Part of the Confermax suite

The audit file,
end to end.

Import the trial balance, map it to lead schedules, post adjustments, run your tests of details and sampling, chase the client for evidence, and sign the file off — in one workspace instead of eleven spreadsheets and an inbox.

Multi-tenant by firm · Engagement-level RBAC · Your library stays yours

app-demo.auditessential.com/as/ledger/1148
Northgate Logistics Ltd · FY2025 statutory audit Dr = Cr Period open
Transactions Trial Balance Working Papers Reports
Code Account Lead Unadjusted Dr Unadjusted Cr AJE net Adjusted Dr
Assets
1010Cash at bank — HSBC currentA 1,284,5101,284,510
1200Trade receivablesB 3,907,220(146,800)3,760,420
1310Inventories — finished goodsC 2,145,006(88,240)2,056,766
1500Property, plant & equipmentE 6,712,8806,712,880
Liabilities
2100Trade & other payablesI 2,884,19062,400
2210Accrued expensesJ 418,905146,800
Totals — 214 accounts, 6 AJEs 18,442,31818,442,318018,442,318

Workpapers structured around the standards your file is reviewed against

ISA 315 ISA 330 ISA 500 ISA 520 ISA 530 ISA 700 IFRS IAS AML / KYB / KYC

The workbench

A trial balance that carries the whole engagement.

Everything downstream — lead schedules, adjustments, tests, reports — is derived from one ledger per engagement per fiscal year. Change a number once and the file agrees with itself.

Import, map, adjust, foot.

Drop in an Excel or CSV trial balance. Columns are matched automatically, you confirm the mapping, and the ledger is written. Nothing is committed until you've seen the preview.

  • 22 lead schedules, A to V — cash through taxation. Auto-mapping proposes the schedule and shows its confidence and source.
  • Unadjusted → AJE → adjusted in the classic three-column layout, with grand totals that flag when debits stop equalling credits.
  • Adjustments have a lifecycle — proposed, accepted or rejected, then cleared — so the review trail is in the file rather than in email.
  • Lock the fiscal year when fieldwork closes. Imports, remapping and new AJEs stop at the lock.
AJE-004 · Cut-off — goods despatched after year end Proposed
CodeAccountDebitCredit
4000Revenue — freight services146,800
1200Trade receivables146,800
5100Cost of services88,240
1310Inventories — finished goods88,240
Balanced235,040235,040
Raised by K. Owusu · Lead B, Lead C · Links to TOD-11 Awaiting manager

Evidence you asked for, tracked to the day it arrives.

PBC requests move through eight states, chase themselves on a schedule, and land as files attached to the engagement — not as attachments buried in a mailbox.

  • A client portal, not an account — the client opens a code-gated portal, verifies by email, and uploads. No licence, no onboarding call.
  • Raise a request straight from a transaction — select rows in the GL, push them to a PBC request, and the reference travels with the evidence.
  • Automatic chasers with a reminder count on every request, so the follow-up isn't someone's Friday afternoon job.
PBC requests · Northgate Logistics · FY2025 18 of 24 received
Bank confirmations — all facilities
Lead A · Due 14 Mar · 2 files
Received
AR ageing at year end + subsequent receipts
Lead B · Due 14 Mar · 1 file
Received
Inventory count sheets — Rotterdam depot
Lead C · Due 18 Mar · chased 2×
Overdue
Post-year-end despatch notes (cut-off sample, 25 items)
Lead B · Raised from 25 GL rows
In review
Signed board minutes — Q3 and Q4
General · Due 21 Mar
Sent

Transaction risk scan

Find the odd entries before the review note does.

One pass over the imported general ledger flags the patterns you'd otherwise hunt for by hand. Every flag opens onto the rows behind it, so it's a starting point for work — not a score.

  • Weekend & holiday postings 31
  • Round-sum amounts — exact thousands and powers of ten 64
  • Unusual Dr/Cr pairings — credit to an asset against a debit to revenue 7
  • Benford first-digit deviation, per ledger and per account χ² 24.8

Benford first-digit distribution

χ² 24.81 / crit. 15.51

8 degrees of freedom, 5% significance · 41,207 postings

1
2
3
4
5
6
7
8
9
Observed Benford expected Above tolerance

Capabilities

The rest of the engagement, in the same file.

No bolt-on modules, no second login, no exporting to a spreadsheet to do the real work.

Tests of details

ISA 330/500 procedures with test items, auto-vouching against imported evidence, exception evaluation and a binder export at the end.

Analytical procedures

ISA 520 substantive analytics: build an expectation from drivers, set the threshold, and record the variance explanation as the workpaper.

Audit sampling

ISA 530 sample selection over the transaction population, pushed straight to PBC requests, with the selection basis retained.

Group consolidation

Combine member ledgers into a group snapshot, post eliminations, and report the consolidated position alongside each component.

KYB & KYC

Client and contact due diligence inside the engagement record — entity checks by jurisdiction, plus global AML and PEP screening on individuals.

Reports & exports

Trial balance, balance sheet, income statement and ratio analysis, exported to Excel or PDF. Generation is server-side, so the output is identical for everyone.

Teams & permissions

Staff see the engagements they're named on or that belong to their team. Module access is set per user; firm-admin screens stay closed.

Cloud storage

Mirror engagement files to Google Drive, Dropbox, OneDrive or S3 with the firm's own credentials, so the archive lives where your retention policy says.

Document generation

Produce a memo or schedule from a spec, or fill the firm's own Excel and Word templates in place so deliverables keep your house style.

Confermax AI

Answers from your library and the standards — with the page it came from.

Retrieval is grounded in two places and nowhere else: your firm's private library, then the curated global standards corpus. Every answer carries its citations, so a reviewer can check the source instead of trusting the model.

Your material is the primary authority.

Firm documents are ingested, normalised and indexed into a library only your firm can query. The global corpus sits underneath it as the fallback, never the other way round.

  • Jurisdiction-aware retrieval — a Hong Kong engagement isn't answered with Vietnamese guidance. IFRS and ISA material is treated as globally applicable and never demoted.
  • Embeddings run locally on the firm's own instance. Indexing a document does not ship it to a third-party embedding API.
  • Ingests what auditors actually receive — digital PDFs, scanned PDFs through OCR, Excel workbooks and Word documents, all normalised into one searchable form.
  • Bring your own model — point the platform at OpenAI, Anthropic, Gemini, DeepSeek or a self-hosted endpoint, per firm.
Confermax AI · context: Northgate FY2025 Skill: Project analysis
What documentation do we need for the cut-off testing on despatches after year end?
For despatch cut-off you're testing the occurrence and period assertions on revenue. Retain the despatch notes either side of year end, the matching invoices, and the reconciliation of the last pre-year-end despatch reference to the sales ledger. Your firm's methodology sets the sample at 25 items either side where revenue is a significant risk.
FIRM Audit Methodology 2025 — §7.4 Revenue cut-off FIRM Northgate — prior year cut-off memo GLOBAL ISA 500 — Audit Evidence
22

Lead schedules seeded, A through V, from cash to taxation

4

Working paper types — lead sheets, TOD, ISA 520, ISA 530

8

States in the PBC workflow, from drafted to closed

15

MCP tools for firms automating against the platform

Security & control

Built for a file somebody else will inspect.

Audit software carries client data that is confidential by statute. The controls are the product, not a settings page.

  • Tenant isolation by firmEvery client, engagement, document and library item belongs to exactly one firm. Cross-firm reads are not addressable.
  • Engagement-level RBACAccess follows named audit staff, the audit manager and team membership. Private engagements are hidden outright.
  • Client portal is scoped, not privilegedClients reach exactly the requests addressed to them, through a code plus an email one-time code. No staff account is issued.
  • API keys are least-privilegeMachine access is issued per firm with a tool allowlist, a role and an optional read-only flag. Sign-offs, period locks and AJE posting stay human-only.
  • Deploy where your data must liveSelf-hosted or single-tenant, with your own database, storage and model endpoint.
MCP · list_pbc_requests
# Scoped to the firm on the key. The firm is never
# read from the request arguments.
Authorization: Bearer cfx_f_<firm>_<token>

 {
    "project": "Northgate FY2025",
    "status": "overdue"
  }

 {
    "count": 3,
    "requests": [
      { "ref": "PBC-014",
        "title": "Inventory count sheets",
        "due": "2026-03-18",
        "reminders": 2 },
      /* … */
    ]
  }

# write_access: false → create_pbc_request denied
# sign-off, period lock, AJE entry: never exposed

Questions

Before you book the call.

Do we have to move our whole methodology across?

No. The workbench works out of the box on the seeded A–V lead schedule taxonomy. Firms that want Confermax AI answering with their own house guidance upload that library separately, at whatever pace suits — it isn't a prerequisite for running an engagement.

What formats can we import?

Excel (.xlsx) and CSV, for both trial balances and general ledger transaction detail. Common header names are detected automatically — Code, Description, Dr, Cr and their usual variants — and anything unrecognised is mapped by hand in the preview step, before anything is committed to the ledger.

Does the client need a licence to respond to a PBC request?

No. Each engagement issues a client code. The client opens the portal with that code, verifies with a one-time code sent to their email, and sees only the requests addressed to them. There is no seat, no password to manage and nothing to install.

Where does our data sit, and does it train anyone's model?

Your documents are indexed into a library scoped to your firm alone, and the embeddings that make it searchable are computed on your instance rather than sent to an external API. Nothing is used to train a model. Firms with residency requirements can self-host or run single-tenant, so the database, the file storage and the model endpoint are all yours.

Can we automate against it?

Yes. The platform ships an MCP server exposing fifteen tools — clients, contacts, projects, PBC requests, ledger summaries, library search and KYB/KYC checks. Keys are issued per firm with a tool allowlist, a role and an optional read-only flag. Sign-offs, period locks and journal entry posting are deliberately not exposed to machine callers.

How long does it take to get running?

A first engagement — client set up, trial balance imported and mapped, PBC list issued — is typically a single working session. Migrating a firm library and prior-year files is scoped separately during onboarding.

See it on your own trial balance.

Bring a real engagement file to a 30-minute call. We'll import it, map it, and you'll see your own numbers in the workbench before the call ends.