For years, "AI governance in finance" meant a slide in a vendor deck. That changed on February 26, 2026, when COSO — the body whose Internal Control–Integrated Framework underpins SOX compliance worldwide — published Achieving Effective Internal Control Over Generative AI, its first formal extension of that framework into AI. Three weeks ago, FloQast announced it's building that framework directly into a live close-management product. The gap between "here's a framework" and "here's a product that enforces it" just closed to about seven months.
If you run finance for an SME on ERPNext or Odoo, or an accounting firm serving them, none of this is abstract. It's the same question Razyyn was built around: when an AI tells you a number, how do you know it's right — and who's accountable if it isn't?
COSO didn't write a new framework — it extended the one you already answer to
COSO didn't invent new principles for AI. It mapped generative AI risk onto its existing five-component Internal Control–Integrated Framework — the same one your auditors already test against for SOX and financial-statement controls:
5
ICIF components the guidance maps AI controls to: control environment, risk assessment, control activities, information & communication, monitoring activities
8
Capability categories the guidance classifies AI use cases into: ingestion, transformation, posting, orchestration, judgment, monitoring, regulatory intelligence, human-AI interaction
Feb 26
2026 — publication date of COSO's Achieving Effective Internal Control Over Generative AI, authored with AICPA as a supporting organization
The practical effect: an AI agent that posts journal entries, flags anomalies, or answers finance questions is no longer graded only on accuracy. It's graded on whether it fits inside a control environment your auditor already understands — audit-ready control mapping, risk-assessment matrices, testing procedures, the works. "The model is usually right" was never going to satisfy that bar, and 2026's own survey data confirms it hasn't.
The trust gap the framework exists to close
COSO published a framework because the trust problem is real and measured, not theoretical:
66%
Of finance leaders say human oversight of agentic AI is extremely or very critical to deployment — Maximor's 2026 survey of 100 middle-market finance leaders
80%+
Of the same finance leaders have already hit an AI hallucination in a finance workflow — only 14% say they fully trust AI output even after reviewing it
71%
Would reject an AI tool that's 99% accurate if it can't explain its reasoning — IDC/Sage survey of 2,275 senior finance decision-makers, July 2026
It gets more specific once you ask what's actually stopping adoption. In PEX's State of Finance benchmark — 687 finance and operations leaders — 36% named "trust in the accuracy of AI's output" as the single biggest barrier, ahead of cost or integration effort. Only 28% said they'd let AI decide a routine finance matter on its own. And on AI-generated financial reports specifically, 61% said they're interested but only 14% actually use the capability — a 47-point gap between wanting it and trusting it enough to switch it on.
That's not an anti-AI signal. It's finance teams asking the same question COSO just formalized: not "is it usually right," but "can I prove it, to an auditor, every time."
Someone already turned the framework into a feature
The distance between "COSO published a framework" and "a vendor shipped it" is normally measured in years. This time it was months. At FloQast's TakeControl conference on September 16–17, 2026, the company announced it's operationalizing COSO's GenAI framework directly inside its platform — risk assessment, control environment and activities, and ongoing monitoring wired into the product, with audit evidence generated automatically through its Connected Compliance integration. It also hired Lucia Wind, COSO's outgoing Board Chair and Executive Director — the person who oversaw the framework's publication — as SVP of Risk & Audit Advisory.
The specific feature worth noting: FloQast's AI Assistant now reviews journal entries before a human approves them, flags errors and anomalies, scores audit risk, and explains its reasoning — but the human reviewer keeps final approval authority. That's the COSO framework in miniature: AI does the checking, a human keeps the sign-off, and every step leaves a trail an auditor can follow.
Why this matters even if you're not buying enterprise close-management software
Most of Razyyn's audience isn't running a Fortune 500 close process — it's SMEs and accounting firms inside ERPNext or Odoo who'll never touch a $50k FloQast contract. But the underlying shift applies at any size: "explain your reasoning and show your work" is becoming the baseline expectation for any AI that touches a ledger, not a nice-to-have for enterprise buyers.
That's the same instinct Razyyn was built around, for the same reason the trust-gap numbers above exist: an AI that states a figure without showing how it got there is a black box, and Sage's own framing for this shift — "from black box to glass box" — is exactly right. Razyyn's Analyse and Audit agents compute every number in Python against your actual ledger data first, and cross-check the model's narration against that computed figure before anything reaches a user. Not because COSO's framework requires it at your scale — it doesn't, yet — but because the same failure mode it's designed to catch (a plausible-sounding number nobody actually checked) is exactly what erodes trust in the surveys above.
What to actually do with this
- Don't deploy anything that can't show its work. If a finance AI gives you a number, ask what computed it and whether that computation is checkable independently of the model's own narration. If the answer is "just the model," that's the exact gap COSO's framework and 71% of surveyed finance leaders are both flagging.
- Pilot with a human-in-the-loop checkpoint, not full autonomy. The finance teams furthest along aren't the ones that gave AI full control — they're the ones using tiered thresholds or review gates, per the governance patterns already in use. Start narrow: journal-entry review or anomaly flagging, with a human keeping sign-off, same as FloQast's own rollout.
- Treat "audit trail" as a requirement, not a feature request. The teams demanding full auditability of every AI decision aren't being difficult — they're the plurality (47.6%) of finance leaders surveyed by Sage/IDC, and they're the ones COSO just built a framework to satisfy.
If you want to see what a validated-before-it-reaches-you answer looks like inside your own ERPNext or Odoo instance, our documentation walks through installation for both, or get in touch and we'll show you on your own data.
Sources: COSO creates audit-ready guidance for governing generative AI — Journal of Accountancy · COSO Releases Roadmap for Governing Generative AI · The majority of CFOs require human oversight of agentic AI — Anrok · Finance Leaders Demand AI Transparency as 71% Reject Unexplained Decisions — Sage · Finance teams still wary of giving AI control — CFO Dive · FloQast Introduces New AI Accounting Innovations at TakeControl 2026
Razyyn