Deploying AI in accounting poses 12 audit risks: CAQ study
April 5, 2024
CFOs see the value of generative artificial intelligence but may not fully grasp its audit risks, according to the Center for Audit Quality.
Dive Brief:
Companies that deploy generative artificial intelligence in financial reporting face 12 audit risks that range from flaws in governance and compliance to failures in preventing fraud and cyberattacks, according to the Center for Audit Quality.
“It is critical that companies have a governance model in place that enables them to know where and how these technologies are being used in their organization,” Dennis McGowan, vice president of professional practice at CAQ, said Friday. Given the rapid rise of generative AI, “we’re only beginning to see — and understand — how the use of this technology might be impacting financial reporting,” he said.
Auditors for companies that use generative AI often confront a “black box” challenge when they can neither interpret nor explain how the technology generates information, CAQ said. The problem grows when “financial reporting processes and ICFR [internal control over financial reporting] become more sophisticated and outputs from the technology are unable to be independently replicated.”
Dive Insight:
One out of three auditors see companies in their industry deploying or planning to deploy AI in financial reporting, CAQ found in a 2023 survey. The proportion will likely grow as companies explore how AI “can streamline or enhance accounting and financial reporting,” the center said.
Accountants are increasingly using generative and other forms of AI to prepare technical accounting memos, to smooth routine tasks such as writing Excel formulas or footing financial statements and to analyze large volumes of data for unusual transactions or unauthorized system access, McGowan said.
Financial executives also use AI to summarize contract terms, prepare the initial suggestion for the accounting treatment of a transaction, and analyze data for budgeting or for understanding variances and costs, he said in an email reply to questions.
“CFOs see the opportunity that generative AI presents, including the streamlining of processes and systems and opportunities for innovation,” McGowan said. “What is less clear is their awareness of risk,” even though audit committees now regularly include AI on their meeting agendas, he said.
CFOs should consider focusing on 12 hazards from generative AI, CAQ said, including:
Governance – the failure to identify and manage AI applications throughout a company;
Regulation – use of generative AI in ways that violate regulations, laws or contracts;
Skills – employees lack the knowledge to oversee or use generative AI effectively and safely;
Fraud – management, employees or third parties use generative AI to commit or conceal crimes;
Data privacy – confidential data is erroneously entered into a generative AI application;
Security – generative AI is vulnerable to cyberattacks, the intentional insertion of flawed data, or deliberate efforts to prompt bogus conclusions from the applications;
Flawed selection or design – the choice of a generative AI application that does not achieve the desired objective;
Error-prone foundation model – the company adopts an unreliable large language model that generates inaccuracies or biased information;
Flawed training – faulty training of the generative AI model generates repeated output errors;
Weak performance - due to inadequate testing, the generative AI application “hallucinates,” or provides incomplete, inaccurate, unreliable or irrelevant information;
Defective prompts – employees fail to ask generative AI accurate questions, yielding unintended or irrelevant information;
Inadequate monitoring – after deploying generative AI, companies fail to closely track output to ensure the technology is functioning as intended.
“Generative AI has the potential to be transformative to business,” McGowan said.
“CFOs have a role to play in assisting their organizations in establishing governance structures that are set up for success,” he said. “They can do this by establishing a strong foundation by linking the governance over AI to their organizations AI strategy and by building literacy among employees around emerging technologies.”
[CFO Dive]