Back to all articles
Governance

AI in the Finance Function: The Governance Questions Boards Should Be Asking Now

Finance teams are adopting AI tools faster than they are controlling them. Here is a proportionate governance response.

AI tools have entered finance functions through the side door. Someone drafts a commentary with a chatbot. Someone else builds a reconciliation helper. A vendor adds an assistant to the accounting platform and it appears one morning without a decision being taken.

None of this is inherently a problem. The problem is that the control environment was designed around processes people perform, and nobody has assessed what changes when part of the process is performed by a model.

Where AI touches financial reporting

Three uses matter for reporting integrity.

The first is preparation: drafting narrative, summarising variances, producing schedules. Risk here is accuracy and unsupported assertion in documents that reach the board.

The second is analysis and estimation: expected credit losses, accruals, forecasting inputs. Risk here is that a judgement affecting the numbers becomes untraceable.

The third is data handling: uploading ledger extracts, customer data or payroll files into tools the business has not assessed. Risk here is confidentiality and, under UK GDPR, lawful processing.

The control questions that matter

A proportionate response does not require an AI policy framework. It requires clear answers to a short list.

  • Which tools are in use in finance, and who approved them?
  • Does any output feed a number in the financial statements or the board pack?
  • Who reviews that output, and against what source?
  • What data leaves the business, and where does it go?
  • Can we reconstruct how a figure was derived six months later?

The last question is the one auditors will reach. Review evidence is meaningless if the input cannot be reproduced.

Human review has to be specified

Saying a human checks the output is not a control. Specify what the reviewer compares the output to, what constitutes an exception, and how the review is evidenced. A commentary generated from variance data should be checked against the variance data, by someone competent to challenge it, with the check recorded.

Where AI supports an estimate, the underlying method and inputs must still be documented as management's own judgement. The tool is not the audit trail.

Data protection is the immediate exposure

Uploading personal data, payroll records or customer information into a public tool without assessing the provider creates a UK GDPR issue independent of any accounting concern. This is the fastest-moving risk and the one most likely to surface without warning.

Decide which tools are approved, confirm what they do with submitted data, and tell the finance team plainly what may and may not be uploaded.

What to put in front of the board

A single page is usually enough: the tools in use, what they are used for, whether any output affects reported figures, the review controls in place, and the data categories involved. Update it quarterly.

That page does two things. It demonstrates that management has considered the risk, which is what auditors and investors want to see. It also surfaces uses nobody had approved, which is usually where the real exposure sits.

The wider point

Every previous shift in finance technology, from spreadsheets to cloud ERP, was absorbed into the control environment eventually, and always after a period where practice ran ahead of governance. The businesses that shorten that gap avoid the findings.