audit-support

Document and execute SOX 404 ICFR testing workflows with workpapers and deficiency classification.

1|Updated Mar 19, 2026
One-click install
npx skills add https://github.com/cy-wali/knowledge --skill audit-support-cy-wali
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: audit-support
Source: https://github.com/cy-wali/knowledge/tree/main/finance/skills/audit-support
Command: npx skills add https://github.com/cy-wali/knowledge --skill audit-support-cy-wali

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill assists internal auditors and finance teams in documenting and executing SOX 404 ICFR testing workflows, including testing workpapers, sample selection, control deficiency classification, and audit readiness. It clarifies that it does not provide audit or legal advice and emphasizes proper professional review.

Core Features & Use Cases

  • SOX 404 testing methodology guidance: Define scoping, risk assessment, control identification, testing design, evaluation, and reporting.
  • Documentation standards: Provides templates and guidance for evidence collection, walkthroughs, test design, and conclusions.
  • Deficiency classification & remediation planning: Helps classify deficiencies (deficiency, significant deficiency, material weakness) and outline remediation steps.
  • Use Case: Prepare for internal or external audits by generating consistent, well-supported testing workpapers across significant accounts such as revenue, inventory, or close processes.

Quick Start

Generate a SOX 404 ICFR testing workpaper outline for the current period, including scoping, risk assessment, testing procedures, and deficiency documentation.

Frequently Asked Questions about audit-support

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I document SOX 404 ICFR testing workpapers for significant accounts?

SOX 404 ICFR control deficiencies are classified as a deficiency, significant deficiency, or material weakness. This classification determines the required remediation planning steps and governance reporting for the financial close process.

What is the best way to design a sampling strategy for SOX internal controls testing?

Designing a sampling strategy for SOX internal controls testing involves applying testing methodology guidance to evaluate risk assessment and control identification. It ensures consistent evidence collection and supports audit readiness across significant accounts.

Does the SOX testing guidance provide professional audit or legal advice?

No, the SOX testing guidance does not provide professional audit or legal advice. It emphasizes that proper professional review is required for all generated testing documentation, evidence collection, and deficiency classification outputs.

What are the limitations of using automated templates for SOX compliance testing?

Automated templates for SOX compliance testing require proper professional review and do not replace official audit or legal advice. They serve to streamline documentation and deficiency classification but necessitate human evaluation for governance reporting.