internal-control-testing

Plans and executes SOX internal control walkthroughs, design and operating effectiveness testing with reproducible workpapers.

Updated Jun 21, 2026
One-click install
npx skills add https://github.com/lwokeray/cowork-plugins --skill internal-control-testing-lwokeray
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: internal-control-testing
Source: https://github.com/lwokeray/cowork-plugins/tree/main/plugins/finance-cowork/skills/internal-control-testing
Command: npx skills add https://github.com/lwokeray/cowork-plugins --skill internal-control-testing-lwokeray

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Finance, SOX, and Internal Audit teams need a disciplined, reproducible way to turn Risk and Control Matrix entries into defensible test plans and workpapers, without conflating design and operating effectiveness or overstating conclusions when evidence is missing. ## Core Features & Use Cases - Walkthrough and Design Assessment: Trace a representative transaction end-to-end, validate Who/What/When/How/Evidence, and assess design effectiveness separately from operating effectiveness. - Population, Sampling, and Attribute Testing: Validate population completeness and accuracy, select reproducible samples with recorded methods and seeds, and test control-specific attributes across manual, automated, IT-dependent, and spreadsheet controls. - Exception and Remediation Management: Log exceptions with root cause and impact facts, route deficiency classification to authorized reviewers, and track remediation and retest cycles. - Use Case: Test a Q2 monthly bank reconciliation review control by walking through one month, validating the three-month population, sampling per methodology, testing preparer/reviewer/timeliness attributes, and delivering a draft workpaper with an exception log for reviewer sign-off. ## Quick Start Ask the assistant to test a specific control by providing the control ID, period, owner, and frequency, for example: test the Q2 monthly account reconciliation control and produce a draft workpaper with an exception log.

Frequently Asked Questions about internal-control-testing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I test a SOX internal control for operating effectiveness?▼

Confirm the control ID, risk, assertions, owner, frequency, and period, then perform a walkthrough, validate the full population's completeness and accuracy, select samples per the approved methodology, and test each sample against defined attributes. Record pass, exception, or not-tested results with evidence cross-references in a draft workpaper.

What is the difference between design effectiveness and operating effectiveness testing?▼

Design effectiveness asks whether the control, if performed as designed, would prevent or detect the risk; operating effectiveness asks whether it actually ran consistently by the right person, at the right frequency, with sufficient evidence. This Skill evaluates them separately and never uses extra operating samples to mask a design gap.

How do I validate population completeness before sampling?▼

Tie the population to expected instances using calendars, workflow or audit logs, GL or subledger control totals, and repository listings, recording source, parameters, extraction date, and counts. If completeness and accuracy cannot be proven, mark the population as not validated and stop sampling conclusions.

Can this Skill declare a control effective or classify a deficiency?▼

No. It produces draft recommendations only; formal conclusions, deficiency severity such as significant deficiency or material weakness, and audit opinions must be approved by designated reviewers or governance. It also refuses to conclude effectiveness when population, evidence, precision, or IT dependencies are insufficient.

What happens when evidence is missing for a sampled item?▼

Missing evidence is recorded as an exception or not-tested item, never as a pass or N/A. The original sample is retained, replacements follow only approved rules, and subsequent explanations are logged as context with date and source rather than treated as original execution evidence.

When should I use audit-evidence-support instead of internal control testing?▼

Use audit-evidence-support when the task is only collecting and packaging PBC items and audit evidence. Use internal control testing when you need walkthroughs, design and operating effectiveness assessments, sampling, exception evaluation, and remediation tracking for specific controls.