About

Built by a Big 4 IT auditor who wants to shape the future of auditing.

Why Varða exists

Everywhere I looked, teams were claiming they'd "automated" their compliance work with AI, but scratch the surface and it was usually a chatbot bolted onto the same manual process, producing a report nobody had actually tested against real evidence. The efficiency wasn't real, and neither was the assurance behind it.

That wasn't a guess from the outside. As part of a Three Lines of Defence secondment at a global mining organisation, I spent real audit time specifically assessing generative AI risk and governance: not using AI, auditing it. I saw up close how thin most "AI-powered" claims actually were once you tested them against evidence instead of marketing.

Varða started as an attempt to actually do what everyone else was claiming: build a tool that gathers real evidence before it judges anything, keeps every AI output editable by a human reviewer, and produces a readiness assessment that would genuinely hold up if an auditor checked it properly. Not a faster way to fake your way through an audit: a genuine way to walk into one prepared, at the speed AI makes possible when it's built the right way around.

Background

I'm Cal, currently a Senior Analyst in Risk Advisory at Deloitte, where I work across internal assurance, investigations, control testing, and risk management for clients spanning agriculture, banking, finance, government, mining, superannuation, retail, and telecommunications.

Bachelor's Degree in Accounting and Information Systems, University of Canterbury.

Across all of it, one thing stayed constant: the gap between what a policy document says and what a business actually does in practice is where the real risk lives, and it's the hardest, slowest part of any audit to test properly.

Solo-built, not solo-informed

Varða is built by one person, but it isn't built in a vacuum. Every real design decision in it (evidence gathered before judgement, AI output that's always editable and never final, testing substance over exact wording) comes out of actual conversations with people across the industry, at every level: graduates doing the fieldwork, seniors owning the testing, partners signing off the report. If something in Varða feels obviously right to an auditor, it's probably because an auditor told me it needed to work that way.

Where things stand today

Varða is early. It's one person, built off real audit experience rather than a large product team, which means it moves fast and stays close to how audits actually get done, but it also means being upfront: this is a young product from a founder still doing the work full-time, not a large vendor with a support desk. If that's the kind of partner you're looking for (someone who understands the work because they've done it, not just sold it), that's exactly what Varða is.

Curious whether Varða fits your compliance program?

Tell us which framework you're working against and we'll talk it through.

Get in Touch → Try It Yourself