Generative AI has entered Indian finance operations through the side door: a credit analyst pasting a borrower note into a public chatbot, a shared-services associate asking a model to draft a variance commentary, a treasury intern summarising a term sheet. None of this is on the IT asset register. All of it will look, to an auditor or a regulator, like an undocumented control environment. This briefing is a working method for CFOs, controllers and internal-audit heads who need governance before the question arrives in an ISA 315 walkthrough or a SEBI disclosure query.
The setting is the Indian close calendar: quarterly results under LODR, Ind AS judgements, GST reconciliations, bank confirmations, and a workforce that already uses English-language models trained on someone else’s data. The same method travels to other emerging-economy groups that run shared service centres, file under IFRS-equivalent standards, and cannot wait for a perfect national AI statute before month-end.
1. The unofficial AI stack is already in the close
Boards hear “AI strategy.” The floor hears “this paragraph is due in forty minutes.” That gap is the risk. Official programmes live in a vendor demo and a steering-committee slide. Unofficial use lives in personal accounts, browser extensions and WhatsApp forwards of “useful prompts.” The unofficial stack does three things finance leaders underestimate.
First, it moves confidential text off the premises. A draft MD&A, a related-party schedule, a list of overdue debtors—any of these can leave the ERP and sit on a foreign server with no contractual confidentiality. Second, it produces fluent error. A model will invent a ratio, misread a covenant, or attribute last year’s exception to this year’s segment. Fluency hides the miss. Third, it erases the audit trail. There is no workpaper that shows which sentence was machine-drafted, which figure was checked, and who pressed send.
Indian groups have an extra wrinkle. Many finance processes sit in a mix of Tally or SAP, Excel, email, and a Big Four-managed close. Generative tools attach to the weakest link—usually email and Excel—not to the ERP. If your policy only covers “AI modules inside the ERP,” you have regulated the part that was already logged.
2. Inventory tools by what they touch, not by vendor logo
Start with a two-week amnesty, not a witch-hunt. Ask every finance manager one question: which generative tools did your team use in the last close, and on what class of document? Collect names. You will find public chatbots, copilots inside office suites, vendor “insights” buttons, and campus-style tools that interns brought from college.
Classify by touch, not by brand.
| Touch class | Examples | Default stance |
|---|---|---|
| Public prompt on unidentified text | Pasting a board note into a consumer chatbot | Prohibit. No exception for “I deleted the names.” |
| Enterprise model on redacted narrative | Licensed copilot on a commentary with figures stripped | Allow with a named reviewer and a saved prompt log. |
| In-system assist on structured fields | ERP or GRC tool suggesting a reconciliation comment | Allow if the suggestion cannot post a journal unaided. |
| Vendor black box on credit or cash | Score or forecast with no documented feature list | Treat as a model risk item; do not let it move money. |
Publish the inventory on the controller’s shared drive. Update it each quarter. An inventory that exists only in a consultant’s deck will not survive staff turnover in a GCC.
3. Fence the ledger, the working papers and the customer file
Three objects must not enter a public model: the general ledger extract, the audit working-paper pack, and any file that identifies a customer, vendor, employee or related party. That is not philosophy. It is the intersection of the IT Act, contractual NDAs with lenders, and ordinary professional secrecy.
Build the fence in language people can remember on a Thursday night.
- No live numbers into a public box. If the cell came from the trial balance, it does not leave the building in a prompt.
- No names. Counterparty, employee, promoter, auditor, banker—none of them belong in a consumer prompt, even “for tone.”
- No unreleased narrative. Draft results, draft qualifications, draft emphasis-of-matter language stay inside the controlled workspace.
Then give people a sanctioned alternative. A prohibition without a licensed workspace simply trains staff to use personal phones. If the group cannot yet buy an enterprise seat, restrict GenAI to tasks that use only public, already-filed information: explaining a standard, outlining a training note, or translating a published circular. That is a narrow door. It is better than an unlocked one.
Inside the fence
Journal proposals, reconciliations, confirmations, impairment memos, related-party lists, payroll exception files, unpublished segment notes.Outside, with care
Teaching a junior the shape of a variance note using invented numbers; summarising a public RBI or MCA circular; drafting an internal training quiz.4. Keep a named human on every material output
Governance fails when “the model said” becomes a reason. Assign a human owner to every material class of output: commentary that will be read by the audit committee, a paper that supports a journal, a credit note that goes to a credit committee, a tax position memo. The owner is not the intern who typed the prompt. The owner is the person whose designation already carries that judgement.
Require a two-line attestation under the output, stored with the workpaper:
I used [tool / version] to draft [section]. I checked every figure against [source]. I accept the judgement in my name. — [Name, designation, date]
That sentence does three jobs. It tells internal audit where to sample. It tells the statutory auditor that management is not pretending the text is handmade. It tells the junior that fluency is not a substitute for a tick mark.
4.1 What “checked” must mean
Checking is not reading for tone. Checking is matching each number to a system report, each legal citation to a gazette or a circular, and each company-specific claim to a document you can produce. If the model drafted four sentences and only one contains a number, check that number as if a first-year article had typed it at midnight—because that is the risk profile.
5. Treat prompts and exports as records, not chat
Chat windows feel disposable. They are not, once they contain a description of your revenue recognition judgement. Two practical controls fit Indian mid-market IT estates.
Prompt log for allowed tools. Enterprise copilots can retain history. Turn retention on for finance tenants. Export a monthly dump of prompts that contain words you care about: impairment, related party, going concern, contingent, GST, transfer price. You are not reading every line. You are building a population internal audit can sample.
Export ban on consumer tools. If the only available tool is a public chatbot, the control is simpler: do not paste. Train that rule the way you train “do not email the payroll file to a personal ID.” Same family of failure.
Also watch shadow exports. Staff will screenshot a model answer into a WhatsApp group called “Close help.” That screenshot is now a record you do not control, sitting on devices you do not wipe. Say so in the policy. Groups used for the close should be official, logged, and closed after the filing.
6. Write a one-page note the statutory auditor can test
Auditors will not accept “we are exploring AI.” They will ask whether the control environment changed. Give them a page they can file.
The page should contain six sentences, no more:
- Which generative tools are approved for finance, and which are banned.
- Which document classes may never be pasted into a model.
- Who attests AI-assisted material output, and where the attestation is stored.
- How prompts or histories are retained for approved tools.
- What internal audit sampled this quarter, and what exceptions were found.
- Whether any AI output can post, approve or release a transaction without a human (the answer should be no).
Attach the inventory as Appendix A. That is the entire first-year programme. Resist the urge to add an ethics appendix, a maturity heatmap and a vendor scorecard to the same page. Those belong in a later board note if the group actually deploys models that score credit or forecast cash.
If you are listed, align the language with existing LODR risk disclosures and with whatever the board already says about information security. Do not invent a parallel “AI risk” paragraph that contradicts the cyber note. Auditors read both.
7. A lighter protocol for mid-market and group finance teams
Not every Indian company has a model-risk committee. Most have a CFO, a CA heading accounts, an IT manager, and a statutory auditor who visits twice a year. The light protocol is enough.
Week 1. Amnesty inventory. One spreadsheet. Tool, team, document class, public or enterprise.
Week 2. Two-page policy: banned pastes, approved tools, attestation sentence, WhatsApp rule. Signed by the CFO. Circulated with the close calendar.
Each close. Controllers ask one question in the wash-up: did anyone use a generative tool on a paper that will be shown to auditors? Collect yes/no and names. That question alone changes behaviour.
Each quarter. Internal audit or a designated manager samples five attested papers. Report exceptions in the existing internal-audit tracker. No new committee required.
Group finance in a promoter-led company should add one extra rule: promoter-office drafts do not get a looser standard than the listed entity. The leakage risk is often higher there, not lower.
Shared service centres serving overseas parents should ask the parent which tenant and which data-residency clause apply. A GCC that uses a personal ChatGPT account on European customer data is not a local efficiency story. It is a parent-level incident waiting for a Tuesday.
8. Field checklist and closing brief
Use this list in the next controllership meeting. Tick only what you can show an auditor next month.
- We have a dated inventory of generative tools used in finance, including unofficial ones.
- Public chatbots are banned for live numbers, names and unreleased narrative.
- A sanctioned workspace exists, or the allowed use-list is narrow enough to live without one.
- Material AI-assisted output carries a named human attestation stored with the workpaper.
- No model can post, approve or release a payment, journal or credit decision unaided.
- Prompt history for approved tools is retained enough to sample.
- Internal audit (or a named deputy) sampled AI-assisted papers this quarter.
- A one-page management note exists for the statutory auditor.
- Annual-report language about AI matches the inventory, not the vendor slide.
- GCC and promoter-office teams sit under the same paste rules as the listed entity.
Generative AI will keep arriving through the side door because it is useful. Usefulness is not a control. The CFO’s job is not to ban fluency. It is to make sure that when a sentence about impairment, going concern or a related party is fluent, a human who can be examined still owns the number underneath it.
Start with the inventory this week. Write the one-page note before the next audit committee. Everything else—vendor bake-offs, “AI centres of excellence,” maturity heatmaps—can wait until the unofficial stack is no longer a surprise. If a board member asks whether the company is “behind on AI,” answer with the inventory and the fence, not with a pilot that pastes the debtor ledger into a public model. Speed without a named owner is not transformation. It is an undocumented change in how the close is written.
AI & Business Series · 11 September 2026
drdpklass.com