CORAA
Questions

The kind we answer before you ask them.

Everything Indian CA firms ask us about Coraa, covered. If something's missing, write to audit@coraa.ai and we'll add it.

About Coraa

About Coraa for Indian audit.

Coraa is an AI-native audit engine designed for professional CA firms in India. We automate ledger scrutiny, vouching, reconciliation, working papers, and audit workflows, moving you from 2% sampling to 100% population coverage while preserving full audit control.
Coraa is audit-native, not a generic chatbot. Built for auditors: understands ledgers, vouchers, GST, TDS, Companies Act. 100% population testing, not samples. Audit-ready outputs: generates working papers, not chat threads. India-hosted, DPDPA-aligned: client data never leaves India. Full audit trail: every action logged, every working reproducible. No model training on your data: client data is never used to train any model.
Coraa runs across the whole engagement. Scrutiny: full-population ledger analysis, journal entry testing, cut-off checks. Vouching: automated invoice matching, OCR, mismatch detection. Reconciliation: GST · TDS · TCS, ITC validation, threshold checks. Working papers: AR/AP ageing, fixed asset schedules, custom templates. Procedures: SA 320 materiality, SA 530 sampling, SA 570 going concern. Findings & Reporting: CARO 2020, Form 3CD, Schedule III, SA 700 opinion.
Getting started

Getting started in minutes, not weeks.

Click Start Free Trial, we set up your firm, connect your data room, and you can run a full scrutiny on a live engagement. We also offer guided live demos.
No. Coraa fits inside your existing workflow. You continue using your firm's methodology and templates, Coraa automates the repetitive parts (extraction, matching, analysis). Judgement and sign-off stay with you.
Most firms are running in 5–10 minutes. For larger firms wanting custom templates or live ERP integration, onboarding typically completes in 1–2 days.
Excel, CSV, PDF vouchers, scanned invoices, and direct exports from Tally, Zoho, SAP, NetSuite, Busy, Marg. We parse and structure automatically, no manual reformatting required.
Data security & compliance

Data security & compliance by architecture.

Yes. Coraa follows enterprise-grade security. India-hosted: AWS ap-south-1 (Mumbai), never leaves Indian soil. Encryption: AES-256 at rest, TLS 1.3 in transit. Workspace isolation: each firm in a separate environment. No AI training: your data is never used to train models. Certified: ISO 27001:2022 (SOC 2 Type II in progress), DPDPA & GDPR aligned. Deletion on demand: you can purge all data at any time.
Yes, fully aligned with India's Digital Personal Data Protection Act 2023. All data resides in India, segregated by engagement, with full audit trails and deletion controls. We never share client data without authorisation.
Yes. Role-based access, full audit trails, cryptographic provenance. Firms run statutory audits, tax audits, and internal audits of listed companies on Coraa today.
As long as you need. You control retention; we recommend matching your firm's standard policy (typically 7–10 years for audit documentation), but deletion is one click.
Coraa runs on open-source LLMs, hosted and served entirely on India-based infrastructure — never a shared public API and never a foreign-hosted endpoint. The proprietary part is Coraa's own patent-pending (filed in India and via PCT) deterministic execution layer that wraps those models, so the same ledger against the same standards produces the same, byte-identical output every time. The models are open-source; the reproducibility engine is Coraa's own IP.
Yes. The standard Coraa subscription agreement includes a DPDPA-compliant Data Processing Agreement, and our sub-processor list and technical and organisational measures are published at trust.coraa.ai — you're welcome to share either with your clients as part of your own vendor due diligence.
Yes. Coraa ships nine standard roles that scope article assistants, audit managers and partners to specific engagements, and clients get a separate, limited Client Portal view via magic-link, never the full workspace. Every action, regardless of role, is logged per SA 230.
Features & capabilities

Features & capabilities every working shown.

Instead of sampling 2–10% of transactions, Coraa tests 100% of the ledger. Every voucher, every entry, reducing sampling risk and standing up under peer review.
Yes. The Reconciliation hub matches books vs GSTR-2A/2B/3B, flags ITC mismatches under Rule 36(4), validates TDS deductions, checks Section 17(5) blocks, and generates reconciliation working papers, vendor-level, with short/excess deduction calls.
Yes, audit-ready: AR/AP ageing with MSMED split, fixed asset schedule, depreciation workings, TDS classification, AS 3 / Ind AS 7 cash flow. Use Coraa's templates or upload your firm's.
Yes. 100+ pre-built templates, plus full support for your firm's own formats. Working Papers, Form 3CD, CARO 2020, Schedule III, Independent Auditor's Report, all renderable in your branding.
Yes. Live connector for Tally Prime, OAuth for Zoho Books, Excel for SAP S/4HANA, NetSuite, Busy, Marg. MS Dynamics and QuickBooks coming.
Coraa's engine only ever suggests, it never auto-confirms a classification, a flag, or a conclusion into the audit file. Every ledger classification and every finding is presented for the auditor's explicit accept or override before it becomes part of the working papers. What Coraa removes is the manual first pass across 100% of transactions; the professional judgement SA 200 requires stays with you.
Yes. Every flag cites the specific rule or standard it fired on, and the Findings Inbox lets the audit team Resolve, Dismiss, or Pin any finding for partner attention, with a comments thread for the team's reasoning attached. Nothing is a black box.
Coraa covers the full sequence, not just analysis. The Reporting module drafts Schedule III financials with Notes, the CARO 2020 report clause by clause (all 21 clauses), Form 3CD (44 clauses), and the Independent Auditor's Report itself under SA 700, gated by a seven-step UDIN sign-off. You don't need separate documentation software behind it.
No live OTP session needed. Coraa works from the GST portal exports your client or their GST practitioner already has — GSTR-2A, 2B, 3B and 1 as PDFs, JSON, or Excel downloads, across every GSTIN — and merges them into one canonical reconciliation. Nobody has to hand over portal access or share an OTP to run it.
Pricing & plans

Pricing & plans priced like a tool, not a seat.

CORAA starts with a 10-entity audit pack at ₹30,000 list price, which works out to ₹3,000 per audit. All users are included, with no per-seat charges.
Yes — your first audit is free. Run a real audit before committing.
Every module, all features. Unlimited users. the digital twin of the books, OCR vouching, GST/TDS/TCS reconciliation, full working paper pack, Form 3CD, CARO 2020, Schedule III, SA 700 opinion. Onboarding and support included.
Yes. Additional entities are charged at your tier's per-entity rate, prorated.
No. Every plan includes unlimited users, your articles, managers and partners all get seats at no extra cost. Pricing scales only with the number of client entities you audit, never with headcount.
No, not on their own. An entity is one legal entity for one financial year, so a single company with multiple branches or GSTINs under one PAN/CIN still counts as one entity. Separate legal entities, subsidiaries, or group companies each count separately, even if they share a promoter.
Technical & support

Technical & support humans who answer.

No. Built for auditors, not IT teams. If you can use Excel and email, you can use Coraa. We provide training and white-glove onboarding.
Email (audit@coraa.ai), live chat during business hours, video tutorials, and a dedicated success manager for firm plans. Typical response time under 4 hours.
Yes. Each client gets a dedicated, isolated data room. Switch instantly; audit trails stay separate per engagement.
Yes, web-based, works on any browser. Desktop, laptop, tablet, or mobile.
Audit standards

Audit standards by chapter and verse.

Yes. Built on Ind AS, AS, Companies Act 2013, the GST framework, and the Income Tax Act. The engine understands ledger structures, section thresholds, and statutory reporting logic specific to India.
Yes. Statutory, tax, internal audits, limited reviews, all supported with complete documentation, audit trails, and evidence linking.
Yes. Professional audit documentation with full audit trails, source references, and confidence scores. Meets ICAI documentation standards and stands up to peer review.
No. Coraa is an engine, not a replacement. It automates the repetitive parts, judgement, professional skepticism, and UDIN-gated sign-off remain with you.
ICAI doesn't run a formal approval or certification scheme for third-party audit software, so no vendor, Coraa included, can truthfully claim ICAI approval as a status. What Coraa does is align to the substance of what ICAI issues: the Standards on Auditing, ICAI's Standards on Internal Audit, and SA 230 documentation requirements. Using Coraa doesn't change your obligations under your engagement letter, the professional judgement and sign-off stay yours.
Still curious

We'd rather show you the working.

Run your first audit free
FAQ · CORAA AI Native Audit Engine | CORAA