As artificial intelligence (AI) becomes more common in finance, many controllers are asking the same question: How can we use AI effectively without creating control problems? 

    AI itself is not the issue; governance, oversight, and control design are. For controllers, the goal is not to avoid AI, but to use it in a way that supports efficiency without weakening accountability. As organizations explore these questions, the following Q and A offers practical guidance for finance leaders on how AI can fit within a controlled environment. 

    We’re starting to use AI in finance. What should we focus on first?

    We recommend starting with governance before scale. Your organization should have an AI usage policy, a clear approval process for use cases, defined ownership, and coordination between AI governance and data governance. A steering committee or similar review group is a strong sign that the organization is approaching AI thoughtfully. Organizations can also identify department champions who can evaluate opportunities, monitor adoption, and escalate risks as AI use expands.

    Our organization rolled out an AI tool to employees. Are there any audit considerations around this?

    Not necessarily; the key questions to ask are what can the tool access, how permissions are configured, and whether employees understand acceptable use. AI can make it easier to find, summarize, and connect information, which means weak access controls may become more visible in an AI-enabled environment. In many cases, the issue is not the tool itself, but whether the underlying data environment is properly secured. For example, if sensitive data such as salary information or Social Security numbers are buried somewhere in a folder structure, an AI tool may surface it far more quickly than a human would. That creates risk. More directly related to the audit, consider whether an employee could ask the tool to find and summarize draft financial information prior to issuance, potentially resulting in an inappropriate disclosure.

    What kinds of AI use cases in finance are generally considered lower-risk use cases?

    Lower-risk use cases typically involve AI supporting a person rather than making decisions for them. That may include drafting narratives, summarizing reports, organizing data, highlighting contract terms for review, or assisting with trend analysis. In these situations, the preparer remains responsible for the output, and the reviewer still performs a meaningful review. Used this way, AI can help improve efficiency without fundamentally changing the control structure.

    When does AI become a bigger concern from an audit perspective?

    The risk increases when AI begins to affect financial reporting or financial transactions with limited human oversight. Examples include automated journal entries, invoice processing, payment decisions, or support for accounting estimates where management relies heavily on the output. If AI is effectively deciding, posting, approving, or driving the result, the focus shifts quickly to whether controls are designed to prevent errors, detect anomalies, and help support management accountability.

    Is it acceptable if AI helps prepare invoices or journal entries?

    It can be, but the quality of the review control matters. If AI ingests invoices, suggests coding, or prepares support for a journal entry, someone with the appropriate knowledge should review the output before it is finalized. An understanding of the full workflow is critical: what the AI is doing, what the reviewer can see, whether data can be changed, and whether the review is substantive or just a sign-off. The more automation is involved, the more important it is that human review is real and well understood.

    Consider the following examples:

    Share.

    Comments are closed.