Compliance decisions
SOX evidence for AI during financial close
Treat AI output as an input to the financial-close process, not proof that a control operated. Retain the source, the relevant draft, the reviewer’s checks and the authorised accounting decision. AI security events can support input-protection evidence; they do not establish effective internal control over financial reporting.
For Controllers, SOX and ICFR owners, internal audit and security teams
The useful evidence explains why the final close decision was supported.
All invoice values, periods, documents and review actions are fictional. No actual journal, controller approval, audit or product test has occurred.01
Start from the existing control objective
PCAOB AS 2201 addresses the audit of internal control over financial reporting, including risk assessment and period-end reporting controls. It is not an AI-specific statute or a mandate to retain every prompt. Identify the financial-reporting risk and the control already intended to address it.
For a close task, that could mean checking the completeness and accuracy of an accrual or the basis for a journal adjustment. Explain where employee AI use enters the process and which control objective could be affected. Do not create a second approval label that obscures the established accounting owner.
Source context: PCAOB AS 2201: Audit of internal control over financial reporting
02
Keep the source and transformation traceable
An AI-generated explanation is only as reviewable as its underlying evidence. Retain a controlled reference to the source records, the relevant input scope and the draft that influenced the decision. Do not spread confidential close data into unrelated tools simply to make an evidence packet look complete.
The simplified fictional example uses a 12,000-unit invoice with an assumed allocation of 9,000 to June and 3,000 to July. A draft that treats all 12,000 as June expense conflicts with those stipulated facts. The example illustrates a review discrepancy, not an accounting policy for real invoices.
Source context: PCAOB AS 2201: Audit of internal control over financial reporting
03
Show the reviewer’s actual work
AS 2201 distinguishes testing control design from testing operating effectiveness. A procedure can be well designed without evidence that it operated in a particular case. A button labelled approved or a record of AI usage does not explain what the reviewer compared or why the result was accepted.
Capture the relevant checks, exceptions and resolution at the level the control requires. In the teaching case, the reviewer role compares the proposed allocation with the stipulated source and identifies the unsupported 3,000 difference. Do not present that fictional review as an actual professional sign-off or an auditor’s conclusion.
Source context: PCAOB AS 2201: Audit of internal control over financial reporting
04
Separate input protection from financial accuracy
An input policy may help prevent an unnecessary customer identifier or confidential attachment from reaching an AI service. That evidence concerns the data-handling boundary. It does not show that the generated accounting explanation is complete, that assumptions are reasonable or that a journal is authorised.
Keep the security-control record linked where useful, but retain the accounting evidence in the appropriate close system. Distinguish a test of the installed input path from the financial reviewer’s decision and the auditor’s independent work.
Source context: PCAOB AS 2201: Audit of internal control over financial reporting
05
Preserve the final decision and change history
Retain the final supported workpaper, the relevant approval under the existing process and a trace of material changes. If AI output was rejected or revised, record the issue that mattered to the control rather than preserving every irrelevant conversational turn.
Agree evidence scope and retention with the responsible control and records owners. AS 2201 does not create a universal AI-chat retention period. Revisit the control design if AI use changes the preparation, review or posting process, and evaluate actual operation before claiming the control is effective.
Source context: PCAOB AS 2201: Audit of internal control over financial reporting
Put it into practice
Synthetic close-review evidence packet
A simplified two-period allocation exposes a draft error and shows the evidence needed to resolve it through the existing close process.
All invoice values, periods, documents and review actions are fictional. No actual journal, controller approval, audit or product test has occurred.
Stipulated source
June 9,000 + July 3,000
Illustrative AI draft
June 12,000
Does not match the exercise facts.
Review evidence
Identify and explain the 3,000 mismatch
No real accounting approval is represented.
| Evidence item | Invented case content | What it establishes |
|---|---|---|
| Source TEST-INV-01 | Total 12,000; assumed allocation June 9,000 and July 3,000. | The stipulated facts for this teaching example, not a real accounting determination. |
| Draft TEST-AI-01 | Proposes 12,000 as June expense. | The specific generated statement requiring review. |
| Review TEST-REV-01 | Compare draft with the assumed period allocation; identify a 3,000 mismatch. | An example of the check that would need actual reviewer evidence. |
| Revised workpaper TEST-WP-01 | June 9,000; July 3,000, under the exercise assumptions. | The illustrative correction and its source reference. |
| Approval and posting | No live approval or posting occurs in this exercise. | Use the existing authorised close process for a real decision. |
| Security evidence | Input-control evaluation is separate and not run here. | A policy event would address the tested data path, not financial correctness. |
Work through your review
Use the checks to organise the evidence you need. Your selections stay in this tab.
0 of 3 reviewed
Example files for this task
Keep the source material and the instructions together. You can also download the complete worksheet or matrix as CSV.
sox-ai-close-evidence.mdInspect
# Synthetic close-review evidence packet
All invoice values, periods, documents and review actions are fictional. No actual journal, controller approval, audit or product test has occurred.
A simplified two-period allocation exposes a draft error and shows the evidence needed to resolve it through the existing close process.
| Evidence item | Invented case content | What it establishes |
| --- | --- | --- |
| Source TEST-INV-01 | Total 12,000; assumed allocation June 9,000 and July 3,000. | The stipulated facts for this teaching example, not a real accounting determination. |
| Draft TEST-AI-01 | Proposes 12,000 as June expense. | The specific generated statement requiring review. |
| Review TEST-REV-01 | Compare draft with the assumed period allocation; identify a 3,000 mismatch. | An example of the check that would need actual reviewer evidence. |
| Revised workpaper TEST-WP-01 | June 9,000; July 3,000, under the exercise assumptions. | The illustrative correction and its source reference. |
| Approval and posting | No live approval or posting occurs in this exercise. | Use the existing authorised close process for a real decision. |
| Security evidence | Input-control evaluation is separate and not run here. | A policy event would address the tested data path, not financial correctness. |
## Review steps
- Name the control objective: Identify the financial-reporting risk and the existing preparation, review and approval responsibilities.
- Retain the decision trail: Link source facts, material AI draft, review checks, exceptions and the final supported workpaper.
- Keep evidence meanings distinct: Do not substitute an AI usage or DLP event for accounting review or auditor testing.
## Simplified financial fixture
Invoice reference: TEST-INV-01
Total in invented currency units: 12000
Assumed June amount: 9000
Assumed July amount: 3000
AI draft statement: all 12000 belongs in June
Review discrepancy: 3000 does not match the stipulated period allocation
The allocation is an exercise assumption, not accounting advice. No real invoice or accounting record is represented.
## Review-note example
“Under the exercise assumptions, the draft’s June amount conflicts with the source allocation. Revise the workpaper to show 9000 for June and 3000 for July, retain the source reference and follow the normal approval process.”
This is authored example wording, not a completed human review.
## Source and scope
Guide: https://aona.ai/resources/guides/sox-ai-financial-close-evidence/
Source check: 21 September 2026. General information, not professional approval or a completed control test.
- PCAOB AS 2201: Audit of internal control over financial reporting: https://pcaobus.org/oversight/standards/auditing-standards/details/AS2201
Download sox-ai-close-evidence.mdsox-ai-close-evidence.csvInspect
Evidence item,Invented case content,What it establishes
Source TEST-INV-01,"Total 12,000; assumed allocation June 9,000 and July 3,000.","The stipulated facts for this teaching example, not a real accounting determination."
Draft TEST-AI-01,"Proposes 12,000 as June expense.",The specific generated statement requiring review.
Review TEST-REV-01,"Compare draft with the assumed period allocation; identify a 3,000 mismatch.",An example of the check that would need actual reviewer evidence.
Revised workpaper TEST-WP-01,"June 9,000; July 3,000, under the exercise assumptions.",The illustrative correction and its source reference.
Approval and posting,No live approval or posting occurs in this exercise.,Use the existing authorised close process for a real decision.
Security evidence,Input-control evaluation is separate and not run here.,"A policy event would address the tested data path, not financial correctness."
Download sox-ai-close-evidence.csvsynthetic-close-values.csvInspect
reference,item,amount,status
TEST-INV-01,total,12000,fictional
TEST-INV-01,June allocation,9000,exercise assumption
TEST-INV-01,July allocation,3000,exercise assumption
TEST-AI-01,draft June amount,12000,intentionally incorrect example
Download synthetic-close-values.csvBefore you proceed
Keep these distinctions clear
- An approval label is not the reviewer’s reasoning
- Retain the checks and material exception resolution required by the control.
- DLP evidence does not prove ICFR effectiveness
- Input protection and financial-reporting control evidence answer different questions.
Apply it to employee AI use
Bring your actual data path.
Aona can contribute scoped evidence about employee AI use and sensitive-input policies on supported installed paths.
It does not validate accounting, approve journal entries, perform the auditor’s tests or establish effective ICFR.
Use the synthetic close context to assess input protection separately from the organisation’s existing financial review.
Review your use caseFAQ
Questions for this decision
Does SOX require a special AI approval system?
Can a prompt log prove a close control worked?
Must every AI conversation be kept for six years?
Are the example amounts a recommended accounting treatment?
Evidence behind the guide
Sources and scope
Prepared by Aona. Sources checked 2026-09-21. The cited material supports the specific points below; it does not certify a product or your use case.
- PCAOB AS 2201: Audit of internal control over financial reporting
Risk-based ICFR audit, period-end reporting controls, and distinct testing of design and operating effectiveness.
standard · checked 2026-09-21