4 Questions To Ask About AI and Financial Reporting
Audit committees can ask some fundamental questions to ensure that AI doesn’t introduce risk or errors into financial reporting.
Brought to you by Crowe Advisory

For audit committees, governance becomes more difficult when its scope is unclear. With the growing use of artificial intelligence in banking operations, that scope is not only unclear, but also rapidly expanding.
AI today significantly influences many of the systems and processes and much of the information that feed into financial reporting. Bank boards and audit committees need to understand how AI is being used and how it affects the underlying data, analyses and judgments that support financial reporting.
As the range of AI governance expands, boards and audit committees should regularly ask management four overarching questions.
1. Where is AI being used?
Today, AI is embedded in various systems and processes that produce information that management relies on for financial reporting, including forecasting, data preparation, analysis and documentation. Even if a bank is not deliberately adopting AI tools for these purposes, AI capabilities commonly are embedded in third-party enterprise software.
Effective due diligence during the vendor selection process should identify AI inputs into operational platforms, but most software applications are continually evolving. Routine updates, configuration changes and individual employee adaptations can rapidly expand AI’s role — and the associated risks — without those use cases ever appearing on a formal AI project list.
This makes a comprehensive AI inventory a crucial starting point. The inventory should include formally approved AI applications, embedded vendor capabilities, third-party tools and individual employee use cases. The inventory should identify each AI tool or function in use, the business processes affected, the data being used, the responsible owner and the potential consequences of a wrong output. Above all, this inventory should be revisited and updated regularly.
2. Which AI use cases create the greatest financial reporting risk?
Not every AI application or use case warrants the same level of oversight. For example, using document AI to extract information might present relatively limited risk if the results can be readily verified. On the other hand, using generative AI to publish financial information entails greater risk, including possible data misrepresentation, liability issues, intellectual property questions, data leakage or reputational risks. Similarly, any AI use case that influences a forecast, estimate, valuation or other management judgment warrants more scrutiny.
Management should rank AI uses according to their potential financial statement impact, as well as the level of judgment and the degree of human oversight involved. Resources should focus on use cases that have the greatest potential financial, regulatory, customer, operational or reputational consequences.
The audit committee should verify that management has a documented methodology for risk-ranking AI use cases and confirm that applications that could affect financial reporting receive appropriate priority.
3. How has the design of our controls changed to address AI risks?
Audit committee and board members periodically should reevaluate governance as the technology continues to evolve. Management should provide documentation that captures all significant AI tasks and decision points and that demonstrates how changes to AI tools, configurations, data, or underlying models could affect control effectiveness.
Existing IT controls might be adequate in some cases, but control design should reflect the risk and volume of each AI-enabled activity. Depending on the use case, management might require human review of every output, test a risk-based sample, compare results from independent models, or use predictive analytics and defined thresholds to flag exceptions. Documentation should explain why the chosen approach is sufficiently precise, who performs the review, what evidence is retained, and how errors or changes to the tool, model or configuration are addressed. Management also should consider monitoring and logging to allow for audit trail creation and identification of significant issues.
4. What assurance is internal audit providing?
AI governance should not rest with a single function. Management needs to own AI governance, while the risk and compliance functions can provide second-line oversight. Internal audit should evaluate AI governance from end to end and provide a sufficient level of independent reporting, assessment and assurance to the board, with the external auditor retaining its independent role with respect to financial reporting.
For the audit committee, the fundamental governance questions revolve around understanding who owns each AI use case and who provides independent oversight or assurance. All roles should be clearly defined, with someone independent of the process capable of challenging management’s assumptions about AI risks and controls.
As AI usage continues to grow, the objective is not to limit its application. Rather, the goal is to make sure governance keeps pace with adoption – before an AI-enabled process creates a problem that reaches the board too late.