Internal Financial Controls Agent

The Internal Financial Controls Agent collects control evidence, tests design and operating effectiveness, identifies gaps and tracks remediation across your key financial processes. It prepares documentation that supports the CEO and FD responsibility statement under JSE Listings Requirements paragraph 3.84(k) and the combined assurance model under King IV and King V.

Ideal forInternal audit teams

The difference

From 3-4 months to 4-6 weeks

Your finance and internal audit teams reach year-end with evidence already in place, leaving time to fix issues rather than document them.

Done by hand

3-4 months

With the Vanine agent

4-6 weeks

Time returned to your team

80%

Indicative figures. We measure your own baseline in the first fortnight so the numbers you see are yours.

Controls evidenced all year

The 3.84(k) CEO and FD attestation and King V, which applies to financial years starting on or after 1 January 2026, push listed companies and SOEs to evidence controls continuously rather than once a year.

Less document hunting

Gathering evidence from ERPs, approval workflows and logs is the most time-consuming part of controls work. The agent does it automatically and consistently.

Confidence for the audit committee

Assurance-ready workpapers, gap tracking and validated remediation give the audit committee and external auditors a clear, defensible view of control effectiveness.

Capabilities

Continuous evidence for your 3.84(k) statement and combined assurance.

Built for finance and internal audit teams at JSE-listed companies, audit committees, and controllers at SOEs and PFMA entities.

Automated evidence gathering

Collects control evidence from transaction logs, ERP configurations (SAP, Oracle, Dynamics 365, Syspro, Sage), approval workflows and audit trails, removing manual document hunting.

Control effectiveness testing

Tests design and operating effectiveness by analysing transaction samples, exception reports and system access logs against your control objectives and risk and control matrix.

Gap identification and remediation tracking

Identifies control gaps, missing evidence and design deficiencies, then tracks remediation and validates closure with supporting documentation for the audit committee.

Assurance-ready documentation

Produces control testing workpapers and evidence matrices that internal audit, external auditors and the audit committee can use to support the 3.84(k) responsibility statement.

Multi-process coverage

Covers revenue (IFRS 15), procurement and payables, payroll, inventory, VAT and financial reporting, with process-specific control logic.

Continuous monitoring for combined assurance

Monitors control performance through the year and flags emerging risks early, feeding the combined assurance view King expects, including oversight of technology and AI used in reporting.

How it works

From your systems to a result you sign off

Control conclusions and the 3.84(k) responsibility statement remain with management, internal audit and the audit committee. Outputs land ready for their review and sign-off.

SAPSageDynamics 365OracleSharePointTeams
Any system you use
Connects

Connect the places your control evidence already live.

Transaction logs, configurations and access logs from your ERP, approval workflow records, your risk and control matrix, and evidence libraries in SharePoint. Already use something else? We connect that too.

  • OpenAI Frontier
  • Microsoft 365 (SharePoint, Teams, Excel)
  • Copilot Studio
  • SAP, Oracle, Dynamics 365, Syspro, Sage
  • TeamMate+, AuditBoard and GRC platforms
  • ERP audit logs and approval workflows
  • Your own AI platform or models
Works in

Runs on a scheduled monitoring cycle, with your team able to query results and request tests in Teams or OpenAI Frontier.

Automated evidence gathering
Control effectiveness testing
Gap identification and remediation tracking
Assurance-ready documentation
Multi-process coverage
Continuous monitoring for combined assurance
Delivers to

Testing workpapers, evidence matrices and remediation trackers in TeamMate+, AuditBoard or your GRC platform, with summaries for the audit committee.

Step by step

  1. 01

    The monitoring cycle starts, or a control owner requests a test.

  2. 02

    The agent collects evidence from ERPs, workflows and logs.

  3. 03

    It tests design and operating effectiveness against your risk and control matrix.

  4. 04

    It records gaps, tracks remediation and prepares workpapers.

  5. 05

    Internal audit and management review the results and sign off for the audit committee.

Deployment

Runs inside the tools your team already uses

The same agent and the same cited output, delivered three ways: through the AI assistant you have rolled out, on a model you host yourself, or inside your own software.

Model Context Protocol

In the frontier assistant you already pay for

We publish the agent as an MCP server. Add it as a connector and your team calls it from the chat they use every day, with no new tool to learn.

Adopting frontier AI across your teams
Called from ClaudeMCP connected

"Collect evidence for the P2P controls"

Toolinternal_financial_controls.gather_evidence
process
Procure to pay
year
FY2026
Returned38 controls, evidence linkedEvery finding linked to its source document
Self-hosted

On a model you host yourself

Run the agent on open-weight models in your data centre or private cloud. Your control evidence never leave your network, which keeps POPIA and data residency straightforward.

  • Llama
  • Mistral
  • Ollama
  • or any OpenAI-compatible endpoint
Sovereign AI on your infrastructure
Bespoke systems

Inside your own software

Trigger a run from your own workflows, and push the finished output into your ERP, GRC or reporting systems. We build the integration with your team.

  • REST API
  • Webhooks
  • Batch jobs
  • Embeddable review panel
Custom integrations from our software factory
Governance

Governed the same way, every route

Whichever way your team reaches the agent, identity, permissions and audit stay with your existing controls.

  • Single sign-on through Entra ID, Okta or Google Workspace
  • Reads only the documents each user is already allowed to open
  • Every tool call written to an audit log you can export
How your data is handled

DATA SECURITY & PRIVACY

Your control evidence stay yours.

The agent runs inside your tenancy, reads only what each task needs, and never trains on your control evidence. Every step is logged so your auditors can see exactly what it touched.

Built for regulated work.

+
WHAT THE AGENT KEEPSONLY THE OUTPUTENCRYPTED AT REST0 BIT AES0% DELETABLE0 TRAINING RUNS

YOUR CONTROL EVIDENCE NEVER LEAVE YOUR ENVIRONMENT

Precision AI for Institutional Workflows

Build once.Deploy across teams.Improve over time.