
In February 2026, COSO published Achieving Effective Internal Control Over Generative AI, written by Scott Emett, Marc Eulerich, Jason Guthrie, Jason Pikoos and David Wood, building on the Internal Control Integrated Framework.
Why Splitting Them Up Matters
The most immediately useful thing in it is not a control. It is a taxonomy. The guidance splits AI into eight capability types: ingestion, transformation, posting, orchestration, judgment, monitoring, regulatory intelligence and human-AI interaction, each with its own control considerations.
Most firms are still evaluating AI as one thing. Are we using it, which tool, is it approved, what does the policy say.
That framing hides the only distinction that matters for internal control, which is what the AI is allowed to touch.
An AI that reads a bank statement and extracts figures for a person to use is doing ingestion. If it gets something wrong, a human looking at the output catches it, and the error never leaves the desk. An AI that posts a journal entry has changed the accounting records. If it gets that wrong, the error is in the books and the detection has to happen downstream, by someone who was not watching.
Same technology. Same vendor, quite possibly the same product. Entirely different control requirement.
Posting Is the Line
So the question worth asking about every tool in the firm is narrow: does this thing write, or does it only read and suggest.
If it writes, the control cannot be a prompt. This is the part that gets fudged in practice. A system instruction saying ask before posting is a request to the model, and a request is not an authorisation control. The application has to prevent the write until an identified approver, authenticated as themselves, permits it. Anything softer is a preference that a model can fail to honour and that nobody can evidence afterwards.
The accounting principles here are not new and did not need AI to invent them. Preparer and approver are different people. Authorisation is enforced by the system rather than requested by a note. Every posting carries a trail back to who approved it and on what basis. What is new is that the preparer is now a piece of software that will produce a confident, well-formatted entry whether or not it is right.
What the Record Has to Contain
The second half of the guidance is about evidence, and this is where firms tend to discover their gap.
Coverage of the COSO material describes capturing prompts, inputs, outputs, source references, model and configuration versions, and confidence scores, because all of them can bear on whether a control operated effectively. Read that as a practical requirement rather than a compliance list. If an entry posted in March is questioned in November, the questions will be what was this based on, which version of the tool produced it, and who approved it.
A firm that can answer those three has an auditable process. A firm that cannot has an entry that appeared, and a story about how the software is usually reliable.
The Practical Exercise
None of this requires a project. It requires an afternoon and a list.
Write down every tool in the firm that touches client financial data. Against each one, mark which of the eight capabilities it actually performs. Most will land in ingestion and transformation, which is the low-risk end and where the majority of real value currently sits.
The ones that mark posting are the short list. Those need an enforced approval gate, separation between whatever prepares and whoever approves, and a retained record of what the entry was based on. If a tool posts and cannot give you that, it is not ready for your ledger regardless of how good its extraction is.
MetaWurks sits deliberately on the reading side of that line. It ingests a client's invoices, contracts, statements and correspondence and lets an accountant query the whole set in plain English. It writes nothing to any ledger, which is a design decision rather than a missing feature. Role based access controls decide who can open which client's records, audit logs record who opened what and when, and documents ingested into the platform are not used to train models or exposed to other users.
Where it helps on the posting side is the part COSO cares about: when someone reviews a proposed entry, the supporting material behind it is a question away rather than a hunt, which is the difference between an approval that means something and a click.
Eight capabilities. One of them changes the numbers. Find out which of your tools is in that column before somebody asks you in November.
Join the Conversation
Of the AI tools your firm uses on client work, which ones can write to a ledger, and is the approval gate on those enforced by the software or by a sentence in a prompt?