
Internal Audit Documentation Analyzer
Analyze audit evidence and control documentation to identify gaps and develop findings
What You Can Do
You can upload control documentation, audit evidence, compliance artifacts, and audit trails for Claude to analyze systematically. Claude identifies control design weaknesses, tests the adequacy of your audit procedures, quantifies risk exposure, and generates audit findings with explicit linkage to control frameworks and risk registers. This reduces manual documentation synthesis by 40-60% while improving consistency across multiple control areas.
Features
Analyzes design and operating effectiveness documentation to surface control weaknesses against audit requirements and frameworks
Evaluates whether testing evidence supports your control conclusions and flags insufficient or contradictory documentation
Structures risk impact analysis by linking control deficiencies to business processes and quantifying exposure
Generates audit findings with explicit condition, criteria, cause, and effect linkage to support audit conclusions
Identifies systemic issues across multiple control areas and highlights root causes across the control environment
Analyzes approval chains, reconciliations, exception logs, and audit trails to validate operating effectiveness
Links findings and test results to relevant control frameworks (COSO, SOX, ISO) for report alignment
Assesses whether audit procedures and sample sizes provide sufficient evidence for control conclusions
Example Output
Input: Control procedure documentation for a cash disbursement process, supporting evidence of authorization testing, and a sample of transactions
Output:
CONTROL FINDING: Insufficient Segregation of Duties
- CONDITION: In 15 of 50 transactions tested, the same individual both approved and processed payment
- CRITERIA: SOX 404(b) requires segregation of authorization and execution duties
- CAUSE: System configuration allows same user role for both functions; supervisory review compensating control not consistently applied
- EFFECT: Increased risk of unauthorized or erroneous payments; estimated monthly exposure $240K
- RISK RATING: Medium → High (if approval delays increase volume)
- RECOMMENDATION: Restrict user role permissions or implement mandatory dual approval for >$100K
Input: Board-approved reconciliation procedures vs. actual performed reconciliations
Output: Testing inadequacy flag — sample size of 10 reconciliations insufficient for quarterly population of 180; recommend expanding to 30 with documented sampling methodology.
What's Included
- SKILL.md instruction file: Complete system prompt for control documentation analysis workflows
- Control Gap Assessment Template: Structured checklist for identifying design vs. operating effectiveness gaps
- Audit Finding Framework: COSO-aligned template for condition-criteria-cause-effect documentation
- Risk Quantification Worksheet: Tool for converting control deficiencies into financial/operational impact metrics
- Testing Adequacy Checklist: Guidance for evaluating sample sizes, evidence completeness, and procedure effectiveness
Who It's For
- Internal auditors — Conducting control testing and developing audit findings across finance, operations, or IT domains
- Compliance managers — Evaluating control design and operating effectiveness against regulatory frameworks (SOX, GDPR, HIPAA)
- Risk and audit committee support staff — Synthesizing control assessments for board reporting
- Finance shared service leaders — Analyzing control documentation across multiple process areas to identify systemic weaknesses
- IT audit specialists — Reviewing system access controls, change management documentation, and IT control evidence
Best For
- Annual or periodic control testing programs where multiple control areas require systematic documentation review
- Remediation follow-up audits where prior-year findings need to be re-evaluated against updated procedures and evidence
- Compliance assessments against industry frameworks (COSO, COBIT, ISO) requiring linkage of controls to standards
- Preparation of audit reports and management findings requiring explicit justification and risk quantification
- Cross-functional control environment assessments identifying patterns and root causes across multiple business processes







