Artificial intelligence is becoming part of everyday work in accounting departments. Employees may use it to research technical questions, prepare commentary, analyze information, draft communications, summarize documents, or assist with recurring financial tasks. As these uses expand, Controllers face a practical governance question: What rules should determine how AI is used within the accounting function?

Many organizations already have broader corporate policies concerning artificial intelligence, information security, or acceptable technology use. Those policies provide an important foundation, but accounting presents additional considerations. Financial information is sensitive, accounting decisions require professional judgment, and the work performed by the department may eventually become part of an audit trail.

For these reasons, Controllers should consider establishing clear expectations for AI-generated accounting work.

Informal AI Use Creates an Oversight Problem

One difficulty with AI adoption is that employees can begin using the technology before an organization formally implements it.

An accountant does not necessarily need an enterprise technology project to paste information into an AI application, ask for help with a spreadsheet formula, draft variance commentary, or research an accounting issue. These individual uses may appear minor, but collectively they can create substantial uncertainty.

Controllers may not know which applications employees are using, what information is being entered, how outputs are being verified, or whether AI-generated material is being retained as part of the department’s documentation.

A formal policy gives employees a common set of expectations. It also allows the finance organization to distinguish acceptable assistance from activities that require additional review or should remain prohibited.

Define What Information Can Be Entered Into AI Systems

Data handling should be among the first subjects addressed.

Accounting departments work with information that may include employee compensation, banking details, customer records, forecasts, acquisition information, tax data, vendor information, and other confidential material. Employees should understand which information can be used with approved AI applications and which information cannot leave controlled systems.

The policy should also identify approved applications rather than leaving individual employees to select tools independently.

This distinction becomes particularly important when consumer AI applications and enterprise AI platforms have different contractual provisions, security controls, data retention practices, and administrative capabilities.

Controllers do not need to become information security specialists, but they should participate in determining how financial information may be handled by these systems.

Establish Review Requirements Based on Risk

AI output should not receive the same degree of scrutiny in every situation.

Using AI to improve the wording of an internal meeting agenda presents considerably less financial risk than using it to prepare a journal entry, research a revenue recognition question, or generate an account reconciliation.

An accounting AI policy can establish review requirements according to the significance of the work.

Low-risk administrative uses may require little additional oversight. Work affecting financial reporting, accounting conclusions, regulatory filings, internal controls, or management decisions should receive appropriate human review.

The objective is to establish accountability before questions arise.

Preserve Responsibility for Accounting Decisions

AI may assist an employee in reaching a conclusion, but responsibility for that conclusion must remain identifiable.

If an AI system helps prepare a reconciliation, someone should still be responsible for reviewing it. If it assists with technical accounting research, a qualified professional should evaluate the relevant guidance and determine whether the conclusion applies to the organization’s circumstances.

This principle becomes more important as AI systems gain the ability to complete multiple steps within a workflow.

Controllers should be able to answer a basic question for any material accounting activity: Who is accountable for the final result?

The answer should be a person, not a software application.

Determine What Documentation Must Be Retained

Accounting departments routinely preserve evidence supporting calculations, approvals, reconciliations, journal entries, and financial reporting decisions. AI-assisted work raises a related question concerning what evidence should accompany the final output.

In some circumstances, retaining the final reviewed document may be sufficient. In others, the organization may need a record of source information, system activity, approvals, calculations, assumptions, or changes made during the process.

The appropriate standard will depend upon the activity and the organization’s control environment.

Controllers should address documentation requirements while AI processes are being designed rather than attempting to reconstruct them when auditors or management request supporting evidence later.

Include AI in Existing Internal Controls

Organizations do not necessarily need an entirely separate control structure for artificial intelligence.

In many cases, existing principles still apply. Access should be restricted appropriately. Duties should remain properly separated. Material transactions should receive approval. Changes to important systems should be controlled. Financial outputs should be reviewed.

The challenge is determining whether an AI-enabled process changes how those controls operate.

For example, if a task previously prepared by an accountant is prepared partly by an AI system, the review procedure may need to change. The reviewer may need additional information about source data, system actions, exceptions, or assumptions.

Controllers should therefore evaluate AI as part of the existing control environment rather than treating it solely as a productivity tool.

Revisit the Policy as Usage Changes

An AI policy written today will probably require revision.

The technology is changing quickly, but the more important reason for periodic review is that organizational use will change as well. A finance department that initially permits AI only for research and drafting may eventually use approved systems for reconciliations, reporting, forecasting, or transaction processing.

Policies should develop alongside those responsibilities.

Controllers can schedule periodic reviews with accounting, IT, information security, legal, internal audit, and other relevant functions to determine whether current guidance still reflects how employees are actually working.

Governance Should Grow With Adoption

Finance organizations do not need to prohibit AI simply because every question surrounding its use has not been resolved. They do, however, need standards that reflect the responsibilities associated with financial information and accounting work.

A practical policy can establish approved tools, acceptable uses, data restrictions, review requirements, documentation expectations, and individual accountability.

As AI becomes more capable, those fundamentals will become increasingly important. Controllers who establish them early will have a clearer basis for evaluating new applications without sacrificing the oversight expected of the accounting function.