Skip to content

Agent Operating Guide

audit-support

The auto-loaded SOX 404 control-testing methodology reference the other SOX skills consult: sample sizing, selection, population validation, deficiency grading, and control types.

audit-support is the plugin’s SOX 404 methodology reference. Unlike every other skill here, you don’t invoke it: it has no slash command. It loads automatically whenever another skill (for example /sox-testing or /sox-test) needs a methodology fact to cite in a workpaper. Keeping the methodology in one place means the testing skills reference a single source instead of each carrying their own drifting copy.

You never run audit-support directly. The SOX skills consult it in the background when they need sample-size buckets by risk level, a sample-selection method, population-validation standards, a deficiency grade, or a control-type definition: and they carry the user interaction. If you want to run SOX testing, start with /sox-testing; this page documents the methodology those skills draw on so you know what standards they apply.

  • Testing methodology: the SOX 404 flow (scoping, risk assessment, control identification, testing, evaluation, reporting), significant-account scoping, relevant assertions by account type, and design vs operating effectiveness.
  • Sample selection: the four methods (random, targeted/judgmental, haphazard, systematic) and sample-size guidance by control frequency and risk level.
  • Population (IPE) validation: the acceptable bases for proving a population is complete before sampling, plus zero-occurrence dispositions and same-method replacement rules.
  • Period handling: mid-period control changes, interim testing and roll-forward, the pre-committed exception-expansion policy, and evidence temporal validity.
  • Deficiency classification: the CD / SD / MW severity scale, the CCCER finding format, the four-factor severity-grading procedure (magnitude, likelihood, compensating controls, aggregation), and deficiency aggregation.
  • Control types: the taxonomy (ITGC, manual, automated, IT-dependent manual, entity-level) with test approaches, plus management-review-control precision and test-step templates by control area.
  • /sox-testing: the engine that consults this reference while planning and running a control area’s testing.
  • /sox-test: the AssureSwarm bridge that runs the engine on a workflow step.
  • The full SOX engine family.

Not audit or legal advice. Workpapers and assessments produced by these skills require review by qualified financial professionals before being relied on for SOX 404 compliance.