top of page
Search

The AI Risk Your Controls Are Designed to Miss

  • clydecalhoun
  • Jun 19
  • 3 min read

Here's a number that should concern every CFO.


In a global study of 48,000 people, 57% admitted they present AI-generated work as their own. Another 66% said they don't consistently verify whether that output is accurate.


Here's a number that should concern every CFO.

Put those numbers together and a troubling reality emerges. More than half your workforce is incorporating AI into their work without disclosing it, and most of them aren't validating the results before they use them. The forecast, estimate, recommendation, or analysis that reaches your desk still looks like human judgment. Increasingly, it isn't.


The significance of those numbers isn't employee behavior. It's what that behavior means for decision quality and oversight.


And this is no longer theoretical.


In an EY survey of C-suite leaders at large enterprises, nearly every organization reported experiencing a financial loss tied to AI-related risks. Among those reporting losses, the average impact was a conservative $4.4 million. At enterprise scale, this exposure isn't coming. It's already here, often buried inside operational issues, forecasting misses, reporting errors, customer impacts, or decisions that simply didn't produce the expected outcome.


This breaks something most finance leaders assume is solid: their controls.

Most internal controls are built on a quiet assumption that judgment originates with a person. Someone builds the forecast, someone reviews it, and someone approves it. The control fires at each handoff and the system works exactly as designed.


AI didn't replace that chain.


It slipped in front of it.


The forecast now arrives already shaped by a model nobody named and built on assumptions your FP&A team never set. Your reviewer signs off. The audit trail shows clean human approval at every step. The control fires perfectly. Yet it may be evaluating a judgment that was substantially influenced before any human reviewer became involved.


That's the trap.


Your controls aren't failing. They're doing exactly what they were designed to do. The problem is that most internal controls were designed to evaluate and document human judgment. AI introduces a new source of judgment that often enters the process before those controls engage.


The control still fires. The approval still happens. The documentation still exists. But the most important decision may have already been influenced by a system that no one evaluated, challenged, or documented.


A passing control feels like safety. Right now, it may be measuring the wrong moment.

So here's the question every CFO should be asking: where is AI already influencing decisions that matter? Not where AI has been formally approved. Not where IT has deployed a tool. Where is AI actually shaping forecasts, pricing decisions, financial analyses, customer communications, operational recommendations, and management reporting?


Most organizations know their employees are using AI. Far fewer know where, how often, and in which decisions AI is influencing outcomes.


That's the visibility gap.


Start with one question, asked across the handful of decisions that cross your materiality threshold: by the time this number reaches a human, what has already shaped it? Not "do we have an AI tool," but what touched the input before anyone reviewed it, including the AI already embedded in the systems you run, your ERP, your planning tools, your CRM.


An afternoon gets you a rough first cut. A map that holds up to the board takes weeks, because the exposure sits in places no one labeled as AI. Either way, the gap is already there, and right now it's running unmeasured.


The organizations that get ahead of this won't necessarily be the ones that adopt AI the fastest. They'll be the ones that develop a clear understanding of where AI is already influencing business decisions.


Because a control can fire perfectly and still miss the risk it was never built to see.

If you’d like to learn more about AI decision governance and what steps you need to take specifically for your organization, schedule a discovery call, and let’s talk.


About Root Idea

Root Idea helps CFOs protect the business from AI decision risk. Root Idea works directly alongside finance teams to map AI influence, establishes decision governance controls that hold up to board scrutiny, and delivers training and change management to make governance stick. 

If your organization is scaling AI and governance hasn't kept pace, that's exactly the conversation we're built for. Learn more at rootidea.ai.



 
 
 

Comments


bottom of page