Manav.id
Regulated ยท 16 min read

Someone signs to say the numbers are true. What did they check?

Sarbanes Oxley put personal accountability for financial reports on two named individuals, on purpose, because diffuse responsibility is how the frauds of 2001 happened. As AI systems draft, reconcile and summarise the material underneath that signature, it is worth asking what the certifying officer's review now consists of, and what record exists that it happened.

Thursday, six in the evening

Picture the chief financial officer of a mid cap company on the Thursday before a filing. The disclosure committee met on Tuesday. Audit signed off this morning. The final package landed in her inbox ninety minutes ago and runs to a hundred and eighty pages.

She reads the management discussion and analysis properly, twice, because that is where the judgment lives and where she will be asked questions. She reads the risk factors, most of which she has seen in three prior drafts. She skims the notes. She looks hard at two numbers she has been arguing about for a week. Somewhere around ten in the evening she opens the certification page, and she signs it.

The certification says, among other things, that she has reviewed the report, that based on her knowledge it contains no untrue statement of a material fact, and that she is responsible for establishing and maintaining the company's disclosure controls and internal control over financial reporting.

Now the honest question, and it is not a gotcha. What did she actually check?

She did not recompute the revenue figure. She has never recomputed a revenue figure. No chief financial officer of a company of any size has ever personally verified the numbers in a filing, and the statute has never assumed one would. That is not a scandal. It is the entire reason the regime is built the way it is.

Short answer: Yes, an officer can certify financial statements that AI helped prepare. The certification has always rested on internal control over financial reporting rather than on personal recomputation. The open question is narrower: the control framework assumes a chain of human review beneath the signature, and if parts of that chain become machine generated without any change in how review is evidenced, the structure the certification relies on has changed without being re-examined.

What does a SOX certification actually say?

Worth setting out precisely, because it is quoted loosely and the detail matters.

Section 302 of the Sarbanes Oxley Act of 2002, implemented by the Securities and Exchange Commission through Rules 13a-14 and 15d-14, requires the principal executive officer and principal financial officer to certify each periodic report. The certification covers several distinct assertions: that the officer has reviewed the report; that based on their knowledge it does not contain an untrue statement of material fact or omit a material fact necessary to make the statements not misleading; that based on their knowledge the financial statements and other financial information fairly present the financial condition and results of operations; that they are responsible for establishing and maintaining disclosure controls and procedures and internal control over financial reporting; that they have evaluated the effectiveness of those controls; and that they have disclosed to the auditors and the audit committee any significant deficiencies, material weaknesses, and any fraud involving management or employees with a significant role in internal control.

Section 906, codified at 18 U.S.C. 1350, adds a separate criminal certification with real teeth: knowing violations carry fines and imprisonment, and willful violations carry substantially higher maximums. Congress meant it to concentrate the mind.

Notice the shape of those assertions. Only one of them is about the officer's own knowledge of specific facts. The rest are about the system: whether controls exist, whether they were evaluated, whether deficiencies were escalated. Section 404 then requires management's assessment of internal control over financial reporting, with an auditor attestation for larger filers. The regime is not asking an executive to vouch for arithmetic. It is asking them to vouch for a machine that produces arithmetic, and to be personally on the hook if that machine is broken and they said otherwise.

Why personal certification exists at all

The design choice is deliberate and it came out of a specific failure. In the collapses that produced the Act, one recurring feature was that no individual could be found who had personally asserted anything. Responsibility was distributed across committees, memoranda, and the space between the finance function and the board until it evaporated.

So the drafters did something blunt: they picked two people, by title, and made them sign. Not because those two know the most, but because a name on a document is the only reliable way to prevent responsibility from dissolving. The certification is a device for concentrating accountability, and it works largely through anticipation. An officer who knows they will personally sign asks different questions in September than one who knows a department will file something in October.

The officer never verified the numbers personally. So what changed?

If personal recomputation was never the point, why does AI in the close process raise a question at all? This is the objection a thoughtful controller will make within thirty seconds, and it deserves a real answer rather than a hand wave.

The answer is that the certification rests on a chain, and the chain has assumptions baked into it that nobody wrote down because they were too obvious to state.

When the officer certifies that controls are effective, the controls being described are overwhelmingly human review controls. A reconciliation is prepared by one person and reviewed by another. A journal entry above a threshold requires approval. A disclosure draft is written by the reporting team, reviewed by technical accounting, reviewed by legal, reviewed by the disclosure committee. The auditor tests these by asking for evidence: a sign off in the close management system, an initial on a workpaper, an approval in the workflow tool.

The unstated assumption is that when the evidence says reviewed by J. Patel, a person named J. Patel brought human attention to bear on the thing being reviewed. That assumption held for decades not because it was enforced but because there was no other way for the work to get done.

Now parts of the chain can be performed by systems that draft disclosure language, propose reserve estimates, reconcile transaction populations, and assemble filing packages. Much of this is genuinely good. Reconciliation is exactly the kind of work machines should do, and a model that flags an anomaly a tired analyst would miss at eleven at night is a control improvement, not a control weakness. The naive version of this argument, that AI in the close is inherently a risk, is wrong and should be resisted.

The precise issue is different. If a review step becomes a system generating output and a human clicking to accept it, the evidence produced is identical to the evidence produced by a human doing the review carefully. Same sign off, same timestamp, same name. The control's evidentiary output did not change when the control's substance changed. That is the observation worth making, and it is a governance observation rather than an accusation about anybody's diligence.

What is a sub-certification, and what is it worth?

Most large registrants run a sub-certification cascade. Business unit leaders, regional controllers and functional heads certify upward to the group, and the chief financial officer relies on that chain when she signs. It is sensible practice and nothing in this post suggests otherwise.

The question is what the artefact is. In a great many companies, a sub-certification is an email. Sometimes it is a form in a close management platform. Occasionally it is a signature block in a document management tool that recorded that an email address clicked a link.

We have written at length about why an approval delivered through a mailbox inherits the security and the meaning of the mailbox rather than of the person, in reply APPROVE is not an approval, and about what an electronic signature platform actually attests in your e-signature proves someone opened an email. The same analysis applies here, with the stakes raised, because this is the evidence chain underneath a criminal certification.

There is also a version drift problem that almost nobody checks. The officer certifies a report. The artefact she reviewed on Thursday evening and the artefact transmitted to EDGAR on Friday morning are, in the ordinary case, the same. But nothing in the process cryptographically establishes that. The link between the thing reviewed and the thing filed is a workflow assumption, and workflow assumptions are what fail during a late night correction to a footnote.

Link in the reliance chainWhat the officer relies onWhat currently evidences it
Transaction processingSystem controls and reconciliationsClose platform sign offs, exception reports
Estimates and judgmentsTechnical accounting reviewMemoranda, workpapers, review notes
Disclosure draftingReporting team and legal reviewDocument version history, comments
Sub-certificationsBusiness unit leaders' assertionsEmail, or a form submission
Disclosure committeeCommittee deliberationMinutes written by a secretary
Final package assemblyReporting and filing agentPlatform state; version identifier
Officer certificationThe officer's own reviewA name in a signature block

Read the right hand column downward. Almost every entry is an application state that the company wrote about itself. That is not fraud and it is not negligence, it is simply how enterprise software records things. It is also why the question of what changed when an agent joined the chain is hard to answer from the inside: the records look the same either way.

Where does the agent enter the chain?

The useful discipline here is to stop talking about AI in general and mark the specific boundary where machine output becomes human assertion.

Say a system drafts the liquidity paragraph of the management discussion and analysis from the cash flow data and prior period language. A member of the reporting team reads it, changes two sentences, and moves it into the package. The boundary is at that person. Everything upstream is preparation, which has always been delegable and has always included tools. Everything downstream inherits their assertion.

What is worth evidencing is not the tool's involvement, which is unremarkable, but the fact and the object of the human act at the boundary: this person, this version, this moment. Note the parallel with the deployment problem in software, where the artefact is well attested by machines and the human decision to release it is not, which we cover in who approved this deploy. Different domain, same missing record.

It is also the same failure this series calls approval theater when it appears in agent systems: a control that consists of a human clicking a button that the surrounding system fully controls. That post makes the argument in its sharpest form. The certification case is the highest legal stakes version and, oddly, the one with the least technical machinery behind it.

What would evidence of human review look like?

Here is the modest version, and modest is the correct register.

At the moment of certification, the officer's own enrolled device signs a payload that names the exact bytes being filed. Not a document reference, not a version label in a platform, but a hash of the submission itself.

{
  "type": "sox.302.certification",
  "registrant": "0000320193",
  "report": "10-Q",
  "period_end": "2026-06-30",
  "submission_sha256": "b7e1...49af",   // the exact filed bytes
  "package_version": "FIN-2026Q2-r14",
  "officer_role": "principal financial officer",
  "relied_on": [
    "subcert:bu-emea:rcpt_31d0a2",
    "subcert:bu-amer:rcpt_88f14c",
    "subcert:tax:rcpt_0c7b91"
  ],
  "signed_at": "2026-07-30T22:41:06Z"
}

Two things in that object are doing work.

submission_sha256 closes the version drift question permanently. If the filed bytes differ by one character from the bytes the officer signed over, the receipt does not verify and anyone can determine that without asking the company. That is a small assurance and an absolute one.

relied_on makes the reliance chain explicit and machine checkable. Each sub-certification becomes a receipt signed by that leader's device over their own scope statement, rather than an email in a folder. The officer's certification then references them, so the chain the auditor is asked to test exists as a set of verifiable artefacts instead of a set of assertions about a set of emails.

The signing step itself is the same primitive used anywhere else a human authorises a specific payload, which you can try at the signing demo, and the verification call is documented in the developer docs.

These verify offline against a published key, which matters more than it sounds. An auditor, a regulator, or a successor management team three years later can check them without the platform that produced them still existing and without asking the company to vouch for its own records. The general form of that argument, and its limits, is in audit trail design for AI agents.

Honest limits, and this one is the weakest wedge in the series

Now the part that matters most, because the temptation to oversell here is strong and giving in to it would be self defeating.

A signature does not make the review better. This is the whole of it. An officer who signs a hash of a document she skimmed has produced excellent evidence of having skimmed it. The quality of the inquiry is what actually protects investors, and no cryptographic artefact touches the quality of the inquiry. Anyone selling technology as a fix for certification quality is selling something, and you should ask them this exact question.

The gain is concentrated in the layers below. The officer's own signature is a marginal improvement over the current signature block. The genuinely useful change is turning sub-certifications and preparer or reviewer attestations from mailbox artefacts into signed receipts, because that is where the chain is longest, the volume is highest, and the current evidence is weakest.

It does not address the agent boundary by itself. Recording that a human signed at a boundary does not establish what they did at that boundary. If the answer to "what does reviewed mean when a model drafted it" is going to be satisfying, it will come from control design and from auditing standards, not from a signing scheme. What signing does is make the boundary visible and locatable, which is a precondition for the harder work rather than a substitute for it.

No auditor is asking for this today. Audit evidence standards are set through a professional and regulatory process, and a company adopting device bound certification receipts in this quarter is producing evidence nobody currently requires. That may change and there is a reasonable argument it will, but stating it as a present expectation would be false.

Threshold signing is not shipped. Both officers certifying a single receipt jointly would be the natural shape. Manav has not shipped threshold or M of N signing, so today this is two independent receipts over the same submission hash, which is functionally adequate and less elegant.

None of this is legal or accounting advice. Certification obligations belong to the registrant and its officers, informed by counsel and by their auditors. No vendor, including this one, can allocate or relieve that responsibility.

What to do this quarter

  1. Draw the map. List every step in the close and disclosure process and mark each one human, machine, or machine with human acceptance. Most finance functions have never done this and the third category is usually larger than expected.
  2. Ask what evidence changed. For each step in that third category, ask whether the evidence the auditor tests looks any different than it did two years ago. Where the answer is no, you have found a place where control substance and control evidence have separated.
  3. Look at your sub-certifications as artefacts. Not the policy, the actual artefacts. If they are emails, note that the evidentiary strength of your reliance chain is the evidentiary strength of a mailbox.
  4. Test version integrity once. Take last quarter's filing and try to establish, from records alone, that the bytes the officers reviewed are the bytes transmitted. If that takes more than an hour, it is not a control.
  5. Put it to the audit committee as a question. Not as a proposal. The useful move at this stage is to have the committee ask management what human review means in a close that includes AI assistance, and to have that question minuted.
  6. Ask your auditor what they would accept. They may not have a view yet. That answer is itself informative and worth recording.
  7. Resist buying anything yet. The mapping exercise costs a week and tells you whether you have a problem. Vendors, including us, benefit when that step gets skipped.

Frequently asked questions

Can a CEO or CFO certify financial statements that AI helped prepare? Yes. The certification has always rested on internal control over financial reporting rather than on personal recomputation, and using tools to prepare underlying material is not new. The live question is narrower: whether the human review steps the control framework assumes are still occurring in substance, and whether the evidence of those steps still means what it used to mean.

What exactly does a Section 302 certification assert? That the officer reviewed the report; that based on their knowledge it contains no untrue statement of material fact or material omission; that the financial information fairly presents the company's condition and results; that they are responsible for disclosure controls and internal control over financial reporting and have evaluated their effectiveness; and that they have disclosed significant deficiencies, material weaknesses and relevant fraud to the auditors and audit committee.

What is a sub-certification? A practice, not a statutory requirement, in which business unit and functional leaders certify upward to the certifying officers so that reliance is documented. It is sensible and widespread. Its weakness is that the artefact is frequently an email, which carries the security and the meaning of a mailbox rather than of the person the mailbox belongs to.

Does the SEC have a rule governing AI in financial reporting? The Commission's public attention to AI has focused largely on misleading claims companies make about their own AI capabilities rather than on the use of AI inside the reporting process, and we are not aware of a standalone rule specifically governing the latter. Check the Commission's current rulemaking index rather than relying on any secondary summary, including this one.

Would a cryptographic signature improve the quality of certification? No, and it is important to say so. It improves the evidence that a specific human signed specific bytes at a specific time, and it makes a reliance chain checkable. The quality of the underlying inquiry is a matter of control design, staffing and professional judgment, and no signing scheme touches it.

Are auditors asking for signed certification receipts? Not as a general expectation today. Audit evidence standards move through professional and regulatory channels. A registrant adopting this now would be producing evidence ahead of demand, which is a reasonable strategic choice for some companies and premature for most.

Where is the strongest case for this, if not the officer signature? The layers underneath. Sub-certifications, preparer and reviewer attestations on specific work products, and the boundary where machine generated material becomes a human assertion. That is where the chain is longest and the current evidence is thinnest.

Sources

  1. Sarbanes Oxley Act of 2002, legislative text and history: congress.gov
  2. 18 U.S.C. 1350, failure of corporate officers to certify financial reports: law.cornell.edu, 18 U.S.C. 1350
  3. SEC rules under the Securities Exchange Act, including Rules 13a-14 and 15d-14, in the Code of Federal Regulations: ecfr.gov, Title 17 Part 240
  4. Securities and Exchange Commission, rulemaking activity and enforcement actions: sec.gov
  5. Public Company Accounting Oversight Board, auditing and quality control standards: pcaobus.org, standards
  6. Committee of Sponsoring Organizations of the Treadway Commission, internal control framework: coso.org
The certification was always a device for stopping responsibility from dissolving. It is worth checking that the chain underneath it still contains the people it says it does.