AI Agent Governance for Finance Teams: Where to Start

Oracle and SAP now ship finance agents inside the ERP. Here is how CFOs govern them using COSO’s roadmap.

AI agent governance controls for finance teams

AI agent governance starts with treating each agent as a user with its own identity, permissions and audit trail. The Committee of Sponsoring Organizations of the Treadway Commission (COSO), whose framework most US-listed companies use to assess internal control, set out a six-step sequence in February 2026: govern, inventory, assess, design, implement and monitor. The first job is finding which agents are already live.

Why AI agent governance is now a finance problem

AI agents have moved from pilots into the enterprise resource planning (ERP) systems finance teams already run. Oracle’s Fusion ERP release 26B, detailed by the company in June 2026, includes four: a Ledger Agent, an Expenses Agent, a Payables Agent and a Payments Agent.

The Oracle Payables Agent converts emails, PDFs, spreadsheets and scanned invoices into standard workflows and flags duplicate invoices, according to the company. The Payments Agent helps decide when to pay suppliers and where early payment discounts apply.

SAP is releasing finance agents in phases across the second and third quarters of 2026, covering close, planning, billing, receivables, tax and treasury. Its close agent automates postings and reconciliations and resolves discrepancies, the company says.

Workday’s Accounting Agent reconciles accounts continuously against live transactions and assembles audit evidence as it works, according to Workday. The company reports customers have saved 450 hours a year on audit evidence and cut accounts payable invoice lifecycle time by 75%.

These agents sit inside processes that feed the financial statements. That places them within the scope of internal control over financial reporting (ICFR), including Section 404 of the Sarbanes-Oxley Act (SOX 404) for US registrants.

The control risks specific to AI agents

An AI agent differs from an analytics tool because it acts. The GenAI Security Project of the Open Worldwide Application Security Project (OWASP), a non-profit security foundation, published its Top 10 for Agentic Applications in December 2025. Four of its risks map directly onto finance processes.

Goal hijack (ASI01). A payables agent reads supplier documents. Instructions embedded in an invoice or email can redirect what the agent does, such as changing remittance details or clearing a payment it should flag.

Identity and privilege abuse (ASI03). Agents often run under service accounts. If one account can both create and approve a transaction, segregation of duties fails even where every human role is set up correctly.

Cascading failures (ASI08). Agents increasingly hand work to one another. A payables agent that miscodes an invoice passes the error to a payments agent, and the error can reach cash before anyone reviews it.

Human-agent trust exploitation (ASI09). Agents present output with confident, well-reasoned explanations. Reviewers who rely on those explanations can approve a harmful action through a review step that still exists on paper.

Model changes add a fifth risk. A vendor can update the model behind an agent without the customer changing any configuration, altering behaviour inside a control that was tested on the earlier version.

The frameworks behind AI agent governance

COSO is a joint initiative of five US professional bodies: the American Accounting Association, the American Institute of Certified Public Accountants, Financial Executives International, the Institute of Internal Auditors and the Institute of Management Accountants. Its Internal Control Integrated Framework, last updated in 2013, is the benchmark auditors test ICFR against.

FrameworkStatusWhat it coversBest suited to
COSO, Achieving Effective Internal Control Over Generative AIPublished February 23, 2026Maps AI risks onto COSO’s 17 internal control principles, with a six-step roadmapFinance teams with ICFR or SOX 404 obligations
US National Institute of Standards and Technology (NIST) AI Risk Management Framework 1.0Published January 2023, voluntaryGovern, map, measure and manage functions for AI riskGroups setting enterprise-wide AI risk policy
ISO/IEC 42001:2023Published December 2023, certifiableA management system for developing, providing and using AIGroups wanting third-party certification
EU AI ActAnnex III high-risk obligations apply from December 2, 2027Risk-tiered legal obligations for AI systems in the EU marketGroups with EU operations, customers or staff

The COSO guidance sorts generative AI into eight capability categories, each with its own risk profile. Two cover agents directly: automated transaction processing and reconciliation, and workflow orchestration and autonomous task execution.

ISO/IEC 42001, issued by the International Organization for Standardization and the International Electrotechnical Commission, certifies an organisation’s AI management system, not individual products. The EU AI Act’s Annex III deadline moved from August 2026 to December 2027 under the Digital Omnibus on AI, Regulation (EU) 2026/1744, published in the Official Journal of the European Union on July 24, 2026.

How to start AI agent governance in six steps

The six steps follow the COSO roadmap, applied to agents acting in finance systems.

Govern. Name one accountable owner per agent, usually the process owner rather than IT. Decide which committee holds the agent register and reports on it to the board.

Inventory. List every agent touching finance data, including those enabled through ERP release updates. Record the process, the data each agent reads, the systems it writes to and the account it runs under.

Assess. Rate each agent by what it can do without a person. An agent that answers ledger queries carries less risk than one that schedules supplier payments.

Design. Give each agent its own identity, never a shared service account. Set value thresholds above which a person approves, matching the existing approval matrix. COSO lists access restrictions, input validation, prompt governance, output validation, logging and drift monitoring as the core control building blocks.

Implement. Switch agents on process by process, starting with read-only use. Run each agent in parallel with the existing process for at least one close cycle before it acts alone. Keep the parallel-run results as evidence for external auditors.

Monitor. COSO calls for continuous monitoring rather than one-off approval. It points to indicators such as transaction volume, transaction size and override rates, where a sudden shift signals a change in agent behaviour. Re-test the control whenever the vendor changes the underlying model.

What external auditors will test on AI agents

External auditors reach AI agents through IT general controls. Access, change management and operations are tested on any system that feeds the financial statements, and an agent is no exception.

Access testing asks who, or what, can post, approve and change master data. An agent sharing a service account with a human user creates a segregation of duties finding.

Change management covers model updates as well as configuration changes. Auditors look for evidence that the finance team knew when the vendor changed the model and re-tested the affected controls.

Agent output used in a control, such as an exception report from a reconciliation agent, counts as information produced by the entity. Auditors test its completeness and accuracy before relying on the review that uses it.

What to ask vendors about agent controls

Vendor answers determine how much AI agent governance the finance team has to build itself. Ask before the feature is switched on, since agents increasingly arrive in routine ERP release updates.

  • Does each agent run under its own identity, with permissions the customer configures?
  • Which actions can the agent take without approval, and can value thresholds be set?
  • What does the agent log, for how long, and can logs be exported for audit?
  • How does the agent handle instructions embedded in documents it processes?
  • Does the vendor notify customers before changing the underlying model?
  • Can the customer pause an agent, or keep it on the previous model version?
  • Does the vendor hold ISO/IEC 42001 certification or a System and Organization Controls (SOC) report covering its AI features?