AI for Risk, Compliance & Audit
Capable · M8 · lesson 8 of 26 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
📖
in this lesson

Creating Clear, Accurate Policy and Procedure Documents with AI Support

15 min

Introduction

You will learn how to use AI to generate first drafts of policy summaries, procedure descriptions, and control narratives that are accurate, accessible to your audience, and suitable for approval and implementation--while establishing review discipline that ensures these documents reflect your organization's intent and standards.

At the Assisted Use level, you are moving from understanding concepts to applying them with guidance. You will begin using AI tools under supervision, learning to evaluate their outputs critically and document your verification processes. This is where theory meets practice -- with appropriate guardrails in place.

This lesson is designed to be accessible to professionals at all experience levels while providing the depth needed for practical application. Whether you are encountering these concepts for the first time or building on existing knowledge, the material ahead will strengthen your ability to navigate AI governance challenges with confidence and competence.

Core Concepts

Anti-Patterns / Misuse Risks

Anti-Pattern 1: Insufficient Review "AI generated a policy draft and I sent it to staff without having legal or policy owner review it."

Risk: The draft may misstate requirements, omit caveats, or conflict with other policies. Staff confusion or non-compliance may result.

Safeguard: Always have policy or procedure drafts reviewed by subject matter experts (policy owner, legal, compliance, affected leadership) before distribution or use.


Anti-Pattern 2: Generic Content "AI created a vendor management procedure. It's generic, but it's good enough."

Risk: Generic procedures may not reflect your organization's actual practices, approval authorities, or operational constraints. Staff won't follow a procedure that doesn't match reality.

Safeguard: Customize AI drafts to reflect your specific business processes, roles, and control environment. Get feedback from practitioners before finalizing.


Anti-Pattern 3: Unapproved Drafts in Circulation "I shared an AI-generated draft policy with a few colleagues to get feedback. It's getting passed around, and now people think it's official."

Risk: Unapproved drafts may be misunderstood, followed, or cited as policy before they're finalized. This creates confusion and risk.

Safeguard: Clearly mark AI drafts as "DRAFT - Not Yet Approved" and control distribution to a small review group until finalized and approved.


Anti-Pattern 4: Minimal Customization "AI created a control narrative for our monthly reconciliation. It's pretty generic, but it works."

Risk: Generic narratives don't reflect your specific controls, evidence, or testing approach. An auditor may question whether the described control is actually in place.

Safeguard: Customize all narratives with specific names, systems, timelines, and evidence unique to your organization. Have the control owner review and verify accuracy.


Anti-Pattern 5: No Evidence of Approval "I use the AI-generated procedure, so I guess it's approved."

Risk: Without documented approval, there's no accountability for the procedure. If it creates issues, it's unclear who authorized it or when it became effective.

Safeguard: Always obtain and document explicit approval from appropriate authority (policy owner, legal, CFO, CEO, board) before procedures are finalized and distributed.

Human Judgment Checkpoints

Before finalizing an AI-assisted draft for approval, ask yourself:

  • Accuracy Check: Does this draft accurately reflect the policy, procedure, or control it describes? Have I verified key facts?
  • Completeness Check: Is anything material missing? Are exceptions, escalations, or nuances covered?
  • Audience Fit Check: Is the language and level of detail appropriate for the audience? Will they understand what to do?
  • Organizational Fit Check: Does this reflect our organization's culture, processes, and standards? Or does it feel generic?
  • Legal/Compliance Check: Does this create any legal risk or compliance issues? Should legal review this?
  • Practicality Check: Can people actually follow this procedure? Have I tested it with practitioners?
  • Approval Check: Who needs to approve this? Do they understand what they're approving?
  • Documentation Check: Will I be able to explain how this draft was produced, reviewed, and approved?

[Practical Tip]

As you work through these concepts, consider how each one applies to your current role. Think of a specific scenario from your recent work where this concept would have been relevant. Building these mental connections between theory and practice is the fastest way to internalize new knowledge and make it actionable in your daily responsibilities.

Traceability / Defensibility Considerations

Policies and procedures are the foundation of governance. If you're challenged on a practice, you point to the policy or procedure.

What to Record: - Policy or procedure objective and scope - Source materials used to create the draft (e.g., current informal practice, interviews, frameworks) - AI tool and specific prompt used - AI-generated draft (save a copy) - Review comments from subject matter experts - Revisions made based on review - Final approved version - Who approved and when - Distribution list (who has access) - Effective date - When last reviewed and by whom

Why This Matters: - A regulator asks: "How did you know to do X process this way?" - Your answer: "We have a documented procedure [dated, approved] that describes this process. Here's the procedure and the approval. It was created by [process owner], reviewed by [experts], and approved by [authority]. We test compliance with this procedure annually. Last tested on [date]." - Without documentation: "I just... know we do it this way" provides no assurance.

Responsible AI and Control Considerations

Responsible Drafting Practices: 1. Transparency: Be clear that AI assisted in drafting; show that human experts reviewed and refined 2. Customization: Don't settle for generic AI output; invest time in making drafts organization-specific 3. Verification: Have drafts verified by practitioners before final approval (not just reviewed for language) 4. Approval discipline: Ensure that final approved version is clearly identified and that unapproved drafts don't circulate 5. Ownership: You are accountable for the policy or procedure, not the AI; you must be able to defend it

Control Considerations: - Policies and procedures should be part of your control environment; AI assists but does not replace human judgment - Ensure that procedures are tested (through observation or task performance) to confirm they're being followed as written - Maintain version control; don't allow multiple versions to circulate - Periodically review and update procedures to ensure they remain relevant and accurate - Document that procedures are communicated and understood (e.g., through training, acknowledgments)

[Practical Tip]

As you work through these concepts, consider how each one applies to your current role. Think of a specific scenario from your recent work where this concept would have been relevant. Building these mental connections between theory and practice is the fastest way to internalize new knowledge and make it actionable in your daily responsibilities.

Practice / Reflection Prompts

  • Take a policy or procedure you're familiar with. Ask AI to draft a summary or procedure description for it. Then compare the AI draft to the actual document. Where did AI miss nuance? Where could the AI draft mislead someone?
  • Identify a procedure in your organization that's outdated or poorly written. Ask AI to draft a replacement based on the current process (not the old procedure). Then gather feedback from people who actually do the work. How close is the AI draft to what would serve them?
  • Partner with a colleague. Have AI draft a policy summary for a document you both know. Compare your review feedback with theirs. What did you each notice as gaps or errors?
  • Test a procedure. Take an AI-generated procedure (or one you reviewed) and have someone who's unfamiliar with the process follow it. Do they understand what to do? What's confusing? What's missing?
  • Track one policy change. Document how the policy was drafted, reviewed, approved, and rolled out. Would an auditor be satisfied with your documentation? What else would strengthen your record?

Practical Application

Understanding concepts in the abstract is valuable, but the real test is whether you can apply them in professional practice. This section bridges the gap between theory and application with concrete scenarios drawn from oversight work.

Use Case 1: Data Governance Policy Summary Your organization created a comprehensive data governance policy (15 pages). New employees need a one-page summary of key rules and escalation procedures.

Process: 1. Gather input: Review the full policy, identify key rules and escalation triggers 2. Prompt AI: "Create a one-page summary of this data governance policy for new employees. Include: (1) key rules about data classification, (2) who approves sensitive data uses, (3) escalation steps for questions." 3. AI generates a draft one-pager 4. Review with policy owner: Does it accurately reflect the policy intent? Is the escalation pathway correct? Is the language clear? 5. Revise: Adjust tone, add details, remove generic language 6. Approve: Policy owner signs off on the summary 7. Document: Record that AI generated the draft, policy owner reviewed it, and it was approved for distribution

Use Case 2: Vendor Management Procedure Your organization is formalizing vendor management procedures. You need to document the steps: how to initiate a vendor request, what due diligence is required, how contracts are reviewed, and how performance is monitored.

Process: 1. Gather input: Interview stakeholders (procurement, legal, finance, operations); review current informal process 2. Prompt AI: "Based on these steps [provide key steps], create a procedure document for vendor management. Include: approval authority at each step, required documentation, timeline, responsible parties, escalation triggers." 3. AI generates a draft procedure (outline or detailed) 4. Review with stakeholders: Does the procedure match current practice? Are approval authorities correct? Are escalation triggers clear? 5. Revise and refine: Adjust to reflect organizational context, add specific role names, clarify timelines 6. Approve: Have procurement lead, compliance officer, and operations VP review and approve 7. Test: Use the procedure with a real vendor request and refine based on usability feedback 8. Document: Record AI's role in drafting, who reviewed, what changes were made, and final approvals

Use Case 3: Internal Control Narrative Your audit team is documenting controls for financial reporting. You need clear narratives explaining how a key control (e.g., monthly reconciliation) operates, who performs it, how it's supervised, and what evidence is retained.

Process: 1. Gather information: Interview control owner (accountant, manager), review control documentation, observe the process 2. Prompt AI: "Write a control narrative for this process [describe the process]. Include: control objective, control activity, frequency, responsible person, supervisory review, evidence retained, effectiveness assessment." 3. AI generates a draft narrative 4. Review with control owner: Does this accurately describe how the control operates? Are responsibilities correct? Are there exceptions or contingencies not mentioned? 5. Revise: Adjust for accuracy and completeness; add specific names or system details 6. Verify: Have the control owner perform the control while reading the narrative; refine based on gaps 7. Approve: Have the control owner and audit lead approve the narrative 8. Document: Record that AI assisted in narrative drafting, control owner reviewed, and it was verified through observation

Detailed Examples

The following examples illustrate how the concepts from this lesson play out in real-world oversight scenarios. Each example is designed to help you recognize similar situations in your own work and respond with appropriate professional judgment.

Example 1: Data Governance One-Pager

Full Policy Provided to AI (summary): Data Governance Policy requires classification of all data, approval for sensitive data uses, encryption for data in transit and at rest, documented data owners, retention timelines, and escalation to Chief Data Officer for questions or exceptions.

Your Prompt to AI: "Create a one-page quick-reference guide for this data governance policy. The audience is all employees. Include: (1) the 3-4 key rules about data handling, (2) who to ask if unsure, (3) simple checklist they can use when handling sensitive data."

AI Draft: ``` DATA GOVERNANCE QUICK REFERENCE Your Quick Guide to Handling Data Safely

KEY RULES: 1. Classify all data as Public, Internal, Sensitive, or Restricted 2. Get approval before using sensitive or restricted data 3. Encrypt sensitive data when moving or storing it 4. Know who owns the data you use 5. Follow retention schedules (delete on time)

IF YOU'RE UNSURE: Ask your manager -> Escalate to Data Office if needed -> Contact CDO for exceptions

CHECKLIST - Before Using Data: - What's the data classification? - Do I have approval to use this? - Is it encrypted in transit and storage? - Do I know the data owner? - What's the retention timeline? ```

Your Review with Data Office Lead: - Accuracy: All key rules captured? Yes, but we should emphasize that "sensitive" and "restricted" require explicit approval - Completeness: Missing anything? -> Add email address or contact info for Data Office (people won't remember "CDO") - Tone: Is this language right for all employees? Yes, simple and action-oriented - Audience fit: Would a new hire understand this? -> Maybe add one example (e.g., "Social Security numbers are Restricted")

Your Revised Version: ``` DATA GOVERNANCE QUICK REFERENCE Your Quick Guide to Handling Data Safely

KEY RULES: 1. Classify all data: Public, Internal, Sensitive, or Restricted Example: Social Security numbers = Restricted 2. GET APPROVAL before using Sensitive or Restricted data 3. Encrypt Sensitive and Restricted data in storage and when sending 4. Know who owns the data you use (ask your manager if unsure) 5. Delete data on schedule (follow retention dates)

NEED HELP? Start here: Ask your manager Still unsure? Email Data Office at [email protected] Exception? Contact Chief Data Officer ([email protected])

QUICK CHECKLIST - Before Using Data: - What classification is this data? - Do I have approval (if Sensitive/Restricted)? - Is it encrypted? - Who owns it? - When should it be deleted? ```

Approval and Documentation: "AI generated initial one-pager from full policy. Reviewed by Data Office lead on 2026-03-09. Revised to add specific contact info and example. Approved by Chief Data Officer on 2026-03-10. Distributed to all employees."


Example 2: Vendor Management Procedure

Input Provided to AI (from stakeholder interviews and current process): Vendor Management Steps: 1. Initiator submits vendor request with business justification 2. Procurement reviews and approves (or rejects) 3. Legal reviews contract and required clauses 4. Finance reviews pricing and terms 5. Operations confirms feasibility 6. Purchase order issued 7. Vendor performance tracked monthly 8. Annual vendor review and risk assessment

Your Prompt to AI: "Create a vendor management procedure document. The audience is procurement staff and operational users. For each step, include: who is responsible, what they do, how long it should take, what documents are required, and when to escalate. Use this format: Step -> Responsible Party -> Action -> Timeline -> Deliverables -> Escalation Triggers."

AI Draft (simplified): ``` VENDOR MANAGEMENT PROCEDURE

STEP 1: VENDOR REQUEST SUBMISSION Responsible: Business Unit Manager Action: Complete vendor request form with business justification Timeline: 2 business days Deliverables: Completed request form, business case Escalation: If cost > $100K, requires VP approval

STEP 2: PROCUREMENT REVIEW Responsible: Procurement Manager Action: Verify vendor qualifications, check if vendor exists in system, identify if new vendor or expansion Timeline: 3 business days Deliverables: Procurement approval or rejection Escalation: If vendor has history of issues, escalate to Procurement Director

STEP 3: LEGAL CONTRACT REVIEW Responsible: Legal Counsel Action: Review contract for required clauses (insurance, indemnification, data protection, termination) Timeline: 5 business days Deliverables: Contract approval or list of required revisions Escalation: If contract materially deviates from standard terms, escalate to General Counsel

[Continue for remaining steps...] ```

Your Review with Procurement, Legal, Finance, and Operations: - Accuracy: Do the steps match current process? Yes, generally; one addition: Compliance must review if vendor handles sensitive data - Responsibilities: Are approval authorities correct? Yes, but Procurement Manager should not unilaterally reject vendors over $100K; escalate to Director - Timelines: Are these realistic? -> Some timeline adjustments needed (Legal review typically 7-10 days; Finance 2-3 days) - Completeness: Missing anything? -> Add step for contract execution and vendor onboarding; add reference to required vendor documentation (insurance certificates, W-9) - Escalation triggers: Are these clear? -> Clarify: What happens if Compliance review identifies risk? Does that auto-escalate to CFO?

Your Revised Procedure: ``` VENDOR MANAGEMENT PROCEDURE

STEP 1: VENDOR REQUEST SUBMISSION Responsible: Business Unit Manager Action: Complete Vendor Request Form (Appendix A) with business justification and cost estimate Timeline: Submit when vendor need identified Deliverables: Completed request form, business case document Escalation: Requests > $100K require VP sign-off before submission

STEP 2: PROCUREMENT REVIEW Responsible: Procurement Manager Action: Verify vendor qualifications, check vendor system (new or existing), identify risk level Timeline: 3 business days Deliverables: Procurement assessment memo Escalation: If vendor has history of issues or is high-risk, escalate to Procurement Director for approval before proceeding

STEP 3: COMPLIANCE REVIEW (if applicable) Responsible: Compliance Officer Action: Review if vendor handles personal data, sensitive data, or has regulatory implications. Assess compliance requirements. Timeline: 3 business days (concurrent with Procurement) Deliverables: Compliance clearance or risk mitigation requirements Escalation: If compliance risks exist, must be addressed in contract before execution

STEP 4: LEGAL CONTRACT REVIEW Responsible: Legal Counsel Action: Review contract for required clauses: insurance, indemnification, data protection, confidentiality, termination, liability limits Timeline: 7-10 business days Deliverables: Contract approval or revision list Escalation: If contract materially deviates from standard terms, escalate to General Counsel before approval

STEP 5: FINANCE REVIEW Responsible: Finance Manager Action: Review pricing, payment terms, budget availability, cost allocation Timeline: 2 business days (concurrent with Legal) Deliverables: Finance approval or pricing questions Escalation: If cost impact is material (> 10% above initial estimate), escalate to CFO

STEP 6: OPERATIONS FEASIBILITY CHECK Responsible: Operations Manager Action: Confirm vendor can meet operational requirements (delivery, service level, support) Timeline: 2 business days Deliverables: Operations approval or requirements clarification Escalation: If vendor cannot meet operational requirements, escalate to Chief Operations Officer

STEP 7: CONTRACT EXECUTION Responsible: Procurement and Legal Action: Finalize contract, obtain required signatures (vendor CEO and CFO or equivalent authority) Timeline: 2 business days after all approvals Deliverables: Fully executed contract Escalation: If vendor delays execution or refuses to accept standard terms, escalate to Procurement Director

STEP 8: VENDOR ONBOARDING Responsible: Procurement Action: Collect vendor onboarding documents (W-9, insurance certificates, banking info, compliance attestations), set up in procurement system, provide vendor with operational contacts Timeline: 3 business days post-execution Deliverables: Vendor record in system, operations kickoff meeting scheduled Escalation: If vendor fails to provide required documents, payment cannot be processed

STEP 9: ONGOING PERFORMANCE TRACKING Responsible: Operations Manager (with Procurement and Finance) Action: Monitor vendor performance monthly against SLA, on-time delivery, service quality. Escalate issues immediately if performance drops. Timeline: Monthly reviews Deliverables: Vendor performance scorecard Escalation: If performance issues emerge, notify vendor and develop improvement plan. Escalate to Procurement Director if non-resolution after 30 days.

STEP 10: ANNUAL VENDOR REVIEW Responsible: Procurement (with Compliance and Operations) Action: Assess vendor performance, compliance, financial stability, operational fit. Decide: continue, improve, replace. Timeline: Q4 each year Deliverables: Vendor risk assessment and recommendation Escalation: If vendor poses emerging risk, escalate to CFO for decision on continuation ```

Approval and Documentation: "AI generated initial procedure draft. Reviewed by Procurement Manager, Legal Counsel, Finance Manager, Operations Manager, and Compliance Officer on 2026-03-08. Revised to add Compliance step, adjust timelines, clarify escalation triggers, and add onboarding details. Approved by CFO and COO on 2026-03-10. Effective date 2026-04-01. AI role: initial structure and clear formatting; humans: accuracy, completeness, escalation logic."


Example 3: Internal Control Narrative

Information Gathered from Control Owner: Control: Monthly GL Reconciliation Objective: Ensure all GL accounts are accurate and complete Activity: Accountant reconciles each GL account to supporting detail (subledger, bank statement, system report); identifies and resolves discrepancies Frequency: Monthly, last business day Supervisor: Controller reviews and signs off Evidence: Reconciliation worksheet, supporting documents, supervisor approval Exception: Bank reconciliation takes 2-3 days due to float

Your Prompt to AI: "Write a control narrative for this process [provide details above]. Structure it: Objective -> Control Activity -> Frequency -> Responsible Parties -> Supervisory Review -> Evidence -> When Last Tested. Write in clear, non-technical language suitable for an auditor."

AI Draft: ``` CONTROL: MONTHLY GENERAL LEDGER RECONCILIATION

CONTROL OBJECTIVE: Ensure that the general ledger accurately reflects all financial transactions and balances, and that discrepancies are identified and resolved timely.

CONTROL ACTIVITY: On the last business day of each month, the Accountant reconciles each GL account by: 1. Identifying the GL account balance from the accounting system 2. Obtaining the supporting detail (subledger, bank statement, system report, etc.) 3. Comparing the GL balance to the supporting detail 4. Identifying any discrepancies 5. Investigating the root cause (timing, error, missing transaction) 6. Recording corrections in the GL if an error is identified 7. Documenting the reconciliation on the reconciliation worksheet

FREQUENCY: Monthly, completed by the last business day of the month

RESPONSIBLE PARTIES: Accountant: Performs the reconciliation and documents findings Controller: Reviews and approves the reconciliation; resolves escalations

SUPERVISORY REVIEW: After the Accountant completes the reconciliation, the Controller: 1. Reviews the reconciliation worksheet and supporting documentation 2. Verifies that all discrepancies identified were investigated 3. Verifies that corrections were made appropriately 4. Signs and dates the reconciliation worksheet 5. Escalates unusual discrepancies or trends to the CFO if needed

EVIDENCE RETAINED: - Reconciliation worksheet (showing GL balance, supporting detail, discrepancies, and adjustments) - Supporting documentation (bank statements, subledgers, exception reports, correction entries) - Controller approval signature and date - Discrepancy log (tracking discrepancies across months to identify trends)

TESTING: The Internal Audit function tests this control by: - Selecting a sample of monthly reconciliations (typically 3-6 months per year) - Verifying that the reconciliation was completed timely - Recalculating the reconciliation to confirm accuracy - Confirming that discrepancies were investigated and resolved - Verifying evidence is retained and properly documented

EXCEPTION: Bank reconciliation accounts may take 2-3 additional days due to float (transactions pending clearing). ```

Your Review with Accountant and Controller: - Accuracy: Does this describe how you actually do the reconciliation? -> Yes, mostly; clarify that you investigate discrepancies immediately and sometimes the adjustment is in the following month if it relates to timing - Completeness: Are there steps missing? -> Add: accountant documents the reason for each discrepancy (for auditor's understanding); add that GL accounts are reconciled in sequence (payroll, balance sheet, revenue, expense) with a specific order - Supervisory review: Is the Controller's approval process clear? -> Yes; add that Controller may request additional detail if discrepancy seems unusual - Evidence: Is the description of evidence complete? -> Yes; clarify that discrepancy log is electronic (in Excel file) and kept for 12 months rolling - Exceptions: Are there other exceptions? -> Yes, month-end accruals and cutoff items may require adjustments in the following month; document that process

Your Revised Narrative: ``` CONTROL: MONTHLY GENERAL LEDGER RECONCILIATION

CONTROL OBJECTIVE: Ensure that the general ledger accurately reflects all financial transactions and balances, and that all discrepancies are identified, investigated, and resolved timely.

CONTROL ACTIVITY: On the last business day of each month, the Accountant reconciles the GL accounts in the following sequence: (1) Payroll accounts, (2) Balance sheet accounts, (3) Revenue accounts, (4) Expense accounts. For each account: 1. Obtain the GL account balance from SAP (as of month-end) 2. Obtain the supporting detail (bank statement, subledger report, manual spreadsheet, system report) 3. Compare GL balance to supporting detail 4. Identify discrepancies (differences in balance, missing transactions, timing differences) 5. Investigate root cause and document the reason in the reconciliation worksheet: - Timing difference: Transaction pending clearing or accrual not yet recorded - Error: Incorrect amount recorded; correction entry required - Missing transaction: Transaction that should have been recorded; correction entry required - Other: Note reason for further investigation 6. For errors or missing transactions, prepare and record a correcting entry in SAP (or manual GL entry if SAP not available) 7. For timing differences or accruals, document the expected resolution date and follow up in next month's reconciliation 8. Complete the reconciliation worksheet (template: Finance Shared Drive) with GL balance, supporting balance, reconciling items, and correcting entries

FREQUENCY: Monthly, completed by the last business day of the month. Bank reconciliation accounts (checking, credit card, etc.) may take 2-3 additional days due to item clearing.

RESPONSIBLE PARTIES: Accountant (Senior Accountant, currently [Name]): Performs the reconciliation, documents findings, prepares correcting entries Controller (currently [Name]): Reviews reconciliation, approves, resolves questions

SUPERVISORY REVIEW: After the Accountant completes the reconciliation: 1. Controller reviews the reconciliation worksheet and supporting documentation 2. Controller verifies that all discrepancies identified were investigated and the reason documented 3. Controller verifies that correcting entries were recorded correctly in SAP 4. For timing differences, Controller confirms that follow-up is scheduled for next month 5. Controller signs and dates the reconciliation worksheet, indicating approval 6. For unusual or large discrepancies, Controller may request additional detail or escalate to CFO for investigation

EVIDENCE RETAINED: - Reconciliation worksheet (SAP export showing GL balance, month-end cutoff, and reconciling items; plus manual worksheet documenting discrepancies and corrections) - Supporting documentation: Bank statements, subledger reports, manual spreadsheets, system exception reports - Correcting entry records (SAP transaction listing or GL entry documentation) - Controller approval signature and date on reconciliation worksheet - Discrepancy log (rolling 12-month electronic log in Excel; filed on Finance Shared Drive; tracks discrepancies by account and month)

WHEN LAST TESTED: Internal Audit tested this control on [date of last test]. Sample tested: 6 months of reconciliations (January through June 2025). Results: Effective. All reconciliations were completed timely, discrepancies were appropriately investigated and documented, and correcting entries were accurate.

EXCEPTION HANDLING: 1. Month-end accruals (e.g., accrued payroll, accrued expenses) may be recorded in the following month after supporting invoices are received. Accountant documents the accrual in the current month's reconciliation and confirms recording in the following month. 2. Cutoff timing differences (e.g., goods in transit, period-end invoices) are documented and reconciled in the correct period per revenue recognition policy. Accountant annotates the reason for deferral in the reconciliation worksheet. 3. System timing lags: If SAP is not updated by month-end, Accountant uses the prior month's closing data and reconciles to actual SAP update once available (typically within 3 business days of month-end). ```

Final Approval and Documentation: "AI generated initial control narrative based on process description. Reviewed with Accountant and Controller on 2026-03-08. Revised to reflect actual process sequence, document exception handling, clarify evidence retention, and add details on correcting entry process. Verified through process observation on 2026-03-09 (Accountant performed monthly reconciliation while reading narrative; narrative found to be accurate and complete). Approved by Controller on 2026-03-09 and CFO on 2026-03-10. Effective immediately for audit testing purposes."

Putting It Into Practice

At the Assisted Use level, implementation means beginning to incorporate these concepts into your supervised AI work:

  • Practice with guidance: Use AI tools for low-stakes tasks with a mentor or supervisor available for review. Build confidence gradually before taking on more complex scenarios.
  • Verify systematically: Develop a personal checklist for reviewing AI outputs. Even a simple three-point check (accuracy, completeness, appropriateness) dramatically improves output quality.
  • Document your process: Record what AI tool you used, what prompt or input you provided, what output you received, and what verification steps you performed. This documentation habit is essential.
  • Seek feedback: Share your AI-assisted work products with experienced colleagues. Their input helps calibrate your judgment about when AI outputs are reliable and when they require additional scrutiny.

Key Takeaways

Review the core concepts from this lesson and consider how each one applies to your professional practice.

As you continue through this credential program, you will build on the foundation established in this lesson. Each subsequent lesson adds new dimensions to your understanding and expands your capability to work effectively with AI in oversight roles.