Mapping AI risk to your SOX controls
Here's the shift most banks haven't internalized: the moment an AI system influences a number that flows into financial reporting, it becomes a SOX-relevant control. "The AI generated it" is not a defense to an auditor. The good news is you don't need a brand-new rulebook — you need to extend the controls you already run.
Treat the AI like any other reporting control
SOX and your IT general controls already cover the things AI threatens; they just weren't written with probabilistic, autonomous systems in mind. Map AI to them directly:
- Data integrity → the data feeding the AI must be complete, accurate, and traceable (lineage), exactly as your reporting data already must be.
- Change management → a model update is a change. Version it, test it, document it, approve it — like any release that touches financial systems.
- Access controls → least privilege applies to AI agents and service accounts, not just people.
- Evidence & auditability → every AI-generated figure should carry provenance (sources, definitions, as-of date) and leave an audit trail.
- Human oversight → high-stakes outputs that hit the reporting pack get a human check. Accountability never disappears; it relocates.
If your model influences a financial figure, it's in scope. Govern it with the controls a CFO and an auditor already understand.
Where model risk fits
If you have a model-risk function (SR 11-7), AI extends it rather than replacing it: model inventory, validation, monitoring, and documentation all apply. SR 11-7 itself wasn't written for generative and agentic systems — but the Treasury's FS AI RMF now carries those same disciplines onto them, in finance-specific control objectives you can map straight onto your SOX environment. The win is integration: one control environment, AI included, evidenced as you operate rather than reconstructed in a pre-audit fire drill.
"We'll formalize it next year" is a finding now
SOX isn't a project you finish — it's an annual cycle, and the AI-derived numbers flowing into your reporting are in scope this cycle, not the next one. Auditors are already asking how AI-touched figures are controlled, evidenced, and traced. If your answer is that you'll stand the controls up next year, you've just described a deficiency in this year's attestation. The control gap doesn't wait for your roadmap — it gets tested on the audit calendar.
Deferring AI controls to next year's cycle doesn't postpone the risk — it dates the finding.
Is your data ready for AI reporting — before this year's audit?
Take the free 4-minute risk assessment and get your maturity level with prioritized fixes — instantly.
Take the free assessment See pricing & engagement →