audit-risk-assessment

audit-risk-assessment is a skill for Claude Code, Codex from guoliang1114-boop/AriaAI. It costs 88 tokens per session (2,873 once invoked), scanned A, original, MIT.

An audit planning guide based on ISA 315, an international standard for identifying and assessing the risk of significant errors in financial statements. It covers the business, internal controls, important accounts and financial-reporting claims.

In plain words
What is it for?
Use it to prepare an audit plan, assess significant misstatement risks, review internal controls, set materiality, define an audit strategy, and produce a structured risk-assessment report.
Why use it?
It gives auditors a structured way to understand a client and decide where financial statements could be materially wrong before detailed testing begins.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Good fit Use it to prepare an audit plan, assess significant misstatement risks, review internal controls, set materiality, define an audit strategy, and produce a structured risk-assessment report.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/guoliang1114-boop/ariaai/audit-risk-assessment
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add guoliang1114-boop/AriaAI --skill audit-risk-assessment
Clone the repo
git clone --depth 1 https://github.com/guoliang1114-boop/AriaAI

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for audit-risk-assessment

README.md
[![agentmods](https://agentmods.dev/badge/skills/guoliang1114-boop/ariaai/audit-risk-assessment/github.svg)](https://agentmods.dev/skills/guoliang1114-boop/ariaai/audit-risk-assessment)
Your own site
<a href="https://agentmods.dev/skills/guoliang1114-boop/ariaai/audit-risk-assessment"><img src="https://agentmods.dev/badge/skills/guoliang1114-boop/ariaai/audit-risk-assessment/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for audit-risk-assessment

Your own site · 80×15
<a href="https://agentmods.dev/skills/guoliang1114-boop/ariaai/audit-risk-assessment"><img src="https://agentmods.dev/badge/skills/guoliang1114-boop/ariaai/audit-risk-assessment.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 88 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,873 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe. Third-party audits
  • NVIDIA SkillSpector pass 7 Sept 2026
How audits are shown
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00088 $0.02873
Opus 5 $0.00044 $0.01437
Sonnet 5 $0.00018 $0.00575
Haiku 4.5 $0.00009 $0.00287

Measured 13d ago against content hash 54cd14665432, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

audit-risk-assessment scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 13d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/audit-risk-assessment/SKILL.md · 240 lines

How it starts

The opening of the file, as written. The whole thing — 240 lines — stays where its author put it; the contents beside it link to each section on GitHub.

审计计划与风险评估

基于国际审计准则 ISA 315 (Revised 2019) 框架,执行审计计划阶段的系统性风险评估。

When To Use

  • 用户需要为客户制定审计计划
  • 用户需要识别和评估重大错报风险(RMM)
  • 用户需要了解被审计单位的内部控制
  • 用户需要确定重要性水平
  • 用户需要设计审计策略和审计程序的总体方向

Tools

Tool Purpose
update_project_markdown_document 保存风险评估文档到项目空间
write_project_office_document 生成风险评估报告(Word/PDF)

Framework: ISA 315 (Revised 2019)

核心概念

  • 固有风险 (Inherent Risk, IR):在考虑相关控制之前,某项认定存在重大错报的可能性。ISA 315 要求在认定层面评估固有风险。
  • 控制风险 (Control Risk, CR):某项重大错报未被实体的内部控制及时防止或发现并纠正的可能性。
  • 检查风险 (Detection Risk, DR):审计师的程序未能发现存在的重大错报的风险。审计师的责任是控制检查风险。
  • 重大错报风险 (Risk of Material Misstatement, RMM):固有风险与控制风险的组合。RMM = IR × CR。
  • 重大账户 (Significant Accounts):存在合理可能性包含重大错报的账户。
  • 认定 (Assertions):存在/发生、完整性、计价/分摊、权利和义务、列报和披露。

五步风险评估流程

Step 1:了解被审计单位及其环境
维度 了解内容
行业因素 行业竞争格局、监管要求、技术变革、市场趋势
所有权与治理 股权结构、董事会构成、管理层激励机制
经营模式 主要业务流程、收入来源、成本结构、关键资产
会计政策 重大会计估计、会计政策变更、复杂交易处理
财务业绩 收入增长率、毛利率趋势、现金流与利润匹配度
Step 2:了解内部控制(COSO 五要素)
要素 关键问题
控制环境 管理层诚信度、治理监督、权责分配、员工胜任能力
风险评估过程 管理层如何识别和应对经营风险
信息系统与沟通 财务报告相关的信息系统、内部控制沟通机制
控制活动 审批授权、核对复核、资产保护、职责分离
对控制的监督 持续监控、独立评估、缺陷报告机制
Step 3:识别重大账户、披露和相关认定

对每个账户评估以下风险因素:

  • 账户规模和构成
  • 因错误或舞弊导致错报的敏感性
  • 交易量、复杂性和同质性
  • 账户性质
  • 会计和报告复杂性
  • 损失风险
  • 重大或有负债的可能性
  • 关联方交易的存在
  • 与前期的变化
Step 4:识别可能的错报来源(WCGW 分析)

对每个重大账户/认定,回答:

  • What Could Go Wrong? 在交易的发起、授权、处理、记录环节中,哪些环节可能出现错报?
  • 管理层已实施了哪些控制?
  • 需要执行哪些穿行测试?
Step 5:评估重大错报风险
  • 在认定层面评估每个重大账户的 RMM
  • 确定哪些风险是显著风险(需要特别审计关注)
  • 识别因舞弊导致的重大错报风险(ISA 240 联动)
  • 确定显著风险是否需要测试控制

Workflow

1. 收集   → 获取客户行业、经营、财务、内控基本信息
2. 了解   → 按 Step 1-2 系统了解被审计单位和内控
3. 识别   → 按 Step 3-4 识别重大账户和 WCGW
4. 评估   → 按 Step 5 在认定层面评估 RMM
5. 重要性 → 计算整体重要性和实际执行的重要性
6. 策略   → 基于风险评估设计审计策略
7. 输出   → 生成结构化风险评估文档

Output Format

# 审计计划与风险评估报告

## 一、被审计单位概况

| 项目 | 内容 |
|------|------|
| 客户名称 | [名称] |
| 行业 | [行业] |
| 审计期间 | [期间] |
| 主要业务 | [描述] |

## 二、重要性水平

| 项目 | 金额 | 计算基础 | 比例 |
|------|------|---------|------|
| 整体重要性 | [金额] | [基准] | [比例] |
| 实际执行的重要性 | [金额] | [整体重要性] | 50%-75% |
| 明显微小错报临界值 | [金额] | — | — |

## 三、重大账户与认定识别

| 科目 | 金额 | 占比 | 相关认定 | 是否重大 |
|------|------|------|---------|---------|
| 收入 | ... | ... | 发生/完整性/截止 | ✅ |
| 应收账款 | ... | ... | 存在/计价 | ✅ |
| 存货 | ... | ... | 存在/计价/完整性 | ✅ |
| ... | ... | ... | ... | ... |

## 四、内部控制了解与评估

### 4.1 控制环境评价

| 维度 | 评价 | 风险等级 |
|------|------|---------|
| 管理层诚信 | [描述] | 🟢/🟡/🔴 |
| 治理监督 | [描述] | 🟢/🟡/🔴 |
| 权责分配 | [描述] | 🟢/🟡/🔴 |
| 员工胜任能力 | [描述] | 🟢/🟡/🔴 |

### 4.2 关键业务流程控制

| 流程 | 关键控制点 | 设计评价 | 是否需测试运行有效性 |
|------|-----------|---------|-------------------|
| 销售到收款 | [控制点] | 有效/缺陷 | 是/否 |
| 采购到付款 | [控制点] | 有效/缺陷 | 是/否 |
| ... | ... | ... | ... |

## 五、WCGW 分析与风险评估矩阵

| 科目 | 认定 | WCGW(可能的错报) | 固有风险 | 控制风险 | RMM | 是否显著风险 |
|------|------|-------------------|---------|---------|-----|------------|
| 收入 | 发生 | 虚构销售交易 | 高 | 中 | 高 | ✅ |
| 收入 | 截止 | 收入确认时点错误 | 中 | 中 | 中 | ❌ |
| 应收账款 | 计价 | 坏账准备计提不足 | 高 | 中 | 高 | ✅ |
| 存货 | 存在 | 虚构存货或数量高估 | 中 | 低 | 低 | ❌ |
| ... | ... | ... | ... | ... | ... | ... |

## 六、舞弊风险评估

| 舞弊风险 | 驱动因素 | 影响科目 | 应对措施 |
|---------|---------|---------|---------|
| 收入虚增 | 业绩压力/对赌 | 收入/应收账款 | [措施] |
| 费用资本化 | 利润目标 | 固定资产/开发支出 | [措施] |
| ... | ... | ... | ... |

## 七、审计策略

| 风险领域 | 审计策略 | 审计程序类型 | 时间安排 |
|---------|---------|------------|---------|
| 收入确认 | 增加实质性程序 | 细节测试+分析性复核 | 期末+期后 |
| 关联方交易 | 扩大测试范围 | 函证+细节测试 | 期末 |
| ... | ... | ... | ... |

## 八、未解决事项

| 事项 | 影响 | 待补充资料 | 责任人 |
|------|------|-----------|--------|
| ... | ... | ... | ... |

Read the full file on GitHub · 240 lines

Files

What ships with it

2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 13d ago First seen · 240 lines · 88 tokens per session scan A 54cd14665432

Subscribe to this mod's changes

audit-risk-assessment is a skill published in the GitHub repository guoliang1114-boop/AriaAI (37 stars, last pushed today), licensed MIT. It adds 88 tokens to every session and 2,873 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

domain_aml

Guidance for monitoring cross-border payments for money laundering and sanctions risks. It explains terms such as suspicious transactions and watchlists, which can include sanctioned people or politically exposed persons.

fdueblab/Micro-Agent · 0 tokens

fin-audit-support

Support SOX 404 compliance with control testing methodology, sample selection, and documentation standards. Use when generating testing workpapers, selecting audit samples, classifying control deficiencies, or preparing for internal or external audits.

evolution-foundation/evo-nexus · 47 tokens

fin-sox-testing

Generate SOX sample selections, testing workpapers, and control assessments. Use when planning quarterly or annual SOX 404 testing, pulling a sample for a control (revenue, P2P, ITGC, close), building a testing workpaper template, or evaluating and classifying a control deficiency.

evolution-foundation/evo-nexus · 66 tokens

fin-journal-entry

Prepare journal entries with proper debits, credits, and supporting detail. Use when booking month-end accruals (AP, payroll, prepaid), recording depreciation or amortization, posting revenue recognition or deferred revenue adjustments, or documenting an entry for audit review.

evolution-foundation/evo-nexus · 56 tokens

regulatory_filing

Parse and retrieve SEC/FINRA filings for an entity.

supremeb/Oniva-ai · 17 tokens

expense-review-policy

Review invoices and contracts against accounts-payable policy before human approval.

openai/openai-cookbook · 17 tokens