Audit work, structured for the AI era.
Punchcard turns every request, test, and review step into a structured unit of audit work. Send a punchcard to a client. An agent completes it. You review it. Together they make the audit.
Built for external and internal audit and their clients. SOC 2 certified. GDPR-aligned.
Trusted by audit teams at


What is a punchcard?
A new unit of audit work.
A punchcard is a structured piece of audit work — a request, a test, a review step — with everything it needs to be completed and traced back to evidence. Send one to a client. An agent completes it. You review it. Together, punchcards make up the complete work of the audit.
1. Send
A structured request with selections, support types, and fields to extract. Clients see exactly what's needed — and get instant feedback when something doesn't tie out.
- Invoice — Selection #042
- Bank statement — Selection #042
- AR aging — doesn’t tie to TB
- Shipping doc — Selection #042
2. Complete
An AI agent reads the evidence, extracts the fields, runs the comparisons, and prepares the workpaper with citations. Mechanical work runs at scale. Judgment stays with the auditor.
3. Review
Every cell carries a reasoning trace and clickable citation. Validate, override, comment, and sign off — then export standardized workpapers without leaving the spreadsheet.
Flagship capability
Co-audit: substantive testing in minutes.
Co-audit is the first punchcard most firms send. Plain English in, audit workpapers with citations out. Up to 10× efficiency on substantive testing — without giving up judgment, traceability, or review.
Reads the documents your auditors do
Contracts, invoices, bank statements, payroll, debt agreements, revenue documents, offering memos. Extracts the fields and runs the comparisons.
Cites back to source evidence
Every conclusion is inspectable. One click takes you to the exact page, the exact line, the exact paragraph the agent reasoned from.
Built for substantive testing — and SOX
Great at substantive testing, revenue and expense testing, search for unrecorded liabilities, and operating-effectiveness testing of SOX controls.
More punchcards in the system
One system. Every kind of audit work.
Co-audit is one capability. The same operating system handles matching, testing, financial statement review, and more — each one a punchcard your team can send, complete, or review.
The matching punchcard.
Match Agent ties every selection to its supporting evidence — invoice to PO to receiving report, payment to bank statement, contract to revenue entry — without the manual hunt.
- Three-way matches at scale
- Flags missing or mismatched support on upload
- Exports tie-out tables ready for review
The testing punchcard.
Test Agent runs your audit procedures across every sample — extracting fields, comparing values, applying tolerances, generating tick marks, and citing the source for every conclusion.
- Procedure templates per assertion
- Tolerances and exceptions flagged
- Reasoning trace on every cell
The FSR punchcard.
Financial Statement Review reads the draft financials, ties balances to the trial balance, checks disclosure completeness, and surfaces inconsistencies between the notes and the numbers.
- TB-to-FS tie-out
- Disclosure checklist coverage
- Cross-section consistency checks
Who it's for
Built for the audit work you actually do.
One operating system. Same evidence, same testing, same review surface — whether you're signing the opinion or running the internal audit plan.
For external audit
CPA firms running assurance engagements.
Streamline client requests, evidence collection, substantive testing, and workpaper preparation. Keep professional judgment in your hands and turn engagement weeks into days.
- Per-selection client request flows
- Substantive testing with citations
- Reviewable, exportable workpapers
For internal audit
In-house teams across operational, financial, and IT audit.
Standardize procedures, automate evidence gathering and testing, and free your team for risk-based judgment work. Strong at operating-effectiveness testing of SOX controls.
- Standardized procedure templates
- SOX-controls testing with traceable evidence
- One workspace for evidence, testing, and review
What auditors are saying about Co-audit
In her first day using Co-audit, a senior at Richey May completed revenue testing across 41 selections and 123 supporting documents in 30 minutes — work that would normally take days to do manually.
Co-audit gives our auditors back the hours that don't require professional judgment, so they can spend more time where the risk actually lives.
Steve Checketts
Partner, Richey May
For a new classification standard on insurance investment bonds, I had Co-audit scan 12,750 pages of offering memos across 15 selections and quote the sections supporting each classification, against a flowchart I wrote. That isn't a procedure we would have attempted manually.
Co-audit didn't just make the work faster — it let us do work we wouldn't have done at all.
Paige Bassoli
Associate, JLK Rosenberger
Assurance, one punchcard at a time.
See Punchcard handle a real engagement. We'll walk through requests, testing, and review using your evidence — every judgment call still in human hands.
Trusted by RSM, Richey May, JLK Rosenberger, and more.