Internal Audit Agent
The Internal Audit Agent samples purchase orders, expense claims, journals and payments, and verifies each approval against your delegation of authority. It flags control violations, including irregular or fruitless and wasteful expenditure in PFMA and MFMA entities, and generates audit-ready working papers so your team can focus on risk assessment and recommendations.
Ideal forInternal audit teams
The difference
From 3-4 weeks per audit to 2-3 days
Your audit team completes more of the plan each year and spends its time on root causes and recommendations.
Done by hand
3-4 weeks per audit
With the Vanine agent
2-3 days
Time returned to your team
90%
Indicative figures. We measure your own baseline in the first fortnight so the numbers you see are yours.
Stretched teams, wider coverage
Internal audit functions in banks, insurers, SOEs and departments are under pressure to cover more with the same people. The agent takes on sampling and testing so auditors focus on judgement.
Working papers that stand up
Every finding links to its source transaction, producing working papers that meet IIA Standards and support combined assurance reporting to the audit committee.
From periodic to continuous
Instead of waiting for the next audit cycle, you can test transactions as they occur and raise issues early.
Capabilities
Test more transactions, find more exceptions, draft working papers faster.
Built for internal audit functions in corporates, banks, insurers, SOEs and government departments, and for co-sourced internal audit providers.
Automated transaction sampling
Samples purchase orders, expense claims, journals and payments from systems such as SAP, Sage or Syspro using statistical or risk-based selection for representative coverage.
Approval chain verification
Traces each transaction through its approval workflow, verifying that required approvals were obtained, approvers had the right authority and the sequence followed policy.
Delegation of authority validation
Cross-references amounts and transaction types against your delegation of authority framework, flagging approvals beyond delegated limits and segregation of duties conflicts.
Exception identification
Detects missing or backdated approvals, duplicate payments, policy breaches and unusual patterns, including irregular or fruitless and wasteful expenditure in PFMA and MFMA entities.
Audit trail documentation
Produces working papers with citations linking each finding to the source transaction, meeting IIA Standards and supporting combined assurance reporting to the audit committee.
Continuous monitoring capability
Moves you from periodic sampling to continuous control monitoring, testing transactions as they occur and giving early warning of emerging issues.
How it works
From your systems to a result you sign off
Findings and working papers land ready for review, and sign-off stays with the engagement or audit lead.
Connect the places your audit files already live.
Transaction extracts and approval records from your ERP, your delegation of authority framework and supporting documents in SharePoint. Already use something else? We connect that too.
- OpenAI Frontier
- Microsoft 365 (SharePoint, Teams, Excel)
- Copilot Studio
- SAP, Sage, Syspro, Oracle, Dynamics 365
- TeamMate+, CaseWare
- Your own AI platform or models
Runs per audit engagement or on a continuous monitoring schedule, with auditors directing it in Teams or OpenAI Frontier.
Draft working papers and exception schedules imported into TeamMate+ or CaseWare, with summaries in Excel for the audit committee.
Step by step
- 01
The audit engagement starts or the monitoring cycle runs.
- 02
The agent extracts and samples transactions from your ERP.
- 03
It verifies approvals against your delegation of authority and flags exceptions.
- 04
It drafts working papers with every finding linked to source.
- 05
The audit lead reviews the findings and signs off the working papers.
Deployment
Runs inside the tools your team already uses
The same agent and the same cited output, delivered three ways: through the AI assistant you have rolled out, on a model you host yourself, or inside your own software.
In the frontier assistant you already pay for
We publish the agent as an MCP server. Add it as a connector and your team calls it from the chat they use every day, with no new tool to learn.
"Test all Q3 payments over R100,000"
- quarter
- 2026-Q3
- framework
- DoA v9
On a model you host yourself
Run the agent on open-weight models in your data centre or private cloud. Your audit files never leave your network, which keeps POPIA and data residency straightforward.
- Llama
- Mistral
- Ollama
- or any OpenAI-compatible endpoint
Inside your own software
Trigger a run from your own workflows, and push the finished output into your ERP, GRC or reporting systems. We build the integration with your team.
- REST API
- Webhooks
- Batch jobs
- Embeddable review panel
Governed the same way, every route
Whichever way your team reaches the agent, identity, permissions and audit stay with your existing controls.
- Single sign-on through Entra ID, Okta or Google Workspace
- Reads only the documents each user is already allowed to open
- Every tool call written to an audit log you can export
How we deliver it
One agent, three ways to hold it
Start where your team already works, then take it as far into your systems as the value justifies.
DATA SECURITY & PRIVACY
Your audit files stay yours.
The agent runs inside your tenancy, reads only what each task needs, and never trains on your audit files. Every step is logged so your auditors can see exactly what it touched.
Built for regulated work.
+YOUR AUDIT FILES NEVER LEAVE YOUR ENVIRONMENT
More agents
More agents we build for South African enterprises
Each one is built on the same foundation: your documents, your rules, and your people signing off.
Precision AI for Institutional Workflows


