AI agent for auditors
Compliance Control Testing Sample Agent
A defensible test result for a control, with an expanded sample when problems appear
What it does
A small, hand-picked sample can hide the very failures a control test should find. This agent selects a risk-based sample for a control, weighting higher-value, newer or flagged cases and including a random share. It pulls the evidence for each case from the systems, such as approvals, records and timestamps, and tests it against each step of the control. It records pass, fail or cannot test. When failures exceed the set threshold, it expands the sample, targeting similar cases, and tests again. It repeats until the failure rate is clear. It then drafts findings with examples and the likely cause. The analyst approves findings before they go to the control owner. Edge case: failures cluster in one branch.
How it works
Follow the arrows from top to bottom. The orange dashed arrow is the loop: when a check fails, the agent goes back and tries again.
Read the steps as a list
- Control test is due
- Read the control steps and the case population
- Select a risk-based sample with a random share
- Pull evidence for each sampled case
- Test each case against each control step
- Is the failure rate below the threshold?If not: expand the sample with cases similar to the failures. Back to step 3.
- Retest the expanded sample and group failures by cause
- Is the failure rate stable or is the cause clear?If not: expand again until the pattern is clear or the sample is complete. Back to step 6.
- Draft findings with examples and likely cause
- Analyst approves the findingsThe agent waits here for your OK.
- Control test report
How it decides
Sample size grows when failures exceed the threshold, and expansion focuses on cases similar to the failures.
- Use 60 percent risk-weighted and 40 percent random cases
- Expand when failures exceed 5 percent
- Mark a case cannot test if evidence is missing, and count it
- Group failures by branch, team and period
Make it yours
Every agent is a starting point. You choose these settings for your own situation.
- Sample size (default 40)
- Failure threshold (default 5 percent)
- Random share (default 40 percent)
- Systems used
What keeps you in control
It always asks you first
- Findings sent to the control owner
Hard limits
- Never closes a control as effective without evidence
- Never contacts the control owner before approval
It stops when
- Done: failure rate is clear and findings approved
- Stop: evidence cannot be pulled for over 20 percent of the sample
Set it up
We guide you through the set-up, step by step
Members get the full set-up guide for this agent. No technical skills needed: you copy, paste and upload.
- One set of instructions to paste into your AI, with the clicks for ChatGPT, Claude, Microsoft 365 Copilot, Gemini and Grok
- The agent then walks you through connecting your own data, one source at a time
- A downloadable copy with the flow chart, the rules and the full guide