← MangumCFO
Regulated enterprise AI

AI has moved from the demo into the decision.

Models now shape pricing, forecasts, inventory and credit calls, vendor selection, and increasingly the close itself. In a regulated business that raises a question no vendor demonstration answers: when the decision is challenged — by an auditor, a regulator, a customer, or a court — what can be proven?

For most organizations the honest answer is very little. The prompt is gone. The model version changed without notice. The retrieved documents were never retained. Nobody can say whether a person reviewed the output or waved it through. The control environment that took twenty years to build around the ERP does not yet exist around AI tools.

This is a finance problem before it is a technology problem. It belongs on the same shelf as segregation of duties, spend authority, and revenue recognition, and it will be examined the same way.

"Regulated" doesn't mean banks. It means anyone whose numbers face an auditor, a lender, a customer contract, a privacy regime, a legal challenge, or the AI legislation now arriving. That is nearly everyone.

Why the old financial risk controls don't cover it

The existing rulebooks were written for machines that behave.

The checks companies already run assume software that gives the same answer every time and changes only when someone schedules it. These systems do neither. So the practical questions go unanswered: where does a control belong, what do you keep as proof, and what do you hand the auditor when they ask.

What a finance function actually needs is narrower and more practical: controls for systems that will not give the same answer twice, expressed in the language your auditor already speaks — not the language of the AI industry. Guidance is arriving quickly from regulators and standard-setters — faster, in most cases, than finance functions can absorb it, and none of it is specific to your process. The translation work is what we engage with you on.

What the work covers

Control mapping

Where models touch financially material processes, what a wrong output costs, and which of those paths a control has to sit on.

Evidence and attestation

What is recorded the moment the AI model answers, so a decision can be reconstructed a year later: inputs, model and version, retrieved context, output, reviewer, disposition. Written once, tamper-evident, retained on the schedule of the accounting record.

Human gates

Which decisions require a person, at what threshold, holding what authority — documented like any other approval, not left to whoever is closest to the screen.

Obligation tracking

Commitments a model makes or relies on — to customers, suppliers, lenders, regulators — held in a ledger that can be reconciled, rather than distributed across transcripts nobody keeps.

Model and vendor risk

Concentration, change management, contractual audit rights, and a workable exit. Few AI vendor agreements give a CFO all four.

Cost governance

AI usage behaves like an expense without cost controls. It needs an owner, a budget, and unit economics before it needs agent autonomy.

Audit posture

Translating all of the above into the vocabulary auditors, insurers, and regulators already use, so the answer to “show me your AI controls” is a document rather than a meeting.

Board reporting

A standing view of where models sit in the business, what they are permitted to decide, and what has been overridden — in a form an audit committee can act on.

What this is not

Not a policy document

Most AI governance engagements end in a policy no one can operationalize. This one ends in controls that fire, evidence that persists, and a named owner on each.

Not a model evaluation

Benchmarks describe how a model performs against a test set. They tell an auditor nothing about the decision the company made on a particular Tuesday in March.

Not a technology selection

The control layer is vendor-independent by design, because the model in use eighteen months from now is not the model in use today, and the evidence has to survive the swap.

How an engagement runs

It starts with a map, not a tool. Two to four weeks walking the processes where AI software already touches money — pricing, forecasting, purchasing, the close — writing down, for each one, what a wrong answer costs and who would be asked to explain it. Most companies find the list is shorter than they feared and more expensive than they assumed.

Then controls, in order of exposure. For each decision point: the approval a person has to give, the record kept when the AI model answers, and the threshold above which the software waits. The controls sit inside the tools already in use — nothing here requires buying new technology — and each one ends with a named owner, because a control nobody owns is a suggestion.

The engagement ends with a handover, not a dependency: the map, the approval matrix, the record-keeping running on its own, and a finance team that can answer for all three without a consultant in the room.

The auditor conversation

When it comes — "show me your AI controls" — the answer is a short document: here are the decisions models touch, here is who approves what, and here is the record for any decision you would like reconstructed; pick one. That conversation has historically gone very differently.

The executives who put controls in early are the ones who never have to explain a decision they can't reconstruct. The ones who wait are betting that the first hard question arrives on a convenient day.

Why this practice

The practice maintains its own working implementation of this control stack — an attestation and obligation-ledger layer that records what a model was asked, what it returned, which sources it drew on, and who accepted the result. It was built because the advice had to be tested against something that runs, and because nothing off the shelf produced the evidence the work required. Specifics are available under NDA.

Start a conversation