AI is becoming embedded across entire organisations, from fraud detection and compliance monitoring to forecasting and decision support. Yet many still struggle to demonstrate who owns AI-enabled decisions, how controls operate and whether governance arrangements are effective.
Disclosure creates visibility, but visibility is not assurance. Finance leaders must connect AI statements to evidence that can be examined, challenged and relied on.
As AI adoption expands, so do the governance questions
If an AI system influences a customer, credit, fraud or reporting decision, who can demonstrate that it is properly controlled? A board may approve an AI-enabled fraud-detection system, and the annual report may describe responsible AI principles, but when the audit committee asks who owns the model, when it was last independently validated, how its performance is monitored and how failures are escalated, the answers are less clear. The organisation has disclosed its use of AI, but it has not necessarily demonstrated accountability.
This distinction matters because AI is moving from experimentation into operational activity. As adoption expands, so do questions about data quality, model risk, explainability, third-party dependencies and responsibility for outcomes.
The evidence
Finance professionals already understand that confidence should be supported by evidence. Controls, testing, monitoring and challenge are expected. AI governance deserves the same discipline.
Disclosure remains important, but it is not enough. While it can improve transparency, disclosure needs to be treated as conclusive evidence of governance effectiveness.
Three categories should therefore remain separate: disclosure communicates what an organisation says, policy describes what it intends, and assurance provides evidence that governance arrangements and controls operate as intended. When these categories are blurred, communication can be mistaken for accountability.
Assurance does not necessarily require a formal external audit opinion
Measurement issues
My doctoral research, covering 34 financial services businesses drawn from the FTSE 350 universe along with 490 available company-year observations from 2010 to 2024, identifies an important measurement problem. Public disclosures may indicate capability and communication maturity, but they do not provide sufficient evidence to determine whether relevant governance and control arrangements operate effectively in practice.
Finance leaders should ask what the organisation measures, whether the evidence is auditable and whether it reflects control effectiveness rather than disclosure volume.
Oversight should be proportionate to materiality and potential harm. An administrative tool used to summarise internal documents does not normally require the same validation and board attention as a system influencing credit, pricing, fraud intervention, capital allocation or regulatory reporting.
Between these extremes are forecasting, customer segmentation and operational monitoring applications. The appropriate level of scrutiny depends on how outputs are used, who may be affected, and the consequences of error. Materiality should shape approval, testing, human review, reporting frequency and escalation.
Aspiration should not be presented as verified practice
Assurance does not necessarily require a formal external audit opinion. Depending on the risk of the use case, relevant evidence may include independent model validation, internal audit testing, risk or compliance review, documented control operation, credible management challenge and reliable incident reporting.
Take action
Finance leaders should consider the following actions:
- Separate disclosure from assurance. Board information should be clearly labelled as an external statement, an internal commitment or evidence that a control operates. This prevents aspiration from being presented as verified practice.
- Apply investment discipline. Each material AI proposal should be required to define the business problem, accountable owner, total cost, expected benefit, decision impact, risk classification, control requirements and measures of success.
- Strengthen board reporting. Project counts are not sufficient. Material use cases, responsible executives, deployment status, monitoring results, control exceptions, incidents and unresolved decisions should all be reported.
- Demand point-in-time evidence. The date of introduction of a policy, committee, control or material use case should be reported. A current webpage should not automatically be treated as evidence of historical practice.
- Test the metric before trusting it. The following questions about an AI score should be asked. What drives variation in the score? Does it capture meaningful change? And does it reflect control effectiveness rather than organisational scale or communication capability?
Materiality in practice
Consider two institutions. One publishes comprehensive AI principles but cannot show who reviews model exceptions or how incidents reach the board. The other discloses less, yet maintains named ownership, documented validation and clear escalation routes. The first may appear more mature externally, but the second may be better governed in practice.
The CFO’s task is to connect communication to auditable evidence and to calibrate validation, human oversight and board attention to the consequences of failure. A productivity tool that saves staff time should not be assessed in the same way as a model influencing credit, pricing, capital or financial reporting.
The opportunity is to extend familiar disciplines to AI-supported decisions
For CFOs and boards, the opportunity is to extend familiar disciplines of accountability, investment appraisal, data provenance, control testing and professional scepticism to AI-supported decisions.
Organisations will be better positioned to earn trust if they can demonstrate who owns material AI use cases, how relevant governance and control arrangements operate, how incidents are managed and whether value is being realised. The advantage may not belong to the institution deploying the most AI but to the institution that can demonstrate that its AI is governed, controlled and accountable.
Questions the board should ask
- Which AI use cases are material to customers, financial reporting, risk decisions and regulatory obligations?
- Who is accountable for each material use case, and which decisions remain subject to human review?
- What evidence demonstrates that validation, monitoring and escalation controls operate effectively?
- How are incidents, model changes, third-party dependencies and control exceptions reported?
- Can disclosures be traced to dated evidence, or do they describe only the current position?
- Does the maturity assessment measure genuine change or mainly scale and communication capability?