|
Hello hello, People ask me all the time this: “Nicolas, how do we keep our data safe using AI?” And, you know what still shocks me, even now? Every week I see finance teams using free AI tools that put their company data at risk. When I give finance training, I see a lot of people still using ChatGPT, the free version. Or, the wrong version of Copilot that is meant for personal use, not business use. With free AI tools, your data gets stored indefinitely unless you manually opt out. If you do not opt out, that information will be used to train future models. Here is the problem with this. Most finance leaders are in "deny and hope" mode. They know that their teams are using the wrong AI tools without approval (Shadow IT). They just don't want to deal with it. So, they pretend like this is not happening. But now, your sensitive financial data is now in servers that you do not control. Stuff like, pre-announcement earnings, M&A models, customer pricing. Or worse, personal employee data or customer information that could lead to GDPR fines And here is what’s super important. This is not just a compliance risk. This is an audit risk. The UK's Financial Reporting Council (FRC) just published guidance on the use of AI during audits. The message is that auditors need to understand what AI tools you're using, and what controls exist around them. So let me ask you. Do you know which AI tools your team is using right now? Do you know what data they're putting into those tools? The good news is you don't need to ban AI. You just need a practical governance framework. And that's what I'm going to show you today. Gray Zone ParalysisHere's what I see happening in most finance teams right now. Leadership knows AI tools are being used. But nobody wants to be the person who creates the policy. So it sits in this gray zone where people ignore the problem. Some companies try to ban everything “We’re blocking ChatGPT” - Done. But, here is the thing. Your team is still using it! They just do it on their phones instead of their work laptops. Or they use Claude instead of ChatGPT. Or they call it "research assistance" and keep going. You cannot block what you cannot see (this is called shadow IT). Shadow IT is when your employees use software, apps, cloud services, or device that employees use that are not approved by the business. Other companies take the opposite approach: "Use whatever tools help you work faster." No guidance at all with a high potential for risk. Both approaches create this risk. Your experienced FP&A manager knows not to put sensitive data into free tools. She uses the paid versions with proper data controls. But your new hire in accounts payable? He just learned that ChatGPT can reconcile your vendor statements faster. So he uploads the full AP aging report, including the vendor’s bank details and payment terms. He's not trying to cause a data breach. He's just trying to close the month on time so he can go home on time. And here's what makes this worse. Your team is stuck between productivity and compliance, with no clear instructions. This week, I spoke to a CFO who said: "I almost feel like I'm paralyzed because of what I don't know and I don't want to go down the wrong path... this is one of those decisions where it could be quite consequential if you do it wrong." And he is dead right, this problem will not go away if you do not make the right decisions now. Your team needs to move faster. And AI tools will help them do this. But without clear guidance on what's safe versus what's risky, you're creating a big compliance gap. And when your auditors ask about AI controls in your financial reporting process? "We told people not to use it" isn't a control. This is just hoping. So how do we solve this? Controlled AdoptionThis is what you need to do: ‘Controlled AI adoption’. A practical framework that protects your data while letting your team use the tools that make them productive. Instead of trying to control whether people use AI, you control what data goes into which tools. And this is something you can actually enforce. Here is the important thing to remember: Not all AI tools are created equal when it comes to data protection. The free version of ChatGPT stores your data indefinitely and uses it for training. But, the Enterprise version of ChatGPT with proper business agreements? This is different. Your data stays yours, gets deleted on your schedule, and never trains the model. It is the same interface, but much lower risk. So the framework is simple. Match your data sensitivity to the right plan. The public information that is on your website already? It’s fine to use free tools. But, the sensitive financial data or customer information? Premium tools only. Tools with SOC 2 certification, GDPR compliance, and contractual data protections. Plus, anything that goes into a financial statement or audit workpaper? This requires human review before you can use it. This is no longer a ‘nice to have’. This is what your auditors will ask about in your next review. So here's what I'm going to show you. A three-layer governance framework you can implement this month. Let me walk you through each one. 3 Layers of Data ControlYou are going to build three layers of control. Each layer protects you from different risks. And together, they create a system that you can explain to your auditors.
|
| Reserve your FREE Masterclass Space Here |
Disclaimer: The content in this newsletter is for general information only and does not constitute legal or professional advice. AI Finance Club GmbH and Nicolas Boucher make no guarantees as to the accuracy or completeness of any information, and you use it at your own risk. Laws and requirements vary by country, industry, and situation, so you should consult a qualified professional before acting on any information here. To the fullest extent permitted by law, we accept no liability for any loss or damage arising from use of this newsletter or its contents.
Join 270,000+ Professionals and receive the best insights about Finance & AI. More than 1 million people follow me on social media. Join us today and get 5 goodies from me!
Sponsored by Agicap Want to learn how to become an AI CFO? Join our FREE masterclass where I'll show you how to go from a traditional CFO to an AI CFO with super practical use cases you can start using straight away. Don't miss this 60 minute free masterclass with me. Spaces are limited so click the link below now to reserve your place. Reserve Your FREE Masterclass Seat Here Bonjour ;) Let me ask you this. How many times this week did you ask ChatGPT something, get back a response, and then...
Sponsored by Agicap Want to learn how to become an AI CFO? Join our FREE masterclass where I'll show you how to go from a traditional CFO to an AI CFO with super practical use cases you can start using straight away. Don't miss this 60 minute free masterclass with me. Spaces are limited so click the link below now to reserve your place. Reserve Your FREE Masterclass Seat Here Hello hello! So, you’ve finally got your models built, and your numbers are accurate. But now you are dreading the 3...
Sponsored by SAP Staying up to date with SAP was always a big advantage for me in my career. And learning how finance teams are using AI and data to lead decision making will put you ahead. To make sure you don’t miss out on expert insights you can use in your work and to advance your career. Join SAP’s finance webinar series now by clicking the button below: Reserve your FREE spot here Hello hello! Tell me, do you spend a lot of time reviewing the work of your team, because you’re worried AI...