The AI safety debate is not an accounting control framework: what CFOs need before AI touches financial reporting

CFOs need an accounting control framework before AI influences financial reporting: approved source data, repeatable calculations, documented reviewer checks, and a named owner for each decision. Public AI safety commitments inform vendor assessment. Finance must separately define which outputs can enter reporting, what evidence permits release, and when automation must stop.
Why now: September 10, 2026 brings the safety debate closer to finance
On 2026-09-10, Anthropic published its September threat intelligence report. It describes misuse disrupted between December 2025 and August 2026, including sensitive information passing through model services during alleged distillation activity. One example involves internal capital expenditure forecasts submitted through a third-party model router. These are Anthropic's reported findings; the publication date should not be confused with the dates of the underlying activity.
Also on September 10, Senator Josh Hawley's office announced an investigation concerning alleged unauthorized activity by AI agents and broader AI risks. An investigation establishes official scrutiny, not a final finding about every allegation. Neither announcement supplies an accounting standard or proves that a particular finance deployment is unsafe.
The practical inference for CFOs is narrower: assess where financial information travels and what authority an AI workflow receives. A confidential forecast can leave the organization without a journal entry changing. A reporting narrative can influence a board decision without the assistant having write access to the ledger. The control boundary therefore begins before posting.
Finance vendors already discuss this territory. BlackLine's June 17 guardrails article addresses operational risk and human oversight. FloQast's April 14 HubSpot case study discusses repeatable code and deterministic accrual logic. Those are relevant foundations. This article adds a specific operating decision: the evidence, delegated authority, and failure procedure a CFO should approve before an AI-assisted output enters a reporting package.
Approve a reporting use case with a written control charter
The charter identifies source data, the calculation, reviewer checks, and the decision owner.
Start with one workflow, such as drafting monthly operating-expense commentary for three entities. Define the report, users, source systems, covered periods, and intended recipients. Give the workflow a business owner and a named deputy. Approval should attach to that bounded use case; buying access to an AI service should not automatically authorize every finance application.
Write down what the assistant may retrieve, propose, and execute. For an initial deployment, it might retrieve approved balances and draft commentary while remaining unable to change mappings, post entries, or send the board package. Enforce those boundaries through application permissions and service accounts. A sentence in a prompt is insufficient evidence that access is restricted.
The charter should also identify prohibited inputs and approved processing routes. Finance and security should establish which provider, intermediary, and storage location can receive the data, along with applicable retention and training settings. Minimize the records supplied. A variance explanation may need approved account totals and selected supporting transactions, rather than a complete payroll file.
Assign responsibilities that match the decision. The controller owns accounting definitions, review procedures, and release criteria. The technology or security owner implements access restrictions and maintains the approved service configuration. A qualified reviewer assesses the output. The CFO approves the deployment scope and escalation policy, with report-release authority delegated explicitly where appropriate.
Do not make internal audit the operator or routine approver of the control it may later assess. Similarly, a vendor's security review does not approve the company's accounting treatment. Each responsibility needs its own evidence and owner. Small teams can document an independent second review by another qualified person when ordinary staffing cannot provide separation.
Record these arrangements on one control sheet: workflow name, permitted actions, source population, calculation version, reviewer, release owner, blocking conditions, fallback procedure, and next review date. FinBoard's guide to designing audit-ready controls provides the broader close-process context. The additional requirement here is to connect every permission to the specific AI-assisted use case.
Accounting controls: separate data, calculation, review, and decision
For each reporting use case, preserve source data, document the calculation, assign review, and name the decision owner.
A useful accounting control framework makes four responsibilities visible in the workpaper. Source data supplies evidence. Deterministic calculation transforms approved inputs using defined rules. Review tests the result and its accounting meaning. Decision ownership determines whether the proposal may affect the books or the report. These responsibilities remain separate even when one application presents them together.
| Control layer | What it supplies | Required check | Accountable owner |
|---|---|---|---|
| Source data | Ledger records, contracts, invoices, entity identifiers, period boundaries, and extraction timestamp | Reconcile the population and inspect missing, duplicate, stale, or unauthorized records | Accounting data owner |
| Deterministic calculation | Balances, period movements, accrual amounts, and variances from approved rules | Reproduce the result with the recorded inputs, signs, filters, and rule version | Controller or delegated calculation owner |
| Reviewer assessment | Acceptance, correction, or rejection with supporting rationale | Test classification, cutoff, completeness, assumptions, and narrative support | Named qualified reviewer |
| Decision and release | Authorization of an exact entry or reporting package | Confirm unresolved exceptions, approved values, recipient scope, and execution result | Designated accounting approver or report-release owner |
Source data: Preserve the entity, transaction identifier, account, currency, accounting date, amount, and supporting document reference. Retain the extraction timestamp and source query or report parameters. A saved output without its population definition cannot demonstrate completeness. For multiple entities, establish which companies were expected and confirm that every required extract arrived.
Deterministic calculation: Financial measures should come from controlled formulas or report logic. Fix the account mapping, debit and credit treatment, period selection, currency convention, and aggregation rules. The same approved inputs and rule version should reproduce the same result. AI-generated code can qualify only after it has been reviewed, tested, and admitted to that controlled calculation process.
Repeatability alone does not establish correctness. A consistently wrong sign or an omitted entity produces a consistently wrong report. Reconcile at a level that exposes offsetting errors, including relevant accounts and entities. An overall net difference of zero can hide one overstated balance and another understated balance.
Preserve the distinction between a flow and a balance. August expense covers activity during August; accrued liabilities at August 31 represent a point-in-time balance. Summing daily liability balances is not a valid substitute for determining the closing liability. Similarly, a credit to an expense account must reduce expense under the report's presentation rules.
Reviewer checks: Require the reviewer to inspect evidence and accounting conclusions, not merely the wording. The review record should identify the output examined, exceptions investigated, supporting documents, and rationale for any change. Claims about causes need support beyond the arithmetic: an increase in expense does not, by itself, prove a price increase.
Decision ownership: Bind approval to the exact entry or report version. If the source data, calculation, or proposed narrative changes afterward, mark the approval stale and route the changed output back through the required checks. The assistant may prepare an approval packet, but it should not approve its own proposal. Our earlier article on evidence behind AI-generated financial numbers explains the provenance principle; this operating model assigns authority to use those numbers.
Work an accrual through the release gate
Consider an illustrative August software-support accrual. A contract specifies a fixed monthly service fee of $24,000. The service owner confirms that the full month's service was received. The accounts payable ledger contains an $18,000 invoice already posted to August expense, and there is no existing accrual for the remaining amount. These assumptions are part of the example, not facts about a FinBoard customer.
The source packet includes the contract, service confirmation, invoice, relevant general-ledger detail, and an extract of existing accruals. AI can locate the documents and propose that the month is underaccrued. It should identify the references it used and any uncertainty, including whether the invoice covers the same service period.
The approved calculation produces $24,000 less $18,000, or a $6,000 proposed accrual. The proposed entry debits software-support expense for $6,000 and credits accrued liabilities for $6,000. The adjusted August expense for this service becomes $24,000. The closing accrued liability for this item becomes $6,000 under the stated assumptions.
The reviewer checks that the contract is applicable, the service was received, the $18,000 was actually expensed in August, and another preparer has not already recorded the remainder. They also inspect subsequent invoices where available. A balanced entry proves equal debits and credits; it does not prove that a liability exists or that the cost belongs in August.
If the $18,000 invoice instead represents a prepaid service for September, the calculation's input is wrong for this purpose. The reviewer rejects the proposal and resolves the period treatment. If the contract includes variable usage fees, the fixed-fee example no longer supplies enough evidence. The unresolved estimate goes to the accounting owner with the additional support needed.
Once the designated approver accepts the $6,000 entry, execution should use that approved amount, entity, accounts, and period. Retain the posted journal identifier and reconcile the resulting balances. Where company policy uses reversing accruals, document the reversal and subsequent invoice treatment so the same service is not expensed twice.
The reporting step has its own gate. AI may draft a sentence explaining the adjustment, but the reviewer must check that it describes a timing correction rather than inventing a business cause. The report-release owner then authorizes the exact package containing the corrected numbers and approved commentary. Journal approval alone does not approve every downstream narrative.
Define suspension, recovery, and reauthorization before launch
Use explicit blocking conditions. Missing source lineage, an omitted entity, a failed reconciliation, an unapproved calculation change, or an inability to identify the approver should keep the affected output out of reporting. Assign each exception to an owner and a resolution deadline. An exception queue without a responsible person merely relocates the bottleneck.
Set quantitative tolerances for specific comparisons, with documented reasons. Do not apply one universal dollar threshold to every error. An unauthorized disclosure, wrong reporting entity, or unsupported accounting conclusion can require escalation regardless of amount. Evaluate small recurring differences in aggregate so repeated exceptions do not disappear beneath an individual threshold.
Define the response when a control fails after approval. Suspend the affected workflow or release path, preserve its records, and identify which outputs used the same data or calculation version. The controller assesses the accounting impact and required corrections. The report owner assesses whether recipients received affected information and determines the communication response through the company's existing reporting procedures.
Recovery needs a known fallback. Keep a documented method for producing the report from approved source data without the affected AI step. This could be the existing controlled close workpaper and manual narrative review. The fallback should preserve normal approvals; pressure to meet the board deadline should not erase them.
Reauthorization should require an explanation of the failure, a corrected control, and successful testing against the affected scenario and representative normal cases. A new model, retrieval configuration, permission set, or accounting rule can change the risk. Record those changes and assess whether the original approval still applies before restoring the workflow.
For the first close, run the workflow alongside the established process. Include difficult cases such as late invoices, duplicate records, intercompany balances, credit notes, and missing service confirmations. Compare the proposed outputs with independently reviewed results. Track reviewer time, rejected proposals, missing evidence, and corrections discovered after approval, alongside any time saved.
Reviewers also need enough time and competence to operate the control. Monitor backlogs and review a sample of accepted outputs for signs of superficial approval. A high acceptance rate can indicate good preparation or weak challenge; the rate alone cannot distinguish them. FinBoard's accrued-expense control guide offers useful accounting checks for this pilot.
This is a proposed operating model for adaptation to the company's reporting obligations and existing controls. It is not a certification, an audit opinion, or a promise of error-free reporting. The CFO's approval should state the permitted scope and conditions clearly enough that another qualified person can determine whether the workflow is still operating within them.
Frequently Asked Questions
Does an AI safety policy replace accounting controls?
No. An AI safety policy can inform vendor and technology assessment. Accounting controls must separately establish source completeness, calculation accuracy, review evidence, and authority to release financial information.
What should deterministic calculation produce?
Deterministic calculation should produce financial amounts from approved inputs and versioned rules, including account mappings, debit and credit signs, periods, filters, and currency treatment. Repeatability must be paired with reconciliation and accounting review.
Who owns an AI-assisted reporting decision?
The designated accounting approver owns the entry decision, and the designated report-release owner owns publication of the reporting package. The CFO approves the deployment scope and delegation. AI does not approve its own work.
When should a finance team stop an AI workflow?
Stop the affected workflow when source evidence is missing, reconciliation fails, permissions or calculation rules change without approval, or execution differs from the approved output. Preserve records, assess affected reports, and require documented reauthorization.
Bring one reporting workflow and its control charter to your evaluation of FinBoard. Use the source-to-report walkthrough to assess how your team will inspect calculations, resolve exceptions, and own the final reporting decision.


