AI Academy · Book
Executives & Directors · Module 05 · Chapter 003

AI in Finance

Most finance work is reading, reconciling, forecasting and explaining, work that today's AI can draft quickly and fluently. The opportunity is real, though measured results are still early. So is the trap: a system that drafts well can drift into authority nobody granted it. Use AI to draft, forecast and detect; keep the power to approve and pay deliberately designed.

≈ 15 min read

After this chapter you can

  • Explain why finance work, mostly reading, reconciling and explaining, suits AI, and name the three kinds of tool behind "the AI".
  • Apply the draft, decide, control pattern to reporting, forecasting and detection.
  • Judge a forecast by the decisions it changes and detection by how much faster it finds problems.
  • Place any finance AI proposal on the ladder of authority and name the controls each rung needs.
  • Separate read access from write access, and analysis from financial authority.

Imagine this note arriving in your inbox from the finance team, with a line at the bottom saying an AI assistant drafted it in under a minute.

A fluent AI-drafted finance note recommending a hiring pause raises the question of whether anyone checked what stands behind it.Operating margin fell this quarter ashosting costs outgrew revenue.Recommend pausing two planned hires.Drafted by an AI assistant in under a minute. Would you forward it tothe board?
Figure 5.3.1 An illustrative note. The language is fine; the question is what stands behind it.

The note is invented, but it is the kind of thing finance teams now produce every day. Would you forward it? It is clear, confident and sounds exactly like finance. Yet you do not know what data it read. You do not know whether hosting costs really rose or an invoice simply landed in a different month. And you do not know who decided that pausing hires was a recommendation this assistant should be making at all.

That small hesitation is the whole subject of finance AI. The technology is already in the building. In Gartner’s annual survey of finance leaders, the share of finance functions using AI rose from 37 percent in 2023 to 58 percent in 2024, then held at 59 percent in 2025. Nine in ten of those users reported only low or moderate initial impact1. The question is no longer whether finance will use AI. It is how to get the speed without losing the thing that makes finance worth listening to: numbers that someone can defend.

Fluency is cheap; authority is not

Finance leaders tend to miss in one of two directions. Too timid, and AI only polishes meeting packs while the close still takes a week. Too trusting, and a system that writes good sentences ends up changing records or releasing payments that nobody approved.

The stance between them fits in three words: draft, decide, control. AI drafts, detects and recommends. People with the authority to do so decide. And the controls that make finance trustworthy (review, approval, segregation of duties, an audit trail) travel with every use case instead of being added later. Each section below applies that pattern to one part of the finance job, and the chapter ends with the question that matters most to an executive: how much authority any given system should hold.

Fifty-nine percent of finance functions use AI; the leading uses are knowledge management, payables automation and anomaly detection.Use AI in thefinance function59%Knowledge management49%Accounts payableautomation37%Error andanomaly detection34%Source: Gartner survey of 183 finance leaders · 2025
Figure 5.3.2 Use is wide and mostly practical: finding information, processing invoices, spotting errors. Impact so far is modest.

Finance is mostly reading, not arithmetic

Ask a room of executives what share of finance work is arithmetic and the guesses often run high. Spreadsheets solved the arithmetic decades ago. What remains is collecting information from billing, payroll and the ledger and reconciling it; interpreting what the numbers mean; forecasting; explaining why this month differs from last; assessing risk; and communicating all of it to people who must act. Almost all of that is reading, comparing, judging and writing.

That is why finance is fertile ground for AI. It also tells you which kind of AI fits which job, because “the AI” in a finance proposal can mean three quite different tools. As AI vs Machine Learning showed, generative and predictive systems do different work, and many finance problems are still best solved with plain rules.

Generative AI drafts and answers, predictive models forecast, and rules and statistics detect exceptions; each fits a different finance job.ToolGood atFinance examplesGenerative AIReading and writingVariance commentary, policy questions,first draftsPredictive modelsEstimating what comes nextRevenue, cash and demand forecastsRules and statisticsSpotting what breaks a patternDuplicate invoices, unusual payments, matching
Figure 5.3.3 Three different tools hide behind “the AI”. Ask which one a proposal actually uses.

Treat the three as different tools with different failure modes. A generative model fails by writing something plausible and wrong. A forecasting model fails by extrapolating a past that no longer holds. A detection rule fails by raising too many alarms, or too few. The controls you need depend on which failure you are buying.

Reporting: AI drafts, finance accounts

Reporting is where many finance teams start. A manager asks why support costs jumped in one region. Today an analyst searches, queries, builds a chart and writes an answer, and much of that time goes into finding things rather than thinking about them. AI shortens the finding. The workable pattern is a short chain: the question comes in, the system retrieves data from approved sources only, it drafts the analysis and commentary, and finance validates the figures against the ledger and adds what the data cannot know. Only then is anything issued.

In finance reporting AI retrieves authorized data and drafts, but finance validates before any report is issued.QuestionFrom a managerRetrieveAuthorized dataonlyDraftAnalysis andcommentaryValidateFinance checksand adds contextOnly then is a report issued
Figure 5.3.4 AI generates; finance accounts. The validation step is part of the design, not a courtesy.

Why so strict? Because the failure is fluent. When researchers built FinanceBench in 2023, a benchmark of questions about public-company filings, a leading model connected to a retrieval system answered 81 percent of questions incorrectly or refused to answer2. Models have improved since, but the failure mode has not disappeared, and the hallucination research explains why it is built into how these systems generate text3. COSO, whose framework most companies use to design internal control, put it plainly in its February 2026 guidance: generative AI “can be confidently wrong”4. When the PCAOB’s staff talked to audit firms and public companies, the same message came back: invest, but keep human supervision and review of the outputs5.

The value is real too. In a field study of accountants on an AI-enabled platform serving 79 small and mid-sized firms, heavier AI use was associated with an 18 percent increase in weekly client support per standard deviation of use and a faster month-end close, and accountants intervened most where the AI reported low confidence in its own output6.

One design warning belongs here. A review step that approves hundreds of good drafts in a row trains people to stop reading. Lisanne Bainbridge called this one of the ironies of automation: the more reliable the system, the less practiced the human who must catch its rare failure7. Direct review effort where it counts, for example at every line above a materiality threshold, instead of asking someone to skim everything.

Forecasting: judged by the decision it changes

Forecasting is the second natural opportunity: revenue, expenses, cash, working capital, demand. The test for a better forecast is not its accuracy score. It is the answer to a simple question: what decision changes because of it? When to hire, how much inventory to hold, which investment to make, how much cash to keep on hand. A forecast that improves none of those decisions is a statistic, not decision support.

A better forecast matters only through the decisions it improves - hiring, inventory, investment, cash, sales plans and scenarios.OutlookOnly if adecision changesHiringInventoryInvestmentCashSales plansScenarios
Figure 5.3.5 Judge a forecast by the decisions it improves, not by its accuracy score alone.

Models learn from history, and history cannot see the major customer negotiation, the planned price change or next quarter’s acquisition. So strong forecasting combines the model, explicit business assumptions and finance judgment, and records which is which. Be careful how that judgment enters. A study of more than 60,000 forecasts at four companies found that large, deliberate adjustments to statistical forecasts tended to improve them, while small tweaks often made them worse, and upward adjustments were especially likely to be wrong8. The lesson for a finance leader is to require a reason for every override and to watch for optimism.

AI also makes scenarios cheap. What if revenue falls ten percent, or the largest customer leaves? When a forecast moves, the executive question is why: volume, price, mix, region or a known event. If nobody can answer, you have a prediction, not decision support. How to read a forecast as a range rather than a single number is covered in AI in Prediction, Forecasting and Optimization.

Detection: more eyes, not a new judge

The third area is finance operations and controls: reconciliations, invoices, expenses and the search for errors and fraud. Here the case for AI is about time. In the 2026 edition of the largest global study of occupational fraud, the Association of Certified Fraud Examiners analyzed 2,402 cases. The typical scheme ran for 12 months before it was found, and more than half involved missing internal controls or controls that someone overrode. Speed of detection mattered enormously: frauds caught within six months had a median loss of about 40,000, while schemes that ran for more than five years cost over 1.1 million9.

The median fraud runs 12 months; caught within six months it costs about 40,000, after five years more than 1.1 million.12Months to detectMedian fraud before discovery40,000Median loss if found earlyDetected within six months1.1M+Median loss if found lateRan for more than five yearsSource: ACFE, 2,402 cases · 2026
Figure 5.3.6 Fraud losses grow with time undetected. Faster detection is where analytics and AI earn their keep.

Notice what that argues for. Tips remain the most common way fraud is found: 43 percent of the ACFE cases were uncovered by a tip9. Analytics and machine learning add more eyes that never tire, scanning every transaction rather than a sample. There is some evidence that this pays: in the same study, organizations using proactive data monitoring reported lower losses, an association rather than proof that the monitoring caused them9. The engine is usually statistics, machine learning and rules; generative AI is more useful for helping an investigator understand and explain a flagged case than for doing the flagging.

Two costs come with it. The first is false positives. Every false alarm takes an analyst’s time and can delay a supplier who did nothing wrong, and a detector that raises alarms all day destroys its own value. The second is the temptation to let the detector act. Flagging a payment for review and stopping it are different decisions, which is where the next section begins. The routing of invoices and documents through extraction and confidence checks is the subject of AI in Document and Data Processing.

Authority is a ladder you climb on purpose

Finance runs on a separation that predates computers. One person prepares, another reviews, someone with delegated authority approves, and the system executes. COSO’s internal control framework names segregation of duties as a point of focus for control activities10, and the Institute of Internal Auditors’ three lines model builds independent assurance on top of it11. That separation is a large part of why auditors, boards and investors trust your numbers. AI should not quietly collapse it.

The useful way to think about any finance AI proposal is as a position on a ladder of authority.

Finance AI authority climbs from reading to drafting to limited action to approval; most finance AI belongs on the drafting rung and approval stays with a named person.Read and analyzeAnswers from approved dataDraft and recommendCommentary, forecasts, flagsMOST FINANCE AI BELONGS HEREAct within limitsSmall, reversible, loggedApprove and executeA named person signs
Figure 5.3.7 Each rung up needs its own design. Approval of consequential actions stays with a named person.

On the first rung the system reads approved data and answers questions. On the second it drafts commentary, forecasts and flags for a person to act on; most finance AI should live here. On the third it takes small, reversible actions below a threshold, such as holding a duplicate invoice, with every action logged. The fourth rung, approving and executing consequential actions such as payments, journal entries and regulatory filings, stays with a named person who holds the authority to sign.

COSO’s 2026 guidance makes the same distinction in its own vocabulary. Among the capabilities it asks organizations to control separately are posting, where the AI writes to the books, and judgment, where it makes evaluative calls4. Each rung up therefore needs deliberate design: access scoped to what the task requires, transaction limits, segregation between the system that proposes and the person who approves, and a record of the input, data source, output, user, approval and time. If you cannot reconstruct what happened, you cannot defend it to an auditor. The general case for limiting what autonomous systems may do is made in Agentic AI and Autonomous Actions; in finance the ladder is simply that principle wearing a controller’s badge.

Analyze is not authorize

One picture helps keep the ladder in mind. A library card gets you into the reading room: you can read every ledger, compare every year and explain what you find. A bank signature card lets you move money. A finance assistant with read-only access holds a library card. A system with write access, one that can change a record or release a payment, holds a signature card, and its impact is in a different league.

Read access is a library card for analysis; write access is a signature card for authority - analyze is not authorize.LIBRARY CARDRead every ledger andexplain what you find.AnalyzeSIGNATURE CARDMove money or change afinancial record.Authorizevs
Figure 5.3.8 Analyze is not authorize. The authority to act is designed separately from the ability to analyze.

Many proposals blur the two. A helpful analyst is demonstrated, and a few releases later it has become a payment engine. So ask which card a system holds, and treat any upgrade from one to the other as a new decision. A library card is not harmless either: it can still expose salaries or margins to the wrong person, and a misleading analysis can still drive a bad decision.

Story: the close that learned to explain itself

The following is an illustrative composite, not a documented case. It is built from the patterns above.

A software company that sells subscriptions to other businesses closes its books each month in about a week, close to the 6.4-day median that APQC’s benchmark of some 2,300 organizations reported12. After the close, a small team of analysts writes the commentary for the leadership pack. They pull figures from the billing system, the customer database and the ledger, compare periods line by line and write the explanations by hand: why billings moved, why hosting costs rose, why one region is behind plan. By the time leaders read it, many of the decisions it should have informed have already been made. The analysts spend their time explaining the past.

The company redesigned the close, not just the tools. The system now reads only authorized data from the ledger and billing. It flags every variance above a materiality threshold that the controller sets, and drafts the first explanation with links to the underlying transactions. Analysts review every material line and add what the data cannot know, such as a pricing change or a delayed deal. The controller signs. The system holds a library card, not a signature card.

In one of the first months, the draft said billings had dropped because customers were leaving. It read perfectly. An analyst checked: no customer had left. A large multi-year contract had moved from monthly to annual invoicing. Billing timing, not churn. Had that sentence reached the leadership pack, it could have triggered a retention campaign aimed at a problem that did not exist.

The commentary now arrives earlier, and the analysts spend their time on causes and next steps. But the lesson the finance team took from the redesign was not the time saved. It was the caught error. The review step was not a courtesy. It was the design.

What this means for leaders

Finance AI rewards ambition in drafting, forecasting and detection, and caution in authority. Four lessons follow. First, place every proposal on the ladder before you discuss its features, and default to the drafting rung. Second, ask which of the three tools is actually in use, because the failure you must control depends on it. Third, judge forecasting by the decisions it changes and detection by how much faster it finds problems, not by accuracy claims in a demonstration. Fourth, budget for review as part of the system, aimed at what is material, rather than as an afterthought that slowly turns into a rubber stamp.

Check yourself

  1. Finance is rules-based, so most of it can be automated end to end.
  2. If an AI system is read-only, it carries no risk.
  3. A forecast should be judged mainly by the decisions it improves.
  4. Small judgmental tweaks to a statistical forecast reliably improve it.
  5. Fraud caught early costs far less than fraud caught late.
  6. An AI tool whose errors people can fix will always save money.

Reflection: where does your line sit?

What comes next

In finance, a wrong answer costs money and credibility, and most of it can be reversed. The next chapter, AI in Human Resources, turns to a function where AI touches decisions about people’s jobs and careers, and where the cost of a confident mistake falls on an employee rather than a ledger.

Laws referenced

EU AI Act · EU

Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744

Risk-based rules. Prohibited practices include social scoring, untargeted scraping of facial images, and emotion recognition in workplaces and schools (with narrow exceptions). High-risk systems (Annex III: biometrics, safety components of critical infrastructure such as energy, water and traffic, employment and worker management, credit, education, essential services, law enforcement, migration, justice) need risk management, data governance, documentation, logging, human oversight, human oversight that keeps people able to understand the system, notice automation bias (over-reliance on its output), override it or stop it (Art. 14(4)), appropriate accuracy, robustness and cybersecurity (Art. 15), automatic logging of events (Art. 12), a provider quality-management system (Art. 17) and conformity assessment. An Annex III system is not high-risk if it poses no significant risk of harm, for example a narrow procedural or preparatory task that does not replace human assessment; systems that profile people are always high-risk, and a provider relying on this exception must document it and register (Art. 6(3)). Deployers of high-risk AI must use it as instructed, assign competent human oversight, monitor its operation, keep logs for at least six months and report serious incidents (Art. 26); employers must inform workers' representatives (Art. 26(7)). Public bodies, private providers of public services, and deployers of credit-scoring or life and health insurance pricing systems must carry out a fundamental-rights impact assessment before first use (Art. 27). Providers must run post-market monitoring (Art. 72). A deployer that puts its name on a high-risk system, substantially modifies it, or changes its purpose so that it becomes high-risk takes on the provider's obligations (Art. 25(1)). A substantial modification (Art. 3(23)) of a high-risk system needs a new conformity assessment, unless the change was pre-determined and documented at the first assessment, as with planned continuous learning (Art. 43(4)). Providers of general-purpose AI models (from 2 Aug 2025) must keep technical documentation, have a policy to comply with EU copyright law including text-and-data-mining opt-outs, and publish a sufficiently detailed summary of training content (Art. 53). Research, testing and development before a system is placed on the market or put into service is outside the Act, except testing in real-world conditions (Art. 2(8)). Since the 2026 Omnibus, the Art. 4 AI-literacy duty is an obligation of effort (take measures to support literacy), not of result. Fines reach EUR 35 million or 7% of global turnover for prohibited practices.

  • 2024-08-01 — Entered into force
  • 2025-02-02 — Prohibited practices (Art. 5) and the AI-literacy duty (Art. 4) apply
  • 2026-07-27 — Omnibus softens Art. 4: providers and deployers must take measures to support AI literacy; no specific level must be guaranteed
  • 2025-08-02 — General-purpose AI model obligations apply; governance and penalties regime in place
  • 2026-08-02 — Transparency duties (Art. 50) apply: disclose AI interaction, label synthetic and deepfake content (marking for generative systems already on the market: 2 Dec 2026)
  • 2027-12-02 — High-risk obligations for Annex III systems (e.g. hiring, credit, education, essential services) - moved from 2 Aug 2026 by the 2026 Omnibus
  • 2028-08-02 — High-risk obligations for AI in products regulated under Annex I

Last verified 2026-10-06 · official text

Sarbanes-Oxley Act (internal control over financial reporting) · US - federal (SEC-registered companies)

Sarbanes-Oxley Act of 2002, Sections 302 and 404 (Public Law 107-204)

Section 302 requires the CEO and CFO to certify each periodic report and the effectiveness of disclosure controls. Section 404 requires management to assess internal control over financial reporting each year, with auditor attestation for larger filers. AI used in close, reconciliation or reporting processes falls inside these controls: its outputs need the same evidence, review and change control as any other step that affects the financial statements.

  • 2002-07-30 — Signed into law

Last verified 2026-10-08 · official text

References

  1. Gartner. Gartner Survey Shows Finance AI Adoption Remains Steady in 2025. Gartner press release, 18 November 2025. 2025.
  2. Pranab Islam, Anand Kannappan, Douwe Kiela et al. FinanceBench: A New Benchmark for Financial Question Answering. arXiv 2311.11944. 2023.
  3. Ziwei Ji et al. Survey of Hallucination in Natural Language Generation. ACM Computing Surveys 55(12). 2023.
  4. Scott Emett, Marc Eulerich, Jason Guthrie, Jason Pikoos and David A. Wood. Achieving Effective Internal Control Over Generative AI. Committee of Sponsoring Organizations of the Treadway Commission (COSO). 2026.
  5. Public Company Accounting Oversight Board. Staff Update on Outreach Activities Related to the Integration of Generative Artificial Intelligence in Audits and Financial Reporting. PCAOB staff Spotlight, July 2024. 2024.
  6. Jung Ho Choi and Chloe L. Xie. Human + AI in Accounting: Early Evidence from the Field. Journal of Accounting Research 64(3), 1333-1373. 2026.
  7. Lisanne Bainbridge. Ironies of Automation. Automatica 19(6). 1983.
  8. Robert Fildes, Paul Goodwin, Michael Lawrence and Konstantinos Nikolopoulos. Effective forecasting and judgmental adjustments: an empirical evaluation and strategies for improvement in supply-chain planning. International Journal of Forecasting 25(1), 3-23. 2009.
  9. Association of Certified Fraud Examiners. Occupational Fraud 2026: A Report to the Nations. ACFE. 2026.
  10. Committee of Sponsoring Organizations of the Treadway Commission (COSO). Internal Control - Integrated Framework (2013). COSO. 2013.
  11. The Institute of Internal Auditors. The IIA's Three Lines Model: An update of the Three Lines of Defense. The IIA. 2020.
  12. Perry D. Wiggins (APQC). Metric of the Month: Cycle Time for Monthly Close. CFO.com. 2018.

Further reading

Sources last verified 2026-10-08.