Skip to content
How Should CFOs Manage AI Risk in Their Finance Function
Jason DaviesSep 4, 2026, 1:56:01 PM7 min read

How Should CFOs Manage AI Risk in Their Finance Function?

Finance teams are already finding practical uses for AI, often for work that already existed. Reporting commentary, variance analysis, forecasting, reconciliations and management information are all areas where teams may be testing tools or using AI features built into existing platforms.

However, small uses can still carry real risks; outputs and assumptions still need to be accurate and evidenced, and sensitive financial or commercial data still needs to be protected by approved systems.

While enabling teams to use AI where appropriate, CFOs still need to understand where it is being used, what data is involved and how outputs are being reviewed. AI risk should ultimately sit inside the finance function’s risk management process: where the use case is material, it should appear on the finance risk register, with controls that reflect how the tool is being used. It should also be reviewed through annual risk assessment processes, particularly when used in reporting, forecasting, analysis, control or decision support.

A practical approach can be built around three lenses: governance, compliance, and capability:

  • Governance covers ownership, approval, validation and data use

  • Compliance covers regulatory expectations, including the EU AI Act and the FCA’s approach to algorithmic decision-making
  • Capability covers whether finance teams have enough AI literacy to apply professional scepticism to the outputs

Handled well, AI can improve the speed and consistency of finance functions, yet handled poorly, it may enable weak controls in processes that boards, auditors and regulators expect to be reliable.

Governance depends on knowing who owns what

Many finance leaders may have approved AI use somewhere in the function, but the risk sits in the informal use, whether that is colleagues using public AI tools to summarise commentary, reshape data, draft reports, or to check outputs without a clear approval route.

To limit the risk, the finance function needs clear rules, and teams should know which tools are approved, what data cannot be entered, which outputs require review, and which use cases need formal approval.

Ownership also needs to be specific. If AI supports a reporting process, the owner of the process should be accountable for the quality of the output. Similarly, if AI supports forecasting or analysis, finance needs to understand the assumptions, limitations and review steps.

Model validation also becomes more important as the use case becomes more material. In practice, a tool used to draft internal notes will need different controls from one that influences forecasting or decision support, so the level of validation needs to reflect the risk of the output being wrong or misunderstood.

Data governance needs the same clarity, as finance teams work with sensitive commercial and financial information. CFOs need to know whether data is stored or used in third-party tools, and whether existing data policies cover the way it is being used with AI.

Without clear ownership, AI use risks becoming fragmented, as teams make their own judgments, review standards vary, and finance leaders lose sight of where AI is impacting the function.

Compliance should be considered earlier in the process

AI regulation is still developing, but CFOs should not wait until all requirements feel settled before reviewing AI use cases.

The EU AI Act uses a risk-based approach, with obligations depending on how an AI system is classified and used. Some finance use cases may remain low risk, particularly where AI is supporting drafting, summarisation or internal productivity. Other use cases may require closer review if AI is being used in areas that affect regulated decisions, employment-related processes, customer outcomes, risk assessment or access to services.

When operating across the UK and Europe, classification should be understood before a tool becomes embedded into a process; finance teams need to know whether they are using an AI system as a deployer, whether the tool is part of a third-party platform, what obligations sit with the provider, and what responsibilities remain with the firm.

The FCA’s approach is also relevant here. While the regulator has not yet introduced a standalone AI rulebook for financial services, it has been clear that firms need to consider AI through existing requirements around governance, accountability, consumer outcomes, operational resilience, data protection and safe adoption.

Further, algorithmic decision-making needs particular attention. Where AI or automated models influence analysis, reporting, control testing, forecasting or decisions that may affect customers, capital, liquidity, pricing or risk, firms need to understand how the decision is reached, who reviews it and what evidence is retained.

In order to remain compliant, CFOs need to know which AI use cases are already in the finance function, which ones impact regulated activity, which ones rely on third parties, and which ones need closer review from risk, compliance, technology or legal teams.

Capability is part of the control environment

Finance teams do not need to become AI specialists, but they do need a level of understanding in order to challenge the outputs. Teams are expected to question assumptions, check evidence, understand movements and explain figures clearly. If anything, AI only increases the need for review because an AI-generated output can appear confident even when it is incomplete, misleading or based on poor inputs.

Finance teams therefore need to understand the limits of AI outputs. They should know when a tool is drafting, summarising, analysing, classifying or predicting, as each use carries a different level of risk. They also need to know when human review is required, what evidence should sit behind the final output and when an issue should be escalated.

As such, AI literacy should be treated as part of finance capability. Training should cover approved tools, restricted data, review expectations, hallucination risk, bias, model limitations, cyber considerations and the difference between using AI for productivity and using it for decision support.

The strongest control is often an informed reviewer, such as a finance colleague who understands both the business context and the limitations of the tool, as they will be likely to identify when output looks plausible but does not stand up to scrutiny.

AI risk belongs on the finance risk register

If AI is being used materially in the finance function, it should be visible in the finance risk register, focusing on use cases that could affect reporting quality, data confidentiality, regulatory compliance, forecasting, decision support, customer outcomes or operational resilience.

The risk description should also be specific, and identify where AI is being used, what could go wrong, how significant the impact may be and what controls are in place. Here, relevant controls may include approved tool lists, data restrictions, human review requirements, model validation, audit trails, access controls, third-party due diligence, output testing, training and periodic review.

The annual risk assessment process should also include AI, enabling finance leaders to review whether AI use has expanded, whether new tools have been introduced, whether controls are still appropriate and whether any informal use has become part of normal working practice.

However, this review should involve more than finance alone, as AI risk can often be seen across technology, risk, compliance, legal, data protection, internal audit and business ownership. CFOs still need to retain clear accountability for how AI is used inside their own function, but they should not manage the risk in isolation.

Practical actions for CFOs

CFOs should start with a clear picture of current AI use across the finance function. Practical actions should include:

Map current AI use across finance

Identify where AI is being used in reporting, forecasting, analysis, reconciliations, controls, management information or workflow activity.

Separate approved use from informal use

Understand which tools are formally approved, which are embedded in existing platforms and where colleagues may be using public or unapproved tools.

Define data rules

Set clear boundaries around what financial, commercial, employee or customer data can and cannot be entered into AI systems.

Assign ownership

Make sure every material AI use case has a process owner who remains accountable for output quality, review and evidence.

Review regulatory exposure

Assess whether any finance use cases could fall within EU AI Act classifications or touch FCA expectations around governance, accountability, algorithmic decision-making or customer outcomes.

Set validation and review standards

Agree how outputs will be checked, what evidence is needed and when a model or tool requires formal validation.

Build AI literacy across finance teams

Provide colleagues with enough understanding to challenge AI outputs, identify weak assumptions and apply professional scepticism.

Add material AI risks to the finance risk register.

Ensure controls are proportionate to the use case and reviewed through the annual risk assessment process.

How Brighter Consultancy can support

Our AI Governance Health Check provides CFOs and finance leaders with a structured view of AI adoption across the finance function, helping to identify approved and informal use, review data and control risks, assess ownership, and highlight where teams may need stronger guidance, validation or AI literacy.

We also support finance transformation, governance improvement, risk assessment, process review and operating model design, helping firms move from broad AI ambition into practical controls that work inside day-to-day finance activity.

If your organisation is using AI across reporting, forecasting, analysis, controls or decision support,  

COMMENTS

RELATED ARTICLES