Internal Controls And Audit logo

Internal Controls And Audit

CommunityPopular
cbrock84
internal-controls-and-audit

Designs and tests controls over financial reporting — segregation of duties, approval limits, evidence, and preparing for audit. Use this to design controls for a process, prepare for an external audit, respond to an audit finding, set approval thresholds, or assess where a small team's segregation of duties is genuinely broken.

Overview

Publishercbrock84
Repositoryheadcount
Skill nameinternal-controls-and-audit
Stars
1.6K
Forks
237
Bundled files
1
LicenseMIT
Links
  • Markdown instructions

    A SKILL.md file the model loads on demand, so it only costs tokens when a request actually matches.

  • Works with any LLM

    AI skills are plain Markdown, not provider-specific code, so this works with GPT, Claude, Gemini, Grok, or a local model.

  • 1 bundled files

    Scripts, templates, and references the model can read while it works. Files are read-only and never executed.

  • Open source

    Published by cbrock84 on GitHub. Read the source before you install it.

Installation

Install the Internal Controls And Audit AI skill in TypingMind to use it with any LLM, or drop it into another agent that reads SKILL.md.

1

Install in TypingMind

TypingMind installs a skill straight from its GitHub folder — it reads SKILL.md, bundles the resource files, and stores the result locally.

  1. Open the app and go to Plugins → Skills.
  2. Choose "Install from GitHub".
  3. Paste the skill folder URL below and confirm.
  4. Enable the skill in any chat where you want it available.
Plugins → Skills → Add skill → From GitHub URL, then paste the folder URL and press Continue.
2

Install in another agent

Any agent that reads the Agent Skills format can use this skill — copy the folder into that agent's skills directory.

Claude Code — .claude/skills
git clone --depth 1 https://github.com/cbrock84/headcount.git /tmp/headcount
mkdir -p .claude/skills
cp -r /tmp/headcount/plugins/finance/skills/internal-controls-and-audit .claude/skills/internal-controls-and-audit
Restart Claude Code after copying so it picks up the new skill.

Use it in TypingMind

Enable Internal Controls And Audit in any TypingMind chat and the model takes it from there. Its name and description sit in the system prompt, and the moment a request matches, the model loads the full instructions itself — you never invoke it by hand, and it costs no tokens until it is actually used.

The model loads Internal Controls And Audit on its own as soon as a request matches it.

Works with any AI model

AI skills are plain Markdown instructions rather than provider-specific code, so Internal Controls And Audit is not tied to the model it was written for. Install it once in TypingMind and use it with GPT-5, Claude, Gemini, Grok, DeepSeek, Mistral, Llama, or a local model you run yourself — all on your own API keys.

  • Loaded only when it is needed

    The system prompt carries just the name and description. The instructions are fetched on the first matching request, so an idle skill costs nothing.

  • Switch models mid-chat

    Because the skill is instructions rather than code, changing model does not break it — the next model reads the same SKILL.md.

Skill instructions

This is the SKILL.md content the model loads. Read it before installing — a skill is instructions your model will follow.

Internal controls and audit

Controls exist because a single person who can initiate, approve and record a transaction can also conceal one. Everything else is elaboration on that.

This structures control design and audit readiness. Statutory audit requirements, and regimes such as SOX where they apply, are matters for your auditors and qualified advisers.

The five components an auditor will assess

Segregation of duties is one control activity inside a much larger structure, and a team that has only built control activities will still be told its control environment is weak. Auditors assess five components, and a deficiency in any one undermines the others:

  • Control environment — integrity and ethical values, oversight by whoever plays the board role, a structure with defined responsibility and authority, competence for the work assigned, and accountability actually enforced. This is the component small organizations skip and the one that determines whether every other control holds.
  • Risk assessment — objectives defined clearly enough to have risks, risks identified and responded to, fraud risk assessed explicitly rather than assumed away, and change identified as it happens. New systems, new people, and rapid growth all invalidate control designs quietly.
  • Control activities — the controls themselves, including those over the information systems the records depend on, and evidence that they were performed rather than merely designed.
  • Information and communication — quality information available to the people who need it, communicated internally to those who act on it and externally to those who rely on it. A control nobody was told about does not operate.
  • Monitoring — someone checks that controls still work, and identified deficiencies get remediated on a timetable rather than carried forward year after year.

Two of these are consistently the weak ones in organizations under a few hundred people: fraud risk is never assessed on the reasoning that everyone is trusted, and monitoring never happens because the people who would monitor are the people who perform the controls.

Segregation of duties

Four capabilities should not sit with one person: initiating a transaction, approving it, recording it, and holding the asset. Any two combined is a risk; three is an unmonitored opportunity.

Small teams cannot always separate these. That is a normal constraint and pretending otherwise produces a fictional control matrix. Where separation is impossible, compensate visibly:

  • Review by someone outside the process, on a defined cadence rather than when convenient.
  • Exception reporting that goes to someone who is not the preparer.
  • Bank confirmations and reconciliations reviewed independently of whoever performs them.

Document the gap and the compensating control. An acknowledged, mitigated gap is a defensible position; an unacknowledged one is a finding waiting to be written.

Design controls that leave evidence

A control that happened but left no trace did not happen, as far as an auditor can determine. Each control needs a stated owner, frequency, what is examined, and an artifact produced as a by-product of doing the work — not assembled afterwards for the audit.

Prefer preventive controls, which stop the transaction, over detective ones, which find it afterwards. Prefer automated over manual: system-enforced approval limits do not have busy weeks.

Approval thresholds

Set limits by value and by risk, not value alone. A low-value payment to a new supplier deserves more scrutiny than a large one to an established counterparty on contracted terms.

Watch for splitting — transactions repeatedly landing just under a threshold is the pattern the threshold creates, and it is straightforward to monitor for.

Audit findings

Treat a finding as information. Fix the cause rather than the instance, and be skeptical of remediation that consists of more careful behavior: the same conditions will reproduce the finding with different people.

Related but distinct: legal-risk:corporate-governance owns board and entity governance, legal-risk:enterprise-risk owns the risk framework. This skill owns controls over financial reporting.

Sources

references/sources.md in this skill lists the outside authorities that settle the questions here — what each one is authoritative for, and what you may do with it. Check them before answering on anything they cover, and cite what you used. Most are free to read and not free to reproduce; the use note on each is binding.

Never

  • Sign a control matrix that describes separation the team does not actually have.
  • Accept a control with no evidence produced in the ordinary course of performing it.
  • Remediate a finding with a commitment to be more careful.
  • Set approval limits on value alone and not monitor for splitting.

Bundled files

The model reads these on demand while the skill is loaded. They are exposed as readable files and are never executed.

Frequently asked questions

What does the Internal Controls And Audit AI skill do?

Designs and tests controls over financial reporting — segregation of duties, approval limits, evidence, and preparing for audit. Use this to design controls for a process, prepare for an external audit, respond to an audit finding, set approval thresholds, or assess where a small team's segregation of duties is genuinely broken.

Why use Internal Controls And Audit on TypingMind?

Because you install it once and use it with any model. Internal Controls And Audit is plain Markdown rather than provider-specific code, so the same skill runs on GPT-5, Claude, Gemini, Grok, or a local model — and you can switch model mid-chat without it breaking. TypingMind runs on your own API keys, so you pay providers directly instead of a per-seat subscription, and your skills and chats stay in your own storage.

How do I install Internal Controls And Audit in TypingMind?

Open Plugins → Skills → Install from GitHub in TypingMind and paste https://github.com/cbrock84/headcount/tree/main/plugins/finance/skills/internal-controls-and-audit. TypingMind reads its SKILL.md and bundles its files and installs it as a skill you can enable per chat.

Which AI models can use Internal Controls And Audit?

Any model you connect in TypingMind. AI skills are plain Markdown instructions rather than provider-specific code, so GPT, Claude, Gemini, Grok, and local models can all load this skill when a request matches it.

How many AI models can I use with Internal Controls And Audit?

As many as you like. As long as a model supports skills, you can use Internal Controls And Audit with it — GPT, Claude, Gemini, Grok, DeepSeek, Mistral, Llama and more — all on TypingMind with your own API keys.

Is the Internal Controls And Audit AI skill free?

Yes. It is published on GitHub by cbrock84 under the MIT license. You only pay your own AI provider for the tokens you use.

What are AI skills?

An AI skill is a reusable instruction bundle that teaches an AI model how to do one specific task. It follows the open Agent Skills format: a SKILL.md file with a name and description, plus any scripts, templates or reference files the model may need. The model reads the instructions only when your request matches the skill, so an installed skill costs nothing until it is used.

How are AI skills different from plugins or MCP servers?

A plugin or MCP server gives a model new tools to call — code that runs somewhere and returns a result. An AI skill gives the model knowledge and process instead: how to approach a task, which steps to follow, what good output looks like. Skills are plain Markdown, so they need no server, no API key and no runtime, and they work with any model.

View all

Set up your own AI workspace now

Get notified about new features and future giveaways by subscribing to our newsletter 👇