---
name: audit-support
description: Prepare audit-ready request trackers, evidence indexes, walkthroughs, control test workpapers, sample support, and issue responses. Use for internal or external audit support and SOX-style control testing.
---

# Audit Support

This skill organizes evidence and testing; it does not issue an audit opinion.

## PBC and evidence management

For each request record request ID, description, period, population, owner, due date, status, evidence file, source system, extraction parameters, reviewer, and auditor follow-up. Preserve original files and use versioned working copies.

Evidence must be relevant, reliable, complete, period-correct, and traceable to the request. Do not create missing evidence or alter timestamps. Redact or restrict personal and confidential data according to policy.

## Walkthrough and control testing

Document process objective, initiation, systems, roles, key risks, control owner, frequency, evidence, exceptions, and handoffs. For each control distinguish:

- design: whether the control could prevent or detect the stated risk;
- implementation: whether it exists and is in use;
- operating effectiveness: whether it operated consistently during the test period.

Define the population and verify completeness before selecting samples. Record sampling method and rationale; do not claim statistical assurance for judgmental samples.

## Workpaper format

Include objective, scope, risk, control, population, sample, procedure, evidence, result, exception, impact, management response, remediation owner/date, preparer, reviewer, and conclusion. Cross-reference every conclusion to evidence.

Escalate missing evidence, contradictory support, repeat exceptions, management override, access conflicts, suspected fraud, or scope limitations. Use neutral language and separate observed fact from interpretation.
