News & Blogs

The Audit Nobody Should Be Running By Hand Anymore by Anisha Meka

Global · · medium.com

SOX compliance in 2026 still runs on processes built in 2002. AI agents are changing that, monitoring access, change management, and job failures continuously instead of quarterly. The bottleneck isn't the regulation. It's the spreadsheet.


Large public companies spend up to $2.9 million a year on SOX compliance, burning thousands of hours on manual evidence-gathering that often catches violations months after they occurred. The GRC tools that exist today — Workiva, ServiceNow, Optro — digitize the process without automating it. A human still pulls the exports, runs the tests, and writes the narratives.

 

That's starting to change. A new generation of compliance platforms uses domain-specific AI agents to monitor continuously: one watching access provisioning and deprovisioning, another tracking change management tickets, another monitoring batch job failures. When a gap appears between a termination date and a deprovisioning timestamp, the agent flags it immediately with evidence attached, rather than surfacing it in next year's audit report.

 

The human auditor doesn't disappear. They shift from pulling spreadsheets to reviewing AI-drafted narratives and exercising judgment on ambiguous cases. That distinction matters, since regulatory acceptance of AI-assisted evidence is still an open question.

 

Three forces converged to make this possible now: enterprise IT moved to cloud systems with real APIs, large language models became reliable enough for first-pass narrative drafting, and SEC cybersecurity disclosure rules expanded ITGC scope just as audit talent got scarcer. The result is a $1.3 billion market segment growing at nearly 12% annually that has been waiting for tooling that actually automates rather than organizes.

 

There's a layer of irony worth noting: the AI agents built to automate compliance are themselves falling under compliance regimes. The EU AI Act classifies certain operational monitoring systems as high-risk, with human oversight requirements and risk documentation obligations.

 

SOX is an unglamorous case study, but that's the point. High cost, high tedium, clear rules, abundant data. That combination describes far more of the back office than most organizations admit.

 

*Read the full article by Anisha Meka for complete analysis.*


Read more
Comments

No comments yet. Be the first.


Sign in to join the discussion.

Sign in or Create account
Subscribe

By email

Get audit & assurance news in your inbox.


By feed reader

We publish RSS, Atom, and JSON feeds sliced by category and region.

View all feeds →

Have a tip? Submit a story or job →

Subscribe by email

Get audit & assurance news in your inbox. Or use a feed reader — view all feeds →