KT Sparks

EU funding agency, public sector · internal audit · nearly €1 billion paid out yearly

An Audit Assistant That Runs On Premise and Cites Every Line

When an agency pays out nearly €1 billion of EU funds a year, an audit finding cannot slip because an auditor spent five days copying a regulation into a spreadsheet. Sending that material to a cloud AI is not allowed either. We designed an AI that stays inside the building and is unable to cite a law that does not exist.

An Audit Assistant That Runs On Premise and Cites Every Line
Industry
Public Sector
Function
Legal & Compliance

Results

~80%
auditor time saved on each control plan
Projected: a cited draft to review replaces 4-6 working days.
100%
of generated lines backed by a checked citation
The design blocks any answer it cannot verify.
0
data sent off site
On-premise server, open-weight model, no subscription.

01

The challenge

The client is a national public agency that administers EU funding. Its internal audit function reports to the agency's audit committee, and each programme it audits must be tested against the legislation that governs it.

The work was manual from start to finish. For every programme, an auditor read the programme document, hunted for the relevant provision across more than 20 acts (national laws, ordinances, EU regulations) and entered the findings row by row into a spreadsheet control plan. A plan holds about 330 requirements and took 4-6 working days, with no tooling at all.

Why it mattered

  • EU money carries audit risk. If an audit of EU-funded payments misses a legal reference, or relies on an outdated one, the result can be an EU financial correction.
  • Legislation never sits still. Ordinances and regulations are amended all the time, and auditing a past period means finding the rule in force on a particular date.
  • Expertise lived with individuals. Know-how belonged to specific auditors, and the evidence trail was kept by hand.
  • Cloud AI was ruled out. This is sensitive public-sector data, and it has to stay inside the building.

02

What we did

We designed a full AI audit assistant that lives entirely on the client's own infrastructure. There is no cloud, no outside API and no subscription. Our partners, certified internal auditors holding CIA and CGAP credentials, supplied the audit domain expertise.

A legal corpus that stays current

Source familyContent loaded
National legislationEvery law currently in force, a daily check of the state gazette, rulings of the supreme and constitutional courts
EU legislationEUR-Lex and the Official Journal of the EU, case law of the Court of Justice, transposition records, conditionality rules
Client documentsAll versions of the strategic programme, plus secondary legislation, internal procedures and working papers
Audit standardsISA 315 and 330, COSO, COBIT, the IIA Global Internal Audit Standards, and the methodology of the European Commission and the Court of Auditors
  • Every law, every version. Changes are kept with the date they took effect, and an amendment engine applies the amending acts. The system can therefore say what the rule was on any date you ask about.
  • Legal structure, not plain text. Scanned PDFs go through OCR, and articles, paragraphs and points are recognised as legal units instead of being flattened into prose.
  • Hybrid retrieval. Graph, vector and full-text search run across the full corpus. Results are fused and re-ranked, using multilingual embeddings.

A specialised model that never leaves the premises

We chose the newest open-weight Gemma model, served on premise. Two adapters specialise it: one for national law, one for internal audit. Both are trained on material from the client and are retrained every quarter. Its instructions require it to answer with legal citations only, to keep to the control-plan format and to admit when it does not know.

No invented answers

Each generated line names its source: article, paragraph and point, plus the gazette issue and date. If a citation cannot be resolved against the corpus, the answer is blocked and never displayed. Each query goes into an immutable log. That one rule turns the output into usable audit evidence, not a draft someone has to check again.

What auditors can do with it

  1. Generate a control plan. An auditor uploads a programme document and receives a control plan with full citations, in the team's existing spreadsheet template. Three AI agents working in parallel, a lawyer, an auditor and an analyst, give an opinion on every line.
  2. Check requirements. A side-by-side view shows whether each programme requirement appears in the applicable ordinance.
  3. Legal references in one click, each one checkable against its source.
  4. Chat in plain language, with every answer cited.
  5. Review internal documents and flag clauses that conflict with the law in force.
  6. Look up history for audits of earlier periods.

Corrections made by auditors flow back into the model. Access depends on role (auditor, manager, admin). There is a REST API, remote access over VPN and a visual timeline showing how each law evolved. We also audited the hardware needs and specified one on-premise AI server, which the client will procure.

Compliance built into the design

RequirementHow we meet it
Data residencyA single server on agency premises. Nothing is transferred to cloud services
GDPRAny personal data in audit files is processed on premise only, under agency control
EU AI ActTraceability, since every output is cited. Human oversight, since auditors approve. Output that cannot be verified is blocked
Public-sector security and NIS2An isolated server, AI with no internet dependency, access by role, an immutable query log
Vendor lock-inEverything is handed over outright: open-source stack, open-weight model, no subscription

Stack

LayerDesigned with
ModelOpen-weight Gemma 4 plus LoRA adapters, served through vLLM
Retrievalbge-m3 embeddings, a re-ranker and fusion ranking, with ArcadeDB as one store covering bi-temporal, graph, vector and full-text data
DocumentsMinIO document store, Tesseract OCR with Cyrillic correction
PlatformDocker, Redis, REST API, an immutable query log in PostgreSQL, Prometheus and Grafana

03

The outcome

The numbers below are projections, based on how the agency works today and on benchmarks of the architecture.

Current processAssistant in place (projected)
A single control plan4-6 working days to draftA generated draft, reviewed in a day
Requirements per plan~330, entered manuallyExtracted, classified and cited by the system
Legal referencesHunted down by hand across 20+ actsChecked against a versioned corpus
Audits of past periodsRebuilding old versions of the textThe rule in force on the audited date
Data sent off siteNoneNone
  • About 80% less auditor time on each control plan.
  • Some 330 requirements per plan pulled out, classified and linked to a specific legal provision.
  • Audit-grade output on every line: cited, accurate as of the audited date, and blocked when the citation fails verification.
  • Audit know-how shifts from individual people into one system the department shares.
  • No recurring licence fees and no lock-in to a vendor.

The trap to avoid

Legislation changes weekly. Without automatic gazette monitoring and version history, an AI audit tool goes stale within one quarter and starts giving wrong answers with full confidence.