Gana Misra
By Gana MisraCEO, Finrep
Fri Sep 11 2026

AI Audit Trail Requirements for SEC Filers: 2026 Practitioner Walkthrough

Share
AI Audit Trail Requirements for SEC Filers: 2026 Practitioner Walkthrough

AI Audit Trail Requirements for SEC Filers: 2026 Practitioner Walkthrough

If you searched "AI audit trail SEC filings requirements," you almost certainly landed on articles about the SEC's Consolidated Audit Trail. That rule has nothing to do with your 10-K. This walkthrough cuts through that confusion and tells you exactly what documentation your company must produce when AI touches your financial reporting process.

Key takeaway: There are two entirely different "AI audit trail" obligations in the SEC universe. Rule 613 (the Consolidated Audit Trail) applies to broker-dealers and stock exchanges tracking NMS securities orders. SOX/PCAOB audit trail requirements apply to public company issuers using AI in financial reporting. If you are a CFO, controller, or compliance officer at a public company, Rule 613 is not your problem. Your ICFR documentation is.

Which Rule Actually Applies to Your Company?

The answer depends entirely on what your company does, not just what it files with the SEC.

Entity typeGoverning obligationPrimary authority
Broker-dealer, national securities exchange, SRORule 613 Consolidated Audit Trail (CAT)SEC Rule 613
Public company issuer (10-K, 10-Q, 8-K filer) using AI in financial reportingSOX Sections 302/404, PCAOB AS 2201, COSO 2026 guidanceSOX Section 404, PCAOB AS 2201
Public company with EU operations using high-risk AISOX/PCAOB plus EU AI Act Article 12EU AI Act
Investment adviser using AI in client workflowsRule 204-2 (Advisers Act books and records), Reg S-PSEC Advisers Act

The CAT requires broker-dealers and SROs to report every order and quote in NMS securities to a central repository by 8 a.m. Eastern the following trading day, with timestamps in millisecond or finer increments. That is a market-surveillance infrastructure rule. It is not an ICFR documentation standard.

For the rest of this article, the focus is on the obligation that actually applies to most searchers: what a public company must document when AI is involved in preparing or reviewing its SEC filings and financial statements.

A note on the CAT's current trajectory

For broker-dealers who do need to track the CAT: the system is under active review. The SEC issued Concept Release S7-2026-12 on April 16, 2026, seeking public comment on whether the CAT should be restructured or replaced. Chair Paul Atkins's September 2025 statement "A New Day for the CAT" signaled a cost-reduction and data-minimization agenda, and the CAT NMS Plan was amended on March 27, 2026 to reduce operating costs. The CAT's architecture is not settled law right now.

What Changed in 2026 That Makes This Urgent

Three regulatory events converged in the first half of 2026 to move AI audit trail documentation from best practice to enforceable obligation for public company issuers.

February 23, 2026: COSO's generative AI guidance. COSO published "Achieving Effective Internal Control Over Generative AI" -- the first COSO guidance specifically addressing AI and internal controls. It is explicit: effective monitoring of AI-driven processes requires a complete audit trail capturing prompts, inputs, outputs, model and configuration versions, and evidence of human review, sufficient to reconstruct what the AI acted on and show that the control functioned as designed. COSO goes further: a control that cannot demonstrate this linkage may not survive PCAOB AS 2201 scrutiny. That elevates inadequate AI logging from a documentation gap to a potential ICFR deficiency.

March 31, 2026: SEC's dedicated SOX enforcement group. The SEC announced a dedicated SOX enforcement group targeting audit firm misconduct and signaling materially heightened scrutiny of firm-level quality controls. AI-touched ICFR controls are squarely in scope. This is not a rule change, but enforcement posture shifts how auditors behave in walkthroughs.

August 2026: EU AI Act full enforcement. The EU AI Act's high-risk AI provisions reached full enforcement in August 2026. Article 12 requires deployers of high-risk AI systems to maintain logs for at least six months, with requirements around traceability, accuracy of inputs, identification of natural persons involved, and the reference database used. Any company with EU operations or processing EU persons' data is in scope.

Is Your AI Use in Scope for ICFR Documentation?

Before building a documentation program, you need to determine which AI touchpoints in your financial reporting process are "in ICFR scope." Not every AI tool your finance team uses requires full SOX documentation.

In scope for ICFR documentation (examples):

  • AI-assisted journal entry review or posting
  • AI-driven variance analysis used to support management's review controls
  • AI tools that draft or review MD&A disclosures (see our AI-generated MD&A compliance walkthrough)
  • AI-assisted account reconciliation where the output feeds a financial statement line
  • AI tools used in the revenue recognition process (see ASC 606 risks in AI-automated revenue recognition)
  • AI-assisted XBRL tagging where errors could affect filed financial data

Likely out of scope (but document the rationale):

  • AI tools used purely for internal research or benchmarking with no direct financial statement output
  • AI-assisted scheduling or workflow tools with no access to financial data
  • AI tools used by the external auditor in their own audit procedures (that is the auditor's PCAOB obligation, not yours)

Document the scoping decision for every AI touchpoint. "We determined this tool is out of ICFR scope because..." is a sentence your auditor will want to see.

The 12-Field Minimum: What Your AI Audit Trail Must Capture

A defensible AI audit trail for SOX/ICFR purposes must capture at least 12 fields for every AI-influenced decision. This schema is grounded in the cross-framework requirements of SOX, PCAOB AS 2201, COSO's 2026 guidance, and the EU AI Act.

FieldWhy it is requiredCommon gap
Timestamp (NTP-synced, UTC)Establishes sequence of events for walkthroughTimestamps in local time zones, not UTC
Authenticated human user identitySOX, PCAOB, GDPR all require individual attributionAI runs under shared service account or API key
AI system identity and versionEnables reconstruction if model changesVersion not logged; only system name captured
Model identity and versionModel updates can change outputs materiallyModel version not pinned or logged
Inputs received, with source attributionEstablishes what the AI acted onInputs logged as hashes only, not human-readable
Specific policy, rule, or prompt invokedLinks AI action to the control designPrompt not logged; only output captured
Reasoning in human-readable languagePCAOB walkthroughs require explainabilityConfidence score logged instead of reasoning
Action taken in downstream systemsEstablishes financial statement impactLog stops at AI output; downstream action not linked
Human review or approval, with reviewer identityDemonstrates the control functioned as designedApproval logged as a system event, not a named individual
Tamper-evident integrity proofEstablishes log integrity for audit purposesLogs stored in mutable database with no hash
Mapping to financial assertionLinks AI touchpoint to what it affects (existence, completeness, valuation, etc.)No assertion mapping in RCM or process narrative
ICFR scope designation with rationaleDocuments why this touchpoint is in or out of scopeScope decision undocumented

The hardest field to get right is individual user attribution. The most common compliance gap in enterprise AI deployments is that AI accesses regulated data under a shared service account or API key, and no log records which individual directed the access. SOX, PCAOB, and GDPR all require individual attribution that service-account logging cannot provide. Fix this before your next audit cycle begins.

Warning: Confidence scores are not a substitute for human-readable reasoning. A PCAOB walkthrough requires an auditor to understand what the AI did and why. "87% confidence" tells the auditor nothing about whether the control functioned as designed.

Retention: How Long Do You Need to Keep AI Audit Logs?

Retention requirements vary by framework. Where multiple frameworks apply, the longer period governs.

FrameworkMinimum retentionNotes
SOX (audit work papers)7 yearsGoverning floor for any AI log that supports an ICFR control
SOX (operational logs)366 days minimumFor active monitoring and review
EU AI Act Article 126 monthsFor high-risk AI systems; longer if national law requires
HIPAA6 yearsIf PHI is involved
PCI DSS v4.012 months (3 months immediately available)If payment card data is in scope

For a multinational public company using AI in financial reporting, the governing retention period is 7 years. The EU AI Act's 6-month minimum does not override SOX; it is simply a lower floor that SOX already exceeds. Set your AI log retention policy to 7 years and document that SOX governs the determination.

Many finance teams discover their AI log retention is set at 90 days or one year -- a default inherited from IT security log policies. That is a material gap against the SOX floor. Audit your current retention settings before your next external auditor walkthrough.

Step-by-Step: Building Your AI Audit Trail Program

This is the sequence that works in practice, structured for a controller or compliance officer preparing for a PCAOB-inspected audit.

Step 1: Inventory every AI touchpoint in your financial close and reporting process

Walk the financial close calendar and tag every step where an AI tool produces an output that feeds a financial statement, disclosure, or management review control. Include third-party tools (AI-assisted close automation, AI-driven variance analysis, AI-assisted XBRL tagging). Do not rely on IT's software inventory -- it will miss tools that finance teams adopted independently.

For each touchpoint, document: the tool name and vendor, the specific process step, the financial assertion it affects, and your preliminary ICFR scope determination.

Step 2: Assess each touchpoint against the 12-field schema

For each in-scope AI touchpoint, pull a sample log and check it against the 12 fields above. The three gaps you will almost certainly find first:

  1. Service account attribution -- AI runs under an API key with no human identity linked to individual actions.
  2. Confidence scores standing in for reasoning -- the log captures a score, not an explanation.
  3. Retention shorter than 7 years -- the log is in a system with a 90-day or 1-year purge policy.

Document each gap with a remediation owner and target date.

Step 3: Update your SOX documentation to reflect AI involvement

Your Risk and Control Matrix (RCM) and process narratives need to describe AI-assisted controls accurately. If your RCM says "controller reviews variance report" but the variance report is now generated by an AI tool, the control description is stale. Auditors are flagging this.

For each AI-touched control:

  • Update the control description to name the AI tool and its role.
  • Document the human review step and what the reviewer is expected to assess.
  • Map the control to the financial assertions it addresses.
  • Note the AI system version in use at the time of the control operation (model updates mid-period need to be logged).

For a deeper look at how SOX 302 certification intersects with AI-touched controls, see our SOX 302 certification requirements walkthrough.

Step 4: Address the SOX 302 certification risk directly

SOX Section 302 requires the CEO and CFO to certify that they have disclosed to auditors all significant deficiencies and material weaknesses in the design or operation of internal controls. If AI systems are involved in financial reporting and lack adequate audit trails, the certification itself is at risk. A CEO or CFO who certifies ICFR effectiveness when AI-touched controls lack adequate documentation may be making a materially inaccurate certification.

Before the next 10-K or 10-Q certification, confirm that every in-scope AI touchpoint has been assessed and that any gaps are either remediated or disclosed as deficiencies.

Step 5: Fix your vendor contracts

If you use third-party AI tools in your financial reporting process, your vendor contract needs to require audit-ready logs. Specifically, the contract should require the vendor to:

  • Provide logs with all 12 fields above in a machine-readable format.
  • Retain logs for at least 7 years (or make them exportable so you can retain them yourself).
  • Notify you of model version changes before they take effect.
  • Cooperate with external auditor requests for log data.

Many procurement teams negotiate AI vendor contracts without these provisions. Discovering mid-audit that your vendor purges logs after 90 days is an expensive problem. For a broader vendor due diligence framework, see our ISO 42001 financial reporting vendor due diligence walkthrough.

Step 6: Determine whether EU AI Act Article 12 adds obligations

If your company has EU operations or processes data of EU persons, assess whether your financial reporting AI tools qualify as "high-risk AI" under the EU AI Act. Financial institutions, insurers, and companies using AI for credit decisions or employment-related processes are the primary in-scope categories. If Article 12 applies, confirm your logs capture the specific EU requirements: traceability, accuracy of inputs, identification of natural persons involved, and reference database used. Your SOX 7-year retention already exceeds the EU AI Act's 6-month minimum.

Step 7: Prepare your auditor package before the walkthrough

External auditors are arriving at financial close walkthroughs with AI-specific questions. Prepare a package that includes:

  • The AI touchpoint inventory with ICFR scope determinations.
  • Updated RCM entries for AI-assisted controls.
  • Sample log extracts demonstrating the 12-field schema.
  • Evidence of human review for each AI-assisted control (named reviewer, date, what was reviewed).
  • Retention policy documentation showing the 7-year floor.
  • Vendor contract provisions covering log delivery and retention.

Having this package ready before the auditor asks is materially cheaper than remediating a finding mid-cycle.

What About Disclosing AI Use in Your SEC Filings?

This is a live question that SEC staff are actively asking about in comment letters. The SEC has no rule requiring disclosure of AI use in financial reporting processes, but several existing obligations create indirect pressure:

  • Item 1A (Risk Factors): If AI use in financial reporting creates material risks (model error, data integrity, vendor dependency), those risks may need to be disclosed.
  • Item 7 (MD&A): If AI materially affects how you produce financial results or controls, a description may be appropriate.
  • ICFR disclosure: If an AI-touched control has a deficiency, it must be disclosed under SOX 302/404 like any other control weakness.

SEC staff have begun asking companies in comment letters to explain their use of AI in financial reporting. Reviewing those comment letter responses on EDGAR provides practical guidance on what the SEC expects to see. For a detailed treatment of AI disclosure in quarterly filings, see our AI disclosure in Form 10-Q walkthrough.

FAQ

Does Rule 613 (Consolidated Audit Trail) apply to our company's SEC filings? No. Rule 613 applies to self-regulatory organizations (SROs) and their broker-dealer members tracking NMS securities orders. It does not apply to corporate issuers preparing 10-K, 10-Q, or 8-K filings. If you are a public company issuer, your AI audit trail obligations come from SOX, PCAOB AS 2201, and COSO's 2026 guidance.

What did COSO's February 2026 generative AI guidance change? COSO's guidance made explicit what was previously implied: an AI-assisted control that cannot produce a complete audit trail -- capturing prompts, inputs, outputs, model versions, and evidence of human review -- may not satisfy PCAOB AS 2201. This moves adequate AI logging from best practice to a potential ICFR deficiency trigger.

If our AI system runs under a service account, is that a compliance gap? Yes, and it is the most common gap auditors are finding in 2026. SOX, PCAOB, and GDPR all require individual user attribution. A shared service account or API key cannot provide that. Remediation requires either reconfiguring the AI system to authenticate individual users or implementing an identity proxy layer that links each AI action to a named individual.

How long do we need to retain AI audit logs under SOX? At least 366 days of operational logs and 7 years for audit work papers. Where the EU AI Act also applies, its 6-month minimum is already exceeded by the SOX floor. Set your retention policy to 7 years and document SOX as the governing standard.

What will our external auditor ask about AI in our financial close? Expect questions about: which AI tools are used in the close process and whether they are in ICFR scope; whether your RCM and process narratives reflect AI involvement; what logs exist and whether they capture individual user identity and human-readable reasoning; how long logs are retained; and whether model version changes are tracked. Prepare a written package before the walkthrough rather than answering these questions verbally.

Does the SEC's new SOX enforcement group change anything for us? Not directly -- it is an enforcement posture signal, not a new rule. But it means auditors are under more scrutiny for ICFR quality, which flows directly to how rigorously they test AI-touched controls at their clients. Expect more detailed walkthrough requests and less tolerance for "we'll fix it next cycle" responses.

Run your financial reporting on Finrep