
SOX/AML Compliance Assistant
Generate audit-ready SOX/AML compliance documentation and risk assessments
What You Can Do
This skill generates production-ready compliance documentation, audit-trail policies, and anti-money-laundering procedures that meet SOX and federal regulatory requirements. You receive templated policies, risk assessment frameworks, control matrices, and audit evidence documentation that your compliance and finance teams can immediately adapt and deploy. Streamline audit preparation, reduce legal review cycles, and ensure your compliance program meets FinCEN, OCC, and Federal Reserve expectations.
Features
Generates compliance templates and policies that meet SOX standards with control descriptions, risk assessments, and test procedures auditors expect to see.
Creates customizable Know-Your-Customer (KYC), Customer Due Diligence (CDD), transaction monitoring, and Suspicious Activity Report (SAR) procedures.
Automated risk scoring for financial operations with likelihood/impact matrices, control effectiveness evaluation, and inherent vs. residual risk analysis.
Generates control narratives, COSO framework mappings, test procedures, evidence requirements, and exception-handling templates for compliance teams.
Ensures documentation references applicable regulations (FinCEN guidance, OCC bulletins, Federal Reserve expectations, state requirements) specific to your institution type.
Pre-audit readiness checklists covering key control areas, evidence gathering tasks, and common audit findings to address before examiner reviews.
Provides prioritized remediation plans for control gaps and audit findings with implementation timelines and responsibility assignments.
Example Output
Example 1: KYC Procedure
Know-Your-Customer Procedure v2.1
1. Customer Identification Program (CIP)
- Collect: Full legal name, DOB, address, government ID
- Verify: Cross-reference against OFAC/SDN list (daily automated)
- Document: Retain verification evidence for 5 years
- Exception: Escalate unverified identities within 48 hours
2. Risk Classification
Risk Level | Triggers | CDD Depth | Review Frequency
Low | Retail customer, US address | Standard KYC | Annually
Medium | Foreign entity, PEP status | Enhanced CDD | Semi-annually
High | High-risk jurisdiction, beneficial ownership opaque | Full investigation | Quarterly
Example 2: Risk Assessment Matrix
Process: Accounts Payable
Control Risk | Likelihood | Impact | Rating | Existing Mitigant | Residual Risk
Unauthorized payment | Medium | High | 15 (High) | Dual approval required >$50K | 6 (Medium)
Inaccurate GL coding | Low | Medium | 4 (Low) | Automated GL validation | 2 (Low)
Third-party fraud | Medium | High | 15 (High) | Vendor master controls | 9 (Medium)
Example 3: Audit Readiness Checklist
☑ SOX Control Documentation
☑ 50 control narratives completed with risk assessment
☑ Test procedures defined for all key controls (n=47)
☑ 2024 control test evidence collected and organized
☑ Exception reports compiled (instances, root causes, remediation)
☑ Change management log for IT controls
☑ AML Program
☑ Updated KYC procedures with CDD enhancement matrix
☑ Transaction monitoring results (Jan-Dec) with false positive review
☑ SAR filing documentation (3 SARs filed, evidence retained)
☑ OFAC screening logs (daily automated + monthly manual review)
What's Included
- SOX Policy Templates: Control documentation frameworks, process narratives, and risk assessment templates for financial reporting controls (GL reconciliation, journal entry authorization, account close procedures).
- AML Procedures: Complete procedures for Know-Your-Customer (KYC), Enhanced Due Diligence (EDD), transaction monitoring, suspicious activity detection, and SAR filing.
- Risk Assessment Tool: Automated risk scoring framework with likelihood/impact matrices, COSO alignment, and control effectiveness evaluation methodology.
- Audit Evidence Tracker: Templates for control test documentation, exception reports, remediation tracking, and audit response workpapers.
- Compliance Checklists: Pre-audit readiness assessment tools, regulatory requirement cross-references, and control gap identification worksheets.
Who It's For
- Compliance Officers
- Internal Auditors
- Risk Management Professionals
- Finance Controllers and Controllers' Staff
- Legal and Compliance Teams
Best For
- SOX Control Documentation and Testing
- AML Policy Development and Updates
- Pre-Audit Compliance Preparation
- Compliance Gap Analysis and Remediation Planning
- Regulatory Reporting and Examiner Responses







