Skip to main content

COSO GenAI Controls and the AI Risk Register: What Finance Teams Need in 2026

9 min

Generative AI in finance is no longer a technology policy question alone. In February 2026, the Committee of Sponsoring Organizations of the Treadway Commission (COSO) released Achieving Effective Internal Control Over Generative AI (GenAI)—a practical roadmap that maps GenAI risks and controls onto the existing COSO Internal Control—Integrated Framework rather than inventing a parallel governance model.

For controllers, internal audit, and CFO offices at public companies, the publication reframes GenAI as an internal control over financial reporting (ICFR) topic when AI touches journal entries, estimates, reconciliations, management review controls, technical accounting conclusions, or SEC disclosures.

Why GenAI Is Now an ICFR Question

COSO’s guidance is explicitly aimed at professionals responsible for deployment and oversight of AI processes—including controllers and financial reporting groups. The core message: GenAI changes how information is generated and reviewed, but it does not change the obligation to apply COSO principles with rigor.

Practitioner summaries of the release (for example, Virtas Partners’ analysis) emphasize a practical sorting exercise:

  • General productivity uses — drafting emails, summarizing internal notes (lower ICFR relevance if outputs do not enter reporting).
  • Process-affecting uses — workflows that influence data feeding the close or reporting chain.
  • Reporting-significant uses — anything that touches amounts, disclosures, or sign-off materiality.

Risk-ranking should follow that sort, not treat every copilot license as equivalent.

COSO’s Eight GenAI Capability Types (Finance Lens)

COSO organizes GenAI use cases into eight capability types, each with tailored control considerations across the data-to-decision lifecycle:

Capability Finance examples Control focus
Ingestion Pulling data from ERP, data warehouse, documents Source authorization, classification, retention
Transformation Normalizing, mapping, calculating derived fields Logic versioning, reconciliation to source
Posting Proposed journal entries, allocations Segregation of duties, approval before post
Orchestration Multi-step close or AP agent workflows Logging, exception routing, kill switches
Judgment Technical accounting drafts, estimate support Human review, documentation of acceptance/rejection
Monitoring Continuous control monitoring, anomaly alerts Threshold tuning, false-positive management
Regulatory intelligence Disclosure consistency checks Sign-off on external-facing text
Human–AI interaction Prompt libraries, review interfaces Training, prohibited-input policies

KPMG’s summary of the COSO roadmap notes that the guidance also addresses emerging AI reliance—what conditions must exist before finance can depend on model output, and what evidence supports that reliance.

The AI Risk Register: Extension, Not New Bureaucracy

Industry practice increasingly describes an AI risk register as the operational unit for GenAI governance in finance: a single inventory that links each AI touchpoint to risks, controls, evidence, and an accountable owner—updated on the same quarterly cadence as other SOX documentation.

COSO’s framework supports this without requiring a separate program. Public issuers already maintain risk registers under COSO Enterprise Risk Management and SOX 404/ICFR documentation. The AI risk register extends those processes to GenAI and agentic tools.

A workable five-step cycle:

  1. Inventory — List every approved tool, embedded ERP feature, and known shadow-AI use affecting finance workflows.
  2. Risk-rank — Map each entry to COSO’s five components (control environment, risk assessment, control activities, information & communication, monitoring) and flag ICFR significance.
  3. Control design — Define preventive/detective controls, human checkpoints, and evidence artifacts per capability type.
  4. Assign owners — Control owners sit in finance for reporting integrity, not only in IT.
  5. Monitor — Quarterly updates for new deployments, model changes, and regulatory developments; shift toward continuous monitoring where agents run in production.

For model- and functionality-audit angles, pair this with AI governance for finance teams (AICPA & CIMA).

Shadow AI and the Inventory Problem

COSO’s emphasis on deployment oversight implies finance cannot govern only vendor-approved tools. Shadow AI—personal assistants, browser extensions, or unsanctioned uploads of financial data—creates the same ICFR exposure without logging or ownership.

The register should explicitly include:

  • A prohibited-data list (MNPI, payroll, unreleased results, personal data).
  • A channel for declaring new tools before they touch reporting workflows.
  • Consequences for bypassing approved paths—not as IT policing, but as control environment discipline.

What Changes for Audit Committees

If GenAI moves into reporting-sensitive processes, audit committee reporting should evolve: governance scope, concentration of risk in high-materiality use cases, and how management preserves ICFR discipline as adoption expands. The committee does not need to approve every use case, but it should understand the register’s coverage and open exceptions.

Next Steps

The Finance AI strategy hub links COSO controls to economics, orchestration, and skills signals across the finance × AI stack.

Get monthly Finance × AI notes

One concise monthly email with practical finance AI strategy notes, field-tested patterns, and new project updates.

By subscribing, you agree to receive email updates. Unsubscribe at any time.

~Pedro Alizo