Artificial intelligence is no longer a peripheral tool in the finance department; it has begun to infiltrate the very core of financial reporting, proposing journal entries and drafting variance commentary. However, a fundamental pillar of corporate accountability, Section 302 of the Sarbanes-Oxley Act (SOX), still mandates that a named officer personally certify the fairness of a company’s financial condition. Shreyas Sampath, a prominent voice in financial transformation, argues that as AI models, rather than human judgment, increasingly generate this critical output, the "reasonable basis" underpinning an officer’s signature is quietly being eroded, posing significant audit and compliance risks.
The current regulatory landscape, shaped by the landmark SOX legislation enacted in 2002 following major accounting scandals like Enron and WorldCom, places a heavy burden of responsibility on senior executives. Section 302 specifically requires the principal executive and financial officers to certify the accuracy and completeness of financial reports. This certification is a personal attestation, asserting that, to their knowledge, the financial statements fairly present the company’s financial condition.
The introduction of advanced AI, particularly large language models (LLMs), into financial reporting workflows presents a novel challenge to this established framework. When an AI model generates a journal entry that is subsequently booked, or drafts the narrative that explains financial performance fluctuations, the traditional chain of human oversight and accountability is disrupted. Historically, the "reasonable basis" for an officer’s signature rested on a traceable lineage of human decision-making. Each individual involved in preparing the numbers could articulate their judgments, assumptions, and the data supporting their conclusions. This human-centric process provided a clear audit trail and a foundation upon which an officer could confidently place their certification.
However, with AI-generated output, a critical link in this chain is altered. The AI model itself, driven by complex algorithms and vast datasets, cannot be deposed, cannot walk an auditor through its reasoning in a humanly comprehensible way, and cannot stand behind a number with the same accountability as a human controller. This creates a potential gap where human review once occurred, a gap that the certifying officer is now implicitly endorsing.
"The pressure to deploy is real, and adoption is outpacing oversight," notes Sampath, highlighting a trend observed within Fortune 500 companies. Finance leaders are increasingly integrating AI into their operations, with a significant portion, over 50% according to recent industry surveys, now utilizing AI in some capacity. The fastest adopters are pushing these technologies directly into financial reporting, where AI’s output moves beyond mere support for human judgment to actively shaping the data that executives must personally attest to.
The distinction between different AI applications is crucial for understanding the evolving risk landscape. Summarizing board preparation materials with an LLM, for instance, falls into a different risk category than using AI to draft variance commentary or propose journal entries that directly impact the company’s financial records. The former is a decision-support tool, where a human still makes and owns the ultimate decision. The latter, however, produces output that becomes an integral part of the official financial record, directly subject to executive certification.
A common, yet potentially flawed, approach observed is the tendency to configure both types of AI use cases in a similar manner, often by deferring ownership to the IT department. "The answer most of them reach for – that IT owns it – is one that fails an audit," Sampath warns. This approach creates a significant governance gap, as the oversight required for a decision-support tool differs substantially from that needed for a reporting-critical tool. The certifying officer ultimately inherits the implications of this disparity.
The Emerging AI Governance Gap Under SOX
Research published by WTW in March 2026 explicitly framed this as an emerging AI governance gap under SOX, with direct implications for officer certifications under Section 302. The fundamental premise of SOX, conceived in an era before sophisticated AI, was that humans made decisions and could be held accountable for them. An AI model, operating on statistical patterns, lacks this capacity for personal accountability. Therefore, the "reasonable basis" an officer relies upon must be established through robust governance mechanisms built into the AI system before its output is integrated into certified statements.
Consider a seemingly straightforward use case: automated transaction approval workflows. The logic often dictates that transactions exceeding a defined threshold should be automatically approved. However, in practice, complexity arises quickly, particularly with payment categories. A recent client engagement exemplified this pitfall. Transactions met all configured threshold rules, yet the underlying payment data was inaccurate. This resulted in a cascade of over- and underpayments to vendors, leading to reconciliation challenges, compliance exposure, and strained vendor relationships – costs that often dwarched any perceived efficiency gains from automation.
When such an error propagates through the system, impacting the ledger, which in turn feeds the reporting cycle, the officer certifying the financials faces a precarious situation. If questioned about their reasonable basis for signing off on these numbers, the honest, yet potentially damaging, answer might be that an automated control approved the transactions based on pre-defined rules, without a proper validation of the underlying data. This represents a thin basis for certification, originating from a workflow design that prioritized rule validation over data integrity.
The reason this erosion of basis occurs so subtly is that traditional internal control frameworks were designed to assess human adherence to documented procedures. This logic does not translate seamlessly to AI surfacing reconciliation exceptions or proposing journal entries for human review. When a model generates the initial proposal, the review control alone may be insufficient. The model itself often needs to be validated as part of the control design, decisions that should ideally be made at the outset of a project, not discovered retrospectively.
PCAOB Guidance and the Path to Audit Readiness
The Public Company Accounting Oversight Board (PCAOB) has, through public remarks in 2025 and early 2026, reinforced the direction that AI should serve as a tool to support, rather than replace, professional judgment. Clear documentation of how AI outputs are generated and reviewed is paramount. This suggests a future where AI in financial reporting will likely involve a human retaining final sign-off on anything that flows to external reporting, with AI primarily responsible for surfacing exceptions, identifying anomalies, and drafting supporting analysis.
Leading organizations are responding by adopting a "finance-led" approach to AI governance, treating it not solely as an IT problem. These teams understand that finance owns the controls, and therefore must own the parameters, thresholds, and documentation standards that govern AI-driven reporting processes. This includes a commitment to audit readiness from "Sprint One."
This proactive approach involves building essential artifacts before any configuration begins. These typically include:
- A requirements control matrix, clearly defining the controls and their alignment with business objectives.
- A data architecture and process flow diagram that maps every automated decision point, providing transparency into how data is processed and used.
- Functional and technical specifications that precisely define what a reviewer must see, capture, and retain for every AI-assisted output that touches certified reporting.
This meticulous planning ensures that model documentation, input lineage, and review evidence are integral to the workflow from its inception, rather than being retrofitted under audit pressure. Current industry data suggests a significant gap in this preparedness. More than three-quarters of executives surveyed lack strong confidence in their ability to pass an independent AI governance audit within 90 days, a clear indication that many organizations are currently engaged in retrospective efforts.
Why "IT Owns It" Fails the Officer
Programs that consistently falter in their AI adoption and governance often fall into the trap of treating AI governance as a purely IT deliverable. This leads to technically sound controls that are operationally orphaned. When auditors inquire about model drift monitoring for a tool proposing accruals, for example, finance might point to IT, IT might point to the vendor, and ultimately, no one possesses a defensible answer. The certifying officer, standing at the end of this accountability chain, finds themselves without a clear person or process to account for the numbers they have attested to.
Recent analyses from prominent firms like KPMG and Grant Thornton echo this sentiment, emphasizing that effective AI governance requires joint ownership across finance, IT, internal audit, and the relevant control owners. The most common oversight is finance outsourcing the governance question to IT due to the unfamiliarity with the underlying technology. While IT is indeed responsible for infrastructure, model hosting, and integration, the critical parameters that determine the material correctness of an output must be owned by finance.
Finance departments are best positioned to define what constitutes a reasonable accrual, an acceptable variance, or the necessary level of review for a high-dollar payment. When these parameters are set by an IT team or derived from vendor defaults because finance was not actively involved in the design sessions, the control may exist on paper but lacks the necessary endorsement and defensibility from within the finance function. These parameters are, in essence, the operational translation of the "reasonable basis." An officer cannot confidently certify financial statements if the underlying thresholds were established by whoever happened to configure the tool, rather than by the finance function with the expertise to set them appropriately.
Building the Basis Before the Signature: A Strategic Imperative
The finance teams poised for success in the current year will treat AI adoption and control design as a single, integrated project. This may involve a slower initial sprint, but it yields a scalable and defensible solution. The pressure to deploy AI is immense; with 74% of CFOs ranking AI deployment as a top-three strategic priority, the urgency is undeniable. However, this pressure underscores why the question of certification basis cannot be deferred.
Every workflow that moves AI closer to the core of certified reporting adds another layer of output for which an officer will ultimately be responsible. The "reasonable basis" for that signature must be intentionally designed from the outset or painstakingly reconstructed under intense audit scrutiny. Organizations that recognize this imperative are proactively building this foundation now, transforming it from a design choice into a robust pillar of their compliance framework. The future of financial reporting, with AI as an integral component, hinges on the ability of companies to ensure that the executive oversight mandated by SOX remains meaningful and grounded in a tangible, defensible basis, regardless of the origin of the data.
