audit-support

Provide SOX 404 control testing methodology for scoping, sampling, and documenting internal controls.

Updated Apr 16, 2026
One-click install
npx skills add https://github.com/yethikrishna/humble --skill audit-support-yethikrishna
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: audit-support
Source: https://github.com/yethikrishna/humble/tree/main/core/kortix-master/opencode/skills/GENERAL-KNOWLEDGE-WORKER/audit-support
Command: npx skills add https://github.com/yethikrishna/humble --skill audit-support-yethikrishna

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Provides auditors, control owners, and finance teams a clear, repeatable methodology to scope, test, document, and evaluate internal controls for SOX Section 404 so control failures are detected, classified, and remediated consistently.

Core Features & Use Cases

  • Scoping & Risk Assessment: Identify significant accounts, relevant assertions, and control coverage needed to address material misstatement risk.
  • Sample Selection Guidance: Practical methods (random, targeted, systematic, haphazard) and sample size recommendations across frequencies and population sizes.
  • Testing & Evidence Standards: Design vs operating effectiveness testing procedures, acceptable evidence types, and workpaper requirements for defensible conclusions.
  • Deficiency Classification & Remediation: Clear criteria to classify deficiencies, aggregate impacts, root cause analysis, remediation planning, and validation guidance.
  • Control Type Coverage: Guidance for IT General Controls, automated controls, manual controls, IT-dependent manual controls, and entity-level controls.
  • Use Case: Build a testing plan and workpapers for the revenue cycle, select samples, document exceptions, and produce a remediation roadmap for identified deficiencies.

Quick Start

Prepare a SOX 404 testing plan for the revenue recognition process for FY2025 Q4 including scoping, recommended sample selection, test procedures, evidence requirements, and a draft workpaper outline.

Frequently Asked Questions about audit-support

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I select samples for SOX 404 control testing?

Deficiency classification in SOX 404 evaluates control failures by severity, aggregates impacts across controls, performs root cause analysis, and outlines remediation planning with validation guidance to ensure consistent remediation.

What evidence standards are required for SOX workpapers?

SOX workpapers require acceptable evidence types meeting specific documentation standards to support defensible conclusions. Evidence must demonstrate both design and operating effectiveness for the tested internal controls over financial reporting.

How do I scope significant accounts for SOX 404 testing?

Scoping for SOX 404 testing identifies significant accounts, relevant assertions, and required control coverage to address material misstatement risk. This ensures the testing methodology targets financial reporting processes with the highest risk impact.

Does SOX 404 control testing cover IT general controls and automated controls?

SOX 404 control testing covers IT General Controls, automated controls, manual controls, IT-dependent manual controls, and entity-level controls. This ensures comprehensive evaluation of all control types within the internal control framework.

What is the best way to document exceptions found during control testing?

Documenting exceptions during control testing involves recording identified deviations, classifying deficiencies, aggregating impacts, and determining root causes. This documentation feeds directly into the remediation roadmap and validation process.