VELARU MANDATE EXHIBIT PACK — SOX / CORPORATE FINANCIAL AUDIT Jurisdiction: Ireland (ie) Modality: Text / Chat Program: Velaru SOX / Corporate Financial Audit · Ireland (galactic_sox_ie) Product ID: sox:ie:bundle:text Vertical: sox Generated: 2026-08-22T00:35:18.068303Z Authority: Ireland DPC AI Pack — SOX §404 AI Control Evidence Pack Deadline: PCAOB AS 2201 AI audit scrutiny Velaru verify: https://velaru-erra.onrender.com/verify EXHIBIT A — AI INVENTORY [] EXHIBIT B — GOVERNANCE FRAMEWORK { "framework": "Velaru Mandate Registry \u2014 SOX / Corporate Financial Audit", "exhibit_authority": "Ireland DPC AI Pack \u2014 SOX \u00a7404 AI Control Evidence Pack", "regulatory_frameworks": [ "SOX Section 302", "SOX Section 404", "PCAOB AS 1215", "PCAOB AS 2201", "EU AI Act", "GDPR (lead DPA for Meta/Google)", "CBI AI guidance" ], "standards_alignment": [ "POSS-2", "DRP-1", "TCB", "FRE 707 pre-compliance", "ISO 42001" ], "human_oversight": "certify financial control", "third_party_verification": "https://velaru-erra.onrender.com/verify (operator-independent)", "data_lineage": "Hash-chained Ed25519 receipts; optional RFC3161 + external anchor", "mirror_trap": "Company uses AI for financial close \u2014 CFO owns SOX attestation, AI vendor owns nothing. \u00b7 Ireland DPC leads EU enforcement against US tech \u2014 AI decisions in Ireland = DPC jurisdiction.", "chain_integrity": { "depth": 5, "invariant_holds": true } } EXHIBIT D — DATA INPUTS & VALIDATION { "data_validation_method": "Cryptographic receipt per AI decision; public verify without trusting deployer, vendor, or Velaru operator", "bias_testing_proxy": "Asymmetry score from live chain signals", "model_change_control": "Policy lock registry \u2014 criteria hash frozen pre-dispute", "logging_retention": "90-day pre-dispute window minimum; permanent verify permalinks", "external_validator": "Nisaba LLC / Velaru", "validator_independence": "Client-side Ed25519 verify; BYOK tri-receipt optional", "headline_stat": "PCAOB 2026 focus: AI in audit and ICFR \u2014 external auditors cannot rely on client AI logs alone", "global_leaders_addressed": [ "PCAOB", "Big Four", "SEC", "NYSE", "NASDAQ", "DPC", "Central Bank of Ireland", "Stripe EU" ] } MIRROR TRAP (regulatory insight) Company uses AI for financial close — CFO owns SOX attestation, AI vendor owns nothing. · Ireland DPC leads EU enforcement against US tech — AI decisions in Ireland = DPC jurisdiction. NERVE CARDS — WHY GLOBAL LEADERS CARE [ { "title": "ICFR AI", "body": "Material weakness from AI error in revenue recognition \u2014 receipt proves control operated.", "source": "vertical" }, { "title": "Auditor independence", "body": "Auditor using AI on same data \u2014 circular trust problem solved by independent verify.", "source": "vertical" }, { "title": "SEC comment letters", "body": "2026 AI disclosure requests \u2014 material AI risk requires governance evidence.", "source": "vertical" }, { "title": "[Ireland] Tech HQ density", "body": "Meta, Google, Apple EU HQ \u2014 AI governance tested in Irish courts first.", "source": "jurisdiction" }, { "title": "[Ireland] CBI insurance", "body": "Irish insurance undertakings \u2014 Solvency II + AI governance overlap.", "source": "jurisdiction" }, { "title": "[Text / Chat] Modality hook", "body": "Baseline \u2014 all frameworks apply to text decisions.", "source": "modality" } ] BOOK SUMMARY: { "total_insureds": 0, "compliant": 0, "grace_period": 0, "non_compliant": 0, "expired": 0, "not_enrolled": 0, "compliant_pct": 0.0 } TAM / EXPOSURE: Every public company · SOX AI controls emerging requirement INSURANCE LINES: D&O, E&O, Fidelity DISCLAIMER: External validation evidence pack — not legal advice, not filed rate approval.