- 01
Select the framework.
Start from SOC 2, ISO 27001, NIST, CMMC, ARISE, or a custom framework imported by JSON or CSV. Controls and requirements are parsed automatically.
New engagementStep 1 of 6SOC 2 Type IIISO 27001NIST 800-53CMMC L2ARISECustom importControls parsed61Requirements214Mapped to existing evidence38% - 02
Certify the controls in scope.
The engagement team confirms which controls are in scope and assigns an owner to each, so responsibility is set before fieldwork begins.
Control certificationStep 2 of 6CC6.1 Logical accessIn scope · Lead AuditorCC6.2 User provisioningIn scope · AttestorCC6.3 Access removalIn scope · AttestorA1.2 RecoveryCarved out - 03
Analyze evidence at the requirement level.
AI scores each artifact against each requirement and returns a verdict, a rationale, and any coverage gap. The auditor reviews every verdict and can override it.
Evidence analysis · CC6.2Step 3 of 6Access_Review_Q3_2026.pdfViewScore: 67%TOD 100%TOE 50%The quarterly access review documents the approval workflow and names reviewers for each application. It shows two completed review cycles, but one cycle lacks sign-off for the finance system, so operating effectiveness is only partially demonstrated.
View requirement verdicts (2/3 met)
TODAccess reviews follow a documented, approved procedure. Section 2 defines scope, cadence, and reviewer roles.TOEReviews were completed for the period. Records show cycles closed in July and September.TOEEvery in-scope application has reviewer sign-off. The September cycle has no sign-off for the finance system. - 04
Manage findings with the 5Cs.
Each finding is documented by criteria, condition, cause, consequence, and corrective action, with the management response captured alongside it.
Finding F-07 · CC6.3Step 4 of 6CriteriaAccess removed within 24 hours of terminationCondition3 of 25 sampled accounts active after 72 hoursCauseManual offboarding ticket queueConsequenceFormer staff retain system accessCorrective actionAutomate deprovisioning from HR system - 05
Complete final review and sign-off.
Reviewers work through findings, management responses, and overrides in sequence. The sign-off records who approved what, and when.
Final reviewStep 5 of 6Findings reviewed12 of 12Management responses12 of 12AI score overrides4 documentedLead Auditor sign-offPending - 06
Generate the report in one step.
The report assembles findings, management responses, 5Cs observations, and the overall opinion into a publishable document.
Certificate of AttestationStep 6 of 6Northwind HealthSOC 2 Type II · Assessment period Q3 2026Controls assessed64 (58 compliant, 6 partial)Findings0 major, 3 minor, 2 observationsRatingSatisfactoryAttestation IDATT-2026-7KQ4M2XN81Certification availableIssue certification
AssessedAssurance
Audit smarter, not longer.
Assessed Assurance is an AI audit tool for attestation and advisory engagements. AI analyzes evidence, maps controls, and drafts the report; the assessor holds the conclusion.
Client names are fictional.
Most audit hours are not spent on judgment. They are spent chasing evidence, reconciling spreadsheets, and assembling reports by hand. That time belongs to analysis, and to the client.
Requesting, chasing, and matching artifacts to controls consumes most of a typical engagement.
A SOC 2 engagement commonly runs for months from kickoff to report.
Each engagement accumulates its own set of trackers, request lists, and workpapers.
AI handles the assembly so auditors can apply judgment.
Each document, policy, or screenshot is scored against every requirement it touches, with coverage gaps flagged.
Imported frameworks are parsed into controls and requirements, then mapped across frameworks so one artifact satisfies the overlap.
Each AI score records the model, the prompt version, and a timestamp. Auditors can override any score, and the override is recorded.
Drag to compare. Illustrative example.
An attestation runs from framework selection to sign-off in one place.
Each step hands its output to the next, so nothing is re-keyed between trackers, and every conclusion stays connected to the evidence behind it.
Advisory work keeps clients improving between audits.
Point-in-time audits cannot keep pace with systems that change continuously. Advisory mode turns the gap analysis into a working program, and Operate mode keeps it running between engagements.
Maturity across the seven ARISE domains.
Scores are calculated at the domain level so leadership can see where the program is strong and where it is thin.
Illustrative scores.
Every role in the engagement works from the same platform.
Assessed Assurance is built for the firms doing the work.
Audit and advisory firms of 10 to 500 practitioners managing SOC 2, ISO, CMMC, and AI governance engagements.
Enterprise GRC teams running internal audit, and regulated industries including financial services, healthcare, and defense.
AI governance audits, a new category where no incumbent has a tooling advantage.
Audit software must meet the standard it measures.
Firms ask these questions first.
Does the AI reach audit conclusions?
No. The AI scores evidence and drafts the record. The assessor reviews every score, can override any of them, and signs the opinion. Overrides are recorded with the rest of the provenance.
Can we bring our own frameworks?
Yes. Import any framework by JSON, CSV, or an AI-parsed document alongside SOC 2, ISO 27001, NIST, CMMC, and ARISE. Controls and requirements are parsed and added to a deduplicated master control library.
What do our clients see?
A portal carrying your firm's brand, where clients upload evidence, answer PBC requests, manage their own team, and track progress. They see only what you assign to them.
Is it continuous monitoring?
Assessed Assurance makes a defined engagement faster and more consistent. Advisory and Operate modes track maturity, risk treatment, and evidence freshness between audits, with re-certification alerts when evidence expires.
How is evidence protected?
Multi-factor authentication, field-level encryption, role-based access, and integrity hashing with version history on every artifact, supported by activity logs and backup and restore.
Run your next engagement on Assessed Assurance.
Join the beta and take an attestation from framework import to final opinion.
