In finance, an AI without an audit trail is a liability engine
AI in finance, accounting, risk, and control
The question: Where can AI increase financial productivity without weakening control?
Finance is the most attractive automation target — high volume, rule-rich, text-heavy — and the least forgiving: auditability, segregation of duties, and regulatory discipline are non-negotiable. The craft is automating the work without automating away the evidence.
What the lesson covers
The finance AI use-case map: transaction classification and reconciliation, anomaly and fraud detection, forecasting and scenario modelling, variance analysis with narrative drafting, contract and document review, reporting commentary, and audit sampling. Note the split: analytical AI (fraud, forecasting) is mature classical ML; generative AI adds drafting and document understanding.
Controls are the frame: every automation must preserve accuracy, completeness, authorisation, segregation of duties, and traceability. The Finance AI Control Stack: source data → model logic → evidence trail → approval → audit log → monitoring. An AI step that breaks the evidence chain ("where did this number come from?") is not efficiency — it is deferred audit cost plus liability.
Generative AI drafts financial narratives well — variance commentary, board packs, management letters — but every number must be source-linked and every draft must pass a named reviewer. The pattern that works: numbers come from systems (deterministic), words come from AI (drafted), sign-off comes from humans (accountable). Never let the model compute the numbers it narrates.
Model risk management applies to AI as it always did to credit models: validation before use, performance monitoring, documentation, change control, and accountable owners. Under the EU AI Act, credit scoring of natural persons is high-risk — with documentation, human oversight, and robustness obligations. Fraud models face drift by design: fraudsters adapt, so monitoring is the control, not the afterthought.
Where to start in practice: high-volume, low-judgment, evidence-preserving tasks — classification with human review of exceptions, reconciliation matching, first-draft commentary. Where to be slow: anything touching external reporting, credit decisions, or payments without approval gates.
Key points
- Analytical AI (fraud, forecasting) is mature; generative AI adds drafting and document understanding — different risk profiles.
- Every automation must preserve: accuracy, completeness, authorisation, segregation of duties, traceability.
- Numbers from systems, words from AI, sign-off from humans — never let the model compute what it narrates.
- Model risk management: validation, monitoring, documentation, owners. Credit scoring is EU AI Act high-risk.
- Start where volume is high, judgment is low, and evidence survives.
Framework — Finance AI Control Stack
source data → model logic → evidence trail → approval → audit log → monitoring. Design question for every automation step: "can an auditor replay this?" If not, redesign before deploying.
The lab
Read a loan book like a risk manager, then design a control-aware finance workflow.
Open this lesson, its lab and its quiz
Sources and further reading
- Model risk management principles (SR 11-7 — the classic) — US Federal Reserve
- EU AI Act — high-risk obligations — AI Act Explorer