SOX control testing and GRC
Audit Executive tests ITGC, ITAC, business and HR controls end to end. The AI reads the evidence and proposes a result. Your auditors decide. Every conclusion traces back to a document, a seed and a named person.
Hosted for you in a dedicated instance, or installed on your own servers.
Access was approved by the user's line manager before it was granted.
Ticket shows manager approval on 03 Mar at 10:14. Provisioning log shows the role granted on 03 Mar at 16:52, after approval.
Approved by R. Mehta (Line Manager) 03-Mar-2026 10:14
Why it exists
For years SOX testing has been done by hand.
Screenshots pasted into Word. A sample picked in Excel, and months later nobody could say how. Evidence in a folder that did not match the sample. Then review comments, and half of it again.
Audit Executive replaces that with one workflow where every step leaves proof.
How it works
AI drafts the questions from the control, its attributes and its risks. The control owner answers in their portal. You conclude on design.
Upload the system report. It is hashed on arrival, with the source and completeness checks recorded next to it.
Size follows frequency and risk. Items are drawn from a stored seed, so anyone can re-draw the same selection.
Request it from the owner or upload it yourself. Every file is hashed, linked to its sample item, and re-checked when opened.
AI reads the evidence for each attribute and proposes pass, fail or inconclusive, quoting what it relied on.
Every fail becomes an exception to evaluate for severity and root cause, then an issue with an owner and a date.
Review notes by section, responses, clearance. The reviewer can never be the preparer.
Two named sign-offs, then a locked workpaper in PDF and Excel with its own audit trail.
Principles, enforced in code
An auditor accepts the result or overrides it. Nothing signs itself off, because a conclusion you cannot explain to a reviewer, or to an inspector, is not a conclusion.
A pass must name the evidence it rests on. If the AI cites nothing, or quotes text that is not in the file, its pass is downgraded automatically. An auditor cannot record a pass without linking evidence either.
The population is hashed and the seed is stored. Anyone can reproduce the selection exactly, and the workpaper re-checks it every time it is printed.
An append-only, hash-chained audit trail covers uploads, AI proposals, decisions, overrides and sign-offs. Edit one row and the chain breaks.
AI, your way
Your administrator chooses. Two safeguards come as standard: a switch that blocks every call leaving your network, which IT can lock on at deployment, and a full manual mode.
Best at reading screenshots, scanned approvals and tables. Uses your own API key and contract, so evidence goes from your server to Anthropic and never through us.
Any OpenAI-compatible server on your network, such as Ollama or vLLM. Nothing leaves your infrastructure.
No AI at all. The entire workflow, from walkthrough to sign-off, still works.
Coverage
GRC built in
Deployment
Choose a dedicated hosted instance with its own database, or install the same software on your own servers. Either way, your evidence never shares a database with another firm's.