AI for CFOs · Independent decision intelligenceSource-backed reporting · No paid editorial rankings
CFO AI Ledger

An independent finance-leadership publication that examines where AI changes planning, close, cash, control, disclosure, and capital decisions—and what evidence a CFO must require before relying on it.

CFO briefings

COSO puts generative AI inside the control system

COSO's current internal-control record gives CFOs a direct answer: govern generative AI as a change to operations, reporting, information, and review—not as an isolated model-access decision.

Answer capsule

COSO's current internal-control record gives CFOs a direct answer: govern generative AI as a change to operations, reporting, information, and review—not as an isolated model-access decision.

What the source establishes

  • COSO's current internal-control page says the Internal Control—Integrated Framework was originally issued in 1992 and refreshed in 2013.
  • COSO says the framework was developed to improve confidence in all types of data and information, not only information used in external financial reporting.
  • The page says effective internal controls can support purpose, objectives, strategy, sustained growth, and confidence and integrity in information.
  • The current page lists a 2026 paper titled Achieving Effective Internal Control Over Generative AI; the listing does not by itself establish that a particular finance workflow has effective controls.

Control the information path, not just model access

A finance review should follow the complete path from approved source records to retrieval, instructions, generated output, human edits, financial systems, management reporting, and retained evidence. Identity and access controls matter, but they do not show whether the model used the right period, entity, account definition, policy, or planning assumption. Name the owner at each handoff and the control that prevents an unverified explanation from becoming an approved forecast, disclosure, journal proposal, or payment instruction.

The accountable team should translate this point into a named workflow, affected population, source data, human owner, approval right, exception path, retained evidence, and review date. That translation is what separates an interesting AI development from a decision that can be governed and evaluated.

Keep financial judgment outside generated output

A generated variance explanation or scenario narrative can help a reviewer navigate evidence. It cannot establish materiality, accounting treatment, forecast probability, control effectiveness, or transaction authority. Define which outputs are drafts, which require reconciliation, who can approve them, and where segregation of duties applies. The control conclusion should be tied to the actual finance process and configuration rather than a general statement that the organization follows a framework.

The accountable team should translate this point into a named workflow, affected population, source data, human owner, approval right, exception path, retained evidence, and review date. That translation is what separates an interesting AI development from a decision that can be governed and evaluated.

Make change and monitoring visible

Controls can weaken when a model, retrieval source, integration, prompt template, approval route, user population, or business process changes. Require an inventory of those dependencies, a named change owner, representative regression tests, exception monitoring, and a trigger for reopening the control assessment. Monitoring should distinguish usage from reliability: more generated output does not show that reviewers detected errors, resolved exceptions, or preserved a reconstructable decision record.

The accountable team should translate this point into a named workflow, affected population, source data, human owner, approval right, exception path, retained evidence, and review date. That translation is what separates an interesting AI development from a decision that can be governed and evaluated.

Write a CFO control conclusion

For each material use, record the financial objective, source systems, affected assertions or decisions, model and vendor dependencies, preventive and detective controls, reviewers, evidence retained, unresolved limitations, and next reassessment date. Label which facts come from COSO, which are internal design choices, and which were observed in testing. That record lets finance support a bounded use while refusing the broader claim that a policy, framework reference, or product feature proves operating effectiveness.

The accountable team should translate this point into a named workflow, affected population, source data, human owner, approval right, exception path, retained evidence, and review date. That translation is what separates an interesting AI development from a decision that can be governed and evaluated.

Decision test

Ask whether the source changes the decision itself, the evidence required, the implementation sequence, or only the language used to describe an existing capability. Record which claims are directly supported, which are provider statements, which require an independent test, and which remain unknown. A source-linked review should make uncertainty easier to see, not bury it inside a blended score.

Questions to take into review

  • Is the AI itself in scope for change and access controls?
  • Can evidence provenance survive export and retention?
  • Which source supports each number and assertion?
  • How is materiality assessed outside the model?
  • Which planning model and dimensions ground the answer?
  • Can every assumption be traced to an owner and date?
The publication supports research and executive decision preparation. It does not provide legal, financial, accounting, employment, clinical, cybersecurity, investment, procurement, or implementation advice.