SEC Cyber Disclosure AI Controls Mapping
SEC cyber disclosure AI controls mapping should connect each Item 1.05 and Item 106 disclosure objective to an owner, control point, test, retained evidence, result, and open gap. This guide keeps legal materiality and disclosure decisions separate from the narrower incident evidence available for routed authenticated AI HTTP traffic.

A control map says SEC cyber disclosure: SIEM and colors the row green. The SIEM has detection events, but it cannot show who made the materiality decision or when the four-business-day clock started. It also cannot show which annual disclosure sentence the board record supports. Useful SEC cyber disclosure AI controls mapping needs eight fields and an explicit boundary. I prefer an honest partial result over a green cell that combines legal judgment and incident response with gateway telemetry.
TL;DR
- Map source objective and scoped risk, accountable owner and control point, test and evidence, then result and gap on every row.
- Keep Item 1.05 incident disclosure separate from Item 106 annual risk management and governance disclosure.
- Preserve discovery and materiality timestamps as distinct events, then do the same for filing and amendment times.
- Map AI HTTP decision records to incident and materiality support only. The SEC rules create no AI-specific gateway duty.
Build an eight-field control record
Each row should contain:
- Source objective: exact SEC form item or Regulation S-K provision and release number, with a short paraphrase.
- Scoped risk: a named failure for one registrant and entity, scoped to a system and route within a stated reporting period.
- Accountable owner: one role with authority to decide, plus supporting roles.
- Control point: the workflow or system where the control executes.
- Test: population and sample, input and expected result, plus the tester and frequency.
- Evidence: source records for design and operation, plus custody and retention.
- Result: one of pass, fail, partial, out of scope, with date and scope.
- Gap: what is not covered, such as an uncovered route or failed join. Add the interim measure, overdue action, owner, due date, retest.
Anchor the map in SEC Release Nos. 33-11216 and 34-97989. The release adopted Form 8-K Item 1.05 and Regulation S-K Item 106, then amended Forms 6-K and 20-F for foreign private issuers. The company supplies implementation controls against those disclosure requirements.
Reporting scope and responsibility mapping
Item 1.05 covers material cybersecurity incidents experienced by the registrant. Item 106 covers annual cyber-risk processes and material effects. It also covers board oversight and management's role and expertise. Securities counsel owns legal interpretation, while the disclosure committee owns the decision workflow under its charter.
Select a reporting entity and trace its incidents into the registrant's population. Verify Forms 6-K and 20-F treatment where applicable. Retain the entity inventory, the procedure and role matrix, along with the calendar and sample. Record missing subsidiaries and unclear foreign issuer treatment. Record unnamed decision authority as a gap. A platform can route facts but holds no authority.
Incident identification and aggregation mapping
Source objective and risk: the final rule defines a cybersecurity incident as an unauthorized occurrence, or a series of related unauthorized occurrences, on or conducted through information resources that jeopardizes the confidentiality or availability of those resources, or their integrity. The mapped risk is an incomplete incident population or missed series of related events.
The incident-response leader owns intake and investigation, with legal responsible for rule interpretation. Freeze the register with its query and filters. Record extraction time, row count, plus hash. Reconcile it against SOC alerts and provider notices. Then check legal and privacy matters, continuity records, plus API-management events. Select several low-severity AI-related events sharing a principal or destination, then verify a documented aggregation decision. Events sharing a data class or technique deserve the same check.
Boundary and gap: AI request denials may support detection and pattern analysis. A denial alone supplies no materiality conclusion. Mark direct provider calls and local models as separate coverage gaps. Opaque vendor activity and events with missing correlation IDs get their own rows. AI audit log chain of custody covers the evidence joins for routed requests.
Escalation and materiality mapping
Source objective and risk: Item 1.05 requires the registrant to determine materiality without unreasonable delay after discovery. The mapped risk is delayed escalation or incomplete fact gathering. Another risk is a materiality decision that overlooks qualitative effects.
The disclosure committee or authorized body owns materiality, with securities counsel guiding the standard. Select one incident determined immaterial and one determined material. Rebuild discovery and escalation timestamps. Do the same for fact updates, the decision, plus any reassessment. Review operational and financial effects alongside customer or vendor relationships. Cover reputation and competitiveness, then litigation and regulatory exposure.
The Division of Corporation Finance's May 21, 2024 staff statement says materiality analysis should consider qualitative and quantitative factors. It also clarifies that the statement has no legal force and creates no new obligations.
Boundary and gap: an AI HTTP control can supply event facts such as the application-supplied principal and destination, the data class and policy decision, plus the time. Business impact and investor significance stay with company owners, as does legal materiality. Put missing impact owners and stale estimates in the gap field.
Filing timing, content, and amendment mapping
Source objective and risk: a material incident generally requires an Item 1.05 Form 8-K within four business days after the registrant's materiality determination. The filing covers material aspects of nature and scope plus timing, along with material impact or reasonably likely material impact. The risk is a missed deadline or unsupported statement. Excessive technical detail and an absent amendment carry the same exposure.
Securities counsel owns drafting and legal sufficiency. The disclosure committee approves, and EDGAR authorization is the final control point. Begin with one accepted filing and trace its timestamp to the approved draft and deadline calculation, then to the materiality decision, the current fact packet, plus the incident row. Verify amendment tracking and retain prior drafts.
The SEC's public-company cybersecurity fact sheet summarizes Item 1.05's trigger and content. It also notes that disclosure detail may be limited when it would impede response or remediation.
Boundary and gap: gateway data can substantiate selected technical facts. It should never generate a filing narrative without legal and factual review. Missing business-impact support and conflicting clocks belong in separate gap entries. Unsupported endpoint scope belongs there as well.
Voluntary disclosure and delay mapping
Source objective and risk: voluntary disclosure of an incident pending materiality review, or determined immaterial, should remain distinguishable from a required Item 1.05 disclosure. National-security or public-safety delay requires the United States Attorney General's written determination and notice to the SEC. The mapped risk is using the wrong Form 8-K item or treating a delay request as approved.
Securities counsel owns filing classification, while the law-enforcement liaison manages a delay request. Use one voluntary filing under Form 8-K's other-events provision to verify that materiality review remained open where appropriate. For a later material determination, verify timely Item 1.05 filing. A delay sample should include the Attorney General determination and SEC notice, along with the approved period and filing record.
The SEC's Form 8-K compliance and disclosure interpretations state that a request by itself leaves the filing obligation unchanged. They also address the filing deadline when an approved delay expires or ends early.
Boundary and gap: route telemetry has no role in approving filing classification or government delay. Missing written authorization and ambiguous expiration time remain visible gaps. An Item 8.01 filing that closed materiality review remains a visible gap too.
Annual Item 106 process mapping
Source objective and risk: Regulation S-K Item 106 requires disclosure of the registrant's processes, if any, for assessing, identifying, and managing material risks from cybersecurity threats. It also addresses material effects or reasonably likely material effects. Board oversight and management's role and expertise belong there too. The risk is annual text unsupported by current operation.
The disclosure committee owns the filing process. The CISO and enterprise-risk function supply evidence, while the corporate secretary maintains board records. Map each disclosure sentence to an artifact and operating example. Trace one material cyber risk into enterprise reporting and one escalation into board material. Compare the text with process changes and provider dependencies, plus open findings.
Boundary and gap: AI-related cyber-risk evidence belongs in Item 106 support when relevant to the company's disclosure. The rule itself does not mandate an AI inventory or AI control plane. AI data lineage for audit can support a selected event's data and route facts without changing the legal scope.
Third-party dependency mapping
Source objective and risk: the rule's cyber-risk and incident concepts can include events involving third-party information resources used by the registrant. The mapped risk is late notice or incomplete facts. Mismatched service scope does the same damage, as does an external event missing from the incident population.
Third-party risk owns monitoring. Procurement and legal control contract terms, while incident response owns escalation. Select one AI service and match its contract to the endpoint. Send a simulated notice into company intake and time its arrival at the disclosure committee. Retain the contract and inventory, along with the exercise output and corrective action.
Boundary and gap: a provider assurance report describes its stated control scope. It cannot prove the registrant used only approved routes. Compare provider usage with internal egress records and preserve every mismatch.
Evidence integrity and assurance mapping
Source objective and risk: disclosure controls need reliable information and a repeatable review trail. The mapped risk is management-selected samples or mutable records. Failed retrieval and closure without retest count the same way.
Records management owns retention, and security engineering protects evidence. Internal audit owns independent assurance. Retrieve an old event and verify its integrity before joining it to incident and disclosure records. Let the reviewer select from the frozen population. Retain failures and original due dates, along with retests and closure approval. Tamper-evident audit logs for AI describes integrity tests. LLM audit log retention covers archive retrieval.
Boundary and gap: signed request evidence supports one defined event. Annual governance and legal judgment stay with other controls, as do business impact, route completeness, plus downstream action. A green result should name the tested applications and routes, the period and sample, plus the policy version.
DeepInspect
DeepInspect is a stateless proxy between authenticated users or agents and LLMs. It enforces identity-bound policy on HTTP AI traffic and produces per-decision audit records with the active policy version and timestamp.
Map DeepInspect to authenticated application-to-LLM HTTP routes that traverse it. Its records can support incident detection and reconciliation, along with chronology and selected-event reconstruction. Identity proofing and principal binding stay with the registrant's assigned owners. So do route completeness, materiality, filing approval, annual disclosure, third-party oversight, retention policy, along with independent audit. Local inference and direct browser sessions require separate rows. So do embedded vendor AI and bypass traffic. Book a demo today.
Frequently asked questions
- Can one control map to both Item 1.05 and Item 106?
A shared incident register may support both areas. Keep separate objectives and tests, plus separate owners and conclusions, because Item 1.05 addresses a material incident while Item 106 addresses annual risk management and governance disclosure.
- Does the SEC require an AI gateway?
The SEC cyber disclosure rules prescribe disclosures and related scope. An HTTP policy gateway is an implementation choice that can contribute facts for traffic within its route.
- What belongs in the result field?
Record the operating conclusion as pass, fail, partial, out of scope. Add the test date and systems, the routes and period, plus the sample and actual result.
Implementedis a design status rather than an operating conclusion.- What belongs in the gap field?
Name the missing entity or route, plus any missing record or failed test. Add the interim measure and owner, along with the target date and retest. Preserve original due dates after extensions.
- Can a signed AI request event close the materiality control?
It can support selected technical facts for covered traffic. The company's authorized body decides materiality using all relevant facts and circumstances, backed by legal and financial evidence, operational and customer detail, plus vendor and regulatory input.