audit-support

Generate SOX 404 control testing workpapers with documentation templates.

23|2|Updated Feb 10, 2026
One-click install
npx skills add https://github.com/luisschmitzheadline/VC-Skills.md --skill audit-support-luisschmitzheadline
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: audit-support
Source: https://github.com/luisschmitzheadline/VC-Skills.md/tree/main/knowledge_skills/due_diligence/kwp-audit-support
Command: npx skills add https://github.com/luisschmitzheadline/VC-Skills.md --skill audit-support-luisschmitzheadline

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

SOX 404 compliance workflows require structured testing documentation, sample selection, and deficiency classification. This skill provides methodology, templates, and best practices to create evidence-rich workpapers and compliant deliverables.

Core Features & Use Cases

  • SOX 404 control testing methodology
  • Sample selection approaches and documentation standards
  • Use cases: generate testing papers and classify deficiencies, prepare for audits

Quick Start

Draft a complete SOX 404 testing workpaper for a selected control, including scope, procedures, and evidence expectations.

Frequently Asked Questions about audit-support

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I document SOX 404 control testing workpapers for ICFR compliance?

SOX 404 control testing documentation requires standardized workpapers covering scope, procedures, sample selection, and evidence expectations. This methodology ensures compliant deliverables and evidence-rich workpapers for ICFR audits.

What is included in a SOX 404 scoping and risk assessment methodology?

SOX 404 scoping and risk assessment methodology covers identifying significant accounts, evaluating assertions, and determining necessary ITGCs and entity-level controls. This process ensures proper focus on critical financial reporting areas during compliance testing.

How do I classify control deficiencies found during SOX testing?

Classifying SOX control deficiencies involves evaluating testing failures against established criteria within the evaluation and reporting phase. The methodology provides structured guidance to distinguish deficiency types and plan necessary remediation actions.

Does this SOX testing guidance cover ITGCs and entity-level controls?

Yes, this SOX testing guidance explicitly aligns with ITGCs and entity-level controls alongside process-level testing. It applies comprehensive testing methodologies across all control types to satisfy ICFR compliance requirements.

What is the best way to select samples for SOX control testing procedures?

Selecting samples for SOX control testing is best handled using standardized sample selection approaches provided in the methodology. These approaches define documentation standards to ensure samples are statistically valid and meet evidence requirements.

How do I create a remediation plan for identified SOX compliance deficiencies?

Creating a remediation plan for SOX deficiencies involves documenting identified issues and outlining corrective actions within the evaluation and reporting phase. The methodology provides structured templates to guide remediation planning and track resolution.