Loading
Loading
LoadingEngagement ENG-2026-014 · Lead: Anjali K. · Fieldwork starts 12 Oct 2026
Inherent and residual scoring on a 5×5 matrix, each risk linked to the controls that address it
| Risk | L | I | Score | Rating |
|---|---|---|---|---|
| R-03Privileged access not reviewed quarterly | 4 | 5 | 20 | Critical |
| R-07Emergency changes bypass CAB approval | 3 | 5 | 15 | Critical |
| R-11Backups not restore-tested in 12 months | 3 | 4 | 12 | High |
| R-14Shared service accounts in core banking | 4 | 3 | 12 | High |
| R-19Vendor SOC 2 reports not obtained ✦ AI | 2 | 3 | 6 | Medium |
Statistical sampling to ISA 530 and data analytics over the full population, without leaving the engagement
Every file is hashed on upload, versioned, and linked to the control or finding it supports
| File | Size | SHA-256 | Version | Status |
|---|---|---|---|---|
| AD_privileged_users_Sep26.csv | 3.2 MB | v1→v2 | Hashing… | |
| PAM_quarterly_review_Q1.pdf | 842 KB | c7e1…9a04 | v1 | ✓ Verified |
| Access_review_signoff_email.eml | 61 KB | 3b90…f12e | v1 | ✓ Verified |
Five-element finding · linked to R-03, C-014 and evidence E-031
Reassign ownership of the quarterly privileged access review to the Head of IT Infrastructure, disable the 14 dormant admin accounts within 5 working days, and add the review to the compliance calendar with automated reminders 10 days before each quarter end.
Ask anything about this engagement. Every answer cites records in the file; nothing is written without your approval.
Connect the AI you already use and ask it questions about this engagement. Read-only, pinned to one client.
Generated from the engagement itself: every finding, rating and evidence reference traces back to the file
Plan, test, evidence and report a complete IS audit in one place. Built by a Chartered Accountant and CISA, for auditors.
Coming soon · Request early accessAudit work today lives in spreadsheets, documents, email threads and shared drives. AuditSphere replaces that sprawl with a single governed workflow where nothing is lost, nothing is skipped, and everything is traceable.
Eight enforced stages from engagement setup to reporting. Stage gates check completeness before work moves forward, so quality is built in rather than reviewed in.
Setup → Universe → Risk → Controls → Planning → Execution → Findings → Reporting
Inherent and residual scoring on a 5×5 matrix. Map a control once and see coverage across ISO 27001, NIST CSF, SOC 2, PCI DSS, RBI and more.
Test once, comply many
Random, systematic, stratified, monetary-unit and judgmental sampling to ISA 530. Benford's law, duplicates, gaps, journal-entry tests, stratification and outliers over the full population.
Reproducible by design
Every file hashed with SHA-256 on upload, version-chained, and linked to the control or finding it supports. Signed, time-limited access links.
Regulator-ready
Five-element findings, management responses, remediation and retest tracking. Workpapers with preparer, reviewer and approver sign-off and a four-eyes rule enforced at the database.
Condition · Criteria · Cause · Effect · Recommendation
Reports generated from the engagement itself, with a draft, review, approve and finalise chain. Export to PDF, DOCX and XLSX.
Locked after partner approval
Connect Claude, ChatGPT, Cursor or any MCP-capable client and ask it questions about an engagement directly. Each connection is a named credential pinned to one client and read-only at the database.
Works with the AI you already use
Fifteen IT audit programs, from logical access and change management to cloud, privacy and incident response, with 80+ test procedures mapped to control objectives and ready to import into any engagement.
Start from a standard, not a blank page
In regulated audit, an answer without provenance is worthless. Every AI output in AuditSphere carries a confidence score and cites the records it drew on. It never invents an ID, and nothing it drafts enters the file until a named person accepts it.
Suggested risks and controls, drafted findings and recommendations, evidence analysis, framework gap analysis, and a copilot grounded in your engagement, and an MCP connection for the agents you already use.
Accept, edit or reject. Actions that would write data or send anything outside the platform require approval from an audit manager or partner.
Every suggestion, decision and override is written to an immutable audit trail with who, when and what.
AuditSphere exposes an MCP server at POST /api/v1/mcp. Claude Desktop, Claude Code, Cursor or any MCP-capable client connects with a credential you issue inside AuditSphere. Every request travels the same path, and a connection can read but never write.
In Workspace → AI connections, create a key. You choose the client it is pinned to and the person it acts as. The key is shown once, stored hashed, and can be rotated or revoked at any time.
Paste the connection into Claude Desktop, Claude Code or any MCP client. Claude Desktop uses the small AuditSphere shim; other clients connect over Streamable HTTP with the key in a header.
"Which controls for R-03 still lack evidence?" The client calls the matching tool. AuditSphere answers only from the pinned client’s records, and only with reads.
Each connection is read-only and pinned to one client. Rotate or revoke a key in one click, and the client loses access immediately.
{
"mcpServers": {
"auditsphere": {
"command": "npx",
"args": ["-y", "@auditsphere/mcp"],
"env": {
"AUDITSPHERE_URL": "https://app.auditsphere.com",
"AUDITSPHERE_KEY": "ask_7f3c…9e21"
}
}
}
}POST https://app.auditsphere.com/api/v1/mcp Authorization: Bearer ask_7f3c…9e21 Content-Type: application/json { "jsonrpc": "2.0", "id": 1, "method": "tools/call", "params": { "name": "list_findings", "arguments": { "engagement": "ENG-2026-014" } } } ← 200 { "jsonrpc": "2.0", "id": 1, "result": { "findings": [ … 7 items … ] } }
The key identifies a person and one client. There is no “which client” parameter on any tool: the pin comes from the credential, so a client cannot ask for someone else’s data by mistake or on purpose.
Eighteen tools, all reads. No tool takes a client parameter. Aggregates return null rather than zero for anything outside the pin, because a zero is itself a fact about a client.
Audit files contain some of the most sensitive information a client holds. AuditSphere is engineered so that isolation, access control and traceability are properties of the system, not policies people are asked to follow.
Tenant separation enforced with PostgreSQL row-level security, not just application code. Every tenant table carries a policy.
Immutable system roles from partner to client read-only, enforced on every endpoint. Only partners approve AI-proposed actions and sign off reports.
Every change captured with before-and-after state, actor and correlation ID, in a log that cannot be edited or deleted.
SHA-256 hashing and version chains on every upload, so you can prove a file is the file you tested.
Twelve frameworks mapped out of the box, with control objectives written in our own words and cross-framework mapping so one test can evidence many requirements.
We are opening AuditSphere to a small group of audit firms and internal audit teams ahead of launch. Tell us about your practice and we will be in touch.
Would rather talk it through first? Book a consultation.