Tightening AI policies can create the very risks they are designed to prevent, as employees turn to unapproved tools when approved options fall short. Dheren Singh argues that CFOs need fit-for-purpose AI, stronger controls and clear accountability rather than blanket restrictions.
One Saturday morning, a single trainee at a big 4 professional-services firm processed 59 million tokens through BringSpark AI.
I do not know whether that use breached the firm’s AI policy, and that is not the point. When people find a tool that helps them work faster, they use it. Finance professionals are no different.
That is a problem for CFOs. Many organisations manage AI risk by limiting staff to a short list of familiar tools. But if those tools are not fit for purpose, employees will find alternatives. The result is often the opposite of the policy’s intent: shadow AI, sensitive data in unapproved systems, and work produced outside of the control environment.
Finance can fail two ways: adopt AI without adequate controls or control it so tightly that people work around the controls.
The biggest AI risk in finance is the gap between policy and practice
King V’s Principle 10 places responsibility for governing technology and AI with the governing body, not simply with an approved policy. The consequences are becoming financially material.
In May 2026, US-listed CB Financial Services disclosed a material cybersecurity incident after non-public customer information was handled through an unauthorised AI application.
A finance employee does not need to “buy software” to introduce a new data processor. A free chatbot, browser extension, spreadsheet add-in or AI assistant can be adopted in minutes.
The answer is not to ban these tools. Staff use them because there is a job to be done.
A safer approach: understand which tools people need, approve fit-for-purpose options, define their data access, and monitor the environment. Governance should make the safe route the easiest route.
A big brand is not the same as the right tool
Another risk is tool mismatch, and it usually arrives through the path of least effort: switching on AI inside software the firm already pays for or accepting whatever tool a consultant already knows.
Generic AI is useful for drafting and summarising, but it is a weak substitute for accounting, tax or regulatory work. I have seen teams use it for forecasts that look excellent while the reasoning is thin.
That is dangerous: polished work can pass a superficial review. A consultant's recommendation rarely helps: advisors deploy what they can implement fast, not what the workflow requires.
A CFO should ask more than, “Is this an approved AI tool?” The better question is, “Is this tool suitable for this task, this data and this level of consequence?”
Human review is necessary, but it is not enough
Choosing the right tool is only part of the answer. Putting a human reviewer at the end of a flawed process does not automatically make it safe. “Human in the loop” has become the standard answer to AI risk. It can also create false comfort.
If the reviewer checks whether an answer sounds reasonable rather than whether the data supports it, there may be little control. AI is unusually good at producing confident, polished explanations.
In 2025, a Deloitte Australia report to a government department contained incorrect citations and errors prepared with generative AI. The department sought repayment of A$97,587 of its roughly A$439,000 contract.
South African regulators are alert to this problem. In May, Sarb deputy governor Fundi Tshazibana warned about firms sending regulators AI-generated material that had not been vetted. Her message was simple: “It is fine to work with AI but you have to check the results and take responsibility for the final product.”
For finance, that means material AI-assisted work should be traceable to evidence. A tax conclusion should link back to the relevant authority. Fit for purpose also means putting that work into action within the systems, processes and tools finance actually uses.
The best AI controls limit consequences
The risk grows as AI moves from answering questions to taking actions.
An assistant can draft a journal. An agent may eventually post it, change master data, send an email and initiate a payment workflow.
At that point, asking the model to “be careful” is not a control.
The strongest controls sit outside the AI. Limit permissions. Separate duties. Require independent approval for material actions. Keep immutable logs. Set transaction thresholds. An agent must not cross control boundaries a human employee never could.
COSO’s 2026 guidance on internal control over generative AI makes the point: existing principles still work but must recognise AI explicitly.
The risk of not adopting AI is real too
CFOs should not respond to these risks by slowing adoption to a crawl.
South Africa’s FSCA and Prudential Authority found 52 percent of surveyed banks were already using AI. Regulators globally see the same pattern. In April, Australia’s APRA warned that governance and risk management were not keeping pace with adoption, while noting that failing to embrace AI could itself be a strategic disadvantage.
That tension matters.
Organisations must solve both sides: make approved tools genuinely useful, while adding the controls and specialist context professional work needs.
The goal is not zero AI risk. That is neither realistic nor commercially sensible.
The goal is to know where AI is being used, what information it can see, what it can do, how its output is checked, and who remains accountable when it is wrong.
Picture that trainee again on a Saturday morning, 59 million tokens in, with no oversight. They were not trying to create a risk. They were trying to get work done, the way anyone does under a deadline, with no help.
The question is not whether that trainee will reach for AI. They already have. It is whether the organisation meets them with a tool built for the work and controls built for the consequences, or leaves them to work it out alone, one unmonitored prompt at a time.
The finance teams that get this right will not be the ones with the strictest AI policies. They will be the ones whose controls are strong enough to let their people use AI well.













