Who signs off when a model prepared the number?

CFO Insights · AI & Technology · Internal Controls

Who signs off when a model prepared the number?

What a signature should mean, the guidance behind it, and a protocol for owner-led companies

By Gregg Carlson · Fractional CFO & Controller · Las Vegas, Nevada · October 2026 · 47 min read · Research current as of October 4, 2026

At a glance

  • The question has changed, and the answer still names a person. Lenders, boards, buyers, and auditors will ask what role a model played and what the person who signed actually verified. In the guidance and cases reviewed for this article, accountability stays with the organization and the individuals using the tool.1,2,3,4
  • COSO’s 2026 guidance applies existing internal control principles to generative AI. It keeps the five components and 17 principles of the 2013 framework, adds eight capability types and a six-step roadmap, and introduces the idea of AI reliance.5,6,7,8,9
  • Reliance, not use, sets the control burden. Tidying a draft is use. Depending on AI output as evidence that a control worked is reliance. This article offers a five-level reliance scale with minimum checks at each level.
  • Review fails in predictable ways. People over-trust fluent automated output, and small error rates compound across chained steps.10,11,12 In illustrative arithmetic, ten dependent steps that are each 95 percent reliable are all correct about 60 percent of the time.
  • A signature is a claim about evidence. Before signing AI-assisted work, three questions need a yes: every figure traced to a source, key calculations independently re-performed, and a named person who owns the judgment calls. A ten-step protocol puts that into practice.
  • Rules differ by region, and the direction is consistent. The UK FRC has issued guidance for auditors, the IAASB is developing non-authoritative guidance, the EU has delayed its high-risk dates, and U.S. bank regulators have placed generative and agentic AI outside their revised model-risk guidance.1,13,14,15,16
  • Owner-led companies can start small, and owners can test any provider. A one-page policy, an inventory of AI uses, a sign-off checklist, a vendor review, and a sampling routine fit in about 90 days. Eight questions separate a controlled use of AI from a marketing claim.

Introduction

Have you ever heard the phrase, “the model produced it, so it must be right”? The statement, while increasingly common, does not say who checked the work. This article is about AI internal controls in finance: what a signature should mean when a model helped prepare the number.

Every finance leader eventually hears some version of the same question from a lender, a board member, an auditor, or a buyer’s diligence team: who prepared this, and who checked it? For decades the answer named people, and the credibility of the number rested on the people and the process behind it. Generative AI adds a third answer: a model drafted part of it. Sometimes that is harmless, such as help polishing a paragraph. Sometimes it is not, such as a model that categorized a thousand transactions, wrote the variance commentary the board will read, or built the cash forecast a lender will rely on. The next question is the one this article is about. What did the person who signed actually verify?

Earlier in my career I helped write the national minimum internal control standards (MICS) for the U.S. tribal gaming industry. Years of evaluating and building systems and controls, in gaming and lodging, in a technology company, and in a local government, point to the same discipline. A process cannot be relied on unless it can be tested, and a signature means something only if there is evidence behind it. That discipline was built around cash rooms, count teams, and ledgers. It applies unchanged to a finance team that now has a very fast, very fluent, occasionally wrong assistant.

A signature is a claim about evidence. If a model prepared the number, the signature must still describe checks a person actually performed.

AI has been part of the daily work in this practice since 2022, and in my experience it has raised productivity substantially. That is a personal experience, not a measured result, and nothing here promises the same outcome to anyone else. Audit work teaches one lasting lesson: capability and control are different questions. The faster a tool produces output, the more it matters what stands between that output and a decision.

This article is written for owners, CFOs, controllers, board members, lenders, and advisers around the world. What I attempt to do here is explain what is different about generative AI, summarize what standard-setters, regulators, and courts have said about accountability, translate the COSO internal control framework into plain English for AI-assisted finance work, and offer a sign-off protocol, a reliance scale, and a 90-day plan that a small finance function can use. As one practitioner summary of COSO’s 2026 guidance puts it, “generative AI does not replace internal control.”9 The evidence comes from public guidance, court records, academic research, and news reports. The framework exhibits are the author’s own and are not measured data. For a practitioner’s view of how AI fits into day-to-day fractional CFO work, see Where AI Fits in a Fractional CFO Practice. I wrote this article with the assistance of AI; the “Important information” section at the end describes how it was prepared.

Generative AI changes the control problem, not the purpose of control

Most finance controls were built for systems that return the same answer from the same input. Generative AI does not, and its errors rarely look like errors. The purpose of internal control is unchanged.

Most finance controls were designed for deterministic systems. A ledger posts the entry you gave it. A spreadsheet formula returns the same answer from the same inputs every time. When something goes wrong, you can trace the logic. Generative AI behaves differently in ways that matter for control design.

Five properties that change the control problem

  • Probabilistic output. The same prompt can produce different answers on different days. Practitioner summaries of COSO's guidance describe generative AI as probabilistic and treat traceability and transparency as essential control elements.5,17
  • Fluent errors. Language models can generate text that reads confidently and is wrong, a failure commonly called hallucination. Researchers have documented it across tasks and models.18 The error rarely looks like an error.
  • Limited visibility into the logic. You usually cannot inspect why a model produced a particular number. You can only inspect the number and the evidence for it.
  • Change without a release note. A vendor can update a model, a default setting, or a retrieval source. A prompt that worked last quarter may behave differently this quarter. COSO-related commentary stresses prompt and configuration governance and change control for exactly this reason.8
  • The ability to act. Newer "agentic" tools do not just draft; they can move files, send messages, and post entries. The FRC has issued separate guidance on generative and agentic AI in audit because the risks differ from simple drafting.1
Exhibit 1
Generative AI differs from traditional software in ways that change how controls must work.
Traditional software or spreadsheet versus a generative AI tool
QuestionTraditional software or spreadsheetGenerative AI tool
Same input, same output?Yes, by designNot necessarily
What does an error look like?Often visible: a broken link, a mismatch, a failed checkOften invisible: a smooth paragraph or plausible figure
Can you inspect the logic?Usually yes, cell by cell or line by lineRarely; you inspect the output and its evidence
How does it change?Through versioned releases you controlPossibly through vendor updates you do not control
Primary test approachTest the logic once; monitor exceptionsTest the output every time it is relied on; monitor the tool and its configuration
Source: Gregg Carlson summary of general differences; specific tools vary

What did not change

COSO's own framing is worth quoting in spirit: generative AI changes how information is generated, processed, and acted upon, but it does not change the purpose of internal control, which is to help an organization achieve its objectives reliably.19 Management is still accountable for reliable reporting. Segregation of duties, review, reconciliation, and documentation still matter. The practical task is to apply old principles to a new kind of worker, one that never gets tired, never says "I'm not sure," and does not know what it does not know. Accounting reports what happened. Internal control is what earns the reader's trust in it.

The tool is fast. The tool is fluent. The tool is not accountable. Someone else is.

In the guidance and cases reviewed, accountability stays with people

None of the sources reviewed treats the model as responsible. The guidance, court decisions, and enforcement actions cited here all point to the organization and the individuals using the tool.

None of the sources reviewed for this article treats the model itself as responsible. The signals from standard-setters, regulators, and courts that are cited here point in the same direction: the organization and the people using the tool remain responsible for what comes out.

Exhibit 2
Guidance and enforcement on AI-assisted finance work arrived between 2023 and 2026, and the dates keep moving.
Selected signals by date and type
DateSignalType
Jan 2023NIST publishes the AI Risk Management Framework 1.0 (voluntary guidance)Guidance
Jun 2023A U.S. federal court sanctions lawyers for filing AI-fabricated case citationsCourt decision
Aug 2024EU Artificial Intelligence Act enters into forceLaw
Sep 2024FTC announces enforcement actions against deceptive AI claimsEnforcement
Jun 2025UK Financial Reporting Council issues its first guidance on AI in auditGuidance
Oct 2025A government report with apparent AI-generated citation errors leads to a partial fee refundIncident
Dec 2025IAASB decides to pursue non-authoritative guidance on AI for audit and assuranceGuidance
Feb 2026COSO publishes guidance on internal control over generative AIGuidance
Mar 2026FRC publishes guidance on generative and agentic AIGuidance
Apr 2026U.S. bank regulators replace SR 11-7 with SR 26-2; generative and agentic AI are outside its scopeGuidance
Jul 2026EU Digital Omnibus on AI enters into force, delaying the high-risk datesLaw (timing change)
Dec 2027EU high-risk obligations for stand-alone AI systems scheduled to applyScheduled
Aug 2028EU high-risk obligations for AI embedded in regulated products scheduled to applyScheduled
Source: NIST, EU institutions, FTC, FRC, IAASB, COSO, U.S. bank regulators, and press reports as cited in the endnotes.1,3,5,13,14,15,20,21,22 EU high-risk dates are as set in Regulation (EU) 2026/1744.

Auditors and assurance standard-setters

The UK Financial Reporting Council published its first guidance on AI in audit in June 2025, covering how to document tools that use AI, and followed in March 2026 with guidance on generative and agentic AI that discusses audit quality risks, possible mitigations, and the exercise of professional judgment in gaining appropriate confidence in tool outputs.1,23 With the March 2026 guidance the FRC stated that regulatory accountability for the deployment of AI tools and the quality of audit outputs remains unchanged, and that it is the firms and responsible individuals, not the tools, who are accountable for audit quality.2

At the international level, the IAASB decided in December 2025 to pursue non-authoritative guidance rather than new binding standards. It reasoned that guidance grounded in existing standards can be updated as technology changes and can address themes such as tool certification, monitoring, and professional skepticism.13 For a finance leader, the practical meaning is that the ISAs and other existing standards continue to govern, and your auditor is working out how to apply them to AI-enabled processes. Expect questions.

Frameworks that tell you how to organize the work

  • COSO (United States, widely used internationally). In February 2026 COSO released Achieving Effective Internal Control Over Generative AI, which adapts the five components of its 2013 framework to generative AI rather than inventing a new governance model.5,19 The chapter on COSO below walks through it.
  • NIST AI Risk Management Framework. Voluntary U.S. guidance organized around governing, mapping, measuring, and managing AI risk, with a companion profile for generative AI published in July 2024.20,24
  • ISO/IEC 42001:2023. An international management-system standard for organizations that develop or use AI.25
  • OECD AI Principles. Intergovernmental principles first adopted in 2019 and updated in 2024, which many national approaches reference.26

Law and enforcement

The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) entered into force in 2024 with a phased timetable. In 2026 the EU adopted the Digital Omnibus on AI (Regulation (EU) 2026/1744), which entered into force on 27 July 2026 and moves most high-risk obligations to 2 December 2027 for stand-alone systems and 2 August 2028 for AI embedded in regulated products, while leaving the Act's risk-based structure in place.14 Whether a given finance use falls into a regulated category depends on the Act’s definitions, how the tool is used, and your role in the supply chain. Companies that operate in or sell into the EU should consult counsel.

In the United States, enforcement so far has focused less on how companies use AI internally and more on what they claim about it. The FTC announced a crackdown on deceptive AI claims in September 2024, and the SEC charged two investment advisers in March 2024 over misleading statements about their use of AI.22,27 The lesson for any finance provider is to describe methods and controls accurately and to avoid promising results.

Courts and the press

Two decisions are widely cited for the principle that an organization answers for its tool. In 2023 a federal court in New York sanctioned lawyers who filed a brief containing case citations that an AI tool had fabricated.3 In 2024 a British Columbia tribunal held an airline responsible for inaccurate information its website chatbot gave a customer.4 Neither is a finance case, and each turned on its own facts and jurisdiction, but the reasoning is instructive.

Finance and advisory work has its own cautionary example. According to Associated Press reporting, the Australian practice of a global professional services firm agreed in 2025 to refund part of a A$440,000 fee after a report prepared for a government department was found to contain errors, including references that could not be verified and an inaccurate court quotation. The revised report disclosed that a generative AI tool had been used in its preparation, and the firm said the matter had been resolved directly with its client.21 The episode is cited because it shows how a reputational and financial cost can arrive even when the substantive conclusions are unchanged, not to criticize any firm. Public reporting does not establish the root cause of the errors, and nothing here is a statement about fault.

What this means for a finance leader

  • Do not expect "an AI did it" to move accountability anywhere.
  • Expect auditors, lenders, and counterparties to ask how AI is used and how outputs are checked.
  • Describe your methods accurately, and avoid unsubstantiated claims about speed, savings, or accuracy.
  • Keep evidence of review. In a dispute, a documented check is worth more than an assurance that checking occurred.

COSO’s framework already covers internal control over AI-assisted finance work

COSO’s 2026 guidance adds no new governance model. It applies the five components of its 2013 framework to generative AI and sorts use cases into eight capability types.

COSO's 2013 Internal Control framework is among the most widely used control frameworks for financial reporting, and many U.S. public company managements use it to assess internal control over financial reporting under the Sarbanes-Oxley Act.6,28 Its five components will be familiar to most auditors. The 2026 guidance leaves them intact and shows how each applies to generative AI.5,29

Exhibit 3
COSO’s five components apply to AI-assisted finance work without a new governance model.
The five components in plain English
COSO componentIn plain English for AI-assisted finance work
Control environmentWho is accountable for AI use? A written policy and an answerable owner.
Risk assessmentWhich uses touch reporting, cash, or confidential data?
Control activitiesTie-out, re-performance, access limits, and change control.
Information and communicationLog what AI did and what a person verified, and tell users the limits.
Monitoring activitiesSample outputs, review incidents, and retest when tools change.
Source: COSO (component names);6 Gregg Carlson (plain-English translations)

Control environment: who owns this?

The tone at the top shows up as a written AI use policy, a named owner, and board or owner visibility into material AI use. COSO's guidance emphasizes that the board should have visibility into generative AI use and its attendant risks.19 In a company of 30 people, this can be one page and one name.

Risk assessment: where does it touch the numbers?

Not every use deserves the same attention. Rank uses by what could go wrong: does the output reach financial statements, a lender, a tax filing, a customer, or confidential data? A tool that rephrases an internal email poses a different risk than one that classifies transactions.

Control activities: what stands between output and reliance?

These are the tie-out, re-performance, access limits, approval steps, and change control that sit between the tool and the decision. The sign-off protocol later in this article turns these into steps.

Information and communication: can someone reconstruct what happened?

If a number is questioned in six months, can you show what the tool was asked, what it produced, what a person changed, and what they verified? Equally important, do the people receiving AI-assisted work know its limits?

Monitoring: how will you know it is still working?

Sample outputs regularly, log incidents, and retest when a vendor changes a model or when your prompts change. Commentary on the COSO guidance highlights sampling of AI-generated outputs and internal audit testing as typical monitoring activities.9

Eight capability types, and where the risk concentrates

COSO organizes generative AI use cases into eight capability types, which it uses to tailor control considerations across the data-to-decision lifecycle.7 The table gives a plain-English reading of each name with a finance example. The descriptions and examples are the author's, not COSO's.

Exhibit 4
COSO sorts generative AI use into eight capability types, each with its own failure mode.
Capability types with finance examples; meanings, examples, and risks are the author’s
Capability typePlain-English meaningFinance exampleMain risk if wrong
IngestionPulling data and documents inReading invoices, bank files, contractsMissing or misread inputs
TransformationCleaning, classifying, summarizingCoding transactions; summarizing a leaseSilent distortion of the data
PostingWriting into systems of recordDrafting or posting journal entriesErrors become books and records
OrchestrationChaining steps or acting autonomouslyAn agent that gathers, calculates, and sendsErrors compound with no pause
JudgmentRecommending or decidingReserve, accrual, or risk-rating suggestionsUnexplainable or biased conclusions
MonitoringWatching for anomaliesScanning transactions for unusual itemsFalse comfort when nothing is flagged
Regulatory intelligenceTracking and interpreting rulesSummarizing a new reporting requirementOutdated or invented rules
Human-AI interactionHow people use and challenge outputReview and escalation of AI draftsOver-trust and rubber-stamping
Source: COSO (capability types);7 Gregg Carlson (meanings, examples, risks)
Exhibit 5
An unchecked error does the most damage where AI sits closest to the books or chains actions together.
Illustrative consequence rating by capability type, typical owner-led company
Bar chart rating the illustrative consequence of an unchecked generative AI error by COSO capability type; posting and orchestration rated highest.
Source: COSO (capability types);7 Gregg Carlson judgment (ratings); illustrative, not measured data

The pattern in the figure is intuitive. The closer an AI step sits to the books and records, and the more it chains actions without a pause, the less room there is for a human to catch a mistake before it matters. That is why posting and orchestration deserve the heaviest controls, and why autonomous agents deserve real caution around the ledgers of smaller companies.

COSO's implementation roadmap

As summarized by practitioners, COSO suggests a six-step path: establish an AI governance structure; inventory generative AI use cases; assess risk by COSO component; design and map controls; implement and communicate; then monitor and adapt.8,19 The 90-day plan later in this article compresses those steps into a plan sized for a small finance function.

Reliance, not use, sets the control burden

Using AI to tighten a paragraph is use. Relying on it to confirm that a control operated is reliance. The more a company relies on the output, the more evidence of review a signature requires.

One idea from the COSO commentary deserves more attention than it has received. It is AI reliance, the situation in which management depends on AI output as part of how a control operates or as evidence that a control operated.9 Once you rely on the output, the output is no longer a convenience. It becomes part of your control structure, and an auditor, lender, or regulator can ask you to demonstrate that it works.

A useful way to think about this is that use and reliance are different. Using AI to tighten a paragraph is use. Relying on AI to tell you that every vendor invoice was matched to a purchase order is reliance. The control burden follows reliance, not use.

Exhibit 6
The control burden rises with the level of reliance on AI output.
Five levels of reliance and the minimum controls at each
LevelWhat the AI is doingMinimum controls (author’s framework)
1 · AssistAI helps you think or format. Nothing it says is relied on.Approved tools only; no confidential data in unapproved tools.
2 · DraftAI produces a first draft that a person rewrites or rejects.Preparer review; sources checked for any fact that is kept.
3 · RecomputeAI output feeds a deliverable or a reported number.Tie-out to source plus independent re-performance; prompt and version log.
4 · Embedded controlAI output is evidence that a control operated (AI reliance).Named control owner, test of the control, change control, second-person review.
5 · Autonomous actionAI posts, pays, sends, or files without a person in the path.Reserve for mature settings with formal approval, limits, and ongoing monitoring.
Source: Gregg Carlson framework; not an industry standard and intended as a starting point

Examples at each level

Level 1: Assist

Brainstorming board-deck themes, restructuring an outline, or explaining a technical accounting concept for your own understanding. Nothing the tool says is relied on. Minimum control: use approved tools and keep confidential data out of unapproved ones.

Level 2: Draft

A first draft of variance commentary that the preparer rewrites, or a first-pass request list for a diligence process. Minimum control: the preparer checks every fact that survives into the final version against a source.

Level 3: Recompute

A tool produces a classification, a calculation, or a forecast roll-forward that feeds a deliverable. The output is an input to a reported number. Minimum control: tie-out to source, independent re-performance of key calculations, and a simple log of the prompt, the tool and version, and who reviewed.

Level 4: Embedded control

The AI output is the control, or the evidence for it: for example, an AI review that is relied on to confirm that expense reports comply with policy. Minimum control: a named control owner, periodic testing of the control with known test cases, change control over prompts and models, and a second-person review. This is where COSO's AI-reliance concept applies most directly.

Level 5: Autonomous action

The tool posts entries, releases payments, sends external communications, or files documents without a person in the path. Reserve this for mature environments with formal approval, authority limits, and ongoing monitoring. For most owner-led companies, this level should stay out of reach for now.

Ask one question of every AI-assisted step: if this output were wrong and nobody noticed, what would change?

A final caution is reliance creep. Uses often begin at Level 1 or 2 and drift upward as the output proves useful. A draft becomes a default, then an input, then an unreviewed step in a process. Inventory your uses on a regular schedule and re-rate them, because the control level that was fine in March may be inadequate by September.

Human review fails in predictable ways, and it can be redesigned

Human-in-the-loop review (“a human reviews everything”) is the most common safeguard and the weakest unless it is designed carefully. Automation bias, fluent errors, and compounding error rates explain why.

Review is not reading. Review is re-deriving.

"A human reviews everything" is the most common safeguard offered for AI-assisted work, and it is also the weakest unless it is designed carefully. Research on human-automation interaction has been warning about this for decades.

Four reasons review degrades

  • Automation bias. People tend to accept automated suggestions, and they miss errors that the automation does not flag. A well-known study of decision aids found that people made mistakes both by failing to notice problems the aid missed and by following incorrect advice.12 A later review concluded that complacency and automation bias affect experts as well as novices and are not reliably eliminated by training or instructions alone.11
  • The irony of automation. Lisanne Bainbridge observed in 1983 that automating most of a task leaves people with the hardest exceptions while weakening the practice that builds the skill to handle them, and that sustained monitoring of a mostly reliable system is something people do poorly.10 A controller who no longer builds reconciliations by hand may lose the instinct for what a wrong one looks like.
  • Fluency hides errors. A broken spreadsheet often announces itself. A well-written paragraph with a wrong cause in it does not.
  • A jagged frontier. A field study of consultants found that generative AI helped on some tasks and hurt on others of similar apparent difficulty, and that the boundary between them was hard for users to see.30 You cannot assume that because the tool did well last month on one task, it will do well on the next.

Small error rates compound

Workflows chain steps: classify, then summarize, then forecast, then narrate. If each step is individually reliable but not perfect, the chance that the whole chain is right shrinks faster than intuition suggests. The arithmetic is simple. At 95% reliability per step, ten dependent steps are all correct about 60% of the time. At 99% per step, it is about 90%. At 90% per step, about 35%.

Exhibit 7
Small error rates compound quickly across chained steps.
Probability that every step is correct, by number of dependent steps, %
Line chart showing that the chance every step in an AI-assisted workflow is correct falls as dependent steps increase, at 99, 95, and 90 percent per-step reliability.
Source: Gregg Carlson calculations (reliability raised to the number of steps, assuming independent steps); illustrative arithmetic, not measured data and not a claim about any particular tool

The point is not that any tool is 95% reliable. The point is that chained workflows, especially autonomous ones, need checkpoints between steps so that an early error does not travel quietly to the end.

Redesigning review so it works

  1. Change the instruction from "read it" to "re-derive it." Reviewing prose invites agreement. Rebuilding a number from source invites disagreement, which is the point.
  2. Calculate first, look second. For high-stakes figures, have the reviewer compute or estimate the answer before seeing the AI's version, so the AI's answer does not anchor the review.
  3. Use known-error tests. Periodically insert a deliberate, documented error into a draft and see whether reviewers catch it. Track the catch rate. If reviewers miss seeded errors, they are missing real ones.
  4. Separate preparer and approver. The person who asked the tool should not be the only person who checks it.
  5. Check sources, not sentences. Give reviewers a checklist that points at documents, ledgers, and bank records.
  6. Set stop rules. If a figure cannot be traced, it comes out. If a citation cannot be found, it comes out. No exceptions near a deadline.
  7. Watch reviewer workload. Review quality falls when volume rises. If AI doubles the drafts, the review budget has to grow too.

A ten-step protocol turns a signature into a claim about evidence

The protocol is small enough for a company without an internal audit department. Three questions gate every signature, and three hypothetical walk-throughs show them in use.

The protocol below is the author's own synthesis of the COSO structure, long experience in internal audit, and the failure modes above. It is not an industry standard, and it is intentionally small enough for a company without an internal audit department. Apply the full protocol at Level 3 and above; apply a lighter version at Level 2.

The controls that hold up, whether on a gaming floor, in a hotel audit, in a public-company close, or in a local government, share one trait. They can be tested. The protocol is built on that test.

The ten steps

  1. Rate the reliance level. Use Exhibit 6. If you are unsure between two levels, use the higher one.
  2. Use approved tools and approved data. The tool and the data classification must match your policy (see the chapter on data, confidentiality, and vendor terms).
  3. Record the request. Note the date, the person, the tool and version, and the instruction given. A shared log or a note in the workpaper is enough.
  4. Tie every figure to a source. Ledger, bank record, filing, contract, or dataset. Untraceable figures do not go in.
  5. Re-perform the key calculations independently. Do not ask the same tool to check itself. Use a separate method, such as a rebuilt spreadsheet or a manual computation.
  6. Test reasonableness and sensitivity. Compare to prior periods, budget, bank balances, and external data. Change the key assumptions and see whether the conclusion survives.
  7. Verify every citation, quotation, and rule. Open the standard, statute, case, or source and confirm that it exists and says what the draft claims. Fabricated citations have been among the most publicized AI failures in professional work, and this step targets them directly.
  8. Name the owner of each judgment. Estimates, valuation views, accruals, and risk calls need a named person and a short written rationale.
  9. Add a second reviewer at Level 3 and above. Rotate reviewers, and run known-error tests from time to time.
  10. Sign a statement of what was checked, and keep the evidence. The signature covers the checks, not the tool.
Exhibit 8
Three questions must all be answered yes before a signature.
Gate for signing AI-assisted work
Decision flow: three questions about source tie-out, re-performance, and ownership of judgment must all be answered yes before signing AI-assisted financial work.
Source: Gregg Carlson framework

Minimum controls by capability type

Exhibit 9
Each capability type needs its own minimum control and its own evidence.
Minimum controls by capability type
Capability typeMinimum control (author's suggestion)Evidence to keep
IngestionCompleteness checks between source and ingested data, such as record counts and control totalsReconciliation of totals
TransformationPerson re-classifies a sample; exception report reviewedSample results and exceptions
PostingAI drafts; a person approves and posts; approval limits applyJournal entry approval trail
OrchestrationCheckpoints between steps; least-privilege access; a stop switchRun logs and access list
JudgmentIndependent estimate or challenge session; written rationaleJudgment memo
MonitoringPeriodic tests using known seeded anomaliesTest log and results
Regulatory intelligenceVerify against the primary sourceCitation check record
Human-AI interactionReviewer checklist; training; track catch rate on known-error testsTraining and review records
Source: Gregg Carlson suggestions; minimums scale with the reliance level in Exhibit 6. Companies with auditors, lenders, or regulators should align final design with their requirements

What a sign-off statement can look like

Notice what the note does not say. It does not say "reviewed AI output." It says what the reviewer did. That distinction is the whole discipline.

A note on agentic tools

Tools that can act, such as moving files, sending messages, or posting entries, change the risk profile because errors can travel before anyone looks. The FRC treats generative and agentic AI in its own guidance for that reason.1 Working rules for any agentic tool in a finance setting can be modest:

  • Begin read-only. Let the tool gather and draft before it is allowed to change anything.
  • Grant the least access that works. No payment authority, no posting rights to the general ledger, and no ability to send external messages without a person pressing the button.
  • Test on copies. Use test data or a sandbox, with known answers, before anything touches live records.
  • Log every action, and keep a stop switch. If you cannot see what the tool did or cannot stop it quickly, it is not ready.
  • Treat it like a new hire on probation. It gets supervision, a narrow scope, and no signing authority.

Three hypothetical walk-throughs

The following are composites built to illustrate the protocol. They are not descriptions of any client, and the numbers are invented.

Walk-through A: Month-end variance commentary (Level 3)

A hypothetical distributor with about $25 million in annual revenue uses an approved AI tool to draft variance commentary from the trial balance and budget each month. The draft is fluent and tidy. It states that the gross margin decline was "driven primarily by higher inbound freight costs."

  • Tie-out: The preparer traces the freight accounts to the ledger. Freight is flat to budget.
  • Re-performance: A quick recomputation of margin by product line shows that a mix shift toward a lower-margin product explains most of the decline.
  • Judgment: The sales lead confirms that a large customer shifted orders late in the period. The controller owns the revised explanation.
  • Result: The commentary changes. The tool's explanation was plausible, which is exactly why it needed checking.

Under a "human reviewed it" standard, the original draft might have passed because it read well. Under the protocol, it failed at the first step, because the figure behind the claim did not trace.

Walk-through B: A 13-week cash forecast for a lender (Level 3)

A hypothetical manufacturer uses an AI tool to build a 13-week cash flow roll-forward from the accounts receivable aging, accounts payable aging, and payroll calendar for a monthly lender report.

  • Tie-out: The opening cash balance in the model differs from the bank statement by a small but unexplained amount.
  • Investigation: A customer payment appears in both the receivable aging as collected and the bank deposit file, so the tool counted it twice.
  • Sensitivity: Pushing collection timing out by two weeks shows the revolving line would be drawn close to its limit in week nine.
  • Judgment: The CFO decides how to present the tight week to the lender and what mitigating actions to describe.

The error was small, but a lender would have caught it in their own review. The forward-looking judgment, how to present a tight quarter, is not something the tool can own. This is the same division of labor that applies to every AI-assisted workflow: the tool drafts and accelerates; the people trace, recompute, judge, and sign.

Walk-through C: A technical accounting research memo (Level 2 becoming Level 3)

A hypothetical owner asks an AI tool to summarize how a recent accounting standard applies to a new customer contract, and the first draft cites a specific paragraph of the standard as support for a recognition conclusion.

  • Citation check: The preparer opens the standard and finds that the cited paragraph addresses a different topic. The conclusion may still be defensible, but the support offered for it does not exist.
  • Re-performance: The preparer works through the contract terms against the actual guidance and reaches a narrower conclusion.
  • Escalation: Because the conclusion affects reported revenue, the CFO takes it to the outside auditor as a technical accounting question before relying on it.
  • Result: The tool helped organize the issue. The conclusion came from the standard, the facts, and a person who owned it.

This is the same failure that made headlines in the legal and consulting examples in the chapter on accountability. The cure is dull and effective: open the source.

Spreadsheet errors and bank model-risk guidance supply the lessons

None of this is new in kind. Finance has long relied on error-prone computation, and the older guidance on model risk still translates to smaller companies.

None of this is new in kind. Finance has lived with unaudited, error-prone, high-stakes computation for decades. It is called the spreadsheet. Two lessons carry over directly.

Lesson one: errors are common, and experience does not remove them

Research on spreadsheet errors, summarized by Raymond Panko, has repeatedly found errors in a substantial share of operational spreadsheets examined, and found that experienced users make them too.31 The consequences can be large. When researchers re-examined a widely cited economics paper on public debt and growth, they reported a spreadsheet coding error alongside other methodological problems that changed the paper's headline results.32 Policy debates had leaned on that work. The point is not to single out any author. It is that important numbers often rest on calculations nobody independently rebuilt.

A language model is a spreadsheet that explains itself in confident prose. The explanation can make the error harder to see, not easier.

Lesson two: model risk management already has a vocabulary

In 2011 the Federal Reserve and the OCC issued supervisory guidance on model risk management for banks (SR 11-7), built around sound development, validation, governance, and "effective challenge" by informed, independent, and objective reviewers.15 In April 2026 the Federal Reserve, OCC, and FDIC replaced it with revised guidance (SR 26-2) that reaffirms core model risk principles but, according to published summaries, places generative and agentic AI outside its scope and leaves governance of those tools to broader risk-management practices.15 Banks are not the audience here, and the gap is instructive: the older principles still translate well to smaller companies, and the question of how to control generative AI is left to each organization.

Exhibit 10
Model-risk ideas from banking translate to owner-led companies.
Model risk idea and an owner-led company version for AI
Model risk ideaOwner-led company version for AI
Model inventoryA list of every AI use in finance, with owner and reliance level
ValidationTest cases with known answers before a use reaches Level 3 or above
Effective challengeA second reviewer who is competent, independent of the preparer, and free to say no
DocumentationThe evidence file behind each sign-off
Ongoing monitoringSampling of outputs and retesting after vendor or prompt changes
Source: Gregg Carlson translation, for illustration. The Federal Reserve and interagency guidance applies to banking organizations and is cited as an analogy only15

Data, confidentiality, and vendor terms set the outer boundary

Controls over output matter little if inputs leave the building in ways contracts do not allow. Classify the data, match it to the tool, and question every vendor.

Controls over output matter little if the inputs leave the building in ways your contracts do not allow. Three questions come first: what data goes into which tool, under what terms, and who can see it.

Classify data, then match it to tools

Exhibit 11
Four data classes can decide which AI tools are allowed.
Data classification and suggested tool rule
Data classExamplesSuggested tool rule (author's starting point)
PublicPublished filings, public market dataAny tool approved by the company
InternalDraft budgets, non-sensitive management reportsBusiness-grade tools with reviewed terms
ConfidentialClient financials, bank details, payroll, deal informationBusiness-grade tools with contractual data protections reviewed by management and, where needed, counsel; remove names and account numbers where practical
RestrictedPersonal identifiers, payment credentials, privileged legal material, material non-public informationNot entered into general AI tools without explicit approval from the owner, counsel, or security lead
Source: Gregg Carlson starting point; not legal advice

Questions to put to any AI vendor

  • Are inputs and outputs retained, for how long, and where are they stored?
  • Are inputs used to train or improve models, and can that be turned off contractually?
  • Who at the vendor, and which subprocessors, can access content?
  • How will we be told about model changes, incidents, and security events?
  • What independent assurance exists, such as a SOC 2 report or ISO/IEC 42001 certification, and what does its scope actually cover?25
  • Can data be deleted on request, and how is that verified?

Treat certifications and reports as evidence to evaluate, not as guarantees. Read the scope, the dates, and the exceptions.

Check your own obligations

Loan agreements, NDAs, customer contracts, and engagement letters often restrict how information may be shared or processed. Data protection and privacy laws may apply wherever personal data is involved, and those laws differ across jurisdictions. A policy that forbids personal accounts for company work is a sensible control against "shadow AI," where staff paste company data into tools nobody approved. The author is not a lawyer, and this section is not legal advice. Have counsel review your policy and your key contracts.

Owner-led companies can start AI internal controls with a 90-day plan

A short list of controls that match the size of the risk is enough to begin. A ten-person finance team can follow the COSO sequence in about a quarter.

None of the above requires an internal audit department. The aim is a short list of controls that match the size of the risk. COSO's roadmap starts with governance, an inventory, and risk assessment,19 and a company with a ten-person finance team can follow the same sequence in about a quarter.

Exhibit 12
A 90-day plan can move a small finance function from an inventory of AI uses to a first sample review.
Illustrative starting plan, weeks 0 to 13
Gantt-style chart of a 13-week starting plan for AI internal controls in a small finance function.
Source: Gregg Carlson; sequencing adapted to the COSO roadmap. Adjust to company size, systems, and the advice of counsel and auditors

The minimum viable AI control file

  1. A one-page policy. Approved tools, data classes, who may use AI for what, the reliance scale, and who to call with a problem.
  2. An inventory. Every AI use in finance, its owner, its reliance level, and its data class. Review it quarterly.
  3. A sign-off checklist. Built into the month-end close and reporting calendar so that it is not a separate project.
  4. A vendor file. The terms and answers to the questions listed in the chapter on data, confidentiality, and vendor terms for each tool.
  5. A sampling routine. Each quarter, pull a few AI-assisted deliverables and re-perform the checks. Include a known-error test.
  6. An incident log. Anything the tool got wrong, what caught it, and what changed afterward.

Then tell your auditor, lender, or board what you did. Companies that can describe their approach in two clear paragraphs are better positioned than companies that must improvise an answer when asked.

Five common objections, and the answers

  • "We are too small for this." Smaller companies have fewer people to catch mistakes, so each check matters more. The controls scale down to a page and a checklist.
  • "This will slow us down." Some steps do take time. The honest framing is that review effort shifts from producing a first draft to verifying one. Measure the net effect in your own business before claiming a saving to anyone.
  • "Our auditor has not asked." Standard-setters are working on the subject now,13 and the cost of building a control file before the questions arrive is small compared with improvising later.
  • "The vendor says the tool is accurate." A vendor's accuracy statement is not evidence about your data and your tasks. Test on your own cases with known answers.
  • "Just ban it." Bans tend to drive use out of sight, which is the shadow AI problem. A clear approved path with sensible limits is usually safer than a prohibition nobody follows.

Who does what

Exhibit 13
Even a small team needs named roles, and the second reviewer cannot be the preparer.
Roles and responsibilities
RoleResponsibilities in a small company
Owner or boardApproves the policy; receives a short annual or quarterly report on AI use, incidents, and sampling results
CFO or senior finance leadOwns the policy, the inventory, and the reliance ratings; owns judgment calls on estimates and outlook
Controller or preparerPerforms the checks, keeps the evidence file, logs incidents
Second reviewerChallenges Level 3 and above deliverables; participates in known-error tests
IT or security lead (or outsourced adviser)Reviews vendor terms, access, and data handling
Outside auditor or adviserConsulted early on what evidence is sufficient for AI-enabled controls
Source: Gregg Carlson framework; roles can be combined in a small team

Boards, lenders, and owners can test any provider with eight questions

Asking is ordinary diligence, not an accusation. The questions work for staff teams, outsourced firms, and fractional executives alike.

If you oversee a finance function, or rely on one, these questions work for any provider, whether a staff team, an outsourced accounting firm, or a fractional executive. Asking them is not an accusation. It is ordinary diligence.

Exhibit 14
Eight questions separate a controlled use of AI from a marketing claim.
Questions for any finance provider
QuestionWhat a good answer includes
Where is AI used in our finance work?A current inventory with owners and reliance levels
What does a person verify before anything reaches us?Specific checks: source tie-out, re-performance, citation checks
Who is accountable for the judgment calls?Named individuals, not "the team" or "the system"
How is our data protected?Approved tools, data classes, vendor terms, and what is never entered
How would we know if the tool got something wrong?Sampling, known-error tests, an incident log
What happens when a vendor changes a model?Change notification and retesting for Level 3 and above
Can we see the evidence file behind a recent deliverable?A real example, shown willingly
How do you substantiate any claims about speed or savings?Measured before-and-after data, or a candid statement that there is none
Source: Gregg Carlson framework

Lenders and acquirers can add a line to their diligence lists: request the target's AI use inventory and policy, and ask which reported figures relied on AI output at Level 3 or above. Sellers who prepare that answer in advance remove a source of friction.

Rules differ by region, and COSO-style controls travel

Binding rules, regulator guidance, and voluntary frameworks vary across markets. The vocabulary of governance, risk assessment, controls, communication, and monitoring is recognized in most of them.

Finance is global, and so are the questions. The table summarizes what exists in a few major areas as of October 2026, based on the sources cited. Status and dates change, and other jurisdictions have their own approaches that are not covered here. Confirm current requirements for the places where you operate.

Exhibit 15
Rules differ by region: binding in the EU, guidance elsewhere, and voluntary frameworks everywhere.
Selected sources as of October 4, 2026
AreaWhat existsNature
United StatesCOSO generative AI control guidance (Feb 2026); NIST AI RMF and generative AI profile; bank model-risk guidance revised Apr 2026 (SR 26-2) with generative and agentic AI outside its scope; FTC and SEC actions on AI claimsMostly voluntary frameworks, plus enforcement of existing laws against misleading claims5,15,20,22,27
European UnionAI Act (Regulation (EU) 2024/1689); Digital Omnibus on AI (Regulation (EU) 2026/1744) in force 27 July 2026, moving high-risk dates to Dec 2027 and Aug 2028Binding regulation with phased application14
United KingdomFRC guidance on AI in audit (Jun 2025) and on generative and agentic AI (Mar 2026)Regulator guidance1,23
International audit standard-settingIAASB pursuing non-authoritative guidance; sources reviewed indicate no binding AI-specific auditing standard from the IAASB or PCAOB as of mid-2026Existing standards continue to apply13,16
International frameworksISO/IEC 42001:2023 management-system standard; OECD AI Principles (2019, updated 2024)Voluntary25,26
Source: NIST, COSO, Federal Reserve, FTC, SEC, EU institutions, FRC, IAASB, ISO, and OECD, as cited in the endnotes. Status changes quickly, and other jurisdictions are not covered

A practical advantage of building around COSO-style controls is portability. The vocabulary of governance, risk assessment, control activities, communication, and monitoring is recognized by auditors and lenders in most markets, so the same control file serves a U.S. lender, a European investor, and a UK auditor with only modest adaptation.

Final thoughts

Controls over AI-assisted finance work fall into two camps: those that test the output and those that trust it. This article has argued for the first, using COSO's framework, a five-level reliance scale, and a ten-step sign-off protocol.

Intuitively it makes sense (with all other factors being equal) that a number backed by a traced source, an independent re-performance, and a named owner deserves more confidence than one backed by a read-through. It also makes sense that the more a company relies on AI output, the more evidence of review its signatures should carry.

Control design is by its nature a combination of art and science. The science is tie-out, re-performance, and documentation. The art is deciding how much reliance a given use deserves and where a person must stay in the path. My typical approach is the same in every industry: define what must be true, test it, and keep the evidence.

For owners, boards, and lenders, the practical test is short. Simply put, what did the person who signed actually check?

Frequently asked questions

What is internal control over generative AI?
It is the application of established internal control principles (a clear control environment, risk assessment, control activities, information and communication, and monitoring) to the use of generative AI. COSO published guidance in February 2026 that adapts its 2013 framework to generative AI.5
Does AI change who is responsible for financial numbers?
No. Regulators, courts, and professional bodies that have addressed the question point to continued accountability for the people and organizations using the tool.2,3,4 A reviewer's signature should reflect checks the reviewer actually performed.
What does AI reliance mean in financial reporting?
It describes depending on AI output as part of how a control operates, or as evidence that it operated.9 The more you rely on the output, the stronger the testing, documentation, and change control around it should be.
Do small companies need AI controls?
They need proportionate ones. A short written policy, an inventory of AI uses, a sign-off checklist, a review of vendor data terms, and periodic sampling are a reasonable starting point and do not require a large team.
Can I use AI tools on confidential financial data?
It depends on the tool's data terms, your contracts, and applicable privacy and confidentiality obligations. Review retention, training use, access, and deletion terms, and check what your lender, customer, and engagement agreements require. Consult counsel for your situation.
How do I verify AI-generated financial analysis?
Trace each figure to a source record, independently re-perform key calculations, test sensitivities, verify every citation, and have a named person own the judgment calls. Finding the output plausible is not verification.
Is there a binding standard for auditing AI?
Sources reviewed by the author indicate that the IAASB is developing non-authoritative guidance rather than new binding standards, and the UK FRC has issued guidance.13,23 Requirements differ by jurisdiction and change quickly, so confirm current status with your advisers.

Glossary

Agentic AI
AI systems that can plan and carry out multi-step tasks, such as moving files or sending messages, with limited human intervention.
AI reliance
Depending on AI output as part of how a control operates or as evidence that a control operated.
Automation bias
The tendency to accept automated suggestions and to overlook errors the automation does not flag.
Change control
A process for approving, testing, and documenting changes to a system, prompt, or configuration before they take effect.
COSO
The Committee of Sponsoring Organizations of the Treadway Commission, which publishes widely used frameworks for internal control and enterprise risk management.
Control activities
Actions, such as approvals, reconciliations, and access limits, that reduce the risk that objectives will not be met.
Data classification
A scheme that sorts information by sensitivity, such as public, internal, confidential, and restricted, so that handling rules can match.
Effective challenge
Critical review by someone competent, independent, and empowered to push back, a concept from model risk management.
Evidence file
The documentation behind a sign-off: sources, checks, reviewer names, dates, and conclusions.
Generative AI
AI that produces new content, such as text, numbers, or images, in response to instructions.
Hallucination
A confident-sounding AI output that is false or unsupported by any source.
Human in the loop
A process in which a person reviews and approves AI output before it is used. Its value depends on how the review is designed.
ICFR
Internal control over financial reporting: the processes that provide reasonable assurance about the reliability of financial statements.
IAASB
The International Auditing and Assurance Standards Board, which sets international auditing and assurance standards.
ISA
International Standards on Auditing, issued by the IAASB.
Jagged frontier
The uneven boundary of AI capability: tools may do well on some tasks and poorly on similar-looking ones.
Known-error test
A deliberate, documented error placed in a draft to measure whether reviewers catch it.
MICS
Minimum internal control standards, such as those applied in the gaming industry.
Model risk
The risk of loss or poor decisions from errors in the design, use, or interpretation of a model.
Prompt log
A record of the instructions given to an AI tool, with the date, person, and tool version.
Re-performance
Independently repeating a calculation or procedure to confirm that it produces the same result.
Reliance level
The degree to which a company depends on AI output, from simple assistance to autonomous action (see Exhibit 6).
Segregation of duties
Dividing responsibilities so that no single person controls all parts of a transaction or process.
Shadow AI
Use of AI tools by staff without company approval or oversight.
Tie-out
Tracing a reported figure back to the underlying record, such as a ledger entry, bank statement, or filing.

Endnotes

  1. Financial Reporting Council (UK), Generative and Agentic AI Guidance, March 30, 2026. frc.org.uk
  2. Financial Reporting Council (UK), "Innovative new guidance supports audit firm adoption of emerging AI technologies," March 30, 2026 (stating that regulatory accountability for the deployment of AI tools and the quality of audit outputs remains unchanged). frc.org.uk
  3. Mata v. Avianca, Inc., No. 1:22-cv-01461 (PKC), 678 F. Supp. 3d 443 (S.D.N.Y. June 22, 2023) (opinion and order on sanctions, ECF No. 54).
  4. Moffatt v. Air Canada, 2024 BCCRT 149 (Civil Resolution Tribunal of British Columbia, February 14, 2024). decisions.civilresolutionbc.ca
  5. Committee of Sponsoring Organizations of the Treadway Commission (COSO), Achieving Effective Internal Control Over Generative AI, February 2026. coso.org/generative-ai
  6. COSO, Internal Control — Integrated Framework, issued May 14, 2013 (updating the 1992 framework). coso.org/guidance-on-ic
  7. Journal of Accountancy, "COSO creates audit-ready guidance for governing generative AI," February 2026 (describes the eight capability types). journalofaccountancy.com
  8. Deloitte, "COSO Releases Publication on Internal Controls Related to Generative AI," Heads Up, April 3, 2026 (Deloitte Accounting Research Tool). dart.deloitte.com
  9. Doeren Mayhew, "COSO Releases Roadmap for Governing Generative AI," 2026 (discusses AI reliance and sampling of outputs). doeren.com
  10. Bainbridge, L., "Ironies of Automation," Automatica 19(6), 1983, pp. 775–779. doi:10.1016/0005-1098(83)90046-8
  11. Parasuraman, R., and Manzey, D. H., "Complacency and Bias in Human Use of Automation: An Attentional Integration," Human Factors 52(3), 2010, pp. 381–410. doi:10.1177/0018720810376055
  12. Skitka, L. J., Mosier, K. L., and Burdick, M., "Does automation bias decision-making?" International Journal of Human-Computer Studies 51(5), 1999, pp. 991–1006. doi:10.1006/ijhc.1999.0252
  13. Accounting Today, "IAASB to pursue non-authoritative guidance for AI," February 10, 2026 (reporting a decision made at the IAASB's December 2025 meeting); IAASB, "IAASB Publishes Global Roundtable Feedback on Technology and Quality Management," February 10, 2026. accountingtoday.com; iaasb.org
  14. Regulation (EU) 2024/1689 (Artificial Intelligence Act); Regulation (EU) 2026/1744 (Digital Omnibus on AI), published in the Official Journal on July 24, 2026 and in force July 27, 2026, as reported in White & Case, "EU AI Omnibus enters into force, amending the AI Act," 2026 (whitecase.com); Hogan Lovells, "EU legislators agree to delay for high-risk AI rules," May 2026, on the provisional agreement of May 7, 2026 (hoganlovells.com).
  15. Board of Governors of the Federal Reserve System, SR 11-7, "Guidance on Model Risk Management," April 4, 2011 (federalreserve.gov); superseded April 17, 2026 by SR 26-2, "Revised Guidance on Model Risk Management," issued with OCC Bulletin 2026-13 and an FDIC issuance. Summary of SR 26-2, including its treatment of generative and agentic AI as outside scope: Schneider Downs, "Banking Agencies Revise Model Risk Management Guidance," 2026 (schneiderdowns.com); Baker Tilly, "Updated Interagency Guidance on Model Risk Management (SR 26-2)," 2026 (bakertilly.com).
  16. RSM UAE (Haifa Balfaqih), "Is AI Already in Your Audit? The Standards Are Still Catching Up," August 24, 2026 (stating that, as of mid-2026, neither the IAASB nor the PCAOB had issued a binding AI-specific auditing standard). rsm.global
  17. Frazier & Deeter, "COSO Releases Guidance on Generative AI," 2026 (practitioner summary of COSO's guidance, including its description of generative AI as probabilistic and its emphasis on traceability and transparency). frazierdeeter.com
  18. Ji, Z., et al., "Survey of Hallucination in Natural Language Generation," ACM Computing Surveys 55(12), Article 248, December 2023. Open version: arxiv.org/abs/2202.03629
  19. Accounting Today, "COSO releases guidance on internal controls for AI," 2026. accountingtoday.com
  20. National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1, January 2023. doi.org/10.6028/NIST.AI.100-1
  21. Associated Press, "Deloitte to partially refund Australian government for report with apparent AI-generated errors," October 2025. ctvnews.ca (AP syndication)
  22. Federal Trade Commission, "FTC Announces Crackdown on Deceptive AI Claims and Schemes," press release, September 25, 2024. ftc.gov
  23. Financial Reporting Council (UK), "FRC publishes landmark guidance providing clarity to audit profession on the uses of AI," June 2025. frc.org.uk
  24. NIST, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1, July 2024. doi.org/10.6028/NIST.AI.600-1
  25. International Organization for Standardization and International Electrotechnical Commission, ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system, published December 2023. iso.org/standard/42001
  26. Organisation for Economic Co-operation and Development, Recommendation of the Council on Artificial Intelligence, OECD/LEGAL/0449, adopted May 22, 2019; revised November 2023 (definition of "AI system") and May 3, 2024. legalinstruments.oecd.org
  27. U.S. Securities and Exchange Commission, "SEC Charges Two Investment Advisers with Making False and Misleading Statements About Their Use of Artificial Intelligence," Press Release 2024-36, March 18, 2024. sec.gov
  28. Sarbanes-Oxley Act of 2002, Section 404 (15 U.S.C. § 7262); Public Company Accounting Oversight Board, AS 2201, An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements. pcaobus.org
  29. The Institute of Internal Auditors, Internal Auditor, "COSO Issues GenAI Guidance," March 11, 2026. internalauditor.theiia.org
  30. Dell'Acqua, F., et al., "Navigating the Jagged Technological Frontier: Field Experimental Evidence of the Effects of Artificial Intelligence on Knowledge Worker Productivity and Quality," Harvard Business School Working Paper 24-013, September 2023. doi.org/10.2139/ssrn.4573321
  31. Panko, R. R., "What We Know About Spreadsheet Errors," Journal of End User Computing 10(2), 1998, pp. 15–21; see also Panko, R. R., "Spreadsheet Errors: What We Know. What We Think We Can Do," 2008, open version at arxiv.org/abs/0802.3457.
  32. Herndon, T., Ash, M., and Pollin, R., "Does high public debt consistently stifle economic growth? A critique of Reinhart and Rogoff," Cambridge Journal of Economics 38(2), March 2014, pp. 257–279. doi:10.1093/cje/bet075

Important information

How this article was prepared. I wrote this article with the assistance of AI. I chose the topic, set the structure and arguments, and supplied the professional experience and views in it. An AI assistant (Claude, from Anthropic) helped me search for and summarize publicly available sources, draft and edit text, and build the exhibits. I directed that work, reviewed and edited the result, and am responsible for the final content. Source titles, dates, and key facts were checked against the cited or related public sources through web search as of October 4, 2026. Not every source was read in full, and I have not independently audited third-party material. AI tools can make mistakes, including misstating or mis-citing sources, so please check the endnotes before relying on any item. The reliance scale, the sign-off protocol, and the exhibits labeled illustrative are my own frameworks, developed with AI assistance. They are not industry standards or measured data.

General information only. This article is provided for general informational and educational purposes only. It is not accounting, audit, tax, legal, investment, or cybersecurity advice, it does not create an advisory, attest, or professional relationship, and nothing in it is an offer to sell or a recommendation to buy or sell any security. The analysis and opinions are my personal views, are subject to change, and I have no obligation to update them. Please treat this article as only a single factor in business, financial, and operational decisions, and consult qualified professionals about your specific situation.

Credentials and experience. I am not a registered investment adviser. My CPA license in Nevada is inactive. I do not hold myself out as an active CPA, and I do not provide attest services or other services reserved to licensed CPAs through this publication. Descriptions of my career are provided for background only, are summarized from my résumé with employer and client names omitted, disclose no confidential information, and imply no particular result for any reader. Statements about my own productivity reflect personal experience, not measured or promised outcomes.

Frameworks, examples, and third-party material. Descriptions of controls, protocols, scales, and walk-throughs reflect my own views and experience. They are not guarantees, may not suit every company, and are not a substitute for professional advice, auditor requirements, or legal obligations. Examples labeled hypothetical describe no client or engagement. Summaries of guidance, laws, cases, and news reports are my characterizations of public sources as of October 4, 2026, may be incomplete or out of date, and may have changed. Discussion of any incident is based on public reporting and is not a statement about fault or cause. References to organizations, publications, cases, and products are for identification and do not imply endorsement.

Liability and copyright. I do not accept liability for any direct or indirect losses arising from use of this article or its contents. Reasonable care was taken in preparing it, but it may contain errors or omissions.

Copyright © 2026 Gregg Carlson. All rights reserved.

CFO Insights · Gregg Carlson · Fractional CFO & Controller · Las Vegas, Nevada · gregg-carlson.com
Gregg Carlson

Gregg Carlson is a CPA (inactive) 25+ years of CFO and Controller experience across public companies, multi-state operators, and family offices. He has led $700M+ in M&A and capital raise transactions across gaming, cannabis, real estate, and technology. He provides fractional CFO and Controller services at gregg-carlson.com.

https://gregg-carlson.com
Next
Next

Where AI Fits in a Fractional CFO Practice