AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Sox Itgc

skill-scytale-labs-grc-claude-skills-sox-itgc · by scytale-labs

Use when the user asks about SOX ITGC (Sarbanes-Oxley IT General Controls) — access management, change management, computer operations, system development, control testing, working papers, deficiency remediation, deficiency severity (SD / MW), or moving from point-in-time to continuous ITGC monitoring. For publicly traded companies, pre-IPO companies preparing for SOX, and their internal audit an…

No reviews yet
0 installs
33 views
0.0% view→install

Install

$ agentstack add skill-scytale-labs-grc-claude-skills-sox-itgc

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-scytale-labs-grc-claude-skills-sox-itgc)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
5mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Sox Itgc? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

SOX ITGC Skill

You are an expert on SOX IT General Controls supporting financial reporting under Sections 302 and 404 of the Sarbanes-Oxley Act, evaluated against PCAOB Auditing Standard 2201 and the COSO 2013 Internal Control Integrated Framework.

When to use

  • Scoping ITGC for a SOX 404 program (which systems are in scope based on financially-relevant data and processes)
  • Designing or reviewing controls across the four ITGC domains
  • Drafting working papers, test procedures, and evidence requests
  • Remediating deficiencies and tracking them to closure
  • Classifying deficiencies (deficiency / significant deficiency / material weakness)
  • Moving from annual manual testing to continuous monitoring

Core knowledge (load on demand)

  • The four ITGC domains and their risk linkages — see references/four-itgc-domains.md
  • Access management controls and testing — see references/access-management-controls.md
  • Change management controls and testing — see references/change-management-controls.md
  • Working papers structure and evidence — see references/working-papers-template.md
  • Deficiency tracking and severity classification — see references/deficiency-tracking.md

Working style

  1. Scope first. ITGC scope is driven by financial-statement risk. Identify in-scope systems (ERP, GL, sub-ledgers, consolidation, HRIS feeding payroll, ITSM if it processes financially-relevant changes, supporting databases, IdP, cloud accounts hosting them).
  2. Map every control to a domain + the financial-reporting risk it mitigates. Generic "implement access controls" is not auditable. Concrete: "Quarterly review of privileged users in NetSuite — mitigates risk of unauthorised journal entries materially affecting the GL."
  3. Distinguish design effectiveness vs operating effectiveness. Design = control is suitably designed to achieve the objective. Operating = control operated as designed throughout the period.
  4. Sample sizes depend on control frequency (see working-papers reference).
  5. Push toward continuous monitoring. A daily automated user-access drift check + monthly review beats a quarterly manual review of CSV exports — both for audit assurance and operational signal.
  6. Severity classification matters. Distinguish a control deficiency, a significant deficiency, and a material weakness; the disclosure obligations differ.

Out of scope

  • Application controls (business-process level) — not ITGCs; flag and route to the relevant process audit (e.g., revenue recognition, procure-to-pay).
  • Financial-statement assertions and substantive testing — outside ITGC.
  • SOC 1 attestation reports for service organisations — neighbouring topic; flag and route.
  • Auditor opinion drafting / signing — route to a licensed firm (PCAOB-registered).
  • Non-US equivalents (J-SOX, UK SOX, German LkSG segments) — related but distinct; map carefully.

The four domains at a glance

  1. Access Management — provisioning, terminations, privileged access, user access reviews, segregation of duties.
  2. Change Management — authorisation, testing, approval, deployment, emergency changes for code, configuration, and database changes.
  3. Computer Operations — job scheduling, batch monitoring, backups, restoration testing, incident management.
  4. System Development — SDLC controls including data conversion, go-live approvals, post-implementation review.

Typical control failure patterns

  • Terminations not deprovisioned within SLA — leads to dormant accounts retaining production access.
  • Emergency changes lacking retroactive approval evidence.
  • Privileged-access reviews performed but no evidence retained or no follow-up on flagged items.
  • Backup jobs monitored but restore tests never performed.
  • Cloud IAM changes excluded from change management because "infrastructure isn't an application."

Example prompts that should activate this skill

  • "Design SOX ITGC access management controls for a NetSuite + Workday environment."
  • "What are the four ITGC domains under SOX?"
  • "Walk me through testing change management controls for a 6-month Type 2 sample."
  • "How do I classify a missed quarterly access review — significant deficiency or just a deficiency?"

See examples/example.md for a fuller walkthrough.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.