compliance-advisor

Plan and document J-SOX and SOX internal controls with COSO (2013) RCMs.

5|4|Updated Nov 9, 2025
One-click install
npx skills add https://github.com/takusaotome/claude-skills-library --skill compliance-advisor
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: compliance-advisor
Source: https://github.com/takusaotome/claude-skills-library/tree/main/skills/compliance-advisor
Command: npx skills add https://github.com/takusaotome/claude-skills-library --skill compliance-advisor

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes assets (resource) and references (resource) components.

What problem does it solve?

This Skill helps you design, evaluate, and audit internal controls for financial reporting compliance, including J-SOX/SOX requirements and risk control matrix (RCM) creation, so you can produce defensible documentation and remediation plans.

Core Features & Use Cases

  • J-SOX/SOX Compliance Support: Guides scoping, control design/effectiveness evaluation, operating effectiveness testing, and deficiency classification (Control Deficiency / Significant Deficiency / Material Weakness).
  • RCM (Risk Control Matrix) Development: Structures process objectives, inherent risks, control mapping, key control identification, and residual risk reasoning using COSO (2013).
  • Risk-Based Internal Audit Planning: Helps define the audit universe, score/prioritize auditable areas, draft an annual audit plan, and outline audit programs and reporting.
  • Regulatory Response Planning: Supports gap analysis for new regulations, builds remediation roadmaps, and establishes monitoring and follow-up.

Quick Start

Provide your company’s target framework (J-SOX or SOX), the financial reporting scope (significant accounts/processes/locations), and the process you want to document so this Skill can guide scoping, RCM construction, and internal audit planning steps.

Frequently Asked Questions about compliance-advisor

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I build a risk control matrix for J-SOX compliance?

To build a risk control matrix for J-SOX compliance, structure process objectives, inherent risks, control mappings, and key control identification using COSO 2013 principles. This Skill guides residual risk reasoning and RCM development with bilingual templates for defensible documentation.

What is the process for classifying SOX internal control deficiencies?

Classifying SOX internal control deficiencies involves evaluating control design and operating effectiveness to categorize findings as Control Deficiency, Significant Deficiency, or Material Weakness. This Skill guides the evaluation workflow and produces structured remediation plans for financial reporting processes.

Can I use COSO 2013 for risk-based internal audit planning?

Yes, you can use COSO 2013 for risk-based internal audit planning by defining the audit universe, scoring and prioritizing auditable areas, and drafting an annual audit plan. This Skill helps outline audit programs and reporting structures aligned with your financial reporting scope.

What do I need to start SOX scoping and documentation?

To start SOX scoping and documentation, provide your target framework, financial reporting scope including significant accounts and locations, and the specific process you want to document. This enables guided scoping, RCM construction, and internal audit planning steps.

Does this support regulatory gap analysis and remediation planning?

Yes, this supports regulatory gap analysis and remediation planning by analyzing new regulations, building remediation roadmaps, and establishing monitoring and follow-up. It applies structured workflow execution across compliance and regulatory gap remediation tasks.

Are there limitations when testing operating effectiveness for SOX controls?

Testing operating effectiveness for SOX controls requires structured workflow execution across compliance, RCM development, and audit planning. Limitations arise if your financial reporting scope, significant accounts, or target framework details are not clearly defined before starting the evaluation.