internal-audit-risk-control-matrixUse this skill when an internal auditor, SOX analyst, or co-sourced audit team needs to convert an audit engagement's objective, scope, and process documenta...
Install via ClawdBot CLI:
clawdbot install archlab-space/internal-audit-risk-control-matrixGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://github.com/archlab-space/Open-Skill-Hub/issuesAudited May 23, 2026 · audit v1.0
Generated Jul 27, 2026
An internal auditor reviews the order-to-cash process for a mid-size manufacturing company under SOX 404. The objective is to assess the design and operating effectiveness of controls over revenue recognition, including order approval, credit checks, shipping, invoicing, and cash application.
An audit manager evaluates the procure-to-pay cycle for a healthcare entity subject to HIPAA. The scope covers purchase requisitions, vendor master maintenance, purchase orders, goods receipt, invoice processing, and payment execution, with emphasis on data privacy and segregation of duties.
A co-sourced IT audit team tests ITGCs for a financial services firm using COBIT 2019. Domains include access management, change management, computer operations, and program development, focusing on a core banking system and its supporting infrastructure.
An audit senior examines the payroll process for a multinational retail corporation. The audit objective is to validate completeness and accuracy of payroll disbursements, including employee master data changes, time tracking, payroll calculation, and tax withholding, in compliance with local labor laws.
An internal auditor conducts a physical verification of fixed assets for a real estate company. The engagement covers existence, valuation, and completeness of assets such as buildings, machinery, and vehicles, reconciling to the general ledger and reviewing capitalization policies.
Offers recurring revenue, requires controls over billing, revenue recognition (ASC 606), and user access management in a cloud environment. Suitable for COSO 2013 application with emphasis on IT controls and automated revenue assurance.
Facilitates third-party seller transactions, requiring robust controls over payment processing, fraud detection, and regulatory compliance (e.g., GDPR, PCI-DSS). Scope includes order initiation, authorization, custody of funds, and reconciliation.
Bills clients based on time and materials or fixed-fee engagements. Key controls revolve around time entry, expense reimbursement, project budgeting, and revenue recognition. Emphasizes manual controls and segregation of duties.
💬 Integration Tip
Use the RCM to map each scenario's subprocesses, risks, and controls into a structured matrix, then export to GRC tools or audit management software for fieldwork execution.
Scored Jun 1, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
全面排查企业的经营风险情况,适用于供应商准入尽调、贷前风险筛查、合作伙伴背景调查等场景,全方位预警潜在经营风险,辅助决策者规避合作隐患。
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score wi...