INTHEBLACK September 2026 - Flipbook - Page 45
“It is not enough to ask whether a human reviewed the
output. The better question is whether the agent was
authorised to perform the exact action, within exact limits,
using approved data, code and policy, and with a named
human accountable.”
DAVID LEE KUO CHUEN, SCHOOL OF BUSINESS, SINGAPORE UNIVERSITY OF SOCIAL SCIENCES
date and a revocation mechanism. The firm
should know who the agent is, what it can
do, what it cannot do and who is accountable
when something goes wrong.”
A clear delineation of tasks between
people and agents is also required.
“An AI agent can draft a memo, prepare
a first-pass analysis or recommend a journal
entry. But a named human should approve
material, irreversible or external-facing
actions,” Lee says. Examples include regulatory
filings, impairment judgements, revenue
recognition judgements, payment releases
and material journals.
Ordinary system access controls may not be
enough if an agent can browse, click buttons
and move through systems like a human user.
“The agent should operate in a sandbox with
domain allow lists, session logs, action-by-action
approval where needed and alerts when it
steps outside its mandate,” Lee says.
National regulatory postures around AI
are emerging. Safe AI Australia’s Guidance for
AI Adoption sets out six essential practices
for responsible governance and adoption
by organisations operating in the country.
The checklist covers accountability,
understanding impacts, managing risks,
sharing essential information, testing and
monitoring, and maintaining human control.
In financial services, the Australian
Prudential Regulation Authority’s (APRA)
Letter to Industry on AI makes it clear
that AI is an operational-resilience, cyber
and board-oversight issue for the entities
it regulates. APRA is among many regulators
looking at AI, while the Australian Securities
and Investments Commission has raised
concerns that AI adoption may be outpacing
governance frameworks.
Singapore’s Model AI Governance
Framework for Agentic AI is instructive
as it was written with agents in mind.
The framework recommends placing limits
on agents’ autonomy and introducing
checkpoints where human approval
is required.
“The requirement to assess and bind risks
upfront means classifying AI use cases by
materiality, autonomy, reversibility and
data sensitivity,” Lee says. “Making humans
meaningfully accountable requires assigning
a CFO sponsor, controller, agent owner, data
owner and internal audit responsibility.”
Above all, the legal obligations professionals
need to meet remain the same, whether an
agent is involved in a finance team’s processes
or not, he continues. “Boards, CFOs, auditors
and lawyers still need to decide who has
authority, what counts as approval and
how liability is allocated.”
OVERSEE AGENTIC OUTPUT
Perrett believes understanding and
documenting how AI agents reach
conclusions is now an intrinsic part
of the accountant’s role.
“That principle should not change because
AI is involved,” Perrett says. “If an existing
process needs a manager to review work
before it is provided to a client, the same
review process should apply to work produced
by an agentic AI system. In many cases,
the supporting documentation generated
by AI may be more comprehensive than
the workpapers traditionally produced by
employees because references, sources and
reasoning can be captured automatically.”
This means that systems need to be
implemented to verify AI output in the
same way as work produced by any other
team member.
“If a task currently needs to be reviewed
and signed off, that will be the case even
if it is performed by an agent. The reviewer
should assess the quality of the work,
intheblack.cpaaustralia.com.au 45