Finance credibility can be lost in one forwarded attachment
A July 29 discussion in r/FPandA captured a failure that generic AI policies miss. A CFO was putting datasets into AI tools, circulating the resulting reports as if they came from finance, and then asking the finance team to diagnose what was wrong. The thread reached 88 points and 31 comments. The problem was not lack of access to AI. It was an undefined publication boundary.
Finance output carries implied authority. A recipient assumes the period is correct, totals reconcile, definitions match prior reports, explanations came from accountable owners, confidential data was handled properly, and a finance professional stands behind the document. An AI tool does not inherit that authority because a CFO, controller, or analyst pasted data into it.
One commenter warned about a report reaching the board with fabricated numbers. Another recommended building a skill or workflow that produces reports the team can stand behind. A third described a simple demonstration: run the same dataset through deterministic code and through an AI tool several times, then compare consistency. Those reactions point to the right control design. Use deterministic computation for numbers, AI for bounded preparation and challenge, and named humans for judgment and release.
This is not an argument to prohibit finance AI. It is an argument to assign it a role. AI can inventory sources, recalculate from supplied data, compare versions, flag inconsistent units, build a claim-evidence table, draft questions, and prepare an exception register. It should not convert missing evidence into polished certainty or silently turn a working paper into official communication.
Core rule: A document is not finance output because a finance leader generated or forwarded it. It becomes finance output when the exact version passes the required controls and a named finance owner accepts responsibility for the stated audience.
Define the release boundary before adding review steps
Teams often write “human review required” and stop. That phrase does not identify which person reviews, what evidence they receive, which errors block release, or which audience changes the standard. The gate starts with status labels that are hard to misunderstand.
| Status | Meaning | May circulate? |
| AI WORKING DRAFT | Unreconciled output for preparation only | Only inside the approved working group |
| FINANCE REVIEW | Sources locked; exceptions and owners visible | Only to named reviewers |
| APPROVED WITH CONDITIONS | Exact version approved for a limited audience after listed edits | Only after conditions are completed and checked |
| RELEASED FINANCE OUTPUT | Exact version signed by the authorized finance owner | Yes, to the recorded audience and channel |
| STOPPED / SUPERSEDED | Blocked, withdrawn, or replaced by a later version | No |
Audience is part of the control. A working variance note sent to one business partner does not need the same sign-off as a board pack, lender certificate, forecast, audit response, regulatory submission, or investor communication. It still needs correct numbers and clear ownership. The gate should raise evidence, subject-matter, disclosure, and approval requirements as external impact increases.
PwC's July CFO guidance places trusted data, governed insights, and decision credibility at the center of the role. AICPA and CIMA's recent Finance Architect research similarly emphasizes judgment and governance alongside technology. These are not abstract aspirations. The report release boundary is where those responsibilities become observable.
Run the release gate in ten controlled steps
1. Classify purpose, audience, and impact
Record the report's decision purpose, reporting period, entity, currency, intended recipients, channel, deadline, and consequences of error. Raise the tier for board, audit, lender, investor, regulatory, tax, covenant, liquidity, workforce, or accounting-policy use. If no accountable audience owner can be named, the report remains a working draft.
2. Lock the source set
Build a source register before reviewing the prose. Each source needs a system or file name, owner, extraction time, reporting period, version, confidentiality class, and stable reference or hash. A report cannot be reproduced if the source spreadsheet changes underneath it.
3. Recalculate with deterministic tools
Use spreadsheet formulas, SQL, Python, or the source system to recompute totals, percentages, variances, rates, and cross-footing. Do not ask a language model to be the only calculator or use its confident narrative as evidence that a number is right. Reconcile to approved control totals and record every unexplained difference.
4. Map every material claim to evidence
Give each source a short ID. Link every material number, trend, cause, forecast, and recommendation to the exact source cell, query, table, owner note, or approved policy. A sentence such as “gross margin declined because of unfavorable mix” contains a calculation and a causal explanation; each needs separate support.
5. Test definitions and consistency
Compare period, entity, currency, units, sign convention, population, filters, eliminations, rounding, and version across tables, charts, headlines, and narrative. Many dangerous errors are internally plausible: thousands shown as full units, favorable expense variances shown with the wrong sign, a chart using forecast v3 while commentary uses v4, or a consolidated number described as one region.
6. Separate fact, calculation, explanation, and judgment
Label the origin of important statements. Source facts come directly from controlled data. Calculations are reproducible transformations. Business explanations come from accountable owners. Hypotheses require follow-up. Accounting, tax, legal, audit, disclosure, and covenant judgments require qualified reviewers. AI may organize these categories but cannot collapse them.
7. Open and own every exception
For each mismatch or unsupported claim, record impact, materiality, owner, evidence needed, due date, and whether it blocks release. “Reviewer to check” is not ownership. A high-risk report should stop when a material number is unsupported, a source version is unclear, or a required domain owner has not reviewed the judgment.
8. Check confidentiality and distribution
Remove or aggregate personal data, payroll detail, bank information, customer identifiers, audit material, tax information, credentials, and material nonpublic information unless the approved purpose and tool permit it. Confirm that the final channel, recipient list, watermark, retention rule, and access permissions match the report tier.
9. Record a decision on the exact version
Use four outcomes: APPROVE, APPROVE WITH EDITS, ESCALATE, or STOP. Bind the decision to a file hash or version ID, audience, conditions, reviewer, approver, and timestamp. Forwarding an edited copy invalidates the prior approval unless the change is covered by a defined immaterial-edit rule.
10. Preserve correction and supersession
Record where the report went and how recipients will be notified if an error is found. Mark superseded versions clearly. A mature gate is not only pre-publication review; it also shortens the path from discovered issue to corrected, traceable communication.
Give the reviewer evidence and authority
| Role | Owns | Cannot delegate to AI |
| Preparer | Source register, calculations, draft, exception log | Truthful description of what was done |
| Finance reviewer | Reconciliation, material claims, consistency, open issues | Professional skepticism and challenge |
| Business owner | Operational causes, actions, forecasts, commitments | Accountability for explanations |
| Controller / specialist | Accounting, controls, tax, audit, covenant, disclosure questions | Domain judgment and policy interpretation |
| Final approver | Exact version, audience, conditions, release decision | Responsibility for circulation under finance authority |
| AI assistant | Preparation, comparison, evidence mapping, exception drafting | Ownership, sign-off, policy exceptions, publication |
NIST AI RMF Govern 3.2 calls for policies that distinguish roles and responsibilities in human-AI configurations. Map 2.1 calls for defining the specific tasks and methods an AI system supports. Applied here, “AI helps with reporting” is too vague. “AI creates a claim-evidence draft from locked sources; the reviewer recalculates material numbers; the controller reviews policy judgments; the CFO approves the exact board version” is operable.
Independence also matters. The person who created an AI transformation should not be the only person validating it for high-impact output. If staffing makes full segregation impractical, use targeted secondary review for material numbers, new calculations, changed methodology, and external-facing statements.
Make every important sentence auditable
A claim-evidence map is more useful than a generic fact check. Give each material claim an ID and record its type, source, calculation, owner, status, and reviewer. The map exposes mixed claims that sound simple but combine several responsibilities.
CLM-014
Report text: "Q3 gross margin fell 180 bps because discounting
in the enterprise channel offset favorable cloud costs."
Calculation: 42.1% - 43.9% = -1.8 percentage points
Source: ERP extract SRC-03, model v4, cells GM_Q3 and GM_Q2
Cause A: discounting - owner note OWN-07, Sales VP, approved
Cause B: cloud cost - cloud ledger SRC-09, recalculated
Open issue: mix bridge differs by 12 bps from report table
Status: BLOCKED pending bridge reconciliation
Reviewer: [name]
Decision: [blank]
Store the AI prompt, model or tool identity, transformation code, and relevant settings when they materially affected the report. This is not about archiving every token forever. It is about preserving enough provenance to reproduce the transformation, investigate an error, and understand whether a later rerun used the same method.
NIST's Generative AI Profile recommends greater tracking, documentation, and human review where generative systems create distinct risks. The Financial Stability Board's 2026 consultation similarly organizes responsible adoption around governance, risk assessment, data management, skills, monitoring, and coordination. A source register, claim map, exception log, and versioned decision are a compact implementation of those principles for a specific finance workflow.
Failure modes the gate must catch
| Failure mode | Why a quick read misses it | Blocking control |
| Fabricated number in fluent commentary | The paragraph sounds plausible and matches the trend | Every material number maps to a source and independent recalculation. |
| Correct number, wrong period or entity | The value exists somewhere in the workbook | Source register and header-level period/entity checks. |
| Unsupported causal explanation | The cause is common in similar businesses | Approved owner evidence or explicit hypothesis label. |
| Chart and narrative use different versions | Both are individually reasonable | Version lock and cross-artifact consistency test. |
| AI changes a formula or workbook | Output totals may still look close | Read-only source, diff review, formula inventory, deterministic rerun. |
| Confidential data enters an unapproved tool | The report task appears routine | Data classification before upload and approved workspace enforcement. |
| Draft forwarded as “from finance” | Sender's title creates implied approval | Visible status label and exact-version release record. |
| Reviewer approves an edited copy | Changes appear cosmetic | Hash or version binding and immaterial-edit policy. |
Implement the gate in 30 days
Week 1: Choose one recurring report
Start with a management report that matters but is not the highest-risk external disclosure. Capture its sources, calendar, owners, current review steps, recurring corrections, and distribution list. Define which output is a working paper and which becomes official.
Week 2: Build the evidence packet
Create templates for the source register, control totals, claim-evidence map, exception log, confidentiality check, and approval record. Configure the workflow pack in an enterprise-approved AI workspace. Keep source data read-only and test with a prior closed period.
Week 3: Run parallel and seed failures
Run the old process and the gated process together. Seed a wrong period, unit mismatch, unsupported cause, stale version, changed formula, and confidential field. Confirm that the gate finds each issue and that reviewers can see why it blocks or escalates.
Week 4: Approve the operating procedure
Document roles, report tiers, required evidence, blocking conditions, tool and data rules, retention, correction, and supersession. Train preparers and approvers on one real example. Measure exceptions found before distribution, review time, post-release corrections, and unsupported claims rather than counting prompts or AI usage.
Do not measure success as “people used AI.” Measure whether the team produced the same or better report with traceable sources, fewer unsupported claims, faster resolution of exceptions, and no increase in corrections or confidential-data incidents.
Final finance release checklist
Purpose and audience recordedThe review tier matches the consequences of error and distribution scope.
Sources lockedSystem, owner, period, timestamp, version, and stable reference are complete.
Numbers recalculatedTotals, percentages, variances, signs, units, and cross-footing reconcile.
Claims tracedMaterial numbers, trends, causes, forecasts, and recommendations have evidence.
Judgments routedAccounting, tax, legal, audit, covenant, and disclosure items reached qualified owners.
Exceptions closed or acceptedEvery open issue has impact, owner, status, and documented disposition.
Confidentiality clearedTool, data, recipients, channel, retention, and access are approved.
Exact version signedThe named finance approver recorded the decision, audience, conditions, and time.
Correction path readyDistribution and supersession records support a fast, visible correction.
FAQ
Can this workflow be used for board or investor reports?
Use it as a preparation layer, then apply the organization's existing disclosure, legal, accounting, audit, internal-control, and executive sign-off procedures. High-impact external reports require more reviewers and evidence, not a longer prompt.
Should finance disclose that AI helped prepare a report?
Follow applicable law, policy, contract, professional standards, and audience expectations. Internally, preserve enough provenance to explain the AI-assisted transformation even when a public disclosure is not required.
Can the AI calculate variances?
It can help generate formulas or code, but material results should run through deterministic computation and reconciliation. Keep the code, formulas, source version, and results available for review.
What is the minimum viable gate?
For a low-risk internal report: lock the sources, recalculate material numbers, map claims, list exceptions, check confidentiality, and require a named finance owner to approve the exact version and audience.