For audit committees, governance becomes more difficult when its scope is unclear. With the growing use of artificial intelligence in banking operations, that scope is not only unclear, but also rapidly expanding.

AI today significantly influences many of the systems and processes and much of the information that feed into financial reporting. Bank boards and audit committees need to understand how AI is being used and how it affects the underlying data, analyses and judgments that support financial reporting.

As the range of AI governance expands, boards and audit committees should regularly ask management four overarching questions.

1. Where is AI being used?
Today, AI is embedded in various systems and processes that produce information that management relies on for financial reporting, including forecasting, data preparation, analysis and documentation. Even if a bank is not deliberately adopting AI tools for these purposes, AI capabilities commonly are embedded in third-party enterprise software.

Effective due diligence during the vendor selection process should identify AI inputs into operational platforms, but most software applications are continually evolving. Routine updates, configuration changes and individual employee adaptations can rapidly expand AI’s role — and the associated risks — without those use cases ever appearing on a formal AI project list.

This makes a comprehensive AI inventory a crucial starting point. The inventory should include formally approved AI applications, embedded vendor capabilities, third-party tools and individual employee use cases. The inventory should identify each AI tool or function in use, the business processes affected, the data being used, the responsible owner and the potential consequences of a wrong output. Above all, this inventory should be revisited and updated regularly.

2. Which AI use cases create the greatest financial reporting risk?
Not every AI application or use case warrants the same level of oversight. For example, using document AI to extract information might present relatively limited risk if the results can be readily verified. On the other hand, using generative AI to publish financial information entails greater risk, including possible data misrepresentation, liability issues, intellectual property questions, data leakage or reputational risks. Similarly, any AI use case that influences a forecast, estimate, valuation or other management judgment warrants more scrutiny.

Management should rank AI uses according to their potential financial statement impact, as well as the level of judgment and the degree of human oversight involved. Resources should focus on use cases that have the greatest potential financial, regulatory, customer, operational or reputational consequences.

The audit committee should verify that management has a documented methodology for risk-ranking AI use cases and confirm that applications that could affect financial reporting receive appropriate priority.

3. How has the design of our controls changed to address AI risks?
Audit committee and board members periodically should reevaluate governance as the technology continues to evolve. Management should provide documentation that captures all significant AI tasks and decision points and that demonstrates how changes to AI tools, configurations, data, or underlying models could affect control effectiveness.

Existing IT controls might be adequate in some cases, but control design should reflect the risk and volume of each AI-enabled activity. Depending on the use case, management might require human review of every output, test a risk-based sample, compare results from independent models, or use predictive analytics and defined thresholds to flag exceptions. Documentation should explain why the chosen approach is sufficiently precise, who performs the review, what evidence is retained, and how errors or changes to the tool, model or configuration are addressed. Management also should consider monitoring and logging to allow for audit trail creation and identification of significant issues.

4. What assurance is internal audit providing?
AI governance should not rest with a single function. Management needs to own AI governance, while the risk and compliance functions can provide second-line oversight. Internal audit should evaluate AI governance from end to end and provide a sufficient level of independent reporting, assessment and assurance to the board, with the external auditor retaining its independent role with respect to financial reporting.

For the audit committee, the fundamental governance questions revolve around understanding who owns each AI use case and who provides independent oversight or assurance. All roles should be clearly defined, with someone independent of the process capable of challenging management’s assumptions about AI risks and controls.

As AI usage continues to grow, the objective is not to limit its application. Rather, the goal is to make sure governance keeps pace with adoption – before an AI-enabled process creates a problem that reaches the board too late.

WRITTEN BY

Paul Elggren

Partner

Paul Elggren is a finance and compliance partner in the consulting group at Crowe. He specializes in Sarbanes-Oxley Act (SOX) readiness, SOX compliance, and risk management services. Paul has more than 15 years of experience providing audit, accounting, and risk management services, with deep experience supporting public and private companies, in many industries and of varying sizes.

WRITTEN BY

Gina Green

Partner

Gina Green is a partner in the audit group at Crowe, specializing in providing audit and assurance services to clients in the financial institutions industry. Her deep audit and assurance experience includes: Documentation and testing of controls for Section 404 of the Sarbanes-Oxley Act, SEC filing consent procedures and registration statements for stock offerings and quarterly and annual filings, and performance of training programs for financial institution auditors.

Gina has more than 18 years of audit experience and completed a two-year fellowship with the assurance professional practice at Crowe, focusing on technical accounting matters, audit quality, and audit methodology.