SOX 404 テスト(企業内統制の規制当局への報告準備)用のサンプル選定、テスト資料、統制評価を作成します。 次のような場合に使用: 四半期または年次のSOX 404テスト計画の立案、統制(売上、購買から支払い、IT全般統制、決算)のサンプル抽出、テスト資料テンプレート作成、統制上の問題点の評価・分類
Generate SOX sample selections, testing workpapers, and control assessments. Use when planning quarterly or annual SOX 404 testing, pulling a sample for a control (revenue, P2P, ITGC, close), building a testing workpaper template, or evaluating and classifying a control deficiency.
見慣れないプレースホルダーが表示される場合、またはどのツールが接続されているか確認が必要な場合は、CONNECTORS.md を参照してください。
重要: このコマンドは SOX コンプライアンスワークフローを支援するものですが、監査や法律上のアドバイスを提供するものではありません。 すべてのテスト用作業調書および評価は、監査文書として使用する前に資格を持つ財務専門家によるレビューを受けてください。
財務報告に係る内部統制(SOX 404)を対象に、サンプル抽出、テスト用作業調書の作成、統制評価の文書化、およびテストテンプレートの提供を行います。
/sox <control-area> <period>
control-area — テスト対象の統制領域:
revenue-recognition — 収益サイクル統制(受注〜入金)procure-to-pay または p2p — 購買・買掛金統制(発注〜支払)payroll — 給与処理および報酬統制financial-close — 期末決算・報告統制treasury — 資金管理・財務統制fixed-assets — 固定資産ライフサイクル統制inventory — 棚卸資産の評価・管理統制itgc — IT 全般統制(アクセス管理・変更管理・運用)entity-level — 全社的統制・モニタリング統制journal-entries — 仕訳処理統制period — テスト対象期間(例: 2024-Q4、2024、2024-H2)統制領域に基づき、主要統制を特定します。以下の統制マトリクスを提示します:
| 統制 # | 統制の説明 | 種別 | 頻度 | キー/非キー | リスク | アサーション |
|---|---|---|---|---|---|---|
| [ID] | [説明] | 手動 / 自動 / IT 依存 | 日次 / 週次 / 月次 / 四半期 / 年次 | キー | 高 / 中 / 低 | [CEAVOP] |
統制の種別:
アサーション(CEAVOP):
統制の実施頻度とリスクに基づき、サンプルサイズを算定します:
| 統制の実施頻度 | 母集団規模(概算) | 推奨サンプル数 |
|---|---|---|
| 年次 | 1 | 1(その実施事例をテスト) |
| 四半期 | 4 | 2 |
| 月次 | 12 | 2〜4(リスクに応じて) |
| 週次 | 52 | 5〜15(リスクに応じて) |
| 日次 | 約 250 | 20〜40(リスクに応じて) |
| 取引ごと | 件数による | 25〜60(リスクおよび件数に応じて) |
以下の要素に応じて調整してください:
適切な手法を用いて母集団からサンプルを抽出します:
ランダム抽出(取引レベル統制のデフォルト):
系統的抽出(定期的な統制向け):
目的的抽出(リスクベーステストにおけるランダム抽出の補完):
サンプルの提示形式:
サンプル抽出
統制: [統制 ID] — [説明]
期間: [テスト対象期間]
母集団: [件数] 件、合計 $[金額]
サンプル数: [N] 件
抽出方法: [ランダム / 系統的 / 目的的]
| サンプル # | 取引日 | 参照番号 / ID | 金額 | 抽出根拠 |
|-----------|--------|-------------|------|---------|
| 1 | [日付] | [参照番号] | $X,XXX | ランダム |
| 2 | [日付] | [参照番号] | $X,XXX | ランダム |
| ... | ... | ... | ... | ... |
統制ごとにテストテンプレートを生成します:
SOX 統制テスト作業調書
==============================
統制 #: [ID]
統制の説明: [統制活動の詳細な説明]
統制オーナー: [役割 / 職名 — テスト担当者が記入]
統制種別: [手動 / 自動 / IT 依存手動]
実施頻度: [統制が機能する頻度]
キー統制: [はい / いいえ]
関連アサーション: [CEAVOP]
テスト期間: [期間]
テスト目的:
[統制の説明] がテスト期間を通じて有効に機能していたかどうかを確認する。
テスト手続:
1. [手順 1 — 検査・閲覧または再実施の対象]
2. [手順 2 — 入手すべき証拠]
3. [手順 3 — 比較・検証する内容]
4. [手順 4 — 実施の網羅性を評価する方法]
5. [手順 5 — 実施の適時性を評価する方法]
期待される証拠:
- [文書の種類 1 — 例: 署名済み承認フォーム]
- [文書の種類 2 — 例: レビューを示すシステムスクリーンショット]
- [文書の種類 3 — 例: 作成者の署名付き照合表]
テスト結果:
| サンプル # | 参照番号 | 手順 1 | 手順 2 | 手順 3 | 結果 | 例外あり? | 備考 |
|-----------|---------|--------|--------|--------|------|----------|------|
| 1 | | 合格 / 不合格 | 合格 / 不合格 | 合格 / 不合格 | 合格 / 不合格 | Y/N | |
| 2 | | 合格 / 不合格 | 合格 / 不合格 | 合格 / 不合格 | 合格 / 不合格 | Y/N | |
確認された例外事項:
| サンプル # | 例外の説明 | 根本原因 | 補完的統制 | 影響 |
|-----------|-----------|---------|----------|------|
| | | | | |
結論:
[ ] 有効 — 例外なく統制が有効に機能した
[ ] 例外付き有効 — 統制は有効に機能した。例外は個別事例の範囲内
[ ] 不備(Deficiency)— 統制が有効に機能しなかった
[ ] 重要な不備(Significant Deficiency)— 監視責任者が注目すべき、軽微でない不備
[ ] 重要な欠陥(Material Weakness)— 重要な虚偽表示が防止・発見されない相当の可能性がある
テスト担当者: ________________ 日付: ________
レビュー担当者: _______________ 日付: ________
統制領域に応じて、あらかじめ構築されたテスト手順テンプレートを提供します:
収益認識(Revenue Recognition):
購買〜支払(Procure to Pay):
決算(Financial Close):
IT 全般統制(ITGC):
特定された不備を以下のように分類します:
不備(Deficiency): 統制が、虚偽表示を適時に防止または発見することを経営者や従業員に許容しない状態。 以下を検討します:
重要な不備(Significant Deficiency): 重要な欠陥ほど深刻ではないが、監視責任を担う者が注目するに足る、単独または組み合わせによる不備。
重要な欠陥(Material Weakness): 単独または組み合わせにより、重要な虚偽表示が適時に防止または発見されない相当の可能性がある不備。
以下を提供します:
If you see unfamiliar placeholders or need to check which tools are connected, see CONNECTORS.md.
Important: This command assists with SOX compliance workflows but does not provide audit or legal advice. All testing workpapers and assessments should be reviewed by qualified financial professionals before use in audit documentation.
Generate sample selections, create testing workpapers, document control assessments, and provide testing templates for SOX 404 internal controls over financial reporting.
/sox <control-area> <period>
control-area — The control area to test:
revenue-recognition — Revenue cycle controls (order-to-cash)procure-to-pay or p2p — Procurement and AP controls (purchase-to-pay)payroll — Payroll processing and compensation controlsfinancial-close — Period-end close and reporting controlstreasury — Cash management and treasury controlsfixed-assets — Capital asset lifecycle controlsinventory — Inventory valuation and management controlsitgc — IT general controls (access, change management, operations)entity-level — Entity-level and monitoring controlsjournal-entries — Journal entry processing controlsperiod — The testing period (e.g., 2024-Q4, 2024, 2024-H2)Based on the control area, identify the key controls. Present the control matrix:
| Control # | Control Description | Type | Frequency | Key/Non-Key | Risk | Assertion |
|---|---|---|---|---|---|---|
| [ID] | [Description] | Manual/Automated/IT-Dependent | Daily/Weekly/Monthly/Quarterly/Annual | Key | High/Medium/Low | [CEAVOP] |
Control types:
Assertions (CEAVOP):
Calculate sample sizes based on control frequency and risk:
| Control Frequency | Population Size (approx.) | Recommended Sample |
|---|---|---|
| Annual | 1 | 1 (test the instance) |
| Quarterly | 4 | 2 |
| Monthly | 12 | 2-4 (based on risk) |
| Weekly | 52 | 5-15 (based on risk) |
| Daily | ~250 | 20-40 (based on risk) |
| Per-transaction | Varies | 25-60 (based on risk and volume) |
Adjust for:
Select samples from the population using the appropriate method:
Random selection (default for transaction-level controls):
Systematic selection (for periodic controls):
Targeted selection (supplement to random, for risk-based testing):
Present the sample:
SAMPLE SELECTION
Control: [Control ID] — [Description]
Period: [Testing period]
Population: [Count] items, $[Total value]
Sample size: [N] items
Selection method: [Random/Systematic/Targeted]
| Sample # | Transaction Date | Reference/ID | Amount | Selection Basis |
|----------|-----------------|--------------|--------|-----------------|
| 1 | [Date] | [Ref] | $X,XXX | Random |
| 2 | [Date] | [Ref] | $X,XXX | Random |
| ... | ... | ... | ... | ... |
Generate a testing template for each control:
SOX CONTROL TESTING WORKPAPER
==============================
Control #: [ID]
Control Description: [Full description of the control activity]
Control Owner: [Role/title — to be filled by tester]
Control Type: [Manual/Automated/IT-Dependent Manual]
Frequency: [How often the control operates]
Key Control: [Yes/No]
Relevant Assertion(s): [CEAVOP]
Testing Period: [Period]
TEST OBJECTIVE:
To determine whether [control description] operated effectively throughout the testing period.
TEST PROCEDURES:
1. [Step 1 — What to inspect, examine, or re-perform]
2. [Step 2 — What evidence to obtain]
3. [Step 3 — What to compare or verify]
4. [Step 4 — How to evaluate completeness of performance]
5. [Step 5 — How to assess timeliness of performance]
EXPECTED EVIDENCE:
- [Document type 1 — e.g., signed approval form]
- [Document type 2 — e.g., system screenshot showing review]
- [Document type 3 — e.g., reconciliation with preparer sign-off]
TEST RESULTS:
| Sample # | Ref | Procedure 1 | Procedure 2 | Procedure 3 | Result | Exception? | Notes |
|----------|-----|-------------|-------------|-------------|--------|------------|-------|
| 1 | | Pass/Fail | Pass/Fail | Pass/Fail | Pass/Fail | Y/N | |
| 2 | | Pass/Fail | Pass/Fail | Pass/Fail | Pass/Fail | Y/N | |
EXCEPTIONS NOTED:
| Sample # | Exception Description | Root Cause | Compensating Control | Impact |
|----------|----------------------|------------|---------------------|--------|
| | | | | |
CONCLUSION:
[ ] Effective — Control operated effectively with no exceptions
[ ] Effective with exceptions — Control operated effectively; exceptions are isolated
[ ] Deficiency — Control did not operate effectively
[ ] Significant Deficiency — Deficiency is more than inconsequential
[ ] Material Weakness — Reasonable possibility of material misstatement not prevented/detected
Tested by: ________________ Date: ________
Reviewed by: _______________ Date: ________
Based on the control area, provide pre-built test step templates:
Revenue Recognition:
Procure to Pay:
Financial Close:
ITGC:
Classify any identified deficiencies:
Deficiency: A control does not allow management or employees to prevent or detect misstatements on a timely basis. Consider:
Significant Deficiency: A deficiency (or combination) that is less severe than a material weakness but important enough to merit attention by those responsible for oversight.
Material Weakness: A deficiency (or combination) such that there is a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis.
Provide:
原文・著作権は Anthropic および各プラグイン作者に帰属します。日本語訳は Claude API による自動翻訳です。