Compliance
SOX
AI touching financial reporting needs documented controls and change management. Versioned, reviewable evidence.
At a glance
Who this covers, and who enforces it
Public companies whose AI systems touch financial reporting, forecasting, or the controls that support it.
- Instrument
- Sarbanes-Oxley Act of 2002 — federal law
- Enforced by
- SEC; audits overseen by the PCAOB
- Applies to
- US-listed public companies
- Key sections
- 302, 404, 906
- Exposure
- Executive certification carries personal liability
Requirements
What it asks for
- 1Documented internal controls (Section 404)
- 2Change management on financial-facing systems
- 3Auditor access to underlying evidence
- 4Support for executive certification
Evidence mapping
What PRISM records against each requirement
Every plan records this evidence as your AI runs. Compliance Reports, which turn it into a reviewed, framework-mapped report, are delivered as a service, on request.
- Documented controls
- Guardrails and Projects & Team show who can change a financial-facing AI system, and under what policy.
- Change management
- The Audit Log timestamps every configuration change with an actor.
- Auditor access
- Export & Audit hands an external auditor the record instead of a log-mining exercise.
- Certification support
- Scores & Alerts give the ongoing evidence behind a quarterly sign-off.
Primary source
Read the actual text
Everything on this page is drawn from Sarbanes-Oxley Act of 2002 — H.R.3763, Congress.gov. The capture is live, not a paraphrase — go straight to the source and check us.

Evidence, not certification
This page describes SOX’s publicly available requirements and how PRISM’s evidence layer supports them. It is not legal advice, and it does not constitute certification, regulatory approval, or a guarantee of compliance. SOX compliance remains your organization’s responsibility, in consultation with qualified counsel.
Keep reading
- All frameworksThe full evidence-layer overview and all twelve frameworks.
- PCI DSSCardholder data kept out of AI logs. Guardrail events and redaction evidence on the paths that matter.
- EU AI ActRisk classification, logging, and human oversight duties for AI systems in the EU. PRISM evidence shows what the system did and who approved each change.
Ask us about your framework
Tell us how SOX applies to your systems and we'll show you the evidence path.