Loading

SOX & controls documentation

Process narrative, RCM, and flowchart in under an hour.

10 minFinanceClaude Cowork
Loading

Set up

Try a plugin

The Finance plugin ships with /sox-testing and other close and compliance skills as a starting point, already structured to turn a walkthrough into narrative, matrix, and flowchart. If your admin manages plugins and it's not available yet, skip this; nothing below requires it.

FinanceStreamline finance and accounting workflows, from journal entries and reconciliation to financial statements and variance analysis. Speed up audit prep, month-end close, and keeping your books clean.
Add
/sox-testingGenerate SOX sample selections, testing workpapers, and control assessments.
Run
/audit-supportSupport SOX 404 compliance with control testing methodology, sample selection, and documentation standards.
Run

Connect your tools

Claude Cowork is more powerful when it works directly with your systems. You control permissions and access. Learn about tool access.

Navigate to Customize → Connectors in Cowork to set up.

Google Drive
Connect
Microsoft 365
Connect
Browse all connectorsOpen in Cowork

Set your working folder

Drag the files you'll use (your walkthrough notes, prior-year narrative, the RCM template, system screenshots) into one folder on your machine, then point Cowork at it. Cowork reads from it and writes the narrative, matrix, and flowchart back to it. If you'll document several processes this cycle, create a Cowork project from the parent Controls folder so the template and house style stay attached.

Controls / Order-to-Cash
walkthrough-notes-OTC.docxApr 22, 202638 KB
RCM-template.xlsxJan 12, 202624 KB
prior-year-narrative-OTC.pdfMar 9, 2025312 KB
system-screenshots/Apr 22, 20266 items
In Cowork’s chat bar:Controls / Order-to-Cash

The prompt

Copy this into Claude Cowork

Here's how this process runs. Write the process narrative in our standard format, build the risk and control matrix mapping each risk to its control, owner, and frequency, and draw the flowchart. Flag any step where a control looks missing or a segregation of duties issue shows up.

Controls / Order-to-Cash

Why this works

Prompt

Start from the current state. "Here's how this process actually runs" anchors the documentation in operational reality, not last year's narrative, so the matrix matches what auditors will walk.

Prompt

Ask for related outputs in one prompt. Naming the narrative, the matrix, and the flowchart in one prompt keeps them consistent with each other; the same step number means the same thing in every file.

Prompt

Ask it to flag what's missing. Asking to "flag any step where a control looks missing" so you can find the gaps while documenting, when they're still easy to fix.

Source

Let the working folder supply the format. Your RCM template and prior-year narrative sit in the working folder, so "our standard format" resolves to your actual columns and headings without you pasting them in.

Get a better draft

Practice

Add an example to match. Drop an example you like into the folder and Cowork matches your structure and voice.

Practice

Ask it to flag uncertainty. Add "flag anything you're not confident about" so you know where to look first when you review the draft.

Make Cowork work for you

A plugin skill is a starting point — customize it with your own practices and expertise. A few minutes of conversation and it runs with your standards from then on.

Make what we've done in this task so far into a skill, or edit the /sox-testing skill with my feedback.

Controls

Make it repeatable

Run it on every walkthrough

When a process owner drops their walkthrough notes, the documentation package should already be drafting. Type /schedule in the prompt, or open Scheduled in the Cowork sidebar, and the customized skill runs whenever a new walkthrough is added to the Controls folder.

/schedule Weekdays at 9am, check Controls for any new walkthrough file and run /sox-testing against it and write the narrative, RCM, and flowchart to a subfolder named for the process.

Controls
Scheduled taskActive
Controls documentation package

Runs /sox-testing on every new walkthrough in Controls and writes the narrative, matrix, and flowchart to a process subfolder.

Every weekday at 9amOpen in Cowork

Share with your teammates

Your customized /sox-testing now carries your RCM columns, your control-ID scheme, and your narrative voice. Share it so every process owner produces the same audit-ready package, and internal audit sees one consistent format across the cycle for $0 instead of consulting rates.

Going forward