Artificial intelligence is finding a place in finance departments, but CFOs and Controllers face a more demanding question than whether the technology can save time. They must determine whether an AI-supported process can withstand the same scrutiny applied to any other process that influences financial reporting.

During the recent Controllers Council and Savant Labs webinar, How CFOs and Controllers Deploy AI That Survives an Audit, CFO Christine Gu joined Corey Merrill of BDO and Chitrang Shah of Savant Labs for a discussion about the practical use of AI in finance, the risks that accompany it, and the controls required when AI begins to influence consequential financial processes.

The discussion made one point particularly clear: AI may alter how finance work is performed, but it does not remove management’s responsibility for accuracy, controls, documentation, and financial reporting.

Where Finance Teams Are Actually Using AI

Many finance organizations remain cautious about allowing AI to participate directly in transactions or financial reporting. Instead, early adoption has concentrated on assistive work that can improve productivity while keeping final decisions with finance professionals.

Christine described several areas where her team has found practical value, including drafting memo outlines, summarizing documents and contracts, creating checklists, conducting research, preparing initial emails, and developing first-pass disclosures. She also distinguished these activities from higher-risk uses, such as allowing an AI model to post journal entries, reach accounting conclusions, or produce numbers that flow directly into financial statements.

Corey organized current finance use cases into three general tiers. The first includes drafting, summarization, research, and preliminary policy reviews. The second includes analysis that can influence human judgment, such as variance explanations, contract reviews, and initial technical accounting work. The third involves AI embedded within processes, including automated matching, anomaly identification, or other activities connected more closely with controls and financial reporting.

Audience polling reflected that progression. Forty-six percent of respondents reported informal or ad hoc AI use that was not touching transactions or key controls, while 23 percent were piloting AI within a key process alongside a legacy process. Another 11 percent reported AI embedded in key processes that drive financial reporting.

As Corey observed, informal adoption can create its own governance problem because leadership may not have complete visibility into where employees are already using AI.

“You can’t govern what you haven’t found yet.”

For finance leaders, developing an inventory of current AI use may therefore be one of the first practical steps toward a more structured governance program.

AI Changes the Risk, Not the Responsibility

Introducing AI does not make familiar financial reporting risks disappear. Completeness, accuracy, authorization, logical access, change management, and segregation of duties remain pertinent. What changes is the mechanism through which those risks can arise.

Christine explained that finance teams must consider whether an AI-generated answer is grounded in the correct information, whether the model may produce varying results, and whether employees can trace the result back to appropriate policies, source data, or accounting guidance.

She summarized the continuing responsibility of management clearly: “Management still owns the financial statement and the control conclusion.”

Corey similarly separated AI risk into two categories. The first involves familiar risks that change as AI becomes part of the process. The second includes newer concerns, particularly output variability and gaps in explainability. A model may produce a different response months later, even when a similar question is presented, and a user may receive an answer without understanding how the model reached it.

These characteristics become especially important when an AI-generated result influences a material judgment, financial statement assertion, disclosure, or control.

Why Repeatability Matters in Finance

A recurring topic throughout the webinar was the distinction between probabilistic AI and deterministic financial workflows.

Chitrang explained that general-purpose AI models can reach an answer through different paths. That characteristic may be acceptable for certain low-risk activities, but it creates complications when finance professionals must reproduce and substantiate reported results.

“When you are reporting financial results, you need to have a clarity on how you arrive to the answer, not just that you arrived to an answer.”

For a finance process to withstand scrutiny, the organization may need considerably more than a correct final result. It needs visibility into source information, processing steps, review points, exceptions, approvals, and the evidence supporting the final conclusion.

That distinction was evident in another audience poll. When attendees were asked whether they could reproduce an AI-assisted output from three months earlier, only 23 percent said they could do so with full supporting documentation. Twenty-four percent indicated that they could explain an output but could not reproduce it.

For organizations already using AI in reporting processes, a useful exercise is to select several prior AI-assisted outputs and determine whether the finance team can recreate them with the supporting documentation available at the time.

Human Review Must Be a Genuine Control

Keeping a person involved in an AI-enabled process is frequently presented as a safeguard, but human involvement alone does not establish an effective control.

Corey identified four considerations for evaluating whether human review functions as a meaningful control:

  • Competence: Is the reviewer qualified to evaluate the AI-generated output?
  • Information: Can the reviewer see the relevant inputs and understand something about how the output was produced?
  • Precision: Is the review designed to detect an error or misstatement large enough to matter?
  • Evidence: Is there documentation showing what was reviewed and what occurred when an issue was identified?

He also proposed a straightforward test: “How many times has the reviewer actually rejected the AI output?”

If the answer is never, finance leaders may need to examine whether the review is functioning as a control or simply serving as an approval step.

Questions to Ask Before Selecting an AI Vendor

Vendor evaluation becomes more consequential as AI moves closer to regulated workflows, financial reporting, or internal controls.

Corey suggested asking whether a vendor can reproduce an output from a prior period, how changes to underlying models are communicated, what AI-related changes may appear in SOC 1 reporting, what information is contained in the audit trail, how customer data is retained or used, and which portions of the application genuinely depend upon AI rather than conventional rules-based technology.

Christine recommended beginning with the architecture and accountability behind the application rather than concentrating solely on the product demonstration. Finance leaders should understand what AI is doing, which activities remain rules-based, which models are being used, whether those models can change, where company data travels, how access and segregation of duties are enforced, and what evidence can be produced for an audit.

Her advice for buyers was particularly practical: “Do not just buy for having an audit ready label.”

An organization should require the vendor to demonstrate the evidence that finance, internal audit, and external auditors will be able to inspect.

Using AI to Improve Audit Readiness

AI can also support the audit process itself when organizations use it within clearly defined boundaries.

Christine described using AI to help organize evidence, identify missing support, summarize populations, draft PBC lists and responses, compare policy language, and flag unusual items for investigation. Her team has also used AI to assist with process narratives and organizing evidence related to controls.

These applications can reduce administrative work and improve consistency, but the underlying conclusions still require human validation against authoritative guidance, transaction facts, established workflows, and available evidence.

Corey reinforced that AI does not alter the underlying standards by which financial reporting and controls are assessed. Financial statement assertions such as existence, completeness, valuation, rights and obligations, presentation, and disclosure remain the foundation. AI may influence how evidence is gathered or prepared, but organizations must still demonstrate that the applicable control addresses the risk of material misstatement and operated as intended.

Choosing the Right Finance Processes for AI

Finance leaders also need a sensible method for deciding where to begin.

Christine recommended evaluating whether a process addresses a meaningful operational problem, whether the associated risk is manageable, whether quality can be measured, and whether sufficient evidence is available. Repetitive and reviewable activities with dependable source data and reversible errors can provide more suitable starting points than highly judgmental, unusual, or material transactions.

Chitrang added that employee interest should also influence the decision. Teams are more likely to embrace automation when it removes repetitive work, they already find burdensome. Rather than automating an entire financial process at once, organizations can begin with a smaller component, such as data preparation for the month-end close, establish that the approach works, and then expand from there.

The Skills Finance Leaders Will Need

The growth of AI does not necessarily require CFOs and Controllers to become data scientists. It does, however, place greater emphasis on several traditional finance capabilities.

Corey highlighted the importance of knowing what a correct answer should look like before asking AI to produce one, along with the ability to evaluate work that the reviewer did not personally prepare. Christine pointed to process design, data literacy, control thinking, source evaluation, review parameters, and documentation of professional judgment.

These abilities become increasingly significant as AI handles more preliminary analysis and preparation. Finance professionals will need to understand enough about the process, data, controls, and expected result to recognize when an automated output deserves further investigation.

Building AI That Can Withstand Scrutiny

The opportunity for finance teams is considerable, particularly in repetitive processes where employees spend substantial time gathering information, preparing documentation, reconciling data, or completing preliminary analysis. The appropriate governance structure depends upon what the AI is doing and how closely its output connects to financial reporting.

As AI moves from experimentation toward established finance workflows, CFOs and Controllers will need to consider repeatability, data lineage, access, segregation of duties, human review, version control, documentation, and the ability to reproduce prior results.

Those requirements are familiar to finance leaders because they reflect principles that already govern dependable financial processes. AI introduces different technology and several additional risks, but accountability remains with management.

Want to hear the complete discussion and learn how finance leaders are approaching AI-enabled workflows, auditability, controls, and governance? Watch the full webinar here.

About the Sponsor

Savant Labs is an AI automation platform for finance and tax teams, designed to modernize manual, data-intensive workflows with greater speed, accuracy, and control. Learn more at www.SavantLabs.io.