Skip to content
Securafy AI Lab by Securafy
AI Compliance & Regulated Industries

The Bright Line for AI in Finance: Assist, Flag, Never Move Money

AI can draft, reconcile, categorise, and flag anomalies across a finance function. What it must not do is initiate, approve, or release a payment. Ric Hall on the assist / flag / never boundary, and why the pressure to automate an approval step arrives disguised as efficiency.

In this article

Should AI Ever Be Allowed to Approve or Move a Payment?

No. That is the short answer, and the one this article defends against every efficiency argument a vendor or an ambitious controller will make. AI can draft the wire instruction, reconcile the invoice, and flag the anomaly. It should never be the entity that authorizes the money to move.

I hear a version of this question from finance leaders whenever a new AI feature ships inside their ERP or AP platform: "Our AI already catches the duplicate invoice and matches the PO in seconds — why are we still making a human click approve?" It's fair. The answer is that the click is not friction. The click is the control.

The Bright Line, In One Paragraph

Here is the direct answer: AI belongs anywhere in finance where it assists a human — drafting, reconciling, extracting, summarizing — or flags something unusual for review. It does not belong where money actually moves, vendor banking details change, or approval thresholds get set. That line exists because segregation of duties, not model accuracy, is the control regulators, auditors, and insurers check for.

Why the Efficiency Case for Automated Approval Is Deceptive

Every AI vendor selling into finance departments eventually pitches the same idea: let the model close the loop. Not just flag the mismatched invoice, but auto-approve the ones that look clean. Not just draft the wire, but release it once confidence is high enough. The pitch is seductive because the ROI math is straightforward — fewer approval bottlenecks, faster vendor payments, lower headcount pressure in AP.

The problem is what that math leaves out. Segregation of duties isn't there to catch the routine error; automated matching and reconciliation already do that well, and AI genuinely improves it. It exists for the rare event: the fraudulent instruction that looks exactly like a legitimate one, because an attacker studied your legitimate ones first. The business case for removing human approval looks strong precisely because the failure it protects against is infrequent and catastrophic, not frequent and small. That is the trap. A control that rarely gets tested is the one that's easiest to argue away, and the one whose absence you discover only after the money is gone.

There is a sharper version of this problem most vendors will not say out loud: the same generative AI capability that makes auto-approval technically feasible is also what is making business email compromise and vendor-impersonation fraud harder to catch. Convincing, urgently worded messages that mimic an executive's tone are no longer a skilled-forger problem; they are a prompt problem, and voice and video synthesis have moved the same trick into real-time calls. The moment AI makes it cheap to remove the human checkpoint is the same moment it makes it cheap for an attacker to defeat whatever checkpoint remains. That is not a coincidence you can automate around. It is a reason to hold the line tighter, not looser.

What Actually Happened at Arup, and Why It Matters to Every Finance Leader

In early 2024, an employee at Arup's Hong Kong office joined what appeared to be a routine video call with the company's UK-based CFO and several colleagues. Every person on that call except the employee was an AI-generated deepfake. Believing the instructions were genuine, the employee carried out fifteen transfers totaling roughly $25 million to five Hong Kong bank accounts, as confirmed by Arup and reported by CNN. The scam began, as most do, with a phishing message impersonating the CFO and requesting a confidential transaction.

The lesson isn't "deepfakes are scary," true but not actionable. The control that failed at Arup was never the video call itself — it was the absence of an independent, out-of-band verification step before a large, urgent transfer went out: a callback to a known number, a second approver who wasn't on that call, a rule that no transaction above a threshold moves on the strength of one video or voice interaction, however convincing. None of that requires distrusting AI. It requires not letting any single interaction be sufficient authority to move money.

What Do Auditors and Insurers Actually Expect Here?

They expect segregation of duties to remain intact regardless of the tooling underneath it, with a human, not a model, as the named approver of record for payment and banking-detail changes. This isn't new AI-specific doctrine; it's internal-control logic that has governed financial reporting for two decades, now tested against a new class of tool.

The Sarbanes-Oxley framework is the reference point most auditors still work from. Under it, every public company must annually assess and report on the effectiveness of its internal control over financial reporting, with its auditor attesting to that assessment — a requirement the AICPA describes in its summary of Sarbanes-Oxley Act Section 404. Segregation of duties is one of the control activities examiners look for first, and the AICPA's own guidance for smaller organizations frames it as dividing incompatible responsibilities — initiating, approving, recording, and holding custody — among different people so no one controls a transaction end to end, a principle laid out in its segregation-of-duties reference chart for smaller organizations. Replace "different people" with "a person and a model" and you haven't satisfied the control. You've automated around it.

The AI-specific overlay comes from the National Institute of Standards and Technology, whose AI Risk Management Framework (AI RMF 1.0) treats human accountability as a cross-cutting governance function, built around the idea that people deploying AI systems remain the accountable decision-makers for what those systems influence. Treasury's interviews with financial institutions echo the same principle: firms said they deliberately keep humans in the loop on AI-influenced decisions because reviewers can develop a false sense of confidence in model output, and because human judgment remains irreplaceable, according to its report on managing AI-specific cybersecurity risks in the financial services sector. That's how institutions running this technology in production have decided to operate it — not abstract regulatory caution.

Cyber insurance underwriters have absorbed the same logic into their questionnaires, because business email compromise is not a hypothetical line item on their loss triangles. The FBI's Internet Crime Complaint Center recorded $2.77 billion in reported BEC losses in 2024 alone, the second-costliest cybercrime category tracked that year, according to the FBI's 2024 Internet Crime Report. Underwriters who have priced that exposure for years now ask pointed questions about callback verification, dual approval, and out-of-band confirmation for banking-detail changes before quoting a policy, and "our AI checks that" doesn't satisfy them without an independent human step behind it.

Where the Line Actually Falls: A Working Reference

The table below is what I actually walk finance leaders through when evaluating a new AP or ERP feature. It's deliberately simple — if you can't place a proposed AI feature into one of these three rows in under a minute, that's itself a signal to slow down.

TierWhat AI may doWhy it's safe
AssistDraft communications, summarize documents, reconcile accounts, categorize transactions, extract line items from invoices, prepare variance commentary, answer questions about historical dataNo transaction moves, no threshold changes, no authority is exercised — output still requires a human to act on it
FlagSurface a suspected duplicate invoice, an unusual vendor bank-detail change, an out-of-pattern approval, or a mismatch, and route it to a named human reviewerThe model adds signal but the decision authority stays with a person; segregation of duties is preserved
NeverInitiate, approve, or release a payment; change vendor banking details; alter approval thresholds; act as the sole approver on any controlThese are the exact points where segregation of duties and human authorization are load-bearing, and where auditors, insurers, and regulators expect to find a person accountable

Notice what the "Assist" row contains: most of the day-to-day workload in a finance function, and AI is genuinely good at it. The bright line isn't anti-AI. It's anti-collapsing three separate roles into one system because that system happens to be fast and confident.

What Should a Finance Leader Actually Do With a Vendor's AI Feature Pitch?

Ask which tier the feature sits in before asking about accuracy rates. A vendor slide touting "auto-approval" or "straight-through processing" above a de minimis threshold is a "Never" feature wearing "Assist" marketing copy, and belongs in the procurement red-flag pile. A feature that stops at flagging and routes to a named human approver who didn't set up the vendor is very likely legitimate.

This is also a governance conversation, not just a tooling one. Our related piece on building practical AI governance for small and mid-sized businesses covers how to formalize exactly this kind of tiering into policy. And because most of these failures start with a convincing message rather than a broken system, pair that governance work with the fundamentals in our breakdown of the phishing and social-engineering tactics businesses actually fall for, since Arup and the broader BEC numbers both start there.

How Securafy Approaches This With Finance Teams

When we evaluate a new AI feature in a client's accounting or ERP stack, we don't start with accuracy claims. We map the feature against the three tiers above, ask who the accountable human approver is for each payment-adjacent step, then test whether that approver can be bypassed under the pressure an attacker would apply. That usually surfaces the gap: a dual-approval rule that collapses when the "CFO" is messaging urgently from a look-alike domain, or a vendor bank-detail process never tested against a convincing impersonation attempt.

From there, we build the control that closes that gap: independent callback verification on banking-detail changes, thresholds no single tool can adjust, and incident response that assumes the impersonation will eventually fool a person, because increasingly, it will. Our work on how cybercriminals are already using AI to launch smarter attacks and our guide to meeting cyber insurance requirements with an MSP feed directly into that work, since underwriting questions and fraud-prevention controls are, in practice, the same list.

Is This Just Caution, or Is It Actually Good Business?

Both, and the two aren't in tension the way the automation pitch implies. A human as the accountable approver on payments doesn't meaningfully slow a well-run AP function, because AI-assisted work — matching, reconciling, extracting, flagging — already removes the slow part. What it protects is the scenario where speed is the wrong thing to optimize for: a fraudulent instruction engineered to look routine. Our piece on where to start with AI security controls for small businesses and why AI without governance is risk, and what to do instead make the same point: the goal is operations where the fast parts and the accountable parts stay separate.

Where To Go From Here

If your finance team is evaluating AI features in AP, ERP, or treasury tools, use the three-tier test above before the next vendor demo, and put it in writing so the next evaluator doesn't have to reinvent it.

If your team is moving faster with AI than your guardrails are, start with structured training rather than another tool. Securafy AI University gives your people role-based AI training with security built into the material, not bolted on afterward.

If you would rather talk through your specific environment first, book a strategy call with Securafy and we will walk your current AI usage, exposure, and the fastest path to safe adoption.

Ric Hall
Ric Hall

Ric Hall is the Chief Revenue Officer at Securafy, with decades of experience in enterprise infrastructure, cloud technology, sales leadership, and business strategy.

He writes for leaders trying to make sense of big technology decisions without getting trapped in vague promises or polished sales language. His articles cover provider selection, IT budgeting, co-managed services, cybersecurity investments, modernization, and the questions businesses should ask before signing a contract.

Ric’s strength is connecting technical decisions to business outcomes, helping leaders understand not just what they are buying, but why it matters and whether it will still make sense 3 years from now.

Writes about: IT budgeting, provider evaluation, cybersecurity ROI, co-managed IT, cloud modernization, vendor selection, technology strategy

More from Ric Hall

Learn AI by building with it

AI University helps teams move beyond AI curiosity through practical lessons, secure workflows, guided experiments, and real projects built for everyday business use.

Explore AI University

Stay current on practical business AI

Get practical updates on AI security, governance, tools, compliance, and implementation without the daily hype cycle.

Join the conversation

Have a question or a different take on this? Add it below.