A Conceptual Framework for AI Enabled IT General Controls and SOX Audit Automation Processes
Ijeoma Stephanie Mbonu, King Chime Aliliele, Uzoamaka Azuka Iwuanyanwu, Esther Uzoka
- 发表年份
- 2022
- 引用次数
- 10
- 访问权限
- 开放获取
摘要
Organizations subject to the Sarbanes–Oxley Act increasingly rely on complex digital ecosystems that demand stronger, faster, and more transparent assurance over IT General Controls (ITGCs). Traditional audit approaches remain heavily manual, resource intensive, and reactive, limiting the ability of auditors and management to detect control failures in real time and maintain consistent compliance. This study proposes a conceptual framework for AI-enabled IT General Controls and SOX audit automation processes designed to enhance reliability, efficiency, and continuous compliance across enterprise environments. The framework integrates machine learning, process mining, natural language processing, and robotic process automation into a unified governance architecture aligned with risk-based auditing principles and modern DevSecOps practices. The model maps the lifecycle of ITGC domains, including identity and access management, change management, IT operations, backup and recovery, and incident response, embedding automated evidence collection, anomaly detection, and predictive risk scoring into each stage. By shifting from periodic testing toward continuous monitoring, the framework enables proactive identification of control weaknesses, faster remediation cycles, and improved coordination between audit, compliance, and technology teams. Explainable AI techniques are incorporated to ensure transparency, traceability, and regulatory acceptance of automated audit decisions. The framework also introduces an intelligent control maturity model that aligns automation capabilities with organizational risk appetite, governance maturity, and reporting obligations. Continuous control monitoring dashboards provide real-time visibility into control effectiveness, enabling data-driven decision making and stronger accountability. The study contributes to theory by bridging audit methodology, artificial intelligence, and enterprise risk management, and to practice by offering a scalable roadmap for AI adoption in SOX compliance programs. The proposed approach supports audit quality, reduces operational cost, enhances audit readiness, and strengthens stakeholder confidence in financial reporting integrity. Future research can empirically validate the framework and explore adaptive AI models for dynamic risk environments.
关键词
相关论文
Statistical Learning Theory
Yuhai Wu, Vladimir Vapnik
1999
Fractional Differential Equations
Igor Podlubný
2025
Applied Nonlinear Control
Jean-Jacques Slotine, Weiping Li
1991
Genetic Programming: On the Programming of Computers by Means of Natural Selection
John R. Koza
1992