Introduction
Artificial intelligence (AI) has moved rapidly from an emerging technology to an established business tool, with organizations increasingly integrating AI-enabled capabilities into core processes, including financial reporting. The 2021 COSO publication, Realize the Full Potential of Artificial Intelligence, authored by Keri Calagna, Brian Cassidy, and Amy Park of Deloitte & Touche, provided organizations with guidance on leveraging the COSO ERM Framework when adopting AI technologies.[i]
The 2026 COSO publication, Achieving Effective Internal Control Over Generative AI (GenAI), authored by Scott Emett of Arizona State University, Marc Eulerich of the University of Duisburg-Essen, Jason Guthrie of Ernst & Young Global Limited, Jason Pikoos of Meta Platforms Inc., and David A. Wood of Brigham Young University, builds on that ERM Framework foundation with a focus on how organizations might address the risks related to the use of GenAI through the lens of COSO’s 2013 Internal Control – Integrated Framework (hereinafter, the “Framework”), and its five components and 17 principles.[i]
When considering the risks of GenAI, a key distinction is the nature of GenAI itself.[i] While more traditional AI applications often operate using deterministic or rule-based models designed to perform narrowly defined tasks (e.g., classification, anomaly detection, or predictive analytics), systems or workflows that leverage GenAI are designed to ingest and adjust data and create new content such as text, calculations, analyses, or summaries, based on probabilistic models.
This distinction affects how to design and test mitigating controls because GenAI goes far beyond mere task automation. It materially influences how information is generated, interpreted and communicated, . There is no independent way to verify outputs or other control activities within the GenAI application’s functionality. The focus shifts from a straightforward consideration of which controls are necessary to determine whether a system is functioning as designed to whether GenAI-generated outputs are reliable.
This article (Part 1 of a 2-part series) discusses guidance from the 2026 COSO report (hereinafter, “the report”) on GenAI’s risks, capabilities, characteristics, and initial considerations for adapting the Framework to GenAI-specific practices.
What are the risks associated with GenAI?
As a starting point, the report identified seven GenAI risks. The report authors make it clear that the publication intentionally omitted guidance on traditional IT general controls, such as network security, even though those concepts remain necessary. The focus was on incremental (or evolving) risks arising from the use of GenAI.
Exhibit One outlines the Gen AI Risks addressed in the report.
Exhibit One — GenAI Risks Addressed
| GenAI Risks | Summary Context |
| Data quality, source and completeness | Bad inputs produce unreliable outputs that may be hard to detect once disseminated. Incomplete source records complicate verifiability. |
| Reliability and consistency | GenAI processes/applications may generate plausible but inaccurate information (e.g., hallucinations). Also, the consistency and reliability of information can be impacted by data changes, seasonality and model drift.[i] |
| Explainability and transparency | GenAI reasoning is not always clear, which can complicate validation, testing and stakeholder confidence. |
| Security and privacy | GenAI shifts the defensive perimeter to user interfaces and the underlying data or knowledge sources it uses. |
| Bias and fairness | Embedded bias can lead to exposure (e.g., legal, regulatory, or reputational) and poor decisions. |
| Third-party and vendor risk | Reliance on vendor-supplied GenAI limits visibility into and oversight of data. |
| Governance and accountability | Changes and rapid flow of information can outpace existing testing and policies. |
It is important to note that these identified risks do not necessarily cover all risks that organizations need to consider across systems that embed GenAI. It is also important to consider that as GenAI evolves in both functionality and use, risk identification and assessment will need to be an ongoing process.
What are the capabilities of GenAI?
With the above scope of risks identified, a logical next step towards implementing effective internal control over GenAI is to identify how organizations use it. As noted in the report, authors focus on the functions GenAI performs rather than looking at individual GenAI products or vendors.
The following list, based on Figure three in the report, summarizes and provides examples for the eight identified GenAI capabilities (i.e., what GenAI can do).
- Extract data. For example, extracting details from incoming customer support messages (e.g., emails or chat logs).
- Transform data. For example, converting extracted data into standardized location or product categories used in established analytics.
- Process transactions. For example, matching supplier invoices to purchase orders and reconciling totals.
- Orchestrate workflows. For example, automatically reconciling the trial balance and subledgers, performing analyses, and assigning follow-up tasks.
- Generate insights, forecasts and judgments. For example, predicting customer demand, predicting product warranty issues, or generating geographic or product-focused market summaries.
- Monitor for anomalies. For example, analyzing production sensor data to detect potential quality issues.
- Interpret regulations. For example, summarizing relevant excerpts related to a large volume of revenue contracts for a financial reporting professional.
- Collaborate with humans. For example, using GenAI to assist with writing code that a programmer then reviews.
Understanding these capabilities will help professionals better determine where, within a control environment, new risks related to GenAI may exist or evolve. Familiarity with where risks originate or spread is important because GenAI capabilities are often embedded across workflows, influencing how data is captured, processed, analyzed, and reported. As a result, risks may arise at multiple points in the information flow.
What are the characteristics of GenAI?
The report next identifies certain foundational characteristics of GenAI. These foundational characteristics are important to consider in determining how to build or adapt effective internal controls. Exhibit two summarizes the characteristics and their implications for internal controls as addressed in the report.
Exhibit Two — GenAI Characteristics and Implications
| Characteristics of GenAI | Internal Control Implications |
| GenAI produces probabilistic outputs that can be confidently wrong. | Rather than treating outputs as facts to accept, controls should treat them as claims to be verified. |
| GenAI is dynamic with models, prompts, and underlying data evolving regularly. | Risk assessment and monitoring must be continuous. |
| GenAI is scalable in terms of quality and efficiency, as well as in terms of errors and bias. | Control design should prevent small errors from escalating into large system issues. |
| GenAI is easily accessible. | Control design should regulate who can build, deploy and interact with GenAI. |
| GenAI can help govern GenAI through its analytical and pattern-recognition capabilities. | If implemented properly, GenAI can improve monitoring, documentation and validation activities. |
From an internal control perspective, these unique characteristics introduce challenges to consistency, auditability and reliability—all foundational elements of effective internal control. As noted in the report, due to its flexibility and clearly stated, understandable structure, the Framework remains relevant, even with the arrival of GenAI.
Integrating GenAI into the Framework
While the COSO Framework remains applicable, its traditional application often relies on systems or controls that are repeatable, traceable, and governed by defined logic (deterministic). Because of the nature of GenAI and its probabilistic functionality, it disrupts the traditional application of a system of internal controls, as the outputs from GenAI capabilities are often neither deterministic nor repeatable. The implication is that the Framework’s principles must be applied in ways that address GenAI’s unique risks, capabilities, and characteristics.
Exhibit Three provides a high-level overview of how each internal control component in the Framework applies to GenAI, along with examples of practical ways the organization can embed the Framework components and associated principles, as addressed in the report.
Exhibit Three — GenAI applied to the Framework
| Framework Component | Application to GenAI (Organizational Response) | Examples of Practical Applications |
| Control environment | Must respond to AI’s accessibility, rapid adoption and potential to bypass approvals. | Establish a GenAI Acceptable Use Policy, assign owners to each AI system, and conduct regular GenAI training. |
| Risk assessment | Must establish a more dynamic process of identifying and analyzing risks than existed before GenAI. | Define objectives and boundaries for each GenAI use case, identify how GenAI-specific threats could prevent objective achievement, and track significant GenAI changes to re-evaluate risks. |
| Control activities | Must account for swift model configuration changes, probabilistic outputs, and the possibility of automation operating with no human intervention. | Require human corroboration in proportion to the risk addressed, treat GenAI models as subject to general technology controls just like any other IT asset, and document how control activities are executed and tested and who is responsible. |
| Information and communication | Must pay increased attention to the information’s source and traceability and clearly express its limitations. | Capture and store all information used in GenAI processes; communicate internally with everyone involved in GenAI about roles, boundaries, and procedures; and communicate externally with stakeholders materially affected by the organization’s use of GenAI about use, impact, and limitations. |
| Monitoring activities | Must ensure that controls not only exist but also continuously remain effective. | Conduct both regular and periodic deep reviews of GenAI-enabled processes, evaluate GenAI processes for both traditional types of deficiencies as well as those specific to GenAI, and communicate deficiencies with material impact to governance bodies. |
Conclusion
GenAI represents a dramatic technological change and is advancing at a pace difficult to keep up with. It alters how information is generated, how risks arise, and how internal controls must operate. The new COSO guidance provides a structured way to address these challenges within the established Framework, emphasizing governance, risk identification, and continuous monitoring.
While this edition, Part 1 of a 2-part series, discusses the new COSO guidance related to GenAI’s risks, capabilities, characteristics, and initial considerations for adapting the Framework to GenAI-specific practices, in Part Two, we will discuss the new COSO guidance’s implementation roadmap, which presents a six-step plan for organizations to incorporate GenAI governance into their internal control environments.
[i] Committee of Sponsoring Organizations of the Treadway Commission (COSO). 2021. Realize the Full Potential of Artificial Intelligence. PDF available at https://www.coso.org/artificial-intelligence.
[i] Committee of Sponsoring Organizations of the Treadway Commission (COSO). 2026. Achieving Effective Internal Control Over Generative AI (GenAI). PDF available at https://www.coso.org/generative-ai
[i] Appendix A of the 2026 COSO publication defines Generative AI (GenAI) as “a subset of ML [machine learning] capable of creating new, original content (e.g., text, images, audio, video) that can be indistinguishable from human-created content. This can extend to models that plan, execute, and adapt multi-step tasks to achieve a defined goal, often by interacting with external tools, data or environments (e.g., AI agents).
[i] The 2026 COSO publication defines model drift as “a gradual degradation of the [model’s] accuracy.”