Gana Misra
By Gana MisraCEO, Finrep
Tue Aug 18 2026

COSO GenAI Guidance: The New Stand

Share
COSO GenAI Guidance: The New Stand

On February 23, 2026, the Committee of Sponsoring Organizations of the Treadway Commission (COSO) released a new publication, Achieving Effective Internal Control Over Generative AI, offering organisations a practical, COSO-aligned approach to managing the risks and opportunities introduced by rapidly advancing generative AI technologies.

The publication applies COSO's Internal Control: Integrated Framework (2013) to AI systems, offering control mapping, risk assessment tools, and governance guidance across the AI lifecycle.

The COSO GenAI guidance is now the single most authoritative control document for AI governance in financial reporting contexts, for three confirmed reasons.

First, the SEC confirmed its authority. NexarAI reported a June 4, 2026 statement by an SEC official confirming that COSO's principles-based frameworks, as well as the SEC's guidance regarding management's reporting of ICFR, are helpful resources for AI governance.

Second, the FEI AI-ICFR framework, published by Meta, Walmart, ServiceNow, and Alphabet's controllers in June 2026 and covered in the companion blog in this cluster, maps directly to COSO. FEI is one of COSO's five sponsoring organisations. The FEI framework explicitly extends the COSO guidance to the specific context of SOX 302 certifications and ICFR controls.

Third, the COSO guidance is the only document that addresses the specific technical failure mode of generative AI (its probabilistic, non-deterministic nature) in the context of the 2013 ICIF that every public company's SOX programme is based on.

Oreate AI confirmed four weeks ago: "the gap between deploying AI and governing AI has widened. The 2026 COSO guidance bridges this gap, providing a clear roadmap for organisations that must answer to stakeholders, regulators, and external auditors."

This post is the plain-language guide to what the COSO GenAI guidance requires, how its eight capability types classify your AI tools differently from traditional IT controls, and what your SOX programme must update before December 15, 2026, when the five PCAOB standards covered in the companion QC 1000 blog take effect simultaneously.

This blog is distinct from the FEI AI-ICFR framework blog (which covers the four control approaches and the 90-day implementation programme from the practitioner perspective) and from the SEC AI reading filings blog (which covers the SEC's AI-powered filing review capability). This blog covers the foundational COSO document that both of those blogs reference.

What Is the COSO April 2026 GenAI Guidance and Why Did It Take This Long?

The publication, titled Achieving Effective Internal Control Over Generative AI, was commissioned by COSO and authored by Scott Emett of Arizona State University, Marc Eulerich of the University of Duisburg-Essen, Jason Guthrie of Ernst and Young, Jason Pikoos of Meta, and David Wood of Brigham Young University. It translates COSO's Internal Control: Integrated Framework into concrete internal control practices tailored to GenAI.

COSO Executive Director and Chair Lucia Wind stated at the February 23 release: "Generative AI is transforming how organisations work, make decisions, and manage information. Its rapid adoption brings enormous potential, but also a new set of risks that demand disciplined oversight. The COSO Internal Control: Integrated Framework gives organisations a clear, proven structure to ensure gen AI is introduced responsibly and with the rigor needed to support reliable operations, reporting, and compliance."

Why it took this long: the 2013 ICIF was designed for deterministic control environments, where the same input consistently produces the same output and where controls can be designed by mapping specific procedures to specific risks. GenAI shattered this paradigm. Generative AI's probabilistic nature forced a complete reimagining of the Internal Control: Integrated Framework. Writing guidance that adapts the 2013 ICIF to probabilistic AI without replacing or overriding the framework required both deep control expertise (the EY and Meta authors) and academic rigour in AI systems (the university authors) working together.

Rather than proposing a new governance model, the publication adapts COSO-ICIF's five components (Control Environment, Risk Assessment, Control Activities, Information and Communication, and Monitoring Activities) into GenAI-specific practices.

The guidance is designed for professionals responsible for deployment and oversight of AI processes including: CFOs and Chief Accounting Officers, controllers and internal audit leaders, risk management officers, and external auditors. Deloitte described the practical features as including audit-ready control mapping for each of the eight capabilities, minimum control expectations aligned to the five COSO components, and illustrative metrics for operational monitoring and audit evidence collection.

What Is the "Capability-First Taxonomy" and How Does It Change How You Categorize AI in Your ICFR Program?

The most significant innovation in the COSO GenAI guidance is the capability-first taxonomy. GenAI use cases are organised into eight capability types: ingestion, transformation, posting, orchestration, judgment, monitoring, regulatory intelligence, and human-AI interaction. Each capability type has tailored control considerations reflecting how GenAI risks manifest across the data-to-decision lifecycle.

The taxonomy is capability-first rather than technology-first or vendor-first because the same AI tool may perform different capability types in different contexts. A large language model used to extract invoice data from vendor documents (ingestion) presents different control risks than the same model used to generate journal entry commentary (judgment). Categorising AI by vendor or product name does not capture this difference. Categorising AI by what it does in each specific use case, its capability, produces the right control design.

The eight capability types and their financial reporting relevance:

Ingestion: data ingestion and extraction, such as extracting borrower financial data from uploaded statements or pulling transaction data from ERP systems. For ICFR purposes, the primary risk is data completeness and accuracy in the extracted data before it enters the financial reporting process.

Transformation: data transformation and integration, such as normalising data across legacy systems or converting transactional data into financial reporting formats. The control risk is that the transformation logic produces a different output than the documented transformation rules specify.

Posting: automated transaction processing and reconciliation, such as automated journal entry posting or AI-assisted account reconciliation. This is the capability type most directly relevant to ICFR because posting errors directly affect financial statement amounts.

Orchestration: workflow orchestration and autonomous task execution, where an AI agent sequences and executes multiple tasks in a multi-step financial reporting workflow without continuous human direction. This is the agentic AI capability type the FEI framework flagged as the highest-risk category.

Judgment: judgment, forecasting, and insight generation, such as AI-assisted credit loss reserve estimation, goodwill impairment DCF modelling, or revenue recognition judgments under ASC 606. The control risk is hallucination: a confident-sounding but factually incorrect estimate that passes initial human review.

Monitoring: AI-powered monitoring and continuous review, such as continuous journal entry monitoring for anomalies or AI-assisted fraud detection. The control design challenge is calibrating the detection threshold so the monitoring catches genuine anomalies without producing excessive false positives that desensitise reviewers.

Regulatory intelligence: knowledge retrieval and summarisation for regulatory interpretation, such as AI tools that summarise new OBBBA provisions, PCAOB standards, or SEC guidance for the tax or disclosure team. The control risk is that the summarisation is incomplete or inaccurate and that the practitioner relies on it without independent verification.

Human-AI interaction: the collaborative interface where humans review, approve, or override AI outputs. This is where the shadow reliance risk the FEI framework described (humans rubber-stamping AI outputs rather than genuinely reviewing them) materialises as a control deficiency.

Why the SEC Confirmed COSO as the Governing Framework for AI in Financial Reporting

At a June 4, 2026 conference, an SEC official confirmed that COSO's principles-based frameworks, as well as the SEC's guidance regarding management's reporting of ICFR, are helpful resources for AI governance in financial reporting.

The SEC's confirmation is significant because it is not the SEC issuing its own AI-specific ICFR guidance. It is the SEC directing preparers to the COSO framework that they already use for their SOX programmes, confirming that the COSO GenAI guidance is the appropriate mechanism for bringing AI under ICFR governance.

The SEC's broader position on AI in financial reporting, consistent across its comment letter practice and its new Financial Reporting and Accounting Unit's mandate, is that AI does not create an exception to existing financial reporting obligations. The materiality standard applies. The disclosure obligations apply. The ICFR effectiveness requirement applies. What the SEC is confirming by endorsing the COSO framework is that the existing ICFR obligation, evaluated under the COSO 2013 framework, extends to AI use in financial reporting processes, and that the COSO GenAI guidance is how companies operationalise that extension.

Deloitte confirmed: "We see COSO's GenAI guidance as most useful when it builds on the 2013 ICIF rather than acting as a prescriptive rulebook. GenAI necessitates a fundamental shift in mindset for both management and auditors, moving from deterministic, rule-based technologies to probabilistic models with inherently variable outcomes, and from static, point-in-time assurance to continuous monitoring of model performance and risk."

The practical consequence of the SEC's endorsement: when a company's ICFR assessment is reviewed by external auditors or by the SEC's new Financial Reporting and Accounting Unit, the question "how are you controlling AI in your financial reporting process?" has a specific reference standard answer: through the COSO GenAI guidance. A company that cannot describe its AI controls in terms of the COSO capability-first taxonomy and the COSO implementation roadmap does not have an adequate answer to that question.

The Four Key Changes the COSO GenAI Guidance Makes to the 2013 Integrated Framework

The four changes addressed in the following sections represent the operational content of the COSO guidance for controllers and SOX teams. Each is a departure from traditional SOX programme design that most companies have not yet implemented.

Change #1: Static Annual Risk Assessments Are Now Obsolete, Continuous AI Risk Assessment Is Required

Traditional ICFR risk assessment is performed annually, typically at the start of the SOX testing cycle. The risk assessment identifies which accounts and assertions are at risk of material misstatement, which controls mitigate those risks, and which controls are key controls subject to testing. Once the annual risk assessment is complete, it remains the basis for the SOX programme until the following year, subject to updates for material changes identified during the year.

The COSO GenAI guidance requires a fundamental shift from static, point-in-time assurance to continuous monitoring of model performance and risk. Monitoring plays a key role when GenAI is used in financial reporting, since "set-and-forget" does not work. Effective monitoring prioritises meaningful evaluation of key performance indicators.

The reason static annual risk assessment is insufficient for GenAI: AI models change in ways that do not trigger the annual risk assessment update process. A vendor may update the model's version, training data, or parameter settings without issuing a formal change notification that reaches the SOX team. The model's accuracy may drift over time as the data it processes diverges from its training data, without any configuration change that would normally trigger a risk assessment update.

The COSO guidance's required response: continuous monitoring of AI model performance using the capability-type-specific KPIs the guidance provides for each of the eight capability types. For the posting capability type (automated journal entry), a continuous KPI might be the error rate in AI-posted journal entries compared to the expected error rate based on historical performance. A sudden increase in the error rate triggers a risk assessment update, a control design review, and potentially a model revalidation, without waiting for the annual SOX cycle.

The practical SOX programme change: convert the AI controls in the SOX programme from annual-testing controls (tested once per year) to continuous monitoring controls (assessed against KPIs throughout the year, with documented escalation protocols for KPI breaches). The monitoring frequency and escalation threshold for each AI control should be calibrated to the materiality of the financial reporting process the AI supports.

Change #2: The GenAI Council Structure, Why CFO, CRO, and Lead Data Scientist Must Own AI Risk Together

The COSO guidance recommends a governance structure for GenAI that is cross-functional rather than housed solely in the finance team or the IT department. The recommended structure is a GenAI Council or equivalent body that brings together the functional leaders who each own a piece of the AI governance problem.

The Council's recommended composition reflects the three domains of knowledge needed to govern AI in financial reporting:

The CFO or Controller owns the financial reporting obligation: the accuracy of financial statements and the effectiveness of ICFR. The CFO is the person who signs the SOX 302 certification and who faces individual enforcement risk if AI-related control failures produce material misstatements.

The Chief Risk Officer owns the risk identification and escalation framework: the organisation's overall risk taxonomy, the escalation protocols for material control failures, and the integration of AI risk into the enterprise risk management programme.

The Lead Data Scientist or Chief AI Officer owns the technical knowledge about AI model behaviour, model drift, model revalidation, and the specific failure modes of each AI capability type in use.

The governance gap the COSO guidance is addressing: in most organisations, each of these leaders has a piece of the AI governance problem but no single body integrates their knowledge into a coherent ICFR control programme. The CFO knows that AI is being used in the close but does not know the technical validation requirements. The data scientist knows the model's accuracy characteristics but does not know the ICFR implications of model drift. The CRO is assessing enterprise-level AI risk but has not mapped it to individual financial statement line items.

The GenAI Council's charter, as described in the guidance, includes: approving the AI inventory and capability classification, setting the monitoring KPIs and escalation thresholds, approving model revalidation schedules, reviewing and approving model changes before deployment, and ensuring ICFR implications of AI changes are assessed before the changes take effect.

Change #3: Shadow AI Is the Single Largest Vulnerability, What the Inventory Requirement Now Covers

Shadow AI refers to any generative AI tools or features used by employees for business purposes without formal authorisation or oversight from IT and compliance departments.

Oreate AI confirmed: shadow AI is the single largest vulnerability in AI governance for financial reporting. The gap between deploying AI and governing AI is widest at the shadow AI boundary.

The COSO guidance's inventory requirement is broader than the SOX-relevant AI inventory described in the FEI framework blog. The FEI framework asked for the AI tools whose outputs directly affect material financial statement amounts. The COSO guidance asks for a complete inventory of all GenAI tools used in business processes, which is then filtered for ICFR relevance.

The reason the inventory must start broader: shadow AI tools by definition have not been formally approved and are not on any existing IT asset list. A finance team member using a personal ChatGPT subscription to assist with MD&A drafting is using shadow AI. A tax analyst using an AI-assisted research tool subscribed through a browser extension is using shadow AI. An accounts payable team using an AI feature within a cloud accounting platform that was recently updated without IT notification is using shadow AI.

The shadow AI inventory process the COSO guidance recommends: survey all business unit leaders about AI tool use in their teams, including AI features within existing software platforms. Categorise each identified tool by the COSO capability taxonomy. Identify which capability types affect financial reporting processes. Assess ICFR implications for those tools.

The risk the COSO guidance highlights for shadow AI specifically: shadow AI tools are not subject to the company's change management process, model validation requirements, or access controls. An AI tool in the posting or judgment capability types that is operating outside the company's change management framework is an ICFR control that has not been designed, tested, or approved. If it produces an error that affects a material financial statement amount, the company has no documented control over that tool and no evidence that its output was adequately reviewed.

Change #4: Probabilistic AI vs. Deterministic Controls, Why Your Control Matrix Must Be Rebuilt for AI's Non-Deterministic Nature

GenAI necessitates a fundamental shift in mindset: moving from deterministic, rule-based technologies to probabilistic models with inherently variable outcomes.

Traditional ICFR controls are designed around deterministic processes. A spreadsheet formula, given the same inputs, always produces the same output. The control over a spreadsheet calculation is validated by testing that the formula is correct and that the input data is accurate. If the formula is correct and the inputs are correct, the output is correct.

GenAI does not work this way. The same prompt, given the same input data, may produce different outputs on different queries, because the model's inference process involves probabilistic sampling that produces variation. A judgment capability AI generating a credit loss reserve estimate will not produce the identical estimate if asked twice. Its outputs are calibrated around a central tendency that is intended to be accurate, but the specific output varies.

The control implications of probabilistic AI output:

Testing a deterministic control by verifying one correct output is sufficient evidence that the control works. Testing a probabilistic AI control by verifying one correct output is not sufficient, because the output varies. Control testing for AI must include a population of test cases that represents the distribution of inputs the model will encounter in production, not just a single test scenario.

A deterministic control failure is binary: the formula is either correct or incorrect. A probabilistic AI control failure is distributional: the model's outputs may be correct most of the time but wrong often enough to produce a material misstatement under specific conditions. The ICFR risk assessment for a probabilistic AI control must assess the probability distribution of errors, not just whether errors are possible.

The control matrix update the COSO guidance requires: for each AI tool in the posting, orchestration, and judgment capability types, the control matrix must document the expected output accuracy range, the testing methodology for assessing whether outputs fall within the acceptable range, the monitoring KPI for ongoing accuracy assessment, and the escalation protocol for when accuracy falls outside the acceptable range.

How COSO GenAI Guidance Interacts With the FEI AI-ICFR Framework and the FASB Disclosure Standard

The COSO guidance is the foundational document. The FEI framework and the SEC's disclosure framework are its downstream applications.

The FEI AI-ICFR framework (June 2026, authored by Meta, Walmart, ServiceNow, and Alphabet controllers) is explicitly mapped to COSO. The four FEI control approaches (human-in-the-loop, performance testing, multi-model validation, data analytics) are the FEI team's operationalisation of the COSO guidance's control activity requirements for each capability type. The shadow reliance concept the FEI framework highlights is the FEI team's application of the COSO guidance's monitoring requirement. A company that implements the FEI framework is implementing the COSO guidance in the specific context of SOX ICFR controls.

The SEC's disclosure framework: as described in the AI regulatory signals blog in this cluster, the SEC's current position applies the existing materiality standard to AI disclosure, using the COSO framework as the reference for what adequate controls look like. A company that has implemented the COSO capability-first taxonomy and the COSO six-step implementation roadmap is in a position to describe its AI governance in terms that satisfy the SEC's disclosure expectation, whatever form that expectation eventually takes.

The QC 1000 and December 15 standards connection: the five PCAOB standards effective December 15, 2026 (covered in the companion blog) include AS 2101 (amended audit planning) and AS 2201 (amended ICFR audit). Both standards require auditors to assess AI tools in ICFR-relevant processes. The COSO GenAI guidance is the reference document auditors will use when assessing whether a company's AI controls are adequate. A company that has implemented the COSO guidance before December 15 is positioned for the first year-end audit under the amended standards.

What Must Be Updated in Your SOX Program Before December 15, 2026?

The COSO guidance includes a six-step implementation roadmap: govern, inventory, assess, design, implement, and monitor. Mapped to the December 15 deadline, the steps that must be completed before that date:

Govern: establish the GenAI Council or equivalent cross-functional governance body. The CFO, CRO, and Lead Data Scientist (or equivalent) must have a defined governance structure with a charter, meeting cadence, and defined accountability for AI ICFR controls.

Inventory: complete the full GenAI inventory, including shadow AI. Survey all finance and related teams. Map each AI tool to one or more of the eight COSO capability types. Identify which capability types affect financial reporting processes and therefore require ICFR assessment.

Assess: perform the ICFR risk assessment for each capability type in the inventory. The assessment must address the probabilistic failure mode specific to GenAI, not just the traditional risks of data accuracy and completeness.

Design: design controls for each ICFR-relevant AI capability, selecting from the four FEI control approaches (HITL, performance testing, multi-model validation, analytics) or combinations thereof. Document the control design in the control matrix, including the KPI for monitoring, the escalation threshold, and the evidence standard.

Implement: implement the controls, including updating the change management programme to treat model version changes and prompt changes as change-managed configuration items, establishing the monitoring dashboard for each AI KPI, and training the relevant finance team members on the new control procedures.

Monitor: establish the continuous monitoring process. This is the ongoing phase that continues after December 15 and that replaces the annual-cycle testing model for AI controls.

Frequently Asked Questions

What is the COSO February 2026 GenAI guidance?

The COSO GenAI guidance, titled Achieving Effective Internal Control Over Generative AI, was released on February 23, 2026 by the Committee of Sponsoring Organizations of the Treadway Commission. It adapts COSO's Internal Control: Integrated Framework (2013) into practical, audit-ready guidance for governing generative AI. It introduces a capability-first taxonomy, a six-step implementation roadmap, and minimum control expectations for each capability type.

What is the capability-first taxonomy in the COSO GenAI guidance?

The capability-first taxonomy organises GenAI use cases into eight capability types: ingestion, transformation, posting, orchestration, judgment, monitoring, regulatory intelligence, and human-AI interaction. Each capability type has tailored control considerations reflecting how GenAI risks manifest across the data-to-decision lifecycle. The taxonomy is capability-first rather than vendor-first because the same AI tool may perform different capability types in different contexts, each with different control requirements.

Did the SEC confirm COSO as the governing framework for AI in financial reporting?

Yes. At a June 4, 2026 conference, an SEC official confirmed that COSO's principles-based frameworks, as well as the SEC's guidance on management's ICFR reporting, are helpful resources for AI governance.

What does the COSO guidance say about shadow AI in financial close processes?

Shadow AI refers to any generative AI tools or features used by employees for business purposes without formal authorisation or oversight. The COSO guidance identifies shadow AI as the single largest vulnerability in AI governance. The guidance requires a complete inventory of all GenAI tools in use, including shadow AI tools, before the ICFR relevance assessment is performed.

Why are static annual risk assessments obsolete under the COSO GenAI guidance?

GenAI necessitates a fundamental shift from static, point-in-time assurance to continuous monitoring of model performance and risk. Monitoring plays a key role when GenAI is used in financial reporting, since "set-and-forget" does not work. AI model accuracy can drift without a configuration change that would trigger a traditional annual risk assessment update. The COSO guidance requires KPI-based continuous monitoring for each AI capability type in the ICFR scope.

Key Takeaways

  • On February 23, 2026, COSO released Achieving Effective Internal Control Over Generative AI, adapting the 2013 Internal Control: Integrated Framework into practical, audit-ready guidance for governing GenAI. The guidance was authored by controllers and academics from EY, Meta, Arizona State, University of Duisburg-Essen, and BYU.

  • The capability-first taxonomy organises all GenAI use cases into eight types: ingestion, transformation, posting, orchestration, judgment, monitoring, regulatory intelligence, and human-AI interaction. Each type has tailored control considerations, minimum control expectations mapped to the five COSO components, and illustrative KPIs.

  • The SEC confirmed the COSO framework as the governing reference for AI in financial reporting at a June 4, 2026 conference.

  • Four key changes from traditional SOX programme design: continuous AI risk assessment replaces static annual assessment; a cross-functional GenAI Council (CFO, CRO, Lead Data Scientist) owns AI governance; shadow AI inventory covers all GenAI tools including unapproved ones; probabilistic control design replaces deterministic control design for AI controls.

  • Shadow AI is the single largest vulnerability. The gap between deploying AI and governing AI is widest at the shadow AI boundary. The inventory must start broad and filter for ICFR relevance, not start with the ICFR-relevant tools and miss shadow AI that has crept into financial reporting processes.

  • The six-step implementation roadmap is: govern, inventory, assess, design, implement, and monitor. Monitoring is the ongoing phase that replaces the annual testing cycle for AI controls.

  • The COSO guidance is the foundational document for the AI in ICFR ecosystem: the FEI AI-ICFR framework extends it for SOX 302 certification contexts, the SEC's disclosure expectation references it as the control baseline, and the December 15 PCAOB standards (AS 2101 and AS 2201) will use it as the auditor's reference for assessing AI ICFR adequacy.

Run your financial reporting on Finrep