Take a looks at DIAB from diabsqlsoftware.com although it's primary purpose is SQL server monitoring and diagnostics it has SOX compliance tools builtin. It does this without adding any objects...
DIAB (DBAinABox) from diabsqlsoftware.com has built in SOX tools to alert you if permissions have been altered. it does this without using a trace or inserting any objects on the...