internal-control-framework

Design COSO-aligned internal controls and audit-scope items for GRC workflows.

2|1|Updated Mar 8, 2026
One-click install
npx skills add https://github.com/duggal1/Sapphire-cli --skill internal-control-framework
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: internal-control-framework
Source: https://github.com/duggal1/Sapphire-cli/tree/main/skills/audit-report/.claude/skills/internal-control-framework
Command: npx skills add https://github.com/duggal1/Sapphire-cli --skill internal-control-framework

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

The Internal Control Framework delivers a structured guide for designing COSO-based internal controls to support audit scope development and control validation, clarifying the link between control objectives and testing artifacts.

Core Features & Use Cases

  • COSO component templates (Control Environment, Risk Assessment, Control Activities, Information/Communication, Monitoring)
  • Guidance for scope definition, control item creation, and evidence collection
  • Use Case: develop an audit scope for a mid-size organization implementing COSO-based controls across finance, IT, and operations

Quick Start

Create an initial COSO-aligned audit scope and populate the corresponding control items template with required evidence.

Frequently Asked Questions about internal-control-framework

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I design COSO-aligned internal controls for an audit scope?

Design COSO-aligned internal controls by using structured templates for the five COSO components—Control Environment, Risk Assessment, Control Activities, Information/Communication, and Monitoring—to define audit scope items and link control objectives to testing artifacts.

What is included in a COSO internal control framework for risk assessments?

A COSO internal control framework for risk assessments includes component templates covering the control environment, risk assessment, control activities, information and communication, and monitoring, along with guidance for control item creation and evidence collection.

Can I use this internal control framework for IT and operations audits?

Yes, you can use this internal control framework to develop audit scopes and populate control testing items across finance, IT, and operations for mid-size organizations implementing COSO-based governance, risk, and compliance workflows.

How do I create control testing evidence templates for internal audits?

Create control testing evidence templates by populating the corresponding control items template with required evidence, linking each testing method directly to its COSO framework control objective for validation.

What's the best way to structure control activities for compliance workflows?

The best way to structure control activities for compliance workflows is to map them within a COSO-aligned framework that documents requirements across all five components, ensuring each control activity has defined testing methods and evidence templates.

Do I need prior COSO knowledge to define an internal control audit scope?

No prior COSO knowledge is strictly required to define an internal control audit scope, as the framework provides structured templates and guidance for scope definition, control item creation, and evidence collection across governance, risk, and compliance processes.