---
title: "Finance AI With No Audit Trail Is Evidence, Not Speed"
slug: "mid-market-finance-ai-adoption-without-governance-audit-trail"
author: "Jaione Amigot"
date: "2026-09-16 09:00:00"
category: "Premium"
topics: "finance AI governance, audit trail, mid-market finance, SOX 404, internal controls, shadow AI, data classification, controller"
summary: "Gartner reports 93% of audit leaders and auditors using AI, while a May 2026 poll found only 38% of chief audit executives have any AI strategy, and PCAOB AS 1105 makes an untraceable entry a rework bill."
banner: ""
thumbnail: ""
linkedin: |
  Most mid-market finance teams did not adopt AI. They allowed it, and called the result transformation.

  The uncomfortable part is what happens next, and it is not a fine. Mid-market companies — $10M to $1B in revenue, per the National Center for the Middle Market — are mostly private, so SOX's internal-control reporting requirements do not apply to them. Even among public filers, the SEC's 2020 amendment removed the 404(b) auditor attestation for smaller reporting companies under $100M in revenue.

  So the exposure is evidentiary, not regulatory. Under PCAOB AS 1105, when a company produces information the auditor relies on, the auditor has to test its accuracy and completeness, or the controls over it. A reconciliation an analyst got from a chatbot has neither. It does not fail an inspection. It fails to be evidence — so the work gets done twice, at audit rates, in the middle of the close.

  Three controls a controller can stand up alone, without an enterprise programme:

  → An inventory of every point where AI touches the close — who, which tool, which account
  → A retained per-run record of prompt, data in, output, model and approver, in storage the author cannot edit
  → Data classification that keeps regulated and client data out of tools the company has no contract with

  With ibl.ai you own all the code and the data — self-hosted inside your own perimeter, model-agnostic across any LLM, usage-based with no per-seat pricing, deployable anywhere from your own cloud to a fully air-gapped network.

  #iblai #AgenticAI #EnterpriseAI #Finance #AuditTrail #Governance
---

## The Short Answer

**Mid-market finance teams adopted AI without a governance layer. Gartner reports 93% of audit leaders and auditors using AI, and a May 2026 poll found only 38% of chief audit executives with an AI strategy. Under PCAOB AS 1105 an auditor must test company-produced information, so an AI-assisted entry with no retained trail is a finding, not a saving. With ibl.ai you own all the code and the data, so the trail is yours to produce.**

The absence of a record is not a gap in the evidence. In an audit or a dispute, it is the evidence.

## What does "mid-market" mean here, and which rules actually bind a mid-market finance team?

It means a revenue band, and the answer to the second half is narrower than most coverage implies.

The [National Center for the Middle Market](https://www.middlemarketcenter.org/expert-perspectives/5-reasons-why-you-need-to-know-the-mighty-middle-market) defines the U.S. middle market as companies with **annual revenues between $10 million and $1 billion**: roughly **200,000 businesses**, about **3% of U.S. companies**, producing **33% of private sector GDP** and 33% of private sector jobs.

Most are private, so SOX's internal-control reporting requirements do not apply to them.

Even among public filers the obligation is thinner than assumed. [15 U.S.C. 7262](https://www.law.cornell.edu/uscode/text/15/7262) requires management to state its responsibility for internal control over financial reporting and assess its effectiveness at year end.

Subsection (c) exempts issuers that are neither large accelerated nor accelerated filers from the 404(b) auditor attestation, and the [SEC's 2020 amendment](https://www.cooley.com/news/insight/2020/2020-04-23-sec-amends-accelerated-filer-definition-exempt-low-revenue-smaller-reporting-companies) widened that carve-out to smaller reporting companies **under $100 million in annual revenue**, effective 27 April 2020.

Banking guidance does not cover the gap either. [SR 26-2](https://www.federalreserve.gov/supervisionreg/srletters/SR2602.pdf), issued by the Federal Reserve, OCC and FDIC on **17 April 2026**, is most relevant to organizations above **$30 billion in total assets**.

Its footnote 3 states that "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance."

The same footnote extends the guidance's principles to "non-generative, non-agentic AI models" — the reading examined in [inference engineering, not architecture](/blog/inference-engineering-not-architecture-financial-firms).

So a controller waiting for a rule to arrive is waiting for something that is not coming. The exposure is evidentiary, and it is already here.

## How much unsanctioned AI is really running inside finance functions?

Enough that the honest answer is nobody has a finance-specific number worth citing, and the adjacent numbers are bad enough.

[BlackFog's survey of 2,000 workers](https://www.cio.com/article/4124760/roughly-half-of-employees-are-using-unsanctioned-ai-tools-and-enterprise-leaders-are-major-culprits.html) at companies with more than 500 employees, reported 29 January 2026, found **49% using unapproved AI tools** and **51% who connected an AI tool to a work system without IT approval**.

**23% said they had put company financial information into one**, and **58% of unapproved-tool users were on free consumer tiers**: accounts the employer has no contract with and no retention control over.

The audit side is further along and no better governed. Gartner reports, [via Help Net Security](https://www.helpnetsecurity.com/2026/09/15/gartner-ai-in-internal-audit/), that **93% of audit leaders and auditors use AI at some level**, and **15%** say their department runs formal use cases routinely.

In a separate **May 2026** poll of **161 chief audit executives**, only **38% have an AI strategy at any level**; of **142 CAEs** polled that month, **54% have not started measuring the value**.

Read those together and the picture is specific: the function that will ask your team how a number was produced is itself using AI without a documented approach to it.

The same exposure shows up in security incidents involving unapproved AI tools, the argument made at length in [shadow IT stored data, shadow agents take actions](/blog/agent-governance-new-shadow-it-day-one-controls).

## Why is an AI-assisted journal entry with no trail a finding rather than a productivity gain?

Because of what an auditor is required to do with information your company produced.

[PCAOB AS 1105](https://pcaobus.org/oversight/standards/auditing-standards/details/AS1105) requires sufficient appropriate audit evidence, where appropriateness is "the measure of the quality of audit evidence, i.e., its relevance and reliability."

When the auditor uses information produced by the company, the standard requires testing its accuracy and completeness — or the controls over it — and confirming it is sufficiently precise and detailed for the audit.

An accrual estimate, a flux explanation or a reconciliation an analyst obtained from a consumer chatbot satisfies none of that. There is no control to test, and no record to test, because the session belongs to a personal account.

The result is rarely a penalty. It is rework: the auditor cannot rely on the number, so the procedure is redone at audit rates, during the close.

The same asymmetry applies in a dispute. An AI-assisted forecast, valuation input or credit decision is discoverable, and in discovery the absence of a trail is not neutral.

You cannot show what the model saw, which version answered, or who approved it. Opposing counsel does not have to prove the number was wrong, only that you cannot show it was right.

Speed without auditability is therefore not innovation. The artifact it leaves behind is evidence you did not choose to create.

## Which three controls can a mid-market controller stand up without an enterprise programme?

Three, and none of them requires a platform purchase, a committee, or a policy your team will not read.

- **An inventory of where AI touches the close.** One sheet: process step, person, tool, and whether the output lands in the ledger, a schedule, or a memo. It has to come first, because the other two controls take a named process as their input.
- **A retained per-run trail.** For every AI-assisted output that reaches a statement, retain the prompt, the input data, the output, the model and version, and the reviewer, in storage the author cannot edit.
- **Data classification with one hard line.** Name the categories that may never leave a system the company controls, then enforce it at the network and identity layer rather than in a policy document.

Classification is where most programmes stall, because it gets written as a taxonomy exercise. One tier naming the data that may not enter an unmanaged tool is more enforceable than five nobody can apply on day three of the close.

## Why does running the platform inside your own perimeter make the trail yours to produce?

Because an audit trail you cannot export on demand is an assurance, not a record.

When the assistant runs on a vendor's infrastructure, the log is the vendor's log. What you receive is what their retention policy, export format and contract term decide you receive, on their timetable rather than your auditor's.

When the platform runs inside your perimeter, every prompt, retrieval, model response and approval is written to your storage, under your retention schedule, queryable by your team. Producing it is a query, not a support ticket.

This is the same structural argument that determines [whether banking AI reaches production](/blog/why-only-15-percent-of-banking-ai-reaches-production), arriving at a smaller company.

## How does ibl.ai give a finance team a trail it can produce on demand?

By putting the platform, and its source, inside the company's own perimeter.

With ibl.ai you own all the code and the data.

The platform deploys on your infrastructure with full source code access, so retention windows, logging schema, approval gates and classification rules are components your team reads and changes rather than vendor behavior you observe.

It is model-agnostic across any LLM, so a governance record survives a model swap instead of being rebuilt around it.

Billing is usage-based with no per-seat pricing, so bringing the whole finance organization under one governed system does not cost more than leaving them on consumer accounts.

You can deploy anywhere: your own cloud, on-premise, GovCloud, or a fully air-gapped network with no outbound connectivity.

Agent access is role-scoped through your identity provider and enforced server-side by the broker, and every tool call is written to a tamper-resistant log the agent cannot alter.

1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

ibl.ai is family-owned and operated from New York, NY.

*Related reading: [shadow IT stored data, shadow agents take actions](/blog/agent-governance-new-shadow-it-day-one-controls) — the six day-one controls that sit under any agent runtime; and [inference engineering, not architecture](/blog/inference-engineering-not-architecture-financial-firms) — the full reading of SR 26-2's footnote 3.*

*Sources: the revenue band and the 3%/33% shares from the [National Center for the Middle Market](https://www.middlemarketcenter.org/expert-perspectives/5-reasons-why-you-need-to-know-the-mighty-middle-market); the ICFR report and 404(b) exemption from [15 U.S.C. 7262](https://www.law.cornell.edu/uscode/text/15/7262), with the 2020 carve-out from [Cooley](https://www.cooley.com/news/insight/2020/2020-04-23-sec-amends-accelerated-filer-definition-exempt-low-revenue-smaller-reporting-companies); the issuance date, applicability and footnote 3 from [SR 26-2](https://www.federalreserve.gov/supervisionreg/srletters/SR2602.pdf); the audit-evidence requirements from [PCAOB AS 1105](https://pcaobus.org/oversight/standards/auditing-standards/details/AS1105); the unapproved-tool figures from [CIO on BlackFog's survey](https://www.cio.com/article/4124760/roughly-half-of-employees-are-using-unsanctioned-ai-tools-and-enterprise-leaders-are-major-culprits.html); the AI-use, strategy and value-measurement figures from [Help Net Security on Gartner's internal-audit research](https://www.helpnetsecurity.com/2026/09/15/gartner-ai-in-internal-audit/).*

## Why does owning the AI stack matter?

**ibl.ai is the agentic AI platform where you own all the code and the data. You self-host the entire stack inside your own perimeter, run it model-agnostic across any LLM and switch anytime, and pay by usage with no per-seat pricing — so you can deploy anywhere: your cloud, on-premise, GovCloud, or fully air-gapped.**

- **You own all the code and the data.** Full source code under a perpetual license, running on your infrastructure. Not API access to someone else's platform — the stack itself is yours.
- **Model-agnostic.** Run any LLM — Claude, GPT, Gemini, Llama, Command, or your own fine-tune — and switch providers without rewriting the platform.
- **No per-seat pricing.** Usage-based billing against a budget cap you set. Cost tracks what your organization actually uses, not how many people you employ.
- **Deploy anywhere.** Your cloud, your VPC, on-premise, GovCloud, or a fully air-gapped network with no outbound connectivity.

1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

ibl.ai is family-owned and operated from New York, NY — a U.S.-headquartered, domestically-owned long-term partner, not a vendor that sells licenses and moves on.
