From us-sox
SOX gap assessment via the SCF crosswalk, framed as ICFR readiness across the four ITGC domains, entity-level controls, and IT-dependent manual controls
How this command is triggered — by the user, by Claude, or both
Slash command
/us-sox:assessThe summary Claude sees in its command listing — used to decide when to auto-load this command
# SOX Assessment Runs a gap assessment for the **Sarbanes-Oxley Act of 2002** by delegating to `/grc-engineer:gap-assessment` with the framework's SCF identifier (`usa-federal-law-sox-2002`), then overlays SOX-specific framing — ICFR scope, ITGC domains, deficiency severity, and SOC 1 vendor reliance. This is a **readiness assessment**, not an external audit. The output identifies gaps an auditor would likely surface; final classification of any gap as a control deficiency, significant deficiency, or material weakness is a judgment call requiring management and the external auditor. ## U...
Runs a gap assessment for the Sarbanes-Oxley Act of 2002 by delegating to /grc-engineer:gap-assessment with the framework's SCF identifier (usa-federal-law-sox-2002), then overlays SOX-specific framing — ICFR scope, ITGC domains, deficiency severity, and SOC 1 vendor reliance.
This is a readiness assessment, not an external audit. The output identifies gaps an auditor would likely surface; final classification of any gap as a control deficiency, significant deficiency, or material weakness is a judgment call requiring management and the external auditor.
/us-sox:assess [--scope=<scope>] [--sources=<connector-list>]
--scope: narrow the assessment
itgc-access — IT General Controls, Access to Programs and Dataitgc-change — IT General Controls, Program Changesitgc-operations — IT General Controls, Computer Operationsitgc-development — IT General Controls, Program Developmentitgc-all — All four ITGC domainsentity-level — Entity-Level Controls (ELCs)itdm — IT-Dependent Manual Controls and report-integrityvendor-soc1 — Vendor SOC 1 reliance evaluationcertifications — §302 / §404 / §906 certification readiness--sources=<connector-list>: comma-separated connector plugins (e.g., aws-inspector,okta-inspector,github-inspector) to pull live evidence into the assessment.Before starting, confirm with the user:
/us-sox:scope first.Under the hood, the SCF mechanics are handled by the persona plugin:
/grc-engineer:gap-assessment "usa-federal-law-sox-2002" [--sources=<connector-list>]
The SCF crosswalk expands 4 SCF controls into 17 SOX-relevant controls. That number is small because SOX itself does not enumerate technical control objectives — the security and IT control catalog flows in from COSO 2013 IC-IF, COBIT, and the AICPA SOC 1 framework rather than from SOX statutory text. This assess command therefore wraps the SCF gap-assessment output in ICFR-shaped sections and adds the entity-level / ITDM / vendor-SOC 1 dimensions that SCF alone does not capture.
SOX READINESS ASSESSMENT
========================
Period: [fiscal year / quarter]
Filer category: [Large accelerated / Accelerated / Non-accelerated / EGC / SRC]
§404(b) applicable: [Yes / No / EGC-exempt until <date>]
External auditor: [firm — engagement type]
Overall readiness: [N]% (control-weighted)
ITGC HEATMAP (per in-scope system)
----------------------------------
System Access Change Operations Development
[App 1] [%] [%] [%] [%]
[App 2] [%] [%] [%] [%]
...
ENTITY-LEVEL CONTROLS
---------------------
[ELC] [Status] [Evidence]
Audit committee oversight [PRESENT] [charter + minutes]
Code of conduct [PRESENT] [policy + ack population]
Whistleblower hotline [PRESENT] [hotline summary]
Fraud risk assessment [PRESENT] [annual FRA]
Period-end close controls [PARTIAL] [JE review log incomplete]
Disclosure committee [PRESENT] [charter + Q-end packs]
...
IT-DEPENDENT MANUAL CONTROLS
----------------------------
ITDM Report-integrity Manual control
[control 1] [TESTED] [SIGNED]
[control 2] [NOT TESTED] [SIGNED]
...
VENDOR SOC 1 RELIANCE
---------------------
Vendor SOC 1 Type II Period covered CUECs operating Bridge letter
[vendor 1] [YES] [start - end] [YES] [YES]
[vendor 2] [SOC 2 only] [n/a] [n/a] [n/a — direct testing]
...
GAP LOG
-------
🔴 MATERIAL-WEAKNESS CANDIDATE (n):
- [gap] (system / domain / SOX section)
Recommendation: [...]
🟡 SIGNIFICANT-DEFICIENCY CANDIDATE (n):
- [gap] (system / domain / SOX section)
Recommendation: [...]
🟠 CONTROL DEFICIENCY (n):
- [gap] (system / domain / SOX section)
Recommendation: [...]
🔵 OBSERVATION (n):
- [gap] (process improvement)
CERTIFICATION READINESS
-----------------------
§302 disclosure-controls basis: [READY / GAPS — see deficiency log]
§404(a) management assessment: [READY / GAPS]
§404(b) auditor attestation: [N/A — non-accelerated / EGC-exempt / coordinated with [firm]]
§906 criminal certification: [READY / GAPS]
Sub-certification population: [N collected / M outstanding]
OPEN BLOCKERS
-------------
- [list — e.g., materiality threshold not set, prior-year material weakness not remediated]
NEXT STEPS
----------
- /us-sox:evidence-checklist for collection planning
- Specific remediation items per gap log
PCAOB AS 2201 defines three levels (paraphrased):
This assess command can identify candidate severity tiers based on magnitude (relative to the auditor's materiality threshold) and likelihood (qualitative judgment based on the nature of the control, history, and compensating controls). Final classification is a judgment call requiring management and the external auditor — not an automated output. Material weakness has public-disclosure implications; do not represent automated severity tags as authoritative.
Frequently-requested scopes in practice:
/grc-engineer:optimize-multi-framework for cross-framework optimization.Statute: Public Law 107-204; 15 U.S.C. §§ 7201 et seq.
Regulators: SEC, PCAOB, DOJ
Depth: Reference (tier 2 of 3)
Related commands: /us-sox:scope, /us-sox:evidence-checklist, /grc-engineer:gap-assessment
npx claudepluginhub dexcopeland/claude-grc-engineering --plugin us-sox/assessCompares a local repository against a topic wiki's research body and the broader market, producing a gap analysis with opportunities and competitive landscape.
/assessAssesses DORA compliance readiness for EU financial entities and ICT providers. Requires scope (full, pillar-specific, entity-type); optional entity classification.
/assessAssesses GLBA compliance readiness for specified scope (full, safeguards, privacy, pretexting) and institution type, producing compliance score and detailed evaluation.
/assessAssesses compliance with NIST 800-53 controls for a specified control family (e.g., AC) or baseline (low, moderate, high), with optional revision (r4 or r5).
/assessAssesses SOC 2 Type I or II audit readiness for specified scope (security, availability, confidentiality, processing integrity, privacy), producing readiness scores, control gaps, evidence requirements, remediation recommendations, and timeline.
/assessAssesses ISMS compliance against ISO 27001:2022 clauses and Annex A controls, producing status reports, gap analysis, Statement of Applicability guidance, and certification readiness.