Gana Misra
By Gana MisraCEO, Finrep
Wed Sep 23 2026

Reviewing AI-Drafted Financial Commentary: A CFO's Process Guide

Share
Reviewing AI-Drafted Financial Commentary: A CFO's Process Guide

Reviewing AI-Drafted Financial Commentary Before Publication: A Practitioner's Framework

71% of CFOs at large enterprises now use AI tools somewhere in the financial reporting process. Only 29% have a formal, documented review protocol for what comes out, according to KPMG's 2026 CFO survey. That gap is where audit risk lives.

This guide is for the finance, ESG, and compliance professionals who are already using AI to draft MD&A sections, earnings releases, CSRD narratives, or board packs, and need a repeatable, defensible process for reviewing that output before it becomes public record. It covers the specific failure modes of large language models on financial text, the staged review sequence that satisfies auditors and disclosure committees, and what to document so the CEO and CFO can certify in good faith.

For background on what regulators are actually requiring around AI-assisted disclosures, see the SEC AI financial reporting guidance compliance map and the companion piece on AI-generated MD&A SEC requirements.

Key takeaway: Financial commentary review is categorically different from general content review. The stakes are SOX certifications, SEC comment letters, PCAOB audit risk, and CSRD assurance. A generic AI content workflow is not enough.

Why Financial Commentary Review Is Different from Ordinary Content Review

Financial commentary carries legal liability that ordinary content does not. Under SOX Sections 302 and 906, the CEO and CFO personally certify that a filed report does not contain any untrue statement of material fact. Legal counsel at major firms including Skadden have confirmed in 2025 memos that this certification obligation applies regardless of whether AI drafted the text. The signatories remain personally liable.

The PCAOB's Staff Spotlight on AI in auditing makes the implication explicit: auditors must evaluate whether management's use of AI in preparing financial statements introduces new risks of material misstatement, and must obtain an understanding of the controls management has in place. If your team cannot show auditors a documented review process, you have a control gap.

For ESG and sustainability narrative, EFRAG's ESRS implementation guidance requires that every quantitative claim be traceable to a specific data point in the sustainability data management system, with the source system, extraction date, and transformation methodology documented. "The AI said so" is not a sufficient audit trail for a CSRD disclosure.

The SEC's Division of Corporation Finance has issued comment letters in 2024 and 2025 specifically questioning companies about their processes for ensuring accuracy in AI-assisted disclosures, particularly in MD&A and risk factor sections. This is no longer a theoretical governance question.

The Five Failure Modes of LLMs on Financial Text

Before building a review process, understand what you are actually looking for. PwC's 2025 guidance on AI in financial reporting identifies five structural failure modes specific to AI-drafted financial narrative:

  1. Temporal confusion. The model mixes figures from different reporting periods, citing Q3 2025 revenue in a Q2 2026 filing, or comparing current-period results against a prior-period comparative that has since been restated.
  2. Entity confusion. Results are attributed to the wrong subsidiary, segment, or geographic region, particularly in companies with complex group structures.
  3. Standard confusion. The model applies IFRS logic to a GAAP filing, or vice versa, producing disclosures that are grammatically correct but technically wrong.
  4. Materiality blindness. Immaterial and material items receive equal narrative emphasis, burying the disclosures that actually move markets.
  5. Forward-looking statement risk. LLMs naturally generate optimistic, projection-heavy language because such language is common in their training data. That language may not qualify for safe-harbour protection under the PSLRA unless accompanied by meaningful cautionary language.

There is a sixth risk that cuts across all five: the plausibility trap. AI-generated financial narrative reads fluently and confidently. Unlike a spreadsheet error that produces an obviously wrong number, an AI narrative error produces a grammatically perfect, contextually plausible sentence that is factually wrong. Reviewers who read for coherence will miss it. You must read for verifiability.

As JD Supra's analysis of AI audit failures puts it: "Effective prompting for financial and audit content means being as specific as the reviewer eventually will be. Name the entities. Reference the specific periods. Specify the accounting standard."

Stage 1: Upstream Quality Control (Before the Draft Exists)

The highest-leverage intervention in the AI review workflow happens before drafting begins, not after. EY's 2025 financial reporting AI guide calls this "upstream quality control" and treats it as the single most important step. Errors introduced at the prompt or data stage propagate through the entire draft and are significantly harder to catch in post-draft review.

Before generating any AI draft of financial commentary, the following must be approved:

  • Data inputs reviewed and locked. The trial balance extract, segment data, prior-period comparatives, and any non-GAAP reconciliations that will feed the prompt must be reviewed and signed off by the finance team member who owns the underlying data. Stale or unreconciled data in, hallucinated precision out.
  • Prompt reviewed and standardised. Prompts should name the specific entity, reporting period, applicable accounting standard (ASC or IFRS), filer category, and document type. Prompts that vary by whoever runs them produce drafts that vary by whoever runs them, making review unpredictable. Maintain a prompt library with version control.
  • Scope defined. Specify which sections the AI is drafting and which remain human-authored. AI drafting of forward-looking sections (outlook, targets, guidance) should require explicit approval from legal counsel before the prompt is run, given PSLRA exposure.
  • Document the inputs. Record the data sources used, the prompt version, and who approved both. This becomes part of the audit trail.

Stage 2: Automated Consistency Checks

Run automated checks before any human reads the draft. Deloitte's AI governance framework for financial reporting is explicit: skipping automated checks forces all the burden onto human reviewers and dramatically increases error rates. These checks are not optional quality-of-life improvements; they are a control layer.

Specific checks to automate:

  • Figure-to-financial-statement matching. Every number cited in the narrative must match the corresponding line in the financial statements. Revenue, gross margin, EBITDA, net income, EPS, cash and equivalents.
  • Percentage change verification. Recalculate every stated percentage change from the base figures cited. LLMs frequently state the directionally correct change but get the magnitude wrong.
  • Segment attribution. Confirm that results are attributed to the correct segment or geographic region, cross-referencing the segment footnote.
  • Prior-period comparative consistency. Verify that prior-period figures match the restated (if applicable) comparatives in the filed prior-period report, not the originally reported figures.
  • Non-GAAP reconciliation alignment. Any non-GAAP metric cited in the narrative must reconcile to the formal non-GAAP reconciliation table.
  • Period reference audit. Flag every date and period reference in the draft and confirm it refers to the correct period.

Tools that connect directly to the general ledger or reporting system can run most of these checks programmatically. For teams without that infrastructure, a structured spreadsheet cross-reference is the minimum acceptable standard.

Stage 3: Subject-Matter Expert Review

The finance team member who owns the underlying data reviews the draft, not whoever happened to run the prompt. This is the human layer that catches what automation cannot: business context, management intent, and the judgment calls that determine whether a disclosure is complete.

At this stage, the reviewer is not reading for style. They are reading for verifiability. For every substantive claim in the draft, the reviewer should be able to answer: where does this come from, and is it accurate?

The Ledge professional judgment checklist frames the standard well: "I am not approving the work only because the system produced it. I have paused to investigate anything that does not look right. I have considered whether additional business context is needed."

Practical checks at this stage:

  • Does the narrative reflect the actual business story, or a plausible-but-wrong version of it?
  • Are material items given appropriate emphasis? Are immaterial items crowding out material ones?
  • Are there omissions? AI drafts what it was prompted to draft; it does not know what it does not know. The SME must check for required disclosures that are absent.
  • Does the tone and framing align with prior filings? Significant shifts in language can attract SEC comment letters.
  • For forward-looking sections: is every projection or target accompanied by appropriate cautionary language? Flag any optimistic language that was not in the approved prompt scope.

The disclosure committee is the appropriate final review gate for AI-drafted content destined for public filing. This is standard governance infrastructure at public companies, and it applies regardless of whether AI was involved in drafting. The involvement of AI makes it more important, not less.

The disclosure committee, typically comprising the CFO, General Counsel, Chief Accounting Officer, and heads of IR and compliance, should add a standing agenda item for AI-assisted content. For each AI-drafted section, the committee should confirm:

  • What was AI-drafted and what was human-authored
  • Which review steps were completed and by whom
  • Whether any forward-looking statements require additional PSLRA safe-harbour language
  • Whether the disclosure is consistent with the company's prior public statements
  • Whether any new disclosure obligations have been triggered (see the AI disclosure in 10-Q guide for current SEC expectations)

Legal counsel must review any section containing projections, targets, or outlook language before it is finalised. This is non-negotiable given PSLRA exposure.

Stage 5: CEO/CFO Sign-Off and Audit Trail Documentation

The SOX 302 certification requires the CEO and CFO to certify they have reviewed the report. That certification is not satisfied by reviewing a summary; it requires a genuine understanding of the content and the process by which it was produced. The audit trail documentation you create at each stage is what allows the CEO and CFO to make that certification in good faith.

What to document and retain:

Documentation itemPurposeRetained by
Approved data inputs and extraction dateProves the draft was grounded in actual financialsFinance / Controller
Prompt version and approval recordEstablishes what the AI was asked to produceFinance / IT
Automated check results and exceptions logDemonstrates systematic consistency verificationFinance / Controller
SME review sign-off with date and nameEstablishes human accountability for content accuracyFinance
Disclosure committee minutes referencing AI-drafted sectionsGovernance record for auditors and audit committeeLegal / Secretary
Legal review confirmation for forward-looking sectionsPSLRA safe-harbour documentationLegal
Final version with tracked changes from AI draftShows the delta between AI output and published textFinance / IR

Auditors will ask for this documentation. The PCAOB's guidance makes clear that auditors must obtain an understanding of management's controls over AI-assisted reporting. "We reviewed it" is not a control; a documented process with named reviewers and retained records is.

The Harvard Law School Forum on Corporate Governance's 2025 analysis notes that audit committees are increasingly asking management to present their AI governance policies for financial reporting, and that companies without documented policies are receiving more pointed questions from auditors and institutional investors.

How the Review Process Differs by Document Type

Not all financial commentary carries the same stakes. Allocate review intensity accordingly.

Document typeRegulatory obligationCEO/CFO certificationAuditor reviewAssurance requirementRecommended review stages
10-K MD&ASEC Reg S-K Item 303Yes (SOX 302/906)YesYes (financial)All 5 stages
10-Q MD&ASEC Reg S-K Item 303Yes (SOX 302/906)LimitedNoAll 5 stages
Earnings release (8-K)Item 2.02No, but market-sensitiveNoNoStages 1-4
ESG/CSRD reportESRS / ISSB S1-S2No (but board approved)NoYes (limited assurance)All 5 stages + data traceability check
Board packInternalNoNoNoStages 1-3
Investor presentationReg FDNoNoNoStages 1-4

For ESG and CSRD narrative specifically, the review process must include a data traceability check that sits alongside Stage 2. Every quantitative claim in the AI-drafted text must be traceable to a specific data point in the sustainability data management system, with the source system, extraction date, and any transformation methodology documented. EFRAG's assurance guidance is unambiguous on this point. The IFRS Foundation's 2025 ISSB implementation guidance applies the same principle to IFRS S1 and S2 disclosures: AI-assisted reporting must be subject to the same internal controls as other disclosure processes, and the governance over it must be documented and available to assurance providers.

Materiality-Weighted Review: Where to Spend the Time

Not every paragraph deserves equal review effort. PwC's 2025 guidance identifies materiality-weighted review as an emerging best practice: allocate more review time and more senior reviewers to sections of financial commentary that address material items. This mirrors the auditor's risk-based approach.

In practice, this means:

  • Sections describing material transactions, impairments, restructurings, or changes in accounting estimates get SME review plus disclosure committee attention.
  • Boilerplate sections (standard liquidity discussion, contractual obligations table narrative) get automated checks plus a lighter SME pass.
  • Any section containing forward-looking statements, non-GAAP metrics, or segment results gets legal review regardless of length.

This approach also addresses the efficiency concern. A structured, risk-tiered review process is faster than ad hoc review, not slower. Teams with formal AI content governance frameworks see 40-60% faster approval cycles, reducing revision rounds from 5-7 down to 2-3, according to Glean's 2026 analysis. The review burden falls on the right people for the right sections, rather than falling entirely on whoever is most available.

FAQ

Does using AI to draft financial commentary create new disclosure obligations? Not automatically, but the SEC is actively scrutinising this area. Comment letters issued in 2024-2025 have asked companies to describe their processes for ensuring accuracy in AI-assisted disclosures. Companies should review the AI disclosure in 10-Q guide for current staff expectations. The audit committee should also be informed of AI use in the reporting process as a matter of governance.

How do I know if an AI-generated figure is grounded in actual data versus hallucinated? You verify it against the source. Every number in an AI-drafted financial narrative must be traced back to the trial balance, the segment schedule, or the approved non-GAAP reconciliation. If you cannot source a figure, remove it. The plausibility trap means a hallucinated figure will read as confidently as a correct one.

Who should own the final quality gate for AI-drafted financial commentary? The disclosure committee owns the final gate for public filings. For internal documents, the CFO or Controller is the appropriate sign-off. Ownership must be explicit and documented; the common failure mode is that finance, legal, IR, and ESG all touch the document but nobody owns the final quality check.

What do auditors actually ask to see about AI use in the reporting process? Auditors will ask for evidence of the controls management has in place over AI-assisted reporting. That means: what data inputs were used and who approved them, what prompt was used and who approved it, what automated checks were run, who reviewed the output and when, and what the disclosure committee considered. The documentation framework in Stage 5 above covers all of these.

How does the ESG review process differ from the financial statement review process? The core stages are the same, but ESG review adds a mandatory data traceability check: every quantitative claim must be traceable to a specific data point in the sustainability data management system. Under CSRD limited assurance, the assurance provider will test this traceability directly. AI-generated ESG narrative that cannot be traced to verified source data will fail assurance review. See the AI hallucination in financial reporting walkthrough for specific failure patterns in sustainability narrative.

Can we use AI to help with the review itself, not just the drafting? Yes, and for the automated consistency checks in Stage 2, AI is the right tool. Automated figure-to-financial-statement matching, percentage change verification, and period reference auditing are all tasks where AI outperforms manual review for speed and completeness. The human judgment layers in Stages 3 and 4 cannot be delegated to AI; the materiality calls, business context checks, and legal assessments require professional judgment that the model does not have.

The 42% of companies that abandoned most of their generative AI initiatives in the past year, up from 17% in 2024, largely did so because quality and governance gaps outpaced the technology. A staged review framework does not slow down AI adoption; it is what makes AI adoption sustainable.

Run your financial reporting on Finrep