Durava provides an AI‑driven platform that automates the entire internal audit lifecycle, ingesting all relevant documents and using proprietary NLP models to extract controls, assess compliance, and generate findings with direct source traceability. The solution includes configurable templates for standards such as ISO 27001, DORA, NIS2, MaRisk, and SOX, and offers role‑based access, audit‑trail logging, and secure deployment in German‑hosted cloud or customer‑managed Azure.
Funding
Funding not disclosed
Founders
Product
Problem
Internal audit departments rely on manual document review and statistical sampling, which limits coverage to 10‑20 % of the document universe and creates blind spots. The process is time‑intensive, fragmented across multiple tools, and struggles to keep pace with expanding regulatory frameworks (e.g., DORA, NIS2, CSRD) and talent shortages.
Solution
Durava delivers an AI‑driven platform that orchestrates the full audit lifecycle—from annual planning through execution, findings management, reporting, and post‑audit monitoring. The system ingests all relevant artefacts (PDF, Word, Excel, PowerPoint, plain text) and applies proprietary machine‑learning models to extract controls, assess compliance, and flag risks across 100 % of the document set. Each AI‑generated finding is hyper‑linked to the exact source passage, eliminating “black‑box” concerns and enabling instant verification. Integrated templates for standards such as ISO 27001, MaRisk, and SOX accelerate plan creation, while a web‑based dashboard provides real‑time analytics, audit trails, and role‑based reporting. Deployment can be cloud‑hosted in German data centres or run in a customer‑managed Azure environment, ensuring full data sovereignty.
Target Audience
The solution is aimed at internal audit and compliance teams within regulated enterprises—banks, insurers, energy providers, and large industrial groups—that require comprehensive, auditable risk assessments and rapid reporting.
Features
- Proprietary NLP and classification models that process batches of up to several hundred documents in parallel, delivering full‑document coverage without sampling.
- Single‑click traceability: every finding links directly to the highlighted source text in the original file.
- Pre‑built, configurable audit templates for major regulatory frameworks (DORA, NIS2, ISO 27001, MaRisk, SOX) with automatic overlap detection.
- Role‑based access control, audit‑trail logging, and exportable compliance reports meeting FHIR‑compatible audit‑log standards.
- Human‑in‑the‑loop review interface that lets auditors validate, annotate, and enrich AI suggestions before final sign‑off.
- Secure hosting options: German‑based cloud or on‑premises Azure deployment with end‑to‑end encryption and GDPR‑compliant data handling.
- RESTful API and SDKs for integration with existing GRC, ERP, and document‑management systems.