Live for SOX ITGC & Cloud Security — or bring your own audit program

The audit agent that shows its work

Prufing tests every control against your evidence, cites the exact line it relied on, and holds every verdict as a draft until you sign it. You review results — not chase documents.

A Prufing engagement dashboard: coverage, exceptions, and review status for a SOX ITGC audit, with every finding awaiting auditor review. The risk and control matrix mid-run: verdicts accumulating across controls. A drafted exception with its cited evidence and Accept, Override and Send back buttons. A cited spreadsheet opened in the app: the Terminations sheet with the cited row highlighted. The exported engagement workpaper with its summary and Draft — not for reliance banner. The downloadable Excel workpaper: a Conclusions sheet with one row per test — control, attribute, status, rationale, and cited excerpt columns.
571
controls in catalog
1028
tests the agent runs
100%
of findings cited to evidence
0
verdicts auto-accepted

Process

How an audit runs

  1. Load the evidence

    Upload policies, exports, tickets, and access reviews. Prufing indexes every page so nothing gets tested against thin air.

    The Evidence tab of a Prufing engagement: uploaded exports and access reviews, every file indexed and available to the agent.
  2. Tally tests the controls

    The agent works the control matrix — reads the procedure, samples your evidence, and drafts a verdict for every test in scope.

    The risk and control matrix mid-run: deficiencies and in-testing statuses accumulating across Access Management controls.
  3. You review, accept, or override

    Every verdict arrives with the cited passage it rests on. Agree, override with a note, or send it back — the auditor stays in charge.

    A drafted exception on a leaver de-provisioning test: the finding, the cited evidence quoted from two files, and Accept, Override and Send back buttons.
  4. Export the workpapers

    Signed conclusions, evidence trail, and activity log leave the system the way reviewers expect to receive them.

    The engagement workpaper: summary counts, cited conclusions, and a Draft — not for reliance banner until an auditor signs.
How Prufing works a control test A control is selected, its evidence is searched, the agent cites the exact row it relied on, records an exception, and holds it as a draft until an auditor signs. CONTROL AM-09 Periodic user access review EVIDENCE IN THIS WORKSPACE mfa_enrolment_report.csv user_access_review_q3.csv match terminated_users_2025.csv CITED reviewer_role: Head of HR | users_in_scope: 34 | users_reviewed: 2 Exception 2 of 34 accounts reviewed Draft — nothing counts until you sign it
Illustration of one test. Timings are indicative.

Product

What you get

CIT-01

Citations down to the line

Every finding links to the exact passage in your evidence that supports it. No orphan conclusions.

MTX-02

A control matrix that fills itself

Scope once; watch coverage, exceptions, and review status accumulate across every domain.

HIL-03

Human-in-the-loop by design

Nothing is auto-accepted. A verdict is a draft until an auditor signs it — and the log remembers who signed what.

EVD-04

The original evidence, retained

The real PDF, spreadsheet, or Word file the agent cited stays attached — and renders right in the app.

Workpapers

It ends in a workpaper, not a chat log.

Every engagement exports as an Excel workbook and a matching report: the conclusion for each test, the steps taken against every requirement, and every quote pinned to the file and line it came from — so a reviewer can re-perform the work, not take our word for it.

Steps taken one row per requirement, per conclusion
Control Requirement Found Quote Source
AM-08 Access revoked within 5 business days of termination Met “Access Revoked: YES — 2025-04-16” terminations.xlsx · line 12
AM-02 Minimum password length of 12 or more enforced Met “minimum_password_length = 14” idp_settings.json · line 61
AM-09 Reviewer sign-off present for the quarter Violated “Sign-off: — (blank)” q2_access_review.xlsx · line 4

The originals stay attached, too — click a citation and the spreadsheet it came from opens in the app, on the cited row. And when the agent can’t ground a step in your evidence, the cell stays blank and the finding says so. No invented citations.

Your program

Bring your own framework.

Most audit teams don’t run a textbook framework. They run the program they have refined over years — in a Word document, a spreadsheet, a PDF from the last engagement. Prufing takes that file and turns it into something the agent can actually test. Adopting your own program is an upload, not a project.

  1. 01 Upload

    The Word doc or control matrix you run today.

  2. 02 Parse

    Read into domains, controls and tests.

  3. 03 Refine

    Close the gaps in conversation, not a form.

  4. 04 Publish

    Testable, then live on an engagement.

Difference

An agent that performs the test — not a workflow tool with AI added.

Legacy GRC platforms were designed as forms, tasks, and reminders: software for tracking whether a human did the audit. AI arrived later and was bolted to the side — summarize this document, draft that policy. The testing itself never moved. Prufing starts at the other end. The agent does the test; the workflow exists so you can review what it concluded.

Workflow tool with AI features Prufing
Unit of work Workflow tool with AI featuresA task with a due date. PrufingA test run against your evidence.
Where the AI sits Workflow tool with AI featuresBeside it — summarize, draft, chat. PrufingInside it — reads the procedure, reaches the verdict.
A verdict is Workflow tool with AI featuresA status someone picks from a dropdown. PrufingA conclusion, quoted to the passage it rests on.
Your job Workflow tool with AI featuresDo the testing, then record that you did. PrufingReview the testing, then sign it — or send it back.

That left column describes a category, not any one vendor. Bring the tool you use today and we’ll run a control side by side with it.

Trust

Built for regulated environments

Workspace isolation

Every engagement is sealed from the next; each request is authorized against membership, not just login.

Evidence is the source of truth

A conclusion the agent can’t trace to a real document is not allowed to pass.

On-prem when you need it

Deploy in your own cloud or air-gapped, bring your own model — evidence never leaves your boundary.

Prove it

Rerun three controls from your last cycle.

Don’t evaluate Prufing on a demo dataset. Evaluate it on work you’ve already concluded — where you know what the right answer was.

  1. 01 Pick

    Three controls from an engagement you have already signed — including one that found an exception.

  2. 02 Rerun

    Upload the same evidence. The agent tests them the way it would on a live engagement.

  3. 03 Compare

    Put its workpaper next to yours, quote by quote. Agreement saves you the hours; disagreement shows you exactly where, cited to the line.