The audit file does the testing. You still sign it.
An ISA audit of IFRS statements, run end to end on a hashed snapshot of the client's books. Engines test every journal, compute materiality, design and evaluate the samples, tie the schedules out, chase the confirmations and aggregate the misstatements. A licensed human concludes and signs. Hysaab never signs an opinion.

An audit is mostly evidence handling. Almost none of it needs a human.
Seven phases, and a gate you cannot talk your way through.
One engagement, from the snapshot to the signature.
It refuses to start on books that do not add up.
Nothing is tested against the live ledger. Hysaab takes a snapshot, hashes it, and runs seven completeness checks before a single procedure is planned. A general ledger that does not roll forward to the trial balance it was handed is a STOP, not a note in the file.
- Roll-forwardOpening plus movement must equal closing, on every account. A balancing figure is refused.
- SequenceMissing journal numbers are listed as gaps for the client to explain.
- HashedSHA-256 on the snapshot. Every later figure cites the hash it came from.

Risk assessed line by line, assertion by assertion.
The engines read the entity from its own numbers: ratios, monthly trends, differences above precision, the fraud triangle, related parties. Out comes a risk register per financial statement line and assertion, with the presumed significant risks of ISA 240 already on it and the factor that raised each one written beside it.
- Approved by a personThe register is a proposal until a partner approves it, and the phase gate will not open before that.
- MaterialityComputed from this year's figures, with every candidate benchmark shown and the choice explained.
- The programmeOnly the procedures that fit the chart are instantiated. No tax recompute where there is no tax account.

Every journal is scored. Not twenty-five of them.
ISA 240 asks you to test journal entries. Most files test a handful chosen by eye. Hysaab scores all of them against thirty criteria, weights the hits, and strata the population into entries above performance materiality, entries the score picked up, and a random sample for the rest. You vouch what it selected and record what you found.
- 743 of 743Scored on this engagement. 175 selected: 146 above performance materiality, 7 on score, 22 at random.
- Thirty criteriaPost-close postings, round numbers, weekends and holidays, blank narratives, seldom-used accounts, keyword hits, duplicates, reversals, segregation conflicts, entries just below an approval threshold.
- AuditableEach row carries the criteria that flagged it. The selection is seeded, so it reproduces.

Monetary-unit sampling, designed and evaluated in the open.
Sample size from the risk and the tolerable misstatement, selection at a fixed interval with the top stratum taken in full, then the evaluation: factual, projected, basic precision, incremental allowance and the upper misstatement limit, against performance materiality. The narrative says what the number means and whether the balance can be accepted.
- ReproducibleSeeded selection. The same population and seed give the same sample, every time.
- Attribute tooControl testing at ninety-five percent confidence with its own sample table.
- Honest answerAn upper limit above performance materiality is reported as not accepted, not explained away.

Confirmations and the request list chase themselves.
Confirmees are selected from the snapshot: every bank, the sampled receivables, the top payables without statements, lenders, counsel, related parties. Letters are drafted per kind with unique references. Reminders fall due on schedule, two unanswered reminders escalate to named alternative procedures, and a reply that came through the client is marked less reliable than one that came direct.
- The request listDerived from the procedures actually planned, not typed from memory, with an owner and a due date per item.
- ReliabilityScored by route and sender domain. A forwarded reply is evidence of a different grade.
- Sent by peopleLetters leave the firm's own mailbox. The software drafts them and tracks them.

Misstatements aggregated against materiality, both bases.
Every procedure that finds a difference posts it to one register. At completion it is evaluated on the rollover and iron-curtain bases, gross and net by line, with the qualitative factors attached. Below clearly trivial stays on the list and leaves the aggregate. The conclusion names the standard that applies if the client does not correct.
- The arithmetic703,500 uncorrected against overall materiality 386,400. Material, with an ISA 705 citation on the conclusion.
- Subsequent eventsPost-period journals and minutes are scanned and classified adjusting or non-adjusting, with the IAS 10 reference.
- File completionNine checks on the file itself. Two are still open on this engagement, and it says so.

Workpapers written as the work happens, signed by people.
Each procedure writes its own workpaper: purpose, source, procedure, results, conclusion, cross-referenced to the others. Preparer, reviewer and partner sign in order. A partner signature locks the version, and a change after that is a new version with a reason, never an edit over the top.
- Tick marksSet by the engine that performed the agreement, not typed. A failed tie-out shows as a cross.
- VersionsImmutable. The reason for every new version is on the paper.
- ConclusionsA reviewer cannot sign a judgement workpaper without recording a conclusion in their own words.

Engines compute. Models draft words. A licensed human concludes.
Hysaab never signs
The opinion is a decision tree a partner walks and records. The report is drafted for the firm to review, and the signed PDF is held as evidence, never produced by the software.
A firewall, not a policy
Audit records belong to the firm. The client grants read access for a fixed window and can revoke it. A team member who holds a seat in the client organisation is refused by the database itself.
Testing never touches live books
Every procedure runs on an immutable, hashed copy. Figures on screen cite the hash. Nothing in the audit module can write to a ledger.
Some things are human only
Inventory counts, inspections and other physical procedures are recorded by the person who performed them. Risk approval, conclusions and the phase gates need a named signature.
Code computes, not the model
Materiality, sample sizes, projections, tie-outs and the misstatement aggregate are computed deterministically and reproduce exactly. The model writes around the numbers, never the numbers.
Flagged until verified
Standards references are marked unverified until the firm's licensed texts are loaded. We would rather show you the gap than let a confident citation into a file you sign.
Part of the professional services stack.
hysaab audit is the audit module of hysaab services OS, the operating system we build for tax and advisory firms. Same clients, same file room, same rule that the AI proposes and a person decides. Take it on its own or with the rest of the practice.
Built against a working methodology, in the open.
hysaab audit was written from a clean-sheet ISA methodology rather than a template pack: acceptance through to archive, with the engines proved against a seeded engagement whose misstatements are known in advance. Every release re-runs it and scores what was found, what was missed and what was flagged in error.
We are opening it to a small group of licensed firms in the UAE and KSA. Founding firms shape the methodology and keep founder pricing for as long as they stay.
Bring us a file and we will run it.
hysaab audit opens to a small group of licensed audit firms first. Tell us about your practice and a real person will walk you through an engagement within one working day.