External requirements
External frameworks such as the CRR, EBA guidelines and ECB guides are processed, structured and made available as an atomic requirement library.
Auditissimo · Research project
Auditissimo is an AI-assisted audit and compliance companion for banking business units and internal audit functions. Regulatory frameworks are broken down into atomic, individually testable requirements and compared against internal rules and actual practice. Evidenced and documented.
An ongoing research project under active development, not a product available on the market. Access to the application is granted to authorised individuals only.
Starting point
A single ECB guide runs to several hundred pages. Deriving an audit programme from it means reading, highlighting, transferring into working papers and then reconciling with the internal rulebook by hand. That takes time, and weeks later it is hard to reconstruct how a finding came about.
Frameworks are decomposed into individually testable requirements, phrased to stand on their own, each referencing its section and paragraph.
The test of design compares external regulation with internal rules. The test of effectiveness compares internal rules with what is actually done.
Assessments per requirement condense into deficiencies, remediation measures and finding texts. In the same data set, without switching tools.
Five modules
The modules mirror the audit process in the order auditors actually work in. Each module builds on the results of the previous one.
External frameworks such as the CRR, EBA guidelines and ECB guides are processed, structured and made available as an atomic requirement library.
Internal policies, concepts and process descriptions are brought into the same atomic form. The prerequisite for any reliable comparison.
Validation reports, minutes and other process artefacts form a searchable evidence base for the audit procedures.
Rule-to-rule comparison: does the internal rulebook cover what external regulation demands? Gaps are named and evidenced.
Rule-to-practice comparison: is what the internal rules require actually done? Assessed requirement by requirement, through to the finding text.
Findings, measures and audit evidence flow into the draft report, each linked back to the underlying requirement.
Audit process
The relevant external frameworks are obtained, decomposed and tagged with their source references.
Internal rules go through the same processing and become linkable to the external requirements.
The requirements yield the audit programme together with the evidence documents that belong to it.
The rule-to-rule comparison shows where the internal rulebook falls short of the regulation.
The rule-to-practice comparison checks, requirement by requirement, whether the internal rule is actually implemented.
Assessments condense into deficiencies and remediation measures and flow into the draft report.
Requirement library
The first application area is IRB rating systems under Art. 191 CRR. The underlying frameworks have been processed: atomised, tagged with source references and with cross-references resolved, so that every requirement remains testable without the original document.
Audit assurance
A companion for internal audit has to meet the same standards it applies. Traceability is therefore not an add-on but a design principle.
The model supplies suggestions, classifications and source references. Assessment, judgement and sign-off remain with people, without exception.
Every model call is logged with model, input and result and remains traceable after the fact.
Every requirement carries its source: document, section, paragraph. No result without a traceable reference.
Research status
Auditissimo grows out of engagement with real audit questions and is trialled together with institutions and internal audit practitioners. Much of it is work in progress, and some of it gets discarded again. That is part of the approach.
Functionality, the models in use and the interface are continuously developed further. Individual modules are still being trialled.
No assurances are given as to availability, completeness or accuracy. All machine-generated results are suggestions and must be reviewed professionally.
The content replaces neither legal advice nor a supervisory assessment. Responsibility for audit judgements remains entirely with the institution.
Observer access for interested institutions is possible and granted case by case. Registration is limited to approved addresses, with a tiered role model and access protection at database level.
We are happy to talk with audit and business functions about the audit approach, about experience from the trials and about observer access to the ongoing development.