OPERATING CONTROLS

Controls designed into the workflow.

AI does not remove the need for finance controls. We work with Finance and IT to define the checks, evidence, approvals and recovery procedures each workflow needs, then implement and test them.

Finance controls across the whole workflow.

We design the workflow so Finance can verify completeness and accuracy, trace outputs to source data, reconstruct the work and reproduce calculations where required. Checks cover source data, calculations, AI steps, handoffs and final outputs—not just the agent’s actions.

We define the evidence to retain and who can approve, reject, correct or escalate. Rerunning AI may produce a different answer; the original result must still be verifiable.

IT controls to implement and test.

These are control principles, not a ready-made product. We use existing platforms where suitable, then configure or build and test what the workflow needs.

Inventory
Define how agents, workflows, owners and versions will be recorded.
Access
Implement separate permissions to read, draft and act across agreed systems and tools.
Operations
Set up run and action logs, with monitoring for failures, usage and cost.
Changes and recovery
Define release checks and test how to stop agents, restore a previous version and correct affected transactions. Restoring software does not undo financial actions.

Choose permissions for each workflow step.

Agree what the agent may do, then implement and test the limits before expanding access.

  1. Read-only

    Retrieve and analyse evidence without changing source systems.

  2. Draft

    Prepare outputs for review before submission.

  3. Controlled action

    Make defined system changes within agreed checks and approvals.

Build and test the failure paths.

Define which failed checks stop the workflow, which exceptions need Finance judgement and which failures go to IT. Implement and test escalation and recovery before allowing system changes.

Discuss the controls for one workflow.

Discuss your process