
Audro
Audro is an AI agent for Swedish statutory audit. It runs the engagement from SIE file to sign-off, covering risk assessment, sampling, cut-off, VAT and F-skatt checks, while the licensed auditor approves every decision.
What is Audro?
Audro is an AI agent built for Swedish statutory audit, published by Audro Technologies AB in Stockholm. Its stated division of labour is blunt: the agent does the grunt work, the auditor keeps the judgement and the signature.
The tool drives a complete engagement from the SIE file to sign-off, planning, testing and documenting as it goes. Work begins by connecting the client, pulling the SIE file and supporting documents straight from Fortnox or uploading them manually. Audro then analyses the accounts, flags risk items against the materiality threshold and proposes an audit plan. Nothing is tested until that plan is approved. Once it is, the agent carries out substantive testing along the plan: cut-off checks, audit sampling that follows the standards, invoice-to-voucher matching, and VAT and F-skatt controls, with every finding backed by audit evidence. The auditor then reviews the findings, approves or rejects each one, and exports finished working papers into the engagement file.
Underneath sit six building blocks: automated SIE parsing, a configurable sampling methodology, automatic invoice matching, risk and anomaly detection against the firm's own rules, systematic VAT and periodisation checks, and full evidence traceability. Judgements are anchored in a knowledge base of ISA standards retrieved while the agent works, rather than in whatever a general-purpose model happens to remember, and an append-only register records what was examined, why a conclusion was reached and which standard was applied.
The design is deliberately interruptible. The agent proposes rather than acts, and material judgement calls, such as materiality, policy choices and requests for client documents, pause and wait for the auditor. Requests to the client are sent from the auditor's own Microsoft 365 mailbox rather than a shared vendor inbox.
The scope is narrow and openly so: K2 and K3 frameworks, SIE files, Swedish VAT and F-skatt, and the Swedish business register. Access is through a browser at app.audro.se, with roles for organisation admin, company admin and member. There is no API, no mobile application and no published price, so evaluation starts with a demonstration.
What it does
- Run a complete Swedish audit engagement from SIE file to sign-off
- Assess risk against the materiality threshold and propose an audit plan for approval
- Perform substantive testing: cut-off checks, audit sampling, invoice matching, VAT and F-skatt controls
- Match every transaction to its supporting document automatically
- Trace each conclusion back to its evidence and to the standard applied
- Send client document requests from the auditor's own Microsoft 365 mailbox
- Export finished working papers into the engagement file
When to use Audro / When not to
A quick filter to help you decide if Audro is the right fit.
When to use Audro
- Swedish audit firms running K2 and K3 engagements for small and mid-sized companies
- Authorised auditors who sign off on SME accounts and want the substantive testing prepared for them
- Independent, sole-practitioner auditors working without a large support team behind them
- Financial controllers carrying out internal audit work inside their own organisation
- Audit teams already working from SIE files and Fortnox ledgers
When not to use Audro
- Auditors working outside Sweden: the tool is built on SIE files, K2 and K3, Swedish VAT and F-skatt, with no other national framework announced
- Firms that need an API or an on-premise deployment, since Audro is a browser-only web application
- Anyone hoping for a fully autonomous audit: the workflow deliberately stops for human approval and the vendor rejects the autopilot framing
- Buyers who require a published price, standard terms of service and a self-serve sign-up before they will evaluate a vendor
- Procurement teams that insist the vendor itself hold SOC 2 or ISO 27001, because Audro holds no certification of its own
How to use Audro
A typical end-to-end flow, from setup to results.
- Request a demonstration: there is no self-serve sign-up, so access starts with a conversation with the vendor
- Sign in to the web application at app.audro.se; nothing is installed locally
- Distribute roles across the firm: organisation admin, company admin and member
- Connect the client, pulling the SIE file and supporting documents from Fortnox, or upload them yourself
- Let Audro analyse the accounts and flag risk items against your materiality threshold
- Review the proposed audit plan and approve it, since nothing is tested until you do
- Let the agent run the substantive testing: cut-off, sampling, invoice matching, VAT and F-skatt controls
- Answer the judgement calls the agent pauses on, such as materiality, policy choices and client requests
- Send document requests to the client through your own Microsoft 365 mailbox
- Go through the findings, approve or reject each one, then export the finished working papers to the file
Pros & Cons
Pros
- Auditor-in-the-loop is structural rather than cosmetic: nothing runs before you approve the plan, and judgement calls pause the workflow
- Every conclusion is traceable from finding to evidence to the standard applied, in an append-only register
- Judgements are grounded in a retrieved ISA standards base rather than in what a general model happens to recall
- Customer data is never used to train models and never written into the knowledge base, stated consistently across three pages
- Tenant isolation is enforced in the database itself with PostgreSQL row-level security, not only in application code
- Security and data protection documentation is unusually detailed: eight named sub-processors, described data flows and a DPA on offer
- Data is stored in the EU by default, with a US region available on request
Cons
- No published pricing whatsoever: no amount, no tier, no plan, and the only way in is a demonstration
- No terms of service, no formal privacy policy and no legal notice; the site is five pages and every legal route returns a 404
- No postal address is published anywhere: the footer gives only the city, Stockholm
- No API, no mobile application and no self-serve sign-up, so access is browser-only
- Audro holds no certification of its own; the SOC 2 and ISO 27001 badges belong to its suppliers, as the site itself makes clear
- AI inference can leave the EU, since the vendor states there is no EU-bounded data zone today for the Claude models it runs
- A very young and very small vendor: the domain was registered in November 2025, there is no web archive history, and the Swedish register lists a single board member and no employees
Pricing & Plans
Audro publishes no pricing. There is no pricing page, and no amount, currency or billing unit appears anywhere on the site or in its application bundle. Neither a permanent free plan nor a free trial is announced. Commercial terms are obtained by requesting a demonstration; the only other entry point on the site is the sign-in screen reserved for existing customers.
Data, GDPR & hosting
A consolidated view of how Audro handles your data.
GDPR overview
GDPR is addressed explicitly, and in unusual detail for a company of this size. The homepage states that Audro complies with GDPR, and a dedicated Data protection and GDPR page, last updated June 2026, sets out the controller and processor split, names eight sub-processors with their purpose, the data they touch and their certifications, and describes how client data flows. A data processing agreement is available to every customer, and Audro undertakes to notify customers before adding or replacing a sub-processor so they can object. International transfers are covered by appropriate safeguards including the EU Standard Contractual Clauses. Data subject requests are handled by the client firm as controller, with Audro supplying the access, export, rectification and deletion functions needed to answer them. Breaches are notified without undue delay. No Article 27 representative is named, which is consistent, since the publisher is established in Sweden.
Who owns the data?
Your firm keeps ownership of everything it puts into Audro. On the published data protection page, the client firm is the data controller and Audro Technologies AB acts only as processor, working on documented instructions. Audro states it processes engagement data solely to produce the result you asked for, and for no independent purpose of its own. Customer data is never used to train AI models and is never written into the vector knowledge base, which holds public ISA standard text only. Embeddings of your own documents stay inside Audro's database. A data processing agreement is offered to every customer.
Reuse rights
Audro publishes no terms of service, so no contractual clause states what you may do with the output. What the data protection page does establish is that the material remains yours: your firm instructs Audro, and Audro's use is confined to producing your result. Finished working papers are exported into your own engagement file, client document requests leave from your own Microsoft 365 mailbox rather than a shared vendor inbox, and access, export, rectification and deletion functions are provided so that you can answer data subject requests as controller. Nothing on the site restricts your reuse of what you export, but nothing grants it in writing either.
Data retention & training
Hosting summary
Audro stores data in the EU by default. The database, authentication and file storage run in an EU region of Supabase, which itself runs on AWS, while the application and processing services run in an EU region of Railway. A US region is available on request for customers who require it. No individual hosting country is ever named: the site speaks in regions rather than jurisdictions. Data is encrypted with AES-256 at rest and TLS in transit, keys are managed by the platform and never exposed to application code, and tenants are separated by PostgreSQL row-level security so a query can only return rows the signed-in user is entitled to. AI inference is a separate matter: it runs on Microsoft Azure, and the page describing where that data rests still carries an unfilled template placeholder. Embeddings of customer documents stay in Audro's own database and are never placed in an external vector service, which holds public standards text only.
Where Audro works
Country-level availability.
Available in
Things to keep in mind
Risks and trade-offs to weigh before adopting Audro.
- Professional responsibility cannot be delegated: the promise that the decisions stay yours is a design principle, not a published contractual guarantee, and the signing auditor still carries the liability
- Automation bias is the real human risk: a neatly prioritised list of findings is easy to approve without re-reading, and the file that results carries your signature
- AI inference may be processed outside the EU even though the data is stored inside it, and Microsoft may retain a sample of content for abuse monitoring
- The data protection page still displays an unfilled template placeholder where the Azure geography of data at rest should appear, which suggests the page has not been fully finished
- With no terms of service and no privacy policy published, contractual protection rests entirely on a data processing agreement negotiated case by case
- The vendor holds no security certification of its own, and every SOC 2 or ISO 27001 mentioned covers only a supplier's processing, not Audro's
- Supplier concentration risk: a company registered in early 2026 with one board member and no declared employees would be holding a firm's most sensitive client material
Setup & Integrations
Technical difficulty
Low for the end user, but not self-serve. Audro is a web application, so there is nothing to install or deploy. Getting started means connecting Fortnox to pull SIE files and supporting documents, or uploading them by hand, granting Microsoft 365 access by OAuth so client requests leave from the auditor's own mailbox, and distributing three roles across the firm. There is no public technical documentation and no installation guide, because there is no self-serve route: accounts are opened after a demonstration. The real prerequisite is professional rather than technical.
Deployment
Integrations
Behind Audro
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
Does Audro replace the auditor?
Which accounting frameworks does Audro work with?
How does accounting data get into the tool?
Is my data used to train AI models?
Where is the data hosted?
Is a data processing agreement available?
Is Audro itself SOC 2 or ISO 27001 certified?
What does Audro cost?
Is there an API or a mobile application?
Should you pick Audro?
Audro is a narrow tool that knows exactly how narrow it is. It targets Swedish statutory audit and nothing else: SIE files, K2 and K3, Swedish VAT and F-skatt, the Swedish business register and a Fortnox connector. Within that scope, the proposition rests on three things a firm can actually check. The auditor stays in command, because the agent proposes a plan and stops at every judgement point. Every conclusion carries its trail, from the finding to the evidence to the standard applied, in an append-only register. And customer data is never used to train models, a claim repeated on three separate pages and backed by a knowledge base that holds public standards text only.
The security and data protection writing is genuinely detailed, and unusually honest about its own limits: the vendor names its eight sub-processors, describes how data flows, states plainly that the SOC 2 and ISO 27001 badges belong to its suppliers rather than to itself, and admits that AI inference may be processed outside the EU because no EU-bounded data zone exists today for the models it uses.
Against that sits a thin commercial surface. There is no published price, no terms of service, no privacy policy, no postal address, no founding date, no API and no team page. The publisher is very young: the domain was registered in late 2025, the site has no web archive history, and the Swedish register shows a single board member and no declared employees. None of that makes the product weak, but it does mean the site alone cannot settle the question. A firm evaluating Audro will have to go through the demonstration and a contractual review, and weigh the supplier risk of entrusting its most sensitive client material to a company this new.
- Choosing a selection results in a full page refresh.
- Opens in a new window.