This is what a purpose-built audit platform looks like. One like it could exist for any practice.
AuditSenior.com is a complete ITGC testing platform, built end-to-end and shown in the open: 37 control templates, enforced 8- and 9-step workflows, deterministic AU-C 530 sampling, evidence-first AI under mandatory auditor review, and a 13-section workpaper export. It exists purely to demonstrate the standard. Nothing on this site is for sale, and nothing here is an offer of services.
Working software, not a slide deck. No audit opinion, assurance, or attestation is issued here — and none is offered. Professional judgment always stays with the licensed auditor.
- 01AI determination shown beside the auditor's disposition — both values, never blended
- 02Evidence filename + SHA-256 — the exact bytes tested, tamper-detectable
- 03Tested + reviewed timestamps, each with the responsible identity
- 04Reproducible sample: method, size, AICPA AU-C 530 basis, deterministic seed
- 05Append-only audit trail the database refuses to mutate
- 01
It enforces the methodology
Every control moves through an 8- or 9-step gated workflow — population, sampling, evidence, AI testing, exceptions, quality review, sign-off. Steps cannot be skipped; no conclusion auto-finalizes.
- 02
It tests with full provenance
AI tests each sample against each control attribute and stores the model used, a confidence score, extracted facts with context, and rationale. Missing evidence returns INCONCLUSIVE — the platform never guesses.
- 03
It produces the workpaper
A 13-section HTML workpaper (print-to-PDF in the browser for archive) plus two CSV side-exports — an Evidence Index with SHA-256 hashes and a Testing Results export. Reviewer-defensible from the file alone.
The capabilities described on this site are implemented in the platform codebase — the exhibits render a clearly-labeled simulated engagement mirroring the real output structures.
- 37
- ITGC control templates control-templates.ts
- 80%
- Minimum coverage to lock a control workflow-gates.ts
- 8·9
- Steps per control WORKFLOW_STEP_COUNTS
- 13
- Workpaper sections per export + 2 CSV side-exports
Deterministic, SHA-256-seeded sampling means a drawn sample can be reconstructed from its stored seed. Quality review runs 6 control-level checks plus 25 per-sample data-integrity check types — self-approval, segregation-of-duties, post-termination activity, SLA-breach detection. Explore the platform →
A control cannot lock until every gate passes
Thirteen hard blockers stand between a draft and a signed control — the ten central gates listed here, plus the coverage floor, the evidence rule, and a confirmed exceptions review. Hard blockers are separated from informational warnings; no conclusion auto-finalizes, and the auditor is always the authoritative gate. This is what “the methodology is enforced by the software” means in practice.
- GATE 01Testing complete
- GATE 02Quality review run
- GATE 03Critical QC findings acknowledged
- GATE 04High QC findings acknowledged
- GATE 05All AI results reviewed
- GATE 06Every attribute tested
- GATE 07No rejected AI results outstanding
- GATE 08Exceptions closed or accepted
- GATE 09SLA-overdue critical/high exceptions resolved
- GATE 10Change-control traceability complete
Locked until every gate passes
Plus the 80% testing-coverage floor, a no-PASS-without-evidence rule, and a confirmed exceptions review. The auditor concludes and signs.
No conclusion auto-finalizes. The judgment stays with the auditor.
Practice-shaped audit software is possible. This build is the proof.
Everything on this site — workflow gates, deterministic reproducible sampling, evidence-first AI with mandatory human review, append-only audit trails, database-level tenant isolation — is architecture, not ITGC-specific magic. A platform on the same foundations could exist for any audit or assurance practice: its own control framework, its own evidence model, its own quality gates and sign-off discipline. This site demonstrates that standard; what any practice does with the idea is its own decision.
A demonstration, not a promise: the ITGC platform shown here is the only reference build shipped to date. It carries no compliance or certification guarantee, and this site offers no services of any kind.
Three ways into the build
The platform tour
The provenance model, the methodology engine, and exhibits that render a simulated engagement mirroring the real output structures.
Inside the platformThe capability catalog
All 37 control templates across four categories, the deliverables, the AI-testing rules, and the gates that keep the methodology defensible.
Every capabilityThe security architecture
Engine-enforced tenant isolation, SHA-256 evidence integrity, an append-only audit trail, and the exact sub-processors that deliver the platform.
How data is handledCurious about the build?
Walk the provenance model and the exhibits, or send the builders a question about the project. Messages create no engagement and no obligation — on either side.