AI Governance Framework for Finance Teams: Building Controls Around AI
Finance teams should govern AI tools through a formal AI governance framework that assigns ownership, documents each AI system’s purpose and risk level, establishes human review checkpoints for high-stakes outputs, and tests AI-driven controls on the same schedule as any other internal control. The right framework is not a one-time compliance exercise. It is an ongoing discipline that sits inside your existing risk management and internal control structure, not alongside it.
Why an AI Governance Framework Is Now a Finance Requirement
AI has moved from an IT curiosity to a core part of how finance functions operate. Accounts payable automation, cash-flow forecasting, anomaly detection, close-process acceleration, and disclosure drafting are live deployments at mid-market companies right now, not pilots. And they carry real risk. AI systems can produce plausible but incorrect outputs (hallucination), degrade silently as data patterns shift (model drift), and introduce algorithmic bias that compounds across reporting periods.
The governance gap is real and measurable. Financial Executives International’s Committee on Corporate Reporting, drawing on controllers and chief accounting officers from major public companies, released its AI Framework: Internal Control Over Financial Reporting in mid-2026 specifically because AI is entering financial reporting processes faster than the governance structures designed to protect them have evolved. For CFOs and controllers responsible for the integrity of ICFR, that gap has direct consequences at year-end.
SOX Section 404 applies to AI-driven controls with no carve-outs. If an AI system touches any process that feeds into financial reporting, the controls over that system are part of ICFR. Management must assess them; for SEC-reporting companies, auditors must attest to them.
The Authoritative Frameworks: NIST AI RMF, ISO 42001, and the FS AI RMF
No single mandatory AI governance standard applies to all US finance teams yet. But three voluntary frameworks have become the practical reference points for 2026, and regulators are starting to use them as examination benchmarks.
NIST AI Risk Management Framework (AI RMF 1.0)
The NIST AI Risk Management Framework, published in January 2023 and currently being revised as part of the White House AI Action Plan, organizes AI risk management around four functions.
- Govern. Establish the policies, roles, culture, and accountability structures that make the other three functions work. This is the organizational foundation: an AI policy, designated ownership, board or audit committee awareness, and a cross-functional AI governance group that includes finance, IT, legal, and compliance.
- Map. Identify each AI system in use, document its purpose, the data it processes, the decisions it influences, and its potential for harm. For finance teams, this means maintaining an AI inventory that names every tool that touches a financial process, including embedded AI in ERP modules and third-party tools.
- Measure. Test and monitor AI system behavior using quantitative and qualitative methods. Output accuracy testing, model drift detection, and bias audits all live here.
- Manage. Allocate resources to address the risks identified through the Map and Measure functions. Document what you did, why, and with what result.
NIST also released AI 600-1, a Generative AI Profile, in July 2024 to address the specific risks posed by large language models. Finance teams using generative AI for disclosure drafting, commentary, or variance analysis should treat that profile as supplemental required reading.
ISO/IEC 42001
ISO/IEC 42001:2023 is the first international standard for an AI management system (AIMS). Published in December 2023, it applies the same structure as ISO 27001 (information security) and ISO 9001 (quality management) to AI: a documented management system, risk assessment, policy, objectives, monitoring, and continual improvement. The European version, EN ISO/IEC 42001:2026, was adopted by CEN in March 2026, and EU member states were required to give it national-standard status by September 2026.
ISO 42001 is voluntary and certifiable. Certification lasts three years and is already held by several major technology companies that finance teams rely on as vendors. For finance leaders, the immediate practical value is not certification. It is using the standard’s Annex A controls as a checklist when evaluating AI vendors and third-party tools.
US Treasury Financial Services AI Risk Management Framework
On February 19, 2026, the US Department of the Treasury released a sector-specific Financial Services AI Risk Management Framework (FS AI RMF), developed through collaboration involving more than 100 financial institutions and government agencies, including NIST. The FS AI RMF adapts the NIST four-function structure to the specific operational and regulatory context of financial services and introduces 230 control objectives organized across seven risk domains: governance, data integrity, model development, monitoring, third-party risk, fairness and consumer protection, and explainability.
The framework is voluntary, but it has been widely described as the de facto standard that examiners and auditors will reference when evaluating how financial institutions manage AI risk. Mid-market companies are not regulated financial institutions, but finance functions at companies in regulated industries or with institutional banking relationships should understand it.
Building an AI Governance Framework: Practical Steps for Finance Teams
Theory does not protect your financial statements. Here is how CFOs and controllers can translate the frameworks above into an operating program.
Step 1: Build an AI Inventory
You cannot govern what you do not know you have. Start with a structured inventory of every AI system used in or near a financial process. For each system, capture:
- The vendor and product name
- The process it supports (e.g., AP matching, revenue recognition, close)
- The data inputs (including whether they include personal or regulated data)
- Who owns the system and who reviews its outputs
- Whether outputs feed directly into financial statements or only assist human judgment
Include AI embedded in ERP platforms, accounting software, and productivity tools. Many finance teams are surprised by how many AI features have been quietly enabled in systems they have used for years.
Step 2: Risk-Tier Each AI Use Case
Not all AI uses carry the same risk. A system that flags duplicate invoices for human review carries different risk than one that classifies revenue automatically, or one that drafts MD&A language. Assign each inventory item a risk tier based on the consequence of an error and the degree of human review before the output is acted on.
High-risk use cases, meaning those where AI output directly affects a financial statement line, an external disclosure, or a regulated filing, require the most rigorous controls: documented model validation, output sampling and testing, formal change management, and audit trails. Lower-risk use cases can operate under lighter controls with periodic monitoring.
Step 3: Align AI Controls with Your Existing Control Framework
The FEI framework and COSO’s 2026 guidance on generative AI, *Achieving Effective Internal Control Over Generative AI* (released February 23, 2026), both make the same point: AI controls are not a separate program. They belong inside the COSO framework your ICFR already runs on. For each high-risk AI use case, evaluate:
- Control environment. Does your AI policy define what data can be processed, which use cases are permitted in SOX-relevant processes, and the boundary between AI-assisted and AI-automated decisions?
- Risk assessment. Have you assessed hallucination risk, model drift, and algorithmic bias for each AI system, and documented that assessment?
- Control activities. Do you have human-in-the-loop checkpoints, output monitoring, model validation procedures, and model change management built into the process?
- Monitoring. Are AI controls tested on the same schedule as other key controls, and are exceptions escalated and resolved?
- Information and communication. Is AI use disclosed appropriately to your board, audit committee, and, where required, to auditors?
Modus’s advisory services include AI governance assessments that map your current AI use to the COSO framework and identify control gaps before your auditors do.
Step 4: Address Third-Party and Vendor Risk
The FS AI RMF dedicates an entire risk domain to third-party AI risk, and for good reason: most of the AI in a finance function is vendor-supplied. Your governance program cannot stop at the edge of your own systems. For high-risk vendor AI, you should:
- Review the vendor’s AI governance documentation and, where available, their ISO 42001 certification or SOC report covering AI systems
- Include AI governance representations in vendor contracts
- Test vendor AI outputs using your own data before relying on them in a financial reporting process
- Define what happens when a vendor changes or updates the AI model underlying a tool you depend on
Model change management is a particularly underappreciated risk. An AI vendor can update the underlying model powering a tool you rely on, changing its behavior, without the change appearing in your traditional IT change management log.
Step 5: Document, Test, and Report
Documentation is not administrative overhead. It is the evidence that your controls exist and operate. For each AI control, maintain:
- A description of the control and the risk it addresses
- The frequency and method of testing
- Test results and any exceptions noted
- Remediation of exceptions and the date resolved
Your audit team will ask for this documentation. Auditors are increasingly required to understand how AI affects the processes they audit, and they will expect management to have the documentation ready. An AI-native audit practice like Modus can assess AI-driven controls more efficiently because we use the same generation of tools, with source-linked workpapers that map directly to your control evidence.
The Regulatory Horizon: What Is Coming
Two developments finance leaders should watch.
EU AI Act obligations for high-risk AI systems. The EU AI Act, which entered into force on August 1, 2024, classifies AI used in credit scoring and insurance access as high-risk. The Digital Omnibus on AI, which entered into force on July 27, 2026 after publication in the Official Journal on July 24, 2026, deferred standalone Annex III high-risk obligations to December 2, 2027 (and Annex I embedded-product obligations to August 2, 2028), but US companies with EU operations should begin compliance preparation now. Penalties for non-compliance with high-risk obligations can reach 15 million euros or 3% of total worldwide annual turnover.
NIST AI RMF revision. The AI RMF 1.0 is currently under revision as part of the White House AI Action Plan. Finance teams that have aligned to the current framework should monitor NIST’s AI Resource Center for updates and expect an iterative update rather than a wholesale replacement.
The direction of travel is clear: AI governance is moving from voluntary best practice toward mandatory control, in financial services and beyond. Finance teams that build the program now will be ahead of the requirement rather than catching up to it.
Frequently Asked Questions
What is an AI governance framework for finance teams?
An AI governance framework for finance teams is a structured program that identifies every AI system in use in financial processes, assigns ownership and risk ratings to each, defines control activities (including human review checkpoints and output testing), and integrates those controls into the organization’s existing internal control framework. The goal is to ensure that AI-driven outputs are accurate, auditable, and compliant with financial reporting requirements.
How does the NIST AI RMF apply to a finance function?
The NIST AI Risk Management Framework’s four functions, Govern, Map, Measure, and Manage, map directly onto good financial-process hygiene. Govern means establishing policy and accountability. Map means maintaining an AI inventory. Measure means testing AI outputs and monitoring for drift or bias. Manage means resolving identified risks and documenting what you did. Finance teams do not need to adopt the framework formally; they need to apply its logic to each AI use case that touches a financial process.
Does SOX Section 404 apply to AI controls?
Yes. SOX Section 404 contains no exemption for AI. If an AI system is part of any process that feeds into financial reporting, the controls over that system are part of internal control over financial reporting. Management must assess those controls under Section 404(a), and for SEC reporting companies, auditors must attest to them under Section 404(b). The FEI’s AI Framework for ICFR, released in 2026, provides practical guidance for controllers and chief accounting officers on how to structure those controls.
What is the difference between the NIST AI RMF and ISO 42001?
The NIST AI RMF is a voluntary risk management framework published by a US government agency. It is flexible and does not require certification. ISO/IEC 42001 is a certifiable international management system standard, structured like ISO 27001, that organizations can be independently audited against. The two are complementary: many organizations use the NIST AI RMF for their internal risk management program and ISO 42001 to demonstrate governance maturity to external stakeholders, customers, or regulators.
What is the US Treasury Financial Services AI Risk Management Framework?
Released on February 19, 2026, the FS AI RMF is a financial-sector-specific framework built on the NIST AI RMF structure. It was developed through public-private collaboration involving more than 100 financial institutions and government agencies, in partnership with the Cyber Risk Institute. The framework provides 230 control objectives organized across seven risk domains, namely governance, data integrity, model development, monitoring, third-party risk, fairness and consumer protection, and explainability, and is designed to be scalable for institutions of different sizes. While voluntary, it is widely expected to serve as the reference benchmark for regulatory examinations of AI risk management in financial institutions.
What AI controls should a CFO or controller put in place first?
Start with three foundational controls. First, build an AI inventory so you know every AI system that touches a financial process. Second, assign a risk tier to each use case and require human review checkpoints for any AI output that directly influences a financial statement line or an external disclosure. Third, document the controls and test them on the same schedule as your other key controls. These three steps address the most common gaps, namely undiscovered AI use, unreviewed AI output, and untested controls, and will put you in the best position for your next audit.
Filed under: AI & Automation