Internal controls design and evaluation using the COSO 2013 framework. USE THIS SKILL when the user asks about SOX compliance, COSO framework, control design, internal controls, control environment, risk-control matrices, control deficiencies, material weakness, ITGCs, segregation of duties, control testing, or any engagement involving the design, documentation, or assessment of internal controls over financial reporting. Produces COSO-aligned control frameworks, risk-control matrices, testing plans, and deficiency remediation roadmaps.
Reporting Framework: US GAAP, IFRS, or other applicable standards
Material Accounts: Key financial statement line items in scope
Known Issues (optional): Prior deficiencies, auditor findings, management concerns
Systems Environment: ERP, GL, and key financial applications in use
Execution Steps
1. COSO 2013 Internal Control Framework Assessment
Evaluate the organization against all 5 components and 17 principles of the COSO 2013 Integrated Framework. Each principle is scored as Present & Functioning (P), Present with Exceptions (E), or Not Present (N).
Component 1: Control Environment
#
Principle
Key Assessment Areas
Score
1
Commitment to integrity and ethical values
Code of conduct, ethics hotline, tone at the top, consequence management
Deficiency identification; classification; escalation to audit committee
P / E / N
COSO Assessment Summary: A component is effective only when ALL underlying principles are Present & Functioning. The system of internal control is effective only when ALL 5 components are effective.
2. Financial Statement Assertion Mapping
Map controls to the 5 financial statement assertions for each significant account:
Assertion
Abbreviation
Definition
Example Controls
Existence / Occurrence
E/O
Assets/liabilities exist; transactions occurred
Physical inventory counts; bank confirmations; transaction matching
Completeness
C
All transactions and balances are recorded
Sequence checks; 3-way match (PO-receipt-invoice); reconciliation to third party
Valuation / Allocation
V/A
Amounts are recorded at appropriate values
Reserve calculations; impairment testing; fair value models; aging analysis
Rights & Obligations
R/O
Entity holds rights to assets; liabilities are obligations
Title documents; contract review; lien searches; confirmation of terms
New hire authorization; pay rate changes approval; payroll register review; bank reconciliation
Treasury / Cash
Unauthorized transactions; incorrect cash balance
Bank reconciliation; dual signatures; wire transfer approval; investment authorization
Financial Close
Misstatement in financial statements
Close calendar; JE approval; account reconciliations; variance analysis; management review
Equity / Stock Comp
Incorrect fair value; unauthorized issuance
Board approval of grants; valuation model review; vesting schedule tracking; expense calculation review
IT General Controls (ITGCs):
ITGC Domain
Control Objective
Key Controls
Access Security
Only authorized users access systems and data
Access provisioning with approval; periodic access reviews (quarterly); privileged access monitoring; password policies; terminated user removal within 24 hours
Change Management
Changes are authorized, tested, and approved
Change request documentation; segregation of dev/test/prod; testing evidence; approval prior to migration; emergency change procedures
Computer Operations
Systems operate reliably and data is protected
Job scheduling and monitoring; backup procedures with offsite storage; backup restoration testing; incident management; disaster recovery planning
Program Development
New systems are properly designed and implemented
SDLC methodology; requirements documentation; user acceptance testing; data migration validation; post-implementation review
5. SOX Scoping Methodology
Step 1: Identify Material Accounts
A financial statement line item is material if a misstatement could reasonably influence economic decisions. Apply quantitative and qualitative materiality:
Quantitative: Typically 5% of pre-tax income (or alternative base: revenue, total assets)
Step 2: Map Material Accounts to Significant Processes
Material Account
Significant Process(es)
Location(s)
System(s)
[Account]
[Process]
[Entity/Location]
[Application]
Step 3: Identify Key Controls
For each significant process, identify key controls: the minimum set of controls that, if operating effectively, reduce the risk of material misstatement to an acceptably low level.
Key Control Criteria:
Addresses a meaningful risk of material misstatement
Operates at a sufficient level of precision
Appropriate evidence of performance is retained
IPE (information produced by the entity) used by the control is reliable
Step 4: Determine Testing Approach
Control Frequency
Minimum Sample Size (Design)
Minimum Sample Size (Operating)
Annual
1
1
Quarterly
1
2-4
Monthly
1
2-5
Weekly
1
5-15
Daily
1
20-25
Per transaction
1
25-60 (based on population size)
Operating Effectiveness Sample Sizes by Population:
Population Size
Sample Size (Low Risk)
Sample Size (High Risk)
< 50
5-10
10-20
50-250
15-20
25-40
250-1,000
20-25
40-60
> 1,000
25
45-60
6. Risk-Control Matrix (RCM) Design
Each significant process requires an RCM with the following structure:
Field
Description
Process
Business process name
Sub-process
Specific activity within the process
Risk ID
Unique identifier
Risk Description
What could go wrong (specific to financial reporting)
A control does not allow management or employees to prevent or detect misstatements on a timely basis in the normal course of performing their functions
Documented; tracked for remediation
Significant Deficiency
A deficiency, or combination of deficiencies, that is less severe than a material weakness yet important enough to merit attention by those charged with governance
Reported to audit committee; remediation plan required
Material Weakness
A deficiency, or combination of deficiencies, such that there is a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis
Disclosed publicly (SOX); immediate remediation; auditor communication
Deficiency Evaluation Factors:
Likelihood of misstatement occurring
Magnitude of potential misstatement (quantitative)
Nature of financial statement accounts affected (qualitative)
Whether compensating controls exist
Whether the deficiency is systemic or isolated
8. Remediation Planning
Remediation Priority Matrix:
Priority
Criteria
Timeline
Immediate
Material weakness; regulatory deadline; active audit finding
0-30 days
High
Significant deficiency; multiple related deficiencies; fraud risk
30-90 days
Medium
Control deficiency with no compensating control; efficiency opportunity
90-180 days
Low
Control deficiency with compensating control; best practice enhancement
180-365 days
9. Management Testing vs. External Auditor Reliance
Factor
Management Testing
External Auditor Testing
Objective
Assess control effectiveness for management assertion (SOX 302/404a)
Form opinion on ICFR effectiveness (SOX 404b)
Scope
All key controls across all significant processes
Risk-based selection; may rely on management testing
Auditor Reliance Factors
N/A
Competence and objectivity of testers; scope and results of testing; risk of the area; nature of controls
Reliance Limits
N/A
Auditor cannot rely solely on management testing for high-risk areas or entity-level controls
# Internal Controls Design & Evaluation: [Organization Name]
**Prepared**: [Date]
**Regulatory Context**: [SOX 302/404 / SOC 1/2 / Voluntary]
**Reporting Framework**: [US GAAP / IFRS]
**Materiality Base**: [Amount] ([Basis: pre-tax income / revenue / total assets])
> **Advisory Disclaimer**: This analysis provides advisory guidance on audit
> readiness and controls design. It does not constitute an audit opinion or
> assurance engagement. Statutory audit opinions must be obtained from an
> independent auditor.
---
## 1. COSO 2013 Framework Assessment
### Component Summary
| Component | Principles Assessed | Present & Functioning | Exceptions | Not Present | Component Effective? |
|-----------|-------------------|----------------------|------------|-------------|---------------------|
| Control Environment | 1-5 | X | X | X | Yes / No |
| Risk Assessment | 6-9 | X | X | X | Yes / No |
| Control Activities | 10-12 | X | X | X | Yes / No |
| Information & Communication | 13-15 | X | X | X | Yes / No |
| Monitoring Activities | 16-17 | X | X | X | Yes / No |
**Overall ICFR Effectiveness**: [Effective / Not Effective - due to deficiencies in Components X, Y]
### Detailed Principle Assessment
| # | Principle | Score | Evidence | Gaps Identified |
|---|-----------|-------|----------|----------------|
| 1 | Integrity and ethical values | P / E / N | [Evidence] | [Gaps] |
| 2 | Board oversight | P / E / N | [Evidence] | [Gaps] |
| ... | ... | ... | ... | ... |
| 17 | Evaluates and communicates deficiencies | P / E / N | [Evidence] | [Gaps] |
---
## 2. SOX Scoping
### Material Accounts and Significant Processes
| Material Account | Balance / Activity | Significant Process | Location(s) | Key System(s) | Risk Level |
|-----------------|-------------------|--------------------|--------------|----|-----------|
| [Account] | $[Amount] | [Process] | [Location] | [System] | High / Med / Low |
### Key Controls Identified
| Control ID | Process | Control Description | Type | Nature | Frequency | Assertion(s) | Key Control? |
|-----------|---------|--------------------|----|--------|-----------|-------------|-------------|
| [ID] | [Process] | [Description] | Prev/Det | Man/Auto/ITDM | [Freq] | E/O, C, V/A, R/O, P/D | Yes / No |
---
## 3. Risk-Control Matrices
### [Process Name] RCM
| Risk ID | Risk Description | Assertion | Account | Control ID | Control Description | Type | Nature | Freq | Key? | IPE | ITGC Dep. |
|---------|-----------------|-----------|---------|-----------|--------------------|----|--------|-----|------|-----|-----------|
| [ID] | [Risk] | [Assert] | [Acct] | [ID] | [Control] | [Type] | [Nature] | [Freq] | Y/N | [IPE] | [ITGC] |
*(Repeat for each significant process)*
---
## 4. IT General Controls Assessment
| ITGC Domain | Application/System | Control Objective | Control Description | Status | Gaps |
|-------------|-------------------|-------------------|--------------------|----|------|
| Access Security | [System] | [Objective] | [Control] | Effective / Gap | [Details] |
| Change Management | [System] | [Objective] | [Control] | Effective / Gap | [Details] |
| Computer Operations | [System] | [Objective] | [Control] | Effective / Gap | [Details] |
| Program Development | [System] | [Objective] | [Control] | Effective / Gap | [Details] |
---
## 5. Control Testing Plan
| Control ID | Test Procedure | Sample Size | Population | Testing Period | Tester | Status |
|-----------|---------------|-------------|-----------|---------------|--------|--------|
| [ID] | [Procedure] | [Size] | [Population] | [Period] | [Role] | Planned / Complete |
---
## 6. Deficiency Register
| Deficiency ID | Process | Control ID | Description | Classification | Root Cause | Compensating Control? |
|--------------|---------|-----------|-------------|---------------|------------|----------------------|
| [ID] | [Process] | [Control] | [Description] | CD / SD / MW | [Cause] | Yes (describe) / No |
---
## 7. Remediation Plan
| Priority | Deficiency ID | Remediation Action | Owner | Start Date | Target Date | Validation Method | Status |
|----------|--------------|-------------------|-------|------------|------------|-------------------|--------|
| Immediate | [ID] | [Action] | [Role] | [Date] | [Date] | [Method] | [Status] |
| High | [ID] | [Action] | [Role] | [Date] | [Date] | [Method] | [Status] |
| Medium | [ID] | [Action] | [Role] | [Date] | [Date] | [Method] | [Status] |
---
## 8. Management Testing Program
| Quarter | Controls to Test | Sample Period | Testing Deadline | Results Due | Auditor Reliance Expected? |
|---------|-----------------|--------------|-----------------|------------|---------------------------|
| Q1 | [Control IDs] | [Period] | [Date] | [Date] | Yes / No |
| Q2 | [Control IDs] | [Period] | [Date] | [Date] | Yes / No |
| Q3 | [Control IDs] | [Period] | [Date] | [Date] | Yes / No |
| Q4 | [Control IDs] | [Period] | [Date] | [Date] | Yes / No |
---
*Advisory recommendation vs. audit requirement: Control design recommendations in this document reflect advisory best practices based on the COSO 2013 framework. The determination of control effectiveness for SOX compliance purposes is made by the external auditor during the integrated audit.*
*Engagement sequences: SOX Implementation (risk assessment -> control design -> testing -> remediation) | IPO Track (audit readiness -> internal controls -> financial reporting -> ESG).*
Quality Checks
All 5 COSO components assessed with all 17 principles individually scored
Financial statement assertions (E/O, C, V/A, R/O, P/D) mapped to every key control
Control activities classified by nature (preventive/detective), type (manual/automated), and frequency
Entity-level controls, process-level controls, and ITGCs all addressed
SOX scoping includes material accounts, significant processes, and key control identification
Risk-control matrices provided for each significant process in scope
ITGC assessment covers all 4 domains (access, change, operations, development)
Sample sizes documented per control frequency and population size
Deficiencies classified using 3-tier framework (deficiency / significant deficiency / material weakness)
Remediation plan prioritized with timelines, owners, and validation methods
Management testing program addresses auditor reliance considerations
Advisory disclaimer is prominently displayed in the output
Deliverable distinguishes advisory recommendations from audit requirements
1---2name: internal-controls-design3description: Internal controls design and evaluation using the COSO 2013 framework. USE THIS SKILL when the user asks about SOX compliance, COSO framework, control design, internal controls, control environment, risk-control matrices, control deficiencies, material weakness, ITGCs, segregation of duties, control testing, or any engagement involving the design, documentation, or assessment of internal controls over financial reporting. Produces COSO-aligned control frameworks, risk-control matrices, testing plans, and deficiency remediation roadmaps.4---56# Internal Controls Design & Evaluation78## Required Inputs910- **Organization**: Company name, industry, size (revenue, headcount), and public/private status11- **Scope**: Full entity, specific process areas, or IT general controls12- **Regulatory Context**: SOX 302/404, SOC 1/2, regulatory exam, voluntary adoption13- **Reporting Framework**: US GAAP, IFRS, or other applicable standards14- **Material Accounts**: Key financial statement line items in scope15- **Known Issues** (optional): Prior deficiencies, auditor findings, management concerns16- **Systems Environment**: ERP, GL, and key financial applications in use1718## Execution Steps1920### 1. COSO 2013 Internal Control Framework Assessment2122Evaluate the organization against all 5 components and 17 principles of the COSO 2013 Integrated Framework. Each principle is scored as Present & Functioning (P), Present with Exceptions (E), or Not Present (N).2324**Component 1: Control Environment**2526| # | Principle | Key Assessment Areas | Score |27|---|-----------|---------------------|-------|28| 1 | Commitment to integrity and ethical values | Code of conduct, ethics hotline, tone at the top, consequence management | P / E / N |29| 2 | Board exercises oversight responsibility | Audit committee charter, meeting frequency, financial expertise, independence | P / E / N |30| 3 | Management establishes structure, authority, and responsibility | Org structure, reporting lines, delegation of authority matrix | P / E / N |31| 4 | Commitment to competence | Job descriptions, hiring standards, training programs, performance evaluation | P / E / N |32| 5 | Enforces accountability | Performance metrics tied to controls, escalation procedures, corrective action | P / E / N |3334**Component 2: Risk Assessment**3536| # | Principle | Key Assessment Areas | Score |37|---|-----------|---------------------|-------|38| 6 | Specifies suitable objectives | Financial reporting objectives linked to assertions; clear and measurable | P / E / N |39| 7 | Identifies and analyzes risk | Risk identification process; considers internal and external factors | P / E / N |40| 8 | Assesses fraud risk | Fraud risk assessment covering incentive, opportunity, rationalization | P / E / N |41| 9 | Identifies and analyzes significant change | Change management triggers; M&A, new products, system changes, regulatory | P / E / N |4243**Component 3: Control Activities**4445| # | Principle | Key Assessment Areas | Score |46|---|-----------|---------------------|-------|47| 10 | Selects and develops control activities | Controls address identified risks; mix of preventive and detective | P / E / N |48| 11 | Selects and develops technology general controls | ITGCs over access, change management, operations, development | P / E / N |49| 12 | Deploys through policies and procedures | Written policies; procedures documented; controls embedded in process | P / E / N |5051**Component 4: Information & Communication**5253| # | Principle | Key Assessment Areas | Score |54|---|-----------|---------------------|-------|55| 13 | Uses relevant information | Information quality; data sources identified; relevant to control objectives | P / E / N |56| 14 | Communicates internally | Control responsibilities communicated; reporting channels established | P / E / N |57| 15 | Communicates externally | External reporting processes; regulatory communication; whistleblower channels | P / E / N |5859**Component 5: Monitoring Activities**6061| # | Principle | Key Assessment Areas | Score |62|---|-----------|---------------------|-------|63| 16 | Conducts ongoing and/or separate evaluations | Management testing program; continuous monitoring; self-assessments | P / E / N |64| 17 | Evaluates and communicates deficiencies | Deficiency identification; classification; escalation to audit committee | P / E / N |6566**COSO Assessment Summary**: A component is effective only when ALL underlying principles are Present & Functioning. The system of internal control is effective only when ALL 5 components are effective.6768### 2. Financial Statement Assertion Mapping6970Map controls to the 5 financial statement assertions for each significant account:7172| Assertion | Abbreviation | Definition | Example Controls |73|-----------|-------------|------------|-----------------|74| Existence / Occurrence | E/O | Assets/liabilities exist; transactions occurred | Physical inventory counts; bank confirmations; transaction matching |75| Completeness | C | All transactions and balances are recorded | Sequence checks; 3-way match (PO-receipt-invoice); reconciliation to third party |76| Valuation / Allocation | V/A | Amounts are recorded at appropriate values | Reserve calculations; impairment testing; fair value models; aging analysis |77| Rights & Obligations | R/O | Entity holds rights to assets; liabilities are obligations | Title documents; contract review; lien searches; confirmation of terms |78| Presentation & Disclosure | P/D | Properly classified, described, and disclosed | Disclosure checklists; financial statement review; classification mapping |7980### 3. Control Activity Design Methodology8182For each identified risk, design a control activity using the following classification framework:8384**Control Classification Matrix:**8586| Dimension | Options | Considerations |87|-----------|---------|---------------|88| **Nature** | Preventive / Detective | Preventive preferred; detective needed as backup layer |89| **Type** | Manual / Automated / IT-Dependent Manual | Automated controls preferred for consistency and efficiency |90| **Frequency** | Transaction-level / Daily / Weekly / Monthly / Quarterly / Annual | Match to transaction volume and risk level |91| **Level** | Entity-Level / Process-Level / Transaction-Level | Entity-level are pervasive; process-level are targeted |9293**Control Design Requirements (each control must specify):**941. **Objective**: What risk does this control mitigate?952. **Assertion(s)**: Which financial statement assertions does it address?963. **Description**: What is performed, by whom, how, and when?974. **Evidence**: What documentation is produced and retained?985. **Precision**: How sensitive is the control to detecting a material error?996. **IPE (Information Produced by the Entity)**: What reports or data does the control rely on?100101### 4. Control Hierarchy: Entity-Level, Process-Level, and ITGCs102103**Entity-Level Controls (ELCs):**104105| Category | Examples | Mapping |106|----------|----------|---------|107| Control Environment | Code of conduct, audit committee oversight, delegation of authority | COSO Principles 1-5 |108| Risk Assessment | Enterprise risk management, fraud risk program | COSO Principles 6-9 |109| Monitoring | Internal audit function, management self-assessment program | COSO Principles 16-17 |110| Information & Communication | Reporting structure, whistleblower program, policy dissemination | COSO Principles 13-15 |111112ELCs operate at the "indirect" level. They do not replace process-level controls but may influence the extent of testing required.113114**Process-Level Controls (PLCs):**115116Design process-level controls for each significant process. Standard significant processes include:117118| Process | Key Risks | Typical Key Controls |119|---------|-----------|---------------------|120| Revenue / Receivables | Revenue recognized prematurely or fictitiously; uncollectible receivables | Contract review and approval; credit approval; shipping/delivery confirmation; AR aging review; reserve calculation |121| Procurement / Payables | Unauthorized purchases; duplicate payments; unrecorded liabilities | Purchase requisition approval; 3-way match; vendor master maintenance; AP aging review; cutoff procedures |122| Inventory | Incorrect valuation; obsolete inventory; existence | Physical inventory counts; standard cost updates; NRV analysis; cycle count program |123| Payroll | Ghost employees; incorrect compensation; unauthorized changes | New hire authorization; pay rate changes approval; payroll register review; bank reconciliation |124| Treasury / Cash | Unauthorized transactions; incorrect cash balance | Bank reconciliation; dual signatures; wire transfer approval; investment authorization |125| Financial Close | Misstatement in financial statements | Close calendar; JE approval; account reconciliations; variance analysis; management review |126| Equity / Stock Comp | Incorrect fair value; unauthorized issuance | Board approval of grants; valuation model review; vesting schedule tracking; expense calculation review |127128**IT General Controls (ITGCs):**129130| ITGC Domain | Control Objective | Key Controls |131|-------------|-------------------|-------------|132| **Access Security** | Only authorized users access systems and data | Access provisioning with approval; periodic access reviews (quarterly); privileged access monitoring; password policies; terminated user removal within 24 hours |133| **Change Management** | Changes are authorized, tested, and approved | Change request documentation; segregation of dev/test/prod; testing evidence; approval prior to migration; emergency change procedures |134| **Computer Operations** | Systems operate reliably and data is protected | Job scheduling and monitoring; backup procedures with offsite storage; backup restoration testing; incident management; disaster recovery planning |135| **Program Development** | New systems are properly designed and implemented | SDLC methodology; requirements documentation; user acceptance testing; data migration validation; post-implementation review |136137### 5. SOX Scoping Methodology138139**Step 1: Identify Material Accounts**140141A financial statement line item is material if a misstatement could reasonably influence economic decisions. Apply quantitative and qualitative materiality:142143- **Quantitative**: Typically 5% of pre-tax income (or alternative base: revenue, total assets)144- **Qualitative**: Items involving estimates, judgments, fraud risk, related parties, unusual transactions145146**Step 2: Map Material Accounts to Significant Processes**147148| Material Account | Significant Process(es) | Location(s) | System(s) |149|-----------------|------------------------|-------------|-----------|150| [Account] | [Process] | [Entity/Location] | [Application] |151152**Step 3: Identify Key Controls**153154For each significant process, identify key controls: the minimum set of controls that, if operating effectively, reduce the risk of material misstatement to an acceptably low level.155156Key Control Criteria:157- Addresses a meaningful risk of material misstatement158- Operates at a sufficient level of precision159- Appropriate evidence of performance is retained160- IPE (information produced by the entity) used by the control is reliable161162**Step 4: Determine Testing Approach**163164| Control Frequency | Minimum Sample Size (Design) | Minimum Sample Size (Operating) |165|-------------------|------------------------------|-------------------------------|166| Annual | 1 | 1 |167| Quarterly | 1 | 2-4 |168| Monthly | 1 | 2-5 |169| Weekly | 1 | 5-15 |170| Daily | 1 | 20-25 |171| Per transaction | 1 | 25-60 (based on population size) |172173**Operating Effectiveness Sample Sizes by Population:**174175| Population Size | Sample Size (Low Risk) | Sample Size (High Risk) |176|----------------|----------------------|------------------------|177| < 50 | 5-10 | 10-20 |178| 50-250 | 15-20 | 25-40 |179| 250-1,000 | 20-25 | 40-60 |180| > 1,000 | 25 | 45-60 |181182### 6. Risk-Control Matrix (RCM) Design183184Each significant process requires an RCM with the following structure:185186| Field | Description |187|-------|-------------|188| Process | Business process name |189| Sub-process | Specific activity within the process |190| Risk ID | Unique identifier |191| Risk Description | What could go wrong (specific to financial reporting) |192| Assertion(s) | E/O, C, V/A, R/O, P/D |193| Account(s) Affected | Financial statement line items |194| Control ID | Unique identifier |195| Control Description | Who does what, when, how, and what evidence |196| Control Type | Preventive / Detective |197| Control Nature | Manual / Automated / IT-Dependent Manual |198| Control Frequency | Transaction / Daily / Weekly / Monthly / Quarterly / Annual |199| Key Control? | Yes / No |200| IPE Used | Reports or data the control depends on |201| ITGC Dependencies | Related IT general controls |202203### 7. Deficiency Classification204205| Classification | Definition | Escalation |206|---------------|------------|------------|207| **Control Deficiency** | A control does not allow management or employees to prevent or detect misstatements on a timely basis in the normal course of performing their functions | Documented; tracked for remediation |208| **Significant Deficiency** | A deficiency, or combination of deficiencies, that is less severe than a material weakness yet important enough to merit attention by those charged with governance | Reported to audit committee; remediation plan required |209| **Material Weakness** | A deficiency, or combination of deficiencies, such that there is a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis | Disclosed publicly (SOX); immediate remediation; auditor communication |210211**Deficiency Evaluation Factors:**212- Likelihood of misstatement occurring213- Magnitude of potential misstatement (quantitative)214- Nature of financial statement accounts affected (qualitative)215- Whether compensating controls exist216- Whether the deficiency is systemic or isolated217218### 8. Remediation Planning219220**Remediation Priority Matrix:**221222| Priority | Criteria | Timeline |223|----------|----------|----------|224| **Immediate** | Material weakness; regulatory deadline; active audit finding | 0-30 days |225| **High** | Significant deficiency; multiple related deficiencies; fraud risk | 30-90 days |226| **Medium** | Control deficiency with no compensating control; efficiency opportunity | 90-180 days |227| **Low** | Control deficiency with compensating control; best practice enhancement | 180-365 days |228229### 9. Management Testing vs. External Auditor Reliance230231| Factor | Management Testing | External Auditor Testing |232|--------|-------------------|------------------------|233| **Objective** | Assess control effectiveness for management assertion (SOX 302/404a) | Form opinion on ICFR effectiveness (SOX 404b) |234| **Scope** | All key controls across all significant processes | Risk-based selection; may rely on management testing |235| **Auditor Reliance Factors** | N/A | Competence and objectivity of testers; scope and results of testing; risk of the area; nature of controls |236| **Reliance Limits** | N/A | Auditor cannot rely solely on management testing for high-risk areas or entity-level controls |237| **Documentation** | Testing workpapers; sample selection; results; conclusions | Independent re-performance; documentation review; sample testing |238239## Output Template240241```markdown242# Internal Controls Design & Evaluation: [Organization Name]243244**Prepared**: [Date]245**Regulatory Context**: [SOX 302/404 / SOC 1/2 / Voluntary]246**Reporting Framework**: [US GAAP / IFRS]247**Materiality Base**: [Amount] ([Basis: pre-tax income / revenue / total assets])248249> **Advisory Disclaimer**: This analysis provides advisory guidance on audit250> readiness and controls design. It does not constitute an audit opinion or251> assurance engagement. Statutory audit opinions must be obtained from an252> independent auditor.253254---255256## 1. COSO 2013 Framework Assessment257258### Component Summary259260| Component | Principles Assessed | Present & Functioning | Exceptions | Not Present | Component Effective? |261|-----------|-------------------|----------------------|------------|-------------|---------------------|262| Control Environment | 1-5 | X | X | X | Yes / No |263| Risk Assessment | 6-9 | X | X | X | Yes / No |264| Control Activities | 10-12 | X | X | X | Yes / No |265| Information & Communication | 13-15 | X | X | X | Yes / No |266| Monitoring Activities | 16-17 | X | X | X | Yes / No |267268**Overall ICFR Effectiveness**: [Effective / Not Effective - due to deficiencies in Components X, Y]269270### Detailed Principle Assessment271272| # | Principle | Score | Evidence | Gaps Identified |273|---|-----------|-------|----------|----------------|274| 1 | Integrity and ethical values | P / E / N | [Evidence] | [Gaps] |275| 2 | Board oversight | P / E / N | [Evidence] | [Gaps] |276| ... | ... | ... | ... | ... |277| 17 | Evaluates and communicates deficiencies | P / E / N | [Evidence] | [Gaps] |278279---280281## 2. SOX Scoping282283### Material Accounts and Significant Processes284285| Material Account | Balance / Activity | Significant Process | Location(s) | Key System(s) | Risk Level |286|-----------------|-------------------|--------------------|--------------|----|-----------|287| [Account] | $[Amount] | [Process] | [Location] | [System] | High / Med / Low |288289### Key Controls Identified290291| Control ID | Process | Control Description | Type | Nature | Frequency | Assertion(s) | Key Control? |292|-----------|---------|--------------------|----|--------|-----------|-------------|-------------|293| [ID] | [Process] | [Description] | Prev/Det | Man/Auto/ITDM | [Freq] | E/O, C, V/A, R/O, P/D | Yes / No |294295---296297## 3. Risk-Control Matrices298299### [Process Name] RCM300301| Risk ID | Risk Description | Assertion | Account | Control ID | Control Description | Type | Nature | Freq | Key? | IPE | ITGC Dep. |302|---------|-----------------|-----------|---------|-----------|--------------------|----|--------|-----|------|-----|-----------|303| [ID] | [Risk] | [Assert] | [Acct] | [ID] | [Control] | [Type] | [Nature] | [Freq] | Y/N | [IPE] | [ITGC] |304305*(Repeat for each significant process)*306307---308309## 4. IT General Controls Assessment310311| ITGC Domain | Application/System | Control Objective | Control Description | Status | Gaps |312|-------------|-------------------|-------------------|--------------------|----|------|313| Access Security | [System] | [Objective] | [Control] | Effective / Gap | [Details] |314| Change Management | [System] | [Objective] | [Control] | Effective / Gap | [Details] |315| Computer Operations | [System] | [Objective] | [Control] | Effective / Gap | [Details] |316| Program Development | [System] | [Objective] | [Control] | Effective / Gap | [Details] |317318---319320## 5. Control Testing Plan321322| Control ID | Test Procedure | Sample Size | Population | Testing Period | Tester | Status |323|-----------|---------------|-------------|-----------|---------------|--------|--------|324| [ID] | [Procedure] | [Size] | [Population] | [Period] | [Role] | Planned / Complete |325326---327328## 6. Deficiency Register329330| Deficiency ID | Process | Control ID | Description | Classification | Root Cause | Compensating Control? |331|--------------|---------|-----------|-------------|---------------|------------|----------------------|332| [ID] | [Process] | [Control] | [Description] | CD / SD / MW | [Cause] | Yes (describe) / No |333334---335336## 7. Remediation Plan337338| Priority | Deficiency ID | Remediation Action | Owner | Start Date | Target Date | Validation Method | Status |339|----------|--------------|-------------------|-------|------------|------------|-------------------|--------|340| Immediate | [ID] | [Action] | [Role] | [Date] | [Date] | [Method] | [Status] |341| High | [ID] | [Action] | [Role] | [Date] | [Date] | [Method] | [Status] |342| Medium | [ID] | [Action] | [Role] | [Date] | [Date] | [Method] | [Status] |343344---345346## 8. Management Testing Program347348| Quarter | Controls to Test | Sample Period | Testing Deadline | Results Due | Auditor Reliance Expected? |349|---------|-----------------|--------------|-----------------|------------|---------------------------|350| Q1 | [Control IDs] | [Period] | [Date] | [Date] | Yes / No |351| Q2 | [Control IDs] | [Period] | [Date] | [Date] | Yes / No |352| Q3 | [Control IDs] | [Period] | [Date] | [Date] | Yes / No |353| Q4 | [Control IDs] | [Period] | [Date] | [Date] | Yes / No |354355---356357*Advisory recommendation vs. audit requirement: Control design recommendations in this document reflect advisory best practices based on the COSO 2013 framework. The determination of control effectiveness for SOX compliance purposes is made by the external auditor during the integrated audit.*358359*Engagement sequences: SOX Implementation (risk assessment -> control design -> testing -> remediation) | IPO Track (audit readiness -> internal controls -> financial reporting -> ESG).*360```361362## Quality Checks363364- [ ] All 5 COSO components assessed with all 17 principles individually scored365- [ ] Financial statement assertions (E/O, C, V/A, R/O, P/D) mapped to every key control366- [ ] Control activities classified by nature (preventive/detective), type (manual/automated), and frequency367- [ ] Entity-level controls, process-level controls, and ITGCs all addressed368- [ ] SOX scoping includes material accounts, significant processes, and key control identification369- [ ] Risk-control matrices provided for each significant process in scope370- [ ] ITGC assessment covers all 4 domains (access, change, operations, development)371- [ ] Sample sizes documented per control frequency and population size372- [ ] Deficiencies classified using 3-tier framework (deficiency / significant deficiency / material weakness)373- [ ] Remediation plan prioritized with timelines, owners, and validation methods374- [ ] Management testing program addresses auditor reliance considerations375- [ ] Advisory disclaimer is prominently displayed in the output376- [ ] Deliverable distinguishes advisory recommendations from audit requirements
Run npx skillmds@latest add kaakati/internal-controls-design in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
Internal controls design and evaluation using the COSO 2013 framework. USE THIS SKILL when the user asks about SOX compliance, COSO framework, control design, internal controls, control environment, risk-control matrices, control deficiencies, material weakness, ITGCs, segregation of duties, control testing, or any engagement involving the design, documentation, or assessment of internal controls over financial reporting. Produces COSO-aligned control frameworks, risk-control matrices, testing plans, and deficiency remediation roadmaps. It is listed under Docs & Writing on SkillMD.
This skill has not completed SkillMD's automated safety review yet. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
Kaakati (@kaakati) published this skill. Their other Agent Skills are listed on their SkillMD profile.