Connect with us

Accounting

No AI disclosure rules doesn’t mean no AI disclosures at all

Published

on

Though the Securities and Exchange Commission has yet to issue regulations specific to AI, this doesn’t mean companies are off the hook when it comes to disclosures, as the technology’s use can easily be slotted into other, already existing requirements. 

Speaking today at a virtual conference hosted by Financial Executives International, Scott Lesmes, partner in charge of public company advisory and governance with law firm Morrison Foerster, noted that there are many risks that come with AI including false or misleading information, data breaches, cyberattacks, intellectual property risk and much more. He said people need to be taking these risks seriously.

“These mistakes are in the real world and have had significant consequences,” he said. 

He pointed to a case where a chatbot advised small business owners that it was legal to fire people for complaining about sexual harassment, which is absolutely is no. He also referred to another case where a real estate company was forced to take a $300 million writeoff for relying on a faulty AI algorithm for property pricing decisions, and another where an AI model used by hospitals to determine which patients are high risk and need extra care was found to be biased against Black people, as it was far less likely to identify them. 

Incidents like this underscore the need for robust AI governance. He noted that there has been a rise in companies forming cross-disciplinary AI governance committees encompassing finance, legal, product, cybersecurity, compliance and in some cases HR and marketing; failing that, he has also seen companies add AI oversight on the duties of existing committees. While some companies have established dedicated AI departments, more commonly they have been giving AI oversight duties to the Chief Information Security Officer or other relevant c-suite position. 

He also noted that there has been a dramatic increase in board supervision of AI, saying that in the most recent 10-K season there was a lot of clients who added “Oversight of AI” in terms of what the board was responsible for; while it was a small percentage, he was certain it was going to increase over time. He has also found that many boards either designate a single AI expert who handles such matters or place the responsibility on either already-existing technology committees or (more commonly) audit committees. 

“There is certainly a tension, audit committees already have such a full plate, so adding another responsibility, especially with such a broad mandate, can be a little unsettling but that is where many companies are putting this, if they handle it on the board level. Audit committee does make some sense, because it is very focused on internal controls as well as compliance,” he said. 

Boards generally need to consider the legal and regulatory factors that may impact operations, and just like how many have management frameworks for oversight, so too should there be AI frameworks for how the board fulfills these responsibilities. In executing these duties, boards needs to understand the critical AI uses and risks in the company, how they integrate with business processes, what is the nature of the AI system, how does the company mitigate risk, how oversight responsibility is divided between board and management, as well as any material AI incidents. 

“The board does not need to know about every AI incident altogether, there needs to be a level of understanding of what’s important enough to share and what’s not. The board should understand the material incidents, how the company responded and the material impact,” he said. 

SEC Disclosures

Ryan Adams, another Morrison Foerster partner in the same practice area, noted that even though regulators like the Securities and Exchange Commission have yet to issue specific rules or guidance around AI, they have stressed the importance of complying with existing obligations, which may or may include disclosures regarding the company’s use of AI and its impact, particularly where it concerns business operations. Already companies need to report material risks and changes in their filings, and as AI further embeds itself into the global economy, it will almost certainly be a factor. 

Further, companies should not be making false claims or misleading potential investors in general, and this applies to AI as well. He noted that the government has been especially interested in “AI washing,” that is exaggerating, or making false claims about the company’s AI capabilities or use. He pointed to one example where the SEC brought charges against the CEO and founder of a startup who said they had a proprietary AI system that could help clients find job candidates from diverse backgrounds, but this AI did not in fact exist. He pointed out that this didn’t even involve a public company, just a private one that was trying to raise investment capital. 

“So it makes clear that the SEC will scrutinize all AI-related claims made by any company, public or private, trying to get investors to raise capital,” he said. 

He added that AI washing can be thought of very similarly to inflating financial results or just making up the numbers entirely. Also, just as an entity should not overstate the capacities of their AI systems, the same has already applied for automation technology in general. Regulators want clear and candid disclosures about how a company uses AI and how it presents material risks. In this regard, he also warned against generic or boilerplate disclosures regarding AI. 

“Regardless of the type of company you are, you have to take this seriously. Anyone touting the benefits of AI with customers or the public needs to make sure what they say is truthful and accurate and can be substantiated, or risk potential legal consequences,” he said. 

It is important to keep materiality in mind. Neither investors nor regulators want to read a list of every conceivable AI-related risk a company faces when only one or two are relevant. He conceded that this might require slightly different thinking, as accountants tend to lean on quantitative factors to assess materiality, but AI can also carry qualitatively material factors as well. There is the risk that AI could inadvertently breach confidentiality agreements through sensitive information in the training data, it could completely disrupt traditional business functions if used properly or completely disrupt new ones if used improperly, there is the risk of being unable to find the experts needed to properly monitor an AI system, there could be third party fees for things like data storage or increased energy use, AI can disrupt competitive dynamics in the market, there could be ethical risk like the aforementioned racist algorithm, and legal or regulatory risks. 

“You could go on forever with these AI risks…  Just because you use AI and a risk is potential does not necessarily mean disclosure is appropriate. You need to spend time thinking about whether AI-related risks are appropriate to disclose and if they are they should be narrowly tailored to describe the material risk,” he said. 

When assessing materiality, he said to go with the same standard accountants have been using for ages: is there a substantial likelihood a reasonable investor would consider this information important to determine whether to buy, sell or hold a security. Where AI introduces a slight wrinkle is that, given the pace of change in the field, it is important for companies to review and reevaluate their risk factors every quarter. 

But risks are not the only thing one should disclose. Adams noted that companies should also consider AI impacts when drafting management discussion and analysis or the executive overview, painting out major developments or initiatives or milestones related to the technology. AI could also come up in discussions of capital expenditures, if the entity made big AI investments that are material and known to the business, that needs to be disclosed. Another area AI plays into is cybersecurity disclosures, which already has a number of SEC requirements around it. The two topics, he said, often go hand in hand, so if AI interacts with cybersecurity in any way it might be worth disclosing. 

Overall, Adams recommended companies fully and accurately disclose their AI use; avoid overly vague or generic language given AI’s wide variations; avoid exaggerated claims around what your AI is capable of doing, taking care especially not to discuss capacities in terms of hypotheticals; be specific about the nature and extent of how the entity is using AI and the role AI plays in business operations; have a good understanding of vendors and other third parties who use AI, as their risks could ripple outwards; establish, or at least begin to establish, an AI governance framework; train the staff in AI so they can understand what it can and cannot do; actively monitor company AI usage; regularly update stakeholders on changes, progress and improvements in company AI use; and have either the legal department or outside counsel review any public statements or marketing materials mentioning AI. 

While the current administration has emphasized a less regulated approach to AI, Adams noted that the SEC is still active in its dialogues with the business community around potential regulation, mentioning a recent meeting with the investment advisor community as well as a strategy roundtable with the financial services community. 

“The big takeaway here is that both the SEC and industry are saying ‘we want to have active and ongoing communications as this develops’ … any regulations we do see, if any, in the future [will be] informed by what is actually happening in the marketplace,” he said.

Continue Reading

Accounting

AI-Driven Automation and Continuous Accounting Frameworks

Published

on

The accounting profession is undergoing a fundamental structural transition as enterprise finance departments shift from periodic month-end closes toward automated continuous accounting models. By integrating specialized machine learning algorithms directly into enterprise resource planning (ERP) platforms, chief accounting officers are transforming financial reporting from a retrospective exercise into a real-time operational asset.

The Shift from Periodic Close to Continuous Financial Reporting
Traditional accounting workflows heavily relied on manual data reconciliation, spreadsheet calculations, and multi-week closing cycles at the end of each fiscal period. In contrast, continuous accounting frameworks utilize automated software agents to process, validate, and post transactional data in real time as business activities occur.

Automated bank reconciliation tools cross-reference incoming bank feeds, invoice records, and purchase orders automatically. By resolving transactional variances instantly throughout the month, corporate accounting teams eliminate the traditional workload spikes associated with quarterly and annual closes.

Machine Learning in Audit Trails and Anomaly Detection
Advanced natural language processing (NLP) and machine learning tools are redefining internal audit and financial control environments. Automated systems analyze 100% of general ledger entries, identifying anomalous transactions, duplicate payments, and unauthorized journal entries in real time.

Rather than relying on random statistical sampling, corporate internal auditors can focus their attention on high-risk flags automatically surfaced by algorithmic monitoring platforms. This continuous risk assessment strengthens internal controls over financial reporting (ICFR) and significantly reduces fraud risk.

Evolving Roles for Accounting Professionals
As routine data entry and manual reconciliation tasks become fully automated, the skill set required for accounting professionals is shifting toward data analysis, system design, and strategic business advisory.
– Systems Governance: Accountants are increasingly responsible for monitoring algorithmic accuracy and managing data integration pipelines.
– Business Partnership: Finance professionals leverage real-time financial dashboards to advise operational leaders on margin management and working capital allocation.
– Regulatory Compliance Management: Accounting teams utilize automated platforms to ensure compliance with dynamic tax codes and international accounting standards.

Core Implementation Recommendations
1. Deploy Automated Reconciliation Tools: Integrate continuous transaction processing modules into existing enterprise ERP architectures.
2. Establish Algorithmic Governance Controls: Implement strict internal testing protocols to ensure automated accounting rules comply with GAAP/IFRS standards.
3. Reskill Accounting Teams: Invest in training finance staff on data analytics, workflow automation, and predictive financial modeling.

Continue Reading

Accounting

Global ESG Reporting Standards and Double Materiality Compliance

Published

on

Corporate accounting departments face expanding reporting expectations as international sustainability disclosure standards achieve regulatory enforcement across major global jurisdictions. Chief Accounting Officers (CAOs) and corporate controllers are establishing rigorous internal accounting controls to treat Environmental, Social, and Governance (ESG) metrics with the same data precision, auditability, and governance as traditional financial statements.

Regulatory Harmonization Under Global Sustainability Frameworks
The implementation of standardized sustainability reporting frameworks—notably rules established by international sustainability accounting boards—has created unified expectations for public and large private enterprises. Corporations must report standardized metrics covering greenhouse gas emissions (Scope 1, 2, and material Scope 3), energy utilization, workforce demographics, and supply chain governance.

In Europe and other participating international jurisdictions, double materiality principles are mandatory. Under double materiality, organizations must report both how external sustainability risks impact corporate financial performance, and how internal corporate operations affect surrounding environmental and social structures.

Integrating Sustainability Metrics into Core ERP Systems
To provide auditable non-financial data, enterprise organizations are integrating specialized carbon accounting and ESG management platforms directly into core ERP systems. Automated data collectors capture energy utility invoices, logistics fuel consumption metrics, and vendor compliance records in real time.

Establishing automated, traceable data pipelines ensures that non-financial reporting is supported by clear audit trails. This structured approach allows external financial auditors to provide reasonable assurance on sustainability disclosures during annual corporate reporting cycles.

Financial Impacts and Capital Market Disclosure
Accurate ESG reporting directly influences corporate cost of capital and institutional credit ratings. Commercial lenders and institutional asset managers systematically incorporate sustainability metrics into risk pricing models. Companies that demonstrate transparent, verifiable progress in operational energy efficiency and climate risk mitigation benefit from expanded access to green bond markets and lower debt pricing.

Action Steps for Accounting Leadership
1. Implement Double Materiality Frameworks: Conduct comprehensive assessments to identify material financial and operational sustainability metrics.
2. Build Auditable Non-Financial Data Pipelines: Automate ESG data collection within core accounting software to ensure data integrity.
3. Align Sustainability with Annual Financial Filings: Prepare non-financial disclosures concurrently with financial statements to satisfy regulatory audit expectations.

Continue Reading

Accounting

Modernizing Internal Controls: Machine Learning and Continuous Monitoring in Auditing

Published

on

Internal audit departments and corporate risk managers are modernizing internal control frameworks by shifting from periodic sampling techniques to continuous monitoring and machine learning analytics. As operational data volumes increase across enterprise organizations, automated control testing ensures financial integrity, prevents corporate fraud, and streamlines annual audit engagements.

The Limitation of Periodic Audit Sampling
Historically, internal and external auditors evaluated internal controls by reviewing random samples of financial transactions—often analyzing less than five percent of total ledger entries. In complex enterprise environments, periodic sampling methods carry inherent risks of overlooking localized financial misstatements, unauthorized disbursements, or operational control breakdowns.

In 2026, progressive internal audit functions are utilizing automated continuous monitoring platforms that evaluate one hundred percent of financial transactions in real time. Continuous control auditing systems continuously monitor general ledger entries, procurement approvals, and expense reimbursements across all operating subsidiaries.

AI-Powered Fraud Detection and Anomaly Identification
Machine learning models trained on historical corporate financial data excel at identifying subtle transactional anomalies that indicate potential fraud or operational error. Automated systems instantly flag duplicate invoice payments, unapproved vendor creation, unusual journal entry timing, and unauthorized override of authority thresholds.

When an anomaly is detected, the automated auditing platform generates an instant risk alert, allowing internal audit teams to investigate root causes immediately. Early detection prevents minor operational errors from escalating into material weaknesses in financial reporting.

Streamlining External Audit Preparation
Continuous internal control monitoring delivers significant benefits during annual external financial audits. External audit firms can review continuous audit logs and automated control testing documentation, reducing the time required for manual field testing.

This integrated approach lowers overall audit compliance fees, reduces administrative burdens on corporate accounting staff, and provides senior management and audit committees with real-time visibility into the organization’s overall risk profile.

Core Implementation Guidelines
1. Transition to 100% Data Testing: Replace legacy sampling methods with automated continuous audit monitoring systems.
2. Deploy Anomaly Detection Algorithms: Implement machine learning models to identify unauthorized transactions and operational control overrides.
3. Align Internal and External Audit Workflows: Coordinate continuous control testing protocols with external auditors to optimize annual compliance cycles.

Continue Reading

Trending