Good AI governance should make finance faster, not slower
There is a false choice at the heart of many conversations about AI in finance. Either organisations allow people to experiment freely and accept the risks, or they impose so many restrictions that adoption slows to a crawl.
Neither option is particularly attractive, but more importantly, neither is necessary. Good governance should not stop finance teams from using AI. It should help them use it with greater confidence by making the boundaries clear and ensuring that the level of control reflects the level of risk.
That matters because AI adoption is already happening. People are using ChatGPT, Copilot, Gemini, Claude, transcription tools, spreadsheet add-ins and AI features embedded inside finance applications. They are drafting emails, summarising documents, analysing data, creating formulas, preparing commentary and exploring forecasts.
The first governance challenge is therefore not deciding whether AI should be used. It is understanding how it is already being used.
The absence of governance does not create freedom
It creates hidden adoption.
A blanket ban may appear decisive, but it rarely eliminates AI use. Employees still have work to complete, they are under pressure to move faster, and they can see that AI may save them time. When the approved route is unclear, slow or impractical, some will inevitably find their own.
The result is increasingly described as “shadow AI”: unapproved tools being used without organisational visibility over the information entered, the provider’s treatment of that information, or the way the resulting output influences decisions and communications.
This is not simply a technology problem. It is an operating-model problem. When leaders fail to provide a workable route, people create one for themselves, often without understanding the risks they are taking on behalf of the organisation.
The answer is not necessarily a longer policy. It is to make responsible behaviour easier than irresponsible behaviour.
Start with discovery, not policy
Before a CFO writes an AI policy, there is a much more useful question to ask:
Where did the finance team use AI last week?
That question should lead to a straightforward, non-judgemental conversation:
- Which tools did people use?
- What tasks were they trying to complete?
- What information did they enter?
- How was the output checked?
- Did it remain a draft, or did it influence a report, decision or communication?
The purpose is not to catch people out or punish initiative. It is to understand the actual behaviour that governance needs to support.
Many organisations begin by designing policies around hypothetical future risks while paying too little attention to the AI use already taking place. The resulting policy may be comprehensive on paper but disconnected from the work people are actually doing. It becomes too generic to help, too restrictive to follow, or both.
Discovery allows the organisation to start with reality. It exposes genuine use cases, identifies where people are finding value and reveals where the most immediate risks sit.
Finance teams need safe lanes
A more practical approach is to divide AI use into three broad categories. The language does not matter as much as the distinction: some uses should be encouraged, some should be controlled, and some should stop until a secure method has been agreed.
The safe lane
This is activity that can generally be encouraged when an approved tool is used. It involves limited exposure and creates output that can readily be checked by a competent person.
Examples might include:
- drafting a generic checklist;
- summarising public information;
- improving the wording of a non-confidential email;
- creating training examples;
- helping with a spreadsheet formula using dummy data;
- generating questions for a meeting.
The control requirement is relatively light. The employee should use an approved tool, avoid unnecessary company information and review the output before relying on it.
Providing this safe lane is important because governance must include permission as well as prohibition. When employees know which uses are acceptable, they are less likely to treat every AI interaction as something that must be hidden.
The controlled lane
This is where the potential value may be significant, but so is the potential exposure.
Examples might include:
- summarising a draft board pack;
- analysing management accounts;
- exploring aged-debt trends;
- reviewing supplier or customer information;
- creating forecast commentary;
- interpreting internal reports.
None of these activities is necessarily inappropriate. However, the organisation needs greater clarity over the tool being used, the data involved, the provider’s retention and training arrangements, the competence of the reviewer and the way the result will influence decisions.
A controlled use case might require an approved enterprise tool, restricted access, data minimisation, a named process owner and documented human review. It may also need to be recorded in a simple AI use-case register so that the organisation retains visibility as adoption grows.
The stop lane
Some activities should not take place in a general-purpose AI tool without explicit approval and a secure workflow.
Examples include:
- payroll data;
- bank details;
- passwords and security credentials;
- unreleased financial results;
- M&A information;
- confidential legal advice;
- sensitive personal data;
- highly confidential customer information.
The purpose of the stop lane is not to declare that AI can never be used with these processes. It is to recognise that the combination of tool, data and task demands a materially different level of security, assurance and control.
A secure AI capability embedded within an approved finance platform may eventually support some of these activities. Pasting the same information into an unapproved public tool is a very different proposition. Governance needs to distinguish between them rather than treating all AI as equally safe or equally dangerous.
Permission is as important as prohibition
Most governance documents focus heavily on what people must not do. That is understandable, but incomplete. Employees also need to know what they are allowed to do and under what conditions.
A finance leader who says only “be careful with AI” has not provided useful guidance. The employee is still left to interpret what “careful” means, which data is sensitive and whether the tool they are using is approved.
A much more useful operating rule would be:
You may use the approved AI assistant to draft generic credit-control email templates, provided no customer-specific information is entered and the final wording is reviewed before use.
That rule enables adoption and establishes a boundary at the same time. It identifies an acceptable use case, an approved environment, a data restriction and a human review requirement.
This is what effective governance should look like in practice: not a vague instruction to “use AI responsibly”, but clear permission, clear limits and clear accountability.
Governance is a finance leadership responsibility
AI security is often handed to IT, legal or information security. Those teams are essential, but they cannot govern finance use cases alone.
They may understand the underlying technology, contractual terms, data architecture and security controls. The CFO and finance leadership team understand the process risk. They know which information is material, which outputs may affect stakeholders, where judgement is essential and where an error would be particularly difficult to reverse.
The CFO is also best placed to understand the difference between an output that helps someone think and one that enters the formal financial reporting process. A draft variance explanation, for example, carries a different risk from an automatically generated lender report or an AI-triggered journal entry.
That makes AI governance a finance leadership issue as much as a technology issue. The role of the CFO is not to approve every prompt, but to establish the operating boundaries within which the team can use AI safely.
Do not wait for the perfect governance framework
There is a tendency to believe that an organisation needs a complete policy, detailed risk framework and sophisticated technology register before it can act. In practice, waiting for the perfect solution leaves the organisation exposed while unstructured adoption continues.
A sensible starting point can be much simpler:
- identify the AI tools already in use;
- understand the tasks for which people are using them;
- classify the data most likely to be entered;
- define a small number of approved use cases;
- state the red lines clearly;
- require human review where outputs could influence a decision;
- record higher-risk use cases in a simple register.
That register can begin in a spreadsheet. The important thing is not the elegance of the governance system, but whether employees understand what they may do tomorrow morning.
The framework can become more sophisticated as use cases, risks and technology mature. Early governance should create visibility and sensible boundaries without introducing so much administration that people work around it.
Control should enable confidence
The strongest finance teams will not necessarily be those using AI least. They may be the teams using it most confidently because they understand the rules within which they are operating.
They know:
- which tools are approved;
- which data is appropriate;
- which activities require additional controls;
- when human judgement is essential;
- where the absolute boundaries sit;
- who remains accountable for the result.
That is the real value of governance. It replaces uncertainty with clarity and allows useful experimentation to continue while making dangerous behaviour easier to recognise and stop.
The question is not whether finance should choose innovation or control. It is whether finance leaders can design controls that make responsible innovation easier than irresponsible experimentation.
That is one of the issues GrowCFO will be exploring with finance, engineering and AI leaders during the GrowCFO and AccountsIQ roundtable, Can Finance Teams Trust AI?, on 29 July. Book your seat now.
The safest finance team may not be the one using AI the least. It may be the one that knows exactly where AI can add value, exactly where the risks begin and exactly how those risks will be managed.