Your program

Bring your own framework.

Most audit teams don’t run a textbook framework. They run the program they have refined over years — in a Word document, a spreadsheet, a PDF from the last engagement. Prufing takes that file and turns it into something the agent can actually test. Adopting your own program is an upload, not a project.

Prufing is in a closed beta — you’ll be asked for your work email, and if we haven’t opened access to you yet you can join the list from there.

From a document to a testable program

  1. 01 Upload

    Hand over the program you already run

    The audit program as it exists today — a Word document, an Excel control matrix, a PDF handed down by your parent company or your regulator. PDF, .docx, .xlsx, .csv or text, up to 20 MB. You don’t retype it into someone else’s schema.

  2. 02 Parse

    The agent reads it into structure

    Prufing pulls out the domains, the controls under each one, and the tests under each control — objective, procedure, expected result, suggested sample. What it won’t do is fill in the parts your document never said: a control that arrives without a procedure or an expected result comes back flagged as untestable, with the reason.

  3. 03 Refine

    Close the gaps by talking to it

    Ask the agent what’s thin and it lists the controls that can’t be tested yet, and why. Fix them in the conversation: split a control, tighten a procedure, add the sampling rule your methodology requires. No form builder, no CSV round-trip.

  4. 04 Publish

    Put it to work, then share it

    An imported program stays a draft until it is testable — every control in scope carrying a procedure and an expected result. Published, it can run an engagement. Listed in the shared catalog, any team can duplicate it as their own starting point.

Parsed program access-management-program.docx
  • AMAccess Management3 controls
  • AM-01Access is approved before it is provisioned3 tests
  • Sample 25 joiners; confirm the documented approval predates the account-creation date.
  • AM-02Access is revoked on exit2 tests
  • AM-03Privileged access is reviewed quarterlyno expected result

YouAM-03 passes only if every account flagged in the review is remediated before the next one.

TallyRecorded as the expected result for AM-03 — it’s testable now. Two controls elsewhere are still missing a procedure.

Illustration. The parse is yours to correct before anything is tested.

What teams ask first

What if the document is messy?
Most are. The parse is conservative by design — it will not invent a procedure or an expected result to make a control look complete. Anything it cannot test comes back flagged with the reason, and you close those gaps in conversation rather than in a form.
Who owns the program?
You do. An imported program belongs to your organisation, and it stays private unless you choose to list it. Duplicating a shipped catalog works the same way — you get your own copy to edit, and ours keeps updating separately.
Can I start from one of yours instead?
Yes. Duplicate any shipped catalog and edit it — most teams want SOX ITGC or ISO 27001 with their own house wording, not a blank page. The import path and the duplicate path produce the same thing: a program you control.
What does a reviewer see?
Each engagement records which program it ran, who published it, and when. Listing a program in the shared catalog does not mean Prufing has reviewed it, and the app says so where it matters — provenance is recorded so the reader can judge the source themselves.

The programs Prufing publishes and the programs customers publish sit in the same catalog. Each engagement records which program it ran, who published it, and when — because “where did this control come from” is the first question a reviewer asks.