Skip to main content
ITGC testing software · licensed to audit firms

The questions an ITGC file is asked, and where each is answered.

AuditSenior is licensed software for testing IT general controls, from the population to the finalized binder. Its demonstration instance is by invitation, for synthetic data only.

Nothing on this site is an offer. No audit opinion, assurance or attestation is issued here.

§ 01   Who asks

Six questions, one line each

  • Engagement partner

    Question: When this file is inspected, will it stand up without me in the room?

    Answer: A finalized engagement exports one self-contained binder that prints each mapped evidence file's SHA-256, the AI determination beside the auditor's recorded disposition, and a review signature or single-auditor declaration.

    What the binder carries
  • ITGC senior or manager

    Question: Checking an AI answer takes longer than testing it myself.

    Answer: Extracted facts link to a preview of their source document, and a PDF opens at the fact’s page when one is recorded.

    Testing, step by step
  • Quality reviewer

    Question: Can someone else re-perform this sample a year from now?

    Answer: Every statistical draw stores its seed, algorithm version and population fingerprint, and can be re-drawn on the platform, which records whether the selection is identical.

    What a re-performance needs
  • Firm IT risk

    Question: Can another firm's tenant ever see our client's data?

    Answer: Tenant-scoped tables carry row-level security keyed to the signed-in session's tenant; a request for another tenant's record is refused and discloses nothing of it.

    Tenant isolation
  • Procurement and legal

    Question: If the vendor disappears, what do we hold?

    Answer: A source-escrow bundle is built only from a clean commit, with every top-level path classified as shipped or withheld; any escrow terms are agreed in writing, outside this site.

    Source escrow
  • AI governance

    Question: What stops the model inventing facts?

    Answer: With no evidence linked, a test returns inconclusive without calling the model, and a file name in a rationale that no mapped evidence corroborates is flagged.

    The AI boundary
§ 02   The build, in figures
37
ITGC control templates
8 / 9
Workflow steps per control (by category)
33
Control-level quality-review checks
14
Numbered sections in the binder

No control is concluded or signed off by the model. An auditor’s account does both, and the binder names the account that signed off.


§ 03   Paths onward

Read on by role

Practitioners and reviewers

The platform

The workflow each control runs through, the control library, and what the binder and the archive package carry.

Quality, national office, IT risk, AI governance

Assurance

Evidence integrity and the audit trail, re-performance, the AI boundary, what the platform refuses to do, and tenant isolation: implemented mechanics, not certifications.

Procurement, legal and firm technology

Licensing

A firm licenses the software, its customization, deployment on the firm's own stack, and maintenance, under a separate written agreement negotiated outside this site.

The maintenance record

Developments

An end-to-end capability map and the method behind the build, and its milestones.

A question about the file?

Write about the platform, the file it produces, or how a firm licenses it.