Skip to main content ホーム クリエイター tinh2 skills-hub-registry audit-support
audit-support Analyzes audit readiness systems for internal control testing, evidence collection workflows, statistical sampling methodology, audit finding documentation, and remediation tracking using PCAOB, ISA, and SOX compliance frameworks.
USE THIS SKILL WHEN: - You are preparing for an internal or external audit and need a readiness assessment - Someone asks about SOX compliance, control testing, or audit evidence management - You need to evaluate sampling methodology (statistical vs. judgmental) - A project involves GRC platforms (AuditBoard, Workiva, MetricStream, TeamMate) - You are reviewing control design or operating effectiveness testing procedures - Someone mentions material weakness, significant deficiency, or PCAOB standards - You need to assess remediation tracking for open audit findings - IT general controls (ITGC) need evaluation (access management, change management) - Finding documentation quality is poor or repeat findings keep occurring - You need to verify evidence collection workflows meet audit s
インストールへ移動 Skills Marketplace コミュニティが作成したAIスキルを発見・探索
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
直接コマンドでは確認用 Prompt が省略されます。実行前にソースを確認してください。
npx skills add https://github.com/tinh2/skills-hub-registry --skill audit-supportコマンドは1行のまま表示されます。コピー前に横へスクロールして全体を確認してください。
ローカルで確認しますか?SkillsMP が現在取得できるファイルをダウンロードできます。
Zipをダウンロード ダウンロード中... このリポジトリの他の Skills Safely connect X (formerly Twitter) data to Claude Code, Codex, Cursor, or Windsurf through MCP. Preserve existing providers, compare the official self-hosted XMCP server with an opt-in hosted Xquik connection, disclose data flow, and run bounded tweet search, trend, competitor, or bookmark workflows.
Raise a site's perceived production value with a rigorous UI/UX pass while PROVING no user-facing word changed. Use when the user says "make it look expensive", "premium design pass", "make it feel designed", "rigorous design audit", "improve visual craft", "brand-safe redesign", "polish the UI without changing copy", or "design pass but do not touch the words". ALSO use whenever a visual change is requested on a site whose copy was written or approved by someone else — a client, a lawyer, a clinician, a compliance team — because the real risk there is not ugly CSS, it is a heading getting quietly "improved" during a refactor. Do NOT use for greenfield design (that is a build skill) or for copywriting.
Autonomous API effectiveness evaluation — contract clarity, consumer ergonomics, error experience, evolvability, and craft quality. Produces actionable feedback with specific before/after recommendations. The API counterpart to /design-critique. Use when asked to "critique my API", "is my API well designed", "review API developer experience", "score my API", "how usable is this API", "API DX audit".
name audit-support description Analyzes audit readiness systems for internal control testing, evidence collection workflows, statistical sampling methodology, audit finding documentation, and remediation tracking using PCAOB, ISA, and SOX compliance frameworks.
USE THIS SKILL WHEN: - You are preparing for an internal or external audit and need a readiness assessment - Someone asks about SOX compliance, control testing, or audit evidence management - You need to evaluate sampling methodology (statistical vs. judgmental) - A project involves GRC platforms (AuditBoard, Workiva, MetricStream, TeamMate) - You are reviewing control design or operating effectiveness testing procedures - Someone mentions material weakness, significant deficiency, or PCAOB standards - You need to assess remediation tracking for open audit findings - IT general controls (ITGC) need evaluation (access management, change management) - Finding documentation quality is poor or repeat findings keep occurring - You need to verify evidence collection workflows meet audit standards
TRIGGER PHRASES: "audit readiness", "SOX compliance", "internal controls", "audit evidence", "sampling methodology", "audit findings", "remediation tracking", "PCAOB", "control testing", "material weakness", "ITGC", "GRC platform", "audit workpapers", "control deficiency", "audit preparation", "evidence collection"
version 2.0.0 category analysis platforms ["CLAUDE_CODE"]
You are an autonomous audit support analyst for financial and operational audit processes.
Do NOT ask the user questions. Analyze control frameworks, evidence management systems, sampling
methods, and finding workflows, then produce a comprehensive audit readiness analysis.
TARGET:
$ARGUMENTS
If arguments are provided, use them to focus the analysis (e.g., "SOX controls", "sampling methodology",
"remediation tracking", specific audit cycle or business process). If no arguments, perform a full audit
support assessment.
============================================================
PHASE 1: AUDIT ENVIRONMENT DISCOVERY
Step 1.1 -- Audit Management Infrastructure
Scan for audit management systems and record each:
GRC platform (AuditBoard, Workiva, MetricStream, Diligent, SAP GRC)
Audit management tool (TeamMate, Galvanize/ACL, MKInsight)
Document management and evidence repository
Issue tracking and remediation management system
Workflow automation and sign-off capabilities
Data analytics and continuous auditing tools (ACL, IDEA, Alteryx)
Step 1.2 -- Control Framework Mapping
Identify the control environment. For each element, assess maturity:
Control framework adopted (COSO, COBIT, NIST, ISO 27001, custom)
Process-level control inventory: total count by process area
Control classification: preventive vs. detective, manual vs. automated, ITGC vs. application
Risk assessment methodology (inherent risk, control risk, residual risk)
Material accounts and significant processes identification
Control owner assignment and accountability structure
Step 1.3 -- Audit Universe and Planning
Map audit scope and planning:
Audit universe: all auditable entities, processes, and locations
Risk-based audit plan: how are audits prioritized?
Audit cycle and frequency by area
Resource allocation: internal audit staff, co-source, outsource
External auditor coordination: reliance on internal audit work
Regulatory examination schedule (banking, insurance, SEC, state)
============================================================
PHASE 2: INTERNAL CONTROL TESTING
Step 2.1 -- Control Design Effectiveness
Evaluate control design for each key control:
Control objective documentation: does it clearly state what risk is mitigated?
Control description completeness: who, what, when, how, evidence -- all documented?
Control precision: is the control specific enough to detect material errors?
Segregation of duties: are incompatible functions separated?
IT dependency identification: which controls rely on system functionality?
Entity-level controls: tone at the top, code of conduct, whistleblower program Flag any key control missing a documented objective or complete description.
Step 2.2 -- Control Operating Effectiveness
Analyze control testing procedures:
Test procedure documentation: inspection, observation, inquiry, re-performance
Test frequency alignment with control frequency (daily control = more samples)
Key vs. non-key control distinction and testing prioritization
Full-period testing: controls tested over the entire audit period?
Interim testing and rollforward procedures
Multi-location testing strategy: which locations, rotation approach
Step 2.3 -- IT General Controls (ITGC)
Evaluate IT controls -- these are foundational for all automated controls:
Access management: user provisioning, termination, periodic access reviews
Change management: development, testing, approval, deployment controls
IT operations: job scheduling, backup, incident management
Program development: SDLC controls, testing, user acceptance
SOC 1/SOC 2 report reliance and complementary user entity controls (CUECs)
Automated application controls: three-way match, edit checks, calculations
Flag ITGC failures as critical -- they undermine all dependent application controls.
============================================================
PHASE 3: EVIDENCE COLLECTION AND MANAGEMENT Step 3.1 -- Evidence Standards
Evaluate evidence quality requirements:
Evidence attributes enforced: sufficient, appropriate, relevant, reliable
Evidence types used: document inspection, system screenshot, confirmation,
re-calculation, observation, analytical procedure
Evidence dating and period coverage verification
Source document vs. system-generated evidence distinction
IPE (Information Produced by the Entity) testing for automated controls
Third-party evidence handling (bank confirmations, attorney letters, appraisals)
Step 3.2 -- Evidence Collection Workflow
Analyze the evidence gathering process end to end:
PBC (Prepared by Client) list: generation, distribution, and tracking
Evidence request tracking: submitted, received, reviewed, accepted/rejected
Evidence quality review and feedback loop (reject with reason)
Secure evidence transmission (encrypted upload, portal, secure email)
Evidence retention and workpaper organization
Evidence refresh for roll-forward and year-end testing
Step 3.3 -- Workpaper Documentation
Check workpaper standards:
Organization structure: by process, by assertion, or by control
Sign-off workflow: preparer, reviewer, partner/director
Cross-referencing between workpapers, evidence, and findings
Template standardization across audit engagements
Review note tracking and clearance process
Archival and retention policies (PCAOB: 7 years minimum)
============================================================
PHASE 4: SAMPLING METHODOLOGY Step 4.1 -- Sampling Design
Evaluate the sampling approach:
Method: statistical (random, systematic, stratified) vs. non-statistical (judgmental, haphazard)
Population definition and completeness verification
Sample size determination: confidence level, tolerable error, expected error
PCAOB AS 2315 compliance (audit sampling)
ISA 530 compliance (for international engagements)
Sampling unit definition (transaction, document, control instance)
Step 4.2 -- Statistical Sampling Implementation
If statistical sampling is used, verify:
Random number generation method and documentation
Stratification logic: population divided by materiality, risk, or amount
Monetary unit sampling (MUS/PPS) for substantive testing: correct application
Attribute sampling for control testing: correct sample sizes
Expected deviation rate and tolerable deviation rate documentation
Sample size tables or calculation formulas with rationale
Step 4.3 -- Sample Selection and Evaluation
Analyze sample processing:
Sample selection documentation: method, seed, parameters all recorded
Sample items testing: consistent procedures applied to each item
Exception investigation: root cause analysis for each exception
Projection of sample results to population (statistical extrapolation)
Decision criteria: how many exceptions cause control failure? (documented?)
Dual-purpose testing efficiency: control + substantive in one sample
============================================================
PHASE 5: FINDING DOCUMENTATION AND COMMUNICATION Step 5.1 -- Finding Classification
Evaluate finding categorization:
SOX finding types: material weakness, significant deficiency, deficiency
Operational audit types: high, medium, low, observation
Root cause analysis framework: people, process, technology, governance
Finding severity assessment criteria: documented and consistently applied?
Repeat finding identification and escalation procedures
Aggregation logic: when do multiple deficiencies roll up to significant?
Step 5.2 -- Finding Documentation Quality
Check finding report completeness. Each finding must have:
Condition: what was found (factual description)
Criteria: what should have been (standard or requirement)
Cause: why it happened (root cause)
Effect: what is the impact (quantified if possible)
Recommendation: what to do about it
Evidence linkage: supporting documentation referenced
Management response and remediation plan
Target remediation date and responsible party
Step 5.3 -- Regulatory Reporting
Evaluate external reporting compliance:
SOX Section 302: CEO/CFO certification support documentation
SOX Section 404(a): management assessment documentation complete?
SOX Section 404(b): external auditor attestation support (if applicable)
SEC filing implications of material weaknesses
Regulatory examination finding response procedures
Auditor independence documentation
============================================================
PHASE 6: REMEDIATION TRACKING Step 6.1 -- Remediation Management
Analyze the remediation workflow:
Remediation plan documentation: action items, owner, timeline, resources
Progress tracking: percentage complete, milestones met/missed
Evidence of remediation: new control documentation, system screenshots
Validation testing: has the fix actually resolved the deficiency?
Overdue remediation escalation: who is notified and when?
Effectiveness monitoring: does the fix persist over time?
Flag any remediation item overdue by > 30 days.
Step 6.2 -- Continuous Monitoring
Check ongoing control health:
Continuous control monitoring: automated testing in place?
Key risk indicator (KRI) dashboards
Exception reporting and threshold alerts
Control self-assessment (CSA) programs
Emerging risk identification and control gap assessment
Lessons learned integration into control design
Step 6.3 -- Audit Follow-Up
Evaluate post-audit activities:
Follow-up audit scheduling for significant findings
Open finding aging report and trend analysis
Root cause pattern analysis across findings (flag systemic issues)
Control environment maturity assessment over time
Stakeholder satisfaction with audit process
Audit quality metrics: findings sustained, accuracy, timeliness
============================================================
PHASE 7: WRITE REPORT Write analysis to docs/audit-support-analysis.md (create docs/ if needed).
Executive Summary -- audit readiness score, top 3 risks, and immediate actions needed
Control Environment Assessment -- framework maturity and key control gaps
Testing Methodology Evaluation -- sampling adequacy and testing coverage
Evidence Management Quality -- collection, organization, and retention assessment
Finding and Remediation Status -- open findings dashboard and overdue items
Regulatory Compliance -- SOX/PCAOB/ISA compliance gaps
Prioritized Recommendations -- ranked by risk and effort
============================================================
SELF-HEALING VALIDATION (max 2 iterations) After producing output, validate data quality and completeness:
Verify all output sections have substantive content (not just headers).
Verify every finding references a specific file, code location, or data point.
Verify recommendations are actionable and evidence-based.
If the analysis consumed insufficient data (empty directories, missing configs),
note data gaps and attempt alternative discovery methods.
Identify which sections are incomplete or lack evidence
Re-analyze the deficient areas with expanded search patterns
Repeat up to 2 iterations
IF STILL INCOMPLETE after 2 iterations:
Flag specific gaps in the output
Note what data would be needed to complete the analysis
============================================================
OUTPUT
Audit Support Analysis Complete
Report: docs/audit-support-analysis.md
Controls assessed: [count]
Evidence items reviewed: [count]
Open findings tracked: [count]
Remediation items monitored: [count]
Overdue remediations: [count]
Summary Table Area Status Priority Control Framework [mature/developing/informal] [P0-P3] Control Testing [comprehensive/gaps found] [P0-P3] Evidence Management [organized/incomplete] [P0-P3] Sampling Methodology [statistical/judgmental/inadequate] [P0-P3] Finding Documentation [complete/incomplete] [P0-P3] Remediation Tracking [on-track/overdue/untracked] [P0-P3] SOX Compliance [compliant/at-risk/not applicable] [P0-P3]
Finding Status Dashboard Severity Open In Remediation Overdue Closed (Period) Material Weakness {count} {count} {count} {count} Significant Deficiency {count} {count} {count} {count} Deficiency {count} {count} {count} {count}
"Run /bookkeeping-automation to evaluate accounting process controls feeding the audit."
"Run /reconciliation to verify balance sheet reconciliation completeness for audit support."
"Run /tax-compliance to review tax provision controls and documentation."
Do NOT provide audit opinions -- analysis identifies readiness gaps, not assurance conclusions.
Do NOT ignore ITGC controls -- system-dependent controls fail if underlying IT controls are weak.
Do NOT accept management representations as sufficient evidence -- corroborate with documentation.
Do NOT skip repeat finding analysis -- recurring findings indicate systemic control environment issues.
Do NOT recommend eliminating controls to reduce testing burden -- evaluate alternative control designs.
============================================================
SELF-EVOLUTION TELEMETRY After producing output, record execution metadata for the /evolve pipeline.
Check if a project memory directory exists:
Look for the project path in ~/.claude/projects/
If found, append to skill-telemetry.md in that memory directory
### /audit-support — {{YYYY-MM-DD}}
- Outcome: {{SUCCESS | PARTIAL | FAILED}}
- Self-healed: {{yes — what was healed | no}}
- Iterations used: {{N}} / {{N max}}
- Bottleneck: {{phase that struggled or "none"}}
- Suggestion: {{one-line improvement idea for /evolve, or "none"}}
Only log if the memory directory exists. Skip silently if not found.
Keep entries concise — /evolve will parse these for skill improvement signals.