Despite high confidence from leaders in AI outputs, more than a quarter of executives said internal audits have detected AI errors that reached external audiences or the board.
This is according to
"As a CAO, that statistic sets off alarms but it's not surprising. That number tells you AI errors aren't hypothetical risks, and business leaders still need human oversight and data lineage, especially in fields like internal and external financial reporting as well as accounting processes where errors can lead to real consequences," she said in an email.
Mike Levy, CEO of internal audit and risk advisory firm
"One thing that's extremely clear is that AI is being adopted and implemented far faster than governance can keep up. ... Without proper governance, the risk of an error like this occurring is extremely high. This is especially true with high velocity change like AI adoption," he said.
When asked whether it is possible that there are probably more errors than the 26% were able to detect, Levy said this was unfortunately possible. In his own practice as well as in conversation, he thinks hallucinations are common especially when people use an unsophisticated approach and do not employ deterministic techniques in their processes. He also pointed out that "external audience" is a fairly broad term that can include emails to vendors, errors in formatting and style, social media posts and more; it is conceivable that AI errors could pop up in any of these places without the company noticing.
This does not seem to be due to people not recognizing that misinformation can be dangerous, as poll respondents already seemed well aware of the risk. The report noted that the proportion of those citing misinformation as a top external threat grew from 24% to 31% in the U.S. (globally the increase was from 23% to 26%). Swain thought the contradiction might be due to executives feeling confident about AI in the abstract, but not as much when discussing their specific organization.
She pointed to another stat in the report that said only 11% felt their own data was AI-ready, and 71% said poor data quality has at least moderately impacted AI in financial and sustainability reporting. AI is only as good as the data fed into it, so if a company's data is inaccurate or incomplete, the output will sound plausible but still be wrong. The AI does not fix the data quality problem but amplifies it. Swain said there is likely a relationship between lack of data-readiness and AI errors.
"It would surprise me more if there wasn't a relationship between that and the 26% of internal auditors finding AI errors. Garbage in, garbage out. That's been true in finance, risk and audit long before anyone was talking about AI. What makes this harder now is that AI outputs often look polished even when the inputs are flawed. Generic AI tools don't have the capability to trace numbers back to their source, which means errors can be harder to catch and harder to explain after the fact," she said.
What is alarming about this, according to Swain, is that the results suggest that many organizations are trusting AI outputs without asking the harder question of "where did this data come from, and can I stand behind it?"
"I can't emphasize this enough: Data governance is not a back-office concern. It is the foundation that determines whether finance professionals can responsibly expand their use of AI, and governance means more than asking whether the data is accurate. You also have to ask who is allowed to consume this data. Data lineage and clear ownership aren't just problems for IT. In finance, data governance isn't optional. It's the prerequisite. If you can't answer, 'Is this data accurate, and is the right person using it?' then you don't have the controls in place to confidently stand behind your AI-assisted outputs," she said.
Levy, from Cherry Hill Advisory, raised a similar point, saying that all these mistakes are likely a breakdown in the governance process, as speed can at times take a backseat to things like people, process, technology, training, monitoring, and steering (as was discussed in a pair of studies discussed
"Sometimes the focus areas do not include things like third parties or ancillary downstream systems, or do not have the proper feedback loop into the steering committees and governance teams that are required," he said. "Since things are moving and evolving so rapidly and quickly, there is a promise of a significant efficiency, optimization, and real-time visibility into cost-efficient and effective processes. There are really serious and significant requirements in order to take full advantage of these things while also managing risk properly."
This is not the first, or even second or third research study finding a severe mismatch between how confident organization are in their governance and data integrity and the actual realities. A
A study from this past May by corporate performance management solutions provider OneStream
They are probably right to question their data's quality, as 72% say bad data cost their organization $500,000 or more, with more than one-third (37%) reporting damages over $1 million. Downstream impacts include delayed reporting and closing (cited by 44%), lost revenue opportunities (41%), a lack of trust in automated insights (38%) and compliance issues (35%).
A similar confidence mismatch was found in a
Overall, the Workiva results, combined with the others, indicates there might be a pattern of overconfidence in AI controls and governance considering the errors identified.






