finding-classification

Audit finding classification and reporting framework. Referenced by findings-analyst and recommendation-writer agents when systematically classifying findings and writing improvement recommendations. Used for 'finding classification', 'audit reporting', 'improvement recommendations' requests. Note: legal sanction decisions and disciplinary procedures are out of scope.

495 stars

Best use case

finding-classification is best used when you need a repeatable AI agent workflow instead of a one-off prompt.

Audit finding classification and reporting framework. Referenced by findings-analyst and recommendation-writer agents when systematically classifying findings and writing improvement recommendations. Used for 'finding classification', 'audit reporting', 'improvement recommendations' requests. Note: legal sanction decisions and disciplinary procedures are out of scope.

Teams using finding-classification should expect a more consistent output, faster repeated execution, less prompt rewriting.

When to use this skill

  • You want a reusable workflow that can be run more than once with consistent structure.

When not to use this skill

  • You only need a quick one-off answer and do not need a reusable workflow.
  • You cannot install or maintain the underlying files, dependencies, or repository context.

Installation

Claude Code / Cursor / Codex

$curl -o ~/.claude/skills/finding-classification/SKILL.md --create-dirs "https://raw.githubusercontent.com/revfactory/harness-100/main/en/94-audit-report/.claude/skills/finding-classification/skill.md"

Manual Installation

  1. Download SKILL.md from GitHub
  2. Place it in .claude/skills/finding-classification/SKILL.md inside your project
  3. Restart your AI agent — it will auto-discover the skill

How finding-classification Compares

Feature / Agentfinding-classificationStandard Approach
Platform SupportNot specifiedLimited / Varies
Context Awareness High Baseline
Installation ComplexityUnknownN/A

Frequently Asked Questions

What does this skill do?

Audit finding classification and reporting framework. Referenced by findings-analyst and recommendation-writer agents when systematically classifying findings and writing improvement recommendations. Used for 'finding classification', 'audit reporting', 'improvement recommendations' requests. Note: legal sanction decisions and disciplinary procedures are out of scope.

Where can I find the source code?

You can find the source code on GitHub using the link provided at the top of the page.

SKILL.md Source

# Finding Classification — Finding Classification Framework

Enhances the finding classification and reporting capabilities of findings-analyst / recommendation-writer agents.

## Finding Rating System

### 4-Level Classification

| Rating | Name | Definition | Response Timeline |
|--------|------|-----------|-------------------|
| Critical | Critical | Risk of major loss/regulatory violation | Immediate (7 days) |
| High | High | Key control failure, recurring | 30 days |
| Medium | Medium | Partial control deficiency, improvement needed | 90 days |
| Low | Low | Efficiency improvement, best practice suggestion | 180 days |

### Classification Decision Tree

```
Q1: Financial impact exceeds $100K or regulatory violation?
├── YES → Critical
└── NO → Q2: Is the control failure recurring?
    ├── YES → High
    └── NO → Q3: Could it worsen without corrective action?
        ├── YES → Medium
        └── NO → Low
```

## Finding Report Structure

### Finding Card

```markdown
## Finding F-[Number]: [Title]

### Rating: [Critical/High/Medium/Low]

### Condition
[Current state discovered — facts only]

### Criteria
[Standard/regulation/policy that should apply]

### Cause
[Why the gap between criteria and condition occurred]

### Effect
[Current/potential impact — quantify where possible]

### Recommendation
[Specific improvement actions]

### Management Response
[Responsible department's response plan]
- Agreement: □ Agree □ Partially agree □ Disagree
- Corrective action: [Specific action]
- Owner: [Name/Title]
- Completion deadline: [YYYY-MM-DD]
```

## Root Cause Analysis

### Cause Categories

| Category | Description | Example |
|----------|-------------|---------|
| Policy/Procedure gap | Regulation missing or insufficient | Approval procedure not established |
| Personnel/Competency | Training or staffing deficiency | Owner not trained |
| System/Tools | IT control deficiency | Access rights management gaps |
| Supervision/Monitoring | Management review absence | Reconciliation not performed |
| Communication | Information transfer failure | Policy changes not shared |

## Recommendation Writing Rules

### SMART Recommendations

```
Bad example: "Controls should be strengthened"
Good example: "By June 2025, implement dual approval 
             for all expenditures exceeding $50,000, 
             and verify compliance through monthly reconciliation"
```

### Recommendation Priority Scoring

| Criteria | Weight |
|----------|--------|
| Risk reduction effect | 40% |
| Implementation ease | 25% |
| Cost efficiency | 20% |
| Urgency | 15% |

## Implementation Tracking Ledger

| Finding | Rating | Corrective Action | Owner | Deadline | Status | Verification Date |
|---------|--------|-------------------|-------|----------|--------|-------------------|
| F-01 | Critical | [Action] | [Name] | [Date] | In progress | - |
| F-02 | High | [Action] | [Name] | [Date] | Completed | [Date] |

### Status Definitions

| Status | Description |
|--------|-------------|
| Not started | Before corrective action begins |
| In progress | Corrective action underway |
| Completed | Correction done, awaiting verification |
| Verified | Auditor verification passed |
| Closed | Finalized |
| Overdue | Past deadline, incomplete |

## Quality Checklist

| Item | Criteria |
|------|----------|
| 4C structure | Condition, Criteria, Cause, Effect |
| Rating consistency | Decision tree applied |
| Quantification | Impact expressed in amounts/counts |
| SMART recommendations | Specific + Measurable + Time-bound |
| Management response | Agreement/disagreement recorded |
| Tracking | 5-stage status management |

Related Skills

sustainability-audit

495
from revfactory/harness-100

Full audit pipeline for ESG/sustainability where an agent team collaborates to generate environmental, social, and governance assessments along with an integrated report and improvement plan. Use this skill for requests such as 'run an ESG audit', 'write a sustainability report', 'ESG assessment', 'carbon emissions calculation', 'ESG rating diagnosis', 'governance review', 'social responsibility assessment', 'GRI report', 'TCFD disclosure', 'ESG improvement plan', and other ESG/sustainability tasks. Also supports assessment of specific pillars (E/S/G) only or improving existing reports. However, actual on-site audit execution, third-party verification certificate issuance, ESG rating agency score changes, and carbon credit trading are outside the scope of this skill.

materiality-assessment

495
from revfactory/harness-100

ESG materiality assessment matrix. Referenced by the esg-reporter and improvement-planner agents when evaluating ESG issue materiality and setting priorities. Use for 'materiality assessment', 'importance analysis', or 'Materiality Matrix' requests. Stakeholder surveys and external certification are out of scope.

ghg-protocol

495
from revfactory/harness-100

GHG Protocol detailed guide. Referenced by the environmental-analyst agent when calculating and reporting greenhouse gas emissions. Use for 'GHG Protocol', 'carbon emissions', 'Scope 1/2/3', or 'carbon footprint' requests. Carbon credit trading and CDM project execution are out of scope.

citation-standards

495
from revfactory/harness-100

Academic citation and reference standards guide. Referenced by the paper-writer and submission-preparer agents when composing citations and references. Use for 'citation format', 'APA', or 'references' requests. Original paper retrieval and professional database access are out of scope.

academic-paper

495
from revfactory/harness-100

Full research pipeline for academic paper writing where an agent team collaborates to generate research design, experiment protocols, analysis, manuscript writing, and submission preparation. Use this skill for requests such as 'write an academic paper', 'research paper writing', 'help me write a paper', 'design a study', 'run statistical analysis', 'prepare journal submission', 'manuscript writing', 'research methodology design', 'hypothesis testing', 'academic writing', and other academic research paper tasks. Also supports analysis, rewriting, and submission preparation when existing data or drafts are available. However, actual data collection execution, official IRB submission, journal system login and upload, and running actual statistical software are outside the scope of this skill.

product-copy-formulas

495
from revfactory/harness-100

Product copy formula library. Referenced by the detail-page-writer and marketing-manager agents when writing purchase-driving copy. Use for 'product copy', 'marketing copy', or 'ad copy' requests. Ad placement and design mockup creation are out of scope.

ecommerce-launcher

495
from revfactory/harness-100

Full launch pipeline for e-commerce products where an agent team collaborates to generate product planning, detail pages, pricing strategy, marketing, and CS setup all at once. Use this skill for requests such as 'launch an e-commerce product', 'prepare a product launch', 'register a product on Naver Smart Store', 'launch on Coupang', 'create a detail page', 'develop a pricing strategy', 'create a marketing plan', 'launch prep', 'product planning brief', 'e-commerce CS manual', and other e-commerce product launch tasks. Also supports supplementing pricing/marketing/CS even when existing briefs or detail pages are provided. However, actual platform API integration (automated product registration), payment system development, logistics system integration, and real-time order management are outside the scope of this skill.

conversion-optimization

495
from revfactory/harness-100

Purchase conversion optimization framework. Referenced by the detail-page-writer and pricing-strategist agents when designing detail pages and pricing with a conversion focus. Use for 'conversion rate optimization', 'CRO', or 'purchase psychology' requests. A/B testing tool setup and funnel automation are out of scope.

real-estate-analyst

495
from revfactory/harness-100

Real estate investment analysis pipeline. An agent team collaborates to produce market research, location analysis, profitability analysis, risk assessment, and investment reports. Use this skill for requests such as 'analyze this real estate', 'apartment investment analysis', 'studio apartment yield', 'real estate market research', 'location analysis', 'real estate investment report', 'buy vs lease', 'reconstruction investment analysis', 'commercial property yield analysis', and other general real estate investment analysis tasks. Actual purchase contracts, brokerage services, interior design, and property management are outside the scope of this skill.

location-scoring

495
from revfactory/harness-100

Location scoring scorecard. Referenced by the location-analyst agent for systematic real estate location evaluation. Use for requests involving 'location analysis', 'location assessment', or 'commercial area analysis'. On-site inspections and surveying are out of scope.

cap-rate-calculator

495
from revfactory/harness-100

Real estate yield calculator. Reference formulas and models used by the profitability-analyst agent for quantitative investment return analysis. Use for requests involving 'Cap Rate', 'yield analysis', 'DCF', or 'cash flow analysis'. Tax advisory and loan underwriting are out of scope.

vendor-scoring

495
from revfactory/harness-100

Vendor evaluation scorecard framework. Referenced by vendor-comparator and evaluation-designer agents when systematically comparing and evaluating vendors. Used for 'vendor evaluation', 'supplier comparison', 'bid evaluation' requests. Note: posting bid announcements and executing contracts are out of scope.