HomeResources › AI Governance
AI in Finance

AI Governance in Finance: Why CFO Confidence and Auditor Readiness Are Not the Same Thing

Two surveys published two days apart in July 2026 reveal a gap that will matter when external audit season arrives: having a governance framework is not the same as being able to produce evidence on demand.

By Azim Khan, FCMA · Updated 2026-06-27 · Finance Value Score by AIS

An AI governance framework is a policy. An AI audit trail is evidence. Right now, CFO confidence is attached to the first, and auditors will ask for the second. Two surveys published two days apart in July 2026 make that gap visible — and quantify how large it already is.

What did the two July 2026 surveys actually find?

Deloitte's Q2 2026 CFO Signals survey, covering 200 North American CFOs at companies with revenues above $1 billion, found that 96 per cent were somewhat or very confident in their company's AI governance framework. That is a striking number. The same survey found that 51 per cent of those CFOs reported insufficient governance authority, and 43 per cent reported inadequate visibility into the AI tools or usage operating inside their organisations. Deloitte published these figures together. That is the tell.

Two days later, Avalara published its Agents of Change survey, fielded across 1,505 CFOs and senior finance leaders in the UK, US, Australia and India — all of whom had deployed, piloted or evaluated AI agents. Forty-four per cent said they were only somewhat confident they could explain an AI agent's actions to an auditor. Thirty per cent had not updated their internal controls in the last twelve months. And 23 per cent said that accountability for a significant agent error would be unclear or would sit with no one.

Avalara sells compliance automation software, and it is worth stating plainly that these findings suit its commercial position. That does not make the data unusable. The survey's sample, fielding methodology and screening criteria are disclosed, the population is relevant, and the questions are specific enough to be instructive. Read it with appropriate scepticism about framing, but do not discard it.

Can both surveys be right at the same time?

Yes, because they are measuring different things. The Deloitte question, in effect, asks: does a policy exist? The Avalara question asks: can you produce evidence of what actually happened, on demand, under audit conditions? A finance function can have a comprehensive AI governance policy — approved by the board, signed off by the audit committee, referenced in the annual report — and still be unable to reconstruct the decision logic behind a single AI-generated journal entry. The policy describes intent. The audit trail demonstrates execution. These are not the same document, and they are not produced by the same process.

Deloitte's own numbers contain the diagnosis. It is not coherent for 96 per cent of CFOs to feel confident in their governance framework while 43 per cent simultaneously report inadequate visibility into AI tools or usage. Visibility is a prerequisite for governance. If you cannot see what the tools are doing, you cannot govern them — you can only assert that you have a policy that says you should. Confidence, in this context, is running ahead of capability.

Why does the distinction between framework and audit trail matter now?

External auditors are increasingly asking not just whether controls exist, but whether those controls are demonstrably operating as described. When an AI agent posts a consolidation entry, applies a revenue recognition threshold, or flags an intercompany balance for elimination, that action sits inside the financial statements. Auditors will want to understand what the agent saw, what rule it applied, what threshold it used, and who — if anyone — reviewed and approved the output before it became part of the close. Governance frameworks rarely answer those questions. Audit trails do.

The Avalara finding that 23 per cent of respondents could not clearly assign accountability for a significant agent error is particularly relevant here. Unclear accountability is not a governance failure in the abstract — it is a control deficiency that an auditor can point to. The question of who is responsible for an AI agent's material error is not philosophical; it is exactly the kind of question that surfaces in a management letter.

How should CFOs think about closing this gap?

The gap is not primarily a technology problem, though tooling matters. It is a process design problem. AI agents embedded in the close, in consolidation, in statutory reporting, and in forecasting need to produce legible outputs: what data they consumed, what logic they applied, what decision they made, and what human touchpoint — if any — sat between the agent's output and the ledger. Many current deployments do not produce this by default. Logging is treated as an IT concern rather than a finance control requirement.

The 30 per cent of Avalara's respondents who had not updated their internal controls documentation in the past year represent a specific and addressable risk. Controls documentation that predates AI agent deployment describes a finance function that no longer exists. That is a straightforward gap to close, and it is one that does not require waiting for a regulatory mandate.

What is one concrete test a CFO can run this week?

Take a single posting that an AI agent made last quarter — one entry, one consolidation adjustment, one flagged exception — and try to reconstruct four things: what the agent saw as its input, what decision it made and why, what threshold or rule it applied, and who approved it before it hit the ledger. If your team can answer all four questions from existing records within an hour, your audit trail is functional. If they cannot, you have located the gap. That is the honest test, and it takes less time to run than any governance review.

The Deloitte and Avalara surveys are measuring different anxieties. The Deloitte number reflects CFO confidence in a policy artefact. The Avalara number reflects CFO uncertainty about whether that policy is operationally real. Auditors will ask the Avalara question. It is worth knowing the answer before they do.

Common questions

What is the difference between an AI governance framework and an AI audit trail?

An AI governance framework is a policy document that describes how AI tools should be overseen, approved and used within a finance function. An AI audit trail is the contemporaneous evidence that those rules were actually followed — including what inputs an agent received, what logic it applied and who reviewed its output. Deloitte's Q2 2026 CFO Signals survey found 96 per cent of CFOs confident in their governance framework, while Avalara's Agents of Change survey found 44 per cent only somewhat confident they could explain an agent's actions to an auditor; the divergence illustrates that the two things are not equivalent.

How confident are CFOs in their AI governance frameworks according to recent surveys?

Deloitte's Q2 2026 CFO Signals survey of 200 North American CFOs at companies with revenues above $1 billion found that 96 per cent were somewhat or very confident in their company's AI governance framework. However, the same survey found that 51 per cent reported insufficient governance authority and 43 per cent reported inadequate visibility into AI tools or usage — suggesting that confidence in the framework is running ahead of operational control.

What proportion of finance leaders can explain an AI agent's actions to an auditor?

Avalara's Agents of Change survey, published in July 2026 and covering 1,505 CFOs and senior finance leaders across the UK, US, Australia and India, found that 44 per cent were only somewhat confident they could explain an AI agent's actions to an auditor. A further 23 per cent said that accountability for a significant agent error would be unclear or would sit with no one.

How many finance functions have updated their internal controls to reflect AI agent deployment?

Avalara's Agents of Change survey found that 30 per cent of respondents had not updated their internal controls documentation in the previous twelve months, despite all respondents having deployed, piloted or evaluated AI agents. Controls documentation that predates AI agent deployment describes a finance function that no longer exists, which represents a specific and addressable audit risk.

What should a CFO do to test whether their AI audit trail is fit for purpose?

A practical test is to take a single posting made by an AI agent last quarter and attempt to reconstruct four things from existing records: what the agent saw as its input, what decision it made, what threshold or rule it applied, and who approved the output before it hit the ledger. If the finance team cannot answer all four questions within an hour, the audit trail has a gap that needs addressing before external audit.

Keep going