Six Steps to Build SOX Entity-Level Controls for AI

Zero entity-level controls (ELCs).
That’s how many ELCs most organizations have formalized around AI today.
At least, that’s what we heard from several of the Internal Audit and SOX leaders who attended a July 2026 Internal Audit Collective roundtable ably helmed by IT Internal Controls Leader Nicole Coats.
The good news: If we’re starting from zero, the only way is up. Fortunately, Nicole and the other roundtable participants generously shared their challenges, insights, and initial attempts. Read on for six actionable ideas to help you get started with ELCs for AI.
The Central Challenge: Visibility and Uncertainty
Visibility on AI use remains the fundamental problem. How do SOX and Internal Audit teams know what’s happening — and what’s changing?
Organizations bring in new AI technologies and activate new AI capabilities in old tools while employees persist in using unauthorized “shadow” AI. Meanwhile, capabilities are advancing fast in AI tools already in use, departments are piloting AI agents, and control owners are leveraging AI tools in financial processes.
One SOX leader captured the consensus perfectly: “We can't know what's going on across the organization ALL the time.” He added, “Are we going to re-evaluate those tools when they implement agentic AI versus the standard chatbot that it had when it went through its first review? There’s a lot of uncertainty.”
To create ELCs for AI, organizations first need guardrails and processes that give them a fighting chance of identifying, evaluating, and re-evaluating the AI tools being used.
As Nicole asserted, “No one has figured this out yet.”
But as roundtable participants talked about their challenges and early efforts, a simple two-fold strategy rose to the top: (1) Focus on ways to improve the flow of information around AI, and (2) start documenting and sharing the ELCs that are working, even though they’re imperfect.
How to Start Building ELCs for AI
1. Know That There’s No “Right Answer” Yet
This was one of the clearest themes of the conversation. AI ELCs are a work-in-progress for every organization. So if you’re feeling behind the 8 ball, you’re nowhere near alone.
Nicole stressed this reality when kicking off the discussion: “If you've joined this call thinking, ‘Our company doesn’t have it figured out,’ you’re not behind. You’re in the same boat a lot of companies are. So I wanted to start the conversation by normalizing that for everyone, if that's where you're at.”
We don’t need to have all the answers to start solving the problem. We just have to start.
Speaking of getting started…
2. Start With an Acceptable Use Policy — But Don’t Stop There
An AI acceptable use policy makes sense as a starting point: AI ELC #1. But having a policy is one thing — and establishing actual AI governance and controls around it is another thing entirely.
As Nicole observed, “People want to check the box and say, ‘Yep, we made a policy, we’re done’.” It can be challenging to get people thinking about it practically, in terms of “these are the types of controls we have to put in place.”
Roundtable participants shared what’s worked for them to build a robust policy, communicate its importance, and start improving it over time. In overview:
- Develop an AI acceptable use policy with input from all relevant stakeholders (GRC, IT, Legal, Operations, Product, AI teams or steering committees, executive leadership, etc.). The Internal Audit Collective’s AI Governance Playbook provides a list of 20 key policy components.
- Have leadership visibly (and repeatedly) communicate its importance. One team partnered with their CFO to present the policy and communicate its importance during a town hall. The CFO then reinforced that message with an email reminder linking to the policy.
- Establish an ELC around periodic employee policy certification, ensuring responsibility for regularly reviewing the policy and recertifying their understanding and compliance.
- Establish a framework for AI policy review and updates, setting the expectation that an effective AI policy must mature as the organization’s AI use and governance evolves.
- Push the AI ELC conversation with leadership, IT, and other stakeholders, reinforcing the criticality of tying the policy to specific ELCs around ownership, monitoring, and accountability.
3. Consider Leveraging Existing ELCs as a Foundation
Roundtable participants agreed that existing ELCs can make a great starting point for AI ELCs. “It doesn’t necessarily have to involve inventing something from scratch,” said one SOX leader.
For example, one team is having the company’s CISO draft ELC policies and standards. The plan is to use that as their basis for proposing ELCs for AI.
So, as you start thinking about ELCs for AI, work with relevant stakeholders to:
- Look at existing governance. What existing ELCs may offer a foundation?
- Map existing ELCs to new AI control needs. Consider whether you can repurpose existing processes (e.g., policies, standards, procedures, technology reviews, project reviews, governance meetings) instead of creating new ones.
- Revisit data governance, reviewing practices through an AI lens. The discussion also raised questions about the importance of underlying data governance. As one leader put it, “With AI, you really have to focus on who has access to what.” Common concerns include overprivileged access, AI agent access to information, prompt injection, poor data hygiene).
4. Formalize Use Case Reviews as an ELC — and Make Sure They Consider Financial/SOX Impacts
Roundtable participants agreed on the critical importance of establishing and requiring formal review and approval of AI use cases prior to deployment. The ELC supports several key AI governance objectives, including maintaining an updated inventory of AI use cases, preventing the spread of unauthorized AI technologies and use cases, and educating AI application owners about permitted and prohibited use cases.
It also gives management and Internal Audit a way to identify AI use cases that could impact the financial statements and come into your SOX scope.
Several roundtable participants worried that employees may already be using AI in SOX-relevant controls without the SOX team knowing about it. In some cases, they may just be unaware of the potential impacts. In other cases, leaders worried that Finance teams and other SOX control owners could be heavily using AI tools — but not willingly admitting to their usage.
They suggested the following ideas:
- Embed AI-focused questions into existing review/approval and audit processes. Again, avoid creating new and separate processes for AI ELCs when possible. For example:
- Add an AI-use question to SOX walkthroughs.
- Require control owners to identify and describe any AI used in controls.
- Create a specific ELC around AI outputs used in financial reporting. Explicitly require disclosure of such use and document human-in-the-loop requirements. One leader is proposing the following ELC for AI: “Any AI output that is used in financial reporting and ICFR processes needs to be reviewed and approved by a qualified preparer or reviewer. So a human-in-the-loop control, but specifically called out for SOX.”
- Propose/formalize ELCs around AI inventories and AI use logging and monitoring. One team is proposing an inventory of internal AI agents, hoping to “contain the sprawl” and keep tabs on all the business process automation being used on internal workflows. They’re also proposing an ELC for AI use logging and monitoring, given the company’s need to stay compliant with EU-specific regulations around AI and GDPR.
- Do a “SOX Roadshow.” For example, every six months or so, Nicole’s team meets with different leaders and teams involved in SOX and asks what’s coming up (e.g., new systems, big projects). Beyond securing earlier involvement, it also gives the team the opportunity to explain potential impacts that could bring AI applications into scope for SOX. Said Nicole, “It’s been helpful to get buy-in from the right level, and have them see the importance of telling us upfront.”
- Create/share SOX guidance tailored to your organization’s AI users. Jason Winter created an excellent quick-reference guide for teams designing, building, or adopting AI that may impact his company’s financial reporting. The two-pager clearly lays out WHEN AI users need to engage the SOX team and WHY doing so matters. (Internal Audit Collective members can access Jason’s template in the forum’s Template Library.)
5. Get in Lock-Step With the People Holding the AI Reins
Again, keeping the control environment synchronized with how the organization is using AI is a central challenge.
For example, one company’s controls were focused on one AI tool — when Internal Audit discovered that the Development team had already moved on to using a different tool.
Leaders suggested the following strategies:
- Query the business and AI application owners more frequently about both (1) new AI functionality added to existing platforms and (2) any new AI tools in use. Annual assessments can’t move fast enough, so consider adding recurring inquiries to existing quarterly processes. One team’s External Auditor suggested asking for more frequent updates — because as the leader called out, “It’s not like [the business] would stop and tell us.”
- Connect directly with key stakeholders who have visibility on spending and initiatives. For example, one leader “made friends with the CTO and with the head of the PMO. The CTO knows where he’s spending money, and the PMO knows who they’re helping.” So he checks in quarterly to ask, “What have you spent money on that we need to know about? And what projects are you engaged in?” Then, Internal Audit combs through the lists they provide to look for potential SOX implications and investigate further if needed. Speaking of which…
- Do targeted reviews of significant AI spending, regularly reviewing project and technology-spend inventories. These sources can serve as an early-warning system for new AI systems and deployments. You could also consider formally reviewing the company’s top-ten AI spend. Just as you would with a top-ten vendor or supplier review:
- Identify scope, including assessing key risks (e.g., criticality, concentration, cost).
- Review contracts, SLAs, pricing, renewals, oversight, and other key controls.
- Assess risks and controls (e.g., onboarding, due diligence, compliance, monitoring).
- Perform testing.
- Report on control gaps, root causes, and remediation.
6. Don’t Lose Sight of Cybersecurity and Data Governance
As one leader put it, “The 800-pound gorilla of AI is taking over everything, kind of drowning out the conversation about other risks.”
In fact, we’d hoped this roundtable discussion would focus equally on AI and cybersecurity ELCs. But AI took over, as it does.
In the end, the discussion did get back to cybersecurity ELCs, as some teams reported increasing pressure from External Auditors to bring cybersecurity into scope for SOX. So teams are being more thoughtful about how they set up and label cybersecurity controls to get ahead of the game.
Recommendations included:
- Maintain a distinct cybersecurity governance agenda — even as AI inevitably works itself in the discussion. Because leaders struggle with whether cybersecurity belongs directly in the SOX control environment, they recommended focusing cybersecurity ELCs on governance, oversight, and board visibility. Example ELCs included looking at cybersecurity policies, annual cybersecurity training requirements, vendor requirements (e.g., ISO certification, SOC 2, right-to-audit clauses in contracts), penetration testing, and looking at what IT leaders are presenting about cybersecurity in board-level meetings.
- Formalize cybersecurity control objectives and ownership. The roundtable participants agreed that most organizations would benefit from more formalized cybersecurity governance (e.g., a risk and control register specific to cybersecurity). Toby DeRoche shared that he’d been developing a proposal for a cybersecurity ELC model and a specific cybersecurity ELC for SOX; Internal Audit Collective members can access Toby’s templates here.
- Tag assets to connect cybersecurity incidents to SOX. Cybersecurity incident management teams don’t always know when an incident may impact SOX-relevant assets. One team recommended tagging such assets in the configuration management database (CMDB) with SOX flags. Another team holds quarterly meetings to review the full scope of applications from a cybersecurity incident perspective, assessing which could have SOX impacts.
THE LAST WORD: We’ll Find the Answers Together
We will figure this out together. We have to.
As one IT Audit leader called out, “It’s a universal problem. And I get grilled on it quite a bit, because every year we have new systems that come into SOX scope that we had no idea about. And every year, we’re like, ‘We're gonna be better next year,’ and it’s not. I don’t know how to fix this.”
Let’s make sure we’re not in the same position next year.
Fortunately, these leaders are right: The best way forward is for us to get started setting up AI ELCs, share our challenges and what’s working, and not let “perfect” get in the way of good.
That makes this a great opportunity for me to remind Internal Audit Collective members about the forum’s fast-growing library. Beyond great templates like those shared in this article, we’re also building our Center of Excellence knowledge bases (AI Governance and T&E Audit are now live), AI Prompt & Agent Library, and Data Analytic Library. Why not take a few minutes to see what’s new — and what you can use to help out your team? Or contribute a tool of your own? (Note: Library links will only work for Internal Audit Collective members.)
The Internal Audit Collective is what we make it. With your help, we can make it what you want it to be.

Recent Articles

How the Art of Small Talk Can Help You Build Trust and Improve Your Professional Relationships

6 Actionable Ideas to Help You Strengthen Your SOX Risk Assessment in 2026
Want to be updated as new blog posts are released? Subscribe to our newsletter.
Join 1K+ readers of The Enabling Positive Change Newsletter for tips, strategies, and resources to improve your approach to Internal Audit and SOX compliance.