top of page
Men in Suits

AI-Generated Financial Disclosures and Audit Trust: How Boards Should Govern AI in Financial Reporting Before Auditors Catch Up

Picture the week before a board meeting to approve quarterly results.

The finance team is stretched, like always. But this quarter, someone has a shortcut. The first draft of the management commentary, a few footnotes, and the summary for the press release were all produced by an AI tool in about twenty minutes. The team tidied them up. They read well. Honestly, they read better than last year's.


The audit committee gets the pack. Nobody mentions the AI. The directors review it, the CFO signs the certificate, the board approves.


Here's my question. Who actually checked what the machine wrote?

Not "did someone look at it". Did someone trace every number, every claim and every explanation back to a source? Because if the answer is "we assumed the reviewer did", then the board has just put its name on something nobody fully verified.


That's the heart of this blog. AI in financial reporting is moving fast, audit rules are moving slowly, and the gap in between is where audit trust gets tested.


Audit committee reviewing financial reports in a boardroom setting

Executive Summary

AI in financial reporting is no longer an experiment. Companies are already using it to draft commentary, footnotes, and summaries. Auditing standards haven't caught up yet, and there's still no audit rulebook written specifically for AI-generated financial disclosures. That leaves a period, which I'll call the verification lag, when AI can write faster than anyone can properly check. During that lag, the responsibility doesn't move to the software or the auditor. It stays with management and the board. This blog explains the risk in plain terms and offers a simple AI governance tool that audit committees can use right now.


Quick Answer: How Should Boards Govern AI-Generated Financial Disclosures?

Boards should treat AI-generated financial disclosures like any other high-risk process: know where AI is used, require a named human reviewer, tie every figure and claim to a source, have the audit committee test samples, and tell the auditors openly. Responsibility for the numbers stays with the board, whoever or whatever drafted them.


In one line: the AI can hold the pen, but it can't sign the page.


Why AI in Financial Reporting Is Now a Board Issue

Because it's already happening at scale, and most boards haven't caught up with it.


Adoption is racing ahead

KPMG surveyed 1,800 large companies in 2024 and found that 72% were already piloting or using AI in financial reporting. Within three years, that was expected to reach 99%. That's close to every company.


And that survey is now two years old. Given how quickly generative tools have spread since, I'd be surprised if the real picture hasn't moved further.


Companies expect auditors to step in

The same KPMG survey found that 64% of companies expect their auditors to play a role in evaluating how they use AI in financial reporting, including assurance over their AI controls.

Fair enough. But here's the catch. Expecting auditors to check it isn't the same as auditors having clear rules for how to check it.


Audit rules are still catching up

In the US, the audit regulator, the PCAOB, published a staff review in July 2024 on generative AI. It found that audit firms were mostly using it for admin and research tasks, while companies were exploring it for things like drafting disclosures. The PCAOB also noted that when companies use generative AI to prepare financial statements, auditors need to understand and assess that use as part of their risk assessment.


Since then, there has been movement. Updated rules on how auditors assess technology-based evidence now apply to calendar-year 2026 audits. And in 2026 the PCAOB asked for public input on its next strategic plan, including how auditing standards should change as AI grows in financial reporting.


So the direction is clear. But asking questions isn't the same as having answers. Right now, much of the checking depends on judgment, not on a settled standard.


Boardroom Perspective: The Signature Gap

Here's the thing I want every director to sit with. In India, the law already puts the responsibility squarely on people, not tools.


Under Section 134(5) of the Companies Act, 2013, directors of a listed company state in the board's report that they've laid down internal financial controls and that those controls are adequate and working. Under SEBI's Listing Regulations, the CEO and CFO certify the financial statements to the board. None of these signatures comes with a footnote saying "except the parts the AI wrote".


That's what I call the signature gap. The people signing are fully accountable. The tool that drafted parts of the document has no accountability at all. And the process connecting the two is often informal.


SEBI has already shown which way Indian regulators are thinking. In February 2025, it notified amendments making the entities it regulates, such as brokers, exchanges and asset managers, solely responsible for the output of AI tools they rely on, whether built in-house or bought from a vendor. Those rules apply to market intermediaries, not to every listed company. But the principle is hard to miss: you can't blame the software.


So where does AI governance usually break down in the boardroom? A few places.


Nobody knows where the AI is. Ask most audit committees which parts of last quarter's report were drafted with AI, and you'll get guesses. You can't govern something you can't see.


Review becomes skim. AI-generated financial disclosures are fluent. They sound confident. That makes reviewers relax, which is exactly the wrong reaction. A well-written wrong sentence is more dangerous than a clumsy one, because it gets waved through.


The auditor isn't told. If the auditors don't know AI was used, they can't plan for it. That's not fair on them, and it weakens audit trust for everyone.


Vendor tools are treated as neutral. Many finance teams use AI features built into their accounting software. That still counts. If it touches the numbers or the words around them, it's part of your controls, whether a specific rule names it or not. Good AI governance covers it too.


The TRACE Test: An AI Governance Tool for Audit Committees

Here's a simple framework I'd suggest for any audit committee. It's called TRACE, because at its heart, audit trust is about being able to trace things back.


T – Tag it. Every part of a financial report that AI helped draft gets marked internally. Commentary, footnotes, summaries, risk factors, the lot. Not for publication, just so everyone knows where to look harder.


R – Review it with a name. Each tagged section has one named human reviewer who signs off. Not "the finance team". A person. Named ownership changes how carefully people read.


A – Anchor it. Every figure, claim and explanation in a tagged section must link to a source: the ledger, a board minute, a contract, a data file. If a sentence can't be anchored, it comes out. This is the single most important step, because it's exactly where AI errors hide.


C – Challenge it. Once a quarter, the audit committee picks a small sample of tagged sections and asks management to walk through the anchors live. Fifteen minutes. It keeps everyone honest.


E – Explain it. Tell the external auditors openly where and how AI was used, and what controls sit around it. Also, be careful what you say publicly about AI. In the US, the SEC has already fined firms for overstating their use of AI, which regulators now call "AI washing".


None of this needs new software or a big budget. It needs discipline and a clear owner. That's usually where good AI governance starts.


Three questions for your next audit committee meeting

  1. "Which parts of our latest financial report were drafted or edited with AI, and who reviewed each one?"

  2. "Can you show us the source behind three sentences we pick at random?"

  3. "Have we told our auditors how AI is used in our reporting, and what did they say?"


If the first answer is "we're not sure", that's where to begin.


Real-World Example: Deloitte Australia and the Report That Looked Right

This case isn't a financial statement. But it's the clearest warning I know of about what happens when AI-assisted work goes out without proper checking, and it happened to a Big Four firm.


In 2025, Deloitte Australia delivered a 237-page report to the Australian government's Department of Employment and Workplace Relations. The contract was worth about A$440,000. The report reviewed a system used to automate welfare penalties.


It looked professional. It read well. It had been published on the department's website.

Then a University of Sydney researcher, Chris Rudge, noticed something off. The report cited academic papers that didn't exist. It included a made-up quote attributed to a federal court judgment. He flagged it publicly.


Deloitte reviewed the report and confirmed that some footnotes and references were wrong. A corrected version was published, and it disclosed that a generative AI tool, Azure OpenAI GPT-4o, had been used in preparing it. Deloitte agreed to refund the final instalment of the contract, while saying the substance of the review and its recommendations hadn't changed. Deloitte didn't say AI caused the errors, but the incident became a global talking point about AI hallucinations in professional work.


Now think about what that means for a boardroom.

This was a firm whose entire business is checking things. The document went through its own processes, reached a government client and was made public, and the errors were still caught by an outside reader, not by the internal review. The problem wasn't that AI was used. The problem was that nothing forced every reference to be anchored to a real source before it went out.


Now swap the welfare report for AI-generated financial disclosures in a company's annual report, and the fake citation for a wrong explanation of revenue growth. The damage to audit trust would be far bigger than a refund.


FAQs on AI in Financial Reporting and Audit Trust

What are AI-generated financial disclosures?

AI-generated financial disclosures are parts of a company's financial reporting, such as management commentary, footnotes, summaries or risk explanations, that were drafted or heavily edited using AI tools. The company remains fully responsible for them, however they were produced.

Management and the board. In India, directors confirm internal financial controls in the board's report, and the CEO and CFO certify the financial statements. Using AI doesn't shift that responsibility to the tool or the vendor.

They can check the numbers and the evidence, but auditing standards weren't written with generative AI in mind. Regulators like the PCAOB are still gathering input on how standards should change, so a lot currently depends on auditor judgment and on the company's own controls.

As soon as there's any AI in financial reporting, including AI features inside accounting or reporting software. Waiting for the auditors to raise it is too late.

In the words around the numbers: commentary, explanations, footnotes and summaries. AI writes fluent text, and fluent text gets reviewed less carefully. That's where unsupported claims can slip through.

By using simple controls, like the TRACE Test: tag AI-assisted sections, name a reviewer, anchor every claim to a source, have the audit committee sample-check, and tell the auditors. Directors don't need to understand how the AI works. They need to know it's being checked.

There's no general rule requiring it yet, but whatever a company does say about AI must be accurate. Regulators have already penalised firms for exaggerating their AI use. Being open with auditors is the more important first step.


Key Insights

  • AI can hold the pen, but only people can sign the page. Accountability never moves to the tool.

  • The verification lag is real: AI drafts faster than audit rules have evolved to check it.

  • Fluent writing lowers people's guard. A well-written error is more dangerous than a clumsy one.

  • Audit trust depends on being able to trace every claim back to a source.


Key Takeaways

  1. Ask management to map exactly where AI is used in financial reporting, including inside vendor software.

  2. Give every AI-assisted section a named human reviewer, not a team.

  3. Use the TRACE Test so the audit committee can check AI-generated financial disclosures in minutes, not months.

  4. Tell your auditors openly how AI is used, so they can plan and audit trust stays intact.

  5. Don't wait for final audit standards. Build your AI governance now, because the board's signature is already on the line.


Governance fluency like this — knowing where accountability sits when the rules haven't caught up — is exactly what we build in Become an International Corporate Director.


Join our live webinar to see how the program prepares directors to govern emerging risks like AI in financial reporting, not just legacy ones.


Comments


  • alt.text.label.LinkedIn
  • alt.text.label.Facebook
bottom of page