AuditAgent B.V.

Wilhelmina van Pruisenweg 104

2595 AN, The Hague, Netherlands

Contact

contact@auditagent.ai

+31 (0)70 369 5275

© 2026 AuditAgent B.V.

AI control testing engine for GRC partners

Turn your GRC

proposition into an AI-

powered advantage.

Place AuditAgent behind your own GRC

solution. Give end clients measurable savings,

higher quality and a visibly innovative AI

proposition — without spending years building

it yourself.

API-first

behind virtually any GRC platform

2+ years

product development

15

developers in South Africa

4

hours saved

per control

Traditional

5

hrs

AuditAgent

± 1 hrs

Time savings you can translate directly

into lower client cost or additional

revenue capacity.

4 hours

saved per control

Higher quality

more focus on real exceptions

More consistency

the same testing logic, every time

Faster feedback

less frustration, faster action

For GRC providers

Do not just sell GRC software.

Sell measurable outcomes.

AuditAgent can run as the automation engine behind

your existing GRC proposition. You add AI-driven

control testing without rebuilding your own

platform.

Greater revenue potential

You are not only selling tooling, but a concrete

business case: fewer hours per control, lower cost

and more capacity for the end client.

Show that you innovate

Give clients a visible AI capability inside their

existing GRC landscape and strengthen your

position as an innovative partner.

Deliver more with the same team

Automation reduces repetitive work. Your

organisation can serve more clients, more

controls and higher testing frequencies with the

same team.

Your platform

GRC

API

AuditAgent

Control Testing Engine

Your client

Measurable ROI

The business case

Four hours saved on every

control adds up extremely fast.

4

hours

saved per control

For large organisations with 500 to many

thousands of controls, this creates direct

economic leverage — especially when controls

are tested multiple times per year.

ANWB example

700

controls

×

4

hours

saved

=

2.800

hours per full

testing cycle

$

Lower cost

fewer specialist hours per control

Q

Higher quality

more attention for complex cases

C

Consistency

more consistent control testing

S

Speed

much faster feedback

L

Less frustration

experts do less repetitive work

M

More capacity

more controls with the same team

Partner versus build

Connecting an LLM is easy.

Building reliable control testing

is not.

AuditAgent's value is not AI alone. The combination

of GRC domain expertise, audit logic, technology,

security, evaluation and years of iteration makes the

engine difficult to replicate.

2+

years of development

Not a proof of concept, but sustained product

development, testing and iteration.

15

developers

A specialised development team in South Africa works

continuously on the engine and platform.

GRC + AI

the combination is the moat

Deep domain expertise plus the AI expertise required to

automate control testing reliably.

1.5y+

realistic catch-up time

In our experience, even a serious build attempt takes at

least around 1.5 years — while AuditAgent keeps

advancing during that time.

The hidden cost of building

Development budget is only

part of the risk.

Large organisations can incur significant

development and token costs before

discovering how difficult reliable, scalable

control testing really is. Partnering gives

you an immediate multi-year head start

without the same experimentation cost

and opportunity cost.

Market validation

Credibility from practice and

from the profession.

Kjell van Milaan

Head of IT Risk & Compliance · ANWB

"Thanks to AuditAgent.ai, we are automating our second-line control validations. Control testers receive feedback much faster, allowing us to quickly separate straightforward findings from the cases that truly require expert review."

Dr. René Matthijsse

Former Director Capgemini & Associate Professor VU

"AuditAgent.ai is a unique innovation in IT auditing and compliance. The combination of AI functionality and GRC controls increases effectiveness and automates the audit process."

Enterprise-ready

Built for the

people who

look at risk

first.

AuditAgent is designed for risk- averse 2LoD and 3LoD environments, with controllability and data security as core principles.

Hosting & data in Europe

Local AI model

ISO 27001

SOC 2

Logging & audit trail

Access control

Our partners associates

Framework support

From ISO 27001 to DORA, NIS2,

SOC and NIST.

ISO/IEC 27001

SOC 2

ISAE 3402

ISAE 3000

GDPR

BIO

NIS2

DORA

HIPAA

PCI DSS v4.0

CCPA / CPRA

SOC 1

NEN 7510

NIST CSF 2.0

ISO 31000

COSO ERM

COBIT 2019

HITRUST CSF

NIST SP 800-53

FedRAMP

CMMC 2.0

CIS Controls

OCEG GRC Capability Model

By professionals, for professionals

Domain expertise and AI

capability in the same founding

team.

Dwayne Valkenburg

CEO · RE MSc CISA

GRC technology professional with experience at Deloitte and PwC. Founder of Cyberus, co- founder of AuditAgent and President of ISACA Netherlands.

Nico van Rooyen

CTO · CISA CISM CEH DPO

Technical and cybersecurity expert with roles at KPMG, EY and multiple CISO positions. Responsible for a secure, scalable and robust platform.

Get in touch

Talk to us about partnering.

AI control testing engine for GRC partners

Turn your GRC proposition into an AI-

powered advantage.

Place AuditAgent behind your own GRC solution. Give end clients

measurable savings, higher quality and a visibly innovative AI

proposition — without spending years building it yourself.

API-first

behind virtually any GRC platform

2+ years

product development

15

developers in South Africa

4

hours saved

per control

Traditional

5

hrs

AuditAgent

± 1 hrs

Time savings you can translate directly

into lower client cost or additional revenue capacity.

4 hours

saved per control

Higher quality

more focus on real exceptions

More consistency

the same testing logic, every time

Faster feedback

less frustration, faster action

For GRC providers

Do not just sell GRC software. Sell measurable

outcomes.

AuditAgent can run as the automation engine behind your existing GRC proposition. You add AI-

driven control testing without rebuilding your own platform.

Greater revenue potential

You are not only selling tooling, but a concrete business

case: fewer hours per control, lower cost and more

capacity for the end client.

Show that you innovate

Give clients a visible AI capability inside their existing GRC

landscape and strengthen your position as an innovative

partner.

Deliver more with the same team

Automation reduces repetitive work. Your organisation

can serve more clients, more controls and higher testing

frequencies with the same team.

Your platform

GRC

API

AuditAgent

Control Testing Engine

Your client

Measurable ROI

The business case

Four hours saved on every control adds up

extremely fast.

4

hours

saved per control

For large organisations with 500 to many thousands of

controls, this creates direct economic leverage — especially

when controls are tested multiple times per year.

ANWB example

700

controls

×

4

hours saved

=

2.800

hours per full testing cycle

$

Lower cost

fewer specialist hours per control

Q

Higher quality

more attention for complex cases

C

Consistency

more consistent control testing

S

Speed

much faster feedback

L

Less frustration

experts do less repetitive work

M

More capacity

more controls with the same team

Partner versus build

Connecting an LLM is easy. Building reliable control

testing is not.

AuditAgent's value is not AI alone. The combination of GRC domain expertise, audit logic, technology,

security, evaluation and years of iteration makes the engine difficult to replicate.

2+

years of development

Not a proof of concept, but sustained product development,

testing and iteration.

15

developers

A specialised development team in South Africa works

continuously on the engine and platform.

GRC + AI

the combination is the moat

Deep domain expertise plus the AI expertise required to

automate control testing reliably.

1.5y+

realistic catch-up time

In our experience, even a serious build attempt takes at least

around 1.5 years — while AuditAgent keeps advancing during

that time.

The hidden cost of building

Development budget is only part of the risk.

Large organisations can incur significant development and token costs before discovering how difficult reliable,

scalable control testing really is. Partnering gives you an immediate multi-year head start without the same

experimentation cost and opportunity cost.

Market validation

Credibility from practice and from the

profession.

Kjell van Milaan

Head of IT Risk & Compliance · ANWB

"Thanks to AuditAgent.ai, we are automating our second-line control

validations. Control testers receive feedback much faster, allowing us to

quickly separate straightforward findings from the cases that truly require

expert review."

Dr. René Matthijsse

Former Director Capgemini & Associate Professor VU

"AuditAgent.ai is a unique innovation in IT auditing and compliance. The

combination of AI functionality and GRC controls increases effectiveness and

automates the audit process."

Enterprise-ready

Built for the people who look at risk first.

AuditAgent is designed for risk-averse 2LoD and 3LoD environments, with controllability and data security as core principles.

Hosting & data in Europe

Local AI model

ISO 27001

SOC 2

Logging & audit trail

Access control

Our partners & associates

Framework support

From ISO 27001 to DORA, NIS2, SOC and NIST.

ISO/IEC 27001

SOC 2

ISAE 3402

ISAE 3000

GDPR

BIO

NIS2

DORA

HIPAA

PCI DSS v4.0

CCPA / CPRA

SOC 1

NEN 7510

NIST CSF 2.0

ISO 31000

COSO ERM

COBIT 2019

HITRUST CSF

NIST SP 800-53

FedRAMP

CMMC 2.0

CIS Controls

OCEG GRC Capability Model

By professionals, for professionals

Domain expertise and AI capability in the same

founding team.

Dwayne Valkenburg

CEO · RE MSc CISA

GRC technology professional with experience at Deloitte and PwC. Founder of

Cyberus, co-founder of AuditAgent and President of ISACA Netherlands.

Nico van Rooyen

CTO · CISA CISM CEH DPO

Technical and cybersecurity expert with roles at KPMG, EY and multiple CISO

positions. Responsible for a secure, scalable and robust platform.

Get in touch

Talk to us about partnering.

AuditAgent B.V.

Wilhelmina van Pruisenweg 104

2595 AN, The Hague, Netherlands

Contact

contact@auditagent.ai

+31 (0)70 369 5275

© 2026 AuditAgent B.V.

AI control testing engine for GRC partners

Turn your GRC proposition into

an AI-powered advantage.

Place AuditAgent behind your own GRC solution. Give end clients

measurable savings, higher quality and a visibly innovative AI

proposition — without spending years building it yourself.

API-first

behind virtually any GRC platform

2+ years

product development

15

developers in South Africa

4

hours saved

per control

Traditional

5

hrs

AuditAgent

± 1 hrs

Time savings you can translate directly

into lower client cost or additional revenue capacity.

4 hours

saved per control

Higher quality

more focus on real exceptions

More consistency

the same testing logic, every time

Faster feedback

less frustration, faster action

For GRC providers

Do not just sell GRC software. Sell measurable

outcomes.

AuditAgent can run as the automation engine behind your existing GRC proposition. You add AI-

driven control testing without rebuilding your own platform.

Greater revenue potential

You are not only selling tooling, but a concrete business

case: fewer hours per control, lower cost and more

capacity for the end client.

Show that you innovate

Give clients a visible AI capability inside their existing GRC

landscape and strengthen your position as an innovative

partner.

Deliver more with the same team

Automation reduces repetitive work. Your organisation

can serve more clients, more controls and higher testing

frequencies with the same team.

Your platform

GRC

API

AuditAgent

Control Testing Engine

Your client

Measurable ROI

The business case

Four hours saved on every control adds up

extremely fast.

4

hours

saved per control

For large organisations with 500 to many thousands of

controls, this creates direct economic leverage — especially

when controls are tested multiple times per year.

ANWB example

700

controls

×

4

hours saved

=

2.800

hours per full testing cycle

$

Lower cost

fewer specialist hours per control

Q

Higher quality

more attention for complex cases

C

Consistency

more consistent control testing

S

Speed

much faster feedback

L

Less frustration

experts do less repetitive work

M

More capacity

more controls with the same team

Partner versus build

Connecting an LLM is easy. Building reliable control

testing is not.

AuditAgent's value is not AI alone. The combination of GRC domain expertise, audit logic, technology,

security, evaluation and years of iteration makes the engine difficult to replicate.

2+

years of development

Not a proof of concept, but sustained product

development, testing and iteration.

15

developers

A specialised development team in South

Africa works continuously on the engine and

platform.

GRC + AI

the combination is the moat

Deep domain expertise plus the AI expertise

required to automate control testing reliably.

1.5y+

realistic catch-up time

In our experience, even a serious build

attempt takes at least around 1.5 years —

while AuditAgent keeps advancing during

that time.

The hidden cost of building

Development budget is only part of the risk.

Large organisations can incur significant development and token costs before discovering how difficult reliable, scalable control testing really is. Partnering gives you an

immediate multi-year head start without the same experimentation cost and opportunity cost.

Market validation

Credibility from practice and from the

profession.

Kjell van Milaan

Head of IT Risk & Compliance · ANWB

"Thanks to AuditAgent.ai, we are

automating our second-line control

validations. Control testers receive

feedback much faster, allowing us to

quickly separate straightforward findings

from the cases that truly require expert

review."

Dr. René Matthijsse

Former Director Capgemini & Associate

Professor VU

"AuditAgent.ai is a unique innovation in IT

auditing and compliance. The combination

of AI functionality and GRC controls

increases effectiveness and automates

the audit process."

Enterprise-ready

Built for the people who

look at risk first.

AuditAgent is designed for risk-averse 2LoD and 3LoD

environments, with controllability and data security as

core principles.

Hosting & data in Europe

Local AI model

ISO 27001

SOC 2

Logging & audit trail

Access control

Our partners & associates

Framework support

From ISO 27001 to DORA, NIS2, SOC and NIST.

ISO/IEC 27001

SOC 2

ISAE 3402

ISAE 3000

GDPR

BIO

NIS2

DORA

HIPAA

PCI DSS v4.0

CCPA / CPRA

SOC 1

NEN 7510

NIST CSF 2.0

ISO 31000

COSO ERM

COBIT 2019

HITRUST CSF

NIST SP 800-53

FedRAMP

CMMC 2.0

CIS Controls

OCEG GRC Capability Model

By professionals, for professionals

Domain expertise and AI capability in the same

founding team.

Dwayne Valkenburg

CEO · RE MSc CISA

GRC technology professional with

experience at Deloitte and PwC. Founder

of Cyberus, co-founder of AuditAgent and

President of ISACA Netherlands.

Nico van Rooyen

CTO · CISA CISM CEH DPO

Technical and cybersecurity expert with

roles at KPMG, EY and multiple CISO

positions. Responsible for a secure,

scalable and robust platform.

Get in touch

Talk to us about partnering.

AuditAgent B.V.

Wilhelmina van Pruisenweg 104

2595 AN, The Hague, Netherlands

Contact

contact@auditagent.ai

+31 (0)70 369 5275

© 2026 AuditAgent B.V.