Performs Sarbanes-Oxley Act (SOX) IT General Controls (ITGC) audits aligned to COSO Internal Control—Integrated Framework and PCAOB AS 2201—covering access to programs and data, program change management, program development, and computer operations relevant to financial reporting systems. Trigger when preparing SOX 404 management assessment, supporting external auditor ITGC reliance, testing change tickets for financially relevant applications, or auditing segregation of duties in ERP and cloud financial systems. Do not use for FedRAMP authorization packages (use fedramp-moderate-baseline), PCI cardholder environments (use pci-dss-network-segmentation), or HIPAA ePHI controls without financial reporting scope (use hipaa-technical-safeguards).
설치
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
Performs Sarbanes-Oxley Act (SOX) IT General Controls (ITGC) audits aligned to COSO Internal Control—Integrated Framework and PCAOB AS 2201—covering access to programs and data, program change management, program development, and computer operations relevant to financial reporting systems. Trigger when preparing SOX 404 management assessment, supporting external auditor ITGC reliance, testing change tickets for financially relevant applications, or auditing segregation of duties in ERP and cloud financial systems. Do not use for FedRAMP authorization packages (use fedramp-moderate-baseline), PCI cardholder environments (use pci-dss-network-segmentation), or HIPAA ePHI controls without financial reporting scope (use hipaa-technical-safeguards).
SOX IT General Controls Audit
Overview
This skill implements IT General Controls (ITGC) testing for Sarbanes-Oxley Act Section 404 management assessment of internal control over financial reporting (ICFR). ITGCs provide the foundation upon which automated application controls and manual controls depend.
ITGC domain
Scope
Typical systems
Access to programs and data
User provisioning, privileged access, SoD, password/MFA
ERP (SAP, Oracle), HCM/payroll interfaces, cloud IAM
Program change management
SDLC, change approval, testing, migration to production
Management assessment of ICFR; auditor attestation
SEC Rule 13a-15 / 15d-15
Management evaluation and disclosure requirements
COSO 2013 Framework
Control environment, risk assessment, control activities, information & communication, monitoring
PCAOB AS 2201
Audit of internal control over financial reporting integrated with financial statement audit
PCAOB AS 2315
Audit sampling for ITGC testing
Key principle: ITGC deficiencies rated deficiency, significant deficiency, or material weakness based on likelihood and magnitude of misstatement to financial statements—not generic security severity alone.
Cross-skill mapping: access and logging domains leverage access-control-identity-audit and audit-logging-integrity; change automation leverages compliance-as-code-governance.
When to Use
Use this skill when:
SOX 404 annual cycle: scoping financially relevant systems and testing ITGCs
External auditor requests ITGC walkthroughs and sample testing for reliance
Auditing ERP/cloud financial systems (Workday Financials, NetSuite, SAP S/4HANA)
Reviewing change management for financially relevant applications and interfaces
Assessing segregation of duties (SoD) in provisioning and developer access
Evaluating computer operations controls for batch processing and backup/recovery
Testing CI/CD and IaC changes affecting financial reporting infrastructure
Do not use this skill when:
FedRAMP or federal cloud authorization (use fedramp-moderate-baseline)
SOC 2-only audits without ICFR scope (use soc2-trust-services-criteria)
GLBA Safeguards Rule for customer information at financial institutions (use glba-ffiec-financial-privacy)
Core Process
Execute steps in order.
Step 1: SOX scoping and financial relevance
Identify in-scope systems using risk-based scoping:
Systems that initiate, authorize, record, process, or report financial transactions
Interfaces feeding general ledger, revenue recognition, inventory, payroll-to-GL
Document locations and entities (domestic, international) in scope for 404.
Classify applications:
Tier 1: Direct GL impact (ERP core modules)
Tier 2: Indirect or supporting (reporting warehouses, integration middleware)
Exclude non-financial systems with documented rationale and management sign-off.
Artifact: sox-it-scope-{id}.json.
Step 2: COSO control environment and risk assessment
Walkthrough Control Environment (COSO principle 1–5):
Tone at top, board/audit committee oversight, organizational structure
HR policies, fraud risk factors, accountability for ITGC performance
Document Risk Assessment (principle 6–9) for IT changes and access—link IT risks to financial assertion risks (existence, completeness, accuracy, cutoff, authorization).
Identify key reports and data used in controls (parameter tables, master data) requiring ITGC coverage.
Note management override paths and monitoring controls.
Step 3: Access to programs and data (ITGC Domain 1)
Execute access-control-identity-audit with SOX mapping:
ITGC control objective
Test approach
New user provisioning
Sample hire tickets; verify approval and role assignment