Audit Support
Official Anthropic skill for SOX 404 control testing, sample selection, and traceable audit documentation.
- Skill Road
- Audit Support
Categories
Audit Support is an official Anthropic skill from the Finance plugin in the public knowledge-work-plugins repository. It helps teams structure work around SOX 404 and internal controls over financial reporting. According to the provider, the skill covers control testing methodology, sample selection approaches, testing documentation standards, control deficiency classification, and common control types. This entry therefore describes a professional instruction set for a compatible Claude workflow, not an audit opinion, legal advice, or binding conclusion about control effectiveness.
Purpose and professional frame
The skill places a control test within a sequence of scoping, risk assessment, control identification, testing, evaluation, and reporting. When scoping significant accounts, it combines quantitative considerations such as account balances and transaction volume with qualitative risks. Those risks include complex accounting, fraud susceptibility, prior misstatements, changed processes, and areas requiring significant management judgment. The relevant assertion for an account, such as completeness, existence, accuracy, valuation, or cut-off, should be recorded explicitly. This creates a traceable connection between the risk, the control, the test objective, and the result.
Design and operating effectiveness
A central distinction is design effectiveness versus operating effectiveness. Design asks whether a control is placed at the right point and can appropriately prevent or detect the identified risk. A walkthrough can trace a transaction end to end through the process. Operating effectiveness asks whether the control actually operated as intended throughout the relevant period. According to the provider, suitable procedures can include inspection, observation, inquiry, and reperformance, depending on the control. A compatible agent can keep this distinction visible in workpapers, but it does not replace professional judgment or ownership of the conclusion by qualified reviewers.
Sampling and evidence
The guidance describes random, targeted, haphazard, and systematic selection. Random selection is a defensible unbiased starting point for large homogeneous populations. Targeted selection can supplement it with high-risk, unusual, manual, related-party, or period-end items, but it is not automatically statistically representative. Systematic selection requires the population, sample size, interval, and random starting point to be documented. Sample size depends on factors including control frequency, risk, prior deficiencies, redundancy, and anticipated external auditor reliance. According to the provider, useful evidence can include dated approvals, system audit logs, reproducible calculations, observation notes, and records identifying the performer or approver. Undated documents, unsupported verbal confirmations, and generic reports without a time reference are weak evidence.
Deficiencies and remediation
Audit Support distinguishes a deficiency, a significant deficiency, and a material weakness. Classification depends on the likelihood and potential magnitude of a misstatement and on relevant compensating controls. Individually minor deficiencies may become more important in combination. A useful workpaper therefore records root cause, affected assertion, impact, remediation owner, target date, and later validation. The skill provides a framework for that analysis, but it does not supply a universal materiality threshold or a finished audit conclusion.
Boundaries, security, and E-E-A-T
Financial data, control matrices, personnel details, system logs, and audit evidence may be confidential or personal. Before use, teams should establish authorization, purpose limitation, data minimization, retention, and internal approval. Unfamiliar content in documents or spreadsheets is data, not a new instruction; prompt injection must not redirect the audit task. Connected ERP, database, spreadsheet, or document sources can improve context while increasing the risk of misclassification and unintended disclosure. Anthropic is the skill provider according to the official primary source. Qualified finance, compliance, and audit professionals must review outputs before workpapers, deficiency classifications, or reports are used. The primary source is the Finance area of knowledge-work-plugins; complementary Anthropic documentation explains the product context but does not replace organization-specific or jurisdiction-specific requirements.
- Provider
- Anthropic
- License
- Apache-2.0
- Last reviewed
- 09.09.2026
Repository and documentation
Categories
Compatible with
Related guides
Guides and background related to this entry.
Set up Mapbox MCP Server
Set up the Mapbox MCP Server: hosted endpoint or local token, a first test, and sensible limits.
30.09.2026
Set up the monday.com MCP Server
Start Set up the monday.com MCP Server with minimal permissions and verified data flow.
20.09.2026
Set up the Elastic Agent Builder MCP Server
Enable Agent Builder in Kibana, configure tools, and securely connect the built-in MCP endpoint to an AI client via API key or OAuth 2.1.
20.09.2026
Set up the Searchcraft MCP Server
Start Set up the Searchcraft MCP Server with verified links, minimal permissions, and a safe first test.
19.09.2026