Every company that clears a main board listing inherits the same problem on day one: financial reporting obligations that scale far faster than the teams built to handle them. Quarterly certifications. Documented internal controls. An audit trail that has to hold up under real scrutiny.
Most growth companies assume more headcount solves this. The data says otherwise.
The Automation Gap Nobody Budgeted For
KPMG’s 2025 SOX Survey found the average program cost jumped to $2.3 million in FY24, up from $1.6 million in FY22, with hours rising 32% to 15,580. That’s not a modest increase. It’s a structural shift in what compliance costs once a company sits under SEC reporting obligations.
Here’s the part that should worry finance leaders more: automation didn’t keep pace with scope.
| Metric | FY22 | FY24 |
|---|---|---|
| Average program cost | $1.6M | $2.3M |
| Average hours | 11,800 | 15,580 |
| In-scope systems | 17 | 40 |
| Automated controls | 21% | 17% |
The average number of in-scope systems more than doubled from FY22 to FY24, yet automated controls actually declined from 21% to 17% over the same period. Companies added complexity faster than they added the tooling to manage it. That’s the trust paradox sitting underneath most listing preparation right now: teams assume growth funds better systems, when in practice growth usually outruns them.
For a company mid-way through an sme to main board migration, this is the exact gap that shows up during a readiness assessment — internal controls that were adequate for a smaller exchange but were never built to withstand continuous testing across dozens of systems.
What Scaling Actually Costs, Control by Control
Break the budget down to the control level and the math gets sharper. KPMG’s earlier survey data put the average cost of compliance at roughly $3,200 per control, with around 12 hours of testing per control for operating effectiveness. Multiply that against a control count that’s grown 18% in two years, and the source of the cost spike stops being abstract. It’s arithmetic, not inflation.
Where AI Actually Fits
This is where AI stops being a buzzword and starts being infrastructure. Continuous control monitoring tools now ingest transaction data directly from ERP systems — NetSuite, SAP, Oracle Fusion — and test control exceptions against every transaction as it posts, not a sampled slice reviewed once a quarter.
Traditional SOX testing has always relied on sampling, typically reviewing 10–15% of transactions and controls. That means a meaningful share of control failures never surface until something large enough breaks through. AI-driven monitoring flips that: instead of quarterly spot checks, systems flag deficiencies within hours of occurring.
The compliance technology market is scaling to match the demand. The RegTech segment tied specifically to AI is forecast to reach $3.3 billion by 2026, growing at a compound annual rate of 36.1% since 2021. That growth isn’t speculative venture activity — it’s finance and audit teams buying tools because manual processes stopped scaling.
The Board’s New Job: Evaluating the Tooling, Not Just the Controls
Audit committees have historically reviewed control design — who signs off on what, and how often it’s tested. AI-driven monitoring adds a layer most boards haven’t had to evaluate before: whether the model doing continuous testing is itself reliable, auditable, and free of blind spots.
That’s a governance question as much as a technical one. A board assembled purely to satisfy independence requirements for a listing may not have the financial-systems literacy to ask the right questions about a monitoring platform’s false-negative rate. Companies rebuilding their board ahead of a main board transition should treat this as part of the director search brief, not an afterthought handled by IT after the listing closes.
A Regulatory Deadline That Changes the Calculus
The timing here isn’t neutral. Amended PCAOB standards — AS 2201 and AS 2101 — become effective on December 15, 2026, formalizing a more top-down, risk-based approach to control scoping centered on entity-level controls. Companies timing a listing application around that window need their monitoring infrastructure decided well before the new standards apply, not scrambled together after their first audit under them.
What This Means for CFOs, in Sequence
The practical path isn’t “buy an AI compliance tool.” It’s sequencing the decision correctly:
- Run the readiness assessment first and map exactly which in-scope systems lack automated testing today.
- Prioritize continuous monitoring for the highest-volume, highest-risk systems — usually revenue recognition and access controls — before expanding coverage broadly.
- Build the audit trail the platform generates into board reporting, so directors see control exceptions in near real time rather than at quarterly review.
- Validate the tool against PCAOB’s updated evidentiary standards before locking in a vendor, since the rules governing tech-aided audit evidence shifted in 2024 and again with the 2026 amendments.
None of this replaces human judgment. Auditors still interpret findings, assess materiality, and sign certifications. What AI changes is the volume of evidence a compliance function can actually review before something reaches an executive’s desk for CEO and CFO sign-off.
That distinction matters under frameworks the U.S. Securities and Exchange Commission maintains specifically to ensure investors get consistent, accurate, timely information — the same standard any company completing a main board transition has to meet on an ongoing basis, not just at the point of listing.
Companies satisfied with their SOX technology have also been dropping. Survey respondents reporting satisfaction with their compliance tooling fell from 92% in FY22 to 58% in FY24 — a signal that legacy systems are straining under exactly the kind of scope expansion a main board listing triggers.
The Practical Takeaway
Growth companies preparing for a listing tend to budget for legal fees, audit firm transitions, and board restructuring. Fewer budget for the compliance technology stack that has to run continuously once quarterly reporting becomes mandatory.
The gap between in-scope systems doubling and automated controls staying flat isn’t a one-year anomaly. It’s a pattern building at exactly the moment more companies are stepping into main board obligations for the first time. Building the monitoring infrastructure before that transition, not during it, is what separates a smooth first year of public reporting from a scramble.
Related: Enterprise AI Implementation: Why Only 6% Turn AI Into Business Value
