Automation Risk in Finance: Internal Controls Every CFO Should Review
Originally published on August 25, 2026
When you automate a process that has an error in it, the error doesn’t go away. It just moves faster. That’s the part a lot of finance teams miss when they start automating, and it’s why internal controls need to keep pace with every workflow a CFO hands off to a machine.
Why Automation Risk Deserves Its Own Category
Finance departments have gotten comfortable running risk assessments for financial reporting. Automation risk asks a related but different question, which is how much oversight a given automated process needs given what could go wrong and how easily anyone would notice. The NIST AI Risk Management Framework, released in 2023 and updated since, gives any organization, not just banks or tech companies, a structure for managing this kind of risk across the full lifecycle of an AI or automation tool.
The stakes are real because less human review means an error has more room to run before anyone catches it. A manual process gets checked by the person doing it. An automated one only gets checked as often as someone built a check into it. If that check doesn’t exist, or exists but nobody is watching it, the automation is quietly generating the same problem at a much higher volume than a person ever could.
The Mistake Most CFOs Make First
The typical starting point for automation is the wrong one. Teams ask what they can automate or where they can apply AI, when the better starting point is naming the pain point first. What’s taking too long. What has too many errors. What’s standing in the way of a business metric the team already cares about. Once that’s identified, there’s a real basis for assessing risk and estimating return.
The next mistake follows close behind, which is skipping the baseline. If a team automates something and assumes it’s faster without measuring the “before,” there’s no way to know if it actually worked. A useful baseline is often a combination of metrics rather than one number. A team that processes 20 invoices a day at close to full accuracy and wants to get to 30 a day needs to know whether that increase in volume comes with a drop in accuracy they’re not willing to accept. Without that baseline, automation gets judged on a feeling instead of a result.
Detection Risk and Impact Risk
Once a process is a real automation candidate, the next step is mapping it out and identifying the specific bottleneck worth automating, rather than pushing to automate an entire process end to end. Full end-to-end automation tends to introduce more risk than it removes. It’s also worth asking whether the process itself needs to change before anything gets automated, since automating a flawed process just produces the same flaws faster.
From there, the real risk assessment comes down to two questions we’ve built into a scoring approach called the DIO model. The first is detection risk, meaning how easily anyone would notice if the automated process started producing bad output. A gross margin that’s supposed to sit in a certain range is easy to monitor, so if it drops below a threshold, that’s a clear signal to look at the automated process behind it. A reconciliation against a control total works the same way, since a dropped or duplicated line item will show up as a mismatch almost immediately. Something more subjective, like a loan eligibility determination or a hiring recommendation, is much harder to check for correctness, which pushes detection risk higher.
The second question is impact, meaning what happens if a bad output slips through undetected. A minor formatting error is a low-impact problem. Something that could cause financial harm, or harm to a person, is a high-impact problem regardless of how rare it is. High detection risk paired with high impact is where a CFO needs the most oversight. Low risk on both fronts is where automation can run with a lighter touch.
Internal Controls That Scale With the Risk
Once the risk level is understood, the controls need to match it. That mirrors how finance already runs an internal controls risk assessment for financial reporting, just applied with more attention to the specific mechanics of an automated process. COSO’s guidance on internal control over generative AI reinforces the same point, extending its existing internal control framework to cover the newer risks that come with AI-driven processes rather than treating AI as something that needs an entirely separate governance model.
In practice, that means documenting the risk assessment and keeping it current, defining what the control is, and confirming the control is happening the way it’s supposed to. If a control calls for someone to review a sample of transactions each month, there needs to be evidence that review is happening, not just a policy that says it should. That’s the same standard an internal or external auditor would apply to any other control, and automated processes don’t get an exception.
Practical First Steps Before You Automate Anything
Before automating anything, map the process, confirm the pain point is real and worth solving, and get a baseline for the metrics that matter. From there, assess detection risk and impact risk together rather than treating them as separate exercises, since the combination is what determines how much oversight the process needs. Human oversight doesn’t disappear just because a process is automated, it just shows up differently, often as spot checks, reconciliations and periodic reviews instead of line-by-line review of every transaction.
None of this means automation isn’t worth the added risk and cost. Going from processing 30 invoices a month to 35 probably isn’t worth the lift. Going from 30 to 300 almost certainly is, even with the added controls that come with it, because the alternative is a team permanently buried in manual work with no time left for the oversight that protects the organization.
Build the Controls Before You Scale the Automation
If your finance team is automating processes without a clear picture of the risk each one introduces, that gap tends to surface at the worst possible time, usually during an audit or right after something goes wrong. James Moore Digital works with CFOs to map automation candidates, score the risk and build the internal controls to match. Visit James Moore Digital to talk through where your team should start.
All content provided in this article is for informational purposes only. Matters discussed in this article are subject to change. For up-to-date information on this subject please contact a James Moore professional. James Moore will not be held responsible for any claim, loss, damage or inconvenience caused as a result of any information within these pages or any information accessed through this site.
Other Posts You Might Like