schedule a follow-up when a finding is marked Remediated โ€” set the follow-up date, assigned auditor and verification scope. A Follow-Up Due filter tab shows findings with upcoming follow-ups, and a badge appears on finding cards with scheduled dates.
โฑ๏ธ
Real Time Tracking (Supabase)
Time logging now saves directly to Supabase โ€” log entries with date, engagement, activity, hours and notes. A recent entries panel shows the last 10 logged entries, and the resource planning page uses hours-based capacity planning with budgeted vs actual hours, configurable weekly hours and an audit target percentage.
๐Ÿ›๏ธ
Audit Universe (Supabase)
The audit universe database is now fully connected to Supabase โ€” risk-scored audit entities drive annual audit plan generation, with AI risk scoring 1โ€“5 per entity.
June 2026 โ€” Update 4 Latest
Premium UI, MRC Testing & Universal Save to Engagement
โœจ
Premium UI redesign
A premium, enterprise-grade redesign rolled out across all 16 core pages โ€” cleaner layouts, consistent components and a faster, calmer feel throughout the platform.
๐Ÿ”ฌ
MRC Testing โ€” 5-Attribute Evaluation
Evidence Intelligence now auto-detects Management Review Controls and evaluates five attributes โ€” Performance, Competence, Timeliness, Effectiveness and Documentation โ€” aligned to PCAOB AS 2201 review-precision expectations.
๐Ÿ’พ
Universal Save to Engagement
"Save as Workpaper" is now available on every one of the 20+ AI agents โ€” file any AI output straight into the right engagement via the Module โ†’ Engagement โ†’ Business Process โ†’ Section โ†’ Workpaper Type hierarchy.
๐Ÿ“Š
Business Process Structure (O2C/P2P/R2R/H2R/ITGC)
Engagement files are organised by business process โ€” Order-to-Cash, Procure-to-Pay, Record-to-Report, Hire-to-Retire and ITGC โ€” with process filtering and By Phase / By Process views.
โœ…
SOX Certifications โ€” New Cycle Creation
Spin up a new 302/906 certification cycle, assign certifiers and track sign-offs to completion.
โ–ถ๏ธ
Full Animated Platform Tour (8 min)
A complete, animated guided tour of the platform โ€” the fastest way to onboard a new team.
๐Ÿ”ต
Animated Logo Standardised Across 118 Pages
The canonical animated AssurAI logo is now consistent across all 118 pages for one coherent brand experience.
๐ŸŽจ
13 Additional Pages Upgraded
A further 13 pages upgraded to the enterprise-grade UI, completing the premium redesign across the platform.
๐Ÿ“˜
Comprehensive Help Guide
A rebuilt, searchable user guide covering every feature โ€” getting started, workpapers, findings, Evidence Intelligence, MRC testing, AI agents and Save to Engagement.
June 2026 โ€” Update 3
Engagement Hierarchy & Save to Engagement
๐Ÿ’พ
Save to Engagement
Universal save modal for all AI agents โ€” pick module, engagement, business process, section and workpaper type, then Save as Draft or Save & Submit for Review.
๐Ÿ“Š
Business Process Structure
SOX engagements are now organised by business process โ€” O2C, P2P, R2R, H2R, ITGC and more โ€” with a process filter, process grouping and a By Phase / By Process ring view.
๐Ÿ—‚๏ธ
Process Map
A visual SOX process map in the SOX module โ€” ELC โ†’ O2C โ†’ P2P โ†’ R2R โ†’ H2R โ†’ Treasury โ†’ ITGC โ†’ Financial Close โ€” click a process to filter the relevant AI tools.
June 2026 โ€” Update 2
Specialist Audit Tools & Automation
๐Ÿ“
Evidence Annotation System
Annotate PDF, image, Excel, and CSV evidence. Link marks to test attributes and workpaper sections. Includes templates, split view, and a submit/approve/return review workflow.
๐Ÿ”
JE Fraud Detector
Detect journal-entry anomalies with Benford's Law and fraud heuristics (round amounts, unusual times, rare users).
๐Ÿ”„
Three-Way Match Agent
Automate PO/GR/Invoice matching with configurable tolerance thresholds; exceptions flagged and saved as workpaper.
๐Ÿ“„
Contract Analyzer
Extract key contract terms from PDF and map them to audit risks automatically.
๐Ÿ“ˆ
Earnings Quality Analyzer
Accruals and cash-conversion ratios, Benford's Law on reported figures, and a 0-100 earnings quality score.
๐Ÿ”
Cybersecurity Control Assessor
ITGC gap analysis against NIST CSF, SOC 2, ISO 27001, and PCAOB with a prioritised remediation roadmap.
๐ŸŒฑ
ESG Data Validator
Validate sustainability disclosures against GRI, SASB, TCFD, and CSRD; traffic-light gap report for assurance readiness.
๐Ÿ’ธ
Duplicate Payment Detector
Find exact and near-duplicate payments across vendor, amount, date, and invoice number with a recovery estimate.
๐Ÿ“‹
Policy Compliance Checker
Test transactions and processes against a policy PDF; AI flags every non-compliant item with a policy reference.
โฑ๏ธ
Time Tracking
Log hours per engagement phase; budget vs actual burn chart with amber/red overrun alerts.
๐ŸŒ
Audit Universe Management
Inventory auditable entities, score by inherent risk, set frequency, and generate a risk-based annual audit plan.
โš™๏ธ
CCM Rules
Define and schedule continuous control monitoring rules that run automatically against live data.
โœ‰๏ธ
Weekly Status Emails
Automated weekly digest of engagement progress, open findings, and upcoming deadlines sent to the audit team.
โœ‰๏ธ
Escalating Evidence Reminders
Automated reminder sequence for outstanding PBC requests โ€” escalates to manager if evidence remains overdue.
โœ…
Annotation Review Workflow
Submit, approve, or return annotation sets with reviewer comments โ€” full audit trail stored per workpaper.
June 2026 โ€” Update 1 Update
Major Feature Update
๐Ÿงช
Full Population Testing
Test every transaction autonomously, not just samples. Up to 50,000 rows with AI judgment and decision logs.
๐Ÿ“‘
Procedure Execution Engine
Upload your existing audit testing plan. AI follows your procedures step by step against uploaded evidence.
๐Ÿ“‹
Automated Judgment Logs
Every AI decision traced to specific data points. Fully auditable at every stage.
๐Ÿ•ต๏ธ
Fraud Risk Assessment
Top 10 fraud schemes per ISA 240 for any process with likelihood/impact ratings and management inquiry questions.
๐Ÿ“
Management Action Plans
Formal management response workflow with owners, target dates and closure evidence.
๐Ÿ“ก
Standards Radar
Automatic weekly monitoring of PCAOB, IIA, SEC, ISACA, FRC and FASB updates mapped to your controls.
๐Ÿ“
Peer Benchmarking
Compare your GRC metrics against 40+ industry benchmarks across 7 categories.
๐Ÿ“†
Engagement Planner
Gantt timeline, team capacity RAG status, deadline alerts and drag-to-reschedule.
๐Ÿ‘ฅ
Real-time Collaboration
Live presence, comment threads and @mentions on workpapers.
๐Ÿ“ฅ
Audit-Ready Excel Output
Export in Big 4, PCAOB or standard templates.
๐Ÿ”
MFA Security
Two-factor authentication via Google Authenticator or Authy.
๐Ÿ”Œ
Enterprise API
REST API access with key management and rate limiting.
๐Ÿ“ˆ
Usage Analytics
Track AI usage, hours saved and workpaper trends.
โœ…
Workpaper Reviewer Agent
Quality score 0-100 against IIA Standards and PCAOB AS 2201.
๐Ÿค–
48 AI Agents
Full suite of autonomous agents for every GRC use case.
May 2026 Launch
Platform Launch
๐Ÿš€
AssurAI launches with 6 modules
SOX & ICFR, Internal Audit, Risk & ERM, Compliance, BCM & Resilience, Financial Intelligence.
โšก
Evidence Intelligence
AI-powered document classification, control mapping and workpaper generation.
๐Ÿค–
AI Agent Pipeline
Chain multiple agents for complex multi-step audit workflows.
๐Ÿ”€
Flowchart Builder
Visual process mapping with AI risk overlay.
๐Ÿ“Š
320+ AI tools
Expert Big 4 prompts across all 6 modules.
๐Ÿ”—
Cross-framework mapping
Map controls across 25 regulatory frameworks simultaneously.
๐Ÿ“Š
Excel Add-In
AI audit tools inside Microsoft Excel.
๐Ÿ“‹
Workpaper management
Full workpaper lifecycle with sign-off workflow.
๐Ÿ”
Evidence request portal
Request portal with auditor access โ€” no login required for clients.
๐Ÿ“ˆ
KRI Monitor
Key risk indicator tracking and continuous monitoring.
๐ŸŒ
20+ native integrations
SAP, Oracle, Workday, Okta, ServiceNow and more.