An Audit Plan With AI at the Top
On September 28, Gartner opened its Enterprise Risk, Audit & Compliance Conference in London by naming the areas internal audit leaders should prioritize in their 2027 plans. Two of its three themes concern artificial intelligence, and the figure that framed the session came from a survey of 190 audit leaders conducted in May and June: 85% said their organizations lack comprehensive AI governance.1 Earlier in the month, Gartner reported that 83% of audit leaders rank AI governance as a 2026 priority while only 34% feel confident they can address it.2
“AI systems are being deployed faster than governance can keep pace.”
— Daniel Ryntjes, Senior Principal Analyst, Gartner, September 28, 2026
Most people will read those numbers as a security problem. For the chief financial officer, however, the sharper question concerns financial reporting. A portion of the AI that audit leaders cannot see is already producing figures that end up in a closed package, a forecast, or a reconciliation. Much of it was built by people in finance who would never describe themselves as developers, using an agent that sits inside the spreadsheet they open every morning.

The Signal Internal audit has placed AI governance at the top of its 2027 agenda in the same year that every major productivity suite made it possible for an analyst to generate a complete financial model from a prompt. The intersection of those two developments lands on the controller’s desk and, eventually, on the certification the CFO signs.
Agents Now Write the Spreadsheets
The spreadsheet has been the canonical citizen-built application for forty years, and finance learned its risks the hard way. The Sarbanes-Oxley Act required chief executives and chief financial officers to certify their financial reports and to assess internal control over financial reporting. Spreadsheets that fed those reports thereby became control objects in their own right.3 Most large companies responded with end-user computing programs that inventory critical workbooks, restrict who can change them, and review the logic inside them.
The cost of skipping that discipline is documented. When JPMorgan Chase settled with the Securities and Exchange Commission in 2013 over the “London Whale” trading losses, the bank admitted to “woefully deficient accounting controls” that included “spreadsheet miscalculations that caused large valuation errors.” It paid a $200 million penalty to the SEC as part of a $920 million global settlement.4 Even so, that case involved formulas a person had written and could, in principle, explain to an investigator.
Over the past year, the authorship of that logic has changed. In a survey of 183 finance leaders published last November, Gartner found that 59% use AI in their departments, with knowledge management, accounts payable automation, and anomaly detection leading the list of use cases.5 Meanwhile, the four vendors that dominate office productivity each shipped an agent that builds spreadsheets directly:
- Microsoft made Agent Mode in Excel generally available on the desktop on January 27, 2026.6
- OpenAI introduced ChatGPT for Excel on March 5, 2026, describing it as a way to “build, update, and analyze spreadsheet models directly in your workbook,” and made it generally available across plans in May.7
- Anthropic released Claude for Excel as a research preview in October 2025, stating that it can “read, analyze, modify, and create new Excel workbooks.”8
- Google began rolling out the ability to “build and edit entire spreadsheets using simple natural language” in Google Sheets on April 22, 2026.9

Additionally, using any of these tools requires no developer, no deployment, and no IT ticket. A senior accountant can describe an accrual roll-forward or a revenue bridge in a sentence and receive a working model in minutes, which is exactly the productivity these vendors promise. The operational cost of supporting that volume of citizen-built software across identity, security, and the service desk was the subject of Citizen Development and the New Frontier of Technical Debt. However, the financial-reporting exposure follows a separate path, since it turns on whether the logic inside a tool can be trusted, reviewed, and reproduced at the moment an auditor asks.
Where End-User Computing Controls Stop Working
A mature end-user computing program rests on a handful of assumptions about how a workbook comes into being and how it changes. Each assumption made sense when a person typed every formula, and each one weakens when an agent generates the logic on request.
Logic review illustrates the problem in terms every controller will recognize. Traditional spreadsheet review asks a second person to trace the formulas and confirm that they implement the intended calculation. When an agent builds a fifty-tab model in minutes, the reviewer inherits logic that nobody on the team authored. The practical temptation is then to check the outputs against expectations and skip the construction entirely. The Committee of Sponsoring Organizations of the Treadway Commission addressed this shift directly in February, when it published Achieving Effective Internal Control Over Generative AI. The guidance calls for “a fundamental shift in mindset” away from “deterministic, rule-based technologies to probabilistic models with inherently variable outcomes,” and it warns that for monitoring, “set-and-forget does not work.”10
“GenAI can be confidently wrong, easily manipulated, or deployed outside formal oversight channels.”
— Lucia Wind, Executive Director and Chair, COSO, February 23, 2026
Research on software developers describes this pattern as cognitive offloading, the delegation of mental work to an external system, and traces a predictable progression from automation bias to uncritical acceptance, habitual reliance, and eventually the erosion of independent skill, as examined in The Atrophy Risk: What Happens to Developers When AI Goes Dark. Furthermore, finance adds a layer that software review rarely has, since the preparer offloads the construction to the agent and the reviewer then defers to the preparer’s sign-off, so the logic can pass through two sets of hands without either one examining it. Over time, the cost is likely to fall on the people who will eventually do the reviewing. Junior accountants have traditionally learned the business by building roll-forwards, accrual schedules, and reconciliations themselves, and a staff that never builds those models will one day be asked to review ones it never learned to construct.
Finance leaders report the same experience from the other side. In a July survey of 270 CFOs and finance leaders at U.S. companies with more than $100 million in revenue, Datarails found that teams spend 26% of their work week verifying or correcting AI outputs. Furthermore, 65% name confident answers built on the wrong data as their most common frustration, and only 4% trust AI for month-end close work without human review.11 Because those figures describe sanctioned tools under supervision, the exposure is likely to grow wherever an analyst builds a tool independently and the review step happens informally or not at all.

The standard end-user computing controls each rest on an assumption that agent-built tools disturb:
| Control | Assumption it relied on | What changes with agent-built tools |
|---|---|---|
| Inventory of critical workbooks | Key spreadsheets are few, long-lived, and known to their owners | New models appear in minutes, often as one-off files outside any register |
| Logic review | A person wrote the formulas and can walk a reviewer through them | The preparer may be unable to explain construction the agent chose |
| Change management | Changes are incremental edits that can be compared version to version | Regenerating a model can alter logic wholesale with no clean comparison |
| Completeness and accuracy of reports | Source data and transformations are traceable and repeatable | Traceable within the session; repeatability depends on retained prompts and versions |
| Access restriction | Only designated staff can modify a key workbook | Anyone with the add-in can build a parallel version from the same data |
Auditors already find weaknesses in completeness and accuracy without any AI in the picture. KPMG’s analysis of fiscal 2025 filings identified 238 companies reporting material weaknesses. Among the recurring failures, it cited documentation of the completeness and accuracy of information produced by the entity, along with the review of journal entries and account reconciliations. The same study found that material weaknesses tied to inadequate accounting resources rose 14% year over year.12 Those two findings reinforce each other, since understaffed finance teams are precisely the teams most likely to reach for an agent that compresses a week of model building into an afternoon.
Questions of data provenance compound the problem once an agent can reach beyond the general ledger. Google describes Gemini in Sheets as drawing on Workspace Intelligence, which synthesizes information across a user’s files, emails, chats, and the web.9 That capability saves hours of gathering, yet it also means a figure in a reconciliation can trace back to an email attachment or a shared document that sits outside every system the auditor has tested. Traditionally, information produced by the entity is validated by tracing it to a controlled source, such as a general ledger extract or a system report with tested logic. Therefore, a model that quietly blends controlled and uncontrolled inputs makes that tracing harder, and the difficulty grows with every source the agent is permitted to reach.
The Certifying Officer’s Exposure
For the CFO, the consequence is concrete, since the Section 302 certifications and the Section 404 assessment draw no distinction between a calculation a staff accountant wrote and one an agent generated.3 Therefore, an agent-built workbook that supports a key control inherits every expectation that applied to the spreadsheet it replaced, along with new questions about how its logic was produced and whether anyone can reproduce it.
External auditors, for their part, have not received a new rulebook for this situation. The Public Company Accounting Oversight Board amended AS 1105 and AS 2301 in 2024 to clarify how auditors evaluate electronic information and technology-assisted analysis. The changes took effect for fiscal years beginning on or after December 15, 2025, and they govern the auditor’s own procedures.13 The Board’s March 2026 request for comment on its strategic priorities asked how the PCAOB itself should deploy technology, including AI, and it proposed no standard on companies’ use of AI in their controls.14 Consequently, the existing framework applies as written, and auditors can be expected to test an agent-built model with the same skepticism they bring to any key spreadsheet, likely with additional questions about how its logic was generated. Gartner’s guidance to chief audit executives points in the same direction, recommending that audit teams participate in AI governance and innovation committees and assess the completeness of the AI inventories that second-line functions maintain.2 Internal audit, in other words, is being advised to look for these tools before the external auditor does.
Two objections come from the controllership side, and each draws on what the vendors have actually built. The first holds that agent-built spreadsheets may be better controlled than hand-built ones. OpenAI says its Excel tool “explains what it’s doing as it works and links answers to the exact cells it references,” and Anthropic describes Claude for Excel as tracking and explaining its changes.7,8 A human analyst working late on a close deadline offers no such narration, and many of the worst spreadsheet failures involved errors that nobody documented. The second objection holds that the direction of travel runs through enterprise systems. Gartner predicts that finance organizations using cloud ERP applications with embedded AI will close their books 30% faster by 2028, and it lists continuous controls monitoring among the capabilities those platforms will bring.15 On that view, the citizen-built workbook is a transitional artifact that governed platforms will eventually absorb.
Both arguments carry weight, and an effective control program should take advantage of them. However, neither one closes the evidentiary gap on its own. In-session explanations help the preparer, but a control owner needs that explanation retained, versioned, and available months later when the auditor selects the item for testing. Furthermore, embedded ERP intelligence and citizen-built tools will coexist for years, since the workbook remains the place where finance staff reconcile whatever the systems of record leave unresolved. The transparency the vendors provide is a strong starting point, but converting it into audit evidence remains the company’s responsibility.
Logging and Retention Across the Spreadsheet Agents
The four suppliers of spreadsheet agents have each built features a control owner can use, and each leaves gaps the enterprise must close on its own:
| Vendor | Spreadsheet agent | Transparency and logging the vendor documents | Gap for a financial-reporting control owner |
|---|---|---|---|
| Microsoft | Agent Mode in Excel (GA, January 2026) | Purview has audited more than 50 billion Copilot interactions for compliance purposes | Capturing interactions leaves the logic of a key workbook unversioned unless the company adds that control |
| OpenAI | ChatGPT for Excel (GA, May 2026) | Step-by-step explanations linked to cells; edits can be reviewed before they apply and undone | Explanations live in the session unless the company retains them |
| Anthropic | Claude for Excel (research preview from October 2025) | Tracks and explains changes and navigates to the cells it references | Same retention question, and preview status at launch |
| Gemini in Sheets (rollout from April 2026) | Admin log events record when and where users invoke Gemini | Documented log events capture usage metadata only |
The table draws on Microsoft’s July earnings call, the vendors’ launch announcements, and Google’s administrator documentation.16,17 Across all four, the pattern is consistent, although it is an interpretation the vendors themselves have not stated. Each supplier has invested in helping the user understand what the agent did in the moment, and each provides administrative visibility into usage. None of the published materials describes a mechanism that designates a workbook as a key report, freezes its logic, and routes any regeneration through change control. That capability belongs to the enterprise’s control environment, and finance will have to assemble it from existing end-user computing tools, document management, and policy.
The vendor landscape also concentrates inside a single application. ChatGPT for Excel works directly in the user’s workbook, and Claude for Excel runs in a sidebar within Microsoft Excel.7,8 Consequently, a company that has standardized on Microsoft 365 may still host agents from three different vendors inside the same workbook, each with its own retention terms and logging.
Bring Agent-Built Tools Inside the Control Perimeter
The objective is to let finance staff keep the speed these agents provide while ensuring that anything feeding a financial report meets the evidentiary standard an auditor will apply, and five practices accomplish most of that work:
-
Map AI use cases to financial reporting processes. COSO’s guidance recommends maintaining a generative AI use-case inventory and mapping in-scope use cases to financial reporting processes.10 Extend the existing end-user computing register to record whether a workbook or tool was agent-built and whether it supports a key control. Internal audit should then test the completeness of that register, as Gartner advises for AI inventories generally.2
-
Freeze the logic once a tool supports a key control. An agent-built model that feeds a reconciliation, an estimate, or a disclosure should be locked, versioned, and stored in a controlled repository. Subsequent changes, including a full regeneration, should pass through the same change review that applies to any key spreadsheet, with the prompt and the resulting differences retained as evidence.
-
Require the preparer to own the construction. Review procedures should confirm that the preparer can explain the model’s logic in their own words, and reviewers should test construction as well as outputs for key reports. A tool whose preparer cannot explain how a figure is produced should not yet support a control.
-
Approve each spreadsheet agent as a control decision. Because one workbook can host agents from several vendors, the add-in catalog determines which vendors’ logs will exist when an auditor asks how a key figure was produced. Finance and IT should approve those agents jointly, confirm that each one’s activity can be retained for the period the audit requires, and disable the ones that cannot meet that standard for workbooks that support key controls.
-
Brief the external auditor before the year-end walkthrough. Auditors will encounter agent-built workbooks during walkthroughs whether or not management raises them. A short session early in the cycle, covering where these tools sit, how they are inventoried, and what evidence is retained, keeps a late discovery from turning into a deficiency discussion.
Each practice leaves the ability to build with finance staff while ensuring that a tool crossing into financial reporting arrives with the documentation and ownership the reporting process already demands.
The Same Signature on the Certification
Finance has managed citizen-built software for as long as spreadsheets have existed, and the profession built a workable control discipline after Sarbanes-Oxley exposed what happens without one. The arrival of agents inside Excel and Google Sheets accelerates the creation of those tools enormously while leaving the obligations around them exactly where they were, with the preparer, the reviewer, and the officers who certify the results. Audit leaders have now placed AI governance at the top of their agenda, and the workbook an analyst generated last quarter is one of the places they will look. CFOs who extend their end-user computing controls to agent-built tools before year-end will be able to answer that inquiry with evidence already on file.
References
- Gartner, “Gartner Identifies 12 Audit Plan Hot Spots for 2027,” press release, September 28, 2026, https://www.gartner.com/en/newsroom/press-releases/2026-09-28-gartner-identifies-12-audit-plan-hot-spots-for-2027.
- Gartner, “The Biggest AI Audit Risk Is What You Can’t See,” Gartner Insights, September 9, 2026, https://www.gartner.com/en/articles/audit-ai-deployment-risk.
- Sarbanes-Oxley Act of 2002, Pub. L. No. 107-204, §§ 302, 404, 116 Stat. 745.
- U.S. Securities and Exchange Commission, “JPMorgan Chase Agrees to Pay $200 Million and Admits Wrongdoing to Settle SEC Charges,” press release 2013-187, September 19, 2013, https://www.sec.gov/news/press-release/2013-187.
- Alexei Alexis, “CFOs’ AI Adoption Slows as Challenges Mount: Gartner,” CFO Dive, November 19, 2025, https://www.cfodive.com/news/cfos-ai-adoption-slows-challenges-mount-gartner/805949/.
- Microsoft, “Agent Mode in Excel Is Now Generally Available on Desktop,” Microsoft Excel Blog, January 27, 2026, https://techcommunity.microsoft.com/blog/excelblog/agent-mode-in-excel-is-now-generally-available-on-desktop/4457408.
- OpenAI, “Introducing ChatGPT for Excel and New Financial Data Integrations,” March 5, 2026, updated May 5, 2026, https://openai.com/index/chatgpt-for-excel/.
- Anthropic, “Advancing Claude for Financial Services,” October 27, 2025, https://www.anthropic.com/news/advancing-claude-for-financial-services.
- Google, “Build and Edit Complex Spreadsheets with Gemini in Google Sheets,” Google Workspace Updates, April 22, 2026, https://workspaceupdates.googleblog.com/2026/04/build-and-edit-complex-spreadsheets-with-Gemini-in-Google-Sheets.html.
- Committee of Sponsoring Organizations of the Treadway Commission, Achieving Effective Internal Control Over Generative AI (COSO, February 23, 2026), as announced in “COSO Releases Practical Roadmap for Managing Generative AI Risks and Controls,” PR Newswire, February 23, 2026, https://www.prnewswire.com/news-releases/coso-releases-practical-roadmap-for-managing-generative-ai-risks-and-controls-302694327.html, and summarized in Deloitte, “COSO Releases Publication on Internal Controls Related to Generative AI,” Heads Up, April 3, 2026, https://dart.deloitte.com/USDART/home/publications/deloitte/heads-up/2026/coso-internal-controls-generative-ai.
- Datarails, “Finance Teams Now Spend a Quarter of Their Week Fact-Checking AI, New Datarails Survey Finds,” PR Newswire, July 2026, https://www.prnewswire.com/news-releases/finance-teams-now-spend-a-quarter-of-their-week-fact-checking-ai-new-datarails-survey-finds-302899700.html.
- KPMG, “Trends in Material Weaknesses,” 2026, https://kpmg.com/us/en/articles/2026/trends-material-weaknesses.html.
- Public Company Accounting Oversight Board, “PCAOB Updates Its Standards to Clarify Auditor Responsibilities When Using Technology-Assisted Analysis,” press release, June 12, 2024, https://pcaobus.org/news-events/news-releases/news-release-detail/pcaob-updates-its-standards-to-clarify-auditor-responsibilities-when-using-technology-assisted-analysis.
- Public Company Accounting Oversight Board, “PCAOB Requests Public Comment on Strategic Priorities,” press release, March 31, 2026, https://pcaobus.org/news-events/news-releases/news-release-detail/pcaob-requests-public-comment-on-strategic-priorities.
- Gartner, “Gartner Predicts Embedded AI in Cloud ERP Applications Will Drive a 30% Faster Financial Close by 2028,” press release, February 24, 2026, https://www.gartner.com/en/newsroom/press-releases/2026-02-24-gartner-predicts-embedded-ai-in-cloud-erp-applications-will-drive-a-30-percent-faster-financial-close-by-2028.
- Microsoft Corporation, “Microsoft Fiscal Year 2026 Fourth Quarter Earnings Conference Call,” transcript, July 29, 2026, https://www.microsoft.com/en-us/investor/events/fy-2026/earnings-fy-2026-q4.
- Google, “Gemini for Workspace Log Events,” Google Workspace Admin Help, accessed October 6, 2026, https://knowledge.workspace.google.com/admin/reports/gemini-for-workspace-log-events.