Global Business Services
Finance

The Governance Gap: 5 Considerations For Building A Controls Framework for Agentic AI

Sally Fletcher
October 6, 2026
4
min. read

How do you fit Agentic AI into your internal controls framework? Which controls are built in and which do you need to configure yourself? This blog explains.

Shift your operation teams to high-value tasks
By enabling Autonomous Finance
Free test demo

Agentic AI is moving into finance operations faster than the controls built to govern it. That was the starting point for The Governance Gap, a recent webinar hosted by SSON in collaboration with Hypatos, featuring Dr Uli Erxleben, Founder and CEO of Hypatos, and Dr Simon Rosa, Partner for Financial Accounting Advisory Services at EY.

Figure 1:

The opening poll set the tone. Most attendees said they have a controls framework that is still evolving, and only 15% described their governance as mature. The common pattern is to deploy agents first and bolt controls on later, but retrofitting controls is far harder than designing them in. The discussion that followed made the case for flipping that sequence, and five ideas stood out.

1. The governance gap is wider than most organizations admit

Industry survey data shared by Uli showed that 49% of companies have not yet updated their governance framework for GenAI and Agentic AI. That does not mean the other 51% are finished. In the speakers' experience, most of them are still in progress, and very few organizations are genuinely ready.

More worrying, 47% of organizations said they have bypassed existing standards to deploy AI. As Uli put it, you don't know what you don't know, so the real figure is likely higher. This arrives just as IT teams have gotten comfortable governing SaaS and GBS organizations are still embedding global process ownership. Agentic AI blends both challenges together, and the result is uncontrolled risk that also holds transformation back.

2. You don't need a new framework; you need continuous monitoring

Simon brought the good news: COSO remains the foundation. Its February 2026 guidance on achieving effective internal control over GenAI groups the work into five areas. These are operational and technology management; transparency, accountability and continuous improvement; data and copliance management; human, ethical and social considerations; and, underpinning everything, strategic alignment and the control environment. Without that last one, Simon warned, even the best framework will not help, and a comprehensive AI governance policy is where many organizations fall short.

The implementation roadmap runs in six steps (see figure 2): governance, inventory, risk assessment, design, implementation and continuous monitoring. Two shifts matter most. Risk should be assessed per capability, not per tool. And the typical annual assessment cycle no longer fits when agents make thousands of decisions a day. In Simon's words, “GenAI is not a new framework problem but a monitoring problem, and set-and-forget controls do not work.”

Figure 2:

3. The platform provides many of the controls, but you own how they are used

Using the accounts payable process as the example, Uli walked through where risk sits at each step. At ingestion, documents can go missing, arrive from unauthorized sources or be tampered with. At extraction, an agent that reads a $10 invoice as $10,000 creates real trouble, so validation such as checking that line items add up to the total has to be designed in. Tax compliance is riskier still: VAT requirements differ by country, and that knowledge must be curated and kept current by the tax department, not pulled from the internet.

The platform must deliver logging, confidence scores, accessible reasoning, anomaly detection, permissions, rollback, accuracy monitoring and alerts. But the software will not run your organization for you. Someone has to define roles, escalation paths and risk appetite, such as the invoice value above which a human must always review. Uli called this the big moment for process owners: they should own the agents' work instructions. With 17 agents in Hypatos' AP product alone, the person authorized to instruct a tax agent is not the same person who instructs an extraction agent, and every change needs an approver.

4. Treat AI output as evidence, and raise the bar accordingly

Simon's advice was to treat AI outputs as evidence, not as the sole truth, and to validate them with a second pair of eyes, just as you would human work. Reliance on AI raises the evidence bar. We accept that trained humans occasionally make mistakes and catch them through sampling, but the same tolerance does not apply to an agent.

The upside is that agents can clear that bar far more convincingly than people. Uli described an agent making a tax decision and writing a full protocol: the relevant attributes under local law, the work instruction it followed, what was on the invoice and how it reached its conclusion. That record goes into the archive for auditors. Simon noted that documenting judgment is exactly where organizations struggle today, because the knowledge sits in people's heads. Agentic AI turns that weakness into a strength, but only if the system is designed to explain every decision and a human reviews where it matters.

5. Governance is what lets you scale, so don’t skip it

Simon named shadow AI as the biggest practical risk he sees with clients. If you don't know what's running, you can't govern it. Asked whether citizen developer tools will lead to more shadow IT, his answer was a clear yes. The fix starts with an inventory and a register of every AI use case, clear rules on what people can and can't build, and governance over the tools themselves.

That groundwork pays off quickly. Uli expects organizations to go from one or two agents to thousands, and the time to plan for that scale is now. Leaders who skip governance risk a failure that costs them the mandate for transformation, or a forced stop to retrofit controls later. Controls are often seen as slowing things down, but done early and done well, they speed adoption up. As Simon summed it up, "the winners will not be the organizations with the most AI, but those with the most trustworthy AI."

What this means for GBS and finance leaders

The message from both speakers was consistent. You already know how to build an internal control system, and the principles have not changed. What has changed is how the work gets done, which means revisiting your risks, assigning clear ownership of agents and their instructions, and moving from periodic assessment to continuous monitoring. Done now, that work is what allows agentic AI to scale with trust rather than stall under scrutiny.

To watch the whole webinar, click here.  

‍

Unleash the potential of your people and business

Dial up results for any team with agentic transaction processing

Further stories from our blog