Ask any IT auditor what consumes a testing cycle and almost nobody says "writing the memo". The template already exists. It has been reviewed, it carries the firm's phrasing, its sheets are laid out the way the reviewer expects, and half its cells compute from the other half. What consumes the cycle is the transcription: reading a 40-page SOC 1 report, a ticket export and a sampling note, deciding which sentence answers which field, and typing it in — 60 or 80 times, across every sheet, without losing track of where each value came from.
This is why "AI writes your audit documentation" has been an underwhelming promise. A model that produces a new document has solved the easy half. You now hold a fluent memo that does not match your template, does not tie to your evidence, and cannot be reviewed without redoing the work you were trying to avoid.
PCAOB AS 1215 sets the bar in one sentence: documentation must let an experienced auditor with no previous connection to the engagement understand the work performed, the evidence obtained, and the conclusions reached. Notice what that requires of each individual value in a workpaper — not that it be correct-sounding, but that its support be locatable.
That single requirement rules out most of what gets marketed as audit documentation automation. If a tool produces a value and you cannot point at the evidence behind it, the value has failed AS 1215 regardless of whether it happens to be right. And a reviewer cannot tell a lucky guess from a supported fact by reading either one.
So a workpaper automation worth using has to hold four lines at once:
NextGen GRC's Workpaper Composer (previously called Document Autofill) takes three things:
The second input is the one people ask about. Why supply a completed workpaper from a different engagement? Because it teaches shape and phrasing that no instruction can convey: how long an answer should be, whether "Scope" wants one line or a paragraph, what register the firm writes in. A prior-year memo is the fastest way to say "like this".
Each evidence file is given an identifier. Each answer must name the identifier it came from. This is enforced deterministically, after the model has answered and before anything is written:
None of those checks depend on the model having complied with its instructions, which is the point. The model proposes; a deterministic layer decides. When you open the filled workbook, every populated cell has a traceable source, and the fill record tells you which evidence extract it was.
This is the discipline that makes the output reviewable, and it is worth stating plainly because it runs against what automation usually optimises for. If the evidence does not answer a field, Workpaper Composer leaves it blank and says why. It does not infer, it does not carry the value across from the reference document, and it does not produce a confident sentence to fill the space.
A blank cell is not a failure of the tool. It is the tool telling you which evidence you still have to go and get — which is exactly the list you want before you close fieldwork, and exactly the list that a document with no blanks in it has hidden from you.
An audit workpaper is a controlled artefact. Three properties are protected mechanically rather than by instruction:
By default, everything runs on your device. The template, the reference and the evidence are read in the browser; the model runs locally; nothing is uploaded. For teams whose evidence includes user names, ticket detail and client identifiers, that is not a preference but a precondition — it is the same architecture behind GrcAI, our private on-device assistant.
There is an optional Fast / Quality mode that sends the selected fields and evidence excerpts to a configured cloud inference service, for machines that cannot run a capable model locally. It is off by default, it requires an explicit choice, and it shows a disclosure naming what is sent before the first use.
A single ZIP, assembled on the device:
Take a memo your team completes for every material service organisation. Inputs: your blank memo, last year's completed memo for a different provider, and this year's SOC 1 Type 2 report.
| Field | Outcome | Why |
|---|---|---|
| Report period | Filled, cited to the SOC 1 extract | Stated explicitly in the report |
| Service auditor | Withheld | The proposed value matched the reference memo — a different engagement's auditor |
| Opinion | Filled, cited | Drawn from the opinion paragraph of your evidence |
| Subservice organisations | Filled, cited | Named in the report, with the carve-out method identified |
| CUEC compliance conclusion | Gap | The report lists the complementary user entity controls; whether you perform them is not in the evidence. This is the field a reviewer would have challenged anyway |
Four fields supported, one correctly refused, one honestly blank. The blank is the useful output: it is a concrete task — evidence the CUECs — rather than a sentence someone would have had to unpick in review.
Automation moves the work; it does not remove the sign-off. Before a filled workpaper goes into the binder:
Worth saying, because automation that oversells itself costs more time than it saves:
The question to ask any audit documentation tool is not "can it write a memo". It is: when it writes a value, can you find the evidence behind it — and when it cannot find evidence, does it tell you, or does it write something anyway?
Workpaper Composer is built around the second half of that question. Your template, your evidence, a citation on every value, gaps left as gaps, and nothing leaving your machine unless you deliberately choose otherwise.
External links are provided for reference and are not affiliated with NextGen GRC. Standards are cited as at the date of publication; always work from the current text.