Internal Audit Agent

The Internal Audit Agent samples purchase orders, expense claims, journals and payments, and verifies each approval against your delegation of authority. It flags control violations, including irregular or fruitless and wasteful expenditure in PFMA and MFMA entities, and generates audit-ready working papers so your team can focus on risk assessment and recommendations.

Ideal forInternal audit teams

The difference

From 3-4 weeks per audit to 2-3 days

Your audit team completes more of the plan each year and spends its time on root causes and recommendations.

Done by hand

3-4 weeks per audit

With the Vanine agent

2-3 days

Time returned to your team

90%

Indicative figures. We measure your own baseline in the first fortnight so the numbers you see are yours.

Stretched teams, wider coverage

Internal audit functions in banks, insurers, SOEs and departments are under pressure to cover more with the same people. The agent takes on sampling and testing so auditors focus on judgement.

Working papers that stand up

Every finding links to its source transaction, producing working papers that meet IIA Standards and support combined assurance reporting to the audit committee.

From periodic to continuous

Instead of waiting for the next audit cycle, you can test transactions as they occur and raise issues early.

Capabilities

Test more transactions, find more exceptions, draft working papers faster.

Built for internal audit functions in corporates, banks, insurers, SOEs and government departments, and for co-sourced internal audit providers.

Automated transaction sampling

Samples purchase orders, expense claims, journals and payments from systems such as SAP, Sage or Syspro using statistical or risk-based selection for representative coverage.

Approval chain verification

Traces each transaction through its approval workflow, verifying that required approvals were obtained, approvers had the right authority and the sequence followed policy.

Delegation of authority validation

Cross-references amounts and transaction types against your delegation of authority framework, flagging approvals beyond delegated limits and segregation of duties conflicts.

Exception identification

Detects missing or backdated approvals, duplicate payments, policy breaches and unusual patterns, including irregular or fruitless and wasteful expenditure in PFMA and MFMA entities.

Audit trail documentation

Produces working papers with citations linking each finding to the source transaction, meeting IIA Standards and supporting combined assurance reporting to the audit committee.

Continuous monitoring capability

Moves you from periodic sampling to continuous control monitoring, testing transactions as they occur and giving early warning of emerging issues.

How it works

From your systems to a result you sign off

Findings and working papers land ready for review, and sign-off stays with the engagement or audit lead.

SAPSageDynamics 365OracleSharePointTeams
Any system you use
Connects

Connect the places your audit files already live.

Transaction extracts and approval records from your ERP, your delegation of authority framework and supporting documents in SharePoint. Already use something else? We connect that too.

  • OpenAI Frontier
  • Microsoft 365 (SharePoint, Teams, Excel)
  • Copilot Studio
  • SAP, Sage, Syspro, Oracle, Dynamics 365
  • TeamMate+, CaseWare
  • Your own AI platform or models
Works in

Runs per audit engagement or on a continuous monitoring schedule, with auditors directing it in Teams or OpenAI Frontier.

Automated transaction sampling
Approval chain verification
Delegation of authority validation
Exception identification
Audit trail documentation
Continuous monitoring capability
Delivers to

Draft working papers and exception schedules imported into TeamMate+ or CaseWare, with summaries in Excel for the audit committee.

Step by step

  1. 01

    The audit engagement starts or the monitoring cycle runs.

  2. 02

    The agent extracts and samples transactions from your ERP.

  3. 03

    It verifies approvals against your delegation of authority and flags exceptions.

  4. 04

    It drafts working papers with every finding linked to source.

  5. 05

    The audit lead reviews the findings and signs off the working papers.

Deployment

Runs inside the tools your team already uses

The same agent and the same cited output, delivered three ways: through the AI assistant you have rolled out, on a model you host yourself, or inside your own software.

Model Context Protocol

In the frontier assistant you already pay for

We publish the agent as an MCP server. Add it as a connector and your team calls it from the chat they use every day, with no new tool to learn.

Adopting frontier AI across your teams
Called from ClaudeMCP connected

"Test all Q3 payments over R100,000"

Toolinternal_audit.sample_transactions
quarter
2026-Q3
framework
DoA v9
Returned1,904 payments testedEvery finding linked to its source document
Self-hosted

On a model you host yourself

Run the agent on open-weight models in your data centre or private cloud. Your audit files never leave your network, which keeps POPIA and data residency straightforward.

  • Llama
  • Mistral
  • Ollama
  • or any OpenAI-compatible endpoint
Sovereign AI on your infrastructure
Bespoke systems

Inside your own software

Trigger a run from your own workflows, and push the finished output into your ERP, GRC or reporting systems. We build the integration with your team.

  • REST API
  • Webhooks
  • Batch jobs
  • Embeddable review panel
Custom integrations from our software factory
Governance

Governed the same way, every route

Whichever way your team reaches the agent, identity, permissions and audit stay with your existing controls.

  • Single sign-on through Entra ID, Okta or Google Workspace
  • Reads only the documents each user is already allowed to open
  • Every tool call written to an audit log you can export
How your data is handled

DATA SECURITY & PRIVACY

Your audit files stay yours.

The agent runs inside your tenancy, reads only what each task needs, and never trains on your audit files. Every step is logged so your auditors can see exactly what it touched.

Built for regulated work.

+
WHAT THE AGENT KEEPSONLY THE OUTPUTENCRYPTED AT REST0 BIT AES0% DELETABLE0 TRAINING RUNS

YOUR AUDIT FILES NEVER LEAVE YOUR ENVIRONMENT

Precision AI for Institutional Workflows

Build once.Deploy across teams.Improve over time.