audit-readiness
Prepare for internal and external audits with SOX 404 control testing, sample selection, workpaper documentation, and deficiency evaluation. Use for SOX compliance, control testing methodology, audit sample selection, audit workpaper preparation, control deficiency classification, material weakness evaluation, ITGC testing, remediation tracking, or audit evidence standards.
What this skill does
## SOX 404 Testing Lifecycle ### End-to-End Phases 1. **Scoping:** Determine which accounts and processes carry enough risk to warrant control coverage 2. **Risk evaluation:** Assess the probability and magnitude of potential misstatement for each in-scope account 3. **Control mapping:** Document the specific controls that mitigate each identified risk 4. **Effectiveness testing:** Evaluate whether controls are properly engineered (design) and consistently executed (operation) 5. **Deficiency assessment:** Judge the severity of any control gaps uncovered during testing 6. **Management reporting:** Formalize the overall ICFR assessment and disclose any material weaknesses ### Determining Which Accounts Are In Scope An account enters scope when it carries a non-remote probability of containing a misstatement that is material on its own or in combination with others. **Size-based indicators:** - The balance surpasses the quantitative materiality benchmark (commonly 3-5% of a reference figure such as revenue, assets, or pre-tax income) - High transaction throughput increases the statistical likelihood of error - The balance depends heavily on estimates or management judgment **Risk-based indicators:** - The accounting is inherently complex (multi-element revenue arrangements, derivative instruments, pension obligations) - The account is a common fraud target (cash, revenue, related-party activity) - Historical audit adjustments or prior restatements have affected the account - Significant management estimates or subjective assumptions underlie the balance - The account or process is new, or has undergone material change ### Financial Statement Assertions by Account Category | Account Category | Primary Assertions to Address | |---|---| | Revenue | Occurrence, Completeness, Measurement, Period allocation | | Trade receivables | Existence, Valuation (reserve adequacy), Ownership rights | | Inventory | Existence, Valuation, Completeness | | Property & equipment | Existence, Valuation, Completeness, Ownership rights | | Trade payables | Completeness, Measurement, Existence | | Accrued obligations | Completeness, Valuation, Measurement | | Shareholders' equity | Completeness, Measurement, Presentation | | Close & reporting process | Presentation, Measurement, Completeness | ### Design vs. Operating Effectiveness **Design effectiveness** asks: Is the control architected to intercept or surface a material misstatement in the targeted assertion? - Assessed via end-to-end walkthroughs (trace a representative transaction through the full process) - Confirm the control sits at the correct process juncture - Confirm the control directly addresses the specified risk - Re-evaluate at least annually, or whenever the process changes **Operating effectiveness** asks: Has the control actually functioned as intended across the entire period under review? - Assessed via inspection, observation, recalculation, or inquiry (with corroboration) - Requires sample sizes large enough to support a reliable conclusion - Must span the full reliance period (not just a single point in time) ## Sampling Methodologies ### Statistical Random Sampling **Applicability:** Standard approach for high-volume, transaction-level controls. **Steps:** 1. Define the universe: every transaction subject to the control during the test period 2. Assign a sequential identifier to each population item 3. Apply a random-number generator to draw the sample 4. Confirm every item had an equal selection probability (no systematic exclusion) **Strengths:** Statistically defensible, free of selection bias **Limitations:** May not capture high-risk outliers; requires a complete population listing ### Risk-Directed (Judgmental) Sampling **Applicability:** Complements random sampling by targeting items with elevated risk characteristics; serves as the primary method for small or heterogeneous populations. **Targeting criteria:** - Transactions above a defined dollar threshold - Atypical or non-standard entries - Activity near the period boundary (cut-off exposure) - Related-party transactions - Manual overrides or exception-processed items - First-time vendors or customers **Strengths:** Focuses testing effort on highest-risk items **Limitations:** Not statistically representative; must document the selection rationale ### Unstructured (Haphazard) Sampling **Applicability:** Situations where a numbered population is unavailable and items are relatively uniform. **Steps:** 1. Select items without a deliberate pattern 2. Distribute selections across the entire test period 3. Guard against unconscious tendencies (gravitating toward top-of-list, round figures, etc.) **Strengths:** Simple, requires no tooling **Limitations:** Not statistically valid; vulnerable to unintentional bias ### Interval-Based (Systematic) Sampling **Applicability:** Sequential populations where uniform period coverage is desired. **Steps:** 1. Compute the selection interval: total population count divided by target sample size 2. Pick a random starting point within the first interval 3. Select every Nth item from that starting point forward **Illustration:** 1,000-item population, 25-item sample -> interval of 40. Random start at item 12. Selections: 12, 52, 92, 132 ... **Strengths:** Guarantees even distribution across the population **Limitations:** Periodic patterns in the data could skew results ### Sample Size Reference Table | Control Cadence | Approximate Population | Lower-Risk Sample | Moderate-Risk Sample | Higher-Risk Sample | |---|---|---|---|---| | Annual | 1 | 1 | 1 | 1 | | Quarterly | 4 | 2 | 2 | 3 | | Monthly | 12 | 2 | 3 | 4 | | Weekly | ~52 | 5 | 8 | 15 | | Daily | ~250 | 20 | 30 | 40 | | Per-transaction (under 250) | < 250 | 20 | 30 | 40 | | Per-transaction (250+) | 250+ | 25 | 40 | 60 | **Conditions that warrant larger samples:** - Elevated inherent risk in the account or process - The control is the only safeguard for a significant risk (no backup control) - A deficiency was noted in a prior testing cycle - The control is newly implemented and untested historically - External auditors plan to rely on management's testing results ## Workpaper & Evidence Standards ### Required Workpaper Sections 1. **Control profile:** - Unique control identifier - Narrative description (who does what, how frequently) - Classification (manual, automated, IT-dependent manual) - Execution frequency - Targeted risk and assertion 2. **Test blueprint:** - Stated objective of the test - Detailed procedural steps - Description of expected evidence when the control is working - Sampling method and rationale for approach chosen 3. **Execution record:** - Population description and total count - Sample items selected (method and specific identifiers) - Item-by-item results (pass/fail with the specific evidence inspected) - Full narrative for every exception observed 4. **Overall conclusion:** - Effectiveness rating (effective / deficiency / significant deficiency / material weakness) - Reasoning supporting the conclusion - Magnitude assessment for any exceptions - Compensating controls evaluated, if relevant 5. **Accountability:** - Tester signature and date - Reviewer signature and date ### What Constitutes Adequate Evidence **Acceptable:** - System screenshots capturing enforced controls or configurations - Documents bearing a signature, initials, or electronic approval stamp - Email trails with an identifiable approver and a discernible date - Application audit logs recording the actor, action, and timestamp - Independent recalculations that reproduce the recorded result - Written observation notes specifying date, location, and observer **Not sufficient on its own:** - Oral statements without corroboration - Documents lacking a date - Evidence with no identifiable performer or approver - System-generated output missing date/time metadata - Notes re
Related in Security
mac-ops
IncludedComprehensive macOS workstation operations — diagnose kernel panics, identify failing drives, audit launchd startup items, decode wake reasons, triage TCC permission denials, manage APFS snapshots, recover from no-boot. Use for: Mac is slow, slow bootup, won't boot, kernel panic, kernel_task hot, mds_stores CPU, photoanalysisd, cloudd, login loop, gray screen, sleep wake failure, drive failing, IO errors, APFS snapshots eating space, Time Machine local snapshots, Spotlight indexing, launchd, LaunchAgent, LaunchDaemon, login items, TCC permissions, Full Disk Access, Screen Recording denied, Gatekeeper, quarantine, com.apple.quarantine, app is damaged, helper tool, /Library/PrivilegedHelperTools, pmset, wake reasons, dark wake, sysdiagnose, panic.ips, DiagnosticReports, configuration profile, MDM profile, remote diagnostics over SSH.
a11y-audit
IncludedRun accessibility audits on web projects combining automated scanning (axe-core, Lighthouse) with WCAG 2.1 AA compliance mapping, manual check guidance, and structured reporting. Output is configurable: markdown report only, markdown plus machine-readable JSON, or markdown plus issue tracker integration. Use this skill whenever the user mentions "accessibility audit", "a11y audit", "WCAG audit", "accessibility check", "compliance scan", or asks to check a web project for accessibility issues. Also trigger when the user wants to verify WCAG conformance or map findings to a specific standard (CAN-ASC-6.2, EN 301 549, ADA/AODA).
erpclaw
IncludedAI-native ERP system with self-extending OS. Full accounting, invoicing, inventory, purchasing, tax, billing, HR, payroll, advanced accounting (ASC 606/842, intercompany, consolidation), and financial reporting. 413 actions across 14 domains, 43 expansion modules. Constitutional guardrails, adversarial audit, schema migration. Double-entry GL, immutable audit trail, US GAAP.
assess
IncludedAssesses and rates quality 0-10 across multiple dimensions (correctness, maintainability, security, performance, testability, simplicity) with pros/cons analysis. Compares against project conventions and prior decisions from memory. Produces structured evaluation reports with actionable improvement suggestions. Use when evaluating code, designs, architectures, or comparing alternative approaches.
spring-boot-security-jwt
IncludedProvides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based access control using Spring Security 6.x. Use when implementing authentication or authorization in Spring Boot applications.
code-hardcode-audit
IncludedDetect hardcoded values, magic numbers, and leaked secrets. TRIGGERS - hardcode audit, magic numbers, PLR2004, secret scanning.