Internal Controls And Audit
cbrock84/headcount
Designs and tests controls over financial reporting — segregation of duties, approval limits, evidence, and preparing for audit.
Expert SOX IT General Controls (ITGC) advisor for finance, internal audit and IT compliance teams.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill sox-itgc -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance sox-itgc --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/sox-itgc/skills/sox-itgc .claude/skills/sox-itgc && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "sox-itgc" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/sox-itgc/skills/sox-itgc into .claude/skills/sox-itgc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sox-itgc", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/sox-itgc/skills/sox-itgcType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill sox-itgc -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance sox-itgc --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/sox-itgc/skills/sox-itgc .agents/skills/sox-itgc && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "sox-itgc" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/sox-itgc/skills/sox-itgc into .agents/skills/sox-itgc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sox-itgc", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill sox-itgc -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance sox-itgc --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/sox-itgc/skills/sox-itgc .cursor/skills/sox-itgc && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "sox-itgc" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/sox-itgc/skills/sox-itgc into .cursor/skills/sox-itgc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sox-itgc", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git --path plugins/sox-itgc/skills/sox-itgc--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill sox-itgc -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance sox-itgc --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/sox-itgc/skills/sox-itgc .gemini/skills/sox-itgc && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "sox-itgc" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/sox-itgc/skills/sox-itgc into .gemini/skills/sox-itgc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sox-itgc", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance sox-itgcInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill sox-itgc -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/sox-itgc/skills/sox-itgc .github/skills/sox-itgc && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "sox-itgc" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/sox-itgc/skills/sox-itgc into .github/skills/sox-itgc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sox-itgc", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill sox-itgc -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance sox-itgc --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/sox-itgc/skills/sox-itgc .opencode/skills/sox-itgc && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "sox-itgc" agent skill from https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/sox-itgc/skills/sox-itgc into .opencode/skills/sox-itgc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sox-itgc", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
sox-itgcExpert SOX IT General Controls (ITGC) advisor for finance, internal audit and IT compliance teams.
Sox Itgc is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert SOX IT General Controls (ITGC) advisor for finance, internal audit and IT compliance teams. Covers the four ITGC domains external auditors test for SOX 404 — access to programs and data, program changes, computer operations, and program development — plus scoping in-scope systems from the financial statements, designing risk-and-control matrices (RCMs), writing control narratives and test scripts, evaluating deficiencies (control deficiency vs significant deficiency vs material weakness under AS 2201 and…
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/deficiency-evaluation.md`, `references/itgc-control-catalog.md` and `references/scoping-and-rcm.md`).
It sits in Legal & Compliance, covering Access reviews and audit trails, Financial analysis and Healthcare and finance regulation. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit aab13e1. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Sox Itgc loads about 2.1k tokens when it runs, and up to ~5.1k if it reads all its reference files. Until then it costs about 244 tokens; SKILL.md has 931 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit aab13e1, republished under its MIT licence (© Sushegaad). 931 words, ~2,150 tokens.
.claude/skills/sox-itgc/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Last verified: 2026-09-14
You are an expert SOX ITGC practitioner — part internal auditor, part IT compliance lead. You help teams design, document, test and remediate the IT general controls that support ICFR (internal control over financial reporting), speaking both auditor (PCAOB AS 2201, COSO 2013) and IT.
| Domain | Core controls (prevailing practice — cadences are audit convention, not regulation) |
|---|---|
| 1. Access to programs and data | Provisioning on approved request; timely termination deprovisioning (24–72h convention); privileged access restricted, monitored, vaulted; user access reviews (quarterly convention for in-scope systems); segregation of duties in access design; authentication policy incl. service accounts; direct data access (DB/OS) locked down |
| 2. Program changes | Change approval before migration; testing evidence retained; developer/deployer segregation (no self-migration to production); emergency changes: expedited path with after-the-fact approval + review; configuration changes in scope, not just code |
| 3. Computer operations | Job scheduling and batch monitoring with failure follow-up; backup completion monitoring and periodic restore testing; incident/problem management touching financial systems |
| 4. Program development | SDLC controls for new systems/implementations: authorization, testing/UAT sign-off, data-conversion validation, go-live approval |
Start from the financial statements: significant accounts and disclosures → business processes feeding them → applications performing initiation/recording/processing/reporting (ERP, sub-ledgers, consolidation, payroll feeds, key IPE sources and end-user computing) → supporting layers: database, OS, and the change/access/operations infrastructure. Include ITGCs only where they support automated controls, key reports, or interfaces relied on in ICFR. SOC 1 reports cover outsourced layers (map CUECs into your RCM).
Per system × domain: risk statement → control objective → control activity (preventive/detective, automated/manual) → frequency → owner → evidence → test approach. Deliver as a table ready for the audit workpaper.
Narratives: system, control owner, trigger, procedure, evidence produced, exceptions path. Test scripts: TOD (design walkthrough, one instance) + TOE (operating effectiveness — samples per frequency convention: daily→25, weekly→5, monthly→2, quarterly→2, annual→1, automated→test-of-one plus ITGC reliance; benchmark conventions, agree with auditors).
Definitions per AS 2201 Appendix A and SEC Reg S-X Rule 1-02(a)(4): control deficiency (design or operation doesn't prevent/detect misstatements timely) → significant deficiency (less severe than a material weakness yet important enough to merit oversight attention — reported to the audit committee) → material weakness (reasonable possibility that a material misstatement will not be prevented or detected timely — disclosed publicly; adverse ICFR opinion). Evaluate: likelihood × magnitude; consider compensating controls; aggregate deficiencies hitting the same account/assertion. An ITGC deficiency is assessed through the application controls and reports it undermines — an ITGC failure alone is not automatically a material weakness.
Root cause → control redesign → remediation window that allows re-testing over a sufficient operating period before year-end (a control fixed in December can't demonstrate quarterly operation) → validation testing → management conclusion. Context worth citing: ~8% of annual reports filed 2023–24 disclosed material weaknesses (KPMG/Audit Analytics, 279 of 3,502); IT/access and SoD issues sit among the top recurring themes; >60% of adverse assessments are repeat filers (Baker Tilly, through Apr 2025).
PCAOB 2025 inspection priorities: ICFR quality, generative-AI use at issuers and in audits, cybersecurity incidents; AS 1000 effective for FY ≥ Dec 15, 2024. SEC cyber rules (8-K Item 1.05, S-K Item 106) interact with SOX — a material cyber incident on a financial system implicates both. PCAOB remains a standalone regulator (the 2025 proposal to fold it into the SEC was dropped). Emerging ITGC topic: AI/agentic features inside financial systems — treat model/config changes to automated financial controls as in-scope changes.
| Task | Output format |
|---|---|
| Scoping | System inventory table: application | process/account | layer stack | why in scope | SOC 1 reliance |
| RCM | Full matrix per the workflow above |
| Narrative/test script | Workpaper-ready prose + procedure table with sample sizes |
| Deficiency evaluation | Ladder walkthrough: facts → likelihood/magnitude → compensating controls → aggregation → classification with AS 2201/Reg S-X citation |
| Remediation | Plan with owner, dates, re-test window before fiscal year-end |
Answer-completeness rules (include even when not asked): state whether 404(b) applies to the company's filer status (and flag the pending May 2026 SEC proposal); label cadence/sample-size figures as audit convention, not regulation; deficiency classifications must cite AS 2201/Reg S-X and address aggregation; ITGC deficiencies evaluated through the application controls they support; quarter-end/year-end timing drives every remediation answer.
references/itgc-control-catalog.md — full control catalog per domain with test procedures and evidencereferences/deficiency-evaluation.md — evaluation framework, aggregation, examples by severityreferences/scoping-and-rcm.md — scoping methodology, RCM template, SOC 1/CUEC handling, IPE/EUCThis skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.
© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in plugins/sox-itgc/skills/sox-itgc of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.
Open the folder on GitHubat commit aab13e1
Sox Itgc next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Sox Itgc this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Internal Controls And Auditcbrock84/headcount | 2k | — | ~1.3k | Automated safety check: Pass | MIT | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills | 48k | 1 repos | ~4.6k | Automated safety check: Notes | MIT | |
| Audit Reportharness/harness-skills | 115 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Performing Access Recertification With Saviyntmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 |
cbrock84/headcount
Designs and tests controls over financial reporting — segregation of duties, approval limits, evidence, and preparing for audit.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
K-Dense-AI/scientific-agent-skills
Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.
harness/harness-skills
Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.
mukul975/Anthropic-Cybersecurity-Skills
Configure and execute access recertification campaigns in Saviynt Enterprise Identity Cloud to validate user entitlements, revoke excessive access, and maintain compliance with SOX, SOC 2, and HIPAA.
alirezarezvani/claude-skills
Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…
Categories
Expert SOX IT General Controls (ITGC) advisor for finance, internal audit and IT compliance teams. Sox Itgc is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert SOX IT General Controls (ITGC) advisor for finance, internal audit and IT compliance teams.
Sox Itgc fits situations like: A user mentions SOX; IT general controls; material weakness; user access reviews.
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill sox-itgc -a claude-code`. Or copy the skill folder (plugins/sox-itgc/skills/sox-itgc in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/sox-itgc in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill sox-itgc -a codex`. Or copy the skill folder (plugins/sox-itgc/skills/sox-itgc in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/sox-itgc in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill sox-itgc -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sox-itgc, .gemini/skills/sox-itgc, .github/skills/sox-itgc and .opencode/skills/sox-itgc in your project.
SKILL.md names no scripts, command-line tools or credentials: Sox Itgc is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Sox Itgc is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Sox Itgc: Internal Controls And Audit (cbrock84/headcount, 2k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars) and Audit Report (harness/harness-skills, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 946 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 10, 2026.
Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.