AI & ML-native audit infrastructure

We don't bolt AI onto audit.
We engineer it into the core.

AuditPro Core is a multi-tenant assurance platform built from the database up around explainable machine intelligence — predictive risk scoring, procurement anomaly detection and rule-based NLP drafters that turn raw findings into board-ready evidence. Every model is glass-box: every score is a published formula, every flag links back to the transaction that triggered it.

Already onboarded? Sign in to your workspace

Explainable by designSOC 2 · ISO 27001POPIA-ready · SA-hostedTamper-evident ledger
audgov.com · ai-engine · risk-pipeline
findings.predict(focus_area="SCM")
AGSA repeat-finding probabilityHIGH · 0.81
weights: repeat_rate 0.4 · overdue 0.35 · severity 0.25 — published formula
anomaly.scan(contracts)
Benford χ² deviation3 vendors flagged
Split-PO cluster (R500k)2 sequences
Vendor concentration1 over 40%
every flag → drill-down to source transaction

Built for organisations preparing for Auditor-General review

MunicipalitiesState-Owned EntitiesNational & Provincial DeptsPublic EntitiesUniversities

Grounded in the auditing canon

The principles every auditor is trained on — engineered into software.

AuditPro Core is not a generic workflow tool with an audit skin. Its data model, controls and intelligence layer are built directly on the methodology taught in the profession's foundational texts — Arens' Auditing & Assurance Services, Montgomery's Auditingand Whittington & Pany's Principles of Auditing. Below is the universal audit pipeline those three pillars share — and exactly how the platform operationalises each phase.

Phase 01

Pre-Fieldwork

The canon

Professional ethics, legal liability, client acceptance and independence.

How AuditPro Core solves it

Conflict-of-interest and gift registers, engagement-acceptance workflows and an independence trail are first-class records — so the auditor's mindset of prudence and skepticism is enforced before a single test is run.

Phase 02

Planning

The canon

Setting materiality, assessing inherent risk and mapping internal controls (the Audit Risk Model: AR = IR × CR × DR).

How AuditPro Core solves it

Predictive risk scoring assesses inherent and control risk over the tenant's own history, derives the required detection risk, and tailors the audit programme automatically. Materiality and sample sizes are calculated, not guessed.

Phase 03

Testing

The canon

Tests of controls vs. substantive procedures — vouching, tracing and the eight types of audit evidence.

How AuditPro Core solves it

Statistical and monetary-unit sampling, full-population analytics and procurement anomaly detection (Benford's Law, split-PO, vendor concentration) execute the substantive work. Every flag drills back to the source transaction.

Phase 04

Conclusion

The canon

Evaluating misstatements, assessing going concern and formulating the final audit opinion.

How AuditPro Core solves it

Findings roll up against materiality with a tamper-evident evidence chain behind every conclusion, and rule-based NLP drafts board-ready management reports — so the opinion is defensible to the cent.

The three pillars of the auditing literature, built in

Arens — Auditing & Assurance Services

The Audit Risk Model & the transaction-cycle approach.

Sales-&-collection, acquisition-&-payment, payroll, inventory and capital cycles are modelled as interconnected evidence, with SOX-style dual assurance over financial data and internal control.

Montgomery's Auditing

Professional prudence, skepticism & forensic foundations.

The auditor's defensive mindset, exhaustive balance-sheet verification and classic fraud-vulnerability points are encoded as controls, reconciliations and anomaly detection.

Whittington & Pany — Principles of Auditing

COSO, sampling theory & other-assurance services.

The five COSO components, attribute and monetary-unit sampling, and the expansion into attestation, IT-system reliability and ESG assurance all map to dedicated modules.

The intelligence layer

Machine intelligence that an auditor can defend.

In assurance, a black box is worthless — if you can't explain the score, you can't put it in a working paper. So we built our AI/ML stack around explainability first: heuristic and statistical models over the tenant's own data, every output reproducible and traceable to source.

Predictive

AGSA Findings Predictive Model

Risk scoring per AGSA focus area — a weighted, published blend of repeat-finding rate, overdue remediation and critical severity over the tenant's own historical findings. Outputs a probability band per area with a written rationale, so internal audit can target effort before the AG arrives.

Forensic

Procurement Anomaly Detection

Benford's-law goodness-of-fit on contract values, vendor-concentration analysis, and split-PO detection across the single-quotation threshold. Reproducible math, not a mystery — every anomaly links back to the contracts that triggered it.

Rule-based NLP Audit-Brief Composer

Paste a finding; the deterministic composer classifies root cause, returns applicable PFMA sections, draft AGSA wording and a management response. Every working paper starts at 80% — drafted by an explainable rule engine, not an opaque LLM.

Management-Report Auto-Drafter

Ingest the AGSA management report (PDF/Word); NLP extracts and classifies findings by root cause, pre-populates action plans with owners and deadlines, and tracks closure against the repeat-finding definition.

Continuous Monitoring & Anomaly Alerts

Automated analytics monitors run on a schedule across transactions, raising exception alerts the moment data crosses a defined boundary — turning point-in-time audit into a live signal.

How a data point becomes a defensible signal

01
Ingest
Per-tenant data, isolated and encrypted at rest.
02
Normalise
Mapped to the framework-aware evidence model.
03
Score
Heuristic + statistical models with published weights.
04
Explain
Every output carries its rationale and source links.
05
Monitor
Re-run on schedule; drift surfaces as alerts.

On the roadmap.Today's models are deliberately explainable heuristics and statistics over your own data. We are extending the pipeline toward trained ML classifiers and retrieval-grounded copilots — shipped only once they meet the same bar: reproducible, auditable, and traceable to source.

Built in-house, end to end

Engineering, not assembly.

AuditPro Core is one codebase, designed and developed as a single system — a typed .NET domain core, a server-rendered Next.js front end, and an intelligence layer that shares the same evidence model. No stitched-together SaaS; no data leaving the tenant boundary to be scored.

Domain-driven core

A rich .NET domain layer — entities, invariants and value objects — so business rules live in code, not in scattered SQL.

Typed API surface

Minimal-API endpoints with enum-as-integer contracts and a single source of truth shared with the typed front end.

Tested & gated

Module-registry integrity tests, tenant-gating contracts and CI checks keep every release auditable and regression-safe.

Multi-tenant isolation

Tenant identity flows from the database through the API to the session and the menu — one boundary, enforced everywhere.

.NET 8Entity Framework CoreSQL ServerNext.jsReactTypeScriptNextAuthArgon2idTailwindCaddy + Docker

Platform

One auditable record. Intelligence everywhere on top of it.

Assurance

Plan, sample, test and evidence every audit against ISSAI and internal charters — working papers, CAATs, findings and recommendations.

Governance & Ethics

Conflict-of-interest and gift registers, committee charters and King IV disclosures, all in one place.

Finance & Operations

Reconcile the fixed-asset register, run reporting engines and evidence statutory compliance end to end.

Performance

Track delivery targets and performance indicators against audited evidence with variance analysis.

Risk & Irregularities

Log irregular expenditure, manage the risk register with traceable owners, and run escalation workflows.

Live Compliance Cockpit

One real-time screen of findings, expenditure pipelines and deviations — each tile mapped to its source.

Architecture & trust

One evidence trail. Every framework. Your data, never elsewhere.

The audit plan, working papers, findings and disclosures live in the same tamper-evident ledger. Every action is time-stamped, every document hashed, every decision traceable — and the AI runs inside that boundary, scoring your data where it lives.

Tamper-evident audit log — a cryptographic chain across every finding, evidence file and sign-off.
Multi-tenant by default — one parent department, many child tenants, one consolidated view.
Framework-aware — controls mapped to ISSAI, MFMA, PFMA, GRAP, King IV and Treasury directives.
SA data residency — encrypted at rest, session audit-logged, POPIA and ISO 27001 controls.
Presentation
Next.js · React · server-rendered, role-aware
Intelligence
Explainable scoring · anomaly detection · NLP
Application / API
.NET 8 minimal APIs · typed contracts · auth
Domain core
Entities · invariants · framework mapping
Data + ledger
SQL Server · per-tenant · tamper-evident log
100%

Explainable models — every score is a published formula, not a black box

5

Public-sector tenant archetypes supported, from municipalities to universities

1

Unified evidence ledger feeding assurance, governance and the AI engine

24/7

Continuous monitors raising anomaly alerts as data crosses defined limits

Want to know more?

Tell us about your entity and we'll be in touch with a walkthrough, pricing and next steps — everything you see is traceable to source.