Your program
Bring your own framework.
Most audit teams don’t run a textbook framework. They run the program they have refined over years — in a Word document, a spreadsheet, a PDF from the last engagement. Prufing takes that file and turns it into something the agent can actually test. Adopting your own program is an upload, not a project.
Prufing is in a closed beta — you’ll be asked for your work email, and if we haven’t opened access to you yet you can join the list from there.
From a document to a testable program
- 01 Upload
Hand over the program you already run
The audit program as it exists today — a Word document, an Excel control matrix, a PDF handed down by your parent company or your regulator. PDF, .docx, .xlsx, .csv or text, up to 20 MB. You don’t retype it into someone else’s schema.
- 02 Parse
The agent reads it into structure
Prufing pulls out the domains, the controls under each one, and the tests under each control — objective, procedure, expected result, suggested sample. What it won’t do is fill in the parts your document never said: a control that arrives without a procedure or an expected result comes back flagged as untestable, with the reason.
- 03 Refine
Close the gaps by talking to it
Ask the agent what’s thin and it lists the controls that can’t be tested yet, and why. Fix them in the conversation: split a control, tighten a procedure, add the sampling rule your methodology requires. No form builder, no CSV round-trip.
- 04 Publish
Put it to work, then share it
An imported program stays a draft until it is testable — every control in scope carrying a procedure and an expected result. Published, it can run an engagement. Listed in the shared catalog, any team can duplicate it as their own starting point.
AMAccess Management3 controls-
AM-01Access is approved before it is provisioned3 tests - Sample 25 joiners; confirm the documented approval predates the account-creation date.
-
AM-02Access is revoked on exit2 tests -
AM-03Privileged access is reviewed quarterlyno expected result
YouAM-03 passes only if every account flagged in the review is remediated before the next one.
TallyRecorded as the expected result for AM-03 — it’s testable now. Two controls elsewhere are still missing a procedure.
What teams ask first
- What if the document is messy?
- Most are. The parse is conservative by design — it will not invent a procedure or an expected result to make a control look complete. Anything it cannot test comes back flagged with the reason, and you close those gaps in conversation rather than in a form.
- Who owns the program?
- You do. An imported program belongs to your organisation, and it stays private unless you choose to list it. Duplicating a shipped catalog works the same way — you get your own copy to edit, and ours keeps updating separately.
- Can I start from one of yours instead?
- Yes. Duplicate any shipped catalog and edit it — most teams want SOX ITGC or ISO 27001 with their own house wording, not a blank page. The import path and the duplicate path produce the same thing: a program you control.
- What does a reviewer see?
- Each engagement records which program it ran, who published it, and when. Listing a program in the shared catalog does not mean Prufing has reviewed it, and the app says so where it matters — provenance is recorded so the reader can judge the source themselves.
The programs Prufing publishes and the programs customers publish sit in the same catalog. Each engagement records which program it ran, who published it, and when — because “where did this control come from” is the first question a reviewer asks.