AI Agent Hub
Back to skills
⚖️

Internal Audit Plan and Report Generator

Professional Updated 2026.08.30

Paste the following prompt into your AI chat to install this skill:

Please install @user_f1076f6a/internal-audit according to https://skillhub.cn/install/skillhub.md.

About this skill

Problem Addressed

Internal audit projects often stall after scope is set: audit plans, risk matrices, workpapers, and findings reports need to be rebuilt repeatedly. This skill targets financial, operational, compliance, and fraud-investigation audit scenarios. It structures audit preparation into a reusable workflow: confirm audit type, scope, objective, and available materials, then generate an audit plan, risk assessment matrix, audit procedures, workpaper templates, and an audit findings report under Chinese internal audit standards. For U.S.-listed, H-share, or IFRS-reporting needs, it can add SOX 404, IFRS, and HKFRS focus areas.

How It Works

The main flow is “plan → procedure → evidence → finding → report.” It maps inherent and control risk signals across common high-risk areas such as revenue recognition, procurement-to-pay, expense reimbursement, inventory, related-party transactions, and treasury. For fraud investigations, it considers pressure, opportunity, and rationalization signals, and uses Benford's law, duplicate-transaction checks, and abnormal amount or timing detection to flag anomalies. Workpaper support includes sampling guidance, control testing, walk-through testing, COSO five-component evaluation, and SOX defect classification: material weakness, significant deficiency, and deficiency.

Boundaries

It produces audit frameworks, procedures, and report drafts, not audit conclusions. Risk ratings, remediation recommendations, and SOX defect classifications require audit management review against complete evidence. If policies, financial data, or business context are missing, output remains a generic template. Statements involving inference and verified facts must be kept separate, and the management response field must not be omitted.

Use Cases

  • Before annual audit kickoff, build risk matrix, audit procedures, and sampling plan for revenue and procurement.
  • For a fraud investigation, run Benford tests, duplicate-transaction checks, and anomaly detection on fund and expense data.
  • For U.S.-listed internal audit, draft SOX 404 control testing, defect classification, and remediation reporting.
  • When organizing workpapers, add walk-through tests, COSO evaluation, findings, and management response fields.

Best For

  • Internal audit leads: need a one-pass setup of scope, risk points, procedures, and report framework before annual audits.
  • Financial auditors: design workpapers, sampling, and confirmation checklists for revenue, procurement, and expenses.
  • Compliance auditors: map SOX 404 control testing, defect levels, and management reporting for U.S.-listed companies.
  • Fraud investigation auditors: filter anomalies in transactions, related parties, and fund flows for priority review.