COSO GenAI Controls and the AI Risk Register: What Finance Teams Need in 2026
Generative AI in finance is no longer a technology policy question alone. In February 2026, the Committee of Sponsoring Organizations of the Treadway Commission (COSO) released Achieving Effective Internal Control Over Generative AI (GenAI)—a practical roadmap that maps GenAI risks and controls onto the existing COSO Internal Control—Integrated Framework rather than inventing a parallel governance model.
For controllers, internal audit, and CFO offices at public companies, the publication reframes GenAI as an internal control over financial reporting (ICFR) topic when AI touches journal entries, estimates, reconciliations, management review controls, technical accounting conclusions, or SEC disclosures.
Why GenAI Is Now an ICFR Question
COSO’s guidance is explicitly aimed at professionals responsible for deployment and oversight of AI processes—including controllers and financial reporting groups. The core message: GenAI changes how information is generated and reviewed, but it does not change the obligation to apply COSO principles with rigor.
Practitioner summaries of the release (for example, Virtas Partners’ analysis) emphasize a practical sorting exercise:
- General productivity uses — drafting emails, summarizing internal notes (lower ICFR relevance if outputs do not enter reporting).
- Process-affecting uses — workflows that influence data feeding the close or reporting chain.
- Reporting-significant uses — anything that touches amounts, disclosures, or sign-off materiality.
Risk-ranking should follow that sort, not treat every copilot license as equivalent.
COSO’s Eight GenAI Capability Types (Finance Lens)
COSO organizes GenAI use cases into eight capability types, each with tailored control considerations across the data-to-decision lifecycle:
| Capability | Finance examples | Control focus |
|---|---|---|
| Ingestion | Pulling data from ERP, data warehouse, documents | Source authorization, classification, retention |
| Transformation | Normalizing, mapping, calculating derived fields | Logic versioning, reconciliation to source |
| Posting | Proposed journal entries, allocations | Segregation of duties, approval before post |
| Orchestration | Multi-step close or AP agent workflows | Logging, exception routing, kill switches |
| Judgment | Technical accounting drafts, estimate support | Human review, documentation of acceptance/rejection |
| Monitoring | Continuous control monitoring, anomaly alerts | Threshold tuning, false-positive management |
| Regulatory intelligence | Disclosure consistency checks | Sign-off on external-facing text |
| Human–AI interaction | Prompt libraries, review interfaces | Training, prohibited-input policies |
KPMG’s summary of the COSO roadmap notes that the guidance also addresses emerging AI reliance—what conditions must exist before finance can depend on model output, and what evidence supports that reliance.
The AI Risk Register: Extension, Not New Bureaucracy
Industry practice increasingly describes an AI risk register as the operational unit for GenAI governance in finance: a single inventory that links each AI touchpoint to risks, controls, evidence, and an accountable owner—updated on the same quarterly cadence as other SOX documentation.
COSO’s framework supports this without requiring a separate program. Public issuers already maintain risk registers under COSO Enterprise Risk Management and SOX 404/ICFR documentation. The AI risk register extends those processes to GenAI and agentic tools.
A workable five-step cycle:
- Inventory — List every approved tool, embedded ERP feature, and known shadow-AI use affecting finance workflows.
- Risk-rank — Map each entry to COSO’s five components (control environment, risk assessment, control activities, information & communication, monitoring) and flag ICFR significance.
- Control design — Define preventive/detective controls, human checkpoints, and evidence artifacts per capability type.
- Assign owners — Control owners sit in finance for reporting integrity, not only in IT.
- Monitor — Quarterly updates for new deployments, model changes, and regulatory developments; shift toward continuous monitoring where agents run in production.
For model- and functionality-audit angles, pair this with AI governance for finance teams (AICPA & CIMA).
Shadow AI and the Inventory Problem
COSO’s emphasis on deployment oversight implies finance cannot govern only vendor-approved tools. Shadow AI—personal assistants, browser extensions, or unsanctioned uploads of financial data—creates the same ICFR exposure without logging or ownership.
The register should explicitly include:
- A prohibited-data list (MNPI, payroll, unreleased results, personal data).
- A channel for declaring new tools before they touch reporting workflows.
- Consequences for bypassing approved paths—not as IT policing, but as control environment discipline.
What Changes for Audit Committees
If GenAI moves into reporting-sensitive processes, audit committee reporting should evolve: governance scope, concentration of risk in high-materiality use cases, and how management preserves ICFR discipline as adoption expands. The committee does not need to approve every use case, but it should understand the register’s coverage and open exceptions.
Next Steps
- Download and socialize the COSO press release and publication summary with controllership, internal audit, and IT.
- Start the inventory before the next close cycle adds agent-assisted steps without evidence.
- For operational logging when agents touch close tasks, see agent audit trails for close and financial reporting.
The Finance AI strategy hub links COSO controls to economics, orchestration, and skills signals across the finance × AI stack.
Get monthly Finance × AI notes
One concise monthly email with practical finance AI strategy notes, field-tested patterns, and new project updates.
By subscribing, you agree to receive email updates. Unsubscribe at any time.
~Pedro Alizo