If we have selected the wrong experience for you, please change it above.
By: Amy Steele | Geoff Kovesdy | Ryan Hittner
In tech startup and entrepreneurial circles, there’s a familiar saying: “driving down the road while it’s still being paved.” With artificial intelligence (AI) in finance and accounting, it’s more like racing down the freeway while the guardrails are still being installed.
As AI rapidly accelerates from finance pilot programs to real-world use cases, a clear gap has developed between deployment and governance. Just 25% of organizations, for instance, report having a fully implemented AI governance program,¹ and only 21% have a mature governance model for autonomous AI agents.² While efforts like Deloitte’s Trustworthy AI™ framework have helped some organizations establish governance programs, what’s really needed is an industrywide standard—a common governance language and approach that organizations can rally around.
Enter COSO, a longtime thought leader in internal control, risk management, and governance. In February, COSO released Achieving effective internal control over Generative AI. Building on COSO’s 2013 Internal Control–Integrated Framework (ICIF), the report lays out a pragmatic approach to GenAI governance. Ahead, we highlight the report’s most important takeaways and share leading practices for putting them into action.
When GenAI burst into the mainstream a few years back, it captured attention because of its ability to process structured and unstructured information; generate text, images, and code; and interact with downstream systems through application programming interfaces. The result? Unprecedented efficiencies and analytical capabilities.
Those capabilities also introduced a distinct set of risks. They include GenAI’s ability to sound confident despite being wrong, model drift and bias accumulation, susceptibility to manipulation through carefully crafted prompts, and “shadow AI”—unauthorized or ungoverned AI implementations outside formal IT oversight.
With these risks in mind, COSO developed a view of GenAI governance based on eight capabilities:
This capabilities-based framework aligns with the five components (covering 17 principles) of the COSO integrated framework: control environment, risk assessment, control activities, information and communication, and monitoring activities. The goal in all this is to help organizations integrate GenAI into their operations by using the framework’s structure to clarify objectives, strengthen control design and execution, and increase rigor in traceability and monitoring.
Two practical features of the COSO AI framework stand out:
Audit-ready control mapping. Each of the eight capabilities includes embedded examples, minimum control expectations aligned to the five COSO components, and illustrative metrics for operational monitoring and audit evidence collection. This mapping helps close the gap between the governance framework and audit requirements.
Implementation tools. COSO helps reduce implementation time from months to weeks by providing starter templates such as risk assessment matrices, control testing procedures, and metric dashboards that teams can tailor to their specific scenarios.
We see COSO’s GenAI guidance as most useful when it builds on the 2013 ICIF rather than acting as a prescriptive rulebook. That matters because GenAI requires a different mindset of both management and auditors. It means shifting from rule-based systems with predictable outputs to probabilistic models with variable results—and from point-in-time assurance to ongoing monitoring of performance and risk.
That monitoring is especially important when GenAI is used in financial reporting, because this is not a “set it and forget it” technology. Effective monitoring focuses on meaningful indicators such as transaction volume, transaction size, and override rates to spot model drift and other issues early. It should also include regular checks on accuracy and reliability, along with reviews of root causes, whether tied to prompt design, retrieval issues, or vendor changes.
Moving forward, organizations can take the following six actions to manage GenAI risks effectively:
Deloitte delivers responsible, tested, human-led, AI-powered innovations, addressing complex challenges with practical, trusted solutions. Deloitte’s AI-enabled offerings, combined with extensive industry, domain, and regulatory experience, can transform financial complexity into strategic clarity. Deloitte's approach is grounded in quality, integrity, and transparency.
Deloitte can advise you on how to leverage the COSO framework to put GenAI controls into practice—from governance and risk assessment to monitoring and documentation. For more information, explore our Heads Up: “COSO Releases Publication on Internal Controls Related to Generative AI” (April 3, 2026) in the Deloitte Accounting Research Tool (DART). You can also reach out to us directly.
Endnotes
The services described herein are illustrative in nature and are intended to demonstrate our experience and capabilities in these areas; however, due to independence restrictions that may apply to audit clients (including affiliates) of Deloitte & Touche LLP, we may be unable to provide certain services based on individual facts and circumstances.
This publication contains general information only and Deloitte is not, by means of this publication, rendering accounting, business, financial, investment, legal, tax, or other professional advice or services. This publication is not a substitute for such professional advice or services, nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified professional advisor. Deloitte shall not be responsible for any loss sustained by any person who relies on this publication.
Copyright © 2026 Deloitte Development LLC. All rights reserved.
Amy is an Audit & Assurance partner performing audits and serving in the National Office of Deloitte & Touche LLP. She leads Deloitte’s National Office Audit & Assurance Services Group’s revenue subject matter team and Deloitte’s audit initiatives related to the cryptocurrency, digital assets, and blockchain emerging sectors. She co-chairs the AICPA’s Digital Assets task force and serves on the Center for Audit Quality’s Emerging Technologies and Cybersecurity task forces. She is also a member of the AICPA’s Assurance Services Executive Committee (ASEC) and the ASEC’s Strategic Direction Working Group. She performs audits in the technology industry, including the software and blockchain sectors. In her National Office role, Amy is responsible for developing and implementing strategies to enhance quality across the Audit & Assurance business, conducting consultations with practitioners to enact leading practices throughout the global Deloitte network, and leading initiatives to innovate and transform how Deloitte performs audits.
Geoff is an Audit & Assurance principal and leads the Digital Controls, AI, and Automation market offering and the IT Risk and AI-driven Risk and Controls-related services. He has advised clients through their strategic and transformation initiatives, including risk management, finance/digital transformations, process reengineering, business process outsourcing/insourcing, and ERP implementations. He leads client relationships through internal audit, finance and accounting, compliance, and cybersecurity. Geoff's specialization is risk management, where he spends a significant amount of time advising his clients in modernizing and transforming risk management activities across the three lines, including leveraging AI/GenAI solutions and innovative ways of working. This includes strategy and operating model development and implementation and developing/deploying digital assets. He has led internal audit, SOX, and compliance activities for multiple Fortune 100 companies and has led reviews across various risk domains, as well as advising on implementing enterprise risk management frameworks and conducting internal audit risk assessments. In addition, Geoff has helped to incubate and bring several new products, technology assets, and services to market and is a recognized speaker at several industry and domain conferences on the topics of risk management, digital risk management, AI/GenAI, and risk excellence (coordinated assurance).
Ryan is an Audit & Assurance principal with more than 20 years of experience helping global institutions strengthen trust, transparency, and performance across complex analytical, financial, and artificial intelligence (AI) systems. His work brings together deep experience in risk management, governance, controls, valuation, modeling, data, automation, and emerging technology to help clients navigate transformation with confidence. Ryan serves as Deloitte’s Global AI Specialist Leader, leading a team of AI professionals who support assessments of AI systems and advise non-attest clients on large-scale AI strategy and governance transformations. His work focuses on helping organizations understand, govern, and manage the business, risk, and control implications of AI, advanced algorithms, and emerging agentic systems. Ryan also serves as Deputy Leader of Deloitte’s Valuation & Analytics practice, a global network of professionals with deep experience across traded financial instruments, data analytics, modeling, and valuation. In this role, he leads Deloitte’s Omnia DNAV AI and Derivatives technologies, which incorporate automation, machine learning, and large-scale data to enhance the delivery of valuation and analytics services. Previously, Ryan served as a leader in Deloitte’s Model Risk Management practice, where he advised financial services institutions on model development, validation, governance, technology enablement, and quantitative risk management. He has led multidisciplinary teams serving several of the top 10 US financial institutions on complex risk, control, and process transformation programs. Ryan frequently serves as a trusted advisor to CEOs, CFOs, CROs, boards, and audit committees on issues at the intersection of risk, technology, governance, financial markets, and business transformation. His experience spans AI and algorithmic risk, model risk management, financial risks and valuation. Ryan received a BA in Computer Science and a BA in Mathematics & Economics from Lafayette College. His work sits at the intersection of financial risk, valuation, modeling, data, automation, machine learning, and AI, helping clients strengthen trust, transparency, and business value across critical decision-making processes. Media highlights and perspectives Ryan has authored many thought leadership articles and blogs and his commentary has been featured in publications including Accounting Today, CFO Dive, Strategic Finance Magazine, and the Wall Street Journal. 2026 [Strategic Finance Magazine] Optimizing AI with Good Governance [Accounting Today] Internal audit’s role in guiding AI responsibly [Internal Auditor Magazine] AI Unleashed [Deloitte blog] COSO AI framework: Internal controls for generative AI 2025 [Deloitte blog] Internal Audit’s role in strengthening AI governance [Deloitte blog] The impact of AI on your audit: Supporting AI transparency and reliability in finance and accounting [Deloitte blog] Generative AI in Financial Reporting and Accounting [WSJ Risk & Compliance Journal] A Day in the Life of an Accounting Generative AI User [FEI Weekly] AI in Finance: Balancing Innovation, Accuracy, and Audit Readiness [Accounting Today] Auditors, management prepare for AI impact on financial data 2024 [Deloitte blog] Mitigating AI fraud risks [Deloitte perspectives] Underscoring the role of AI in investment management [NACD report] NACD 2024 Governance Outlook Report [FM Magazine] What CFOs Need to Know About AI Risk [Internal Auditor] The Fraudsters Have AI, Too [CFO Dive] Bolstering your cyber defenses in the age of AI 2023 [Deloitte perspectives] Perspective on New York City local law 144-21 and preparation for bias audits [Deloitte blog] Reduce AI risk and promote AI trust [Deloitte perspectives] What is an Algorithm? Let’s Demystify Algorithms and Artificial Intelligence (AI) [Pitchbook] Road to Next 2022 [Deloitte perspectives] An Auditor’s Mindset in an AI Driven World | Deloitte US [WSJ article] First Bias Audit Law Starts to Set Stage for Trustworthy AI 2021 [Deloitte perspectives] Applying COSO ERM framework principles to AI