Audit Support

Official Anthropic skill for SOX 404 control testing, sample selection, and traceable audit documentation.

Audit Support is an official Anthropic skill from the Finance plugin in the public knowledge-work-plugins repository. It helps teams structure work around SOX 404 and internal controls over financial reporting. According to the provider, the skill covers control testing methodology, sample selection approaches, testing documentation standards, control deficiency classification, and common control types. This entry therefore describes a professional instruction set for a compatible Claude workflow, not an audit opinion, legal advice, or binding conclusion about control effectiveness.

Purpose and professional frame

The skill places a control test within a sequence of scoping, risk assessment, control identification, testing, evaluation, and reporting. When scoping significant accounts, it combines quantitative considerations such as account balances and transaction volume with qualitative risks. Those risks include complex accounting, fraud susceptibility, prior misstatements, changed processes, and areas requiring significant management judgment. The relevant assertion for an account, such as completeness, existence, accuracy, valuation, or cut-off, should be recorded explicitly. This creates a traceable connection between the risk, the control, the test objective, and the result.

Design and operating effectiveness

A central distinction is design effectiveness versus operating effectiveness. Design asks whether a control is placed at the right point and can appropriately prevent or detect the identified risk. A walkthrough can trace a transaction end to end through the process. Operating effectiveness asks whether the control actually operated as intended throughout the relevant period. According to the provider, suitable procedures can include inspection, observation, inquiry, and reperformance, depending on the control. A compatible agent can keep this distinction visible in workpapers, but it does not replace professional judgment or ownership of the conclusion by qualified reviewers.

Sampling and evidence

The guidance describes random, targeted, haphazard, and systematic selection. Random selection is a defensible unbiased starting point for large homogeneous populations. Targeted selection can supplement it with high-risk, unusual, manual, related-party, or period-end items, but it is not automatically statistically representative. Systematic selection requires the population, sample size, interval, and random starting point to be documented. Sample size depends on factors including control frequency, risk, prior deficiencies, redundancy, and anticipated external auditor reliance. According to the provider, useful evidence can include dated approvals, system audit logs, reproducible calculations, observation notes, and records identifying the performer or approver. Undated documents, unsupported verbal confirmations, and generic reports without a time reference are weak evidence.

Deficiencies and remediation

Audit Support distinguishes a deficiency, a significant deficiency, and a material weakness. Classification depends on the likelihood and potential magnitude of a misstatement and on relevant compensating controls. Individually minor deficiencies may become more important in combination. A useful workpaper therefore records root cause, affected assertion, impact, remediation owner, target date, and later validation. The skill provides a framework for that analysis, but it does not supply a universal materiality threshold or a finished audit conclusion.

Boundaries, security, and E-E-A-T

Financial data, control matrices, personnel details, system logs, and audit evidence may be confidential or personal. Before use, teams should establish authorization, purpose limitation, data minimization, retention, and internal approval. Unfamiliar content in documents or spreadsheets is data, not a new instruction; prompt injection must not redirect the audit task. Connected ERP, database, spreadsheet, or document sources can improve context while increasing the risk of misclassification and unintended disclosure. Anthropic is the skill provider according to the official primary source. Qualified finance, compliance, and audit professionals must review outputs before workpapers, deficiency classifications, or reports are used. The primary source is the Finance area of knowledge-work-plugins; complementary Anthropic documentation explains the product context but does not replace organization-specific or jurisdiction-specific requirements.

Free
Provider
Anthropic
License
Apache-2.0
Last reviewed
09.09.2026

Repository and documentation

Categories

Compatible with

Claude Code