Risk and audit teams are navigating accelerating AI governance, geo-political uncertainty and changing regulations, often with leaner teams than ever before, and many are finding that siloed approaches are no longer sustainable. That’s part of the argument posited recently by Julie Iskow, CEO of Workiva, when she noted:

Finance leaders are being asked to do far more than close books and report results. Today, they’re also responsible for the data that their businesses rely on and how AI is governed and they’re helping their organization navigate a more complex regulatory and risk environment, but that’s only part of the story. AI is also changing what’s expected of the people that are doing the work. CFOs and their teams are expected to deliver insights in hours instead of days. They’re expected to automate more of the work that’s still manual, answer more questions with greater confidence and respond faster as regulations and business conditions continue to change. They’re also no longer expected to simply use enterprise software.

 There’s now an expectation that they’ll extend it and build upon it. Users are becoming builders. They’re creating AI agents. They’re automating complex processes. They’re connecting trusted business data with the rest of their technology ecosystem. They’re extending the platforms they already rely on every day. And they’re expected to do all of this while maintaining the governance, the security, the accuracy and the auditability that the office of the CFO demands. And as AI becomes more embedded in more business processes, trusted, connected and traceable data matters more than ever.

A case in point

Fintech company Best Egg began using Workiva and AI tools for its Governance, Risk and Compliance (GRC) functions several years ago. Before then GRC operations were mainly manual, relying on spreadsheets and emails, and limiting the organization’s ability to see an enterprise-wide view of risk.

The company was founded in 2013 as Marlette Funding, and in 2014 it launched Best Egg as an online consumer lending product, later re-branding the whole company as Best Egg before being bought by Barclays in May this year for $800 million.

That acquisition has led to more robust data and AI governance challenges because as Best Egg is now regulated by the UK, as well as the US. Heather Holding, Chief Risk Officer at Best Egg explains:

They have very, very strict rules, and what we’re seeing is the C-suite is really pushing using, and getting comfortable with AI, and wanting employees to explore these tools. But at the same time you have to be smart about it, and we’re still cautious about it. We need to make sure that we can evidence our controls and to make sure these things work for our regulators.”

The firm uses Workiva’s SaaS integrated reporting platform to centralize its GRC framework, and is now starting to use AI agents to expand its risk and control functions. Holding says:

We started using AI three years ago, with some basic gen AI tools, and leveraging the AI workspace in Workiva. We were using regular gen AI within Workiva generally to help us write policies, make edits to executive summaries, in the most basic places.”

This AI exploration is now being expanded upon, she adds:

Now we’re starting to use AI for analytics and research, identifying gaps within processes and controls, and helping us identify where controls could be stronger, and where we might potentially have some control breaks. It is also helping us using it to help build out our risk and control libraries.”

The next step for Best Egg is exploring leveraging AI agents, according to Holding. It will look at connecting its systems to coding platform Cursor, or to Claude to help in the reporting space, and also pulling the data from Workiva and then publishing it in Microsoft’s Power BI.

Barclays is itself taking a close look at how Best Egg is leveraging AI, according to Holding.

Barclays is making huge investments in AI, and is looking at what we have been using it for, so that it can expand its own use. At Barclays, the primary tool it’s been using is Copilot, where as Best Egg has over 100 AI tools at this point. So we’re trying to see which are the best tools that will work for both organizations, and that both organizations are kind of comfortable with moving forward with.”

And it’s all still early days, she notes:

We’re just starting to scratch the surface, and are also having some conversations around how we can leverage AI agents to help us with control testing.

Re-thinking

Based on Best Egg’s experience to date, Holding thinks the most critical AI challenges for all companies is still governance and data quality:

A lot of folks are still very concerned about how AI is being leveraged, and how they’re integrating different tools. We are going through AI governance processes to ensure they’re safe and sound. It’s going to take a little bit of time to get folks comfortable with some of these new use cases because it is very different. It’s a matter of getting leadership comfortable and leveraging these types of use cases and tools because it is very different.”

This is a view shared by her chosen vendor, with Kim Huffman, CIO Workiva adding that organizations that fundamentally re-design workflow processes to take advantage of AI will be far more effective:

Through AI we are truly re-thinking how the business is done in an organization, and then applying AI to that to develop not an AI-native company or a solution, but AI-native workflows that  look at not just the layer of AI, but the application underneath and the data underneath that. That’s an exercise that requires a lot of thought, and planning, and a lot more change, not just from technology, but from an equal organizational and job redesign perspective. As an approach, you’ve got to trust that the actions that the AI is doing are the right actions.

She believes that organizations have low risk, high opportunity use cases, and high risk, low opportunity use cases, and that as organizations become more comfortable with the technology there will be more of the high risk opportunity use cases:

As we move more into building out agentic capabilities, there’s always going to be a human in the loop. As organizations become more comfortable, they’ll be able to lower the guardrails on the specific processes that they’re using to make sure that they’re comfortable with what the agentic AI is doing.

Confidence

In fact, Workiva’s recent Mid-Year Executive Benchmark Survey found 84% of executives are now fairly confident in the accuracy of AI output without human overview, but 26% say internal audits have detected AI errors that reached external audiences or board members, suggesting there is a disconnect between what executives believe, and what is really happening.  Huffman argues:

That’s when you really start having the important discussions around ‘is the data that’s feeding our AI trusted and governed?’ And ‘can we see what actions the AI is taking? Is it audited and logged, so that we can go back and look at it?’ Because that, especially in the office of the CFO, is going to be critical.

Comparing the survey figures from last year, Huffman thinks that Workiva’s customers and their executives have begun to understand AI better:

The reality of this kind of technology, the data quality, the data foundation, and the trusted data has even become more amplified as critical versus what we saw in the report last year. They are actually seeing it and realizing the importance of AI as they’re beginning to use some of these solutions in their organizations.

Huffman concludes:

At the end of the day, AI is a technology. It’s an immensely democratizing for an organization, but in order to apply it at scale, to really seeing the business benefits in an organization, you’re going to go through the same governance rigor, analysis, discovery and solutioning that you did with most technology tools, focusing not just on the tech but the process and the people and the data.