Sarbanes-Oxley Act (SOX §302 / §404)
source ↗Cornell LIIManagement certification and internal control over financial reporting. Once an agent aggregates ledgers, drafts financial statements, or approves procurement variances, it sits inside the ICFR boundary: the control needs documented design, testing evidence, segregation of duties and an auditable trail of every automated adjustment.
2 components0 articles / obligations3 triggering use casesopen in graph Supervisor Attribution Chain
100% of use casesEvery model inference, data interaction and client-facing artefact is bound to an authorised supervising natural person — never to a shared service account. Required for SEC Rule 204-2 attribution, SOX segregation of duties and AI Act Art. 26 deployer oversight records.
- named in regulationSarbanes-Oxley Act (SOX §302 / §404) → Supervisor Attribution Chain
WORM / Immutable Audit Vault
100% of use casesAppend-only, hash-chained audit vault (WORM object-lock storage, AES-256 at rest, TLS 1.3 in transit). Guarantees tamper-evidence within the organization's trust domain — which stops your own team, but not an admin who can rebuild the vault. Pair with an external trust anchor and key ceremonies outside the operating team for evidence that holds against the insider scenario.
- named in regulationSarbanes-Oxley Act (SOX §302 / §404) → WORM / Immutable Audit Vault