Skip to main content
A working showcase of audit automation

This is what a purpose-built audit platform looks like. One like it could exist for any practice.

AuditSenior.com is a complete ITGC testing platform, built end-to-end and shown in the open: 37 control templates, enforced 8- and 9-step workflows, deterministic AU-C 530 sampling, evidence-first AI under mandatory auditor review, and a 13-section workpaper export. It exists purely to demonstrate the standard. Nothing on this site is for sale, and nothing here is an offer of services.

Working software, not a slide deck. No audit opinion, assurance, or attestation is issued here — and none is offered. Professional judgment always stays with the licensed auditor.

FIG. 01What every test carries into the workpaper
  • 01AI determination shown beside the auditor's disposition — both values, never blended
  • 02Evidence filename + SHA-256 — the exact bytes tested, tamper-detectable
  • 03Tested + reviewed timestamps, each with the responsible identity
  • 04Reproducible sample: method, size, AICPA AU-C 530 basis, deterministic seed
  • 05Append-only audit trail the database refuses to mutate
The full provenance model
§ 01   What the reference build does
  1. 01

    It enforces the methodology

    Every control moves through an 8- or 9-step gated workflow — population, sampling, evidence, AI testing, exceptions, quality review, sign-off. Steps cannot be skipped; no conclusion auto-finalizes.

  2. 02

    It tests with full provenance

    AI tests each sample against each control attribute and stores the model used, a confidence score, extracted facts with context, and rationale. Missing evidence returns INCONCLUSIVE — the platform never guesses.

  3. 03

    It produces the workpaper

    A 13-section HTML workpaper (print-to-PDF in the browser for archive) plus two CSV side-exports — an Evidence Index with SHA-256 hashes and a Testing Results export. Reviewer-defensible from the file alone.

The capabilities described on this site are implemented in the platform codebase — the exhibits render a clearly-labeled simulated engagement mirroring the real output structures.

§ 02   The build, in figures
37
ITGC control templates
control-templates.ts
80%
Minimum coverage to lock a control
workflow-gates.ts
8·9
Steps per control
WORKFLOW_STEP_COUNTS
13
Workpaper sections per export
+ 2 CSV side-exports

Deterministic, SHA-256-seeded sampling means a drawn sample can be reconstructed from its stored seed. Quality review runs 6 control-level checks plus 25 per-sample data-integrity check types — self-approval, segregation-of-duties, post-termination activity, SLA-breach detection. Explore the platform →

§ 03   The sign-off lock

A control cannot lock until every gate passes

Thirteen hard blockers stand between a draft and a signed control — the ten central gates listed here, plus the coverage floor, the evidence rule, and a confirmed exceptions review. Hard blockers are separated from informational warnings; no conclusion auto-finalizes, and the auditor is always the authoritative gate. This is what “the methodology is enforced by the software” means in practice.

  1. GATE 01Testing complete
  2. GATE 02Quality review run
  3. GATE 03Critical QC findings acknowledged
  4. GATE 04High QC findings acknowledged
  5. GATE 05All AI results reviewed
  6. GATE 06Every attribute tested
  7. GATE 07No rejected AI results outstanding
  8. GATE 08Exceptions closed or accepted
  9. GATE 09SLA-overdue critical/high exceptions resolved
  10. GATE 10Change-control traceability complete

Locked until every gate passes

Plus the 80% testing-coverage floor, a no-PASS-without-evidence rule, and a confirmed exceptions review. The auditor concludes and signs.


No conclusion auto-finalizes. The judgment stays with the auditor.


§ 04   The showcase thesis

Practice-shaped audit software is possible. This build is the proof.

Everything on this site — workflow gates, deterministic reproducible sampling, evidence-first AI with mandatory human review, append-only audit trails, database-level tenant isolation — is architecture, not ITGC-specific magic. A platform on the same foundations could exist for any audit or assurance practice: its own control framework, its own evidence model, its own quality gates and sign-off discipline. This site demonstrates that standard; what any practice does with the idea is its own decision.

A demonstration, not a promise: the ITGC platform shown here is the only reference build shipped to date. It carries no compliance or certification guarantee, and this site offers no services of any kind.

§ 05   Explore the showcase

Three ways into the build

01

The platform tour

The provenance model, the methodology engine, and exhibits that render a simulated engagement mirroring the real output structures.

Inside the platform
02

The capability catalog

All 37 control templates across four categories, the deliverables, the AI-testing rules, and the gates that keep the methodology defensible.

Every capability
03

The security architecture

Engine-enforced tenant isolation, SHA-256 evidence integrity, an append-only audit trail, and the exact sub-processors that deliver the platform.

How data is handled

Curious about the build?

Walk the provenance model and the exhibits, or send the builders a question about the project. Messages create no engagement and no obligation — on either side.