IT Audit Agent
The IT Audit Agent tests IT general controls across your financial systems. It validates system configurations, analyses user access rights, tests segregation of duties and reviews change management, flagging compliance gaps against JSE 3.84(k), COBIT, the Joint Standards and POPIA so your audit team can focus on risk assessment and recommendations.
Ideal forIT audit teams
The difference
From 3-4 weeks per system to 4-6 hours
Your IT audit team covers more systems each cycle and focuses its expertise on the highest-risk findings.
Done by hand
3-4 weeks per system
With the Vanine agent
4-6 hours
Time returned to your team
90%
Indicative figures. We measure your own baseline in the first fortnight so the numbers you see are yours.
Recurring regulatory testing made manageable
Joint Standards 1 of 2023 and 2 of 2024 and POPIA section 19 create recurring IT control testing across every regulated financial institution. The agent runs those tests consistently each cycle.
Full-population access reviews
Instead of sampling user lists by hand, the agent reviews every account and role, catching dormant accounts, privilege escalation and SoD conflicts that samples miss.
Fewer year-end surprises
Testing throughout the year gives you a live view of control effectiveness, so issues are fixed well before the audit opinion.
Capabilities
IT general controls tested in hours, with evidence ready for the file.
Built for IT auditors in internal and external audit firms, ISACA SA members, and IT risk teams at banks, insurers and JSE-listed companies.
Automated access rights validation
Analyses user access listings and logs against authorisation matrices to identify privilege escalation, dormant accounts and unauthorised access across ERPs such as SAP, Oracle, Sage and Syspro.
Segregation of duties testing
Cross-references roles and permissions to detect SoD conflicts, ensuring no single user can both initiate and approve critical financial transactions.
System configuration analysis
Validates security parameters and control settings against the internal financial control requirements behind the JSE 3.84(k) responsibility statement, COBIT and, for financial institutions, Joint Standards 1 of 2023 and 2 of 2024.
Change management verification
Reviews change logs, approval workflows and implementation records to confirm changes followed documented change control procedures.
Exception identification and prioritisation
Flags control deficiencies, including POPIA security safeguard gaps, ranks them by risk and generates evidence packages for working papers.
Continuous monitoring capability
Enables control testing throughout the year, giving real-time visibility of control effectiveness and reducing year-end audit surprises.
How it works
From your systems to a result you sign off
Findings land ready for review, and conclusions and sign-off remain with the IT audit lead.
Connect the places your system logs already live.
User access listings and configurations from your ERPs, IAM logs, SIEM exports and change records from ServiceNow or your ITSM tool. Already use something else? We connect that too.
- OpenAI Frontier
- Microsoft 365 (SharePoint, Teams, Excel)
- Copilot Studio
- SAP, Oracle, Sage, Syspro access and configuration extracts
- ServiceNow and ITSM change logs
- IAM logs and SIEM exports
- GRC platforms, TeamMate+, CaseWare
- Your own AI platform or models
Runs per system audit or on a scheduled monitoring cycle, with auditors directing it in Teams or OpenAI Frontier.
Prioritised exception lists and evidence packages written to your GRC platform, TeamMate+ or CaseWare, with summaries in Excel.
Step by step
- 01
The IT audit starts or the monitoring cycle runs.
- 02
The agent collects access listings, configurations, logs and change records.
- 03
It tests access rights, segregation of duties, configurations and change management.
- 04
It ranks exceptions by risk and builds evidence packages for the working papers.
- 05
The IT audit lead reviews the findings and signs off the results.
Deployment
Runs inside the tools your team already uses
The same agent and the same cited output, delivered three ways: through the AI assistant you have rolled out, on a model you host yourself, or inside your own software.
In the frontier assistant you already pay for
We publish the agent as an MCP server. Add it as a connector and your team calls it from the chat they use every day, with no new tool to learn.
"Which SAP users should not have their access?"
- system
- SAP ECC
- year
- FY2026
On a model you host yourself
Run the agent on open-weight models in your data centre or private cloud. Your system logs never leave your network, which keeps POPIA and data residency straightforward.
- Llama
- Mistral
- Ollama
- or any OpenAI-compatible endpoint
Inside your own software
Trigger a run from your own workflows, and push the finished output into your ERP, GRC or reporting systems. We build the integration with your team.
- REST API
- Webhooks
- Batch jobs
- Embeddable review panel
Governed the same way, every route
Whichever way your team reaches the agent, identity, permissions and audit stay with your existing controls.
- Single sign-on through Entra ID, Okta or Google Workspace
- Reads only the documents each user is already allowed to open
- Every tool call written to an audit log you can export
How we deliver it
One agent, three ways to hold it
Start where your team already works, then take it as far into your systems as the value justifies.
DATA SECURITY & PRIVACY
Your system logs stay yours.
The agent runs inside your tenancy, reads only what each task needs, and never trains on your system logs. Every step is logged so your auditors can see exactly what it touched.
Built for regulated work.
+YOUR SYSTEM LOGS NEVER LEAVE YOUR ENVIRONMENT
More agents
More agents we build for South African enterprises
Each one is built on the same foundation: your documents, your rules, and your people signing off.
Precision AI for Institutional Workflows


