Complete AI Training
Sign inGet my AI kit

Your job's AI kit

Get your AI kit

Tell us who you are and what you do. We show you your kit right away and email you the link: skills, prompts, AI agents, MCP servers and courses for your job.

500+ jobs ready, and we make a kit for any other job. No payment needed to look.

Share

AI agent for auditors

Audit Program Draft Agent

A complete audit program where every in-scope risk has a control and a test

Audit Program Draft Agent: what goes in, what the agent does and what you get

What it does

Each audit needs a program of risks, controls and tests, and writing one per engagement is slow and lets gaps slip. This agent takes the audit scope and the relevant framework and lists the in-scope risks. It maps each risk to the expected controls and writes a test for each control, with the evidence needed and a sample approach. It then checks that every risk has at least one control and test. Where a risk has no matching control, it flags a possible control gap to investigate. It compares with prior audits to reuse tests that worked and to note past findings. It sets sample sizes from your methodology. You approve the program before fieldwork. Edge case: a control the client claims exists but has no owner is marked for existence testing first.

How it works

Follow the arrows from top to bottom. The orange dashed arrow is the loop: when a check fails, the agent goes back and tries again.

Start and resultWhat it doesA check on its own workWaits for your OKGoes back and retries
Yes, continueApprovedNo 1 STARTS WHEN Audit planning begins 2 USES A TOOL Read the audit scope, framework and prior auditfiles 3 DOES List in-scope risks 4 DOES Map controls to each risk and draft a test for each 5 CHECKS THE RESULT Does every risk have a control and a test? If not: flag uncovered risks as possible control gaps.Back to step 4. 6 DOES Reuse tests that worked and note prior findings 7 DOES Set sample sizes from the methodology 8 YOU APPROVE Lead auditor approves the program 9 RESULT Audit program ready for fieldwork
Read the steps as a list
  1. Audit planning begins
  2. Read the audit scope, framework and prior audit files
  3. List in-scope risks
  4. Map controls to each risk and draft a test for each
  5. Does every risk have a control and a test?If not: flag uncovered risks as possible control gaps. Back to step 4.
  6. Reuse tests that worked and note prior findings
  7. Set sample sizes from the methodology
  8. Lead auditor approves the programThe agent waits here for your OK.
  9. Audit program ready for fieldwork

How it decides

It requires every in-scope risk to map to a control and a test, and flags risks with no control as potential gaps.

  • Require a control and test per risk
  • Flag risks with no control as gaps
  • Test control existence before effectiveness when ownership is unclear

Make it yours

Every agent is a starting point. You choose these settings for your own situation.

  • Frameworks used
  • Risk library
  • Sample size rules
  • Program format

What keeps you in control

It always asks you first

  • Approving the audit program

Hard limits

  • Does not perform the audit without approval
  • Flags gaps rather than assuming controls exist

It stops when

  • Done: program complete and approved
  • Stop: audit scope is not defined

Set it up

We guide you through the set-up, step by step

Members get the full set-up guide for this agent. No technical skills needed: you copy, paste and upload.

10 minto set it up in your AI
5 AIsChatGPT, Claude, Copilot, Gemini, Grok
  • One set of instructions to paste into your AI, with the clicks for ChatGPT, Claude, Microsoft 365 Copilot, Gemini and Grok
  • The agent then walks you through connecting your own data, one source at a time
  • A downloadable copy with the flow chart, the rules and the full guide
Get access to this agent

An example run

What happensPlanning an access management audit at Greenhollow University in January, the agent mapped controls to 14 risks. The coverage check failed for orphaned accounts: no documented control. It flagged a possible control gap. It set a sample of 25 user accounts for the access review test and reused last year's termination test. The lead auditor approved the program on January 20.

More agents for auditors