How UK CFOs Should Govern AI in the Finance Function in 2026
UK CFOs should govern AI in finance through an AI Management System aligned to ISO/IEC 42001, with human oversight and board accountability. The ACCA Code of Ethics and Companies Act 2006 reporting duties both apply once AI touches the numbers.
Finance functions moved from experimenting with AI to running it inside forecasting, reconciliation and reporting cycles faster than governance structures kept pace. According to Deloitte’s Q4 2025 CFO Signals survey, 87% of CFOs say AI will be very or extremely important to finance operations in 2026, yet only 14% have fully integrated AI agents into the finance function. The gap between ambition and control is exactly where a CFO’s personal exposure sits.
Why Is AI Governance Now a CFO-Level Responsibility?
AI in finance was, until recently, treated as an IT procurement decision. That framing no longer holds once AI tools touch journal entries, variance analysis, cash forecasting or supplier risk scoring — outputs a CFO signs off on and that feed statutory reporting under the Companies Act 2006. According to Gartner’s July 2026 survey of finance leaders, just 36% of CFOs feel confident they are driving measurable value from their AI investment, even as 45% of AI spend leans toward productivity gains rather than decision quality. Confidence and control are lagging deployment, and auditors are increasingly asking finance teams to demonstrate the same rigour applied to any other reporting control.
Ownership matters because liability does not move to IT simply because a tool was IT-procured. If an AI-assisted forecast or provision turns out to be materially wrong, the CFO answers for it — to the audit committee, to auditors, and potentially to regulators.
Executive Action:
- Confirm which AI tools already touch financial reporting, forecasting or supplier risk data — most finance teams underestimate this.
- Name a single accountable owner for AI risk within finance, distinct from the IT AI governance lead.
- Brief the audit committee on AI exposure before the external auditor raises it first.
What Should a Finance Function AI Governance Framework Include?
ISO/IEC 42001, published in 2023 as the first international management system standard for AI, gives CFOs a structure rather than a starting-from-scratch exercise: an AI Management System covering system purpose and explainability, assigned accountability, risk assessment, and ongoing monitoring. For finance specifically, that translates into an inventory of every AI tool and agent used across FP&A, close, tax and treasury; a risk tier for each based on what it touches; and named human sign-off at every tier that feeds external reporting.
The ACCA Code of Ethics still applies in full — integrity, objectivity, professional competence and due care, and confidentiality do not suspend themselves because a large language model produced the first draft of an analysis. A framework should require finance staff to treat AI output the way they would treat a junior analyst’s first draft: reviewed, sense-checked, and never filed unread. Data quality is the prerequisite most frameworks skip — AI does not correct bad inputs, it scales them.
Executive Action:
- Build a single inventory of AI tools and agents in use across the finance function, tiered by reporting impact.
- Map each tier against ISO/IEC 42001’s core requirements — purpose, explainability, accountability, monitoring.
- Use INFORMD’s AI governance self-assessment to benchmark current maturity before the audit cycle.
How Should CFOs Control AI Risk in Financial Reporting?
Auditors now expect the same evidence trail for AI-assisted outputs that they expect for any other control: model documentation, validation evidence, change logs, and records of human override. A forecast adjusted by an AI tool without a logged reason is, to an auditor, indistinguishable from an unexplained manual override — and will be tested as one. Internal controls frameworks that already require narrative explanation of significant judgements, in the spirit of Provision 29 of the UK Corporate Governance Code, extend naturally to AI-influenced judgements; treat AI as another source of estimation uncertainty to be disclosed, not hidden inside a black box.
Explainability is the practical constraint. If finance cannot explain why an AI-generated number differs from the prior model, that number should not go into a board pack or a statutory filing until it can.
Executive Action:
- Require a logged, human-readable reason for every AI-assisted adjustment that reaches a statutory or board number.
- Retain model documentation and change logs for the same period as underlying financial records.
- Brief the audit committee using INFORMD’s capital approval and technology strategy review templates to structure the disclosure.
What Should CFOs Ask Before Approving New AI Tools for Finance?
Vendor demonstrations are not evidence. A tool that performs well on a vendor’s curated dataset can perform poorly on messy, real general ledger data — the recommendation from finance leaders repeatedly is to test in context before adopting, not after. CFOs should fund AI initiatives in stages, tied to the same payback logic and stage-gate review applied to any other capital investment, rather than as an open-ended subscription approved once and never revisited.
Questions worth asking before sign-off: what data does the tool need, and where does it go; who is accountable if the output is wrong; can the vendor produce documentation an auditor would accept; and what does the tool do that the existing finance stack cannot already do more cheaply.
Executive Action:
- Stage-gate AI funding with defined review points rather than approving open-ended subscriptions.
- Test every new AI tool against your own general ledger data, not vendor demo data, before rollout.
- Require vendors to supply audit-ready documentation as a condition of contract, not an afterthought.
INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library (/resources/) or access our free assessment tools (/tools-assessments/).
Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk (/resources/). Questions about your finance function’s AI governance posture? Get in touch.
ISO/IEC 42001 is a general AI management system standard, not finance-specific, but its requirements — accountability, explainability, risk assessment and monitoring — map directly onto AI use in forecasting, reporting and controls. CFOs can adopt it as a framework without pursuing formal certification.
A named individual within finance, distinct from the IT or enterprise AI governance lead, should own AI risk in finance. This person is accountable for the tool inventory, risk tiering and audit committee reporting on AI use in financial processes.
Auditors expect model documentation, validation evidence, change logs and records of human override for any AI-assisted output feeding financial statements — the same evidence standard applied to other significant judgements and estimates.
Fund AI initiatives in stages with defined review points, tied to payback logic, rather than approving open-ended subscriptions. Treat each stage gate like any other capital investment decision, reassessing value delivered before releasing further funding.
