audit-support

Standardize SOX 404 ICFR control testing, sampling, and deficiency classification.

2|1|Updated Apr 3, 2026
One-click install
npx skills add https://github.com/GACLove/feishu-aily-skills --skill audit-support-gaclove
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: audit-support
Source: https://github.com/GACLove/feishu-aily-skills/tree/main/skills/audit-support
Command: npx skills add https://github.com/GACLove/feishu-aily-skills --skill audit-support-gaclove

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Expedites the design, documentation, and execution of SOX 404 ICFR testing by standardizing risk scoping, control identification, and evidence collection to produce defensible workpapers.

Core Features & Use Cases

  • Risk-based scoping and control identification for ICFR across significant accounts.
  • Flexible sampling approaches (random, targeted, systematic, haphazard) with documented rationale and sample size guidance by frequency (annual, quarterly, monthly, weekly, daily).
  • Comprehensive testing documentation standards covering test design, execution, evidence, and remediation planning, aligned to ITGCs, automated, manual, IT-dependent manual, and entity-level controls.
  • Evidence management and deficiency classification to support remediation planning and governance reporting.

Quick Start

Define significant accounts and risks for the period, identify applicable controls, and begin documenting testing workpapers using the standard framework.

Frequently Asked Questions about audit-support

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I document SOX ICFR control testing workpapers efficiently?

You can document SOX ICFR control testing by applying standardized frontmatter metadata, test design frameworks, and evidence collection standards to generate defensible workpapers for external audits.

What sampling methods should I use for SOX 404 control testing?

SOX 404 control testing supports random, systematic, targeted, and haphazard sampling methods, with sample size guidance determined by control execution frequency such as daily, weekly, monthly, quarterly, or annual.

How does deficiency classification work in ICFR audit programs?

Deficiency classification in ICFR audit programs evaluates identified control failures to categorize severity, directly supporting remediation planning and comprehensive governance reporting for management review.

Can I test ITGCs and entity-level controls using the same SOX framework?

Yes, a single SOX testing framework covers ITGCs, automated controls, manual controls, IT-dependent manual controls, and entity-level controls, applying standardized test design and evidence standards across all control types.

What is risk-based scoping for SOX significant accounts?

Risk-based scoping for SOX significant accounts identifies applicable financial risks and associated controls across the period, ensuring testing efforts prioritize controls that mitigate material misstatement risks effectively.

What evidence standards are required for SOX remediation planning?

Evidence standards for SOX remediation require documented test execution results, deficiency classification details, and targeted remediation actions to validate control improvements and support quarterly governance reporting.