SOX control testing and GRC

Assurance you can prove.

Audit Executive tests ITGC, ITAC, business and HR controls end to end. The AI reads the evidence and proposes a result. Your auditors decide. Every conclusion traces back to a document, a seed and a named person.

Hosted for you in a dedicated instance, or installed on your own servers.

ITGC-AC-01 · Item #7 · Attribute APASS

Access was approved by the user's line manager before it was granted.

AI proposal · pass

Ticket shows manager approval on 03 Mar at 10:14. Provisioning log shows the role granted on 03 Mar at 16:52, after approval.

SR-10442.pdf · page 1 QUOTE FOUNDApproved by R. Mehta (Line Manager) 03-Mar-2026 10:14
Auditor decision
Accepted by A. Kapoor · 14 Apr 2026, 11:02

Why it exists

For years SOX testing has been done by hand.

Screenshots pasted into Word. A sample picked in Excel, and months later nobody could say how. Evidence in a folder that did not match the sample. Then review comments, and half of it again.

Audit Executive replaces that with one workflow where every step leaves proof.

How it works

Population to workpaper, in one place.

  1. 01

    Walkthrough

    AI drafts the questions from the control, its attributes and its risks. The control owner answers in their portal. You conclude on design.

  2. 02

    Population

    Upload the system report. It is hashed on arrival, with the source and completeness checks recorded next to it.

  3. 03

    Sampling

    Size follows frequency and risk. Items are drawn from a stored seed, so anyone can re-draw the same selection.

  4. 04

    Evidence

    Request it from the owner or upload it yourself. Every file is hashed, linked to its sample item, and re-checked when opened.

  5. 05

    Testing

    AI reads the evidence for each attribute and proposes pass, fail or inconclusive, quoting what it relied on.

  6. 06

    Exceptions

    Every fail becomes an exception to evaluate for severity and root cause, then an issue with an owner and a date.

  7. 07

    Quality review

    Review notes by section, responses, clearance. The reviewer can never be the preparer.

  8. 08

    Sign-off and workpaper

    Two named sign-offs, then a locked workpaper in PDF and Excel with its own audit trail.

Principles, enforced in code

The AI reads the evidence and tests each attribute. Then it stops.

An auditor accepts the result or overrides it. Nothing signs itself off, because a conclusion you cannot explain to a reviewer, or to an inspector, is not a conclusion.

No evidence, no pass.

A pass must name the evidence it rests on. If the AI cites nothing, or quotes text that is not in the file, its pass is downgraded automatically. An auditor cannot record a pass without linking evidence either.

Every sample re-draws from its seed.

The population is hashed and the seed is stored. Anyone can reproduce the selection exactly, and the workpaper re-checks it every time it is printed.

Every action is on the record.

An append-only, hash-chained audit trail covers uploads, AI proposals, decisions, overrides and sign-offs. Edit one row and the chain breaks.

AI, your way

Pick where the model runs. Or run without one.

Your administrator chooses. Two safeguards come as standard: a switch that blocks every call leaving your network, which IT can lock on at deployment, and a full manual mode.

Claude API

Best at reading screenshots, scanned approvals and tables. Uses your own API key and contract, so evidence goes from your server to Anthropic and never through us.

Local model

Any OpenAI-compatible server on your network, such as Ollama or vLLM. Nothing leaves your infrastructure.

Manual mode

No AI at all. The entire workflow, from walkthrough to sign-off, still works.

Coverage

Every control type in a SOX programme.

ITGC
Access, change management, IT operations, program development
ITAC
Automated matches, calculations, edit checks, interfaces
Business
Procure to pay, order to cash, record to report, treasury
HR
Joiners and leavers, payroll changes, headcount reconciliations

GRC built in

The register and the testing, in one system.

  • Control library with testing attributes, owners, systems and key-control flags
  • Risk register with a likelihood and impact heat map, mapped to controls, with coverage gaps flagged
  • Issues and remediation with action plans, owners and due dates, linked back to the failing test
  • Control owner portal for walkthrough answers and evidence requests
  • Dashboards for testing progress, open deficiencies and how often auditors override the AI

Deployment

Your instance, your data.

Choose a dedicated hosted instance with its own database, or install the same software on your own servers. Either way, your evidence never shares a database with another firm's.

  • ✓Hosted: a dedicated instance and database, never shared. Self-hosted: one Docker Compose file
  • ✓Evidence stored in your instance only, hashed on upload, verified on every open
  • ✓No calls home. No telemetry. Works in air-gapped networks with a local model
  • ✓Role-based access for admins, managers, auditors, control owners and viewers