VELARU GALACTIC EXHIBIT PACK — SOX / CORPORATE FINANCIAL AUDIT Jurisdiction: Global / Multi-jurisdiction (global) Modality: Text / Chat Program: Velaru Mandate Registry — SOX / Corporate Financial Audit (galactic_sox) Product ID: sox:global:bundle:text Vertical: sox Generated: 2026-08-11T00:23:01.727114Z Authority: Global External Validation — SOX §404 AI Control Evidence Pack Deadline: PCAOB AS 2201 AI audit scrutiny Velaru verify: https://velaru.onrender.com/verify EXHIBIT A — AI INVENTORY [] EXHIBIT B — GOVERNANCE FRAMEWORK { "framework": "Velaru Mandate Registry \u2014 SOX / Corporate Financial Audit", "exhibit_authority": "Global External Validation \u2014 SOX \u00a7404 AI Control Evidence Pack", "regulatory_frameworks": [ "SOX Section 302", "SOX Section 404", "PCAOB AS 1215", "PCAOB AS 2201", "ISO 42001", "NIST AI RMF 1.0", "OECD AI Principles" ], "standards_alignment": [ "POSS-2", "DRP-1", "TCB", "FRE 707 pre-compliance", "ISO 42001" ], "human_oversight": "certify financial control", "third_party_verification": "https://velaru.onrender.com/verify (operator-independent)", "data_lineage": "Hash-chained Ed25519 receipts; optional RFC3161 + external anchor", "mirror_trap": "Company uses AI for financial close \u2014 CFO owns SOX attestation, AI vendor owns nothing. \u00b7 Multinationals built for one jurisdiction fail exams in another \u2014 one receipt architecture, many filing packs.", "chain_integrity": { "depth": 39, "invariant_holds": true } } EXHIBIT D — DATA INPUTS & VALIDATION { "data_validation_method": "Cryptographic receipt per AI decision; public verify without trusting deployer, vendor, or Velaru operator", "bias_testing_proxy": "Asymmetry score from live chain signals", "model_change_control": "Policy lock registry \u2014 criteria hash frozen pre-dispute", "logging_retention": "90-day pre-dispute window minimum; permanent verify permalinks", "external_validator": "Nisaba LLC / Velaru", "validator_independence": "Client-side Ed25519 verify; BYOK tri-receipt optional", "headline_stat": "PCAOB 2026 focus: AI in audit and ICFR \u2014 external auditors cannot rely on client AI logs alone", "global_leaders_addressed": [ "PCAOB", "Big Four", "SEC", "NYSE", "NASDAQ", "ISO", "NIST", "OECD" ] } MIRROR TRAP (regulatory insight) Company uses AI for financial close — CFO owns SOX attestation, AI vendor owns nothing. · Multinationals built for one jurisdiction fail exams in another — one receipt architecture, many filing packs. NERVE CARDS — WHY GLOBAL LEADERS CARE [ { "title": "ICFR AI", "body": "Material weakness from AI error in revenue recognition \u2014 receipt proves control operated.", "source": "vertical" }, { "title": "Auditor independence", "body": "Auditor using AI on same data \u2014 circular trust problem solved by independent verify.", "source": "vertical" }, { "title": "SEC comment letters", "body": "2026 AI disclosure requests \u2014 material AI risk requires governance evidence.", "source": "vertical" }, { "title": "[Global / Multi-jurisdiction] Jurisdiction shopping ends", "body": "Regulators share examination findings via IAIS, IOSCO, Basel \u2014 governance gap in one market triggers another.", "source": "jurisdiction" }, { "title": "[Global / Multi-jurisdiction] Vendor contract forum", "body": "AI vendor chooses Delaware law \u2014 deployer owns EU, UK, and US state fines simultaneously.", "source": "jurisdiction" }, { "title": "[Text / Chat] Modality hook", "body": "Baseline \u2014 all frameworks apply to text decisions.", "source": "modality" } ] BOOK SUMMARY: { "total_insureds": 0, "compliant": 0, "grace_period": 0, "non_compliant": 0, "expired": 0, "not_enrolled": 0, "compliant_pct": 0.0 } TAM / EXPOSURE: Every public company · SOX AI controls emerging requirement INSURANCE LINES: D&O, E&O, Fidelity DISCLAIMER: External validation evidence pack — not legal advice, not filed rate approval.