AI adoption in finance is outpacing governance controls, creating a growing model-risk gap, says finance governance researcher Kailash Sadangi.
AI adoption is moving faster than the controls designed to govern it, leaving a growing gap in model-risk accountability across finance functions.”— Kailash Nath SadangiMELBOURNE, VICTORIA, AUSTRALIA, October 2, 2026 /EINPresswire.com/ — A fresh assessment by finance governance researcher Kailash Sadangi reveals a growing discrepancy between the speed of AI integration in corporate finance and the adequacy of internal controls.
Data from KPMG's 2026 global survey shows that active AI usage across finance functions has more than doubled within two years, with over three-quarters of organizations now applying AI to financial planning, reporting, and commercial analysis, and 71% reporting that it meets or exceeds ROI targets. Sadangi's research notes that while finance departments may appear transformed externally, deployment has raced ahead of the control frameworks meant to oversee it.
A separate BCG study on financial institutions found that although 71% rated their own AI capabilities as mid-tier maturity or higher, objective evaluation indicated that only about 25% had truly embedded AI into strategic operations. Sadangi's analysis flags this disparity between perceived and actual governance maturity as a key worry: internal controls, audit trails, and sign-off processes built for human-generated financial data do not automatically apply to model-generated outputs, especially as generative and agentic AI evolve from single-output tools into more autonomous, multi-step decision chains.
Regulators have also started responding to this shift. In April 2026, the US Federal Reserve, the OCC, and the FDIC released SR 26-2, a major update to supervisory guidance on model risk management that had remained largely unchanged for over a decade. The revised guidance explicitly excludes generative and agentic AI from its formal scope, citing the rapid evolution of these technologies. Sadangi's research points to this exclusion as proof that oversight frameworks are still playing catch-up with tools already in daily finance use. Separate global research on generative AI in financial institutions reaches a comparable conclusion, emphasizing that firms must document AI use cases, perform model audits, and embed human oversight in the absence of unified global AI regulation.
Sadangi's analysis also references research on AI-driven cyber threat intelligence in financial institutions, which identifies "shadow use" of AI tools outside formal institutional controls, together with missing security monitoring and audit-ready evidence for AI models themselves, as a recurring failure mode — meaning the models finance teams increasingly depend on are often the least-audited element of the process.
"The risk isn't that AI in finance produces obviously wrong numbers — most of the time it doesn't," said Kailash Sadangi. "The risk is that when a model drifts, hallucinates or degrades in accuracy, the controls designed to catch human error may not be built to catch model error, and few finance functions have clearly assigned who is accountable for closing that gap. Closing it doesn't require finance leaders to become AI engineers — it requires model audits treated as seriously as financial audits, documented human sign-off points built into AI-assisted workflows, and clear ownership of model risk sitting somewhere specific, not spread thinly across IT, risk and finance with nobody formally accountable."
Kailash Sadangi is a senior finance executive with Group CFO experience spanning Australia, the Middle East, and international markets, and a doctoral researcher focusing on CFO-centred governance of AI-enabled decision-making.
Sources referenced:
* KPMG International, "2026 The Decision Advantage: AI in Finance" — https://kpmg.com/kpmg-us/content/dam/kpmg/pdf/2026/kpmg-ai-in-finance.pdf
* BCG data on AI maturity gap in financial institutions — https://www.360factors.com/blog/ai-finance-risk-and-compliance/
* Federal Reserve/OCC/FDIC, SR 26-2 model risk management guidance (2026) — https://arxiv.org/pdf/2607.04103
* "Generative AI in Financial Institutions


