What is this course about?
Regulatory reporting is evidence collection plus narrative, and both are automatable — but automating a control means the automation itself becomes a control that has to be tested. This course covers evidence collection, narrative drafting, SOX considerations for AI in the reporting process, and change management for prompts and models.
Who is this course for?
- Regulatory reporting teams
- SOX and internal control staff
- Internal audit
- Finance technology and controllership
What do I need before starting?
- Regulatory reporting or internal control experience
- Familiarity with your control environment
What will I be able to do afterwards?
- Identify where reporting burden actually concentrates
- Automate evidence collection and control testing support
- Draft report narratives with appropriate review
- Apply SOX control considerations to AI in the reporting process
- Change-manage prompts and model versions as controlled artifacts
What does each module cover?
Where does reporting burden concentrate?
40 minMapping effort across the reporting cycle to find the automatable volume.
Objectives
- Map effort across the reporting cycle
- Identify the automatable concentration
- Set realistic reduction targets
Topics
Activity. Map effort across your reporting cycle and identify the top three concentrations.
How do you automate evidence collection?
50 minGathering control evidence consistently, with provenance for every item.
Objectives
- Automate evidence gathering across systems
- Attach provenance to every item
- Detect missing or stale evidence
Topics
Activity. Automate evidence collection for one control and verify completeness.
How do you support control testing?
50 minAI assistance in testing without the AI becoming the tester of record.
Objectives
- Support testing with AI analysis
- Keep the tester of record human
- Document the assistance provided
Topics
Activity. Run AI-supported testing on one control with documented human conclusions.
How do you draft report narratives?
45 minNarrative generation for filings and management reporting, with review proportional to consequence.
Objectives
- Generate narratives from underlying data
- Ensure narratives match the numbers
- Set review proportional to consequence
Topics
Activity. Generate a narrative and verify every statement against the underlying data.
What does SOX require of AI in reporting?
50 minControl considerations when AI sits in the financial reporting process.
Objectives
- Identify SOX implications of AI in reporting
- Design controls over the AI component
- Prepare for auditor questions
Topics
Activity. Design the control set over an AI component in the reporting process.
When does PCI scope apply?
45 minPCI DSS scope when AI systems touch or could touch cardholder data.
Objectives
- Determine PCI scope for AI systems
- Keep AI systems out of scope where possible
- Handle in-scope systems appropriately
Topics
Activity. Assess your AI systems for PCI scope and design segmentation.
How do you change-manage a prompt?
45 minPrompts and model versions as controlled artifacts subject to change management.
Objectives
- Treat prompts as controlled artifacts
- Version and approve changes
- Test changes before production
Topics
Activity. Put a prompt through your change management process end to end.
Auditing the automation itself
50 minThe workshop module: proving the automation did what it claims.
Objectives
- Design an audit trail for the automation
- Prove the automation performed as documented
- Prepare for auditor testing of the automation
Topics
Activity. Produce evidence that the automation performed as documented for one reporting period.
What is the capstone project?
Automated control testing workflow with an audit trail
Build a reporting automation workflow with provenance-tracked evidence collection, AI-supported testing with human conclusions, verified narratives, SOX controls over the AI component, PCI scope assessment, and prompt change management with a complete audit trail.
Deliverable: A working automation with an audit trail proving it performed as documented.
How are learners assessed?
- Every evidence item traceable to its source with provenance
- Prompt change put through the real change management process
- Audit trail tested by internal audit
What ships with the course?
Facilitator guide
Session-by-session running order, discussion prompts, and the questions that reliably derail a room.
Learner workbook
Exercises, checklists, and the templates each module's activity produces.
Hands-on lab environment
A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.
Assessment bank
Scenario questions and rubric criteria mapped to each stated learning outcome.
Source bibliography
Every primary regulation and standard cited on this page, linked and dated.
Which AI agents does this course use?
The hands-on modules run against agents already deployable on the ibl.ai platform for financial services.
Where does the course material come from?
Every module is grounded in primary sources — the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.
- PCI Security Standards Council
PCI SSC
PCI DSS scope definitions used in Module 6.
- SOC 2
AICPA
Trust services criteria informing the control design.
- U.S. Securities and Exchange Commission
SEC
SOX and financial reporting requirements.
- Cybersecurity Framework
NIST
Control framework the automation controls map into.
Delivery notes
Binding guidance for anyone preparing and delivering this course.
- Module 7's prompt change management is the insight most teams miss. A prompt change alters a control's behavior and must be treated with the same rigor as a code change.
- Module 3's tester-of-record boundary matters for independence. AI may analyze; a human must conclude, and the documentation should make the distinction visible.
- Have external audit review the SOX material. Auditor expectations for AI in the reporting process are still forming and vary by firm.
- Module 8 should be tested by internal audit, not by the team that built the automation. Self-assessed audit trails are consistently inadequate.
- Coordinate with FIN-9 — vendor diligence covers the third-party dimension and should not be duplicated here.
Why run AI training on a platform you own?
You own the course, not a licence to it
Course content, learner data, and the platform run inside your perimeter — you own all the code and the data.
Model-agnostic delivery
Run the course's AI components on any LLM — Claude, GPT, Llama, Gemini, Command — and switch anytime.
No per-seat training licences
Usage-based or self-hosted, so cost tracks actual use rather than headcount.
Deploy anywhere
Cloud, private VPC, on-premise, or fully air-gapped — including for cohorts that cannot use public AI tools.
Frequently asked questions
What does the Regulatory Reporting Automation: SOX, PCI DSS, and Audit Trails course cover?
Regulatory reporting is evidence collection plus narrative, and both are automatable — but automating a control means the automation itself becomes a control that has to be tested. This course covers evidence collection, narrative drafting, SOX considerations for AI in the reporting process, and change management for prompts and models. It runs 5.5 hours across 8 modules across 8 modules, at intermediate level, and closes with a capstone: Automated control testing workflow with an audit trail.
Who should take Regulatory Reporting Automation: SOX, PCI DSS, and Audit Trails?
It is written for Regulatory reporting teams, SOX and internal control staff, Internal audit, Finance technology and controllership. Prerequisites: Regulatory reporting or internal control experience; Familiarity with your control environment.
Can we run this course on our own infrastructure?
Yes. ibl.ai is model-agnostic and deploy-anywhere — cloud, private VPC, on-premise, or fully air-gapped — and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for financial services teams that cannot send work to a public AI tool.
How do we get access to Regulatory Reporting Automation: SOX, PCI DSS, and Audit Trails?
Request access and we will set it up for your cohort — hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.
How much does AI training for financial services cost on ibl.ai?
There is no per-seat pricing — you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.