Gaapio Logo - AI-Powered Technical Accounting Platform
Back to Blog
AI + Judgment / Practical Guidance

COSO's New AI Governance Framework: What It Means for Accountants Who Use AI Today

Zack Larsen, CPA
9 min read

Summary: In early 2026, COSO published "Achieving Effective Internal Control Over Generative AI" — the first formal guidance applying the COSO Internal Control–Integrated Framework to GenAI. This post explains what the framework covers, what it gets right, where the practical gaps are for individual accountants, and how to use it as a lens for evaluating AI tools and your own AI workflow.


For most of the past two years, the accounting profession has been asking: can AI do this work? Can it draft a memo? Research a standard? Flag a journal entry for review?

COSO just changed the question.

In early 2026, the Committee of Sponsoring Organizations of the Treadway Commission published "Achieving Effective Internal Control Over Generative AI" — applying their Internal Control–Integrated Framework to GenAI for the first time. The guidance doesn't debate whether AI belongs in accounting. It takes that as a given and asks instead: how do organizations make sure they can actually trust the work AI produces?

That shift matters for every accountant using AI — whether you're in technical accounting, financial reporting, audit, or the monthly close.


What Is the COSO GenAI Framework?

The COSO Internal Control–Integrated Framework has been the benchmark for internal control since 1992. It's the foundation auditors use when evaluating whether an organization's controls are effective. Applying it to generative AI means the profession is beginning to treat AI governance with the same rigor it applies to financial reporting controls.

The framework, formally titled "Achieving Effective Internal Control Over Generative AI," maps COSO's five established components across eight distinct GenAI capability types.

The five COSO components applied to GenAI are:

  1. Control Environment — The tone and governance structure around AI use, including policies, accountability, and ethical use standards.
  2. Risk Assessment — Identifying and evaluating AI-specific risks: hallucinations, data quality, output reliability, and the risk of over-reliance on AI judgment.
  3. Control Activities — The specific controls applied to AI workflows, including human review requirements, citation standards, and approval processes.
  4. Information and Communication — How AI-related risks, policies, and outputs are communicated across the organization.
  5. Monitoring Activities — Ongoing oversight of AI systems, including performance review, output audits, and process for identifying and correcting failures.

The eight GenAI capability types the framework covers are:

  1. Data ingestion and transformation
  2. Automated reconciliation
  3. Workflow orchestration
  4. Judgment, forecasting, and insight generation
  5. Monitoring and exception detection
  6. Knowledge retrieval (including RAG-based systems)
  7. Content generation
  8. Agentic AI

For most accountants, the capability types that matter most in day-to-day practice are judgment and forecasting and knowledge retrieval — the categories covering AI tools used to research standards, evaluate treatment options, draft memos and disclosures, and answer technical questions.


What COSO Gets Right

COSO correctly identifies that the risks of GenAI in accounting aren't primarily technical — they're judgment risks. When AI is involved in decisions that require professional interpretation, an acceptable-use policy or a monitoring dashboard isn't sufficient. Controls need to reach the level of individual outputs.

Three things the framework gets specifically right:

Requiring citations for material outputs. COSO explicitly flags hallucinations and fabricated citations as key risks under the judgment and forecasting capability type and recommends that organizations require citations for all material AI outputs. This applies whether you're drafting a lease accounting memo, preparing a disclosure, or researching treatment for a new transaction. An AI output without a traceable path back to the source standard — or the underlying data — is an unauditable one.

Human review as a designed control, not a fallback. COSO treats human oversight as a formal control activity — not something that happens when the AI gets something wrong. That distinction matters for how accountants should be engaging with AI outputs. Reviewing an AI-generated analysis isn't optional and it isn't light editing. It's a control step. For audit and financial reporting teams, this has direct implications for documentation: what did the human review, what did they verify, and what judgment calls did they make on top of what the AI produced?

Distinguishing between capability types. Not all AI use in accounting carries the same risk. Using AI to scan a trial balance for unusual items is a fundamentally different risk profile than using AI to research the appropriate accounting treatment for a complex revenue arrangement or an embedded derivative. COSO's framework respects that distinction. Most AI governance policies treat all AI the same way. COSO pushes back on that — and correctly so.


Where the Framework Stops Short — and What That Means for Practitioners

COSO's guidance is designed for organizations. It helps CFOs, audit committees, and internal audit teams answer governance questions: who owns AI risk, how is it documented, what does the approval chain look like?

Those are important questions. But they don't answer the one individual accountants are asking: how do I know I can trust this specific output right now?

That question lives below the governance layer. It's answered by what's inside the AI's analysis — and most of the practical guidance on that is still left to professional judgment.

Here is a practical five-point checklist for evaluating any AI output in an accounting context:

  1. Does it cite the source? The output should point to a specific standard, codification section, regulatory guidance, or data source for each material conclusion. If it references ASC 842 or IFRS 16 without a paragraph citation, that's not the same as a traceable position. If it's analyzing your data, it should show you where each finding comes from.

  2. Does it distinguish between clear guidance and judgment calls? Accounting is full of areas where the standards are unambiguous — and areas where they require interpretation. A reliable AI output will tell you which is which. An output that reads as certain across the board is oversimplifying. That's not more useful; it's less accurate.

  3. Does it engage with your actual facts? Generic AI outputs often describe the textbook version of an issue, not your specific situation. Whether you're evaluating a vendor contract, a lease modification, or a new product offering, the analysis needs to address your structure, your terms, your entity. If the output could have been written for any company in any industry, it probably wasn't analyzing yours.

  4. Does it acknowledge what it doesn't know? Good professional analysis — human or AI — is honest about its limits. If the AI output doesn't flag areas of genuine ambiguity, missing information, or situations where additional facts would change the conclusion, that's a signal the tool is optimizing for confidence rather than accuracy.

  5. Could you hand this to a reviewer? Imagine giving the output to your external auditor, a senior manager, or a peer reviewer. Could they follow the analysis from premise to conclusion? Could you explain how it was generated and what steps you took to verify it? If not, the output isn't ready to rely on.

This checklist applies whether you're using AI to support a technical accounting position, draft a disclosure, prepare audit workpapers, document a control, or respond to a regulatory inquiry.


How to Use the COSO Framework When Evaluating AI Tools

COSO's guidance also gives accounting teams a useful lens for evaluating the AI tools they're considering or already using.

The governance questions belong in any vendor evaluation: How is the model trained and updated? What is the data retention and privacy policy? How does the tool handle confidential financial information? Who is accountable if outputs are wrong? Is there documentation on how the system handles accounting-specific queries?

But the practitioner questions matter just as much — and they're almost always skipped. Before adopting a tool for accounting work, ask the vendor to demonstrate how it handles a judgment-intensive accounting question relevant to your work. Look at the output carefully against the five-point checklist above. Does it cite sources? Does it acknowledge ambiguity? Does it engage with the specific facts, or does it produce a generic answer?

Most general-purpose AI tools are optimized for confidence. The output is well-formatted, the language is authoritative, and the answer sounds complete. Confidence is not the same thing as accuracy — and in accounting, the difference between the two is the difference between a position you can defend and one you can't.


A Note on Where We Sit

At Gaapio, we've built our product around this exact problem — because we've been on the other side of it. Technical accounting memos, SEC comment letter responses, lease and hedge accounting implementations, revenue recognition analyses. I know what an output needs to contain for an accountant to actually be able to rely on it — and most general-purpose AI tools don't clear that bar.

COSO's framework is a meaningful step forward for organizations building AI governance. The practitioner test — can I stand behind this? — is the one that matters when it's your name on the analysis, regardless of whether you're a controller, a technical accountant, or an auditor.


Key Takeaways

  • COSO published its first formal guidance on internal controls for generative AI in early 2026, applying the established five-component COSO framework to eight GenAI capability types.
  • The most relevant capability types for accountants are judgment and forecasting and knowledge retrieval — covering research, analysis, memo drafting, and disclosure work.
  • COSO correctly identifies that AI risks in accounting are primarily judgment risks, not technical ones, and that controls must reach the level of individual outputs — not just organizational policy.
  • COSO's framework answers governance questions for organizations. Individual accountants still need a practical way to evaluate whether a specific AI output is reliable enough to act on.
  • A reliable AI output in an accounting context should: cite sources specifically, distinguish clear guidance from judgment calls, engage with your actual facts, acknowledge its limits, and be explainable to a reviewer.
  • When evaluating AI tools, ask both the governance questions and the practitioner questions. Most vendor evaluations skip the latter.

Source: COSO, "Achieving Effective Internal Control Over Generative AI (GenAI)," Committee of Sponsoring Organizations of the Treadway Commission, 2026.