Pegacorn Group
Finance

How should a board govern AI in the finance function? A control framework for audit committees

7 min read

By The Pegacorn team

How a board and audit committee should govern AI in the finance function — accountability, human approval gates, audit trails, and what belongs in the charter.

A board governs AI in the finance function the same way it governs any other financial control: by defining who is accountable, requiring a human approval gate before AI-generated entries touch the books, mandating an audit trail for every AI action, and reviewing AI use as a standing audit committee agenda item. The board does not need to understand how a model works. It needs to know where AI is used, what it is allowed to do on its own, and where a human signs off before anything becomes part of the financial record.

The mistake most boards make is treating AI in finance as a technology question for management rather than a controls question for the audit committee. AI that drafts a journal entry, codes a transaction, or builds a forecast is doing work that sits inside the company’s internal control over financial reporting. That puts it squarely in the audit committee’s mandate, whether or not anyone has formally added it to the charter.

Why this is a board issue, not just an IT issue

When a tool automatically categorizes transactions, reconciles accounts, or generates a first-draft forecast, it is participating in financial reporting. If that participation is unsupervised, the board has a control gap it cannot see. The relevant question for a director is not “is our AI accurate?” but “what is our AI allowed to do without a human signing off, and can we prove what it did?”

The practical failure mode is quiet: AI-generated work flows into the close, nobody logged which entries originated from a model, and when the auditor asks how a number was derived, the finance team cannot fully reconstruct it. That is a documentation and control weakness, and it is the board’s business. It shows up as a management letter comment at best and a material weakness at worst — and either one is a conversation the audit committee will be asked to explain.

The four questions every audit committee should be able to answer

If the audit committee cannot answer these four questions in the next meeting, that is the work.

  1. Where is AI used in our finance and accounting function today? Most boards cannot answer this. An inventory of AI use — transaction coding in Ramp, reconciliations in the general ledger, expense-report review, forecasting, board-reporting drafts — is the starting point. You cannot govern what you have not mapped.
  2. What is AI allowed to do without human approval? The default for anything that posts to the general ledger or alters the financial record should be: nothing, without human approval. AI can draft, suggest, flag, and prepare. A person approves before it becomes part of the books.
  3. Can we produce an audit trail for every AI action? Every AI-originated entry or recommendation should be logged — what it did, what it was based on, who approved it, and when. If that trail does not exist, the control does not exist. The auditor’s first question when they find an AI-generated entry will be “who approved this,” and the answer needs to be a name and a timestamp, not a shrug.
  4. Who is accountable when the AI is wrong? Accountability does not transfer to a model. The controller or CFO who approved the output owns it. The board should confirm that this line of accountability is explicit and understood.

The human-approval gate

The single most important control is a human approval step between AI-generated work and the financial record. This is not a philosophical stance about AI; it is a straightforward extension of segregation of duties. An AI agent that can both generate and post an entry with no human in between is the same control weakness as one employee who can both create and approve a payment. Auditors treat those the same way, and the audit committee should too.

In practice this means AI operates in a “prepare and recommend” mode, not a “post and execute” mode, anywhere its output affects the books. A person with the authority and competence to evaluate the work approves it before it lands. The approval is logged. The board should ask management to confirm that no AI process can write to the financial record without that gate, and that the log is retrievable on request.

What belongs in the audit committee charter

Boards do not need a separate “AI committee.” AI oversight in finance fits inside the existing audit committee mandate. The charter update is modest: add AI use in financial reporting to the committee’s oversight scope, require management to maintain and present an inventory of AI use in the finance function, and require periodic reporting on AI-related control incidents the way you would any other control matter.

That is three lines in the charter. It is not a new governance discipline. It is the existing discipline applied to a new participant in the process.

What the board should ask management for

A short, recurring management report is enough. Four items:

  • An inventory of where AI is used in finance, updated since the last meeting.
  • The approval gates in place for each use, including who is authorized to approve.
  • Any incidents or exceptions since the last meeting — a mis-coded batch, an unlogged AI action, an approval that shouldn’t have happened.
  • Any expansion of AI’s role that is planned before the next meeting, so the committee can weigh in before rollout, not after.

The board is not auditing the technology. It is confirming that controls exist, that a human approves anything touching the books, and that the trail is there if anyone needs to reconstruct a number. Our CFO checklist for founders and boards has a version of this report format if you want a starting point.

The bottom line

Governing AI in the finance function is not a new discipline. It is the application of controls the board already understands — accountability, segregation of duties, approval gates, and audit trails — to a new kind of participant in the process. Boards that treat it that way will not be surprised. Boards that treat AI as management’s technology problem will find the control gap the hard way, usually during an audit.

When to bring in operator support

You probably don’t need outside help if your finance team is 5-15 people, your AI use in the finance function is narrow and well-documented, and your audit committee already reviews controls on a regular cadence.

You probably do want operator support if:

  • You have AI writing into the general ledger, forecast, or board deck and no one can tell you who reviewed it before it landed.
  • You are heading into a first audit and expect the auditor to ask how AI-generated entries were controlled.
  • You are a Series A/B startup adding AI-native tools quickly and the audit committee has never talked about it.
  • You are the CFO and you want a defensible AI-in-finance policy to bring to the audit committee before you’re asked for one.

Pegacorn Group’s fractional CFO and board reporting practice helps founders and audit committees build the exact controls this post describes — the inventory, the approval gates, the audit trail, and the charter update. The goal is a governance posture on AI in finance that the audit committee, the CFO, and the auditor all agree on before an incident forces the conversation.

If that is the operating bar you want, let’s talk.


This post pairs with: The hire-vs-outsource framework for finance work, Fractional CFO vs. controller vs. VP of Finance, and Surviving your first audit.

About Pegacorn Group

We run finance and HR for venture-backed startups.

Pegacorn Group is the back-office partner for Series A and B startups in cybersecurity, biotech, and deep tech. Fractional CFO, accounting, audit prep, and HR — under one roof.