AuditAgent B.V.
Wilhelmina van Pruisenweg 104
2595 AN, The Hague, Netherlands
Contact
contact@auditagent.ai
+31 (0)70 369 5275
© 2026 AuditAgent B.V.
AI control testing engine for GRC partners
Turn your GRC
proposition into an AI-
powered advantage.
Place AuditAgent behind your own GRC
solution. Give end clients measurable savings,
higher quality and a visibly innovative AI
proposition — without spending years building
it yourself.
API-first
behind virtually any GRC platform
2+ years
product development
15
developers in South Africa
4
hours saved
per control

Traditional
5
hrs
→
AuditAgent
± 1 hrs
Time savings you can translate directly
into lower client cost or additional
revenue capacity.
4 hours
saved per control
Higher quality
more focus on real exceptions
More consistency
the same testing logic, every time
Faster feedback
less frustration, faster action
For GRC providers
Do not just sell GRC software.
Sell measurable outcomes.
AuditAgent can run as the automation engine behind
your existing GRC proposition. You add AI-driven
control testing without rebuilding your own
platform.
Greater revenue potential
You are not only selling tooling, but a concrete
business case: fewer hours per control, lower cost
and more capacity for the end client.
Show that you innovate
Give clients a visible AI capability inside their
existing GRC landscape and strengthen your
position as an innovative partner.
Deliver more with the same team
Automation reduces repetitive work. Your
organisation can serve more clients, more
controls and higher testing frequencies with the
same team.
Your platform
GRC
API
AuditAgent
Control Testing Engine
→
Your client
Measurable ROI
The business case
Four hours saved on every
control adds up extremely fast.
4
hours
saved per control
For large organisations with 500 to many
thousands of controls, this creates direct
economic leverage — especially when controls
are tested multiple times per year.

ANWB example
700
controls
×
4
hours
saved
=
2.800
hours per full
testing cycle
$
Lower cost
fewer specialist hours per control
Q
Higher quality
more attention for complex cases
C
Consistency
more consistent control testing
S
Speed
much faster feedback
L
Less frustration
experts do less repetitive work
M
More capacity
more controls with the same team
Partner versus build
Connecting an LLM is easy.
Building reliable control testing
is not.
AuditAgent's value is not AI alone. The combination
of GRC domain expertise, audit logic, technology,
security, evaluation and years of iteration makes the
engine difficult to replicate.
2+
years of development
Not a proof of concept, but sustained product
development, testing and iteration.
15
developers
A specialised development team in South Africa works
continuously on the engine and platform.
GRC + AI
the combination is the moat
Deep domain expertise plus the AI expertise required to
automate control testing reliably.
1.5y+
realistic catch-up time
In our experience, even a serious build attempt takes at
least around 1.5 years — while AuditAgent keeps
advancing during that time.
The hidden cost of building
Development budget is only
part of the risk.
Large organisations can incur significant
development and token costs before
discovering how difficult reliable, scalable
control testing really is. Partnering gives
you an immediate multi-year head start
without the same experimentation cost
and opportunity cost.
Market validation
Credibility from practice and
from the profession.
Kjell van Milaan
Head of IT Risk & Compliance · ANWB
"Thanks to AuditAgent.ai, we are automating our second-line control validations. Control testers receive feedback much faster, allowing us to quickly separate straightforward findings from the cases that truly require expert review."
Dr. René Matthijsse
Former Director Capgemini & Associate Professor VU
"AuditAgent.ai is a unique innovation in IT auditing and compliance. The combination of AI functionality and GRC controls increases effectiveness and automates the audit process."

Enterprise-ready
Built for the
people who
look at risk
first.
AuditAgent is designed for risk- averse 2LoD and 3LoD environments, with controllability and data security as core principles.
Hosting & data in Europe
Local AI model
ISO 27001
SOC 2
Logging & audit trail
Access control
Our partners associates







Framework support
From ISO 27001 to DORA, NIS2,
SOC and NIST.
ISO/IEC 27001
SOC 2
ISAE 3402
ISAE 3000
GDPR
BIO
NIS2
DORA
HIPAA
PCI DSS v4.0
CCPA / CPRA
SOC 1
NEN 7510
NIST CSF 2.0
ISO 31000
COSO ERM
COBIT 2019
HITRUST CSF
NIST SP 800-53
FedRAMP
CMMC 2.0
CIS Controls
OCEG GRC Capability Model
By professionals, for professionals
Domain expertise and AI
capability in the same founding
team.
Dwayne Valkenburg
CEO · RE MSc CISA
GRC technology professional with experience at Deloitte and PwC. Founder of Cyberus, co- founder of AuditAgent and President of ISACA Netherlands.
Nico van Rooyen
CTO · CISA CISM CEH DPO
Technical and cybersecurity expert with roles at KPMG, EY and multiple CISO positions. Responsible for a secure, scalable and robust platform.
Get in touch
Talk to us about partnering.
AI control testing engine for GRC partners
Turn your GRC proposition into an AI-
powered advantage.
Place AuditAgent behind your own GRC solution. Give end clients
measurable savings, higher quality and a visibly innovative AI
proposition — without spending years building it yourself.
API-first
behind virtually any GRC platform
2+ years
product development
15
developers in South Africa
4
hours saved
per control

Traditional
5
hrs
→
AuditAgent
± 1 hrs
Time savings you can translate directly
into lower client cost or additional revenue capacity.
4 hours
saved per control
Higher quality
more focus on real exceptions
More consistency
the same testing logic, every time
Faster feedback
less frustration, faster action
For GRC providers
Do not just sell GRC software. Sell measurable
outcomes.
AuditAgent can run as the automation engine behind your existing GRC proposition. You add AI-
driven control testing without rebuilding your own platform.
Greater revenue potential
You are not only selling tooling, but a concrete business
case: fewer hours per control, lower cost and more
capacity for the end client.
Show that you innovate
Give clients a visible AI capability inside their existing GRC
landscape and strengthen your position as an innovative
partner.
Deliver more with the same team
Automation reduces repetitive work. Your organisation
can serve more clients, more controls and higher testing
frequencies with the same team.
Your platform
GRC
API
AuditAgent
Control Testing Engine
→
Your client
Measurable ROI
The business case
Four hours saved on every control adds up
extremely fast.
4
hours
saved per control
For large organisations with 500 to many thousands of
controls, this creates direct economic leverage — especially
when controls are tested multiple times per year.

ANWB example
700
controls
×
4
hours saved
=
2.800
hours per full testing cycle
$
Lower cost
fewer specialist hours per control
Q
Higher quality
more attention for complex cases
C
Consistency
more consistent control testing
S
Speed
much faster feedback
L
Less frustration
experts do less repetitive work
M
More capacity
more controls with the same team
Partner versus build
Connecting an LLM is easy. Building reliable control
testing is not.
AuditAgent's value is not AI alone. The combination of GRC domain expertise, audit logic, technology,
security, evaluation and years of iteration makes the engine difficult to replicate.
2+
years of development
Not a proof of concept, but sustained product development,
testing and iteration.
15
developers
A specialised development team in South Africa works
continuously on the engine and platform.
GRC + AI
the combination is the moat
Deep domain expertise plus the AI expertise required to
automate control testing reliably.
1.5y+
realistic catch-up time
In our experience, even a serious build attempt takes at least
around 1.5 years — while AuditAgent keeps advancing during
that time.
The hidden cost of building
Development budget is only part of the risk.
Large organisations can incur significant development and token costs before discovering how difficult reliable,
scalable control testing really is. Partnering gives you an immediate multi-year head start without the same
experimentation cost and opportunity cost.
Market validation
Credibility from practice and from the
profession.
Kjell van Milaan
Head of IT Risk & Compliance · ANWB
"Thanks to AuditAgent.ai, we are automating our second-line control
validations. Control testers receive feedback much faster, allowing us to
quickly separate straightforward findings from the cases that truly require
expert review."

Dr. René Matthijsse
Former Director Capgemini & Associate Professor VU
"AuditAgent.ai is a unique innovation in IT auditing and compliance. The
combination of AI functionality and GRC controls increases effectiveness and
automates the audit process."

Enterprise-ready
Built for the people who look at risk first.
AuditAgent is designed for risk-averse 2LoD and 3LoD environments, with controllability and data security as core principles.
Hosting & data in Europe
Local AI model
ISO 27001
SOC 2
Logging & audit trail
Access control
Our partners & associates







Framework support
From ISO 27001 to DORA, NIS2, SOC and NIST.
ISO/IEC 27001
SOC 2
ISAE 3402
ISAE 3000
GDPR
BIO
NIS2
DORA
HIPAA
PCI DSS v4.0
CCPA / CPRA
SOC 1
NEN 7510
NIST CSF 2.0
ISO 31000
COSO ERM
COBIT 2019
HITRUST CSF
NIST SP 800-53
FedRAMP
CMMC 2.0
CIS Controls
OCEG GRC Capability Model
By professionals, for professionals
Domain expertise and AI capability in the same
founding team.
Dwayne Valkenburg
CEO · RE MSc CISA
GRC technology professional with experience at Deloitte and PwC. Founder of
Cyberus, co-founder of AuditAgent and President of ISACA Netherlands.
Nico van Rooyen
CTO · CISA CISM CEH DPO
Technical and cybersecurity expert with roles at KPMG, EY and multiple CISO
positions. Responsible for a secure, scalable and robust platform.
Get in touch
Talk to us about partnering.
AI control testing engine for GRC partners
Turn your GRC proposition into
an AI-powered advantage.
Place AuditAgent behind your own GRC solution. Give end clients
measurable savings, higher quality and a visibly innovative AI
proposition — without spending years building it yourself.
API-first
behind virtually any GRC platform
2+ years
product development
15
developers in South Africa
4
hours saved
per control

Traditional
5
hrs
→
AuditAgent
± 1 hrs
Time savings you can translate directly
into lower client cost or additional revenue capacity.
4 hours
saved per control
Higher quality
more focus on real exceptions
More consistency
the same testing logic, every time
Faster feedback
less frustration, faster action
For GRC providers
Do not just sell GRC software. Sell measurable
outcomes.
AuditAgent can run as the automation engine behind your existing GRC proposition. You add AI-
driven control testing without rebuilding your own platform.
Greater revenue potential
You are not only selling tooling, but a concrete business
case: fewer hours per control, lower cost and more
capacity for the end client.
Show that you innovate
Give clients a visible AI capability inside their existing GRC
landscape and strengthen your position as an innovative
partner.
Deliver more with the same team
Automation reduces repetitive work. Your organisation
can serve more clients, more controls and higher testing
frequencies with the same team.
Your platform
GRC
API
AuditAgent
Control Testing Engine
→
Your client
Measurable ROI
The business case
Four hours saved on every control adds up
extremely fast.
4
hours
saved per control
For large organisations with 500 to many thousands of
controls, this creates direct economic leverage — especially
when controls are tested multiple times per year.

ANWB example
700
controls
×
4
hours saved
=
2.800
hours per full testing cycle
$
Lower cost
fewer specialist hours per control
Q
Higher quality
more attention for complex cases
C
Consistency
more consistent control testing
S
Speed
much faster feedback
L
Less frustration
experts do less repetitive work
M
More capacity
more controls with the same team
Partner versus build
Connecting an LLM is easy. Building reliable control
testing is not.
AuditAgent's value is not AI alone. The combination of GRC domain expertise, audit logic, technology,
security, evaluation and years of iteration makes the engine difficult to replicate.
2+
years of development
Not a proof of concept, but sustained product
development, testing and iteration.
15
developers
A specialised development team in South
Africa works continuously on the engine and
platform.
GRC + AI
the combination is the moat
Deep domain expertise plus the AI expertise
required to automate control testing reliably.
1.5y+
realistic catch-up time
In our experience, even a serious build
attempt takes at least around 1.5 years —
while AuditAgent keeps advancing during
that time.
The hidden cost of building
Development budget is only part of the risk.
Large organisations can incur significant development and token costs before discovering how difficult reliable, scalable control testing really is. Partnering gives you an
immediate multi-year head start without the same experimentation cost and opportunity cost.
Market validation
Credibility from practice and from the
profession.
Kjell van Milaan
Head of IT Risk & Compliance · ANWB
"Thanks to AuditAgent.ai, we are
automating our second-line control
validations. Control testers receive
feedback much faster, allowing us to
quickly separate straightforward findings
from the cases that truly require expert
review."
Dr. René Matthijsse
Former Director Capgemini & Associate
Professor VU
"AuditAgent.ai is a unique innovation in IT
auditing and compliance. The combination
of AI functionality and GRC controls
increases effectiveness and automates
the audit process."

Enterprise-ready
Built for the people who
look at risk first.
AuditAgent is designed for risk-averse 2LoD and 3LoD
environments, with controllability and data security as
core principles.
Hosting & data in Europe
Local AI model
ISO 27001
SOC 2
Logging & audit trail
Access control
Our partners & associates







Framework support
From ISO 27001 to DORA, NIS2, SOC and NIST.
ISO/IEC 27001
SOC 2
ISAE 3402
ISAE 3000
GDPR
BIO
NIS2
DORA
HIPAA
PCI DSS v4.0
CCPA / CPRA
SOC 1
NEN 7510
NIST CSF 2.0
ISO 31000
COSO ERM
COBIT 2019
HITRUST CSF
NIST SP 800-53
FedRAMP
CMMC 2.0
CIS Controls
OCEG GRC Capability Model
By professionals, for professionals
Domain expertise and AI capability in the same
founding team.
Dwayne Valkenburg
CEO · RE MSc CISA
GRC technology professional with
experience at Deloitte and PwC. Founder
of Cyberus, co-founder of AuditAgent and
President of ISACA Netherlands.
Nico van Rooyen
CTO · CISA CISM CEH DPO
Technical and cybersecurity expert with
roles at KPMG, EY and multiple CISO
positions. Responsible for a secure,
scalable and robust platform.
Get in touch
Talk to us about partnering.