Administration
Methodology & Knowledge Layer
Agents do not invent an approach. They apply your audit manual, your sampling standards, your templates and your prior-year work — and cite the section they relied on.
Methodology documents
7
All indexed
Frameworks mapped
4
COSO, AS 2201, IIA, NIST
Prior-year workpapers
1,164
FY24–FY25 indexed
Citations in Q3 file
2,318
Every conclusion cited
Sources the agents rely on
| Source | Type | Version | Status | Used by |
|---|---|---|---|---|
| Northbridge Internal Audit Manual FY26 | Methodology | v6.2 | Active | All agents |
| SOX Testing Standards & Sampling Guide | Methodology | v4.0 | Active | Testing agents |
| COSO 2013 Framework mapping | Framework | 2013 | Active | Risk & scoping agents |
| PCAOB AS 2201 guidance summary | Standard | 2024 | Active | Deficiency agent |
| IIA Global Internal Audit Standards | Standard | 2024 | Active | QA agent |
| Prior-year workpapers (FY25) | Historical | FY25 | Indexed | All agents |
| FY25 Risk Assessment & heatmap | Historical | FY25 | Indexed | Risk agent |
Knowledge layer
When a procedure is generated, the agent cites the methodology section it applied — for example sample size 45 under §7.3 for a high-risk ongoing control. Deviations from the manual require human approval and are logged.
Sampling standard §7.3
| Risk | Frequency | Sample size | Note |
|---|---|---|---|
| High | Ongoing / daily | 45 | Attribute sampling, 0 tolerable exceptions |
| High | Monthly | 5 | 3 for lower risk with effective ITGCs |
| High | Quarterly | 2 | All quarters if exceptions found |
| Moderate | Ongoing / daily | 25 | Expand on first exception |
| Moderate | Monthly | 3 | — |
| Any | Fully automated | 1 | Permitted only where ITGCs are effective |
Thresholds in force
- Account significance
- 5% of pre-tax income
- Location significance
- 10% of revenue or inventory
- Coverage age trigger
- 18 months
- Tolerable exceptions
- 0 for key controls
- Review note SLA
- 24 hours
- QA sampling
- 20% of effective conclusions