Your program
Bring your own framework.
Most audit teams don’t run a textbook framework. They run the program they have refined over years — in a Word document, a spreadsheet, a PDF from the last engagement. Prufing takes that file and turns it into something the agent can actually test. Adopting your own program is an upload, not a project.
Prufing is in a closed beta — you’ll be asked for your work email, and if we haven’t opened access to you yet you can join the list from there.
From a document to a testable program
Four stages. Click through them — the panel shows where each one happens.
AMAccess Management3 controls-
AM-01Access is approved before it is provisioned3 tests - Sample 25 joiners; confirm the documented approval predates the account-creation date.
-
AM-02Access is revoked on exit2 tests -
AM-03Privileged access is reviewed quarterlyno expected result
YouAM-03 passes only if every account flagged in the review is remediated before the next one.
TallyRecorded as the expected result for AM-03 — it’s testable now. Two controls elsewhere are still missing a procedure.
What teams ask first
What if the document is messy?
Most are. The parse is conservative by design — it will not invent a procedure or an expected result to make a control look complete. Anything it cannot test comes back flagged with the reason, and you close those gaps in conversation rather than in a form.
Who owns the program?
You do. An imported program belongs to your organisation, and it stays private unless you choose to list it. Duplicating a shipped catalog works the same way — you get your own copy to edit, and ours keeps updating separately.
Can I start from one of yours instead?
Yes. Duplicate any shipped catalog and edit it — most teams want SOX ITGC or ISO 27001 with their own house wording, not a blank page. The import path and the duplicate path produce the same thing: a program you control.
What does a reviewer see?
Each engagement records which program it ran, who published it, and when. Listing a program in the shared catalog does not mean Prufing has reviewed it, and the app says so where it matters — provenance is recorded so the reader can judge the source themselves.
The programs Prufing publishes and the programs customers publish sit in the same catalog. Each engagement records which program it ran, who published it, and when — because “where did this control come from” is the first question a reviewer asks.