Regulation explainerOracle ERP AI Agent Studio

Fitting AI agents in Oracle Fusion into SOX internal controls

When an AI agent in Oracle Fusion prepares, changes or influences transactions that reach the financial statements, it becomes part of internal control over financial reporting. This explainer maps agent design to what Sarbanes-Oxley Section 404 and PCAOB AS 2201 expect: separate identities and duties for agents, human authorization, change management for prompts and tools, IT general controls, evidence and testing.

Reviewed 8 min read

On this page
  1. Why an ERP agent is an internal control question
  2. The laws, standards and frameworks that apply
  3. Scope and limits of this explainer
  4. Segregation of duties when an agent joins the process
  5. Keeping authorization with people
  6. Change management and IT general controls for agent configuration
  7. Testing agent controls before and after go-live
  8. Evidence gaps auditors are likely to find
  9. Questions and answers
  10. Sources

Why an ERP agent is an internal control question

Section 404 of the Sarbanes-Oxley Act requires management of a US public company to assess and report on the effectiveness of its internal control over financial reporting (ICFR), and for larger filers it requires the external auditor to attest to that assessment1. Section 302 adds certifications by the chief executive and chief financial officers in each periodic report.

An AI agent enters that picture as soon as it creates, changes or shapes a record that flows into the ledger: a draft journal entry, an invoice match, a proposed write-off, an accrual estimate. It may perform a control (checking a match), support a control (assembling evidence for a reviewer) or sit upstream of a control that must catch its errors. Each role needs a different design and a different test.

The people who own ICFR, usually the controller, internal audit and IT risk, therefore need to be in the agent design from the start. Our own Oracle delivery approach includes testing separation of duties, duplicate handling and correction procedures with the process team before an agent goes live6. Finding an in-scope agent for the first time during the year-end audit is the expensive alternative.

The laws, standards and frameworks that apply

Sarbanes-Oxley Act of 2002, Section 404[^1]

United States (SEC registrants)

Applies whenThe company files periodic reports with the SEC under the Securities Exchange Act, including foreign private issuers listed in the US.

  • Section 404(a): management assesses and reports each year on the effectiveness of ICFR.
  • Section 404(b): the external auditor attests to management's assessment; companies classed as non-accelerated filers are exempt from this attestation.

SEC interpretive guidance on management's report on ICFR (Release No. 33-8810)[^2]

United States

Applies whenManagement plans, performs and documents its own evaluation of ICFR.

  • Use a top-down, risk-based evaluation focused on the risk of material misstatement.
  • Scale the evaluation and its documentation to the risk each control addresses.

PCAOB AS 2201, An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements[^3]

United States (auditors of SEC registrants)

Applies whenThe external auditor performs an integrated audit of ICFR.

  • The auditor follows a top-down approach that starts at the financial statements and entity-level controls.
  • The auditor tests the design and operating effectiveness of controls over significant risks, including controls that depend on IT.

COSO Internal Control—Integrated Framework (refreshed 2013)[^4]

Framework, not law; widely used by US registrants

Applies whenManagement needs a recognized framework against which to evaluate ICFR, as SEC rules require.

  • Evaluate controls across the framework's components, including control activities and information and communication.
  • Show that general controls over technology support the control activities that depend on it.

Scope and limits of this explainer

Segregation of duties when an agent joins the process

Treat each agent as a separate identity with its own roles, then test it against the same conflict rules you apply to people. This matrix is a starting point for procure-to-pay and record-to-report.

ActivityAgent mayA person mustWhat to verify in Fusion security
Supplier and bank detail changesFlag a requested change and gather the supporting documentsVerify the change through an independent channel and approve itNo agent role holds privileges to update supplier bank accounts
Invoice matching and exceptionsPropose matches and explain exceptions with evidenceResolve exceptions outside tolerance and release holdsAgent tools cannot release holds or override tolerances
Journal entriesPrepare a draft entry with supporting calculationsReview and approve before postingThe identity that creates a journal cannot also approve it
PaymentsReport on payment status and upcoming runsApprove and release payment runsNo agent tool can create or release payments
Agent configurationNothing: agents never change their own setupChange topics, tools and models through change controlPeople who build agent teams do not approve the transactions those agents prepare

Adjust to your own conflict matrix. Where a tool runs with the signed-in user's access, that user's role conflicts carry over to what the agent can do on their behalf.

Keeping authorization with people

  • If

    The agent prepares a transaction that a person already approves today.

    Then

    Keep the existing approval and show the approver what the agent relied on.

    The control still operates; the agent changes the preparation, not the authorization.

  • If

    The agent's output would take effect without approval below a threshold.

    Then

    Agree the threshold with the control owner and the auditor first, and add a detective review of a sample of items below it.

    Removing a preventive approval changes the control design and has to be assessed as a change.

  • If

    An approval would route back to the person who triggered the agent.

    Then

    Send it to a different approver through the rules of the approval process attached to the workflow5.

    Self-approval through an agent is still self-approval.

  • If

    The agent performs a check that auditors will rely on, such as a match.

    Then

    Document it as an IT-dependent control with defined logic, test cases and change control.

    Reliance needs evidence that the control works consistently, which unconstrained model behavior does not give by default.

Change management and IT general controls for agent configuration

IT general controls cover access, change and operations. Applied to an agent team, they turn into checks like these.

0 of 8 checked

Testing agent controls before and after go-live

  1. Bring the agent into the risk assessment

    Identify which significant accounts and assertions the agent's process affects, and whether the agent performs, supports or sits upstream of a key control.

    Output
    Updated risk and control matrix
    Owner
    Controller with internal audit
  2. Walk one transaction through end to end

    Follow a real transaction from trigger to posting, capturing the agent's output, the approval and the final record, to confirm the design matches the documentation.

    Output
    Walkthrough evidence
    Owner
    Internal audit
  3. Test the design against failure cases

    Run duplicates, missing data, out-of-tolerance amounts and attempts to skip approval, and confirm each one is stopped or escalated.

    Output
    Design test results
    Owner
    IT risk with the process owner
  4. Test operating effectiveness over a period

    Sample approvals and agent outputs from the period and confirm the control operated as designed each time, including who approved and when.

    Output
    Operating effectiveness workpapers
    Owner
    Internal audit
  5. Retest after every change

    When instructions, tools, models or the Fusion release change, rerun the regression set and record the result before relying on the control again.

    Output
    Change-triggered retest log
    Owner
    IT risk

Evidence gaps auditors are likely to find

No link between the agent's output and the posted record

Early signalThe approver's decision is logged, but not what the agent proposed or which records it used.

MitigationRetain the agent's output, cited sources and the approval outcome against the transaction reference.

Configuration history missing

Early signalNobody can show what the instructions said on a given date.

MitigationVersion the agent configuration and keep the change ticket with each version.

Testing done once at go-live

Early signalNo retest followed a model change or a quarterly update.

MitigationTie retesting to the change process so evidence builds up with each change.

Questions and answers

Can an AI agent post journal entries in a SOX environment?

It can prepare them, and in most designs it should stop there. Letting an agent post without approval removes a preventive control, which management and the auditor would need to assess as a change in control design. A common pattern is an agent that drafts the entry with calculations and support, and a person who reviews and approves it through the normal Fusion journal approval.

Does adding an agent change our materiality or SOX scoping?

Materiality is set for the financial statements, not by the tools you use, so an agent does not change it. It can change scoping, though: if the agent affects a significant account or a key control, the related IT general controls and the agent's configuration become part of what management evaluates and what the auditor may test.

Do these controls matter for companies that are not US-listed?

SOX itself applies to companies with SEC reporting obligations. Private companies, subsidiaries of listed groups and companies preparing to list often adopt the same controls because a parent, lender or future auditor expects them. The design principles here, separate agent identities, human authorization and controlled configuration, are sound practice for any finance process that uses agents.

Who owns an agent's controls, IT or finance?

Both, for different parts. The finance process owner decides what the agent may do and approves changes to its scope. IT or the Fusion administration team owns access, change management and operations for the agent configuration. Internal audit tests both, and the controller decides how the agent appears in the risk and control matrix.

Sources

  1. Sarbanes-Oxley Act of 2002 (Public Law 107-204) — U.S. Government Publishing Office · checked 10 October 2026
  2. Commission Guidance Regarding Management's Report on Internal Control Over Financial Reporting (Release No. 33-8810) — U.S. Securities and Exchange Commission · checked 10 October 2026
  3. AS 2201: An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements — Public Company Accounting Oversight Board · checked 10 October 2026
  4. Internal Control—Integrated Framework — Committee of Sponsoring Organizations of the Treadway Commission (COSO) · checked 10 October 2026
  5. Use the Approval Process Channel for Human Approval Nodes in AI Agent Studio (Fusion 26C) — Oracle · checked 10 October 2026
  6. Oracle ERP AI Agent Studio: delivery approach — ColdAI

More in Oracle ERP AI Agent Studio

Back to Oracle ERP AI Agent Studio

Next step

Review an agent design against your SOX controls

Send the process, the agent's planned tools and your current control matrix. We will point out where the agent touches key controls, what to test and which configuration needs change management.

Request a controls review