EU funding agency, public sector · internal audit · nearly €1 billion paid out yearly
An Audit Assistant That Runs On Premise and Cites Every Line
When an agency pays out nearly €1 billion of EU funds a year, an audit finding cannot slip because an auditor spent five days copying a regulation into a spreadsheet. Sending that material to a cloud AI is not allowed either. We designed an AI that stays inside the building and is unable to cite a law that does not exist.

- Industry
- Public Sector
- Function
- Legal & Compliance
Results
- ~80%
- auditor time saved on each control plan
- Projected: a cited draft to review replaces 4-6 working days.
- 100%
- of generated lines backed by a checked citation
- The design blocks any answer it cannot verify.
- 0
- data sent off site
- On-premise server, open-weight model, no subscription.
01
The challenge
The client is a national public agency that administers EU funding. Its internal audit function reports to the agency's audit committee, and each programme it audits must be tested against the legislation that governs it.
The work was manual from start to finish. For every programme, an auditor read the programme document, hunted for the relevant provision across more than 20 acts (national laws, ordinances, EU regulations) and entered the findings row by row into a spreadsheet control plan. A plan holds about 330 requirements and took 4-6 working days, with no tooling at all.
Why it mattered
- EU money carries audit risk. If an audit of EU-funded payments misses a legal reference, or relies on an outdated one, the result can be an EU financial correction.
- Legislation never sits still. Ordinances and regulations are amended all the time, and auditing a past period means finding the rule in force on a particular date.
- Expertise lived with individuals. Know-how belonged to specific auditors, and the evidence trail was kept by hand.
- Cloud AI was ruled out. This is sensitive public-sector data, and it has to stay inside the building.
02
What we did
We designed a full AI audit assistant that lives entirely on the client's own infrastructure. There is no cloud, no outside API and no subscription. Our partners, certified internal auditors holding CIA and CGAP credentials, supplied the audit domain expertise.
A legal corpus that stays current
| Source family | Content loaded |
|---|---|
| National legislation | Every law currently in force, a daily check of the state gazette, rulings of the supreme and constitutional courts |
| EU legislation | EUR-Lex and the Official Journal of the EU, case law of the Court of Justice, transposition records, conditionality rules |
| Client documents | All versions of the strategic programme, plus secondary legislation, internal procedures and working papers |
| Audit standards | ISA 315 and 330, COSO, COBIT, the IIA Global Internal Audit Standards, and the methodology of the European Commission and the Court of Auditors |
- Every law, every version. Changes are kept with the date they took effect, and an amendment engine applies the amending acts. The system can therefore say what the rule was on any date you ask about.
- Legal structure, not plain text. Scanned PDFs go through OCR, and articles, paragraphs and points are recognised as legal units instead of being flattened into prose.
- Hybrid retrieval. Graph, vector and full-text search run across the full corpus. Results are fused and re-ranked, using multilingual embeddings.
A specialised model that never leaves the premises
We chose the newest open-weight Gemma model, served on premise. Two adapters specialise it: one for national law, one for internal audit. Both are trained on material from the client and are retrained every quarter. Its instructions require it to answer with legal citations only, to keep to the control-plan format and to admit when it does not know.
No invented answers
Each generated line names its source: article, paragraph and point, plus the gazette issue and date. If a citation cannot be resolved against the corpus, the answer is blocked and never displayed. Each query goes into an immutable log. That one rule turns the output into usable audit evidence, not a draft someone has to check again.
What auditors can do with it
- Generate a control plan. An auditor uploads a programme document and receives a control plan with full citations, in the team's existing spreadsheet template. Three AI agents working in parallel, a lawyer, an auditor and an analyst, give an opinion on every line.
- Check requirements. A side-by-side view shows whether each programme requirement appears in the applicable ordinance.
- Legal references in one click, each one checkable against its source.
- Chat in plain language, with every answer cited.
- Review internal documents and flag clauses that conflict with the law in force.
- Look up history for audits of earlier periods.
Corrections made by auditors flow back into the model. Access depends on role (auditor, manager, admin). There is a REST API, remote access over VPN and a visual timeline showing how each law evolved. We also audited the hardware needs and specified one on-premise AI server, which the client will procure.
Compliance built into the design
| Requirement | How we meet it |
|---|---|
| Data residency | A single server on agency premises. Nothing is transferred to cloud services |
| GDPR | Any personal data in audit files is processed on premise only, under agency control |
| EU AI Act | Traceability, since every output is cited. Human oversight, since auditors approve. Output that cannot be verified is blocked |
| Public-sector security and NIS2 | An isolated server, AI with no internet dependency, access by role, an immutable query log |
| Vendor lock-in | Everything is handed over outright: open-source stack, open-weight model, no subscription |
Stack
| Layer | Designed with |
|---|---|
| Model | Open-weight Gemma 4 plus LoRA adapters, served through vLLM |
| Retrieval | bge-m3 embeddings, a re-ranker and fusion ranking, with ArcadeDB as one store covering bi-temporal, graph, vector and full-text data |
| Documents | MinIO document store, Tesseract OCR with Cyrillic correction |
| Platform | Docker, Redis, REST API, an immutable query log in PostgreSQL, Prometheus and Grafana |
03
The outcome
The numbers below are projections, based on how the agency works today and on benchmarks of the architecture.
| Current process | Assistant in place (projected) | |
|---|---|---|
| A single control plan | 4-6 working days to draft | A generated draft, reviewed in a day |
| Requirements per plan | ~330, entered manually | Extracted, classified and cited by the system |
| Legal references | Hunted down by hand across 20+ acts | Checked against a versioned corpus |
| Audits of past periods | Rebuilding old versions of the text | The rule in force on the audited date |
| Data sent off site | None | None |
- About 80% less auditor time on each control plan.
- Some 330 requirements per plan pulled out, classified and linked to a specific legal provision.
- Audit-grade output on every line: cited, accurate as of the audited date, and blocked when the citation fails verification.
- Audit know-how shifts from individual people into one system the department shares.
- No recurring licence fees and no lock-in to a vendor.
The trap to avoid
Legislation changes weekly. Without automatic gazette monitoring and version history, an AI audit tool goes stale within one quarter and starts giving wrong answers with full confidence.
Built with
The platforms and tools this engagement runs on.
More case studies
Similar problems, measured the same way.

Bulgarian road-construction group · ~300 employees · €100M+ revenue · in-house asphalt, concrete and fuel sites
Road Builder ERM: Fleet, Plants, Sites
- to management reports, instead of 30
- < 1 day
- to management reports, instead of 30
- vehicles, machines and plants managed in one place
- 180
- vehicles, machines and plants managed in one place

Investment group, Europe · €150M IFC sustainability-linked loan carrying ESG covenants
ESG Covenant Compliance Platform
- IFC facility protected by the platform
- €150M
- IFC facility protected by the platform
- scanned documents, now one task register
- 70
- scanned documents, now one task register

University · Italy · among Europe's biggest private universities, multiple branches
Automated Admissions Checks with AI for a University in Italy
- admissions checked every year
- ~20,000
- admissions checked every year
- of applications got right by the robot
- ~90-95%
- of applications got right by the robot







