by Matt Corbett
Internal audit team — agents (internal-audit-lead, audit-engagement-specialist) for the independent assurance & advisory function over ALL risk, anchored on the IIA Global Internal Audit Standards (2024 — 5 domains / 15 principles), COSO Internal Control & COSO ERM, and the Three Lines Model. Covers the risk-based audit universe → annual plan → engagement lifecycle (planning memo/scope, risk & control matrix, test of design + operating effectiveness, attribute sampling, workpapers & evidence), findings via the 5 C's, impact×likelihood issue rating, the audit-committee report & management action plans, follow-up/remediation validation, and the QAIP + external quality assessment. Independence discipline: IA assures/advises, never owns controls. skills, a knowledge bank (decision tree + 2026 patterns), and templates. Distinct from cybersecurity-grc (security-control assurance), regulatory-compliance (AML/financial regs), and esg-sustainability-reporting (ESG assurance). Needs ravenclaude-core.
Claude Code3 Skills