The pitch decks all say the same thing: software agents that prepare reconciliations, draft journal entries, flag variances, and hand a finished package to a human for sign off.
The products are real now. BlackLine made its Verity Prepare agents generally available in July 2026, FloQast launched AI agents for close workflows back in March 2025, Microsoft has an account reconciliation agent in preview for Dynamics 365, and Workday has announced a financial close agent slated for 2026.
Adoption is moving just as fast: KPMG’s Global AI in Finance survey of 1,013 senior finance leaders, conducted in March 2026, found active use of AI in finance jumped from 30 percent in 2024 to 75 percent.
Here is the number that should worry CPAs advising those companies: in the same KPMG survey, only 42 percent of leaders said their organizations were fully assurance ready. Finance teams are deploying faster than they are documenting.
The gap is not a reason to stall. It is a reason to put five controls in writing before the first agent touches a production close. If your firm runs client accounting services, this is a checklist you can hand a client this month. If you audit, it is a preview of the questions you will be asking anyway.
1. An agent inventory with a named control owner
You cannot control what you have not listed. For every agent: what task it performs, which accounts and assertions it touches, what data it can read, what it can write, and one named human who owns its output. COSO’s February 2026 guidance on internal control over generative AI exists precisely because, in the words of COSO executive director Lucia Wind, these tools “can be confidently wrong, easily manipulated, or deployed outside formal oversight channels.” An inventory is the antidote to that last failure mode. Unowned agents are the new spreadsheet risk.
2. Evidence the auditor can replay
Ask one question at every vendor demo: when the agent reconciles an account, what is left behind? The answer needs to include the inputs used, the steps taken, the exceptions raised, and the basis for each match or explanation, retained in a form a reviewer can inspect after the fact. If the tool cannot show its work, it is not close ready, whatever the match rate slide says. Vendor claims of 90 percent match rates and 90 percent preparation time savings are marketing figures until your client’s own data reproduces them, so build a validation period into the rollout and keep the results.
3. Human sign-off gates scaled to risk
Agent output that feeds the financial statements needs a human approval step, and the depth of that review should scale with materiality and judgment. A low dollar, rule based bank match needs a light touch. An agent drafted accrual estimate needs the same review an analyst’s estimate would get. Write the gates into the close checklist itself, with names, so review is a control that happens rather than a value that is believed in. The lesson of Deloitte Australia’s October 2025 agreement to refund part of its fee to an Australian government department, after a delivered report was found to contain fabricated citations, is not that AI is unusable. It is that unreviewed output is a professional liability, in any workflow.
4. Third-party assurance, read closely
Most agentic close tools are subservice organizations in SOC terms, and here the profession has homework outstanding: the AICPA has not yet published guidance specific to AI use in SOC reporting, so existing SOC 1 and SOC 2 reports may say little about model behavior, retraining, or prompt controls. Read the report for what it actually covers. Where it is silent on the AI components, cover the gap with contract terms, complementary user entity controls, and your own validation testing, and document that mapping.
5. Monitoring, exception metrics, and an exit
Decide before go live what normal looks like: match rates, exception volumes, error rates found on review, and time to close. Then track those metrics every period and set the threshold at which the agent gets pulled from the workflow. An agent that quietly degrades is more dangerous than one that fails loudly. The kill switch is a control; so is the person authorized to throw it.
The Monday morning version
Put the five controls in a one-page memo: inventory and owners, evidence standards, sign-off gates, third-party assurance mapping, and monitoring with an exit threshold. Date it, have the controller sign it, and give the auditors a copy before they ask. The firms that do this will get the efficiency the vendors are selling. The ones that do not will rediscover, one exception at a time, why the profession wrote its control frameworks in the first place.
===-
Anthony L. Fulmore Sr., Ph.D. is a professor at Texas A&M University, Central Texas campus.
Sign in to get access to this free resource, and all of our whitepapers and reports.
Download this content today!
Register Now Already registered? Click here to Log In