HomeResourcesAI in finance › AI Governance
AI in Finance

AI Governance in Finance: Why CFO Confidence and Auditor Readiness Are Not the Same Thing

Two surveys published two days apart in July 2026 reveal a gap that will matter when external audit season arrives: having a governance framework is not the same as being able to produce evidence on demand.

By Azim Khan, FCMA · Updated 2026-09-01 · Finance Value Score by AIS

An AI governance framework is a policy. An AI audit trail is evidence. Right now, CFO confidence is attached to the first, and auditors will ask for the second. Two surveys published two days apart in July 2026 make that gap visible - and quantify how large it already is.

What is an AI audit trail in a finance function, and what must it capture?

An AI audit trail in a finance function is the contemporaneous, retrievable record of every action an AI agent takes that touches the ledger, the close, consolidation, forecasting or statutory reporting. It is not a policy and it is not a log file held by IT. It is evidence, in the sense that an auditor or a regulator uses that word: something you can produce on demand that demonstrates what actually happened, not what your governance framework says should have happened.

For every AI-generated action, a functional audit trail must capture four things. First, the input the agent saw: the data, the balance, the intercompany figure, or the exception that triggered its reasoning. Second, the rule or threshold it applied: the logic, limit or condition that drove the decision, expressed clearly enough that a finance professional can read it without specialist assistance. Third, the decision it made: the posting, the adjustment, the flag, or the rejection, recorded at the moment it occurred. Fourth, the human review and approval that sat between the agent's output and the ledger: who saw the output, when, and whether they approved, queried or overrode it - and if no human touchpoint existed, that fact must itself be recorded and evidenced as a designed control rather than an oversight. The record must be held somewhere retrievable, for a retention period that matches your audit and regulatory obligations.

That is the standard the rest of this article argues for. The survey evidence below shows how far short of it most finance functions currently fall.

What did the two July 2026 surveys actually find?

Deloitte's Q2 2026 CFO Signals survey, covering 200 North American CFOs at companies with revenues above $1 billion, found that 96 per cent were somewhat or very confident in their company's AI governance framework. That is a striking number. The same survey found that 51 per cent of those CFOs reported insufficient governance authority, and 43 per cent reported inadequate visibility into the AI tools or usage operating inside their organisations. Deloitte published these figures together. That is the tell.

Two days later, Avalara published its Agents of Change survey, fielded across 1,505 CFOs and senior finance leaders in the UK, US, Australia and India - all of whom had deployed, piloted or evaluated AI agents. Forty-four per cent said they were only somewhat confident they could explain an AI agent's actions to an auditor. Thirty per cent had not updated their internal controls in the last twelve months. And 23 per cent said that accountability for a significant agent error would be unclear or would sit with no one.

Avalara sells compliance automation software, and it is worth stating plainly that these findings suit its commercial position. That does not make the data unusable. The survey's sample, fielding methodology and screening criteria are disclosed, the population is relevant, and the questions are specific enough to be instructive. Read it with appropriate scepticism about framing, but do not discard it.

Can both surveys be right at the same time?

Yes, because they are measuring different things. The Deloitte question, in effect, asks: does a policy exist? The Avalara question asks: can you produce evidence of what actually happened, on demand, under audit conditions? A finance function can have a comprehensive AI governance policy - approved by the board, signed off by the audit committee, referenced in the annual report - and still be unable to reconstruct the decision logic behind a single AI-generated journal entry. The policy describes intent. The audit trail demonstrates execution. These are not the same document, and they are not produced by the same process.

Deloitte's own numbers contain the diagnosis. It is not coherent for 96 per cent of CFOs to feel confident in their governance framework while 43 per cent simultaneously report inadequate visibility into AI tools or usage. Visibility is a prerequisite for governance. If you cannot see what the tools are doing, you cannot govern them - you can only assert that you have a policy that says you should. Confidence, in this context, is running ahead of capability.

Why does the distinction between framework and audit trail matter now?

External auditors are increasingly asking not just whether controls exist, but whether those controls are demonstrably operating as described. When an AI agent posts a consolidation entry, applies a revenue recognition threshold, or flags an intercompany balance for elimination, that action sits inside the financial statements. Auditors will want to understand what the agent saw, what rule it applied, what threshold it used, and who - if anyone - reviewed and approved the output before it became part of the close. Governance frameworks rarely answer those questions. Audit trails do.

The Avalara finding that 23 per cent of respondents could not clearly assign accountability for a significant agent error is particularly relevant here. Unclear accountability is not a governance failure in the abstract - it is a control deficiency that an auditor can point to. The question of who is responsible for an AI agent's material error is not philosophical; it is exactly the kind of question that surfaces in a management letter.

How should CFOs think about closing this gap?

The gap is not primarily a technology problem, though tooling matters. It is a process design problem. AI agents embedded in the close, in consolidation, in statutory reporting, and in forecasting need to produce legible outputs: what data they consumed, what logic they applied, what decision they made, and what human touchpoint - if any - sat between the agent's output and the ledger. Many current deployments do not produce this by default. Logging is treated as an IT concern rather than a finance control requirement.

The 30 per cent of Avalara's respondents who had not updated their internal controls documentation in the past year represent a specific and addressable risk. Controls documentation that predates AI agent deployment describes a finance function that no longer exists. That is a straightforward gap to close, and it is one that does not require waiting for a regulatory mandate.

What is one concrete test a CFO can run this week?

Take a single posting that an AI agent made last quarter - one entry, one consolidation adjustment, one flagged exception - and try to reconstruct four things: what the agent saw as its input, what decision it made and why, what threshold or rule it applied, and who approved it before it hit the ledger. If your team can answer all four questions from existing records within an hour, your audit trail is functional. If they cannot, you have located the gap. That is the honest test, and it takes less time to run than any governance review.

The Deloitte and Avalara surveys are measuring different anxieties. The Deloitte number reflects CFO confidence in a policy artefact. The Avalara number reflects CFO uncertainty about whether that policy is operationally real. Auditors will ask the Avalara question. It is worth knowing the answer before they do.

Common questions

What is an AI audit trail in finance?

An AI audit trail in a finance function is the contemporaneous, retrievable record of every action an AI agent takes that touches the ledger or financial reporting. For each AI-generated action it must capture: the input the agent saw, the rule or threshold it applied, the decision it made, and the human review and approval that sat between its output and the ledger - along with where that record is held and for how long. It is evidence of what actually happened, not a policy describing what should happen.

What is the difference between an AI governance framework and an AI audit trail?

An AI governance framework is a policy document that describes how AI tools should be overseen, approved and used within a finance function. An AI audit trail is the contemporaneous evidence that those rules were actually followed - including what inputs an agent received, what logic it applied and who reviewed its output. Deloitte's Q2 2026 CFO Signals survey found 96 per cent of CFOs confident in their governance framework, while Avalara's Agents of Change survey found 44 per cent only somewhat confident they could explain an agent's actions to an auditor; the divergence illustrates that the two things are not equivalent.

How confident are CFOs in their AI governance frameworks according to recent surveys?

Deloitte's Q2 2026 CFO Signals survey of 200 North American CFOs at companies with revenues above $1 billion found that 96 per cent were somewhat or very confident in their company's AI governance framework. However, the same survey found that 51 per cent reported insufficient governance authority and 43 per cent reported inadequate visibility into AI tools or usage - suggesting that confidence in the framework is running ahead of operational control.

What proportion of finance leaders can explain an AI agent's actions to an auditor?

Avalara's Agents of Change survey, published in July 2026 and covering 1,505 CFOs and senior finance leaders across the UK, US, Australia and India, found that 44 per cent were only somewhat confident they could explain an AI agent's actions to an auditor. A further 23 per cent said that accountability for a significant agent error would be unclear or would sit with no one.

How many finance functions have updated their internal controls to reflect AI agent deployment?

Avalara's Agents of Change survey found that 30 per cent of respondents had not updated their internal controls documentation in the previous twelve months, despite all respondents having deployed, piloted or evaluated AI agents. Controls documentation that predates AI agent deployment describes a finance function that no longer exists, which represents a specific and addressable audit risk.

What should a CFO do to test whether their AI audit trail is fit for purpose?

A practical test is to take a single posting made by an AI agent last quarter and attempt to reconstruct four things from existing records: what the agent saw as its input, what decision it made, what threshold or rule it applied, and who approved the output before it hit the ledger. If the finance team cannot answer all four questions within an hour, the audit trail has a gap that needs addressing before external audit.

More in this series

Keep going