[{"data":1,"prerenderedAt":484},["ShallowReactive",2],{"blog-\u002Fblog\u002Fai-agent-logs-are-not-an-audit-trail":3,"blog-related-\u002Fblog\u002Fai-agent-logs-are-not-an-audit-trail":462},{"id":4,"title":5,"audience":6,"body":11,"cluster":390,"conversionGoal":391,"cornerstone":392,"date":393,"description":394,"draft":392,"extension":395,"factCheckedAt":393,"faq":396,"featured":392,"language":391,"meta":409,"minRead":410,"navigation":411,"order":412,"originalAsset":391,"path":413,"pillar":414,"primaryKeyword":415,"publicationOrder":416,"relatedProject":391,"releaseScope":417,"reviewCycle":418,"reviewMethod":419,"reviewStatus":420,"reviewedAt":393,"reviewedBy":421,"searchIntent":422,"seo":423,"sources":424,"stem":455,"tags":456,"type":460,"updated":393,"__hash__":461},"blog\u002Fblog\u002Fai-agent-logs-are-not-an-audit-trail.md","Your AI Agent's Logs Are Not an Audit Trail",[7,8,9,10],"financial-controller","internal-audit","enterprise-architect","treasury-system-lead",{"type":12,"value":13,"toc":380},"minimark",[14,22,25,28,33,36,39,46,49,53,109,121,132,138,141,147,151,154,160,171,177,185,189,195,198,214,222,226,232,238,244,326,332,338,349,353,356,364],[15,16,17,21],"p",{},[18,19,20],"strong",{},"An AI agent's log is not an audit trail, because an auditor does not ask whether a record exists — they ask whether it can be relied on."," A log the agent writes about itself is the actor's own account of what the actor did. It is useful, often indispensable, and on its own it is testimony rather than evidence. The evidence is what the system of record wrote down when the agent touched it, and whether anyone can show that the list of things the agent did is complete.",[15,23,24],{},"The standard engineering answer to \"how do we audit our agents\" is to log everything: every prompt, every tool call, every output, into a store with a long retention setting, perhaps made immutable. That is a good answer to an operations question. It is an incomplete answer to an audit question, because it makes the log thorough without making it independent, provably complete, or retained for the right period.",[15,26,27],{},"What follows is how the evidence question looks from the other side of the desk: the SAP FI and treasury controls that sit under postings and payments.",[29,30,32],"h2",{"id":31},"what-an-auditor-actually-does-with-a-log","What an auditor actually does with a log",[15,34,35],{},"Start with the standards, because they are specific.",[15,37,38],{},"PCAOB AS 1105, paragraph .10, says that when the auditor uses information produced by the company as audit evidence, they must test the accuracy and completeness of that information, or test the controls over its accuracy and completeness — including, where applicable, IT general controls and automated application controls. ISA 500, paragraph 9, carries the same requirement for information produced by the entity. On reliability, AS 1105 .08 is blunt: evidence from a knowledgeable source independent of the company is more reliable than evidence from internal sources only, and internally produced information is more reliable when the controls over it are effective.",[15,40,41,42,45],{},"Now apply that to an agent. Suppose an auditor wants to test the journal entries an agent posted last quarter. They will select a sample, and the sample comes from a list. ",[18,43,44],{},"That list is information produced by the company",", and before any sampled item can say anything, the auditor has to be satisfied the list is complete and accurate. A clean sample drawn from an incomplete population tells you nothing about the items that were never on it.",[15,47,48],{},"So the first question an agent's log faces is not \"what does it contain\" but \"how do you know it contains everything\" — and that is a question most agent logs were not designed to answer.",[29,50,52],{"id":51},"three-ways-an-agent-log-falls-short","Three ways an agent log falls short",[54,55,56,72],"table",{},[57,58,59],"thead",{},[60,61,62,66,69],"tr",{},[63,64,65],"th",{},"Property",[63,67,68],{},"A typical agent log",[63,70,71],{},"What evidence needs",[73,74,75,87,98],"tbody",{},[60,76,77,81,84],{},[78,79,80],"td",{},"Independence",[78,82,83],{},"Written by the agent or its framework — the component whose actions it records",[78,85,86],{},"A record produced by something other than the actor, ideally the system of record",[60,88,89,92,95],{},[78,90,91],{},"Completeness",[78,93,94],{},"No sequence, no reconciliation; a dropped or sampled entry leaves no gap",[78,96,97],{},"A population you can prove is whole, against a count kept by someone else",[60,99,100,103,106],{},[78,101,102],{},"Retention",[78,104,105],{},"Whatever the platform was configured with, for operational or cost reasons",[78,107,108],{},"The period the governing obligation sets, whichever is longest",[15,110,111,114,115,120],{},[18,112,113],{},"Independence."," This is not about the agent lying. It is about correlated failure. The same fault that makes an agent act wrongly — a bad retry, a tool call that timed out after it had in fact succeeded, a framework bug — can also make its record of that action wrong or absent. A person's diary of their own work is not how a finance function evidences four-eyes, and an agent's diary is not different in kind. The same holds one hop further out: the log of ",[116,117,119],"a",{"href":118},"\u002Fblog\u002Fmcp-server-sap-authorization","an MCP server in front of SAP"," is the integration's account of what it asked for, not a record of what SAP did.",[15,122,123,126,127,131],{},[18,124,125],{},"Completeness."," Observability pipelines commonly sample, buffer and drop under load, because they were built to show trends, not to account for every event. That is the right design for ",[116,128,130],{"href":129},"\u002Fblog\u002Fproduction-ai-observability","production observability"," and the wrong one for evidence. A log with no sequence number cannot show that entry 4,812 is missing, because there is no entry 4,812 to miss.",[15,133,134,137],{},[18,135,136],{},"Retention."," A log's retention is a setting somebody chose — often the default, often tuned for cost. Accounting records answer to statute: in Germany, § 257 HGB keeps books and financial statements for ten years, and accounting vouchers for eight for most companies since January 2025 — banks, insurers and investment firms were returned to ten. Even the AI-specific rule defers to the longer regime. Article 26(6) of the EU AI Act requires deployers of high-risk systems to keep the logs under their control for at least six months, and says financial institutions keep them as part of the documentation their financial-services law already requires.",[15,139,140],{},"Two qualifications on that last point. Most finance agents are not high-risk systems under the Act, and since the AI Omnibus entered into force on 27 July 2026 the high-risk requirements for stand-alone systems apply from 2 December 2027. Article 26(6) is not your obligation today. It is a clear statement of the principle: the platform's retention is not the answer; the obligation is.",[142,143,144],"pull-quote",{},[15,145,146],{},"A log the agent writes about itself is testimony. The evidence is what the system of record wrote down when the agent touched it — and a count of those touches that the agent did not keep.",[29,148,150],{"id":149},"the-evidence-is-already-on-the-other-side","The evidence is already on the other side",[15,152,153],{},"In an SAP landscape, most of what an auditor wants is written by the system of record whether or not the agent logs anything.",[15,155,156,159],{},[18,157,158],{},"Change documents."," When a business object with a change document object is changed, SAP writes a header to CDHDR — object class, change document number, user, date, time, transaction code — and the field-level old and new values to CDPOS. That is a record produced by the system, under the identity that made the change, not a description volunteered by the caller. The catch worth checking: a field is only logged if its data element has the change document flag set. Before you rely on change documents for an agent, confirm that the fields it writes are actually among the logged ones.",[15,161,162,165,166,170],{},[18,163,164],{},"The posted document."," An FI document carries a number from a number range, a created-by user and an entry date. Number ranges give you a sequence the agent does not control, and SAP ships a report for gaps in document number assignment (RFBNUM00), because a missing number is something you will be asked to explain. ",[116,167,169],{"href":168},"\u002Fblog\u002Fai-agents-in-sap-what-actually-posts","What actually lands when an agent posts in SAP"," covers why the agent must post through the application rather than into the tables — a direct table write skips the change document and the number range both.",[15,172,173,176],{},[18,174,175],{},"Payment runs."," F110 keeps the proposal and payment data (REGUH, REGUP) and the job logs of each run. It is also a warning about retention: SAP's own reorganisation function for F110 deletes that payment run data and the associated job logs up to a chosen date, and deleted entries cannot be restored. \"The system of record keeps it\" is also a retention decision, and it has to be checked against the obligation too.",[15,178,179,180,184],{},"None of this helps if the agent posts under a shared technical user, because every one of those records will then name the interface. ",[116,181,183],{"href":182},"\u002Fblog\u002Fagent-identity-and-permissions","Agent identity"," comes first; the rest of the evidence depends on it.",[29,186,188],{"id":187},"reconcile-the-two-sides","Reconcile the two sides",[15,190,191,192],{},"Here is the design move that turns the agent's log from a liability into something useful: ",[18,193,194],{},"treat it as one side of a reconciliation, not as the evidence.",[15,196,197],{},"The agent's record says what it believes it did. The system of record says what happened. Match them on a key both sides carry — the document number the ERP assigned, stored against the agent's run ID; the run ID, stored on the document in a reference or text field. Then reconcile, on a schedule, in both directions:",[199,200,201,208],"ul",{},[202,203,204,207],"li",{},[18,205,206],{},"An agent action with no document"," is a failed post the agent believes succeeded, a duplicate suppressed by the ERP, or a write that went somewhere it should not have.",[202,209,210,213],{},[18,211,212],{},"A document under the agent's identity with no agent action"," is the more serious break: something used those credentials, or a path the agent does not log.",[15,215,216,217,221],{},"That is exactly the shape of a bank reconciliation, and it earns its keep the same way — the breaks are the findings. It is also what ",[116,218,220],{"href":219},"\u002Fblog\u002Finterface-monitoring-and-reconciliation","interface monitoring and reconciliation"," has always done for batch interfaces. An agent is an interface that makes decisions.",[29,223,225],{"id":224},"what-to-design-instead","What to design instead",[15,227,228,231],{},[18,229,230],{},"Agent identity on every action."," Its own user, scoped to the task, with the requesting human recorded alongside it, so created-by and changed-by mean something.",[15,233,234,237],{},[18,235,236],{},"An evidence store the agent cannot write to."," Append-only, written by the control layer rather than the agent, with no delete permission for any identity the agent holds. Tamper evidence comes from where the record lives and who can touch it, not from a promise in the logging library.",[15,239,240,243],{},[18,241,242],{},"The chain, linked to the document."," For each consequential action, one record keyed to the posted document:",[54,245,246,256],{},[57,247,248],{},[60,249,250,253],{},[63,251,252],{},"Field",[63,254,255],{},"Why an auditor wants it",[73,257,258,266,274,282,290,298,310,318],{},[60,259,260,263],{},[78,261,262],{},"Document \u002F change number",[78,264,265],{},"Ties the record to the system of record's own evidence",[60,267,268,271],{},[78,269,270],{},"Agent identity and run ID",[78,272,273],{},"Attribution, and a sequence in which a gap is visible",[60,275,276,279],{},[78,277,278],{},"Requesting human",[78,280,281],{},"On whose behalf the action ran",[60,283,284,287],{},[78,285,286],{},"Input reference",[78,288,289],{},"What the agent was looking at, retrievable later",[60,291,292,295],{},[78,293,294],{},"Output \u002F proposal",[78,296,297],{},"What it proposed, before any human edit",[60,299,300,303],{},[78,301,302],{},"Prompt and model version",[78,304,305,306],{},"Which configuration produced it — see ",[116,307,309],{"href":308},"\u002Fblog\u002Fprompt-and-model-versioning","prompt and model versioning",[60,311,312,315],{},[78,313,314],{},"Rule version and result",[78,316,317],{},"Which deterministic check passed it",[60,319,320,323],{},[78,321,322],{},"Approver and timestamp",[78,324,325],{},"The human release, taken from the system of record where possible",[15,327,328,331],{},[18,329,330],{},"A completeness control that runs."," Sequential run IDs, a daily two-way reconciliation to documents under the agent's identity, and a named owner for the breaks.",[15,333,334,337],{},[18,335,336],{},"Retention set from the obligation."," Map each record type to its governing requirement, take the longest, and test every deletion job against it — the agent platform's retention and the ERP's reorganisation runs alike.",[15,339,340,343,344,348],{},[18,341,342],{},"Re-performance where the decision matters."," Put the consequential decision in a deterministic check whose version is recorded, so it can be re-performed months later. ",[116,345,347],{"href":346},"\u002Fblog\u002Ffour-eyes-and-segregation-of-duties-for-ai-agents","Four-eyes for AI agents"," has the argument; the version field is how it survives an audit.",[29,350,352],{"id":351},"what-i-would-decide","What I would decide",[15,354,355],{},"Keep the agent's log, and stop calling it the audit trail. Make the system of record the evidence: the agent posts through the application, under its own identity, so change documents, number ranges and release records are written by something other than the agent. Give every action a sequential run ID and the document number it produced, and reconcile the two populations daily in both directions. Write the linking record to a store the agent cannot touch. And set retention from the obligation rather than the platform — then check that nothing, including the ERP's own housekeeping, deletes the evidence first.",[15,357,358,359,363],{},"None of this is AI-specific. It is what ",[116,360,362],{"href":361},"\u002Fblog\u002Faudit-trails-and-logging-treasury-systems","a treasury audit trail"," always had to be, applied to an actor that writes very fluent descriptions of its own work.",[15,365,366],{},[367,368,369,370,374,375,379],"em",{},"See also ",[116,371,373],{"href":372},"\u002Fblog\u002Fthe-enterprise-ai-control-layer","the enterprise AI control layer"," and ",[116,376,378],{"href":377},"\u002Fblog\u002Feu-ai-act-high-risk-requirements-finance-systems","the EU AI Act's high-risk requirements",".",{"title":381,"searchDepth":382,"depth":382,"links":383},"",2,[384,385,386,387,388,389],{"id":31,"depth":382,"text":32},{"id":51,"depth":382,"text":52},{"id":149,"depth":382,"text":150},{"id":187,"depth":382,"text":188},{"id":224,"depth":382,"text":225},{"id":351,"depth":382,"text":352},"security",null,false,"2026-09-25","A log the agent writes about itself is testimony, not evidence. What an auditor tests instead — completeness, independence, retention — and how to design it.","md",[397,400,403,406],{"question":398,"answer":399},"Is an AI agent's log an audit trail?","Not on its own. An audit trail is evidence that a control operated, and an auditor judges evidence by its source, its completeness and whether it survives for the required period. A log the agent or its framework writes about its own actions fails the first test by construction — it is the actor's account of itself — and usually cannot prove the second or meet the third. It becomes useful when it is one side of a reconciliation against records the system of record wrote independently, such as SAP change documents and the posted documents themselves.",{"question":401,"answer":402},"What do auditors need from an AI agent's activity records?","The same thing they need from any information produced by the company: evidence that it is accurate and complete, or evidence that the controls over it are effective. PCAOB AS 1105 and ISA 500 both require the auditor to address the accuracy and completeness of company-produced information before relying on it. For an agent that means a provably complete population of its actions, each tied to a posted document, an identity, the approval that authorised it, and the prompt and model version behind it.",{"question":404,"answer":405},"How long must AI agent logs be kept?","As long as the longest obligation that applies to the record, which is almost never the default retention of the agent platform. Accounting records carry statutory periods measured in years — in Germany, § 257 HGB sets ten years for books and financial statements and, for most companies, eight for accounting vouchers. For high-risk AI systems, Article 26(6) of the EU AI Act requires deployers to keep the logs under their control for at least six months, and financial institutions keep them within their existing financial-services documentation. Map each record to its requirement and let the longest win.",{"question":407,"answer":408},"How do you prove an AI agent's log is complete?","By reconciling it to a population the agent did not write. Every agent action should carry the document number the system of record assigned, and every document created or changed under the agent's identity should carry the agent's run ID. Reconcile the two sets on a schedule: an action with no document, or a document with no action, is a break to investigate. Add a sequence check on run IDs so a missing entry is detectable, and store the evidence somewhere the agent has no permission to write or delete.",{},9,true,2.92,"\u002Fblog\u002Fai-agent-logs-are-not-an-audit-trail","enterprise-ai-systems","ai agent audit trail",232,"PCAOB AS 1105 as currently effective; extant ISA 500 (the IAASB's revision project was still in progress when checked); EU AI Act Articles 12 and 26 as amended by the AI Omnibus (Regulation (EU) 2026\u002F1744, in force 27 July 2026); SAP change documents and F110 reorganisation as described in SAP Help. Checked 25 September 2026 against cross-checked excerpts of these sources; verify against the primary text for your jurisdiction and version.","semiannual","editorial-and-factual","reviewed","Tan Gravam","informational",{"title":5,"description":394},[425,428,431,434,437,440,443,446,449,452],{"title":426,"url":427,"accessed":393},"PCAOB AS 1105: Audit Evidence (paragraphs .08 and .10 — reliability; information produced by the company)","https:\u002F\u002Fpcaobus.org\u002Foversight\u002Fstandards\u002Fauditing-standards\u002Fdetails\u002FAS1105",{"title":429,"url":430,"accessed":393},"IAASB — ISA 500 series, Audit Evidence (extant ISA 500 paragraph 9 on information produced by the entity; revision project status)","https:\u002F\u002Fwww.iaasb.org\u002Fconsultations-projects\u002Fisa-500-series",{"title":432,"url":433,"accessed":393},"EU AI Act, Article 12: Record-keeping","https:\u002F\u002Fartificialintelligenceact.eu\u002Farticle\u002F12\u002F",{"title":435,"url":436,"accessed":393},"EU AI Act, Article 26: Obligations of deployers of high-risk AI systems (paragraph 6 — log retention)","https:\u002F\u002Fai-act-service-desk.ec.europa.eu\u002Fen\u002Fai-act\u002Farticle-26",{"title":438,"url":439,"accessed":393},"European Commission — AI Omnibus enters into force","https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fnews\u002Fai-omnibus-enters-force",{"title":441,"url":442,"accessed":393},"SAP Help — Change Documents: Concept (CDHDR, CDPOS)","https:\u002F\u002Fhelp.sap.com\u002Fdocs\u002FSAP_NETWEAVER_731_BW_ABAP\u002Fc14d25a8f471453590980dbb47a2aa0e\u002F48dfd498ab14280de10000000a42189c.html",{"title":444,"url":445,"accessed":393},"SAP Help — Set Change Document Flag","https:\u002F\u002Fhelp.sap.com\u002Fdoc\u002Fsaphelp_nw75\u002F7.5.5\u002Fen-US\u002F48\u002Fd1c163f6c96745e10000000a421937\u002Fcontent.htm",{"title":447,"url":448,"accessed":393},"SAP Help — Reorganization in F110","https:\u002F\u002Fhelp.sap.com\u002Fdocs\u002FSUPPORT_CONTENT\u002Ffiaccounting\u002F3361878327.html",{"title":450,"url":451,"accessed":393},"§ 257 HGB — Aufbewahrung von Unterlagen, Aufbewahrungsfristen","https:\u002F\u002Fwww.gesetze-im-internet.de\u002Fhgb\u002F__257.html",{"title":453,"url":454,"accessed":393},"EY — Längere Aufbewahrungsfristen bei Banken, Versicherungen und Wertpapierinstituten","https:\u002F\u002Fwww.ey.com\u002Fde_de\u002Ftechnical\u002Fsteuernachrichten\u002Flaengere-aufbewahrungsfristen-bei-banken-versicherungen-und-wertpapierinstituten","blog\u002Fai-agent-logs-are-not-an-audit-trail",[457,458,459],"enterprise-ai","ai-agents","controls","text","k7s91bO-G6atNnkgy9nt7DmW854nfulKGRB7PQoPGvg",{"related":463,"bridge":391,"next":475,"place":479},[464,468,472],{"path":465,"title":466,"description":467},"\u002Fblog\u002Fai-output-contracts-and-failure-handling","AI Output Contracts and Failure Handling","A model will return the wrong shape, or a confident lie. How to design output contracts, validation and fallbacks so an enterprise process fails safely.",{"path":469,"title":470,"description":471},"\u002Fblog\u002Fai-evaluation-and-regression-testing","Enterprise AI Evaluation & Regression Testing","How to build eval sets for AI running inside an enterprise — cases, scoring, a regression gate — so a prompt or model change is judged on evidence, not vibes.",{"path":129,"title":473,"description":474},"Production AI Observability in the Enterprise","You can't fix what you can't see. How to observe AI running inside an enterprise — quality, cost, latency, drift and failures — as data, not complaints.",{"path":476,"title":477,"description":478},"\u002Fblog\u002Fowasp-llm-top-10-2026-for-enterprise-finance","The OWASP LLM Top 10 (2026), Read From a Finance Seat","All ten 2026 entries with what changed from 2025 — and which of them a finance or treasury deployment actually meets first.",{"label":480,"position":481,"total":482,"hub":483},"Security",4,5,"\u002Ftopics\u002Fenterprise-ai-systems#cluster-security",1790367441561]