All skills
LiveReporting & IssuesReportingWorkpaper

SOX Deficiency Evaluation & Aggregation

Takes the deficiency register you already keep, works out how much money each deficiency put at risk, classifies it against thresholds locked before anyone looked at the results, and combines deficiencies on the same account without counting shared money twice.

Plugin
sox-deficiency-evaluation
Version
v1.1.0
Impact
Very High
Complexity
Medium–High

How it works

Input
Your existing deficiency register, materiality from the planning memo (there is no default — it won't run without one), and last year's register if you want the year-over-year match
What it does
Locks and fingerprints the severity thresholds before the register is read → computes the money at risk for each deficiency, using the worst rate the sample supports rather than the rate observed → reads the risk rating already in the register through the locked scale → combines deficiencies on the same account, counting shared money once → matches this year to last
What has to hold true
Every check is written twice — as the Excel formula you see and as an independent calculation — and the two are compared after Excel recalculates the workbook. Each check was shown capable of failing before it shipped. A deficiency with no usable amount is labelled "rating only", never treated as zero.

The part that makes it reproducible

Output
A 5-tab Excel workpaper (cover, deficiencies, combinations, prior year, validation) that shows its arithmetic and names its own gaps — plus, optionally, the written communication to the audit committee, a board summary, and the evaluation memo, each in Word

Building blocks it runs on

Shared, independently tested components. They ship bundled inside this skill — there is nothing extra to install.

What you'll need to change for your firm

This runs as published, but every audit function documents things its own way. These are the places it assumes a house format:

  • Your materiality figures and the planning memo they come from
  • Your risk-rating scale and how each band translates to likelihood
  • Your register's column layout — messy registers are handled, but the mapping is yours to confirm
  • Who signs off the locked thresholds before a run

Built for Claude

Install it into Claude Cowork and point it at your files.

  1. 1Download the skill bundle — everything it needs, including the shared building blocks, is inside.
  2. 2Add it to Claude Cowork as a plugin (sox-deficiency-evaluation).
  3. 3Point it at your own files and run it against one period you already know the answer to.
Request this skill

Free. We'll send the bundle and the setup notes.

Running on ChatGPT Enterprise or Copilot? We port these into your environment.

Want SOX Deficiency Evaluation & Aggregation fitted to your methodology?

We adapt it to your control matrix, your workpaper template, and your thresholds — then hand it over so your team can run it themselves.