audit-support

Guide SOX 404 control testing, sample selection, and documentation standards.

Updated Feb 6, 2026
One-click install
npx skills add https://github.com/lohasle/knowledge-work-plugins --skill audit-support-lohasle
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: audit-support
Source: https://github.com/lohasle/knowledge-work-plugins/tree/main/finance/skills/audit-support
Command: npx skills add https://github.com/lohasle/knowledge-work-plugins --skill audit-support-lohasle

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill streamlines SOX 404 compliance by providing a structured methodology for control testing, sample selection, and documentation, simplifying audit preparation.

Core Features & Use Cases

  • Control Testing Methodology: Guides users through the steps of SOX 404 compliance, from scoping to reporting.
  • Sample Selection: Offers various methods (random, targeted, haphazard, systematic) for selecting audit samples based on risk and population characteristics.
  • Documentation Standards: Details workpaper requirements, evidence standards, and organizational best practices for audit documentation.
  • Deficiency Classification: Helps classify control deficiencies as deficiencies, significant deficiencies, or material weaknesses.
  • Use Case: When preparing for an internal audit, use this Skill to understand the required documentation for control testing and to select an appropriate sample of transactions for testing accounts payable controls.

Quick Start

Guide me through the process of testing the design effectiveness of a key control for SOX 404 compliance.

Frequently Asked Questions about audit-support

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prepare for SOX 404 compliance testing?

SOX 404 compliance preparation requires a structured methodology for control testing, from scoping to reporting. You must guide the process by selecting appropriate audit samples, documenting workpapers, and mapping assertions to evaluate internal controls over financial reporting.

What is the best way to select samples for internal audit testing?

Sample selection for internal audit testing depends on risk and population characteristics. You can choose from random, targeted, haphazard, or systematic sampling methods to ensure your control testing accurately represents the financial reporting population.

How are control deficiencies classified in SOX audits?

Control deficiencies in SOX audits are classified based on severity as either deficiencies, significant deficiencies, or material weaknesses. This classification determines the impact on internal control over financial reporting and required audit disclosure.

What documentation standards are required for SOX audit workpapers?

SOX audit workpapers must meet specific documentation standards detailing evidence requirements and organizational best practices. Proper documentation proves the design effectiveness and operational testing of internal controls over financial reporting.

Can I use this methodology for risk assessment and assertion mapping?

Yes, risk assessment and assertion mapping are core components of this SOX compliance methodology. They align financial reporting risks with specific control tests to ensure comprehensive evidence requirements are met during the audit.

When do I need to test design effectiveness for internal controls?

Testing design effectiveness for internal controls is needed when preparing for internal or external audits under SOX 404. It verifies that controls are properly designed to prevent material misstatements in financial reporting before testing operational effectiveness.