The central message is measured but important: these technologies do not create a separate AI-specific SOX rulebook. They do, however, require organizations to determine how automated systems affect financially relevant data, control execution, management certifications, and the reliability of audit evidence.
This Week's Key Topics
SEC Filer-Status Proposal Reaches the End of Its Comment Period
The public comment period for SEC Release No. 33-11419 closed on July 20. The proposal would raise the public-float threshold for Large Accelerated Filer status from $700 million to $2 billion, simplify filer classifications, and generally prevent newly public companies from becoming Large Accelerated Filers during their first 60 months following an initial public offering.
If adopted, approximately 81% of reporting companies could be classified as Non-Accelerated Filers and therefore exempt from the external-auditor attestation requirement under SOX Section 404(b). Management's responsibility to assess internal control over financial reporting under Section 404(a), along with officer-certification responsibilities under Section 302, would remain.
For compliance teams, a possible 404(b) exemption should not be interpreted as eliminating the need for a mature ICFR program. Organizations would still need controls sufficient to support management's assessment and executive certifications. The proposal does not require - or establish that companies are already making - specific investments in automated compliance platforms or centralized "compliance data lakes."
Caution: The measure remained a proposal in the source materials and should not be presented as an adopted regulatory change.
Read the SEC proposal overview
Trust by Design for Enterprise AI
PwC's July 21 publication argues that AI governance should be embedded into system design rather than added after deployment. Its suggested operating model includes risk-tiered approvals, identity and access restrictions, lifecycle governance, decision records, continuous observability, escalation criteria, and human intervention for higher-risk applications.
For SOX and ITGC teams, the practical relevance depends on the use case. An AI tool that drafts nonauthoritative commentary presents a different control risk from one that proposes journal entries, changes accounting estimates, resolves reconciliation exceptions, or initiates transactions. Governance should therefore reflect the system's authority, financial significance, autonomy, and the difficulty of detecting an error.
These practices may help organizations create more auditable and controlled AI processes, but they represent professional guidance rather than SEC or PCAOB requirements.
Read PwC's "Trust by Design" publication
AI Agents and Non-Human Identities Expand the Access-Control Perimeter
KPMG and OpenAI announced a strategic alliance on July 21 focused on AI-native enterprise workflows. KPMG describes an environment in which AI agents interact across enterprise data and applications while established platforms continue to serve as systems of record.
This model illustrates an increasingly relevant ITGC question: what access and authority should be granted to service accounts, application programming interfaces, robotic-process-automation identities, integration credentials, and autonomous agents?
For control purposes, the determining factor is not whether an identity is human. It is whether the identity can create, change, approve, transmit, or delete financially relevant information. Higher-risk machine identities may warrant clearly assigned ownership, least-privilege access, credential protection, periodic recertification, activity logging, change approval, and segregation-of-duties controls.
Caution: The source materials do not establish that the PCAOB has created a separate "non-human identity" standard or mandated automated access reviews for every machine account. This is a risk-based application of existing access, system, and evidence principles - not a newly announced regulatory rule.
KPMG also notes that some alliance-related services may not be permissible for its audit clients, underscoring the importance of considering auditor-independence restrictions when implementation and assurance services intersect.
Read the KPMG and OpenAI announcement
Distinguishing AI-Assisted Controls from AI-Executed Controls
A July 27 article from Corporate Compliance Insights examines how executives can maintain a reasonable basis for Section 302 certifications when AI proposes journal entries, develops variance explanations, or otherwise influences reported financial information.
A human approval step does not automatically make an AI-supported process an effective review control. The control design should establish what the reviewer examines, which evidence is available, what thresholds require investigation, and whether the reviewer has the information and competence needed to identify a material model, logic, or data error.
The role of the AI system should be classified according to the actual workflow:
- When AI independently performs a preventive or detective procedure, it may function as an automated control.
- When AI generates an exception report reviewed by a person, the complete control may include the model, source data, report logic, reviewer procedures, investigation criteria, and evidence of resolution.
- When AI only drafts narrative content, it may be a productivity tool rather than a key control.
Potential considerations include approved-use inventories, ownership, input-data validation, configuration and parameter control, versioning, predeployment testing, output monitoring, vendor-change notification, fallback procedures, and retained evidence of review. The appropriate design should remain proportionate to materiality and risk.
Read "When AI Writes the Number, Who Has a Reasonable Basis to Certify It?"
Continuous Monitoring Expands Coverage but Does Not Eliminate Sampling
Continuous control monitoring can provide earlier detection of exceptions and, for appropriate automated tests, evaluate a larger share - or even all - of a transaction population. Examples include identifying privileged-access changes, configuration modifications, duplicate payments, or transactions that violate defined approval rules.
However, continuous monitoring does not automatically replace management review, internal-audit judgment, or external-auditor procedures. The reliability of monitoring results still depends on complete and accurate source data, properly configured rules, controlled changes, appropriate thresholds, effective exception handling, and relevant ITGCs.
The source materials also clarify that PCAOB standards do not prescribe a universal "sample of 25." Depending on the audit objective and assessed risk, auditors may use sampling, selected-item testing, or full-population examination. Similarly, PCAOB AS 1215 addresses the sufficiency and retention of audit documentation; it does not mandate an immutable or blockchain-style chain of custody.
Read the continuous-monitoring source article
Agentic AI Adoption Continues to Outpace Trust
A Boomi-commissioned Forrester study reported that 86% of 409 surveyed senior technology decision-makers had moved AI agents beyond pilot stages, while only 34% said they trusted the agents' actions.
Although the study is not specific to SOX compliance and should not be generalized to all organizations, it illustrates a potentially significant governance gap. Automated agents cannot produce dependable financial outputs unless the underlying data, integrations, permissions, configurations, and actions are appropriately governed and auditable. The primary newsletter similarly connects this trust gap to data quality, integration reliability, and control maturity.
Read the article discussing the Boomi study
Key Takeaways
- Emerging AI, cloud, and automation risks should be evaluated through established, risk-based ICFR and ITGC principles rather than treated as evidence of a new technology-specific SOX framework.
- Organizations should distinguish carefully between AI tools that assist employees, systems that execute controls, and agents that can independently initiate or modify financially relevant activities.
- Machine identities should be governed according to their access and capabilities, while automated monitoring should be supported by reliable data, controlled logic, documented exceptions, and effective human oversight.
- Regulatory proposals, professional frameworks, vendor research, and practitioner commentary carry different levels of authority. Clear attribution is essential when determining what is required, recommended, observed, or merely emerging.
Thank you for reading this week's SOX & ITGC Weekly Digest.