AI Audit Trail Requirements for SEC Filers: 2026 Practitioner Walkthrough
If you searched "AI audit trail SEC filings requirements," you almost certainly landed on articles about the SEC's Consolidated Audit Trail. That rule has nothing to do with your 10-K. This walkthrough cuts through that confusion and tells you exactly what documentation your company must produce when AI touches your financial reporting process.
Key takeaway: There are two entirely different "AI audit trail" obligations in the SEC universe. Rule 613 (the Consolidated Audit Trail) applies to broker-dealers and stock exchanges tracking NMS securities orders. SOX/PCAOB audit trail requirements apply to public company issuers using AI in financial reporting. If you are a CFO, controller, or compliance officer at a public company, Rule 613 is not your problem. Your ICFR documentation is.
Which Rule Actually Applies to Your Company?
The answer depends entirely on what your company does, not just what it files with the SEC.
| Entity type | Governing obligation | Primary authority |
|---|---|---|
| Broker-dealer, national securities exchange, SRO | Rule 613 Consolidated Audit Trail (CAT) | SEC Rule 613 |
| Public company issuer (10-K, 10-Q, 8-K filer) using AI in financial reporting | SOX Sections 302/404, PCAOB AS 2201, COSO 2026 guidance | SOX Section 404, PCAOB AS 2201 |
| Public company with EU operations using high-risk AI | SOX/PCAOB plus EU AI Act Article 12 | EU AI Act |
| Investment adviser using AI in client workflows | Rule 204-2 (Advisers Act books and records), Reg S-P | SEC Advisers Act |
The CAT requires broker-dealers and SROs to report every order and quote in NMS securities to a central repository by 8 a.m. Eastern the following trading day, with timestamps in millisecond or finer increments. That is a market-surveillance infrastructure rule. It is not an ICFR documentation standard.
For the rest of this article, the focus is on the obligation that actually applies to most searchers: what a public company must document when AI is involved in preparing or reviewing its SEC filings and financial statements.
A note on the CAT's current trajectory
For broker-dealers who do need to track the CAT: the system is under active review. The SEC issued Concept Release S7-2026-12 on April 16, 2026, seeking public comment on whether the CAT should be restructured or replaced. Chair Paul Atkins's September 2025 statement "A New Day for the CAT" signaled a cost-reduction and data-minimization agenda, and the CAT NMS Plan was amended on March 27, 2026 to reduce operating costs. The CAT's architecture is not settled law right now.
What Changed in 2026 That Makes This Urgent
Three regulatory events converged in the first half of 2026 to move AI audit trail documentation from best practice to enforceable obligation for public company issuers.
February 23, 2026: COSO's generative AI guidance. COSO published "Achieving Effective Internal Control Over Generative AI" -- the first COSO guidance specifically addressing AI and internal controls. It is explicit: effective monitoring of AI-driven processes requires a complete audit trail capturing prompts, inputs, outputs, model and configuration versions, and evidence of human review, sufficient to reconstruct what the AI acted on and show that the control functioned as designed. COSO goes further: a control that cannot demonstrate this linkage may not survive PCAOB AS 2201 scrutiny. That elevates inadequate AI logging from a documentation gap to a potential ICFR deficiency.
March 31, 2026: SEC's dedicated SOX enforcement group. The SEC announced a dedicated SOX enforcement group targeting audit firm misconduct and signaling materially heightened scrutiny of firm-level quality controls. AI-touched ICFR controls are squarely in scope. This is not a rule change, but enforcement posture shifts how auditors behave in walkthroughs.
August 2026: EU AI Act full enforcement. The EU AI Act's high-risk AI provisions reached full enforcement in August 2026. Article 12 requires deployers of high-risk AI systems to maintain logs for at least six months, with requirements around traceability, accuracy of inputs, identification of natural persons involved, and the reference database used. Any company with EU operations or processing EU persons' data is in scope.
Is Your AI Use in Scope for ICFR Documentation?
Before building a documentation program, you need to determine which AI touchpoints in your financial reporting process are "in ICFR scope." Not every AI tool your finance team uses requires full SOX documentation.
In scope for ICFR documentation (examples):
- AI-assisted journal entry review or posting
- AI-driven variance analysis used to support management's review controls
- AI tools that draft or review MD&A disclosures (see our AI-generated MD&A compliance walkthrough)
- AI-assisted account reconciliation where the output feeds a financial statement line
- AI tools used in the revenue recognition process (see ASC 606 risks in AI-automated revenue recognition)
- AI-assisted XBRL tagging where errors could affect filed financial data
Likely out of scope (but document the rationale):
- AI tools used purely for internal research or benchmarking with no direct financial statement output
- AI-assisted scheduling or workflow tools with no access to financial data
- AI tools used by the external auditor in their own audit procedures (that is the auditor's PCAOB obligation, not yours)
Document the scoping decision for every AI touchpoint. "We determined this tool is out of ICFR scope because..." is a sentence your auditor will want to see.
The 12-Field Minimum: What Your AI Audit Trail Must Capture
A defensible AI audit trail for SOX/ICFR purposes must capture at least 12 fields for every AI-influenced decision. This schema is grounded in the cross-framework requirements of SOX, PCAOB AS 2201, COSO's 2026 guidance, and the EU AI Act.
| Field | Why it is required | Common gap |
|---|---|---|
| Timestamp (NTP-synced, UTC) | Establishes sequence of events for walkthrough | Timestamps in local time zones, not UTC |
| Authenticated human user identity | SOX, PCAOB, GDPR all require individual attribution | AI runs under shared service account or API key |
| AI system identity and version | Enables reconstruction if model changes | Version not logged; only system name captured |
| Model identity and version | Model updates can change outputs materially | Model version not pinned or logged |
| Inputs received, with source attribution | Establishes what the AI acted on | Inputs logged as hashes only, not human-readable |
| Specific policy, rule, or prompt invoked | Links AI action to the control design | Prompt not logged; only output captured |
| Reasoning in human-readable language | PCAOB walkthroughs require explainability | Confidence score logged instead of reasoning |
| Action taken in downstream systems | Establishes financial statement impact | Log stops at AI output; downstream action not linked |
| Human review or approval, with reviewer identity | Demonstrates the control functioned as designed | Approval logged as a system event, not a named individual |
| Tamper-evident integrity proof | Establishes log integrity for audit purposes | Logs stored in mutable database with no hash |
| Mapping to financial assertion | Links AI touchpoint to what it affects (existence, completeness, valuation, etc.) | No assertion mapping in RCM or process narrative |
| ICFR scope designation with rationale | Documents why this touchpoint is in or out of scope | Scope decision undocumented |
The hardest field to get right is individual user attribution. The most common compliance gap in enterprise AI deployments is that AI accesses regulated data under a shared service account or API key, and no log records which individual directed the access. SOX, PCAOB, and GDPR all require individual attribution that service-account logging cannot provide. Fix this before your next audit cycle begins.
Warning: Confidence scores are not a substitute for human-readable reasoning. A PCAOB walkthrough requires an auditor to understand what the AI did and why. "87% confidence" tells the auditor nothing about whether the control functioned as designed.
Retention: How Long Do You Need to Keep AI Audit Logs?
Retention requirements vary by framework. Where multiple frameworks apply, the longer period governs.
| Framework | Minimum retention | Notes |
|---|---|---|
| SOX (audit work papers) | 7 years | Governing floor for any AI log that supports an ICFR control |
| SOX (operational logs) | 366 days minimum | For active monitoring and review |
| EU AI Act Article 12 | 6 months | For high-risk AI systems; longer if national law requires |
| HIPAA | 6 years | If PHI is involved |
| PCI DSS v4.0 | 12 months (3 months immediately available) | If payment card data is in scope |
For a multinational public company using AI in financial reporting, the governing retention period is 7 years. The EU AI Act's 6-month minimum does not override SOX; it is simply a lower floor that SOX already exceeds. Set your AI log retention policy to 7 years and document that SOX governs the determination.
Many finance teams discover their AI log retention is set at 90 days or one year -- a default inherited from IT security log policies. That is a material gap against the SOX floor. Audit your current retention settings before your next external auditor walkthrough.
Step-by-Step: Building Your AI Audit Trail Program
This is the sequence that works in practice, structured for a controller or compliance officer preparing for a PCAOB-inspected audit.
Step 1: Inventory every AI touchpoint in your financial close and reporting process
Walk the financial close calendar and tag every step where an AI tool produces an output that feeds a financial statement, disclosure, or management review control. Include third-party tools (AI-assisted close automation, AI-driven variance analysis, AI-assisted XBRL tagging). Do not rely on IT's software inventory -- it will miss tools that finance teams adopted independently.
For each touchpoint, document: the tool name and vendor, the specific process step, the financial assertion it affects, and your preliminary ICFR scope determination.
Step 2: Assess each touchpoint against the 12-field schema
For each in-scope AI touchpoint, pull a sample log and check it against the 12 fields above. The three gaps you will almost certainly find first:
- Service account attribution -- AI runs under an API key with no human identity linked to individual actions.
- Confidence scores standing in for reasoning -- the log captures a score, not an explanation.
- Retention shorter than 7 years -- the log is in a system with a 90-day or 1-year purge policy.
Document each gap with a remediation owner and target date.
Step 3: Update your SOX documentation to reflect AI involvement
Your Risk and Control Matrix (RCM) and process narratives need to describe AI-assisted controls accurately. If your RCM says "controller reviews variance report" but the variance report is now generated by an AI tool, the control description is stale. Auditors are flagging this.
For each AI-touched control:
- Update the control description to name the AI tool and its role.
- Document the human review step and what the reviewer is expected to assess.
- Map the control to the financial assertions it addresses.
- Note the AI system version in use at the time of the control operation (model updates mid-period need to be logged).
For a deeper look at how SOX 302 certification intersects with AI-touched controls, see our SOX 302 certification requirements walkthrough.
Step 4: Address the SOX 302 certification risk directly
SOX Section 302 requires the CEO and CFO to certify that they have disclosed to auditors all significant deficiencies and material weaknesses in the design or operation of internal controls. If AI systems are involved in financial reporting and lack adequate audit trails, the certification itself is at risk. A CEO or CFO who certifies ICFR effectiveness when AI-touched controls lack adequate documentation may be making a materially inaccurate certification.
Before the next 10-K or 10-Q certification, confirm that every in-scope AI touchpoint has been assessed and that any gaps are either remediated or disclosed as deficiencies.
Step 5: Fix your vendor contracts
If you use third-party AI tools in your financial reporting process, your vendor contract needs to require audit-ready logs. Specifically, the contract should require the vendor to:
- Provide logs with all 12 fields above in a machine-readable format.
- Retain logs for at least 7 years (or make them exportable so you can retain them yourself).
- Notify you of model version changes before they take effect.
- Cooperate with external auditor requests for log data.
Many procurement teams negotiate AI vendor contracts without these provisions. Discovering mid-audit that your vendor purges logs after 90 days is an expensive problem. For a broader vendor due diligence framework, see our ISO 42001 financial reporting vendor due diligence walkthrough.
Step 6: Determine whether EU AI Act Article 12 adds obligations
If your company has EU operations or processes data of EU persons, assess whether your financial reporting AI tools qualify as "high-risk AI" under the EU AI Act. Financial institutions, insurers, and companies using AI for credit decisions or employment-related processes are the primary in-scope categories. If Article 12 applies, confirm your logs capture the specific EU requirements: traceability, accuracy of inputs, identification of natural persons involved, and reference database used. Your SOX 7-year retention already exceeds the EU AI Act's 6-month minimum.
Step 7: Prepare your auditor package before the walkthrough
External auditors are arriving at financial close walkthroughs with AI-specific questions. Prepare a package that includes:
- The AI touchpoint inventory with ICFR scope determinations.
- Updated RCM entries for AI-assisted controls.
- Sample log extracts demonstrating the 12-field schema.
- Evidence of human review for each AI-assisted control (named reviewer, date, what was reviewed).
- Retention policy documentation showing the 7-year floor.
- Vendor contract provisions covering log delivery and retention.
Having this package ready before the auditor asks is materially cheaper than remediating a finding mid-cycle.
What About Disclosing AI Use in Your SEC Filings?
This is a live question that SEC staff are actively asking about in comment letters. The SEC has no rule requiring disclosure of AI use in financial reporting processes, but several existing obligations create indirect pressure:
- Item 1A (Risk Factors): If AI use in financial reporting creates material risks (model error, data integrity, vendor dependency), those risks may need to be disclosed.
- Item 7 (MD&A): If AI materially affects how you produce financial results or controls, a description may be appropriate.
- ICFR disclosure: If an AI-touched control has a deficiency, it must be disclosed under SOX 302/404 like any other control weakness.
SEC staff have begun asking companies in comment letters to explain their use of AI in financial reporting. Reviewing those comment letter responses on EDGAR provides practical guidance on what the SEC expects to see. For a detailed treatment of AI disclosure in quarterly filings, see our AI disclosure in Form 10-Q walkthrough.
FAQ
Does Rule 613 (Consolidated Audit Trail) apply to our company's SEC filings? No. Rule 613 applies to self-regulatory organizations (SROs) and their broker-dealer members tracking NMS securities orders. It does not apply to corporate issuers preparing 10-K, 10-Q, or 8-K filings. If you are a public company issuer, your AI audit trail obligations come from SOX, PCAOB AS 2201, and COSO's 2026 guidance.
What did COSO's February 2026 generative AI guidance change? COSO's guidance made explicit what was previously implied: an AI-assisted control that cannot produce a complete audit trail -- capturing prompts, inputs, outputs, model versions, and evidence of human review -- may not satisfy PCAOB AS 2201. This moves adequate AI logging from best practice to a potential ICFR deficiency trigger.
If our AI system runs under a service account, is that a compliance gap? Yes, and it is the most common gap auditors are finding in 2026. SOX, PCAOB, and GDPR all require individual user attribution. A shared service account or API key cannot provide that. Remediation requires either reconfiguring the AI system to authenticate individual users or implementing an identity proxy layer that links each AI action to a named individual.
How long do we need to retain AI audit logs under SOX? At least 366 days of operational logs and 7 years for audit work papers. Where the EU AI Act also applies, its 6-month minimum is already exceeded by the SOX floor. Set your retention policy to 7 years and document SOX as the governing standard.
What will our external auditor ask about AI in our financial close? Expect questions about: which AI tools are used in the close process and whether they are in ICFR scope; whether your RCM and process narratives reflect AI involvement; what logs exist and whether they capture individual user identity and human-readable reasoning; how long logs are retained; and whether model version changes are tracked. Prepare a written package before the walkthrough rather than answering these questions verbally.
Does the SEC's new SOX enforcement group change anything for us? Not directly -- it is an enforcement posture signal, not a new rule. But it means auditors are under more scrutiny for ICFR quality, which flows directly to how rigorously they test AI-touched controls at their clients. Expect more detailed walkthrough requests and less tolerance for "we'll fix it next cycle" responses.







