AI in Financial Reporting: Use Cases and Controls
In 2024, KPMG asked 1,800 companies across ten countries whether they were using AI in financial reporting. 72% said they were already piloting or using it. Only 10% had adopted it widely. The same survey found that 64% expect their auditors to evaluate how they use AI and to provide assurance over the controls around it. That gap is the whole story of AI in financial reporting today: almost everyone is experimenting, very few have scaled, and the people who sign the audit opinion are about to start asking hard questions.
This guide is for CFOs, controllers, chief accounting officers and finance leaders at mid-sized companies who want to use AI in the reporting cycle without creating a control problem. You will find where AI actually saves time in the close and in disclosure, where it creates new risk, what auditors and regulators have said so far, a control framework you can adopt, a readiness scorecard and a 90-day roadmap. No vendor ranking: the right tool depends on your ERP, your close calendar and the maturity of your controls.
Why AI in financial reporting is a controls question first
Most AI projects in finance start as productivity projects. Someone sees a demo of a model reconciling accounts or drafting variance commentary, and the business case writes itself: fewer hours in the close, faster reporting, less overtime in the last week of the quarter.
Financial reporting is different from most business functions in one important way. Every number that reaches the financial statements sits inside a system of internal control. For public companies in the United States, management certifies the effectiveness of internal control over financial reporting under Section 404 of the Sarbanes-Oxley Act, and the auditor tests it. Private companies face lenders, investors and auditors who apply similar logic.
That means the real question is not "can AI do this task?" It is "can we show that the output of this task is complete, accurate and reviewed, in a way that an auditor will accept?" A model that drafts a reconciliation in five minutes is worthless if nobody can explain how it reached its conclusions, or if the review step becomes a rubber stamp.
The good news is that this question has an answer. Finance teams have always relied on tools they did not build: ERPs, consolidation software, spreadsheets with macros. The control logic for AI is an extension of the control logic for those tools, with a few new risks that need specific attention.
Where finance teams actually stand
The data on adoption is consistent across sources, and it tells a story of fast experimentation and slow scaling.
Gartner. A survey of 183 CFOs and senior finance leaders conducted in May and June 2025, reported by CPA Practice Advisor, found that 59% of finance functions use AI, essentially flat from 58% in 2024, after a sharp jump from 37% in 2023. The most common use cases were knowledge management (49%), accounts payable automation (37%) and error and anomaly detection (34%). Gartner also found that 91% of organizations experienced low to moderate initial impact.
KPMG. The KPMG AI in financial reporting and audit survey, fielded in February and March 2024 among companies with revenue from 250 million dollars upward, found that 72% were piloting or using AI in financial reporting, 30% were piloting or using generative AI, and only 2% had widely adopted generative AI. Respondents expected almost universal use of AI within three years.
Deloitte. A Deloitte poll of more than 3,300 finance and accounting professionals, published in July 2025, found that 80.5% believe AI agents and generative AI chatbots could become standard tools for the profession within five years, but only 13.5% of organizations were using agentic AI. The top barrier was trust (21.3%), followed by system integration (20.1%).
Put together, these numbers say something useful. Adoption is not the problem. Impact is. Finance teams are trying AI everywhere and getting modest results, mostly because they are applying it to tasks without redesigning the process and the controls around it.
AI in financial reporting: use cases and controls across the cycle
The financial reporting cycle has distinct stages, and AI fits each one differently. Here is where it delivers value today, ordered roughly from lowest to highest control risk.
1. Research and knowledge management
Finding the relevant accounting guidance, summarizing a new standard, answering "how did we account for this last year?" by searching prior memos and workpapers. This is the most common use case in the Gartner survey for a reason: it saves time and the output is reviewed by a professional before it influences anything.
Control focus: the output is an input to professional judgment, not a conclusion. The key risk is a confident answer citing guidance that does not exist or does not apply. Tools that cite sources, and a habit of checking them, are the main control.
2. Data preparation and transaction matching
Matching bank transactions to the ledger, matching intercompany balances, matching invoices to receipts and purchase orders. Machine learning has done this for years. Newer tools handle messier data: partial references, inconsistent descriptions, multiple currencies.
Control focus: match rules and confidence thresholds need to be documented and approved. Exceptions must route to a person. You need evidence of what the system matched automatically and what a human resolved.
3. Account reconciliations
AI can prepare a first draft of a reconciliation, propose explanations for reconciling items based on history and flag items that have aged beyond policy. In a well-designed process, it turns the preparer into a reviewer of the draft and frees the reviewer to focus on the items that actually matter.
Control focus: the reconciliation still needs a named preparer and a named reviewer. If AI prepares the draft, the human "preparer" must actually validate it, and the reviewer needs to know which parts were generated. This connects directly to your segregation of duties matrix: an AI agent with access to both post and approve is a segregation problem, not a productivity win.
4. Journal entries and accruals
Proposing recurring accruals based on historical patterns and open purchase orders, suggesting account coding, preparing standard entries. This is where AI starts to touch the ledger directly.
Control focus: no AI-generated journal entry should post without human approval appropriate to its risk. Thresholds, approval workflows and logs of who approved what are essential. Many companies start by letting AI propose and humans post, and only later consider automated posting for low-value, high-volume entries with strong detective controls.
5. Anomaly detection and close analytics
Scanning the full population of transactions for unusual patterns: entries posted at odd hours, round amounts, unusual account combinations, duplicates, sudden changes in a vendor's behavior. Anomaly detection is the third most common AI use case in finance in the Gartner data.
Control focus: anomaly detection is a detective control, and it can strengthen your control environment if it is designed as one. That means documenting what it looks for, who reviews the alerts, how quickly, and what evidence is kept when an alert is closed without action.
6. Flux analysis and variance commentary
Drafting explanations for period-over-period changes in balances and line items, pulling drivers from subledgers and operational data. This is one of the biggest time savers in the close, and one of the riskiest uses of generative AI, because a plausible explanation is not necessarily a correct one.
Control focus: every explanation must be traceable to underlying data. The reviewer needs to verify the driver, not just read the sentence. A good test: could the reviewer answer an auditor's follow-up question without asking the model?
7. Disclosure drafting and footnotes
Drafting first versions of management commentary, footnotes, and internal reporting packs; checking consistency between numbers in the text and in the tables; comparing disclosures to prior periods and to peer filings.
Control focus: this is the highest-visibility use case and the one with the most reputational risk. Generated text needs to go through the same disclosure committee review as any other draft, with clear marking of what was generated. Consistency checks, where AI compares numbers across the document, are lower risk and very high value.
What auditors and regulators have said so far
There is no dedicated auditing standard for AI yet, but auditors, standard setters and regulators have published enough to show where expectations are heading.
The PCAOB spotlight
In July 2024 the PCAOB staff published a spotlight on generative AI in audits and financial reporting, based on outreach with audit firms and public companies. The staff observed that companies were using generative AI mainly in less complex and repetitive processes, and that both firms and companies stressed the need for human supervision and review of outputs, along with attention to data security, output reliability and consistency, and governance.
The message for preparers is direct: the existing framework of internal control applies. If AI is part of a process that affects financial reporting, it is part of the control environment, and auditors will want to understand it.
The Center for Audit Quality's 12 risks
In April 2024 the Center for Audit Quality published Auditing in the Age of Generative AI, which lists 12 risks for companies using generative AI in financial reporting. CFO Dive's summary groups them clearly:
- governance, regulation and skills gaps;
- fraud, data privacy and security;
- flawed selection or design of the application, an error-prone foundation model, flawed training;
- weak performance, including hallucinations, defective prompts and inadequate monitoring after deployment.
It is a useful checklist. If you can explain how your process addresses each of the 12 risks for a given use case, you are ready to talk to your auditor about it.
KPMG on auditor expectations
The KPMG survey adds the other side of the conversation: 64% of companies expect their auditors to evaluate AI use and provide assurance over AI controls, 64% expect detailed reviews of the control environment around AI, and 53% expect assessments of AI governance maturity. In other words, finance leaders already know the questions are coming.
AI washing and disclosure risk
There is also a disclosure dimension. In March 2024 the SEC announced its first enforcement actions for "AI washing", settling charges against two investment advisers, Delphia and Global Predictions, for false and misleading statements about their use of AI, with civil penalties of 225,000 and 175,000 dollars. The cases concerned marketing claims, not financial statements, but the principle extends: whatever your company says publicly about its use of AI must be accurate and supportable.
The European angle
For companies operating in the EU, the AI Act (Regulation (EU) 2024/1689) has been in force since 1 August 2024. Most financial reporting uses are not classified as high-risk. Some adjacent uses are: AI used to evaluate creditworthiness of individuals falls under Annex III, with high-risk obligations applying from 2 December 2027. Article 4 has applied since 2 February 2025 and asks providers and deployers to take measures that support the AI literacy of their staff. For a finance team, that means documented guidance and training on how the tools work and where they fail. Our guide to AI governance for business covers the broader framework.
A control framework for AI in the reporting process
The CAQ list tells you what can go wrong. A control framework tells you what to do about it. Here is a practical one, organized in five layers.
Layer 1: Inventory
You cannot control what you do not know exists. Build and maintain an inventory of every AI use that touches financial reporting, including the ones people adopted on their own. For each use, record:
- the process and the financial statement areas affected;
- the tool, the vendor and the model behind it;
- the data it uses and where that data goes;
- the owner;
- whether it proposes, decides or executes.
Unsanctioned use is the first thing to look for. An analyst pasting trial balance data into a consumer chatbot to draft commentary is a data security issue and an undocumented process. We covered how to bring it into the open in our guide to shadow AI.
Layer 2: Risk assessment
Classify each use by how much it can affect the financial statements and how much human judgment sits between the AI output and the ledger. A simple grid works:
| AI proposes, human decides | AI decides within rules, human reviews exceptions | AI executes without review | |
|---|---|---|---|
| Low impact (research, formatting) | Standard review | Periodic sample review | Acceptable with monitoring |
| Medium impact (reconciliations, accruals) | Documented review | Review plus detective controls | Avoid |
| High impact (estimates, disclosures, judgments) | Enhanced review and sign-off | Avoid | Not acceptable |
The rule of thumb: the higher the impact, the closer a human must sit to the decision.
Layer 3: Design controls
For each in-scope use, design controls that address the specific risks:
- Input controls: completeness and accuracy of the data the model receives. If the model drafts a reconciliation from a subledger extract, the extract itself needs a control.
- Processing controls: documented configuration, prompts and thresholds, change management when any of them change, version control on models where the vendor allows it.
- Output controls: human review with evidence, and clarity about what the reviewer is expected to verify.
- Access controls: who can use the tool, who can change its configuration, what systems it can write to.
- Monitoring controls: periodic testing of outputs against known answers, tracking of error rates and overrides.
Layer 4: Evidence
Auditors test controls through evidence. For AI-assisted processes, that means retaining the inputs, the outputs, the version or configuration used, the reviewer's actions and the final result. A review that leaves no trace did not happen, from an audit perspective.
Layer 5: Governance
Someone needs to own the framework. In most mid-sized companies, the natural owner is the controller or chief accounting officer, working with IT and internal audit. Their job is to approve new uses, keep the inventory current, review monitoring results and report to the audit committee.
The review problem: why "human in the loop" is not enough
Every AI policy in finance says that a human reviews the output. The problem is that reviewing well is hard, and AI makes it harder in a specific way.
When an experienced accountant reviews a junior's reconciliation, they know the junior's typical mistakes and look for them. Errors tend to be visible: a missing item, a wrong sign, a sloppy explanation. Generated output is different. It is fluent, well formatted and internally consistent. Its errors are plausible. A variance explanation that attributes a revenue increase to "higher volume in the northeast region" reads perfectly well even when the real driver was a pricing change.
This is why the Deloitte data on trust is interesting. Only 2.7% of respondents trusted full AI autonomy, and 59.7% trusted AI only within a defined framework with human judgment for complex decisions. The instinct is right. But a framework only works if the review is designed for AI output, not copied from the review of human work.
Three practices help:
- Define what the reviewer verifies. Not "review the reconciliation" but "confirm that each reconciling item over the threshold is supported by a source document and that the aging is correct."
- Make generated content visible. The reviewer should always know which parts were generated and which were written or changed by a person.
- Test the reviewers. Periodically seed known errors into AI outputs in a test environment and see whether reviewers catch them. It is uncomfortable, and it is the only way to know whether the review is real.
Choosing tools: criteria in order of weight
Once you know which use cases you want to pursue, tool selection follows. Here are the criteria, from most to least important.
1. Fit with your ERP and close process
The best AI capability is useless if it lives outside the systems where your data and your workflow are. Native features of your ERP or close management platform often beat a more powerful standalone tool, because they inherit the access controls, audit trail and data model you already have.
2. Auditability
Can the tool show what it did, with what data, and what a human changed? Can you export that evidence in a form your auditor can test? If the vendor cannot answer this clearly, the tool is not ready for financial reporting.
3. Data handling
Where is your data processed and stored? Is it used to train models for other customers? Who are the subprocessors? Financial data before earnings release is material non-public information for listed companies, which raises the bar further.
4. Configurability and change control
Can you set thresholds, rules and approval paths? When the vendor updates the model, will you know, and can you test the change before it affects your close?
5. Accuracy on your data
Pilot on your own historical data, with known answers. A tool that performs well on the vendor's demo data may struggle with your chart of accounts, your naming conventions or your intercompany structure.
6. Total cost
Licenses, implementation, integration, the time your team spends configuring and supervising, and consumption-based fees. Measure the cost against hours actually saved in the pilot, not projected savings.
A worked example: the mid-sized company's first quarter
Consider a hypothetical company with 400 million dollars in revenue, a twelve-person finance team, a ten-day close and a mix of manual reconciliations and spreadsheet-based flux analysis. The controller wants to shorten the close and reduce overtime without weakening controls.
Week 1 to 4. The team maps the close calendar and measures where hours go. Account reconciliations and flux commentary turn out to consume the largest share of senior staff time. The team also discovers three analysts already using a consumer chatbot to draft commentary, with trial balance data pasted in.
Week 5 to 8. The controller stops the unsanctioned use and offers an approved alternative within the company's productivity suite, with a contract covering data handling. Two pilots start: AI-drafted reconciliations for 40 high-volume balance sheet accounts, and AI-drafted flux commentary for the income statement. Each has a defined review procedure and evidence requirements. Internal audit is informed from the start.
Week 9 to 12. The team compares the pilot close to the prior quarter. They track hours, number of review comments, errors caught, and errors missed (found later). They walk the external auditor through the process before year end, not after.
The point of the example is not the specific results, which will differ for every company. It is the sequence: measure, contain, pilot with controls, involve audit early, then decide. The companies that get stuck usually skip one of these steps.
Readiness scorecard
Score each item 0 (no), 1 (partly) or 2 (yes).
Foundations
- Your close calendar is documented, with owners and durations for each task.
- Your key reconciliations follow standard templates with defined thresholds.
- Your chart of accounts and master data are reasonably clean and consistent.
- You know how many hours each phase of the close takes.
Governance
- You have an inventory of AI tools used in finance, including informal use.
- You have a written policy on what data can be used with which tools.
- A named person owns AI governance for financial reporting.
- Internal audit or your external auditor has been briefed on your AI plans.
Controls and evidence
- Your review procedures define what the reviewer must verify, not just who signs.
- Your systems keep an audit trail of changes to configuration and rules.
- You can retain inputs, outputs and review evidence for AI-assisted tasks.
- You monitor exceptions and overrides as part of the close.
How to read your score:
- 0 to 10: fix the foundations first. AI will amplify a messy close, not fix it.
- 11 to 18: ready for one or two controlled pilots in lower-risk areas.
- 19 to 24: ready to scale to higher-impact areas, with auditors engaged.
AI in financial reporting: a 90-day roadmap
Days 1 to 30: map and contain
- Map the close and reporting process; measure hours by task.
- Build the AI inventory, including informal use. Ask without blame.
- Issue a short interim policy on data and approved tools.
- Pick one or two use cases with high hours and low to medium financial statement impact.
- Brief internal audit and set expectations with the external auditor.
Days 31 to 60: pilot with controls
- Select tools based on ERP fit, auditability and data handling.
- Document the process, controls and evidence for each pilot.
- Run the pilot in parallel with the existing process for at least one close.
- Track hours, review comments, errors caught and errors found later.
- Write down every surprise.
Days 61 to 90: decide and formalize
- Compare results with the baseline and decide: scale, adjust or stop.
- Update process narratives and control documentation.
- Train all users, including reviewers, on what to verify.
- Set up quarterly monitoring and reporting to the audit committee.
- Choose the next use case.
If you want a structured outside view on where AI fits in your reporting cycle and how to design the controls around it, a working session on your actual close process is a good place to start. You can request one through the consultation page on this site.
The skills your finance team needs
Tools are the easy part. The harder part is the set of skills that lets a finance team use AI without lowering its standards. Three groups of people need different things.
Preparers
Staff accountants and analysts who work with AI every day need to know how to give the tool good inputs, how to read its output critically and when to stop trusting it. Concretely, that means understanding the data the model sees, recognizing the signs of a generated explanation that is not grounded in the numbers, and knowing the escalation path when something looks wrong. It also means knowing the data rules: what can be used with which tool, and why.
Reviewers
Senior accountants, controllers and managers need the review skills described above. They need to know which parts of a deliverable were generated, what they are expected to verify, and how generated errors typically look. Reviewers are also the people who decide when a use case is working and when it is not, so they need to track and report what they find.
Leaders and owners
The CFO, the chief accounting officer and the owner of AI governance need enough understanding to make risk decisions: which use cases to approve, how to classify their impact, what to tell the audit committee and the auditor. They do not need to understand model architecture. They need to understand failure modes, controls and evidence.
How to build these skills
Short, practical sessions built on your own processes work better than generic courses. A useful format is a working session where the team runs a real reconciliation or commentary task with the approved tool, then reviews the output together and discusses what was right, what was wrong and how they would have caught it. Document who attended and what was covered. Beyond being good practice, it gives you evidence of the literacy measures that frameworks such as the EU AI Act expect.
Finally, make room for feedback. The people closest to the work will see problems first: a model that struggles with a particular entity, a prompt that produces inconsistent results, a vendor update that changed behavior. A simple channel to report these, reviewed during the close retrospective, turns individual observations into improvements in the process.
Common mistakes
Starting with the most visible use case. Disclosure drafting is impressive in a demo and the riskiest place to start. Reconciliations and matching usually deliver more hours with less risk.
Treating AI as an IT project. The value and the risk both sit in the finance process. Finance must own the design, with IT as a partner.
Ignoring informal use. If you do not know what your team is already using, your control environment has a gap you cannot see.
Copying the old review step. Reviewing generated output needs a different review design, as discussed above.
Telling the auditor at year end. Auditors do not like surprises. Bringing them in during design makes the conversation easier and often improves the controls.
Measuring adoption instead of impact. Licenses activated and prompts written are not results. Hours saved, days removed from the close and errors caught are.
Automating a broken process. If your close has unclear ownership and inconsistent reconciliations, AI will make the same mistakes faster. Our guides to the month-end close process and the record to report process are a good place to fix the foundations first.
How to measure the return
AI in financial reporting pays back in four currencies, and you should track all four.
- Time. Hours saved per close, days removed from the calendar, overtime reduced. Measure against a baseline, not a vendor estimate.
- Quality. Errors caught before review, adjustments proposed by auditors, restatements and late adjustments. A faster close with more errors is not a win.
- Capacity. What the team does with the time saved. If senior accountants move from preparing reconciliations to analysis and business partnering, the value is larger than the hours suggest.
- Risk. Reduction in unsanctioned tool use, better evidence, fewer control deficiencies.
The Gartner finding that 91% of organizations saw low to moderate initial impact is a warning about expectations, not about the technology. Impact tends to come when a process is redesigned around the tool, and when the team uses it consistently. The pattern is the same one I have seen across industries.
The view from someone who works on processes
In my work with companies, from a hotel that grew revenue from 9 to 10 million to a sports distribution company that grew sales 30% with AI-driven marketing, the lesson has been consistent: technology amplifies a clear process and makes a confused one worse. Finance is the function where that lesson matters most, because the cost of a confused process shows up in the numbers you publish.
AI in financial reporting is not a question of whether. The adoption data makes that clear. It is a question of how: which tasks, with which controls, owned by whom, and with what evidence. The finance teams that answer those questions first will close faster, with fewer errors, and walk into their next audit with a story to tell rather than a gap to explain.
For a broader view of AI across the finance function, see our AI guide for CFOs and our complete guide to AI for accounting. And if you want to design your own roadmap with a clear control framework, you can request a consultation through the dedicated page on this site.
FAQ
How is AI used in financial reporting?
AI is used across the reporting cycle: researching accounting guidance, matching transactions, drafting account reconciliations, proposing accruals and coding, detecting anomalies in journal entries, drafting flux commentary and checking consistency in disclosures. Surveys show broad experimentation but limited scale: KPMG found 72% of companies piloting or using AI in financial reporting in 2024, but only 10% had adopted it widely. The value comes from redesigning processes and controls around the tools.
What are the main AI in financial reporting use cases and controls?
The main use cases are reconciliations, transaction matching, journal entry proposals, anomaly detection, variance commentary and disclosure drafting. Each needs controls on inputs, processing, outputs and access: documented configuration and thresholds, human review with defined verification steps, retained evidence of inputs and outputs, and monitoring of errors and overrides. The higher the impact on the financial statements, the closer a human must sit to the decision.
Will auditors accept AI-generated work in the close?
Auditors can rely on AI-assisted processes if the controls around them are designed and evidenced properly. The PCAOB staff, in its 2024 spotlight, noted that both audit firms and companies stress human supervision and review of AI outputs. KPMG found that 64% of companies expect auditors to provide assurance over AI controls. The safest approach is to involve auditors early, during design, rather than presenting a finished process at year end.
What are the biggest risks of using generative AI in financial reporting?
The Center for Audit Quality lists 12 risks, including weak governance, regulatory breaches, skills gaps, fraud, data privacy and security, flawed model selection or training, hallucinations, defective prompts and inadequate monitoring. In practice, the most common problems are plausible but wrong explanations that pass a superficial review, confidential financial data sent to tools without proper contracts, and undocumented informal use that sits outside the control environment.
Does the EU AI Act apply to AI in financial reporting?
The AI Act applies to AI systems placed on the market or used in the EU, but most financial reporting uses are not classified as high-risk. Some adjacent uses are, such as AI that assesses the creditworthiness of individuals, with high-risk obligations applying from 2 December 2027. Since 2 February 2025, Article 4 has asked providers and deployers to take measures supporting the AI literacy of their staff, which for finance teams means documented guidance and training.
Where should a finance team start with AI?
Start by mapping the close and measuring where hours go, then build an inventory of AI tools already in use, including informal ones. Pick one or two use cases with high time cost and low to medium financial statement impact, such as reconciliations or transaction matching. Pilot them with documented controls, run them in parallel with the existing process for a close, involve internal and external audit early, and measure hours, errors caught and errors missed.
Can AI replace accountants in the financial close?
Not in any meaningful sense today. AI can take over a large share of preparation work, such as matching, drafting reconciliations and first-pass commentary, but judgment, review, estimates and accountability remain human. In the Deloitte poll, only 2.7% of finance professionals trusted full AI autonomy. The realistic shift is from preparing to reviewing and analyzing, which requires accountants who understand both the accounting and how the tools fail.