Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Thought leadership & research. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

Key Findings

Accounting firms need documented AI agent approvals before auditors or state boards ask. Build controls that protect close quality and margins.

AI Agent Governance for Accounting Firms
Insight ai

AI Agent Governance for Accounting Firms

Sam McKay

AI agents are already in the workflow

Accounting firms don’t need a lecture about artificial intelligence. Many teams are already using it, often in small ways that don’t appear in a technology plan.

A bookkeeper uploads a bank statement and asks a tool to suggest transaction categories. A tax preparer uses an assistant to draft a client follow-up email. A manager feeds a trial balance into a model and asks what changed this month. Someone builds a workflow that extracts invoices, chases missing documents, or writes a first-pass variance commentary.

Those are useful starts. They can also become a problem if nobody can answer four basic questions:

  1. What did the agent do?
  2. What source data did it use?
  3. Who checked its work?
  4. Who had the authority to approve the result?

That is the governance gap facing accounting and bookkeeping firms. AI agents are moving from simple drafting tasks into workflow steps that influence reconciliations, journal entries, client communications, tax workpapers, and financial reporting. The work may still be reviewed by a person, but unless that review is designed, assigned, and recorded, it is hard to prove human oversight later.

Auditors, client finance teams, insurers, and state boards won’t be interested in a vague assurance that someone looked at it. They will want to know what controls were in place, when the review happened, and what happened when the system got something wrong.

For firms in the $1 million to $25 million range, this isn’t a theoretical compliance exercise. Weakly governed automation often sits inside the same operational leaks that cost a firm $60,000 to $180,000 a year. That cost shows up as rework, unbilled cleanup, partner review time, slow onboarding, and advisory meetings that never make it onto the calendar.

The right response isn’t to ban AI agents. It’s to build a practical approval framework before the automation becomes too embedded to control.

Where governance breaks in a real accounting workflow

The main risk isn’t that an AI tool writes a poor sentence. The real risk is that a useful tool quietly becomes part of a financial workflow without clear decision rights.

Consider month-end close. A staff member may use automation to pull bank, AP, AR, and payroll information into a workpaper. That automation identifies unusual transactions, proposes account coding, matches payments, and drafts journal entries. On a busy week, the staff member accepts most recommendations because the work needs to move.

Nothing about that is automatically reckless. In fact, it can be an excellent use of AI. The issue is what happens next.

If the proposed journal entry is posted, who approved it? If an exception was flagged but then dismissed, where is that judgment recorded? If the agent drew on incomplete source data, how would a reviewer know? If a client asks why a balance moved, can your team reconstruct the path from source transaction to final report?

The same problem appears in client onboarding.

A new client sends a mixed folder of statements, payroll exports, sales reports, historical ledgers, and old tax files. An AI agent can collect documents, read them, map accounts, identify gaps, and produce an opening trial balance. That can compress weeks of manual back-and-forth.

But an opening balance isn’t a marketing deliverable. It becomes the basis for every report and return that follows. Your team needs a defined point at which someone verifies the source documents, resolves judgment calls, and signs off on the chart of accounts and opening balances.

Tax work raises the stakes further. An agent may summarize a client’s documents, flag potential deductions, prepare a checklist, or draft workpaper notes. That work must remain within a structure where a qualified person applies professional judgment and owns the final output.

Governance is not about adding a signature to every low-risk action. It is about deciding which actions can run automatically, which need review, and which must never be delegated.

Start with the work, not the software

Most firms begin by comparing AI products. That’s understandable, but it is the wrong first step if governance is your concern.

Start with the workflow you want to improve. Map the steps, the inputs, the decisions, the people involved, and the output that leaves the firm. Then identify where an agent can assist without taking ownership of professional judgment.

Take the Month-End Close Agent from Omni ops. It pulls bank, AP, AR, and payroll feeds, reconciles items, flags variances, drafts journal entries, and prepares a partner-ready close pack.

That sounds like one activity. It is actually several different risk levels.

Low-risk actions can be automated

The agent can usually perform routine collection and preparation work with limited human intervention:

  • Pull approved data feeds into a defined close workspace
  • Match transactions using documented matching rules
  • Gather supporting documents for known account categories
  • Prepare a list of unreconciled items
  • Draft variance explanations using approved source information
  • Create a close checklist and identify missing evidence

These tasks need logging and exception handling, but they don’t all need partner approval. The controls should confirm that the agent used the approved data source, followed the latest workflow version, and recorded what it produced.

Judgment-based actions need a reviewer

Other tasks should stop at a review gate:

  • Proposed journal entries above a materiality threshold
  • Changes to account mapping
  • Unusual accruals or reversals
  • Variances outside a predefined range
  • Reclassification of transactions that affect management reporting
  • Any client-facing explanation of an unexpected result

The agent can do the preparation. A staff accountant or manager reviews the evidence and approves, rejects, or amends the recommendation. The workflow records that action.

Reserved actions need senior authority

Some decisions should never be pushed through a general automation queue:

  • Final approval of financial statements
  • Tax positions that require technical judgment
  • New client acceptance decisions
  • Material prior-period adjustments
  • Changes to client reporting policies
  • Advice that could affect financing, tax exposure, or an owner’s personal decision

This is where firms get into trouble when they say, “The AI only assists us.” Assistance is not a control. A named reviewer, an approval standard, and a usable record are controls.

Build an approval framework people will actually follow

A governance framework doesn’t need to read like a bank policy manual. For a growing accounting firm, it should fit on a few working pages and be built into the workflow itself.

There are six components I would put in place first.

1. Assign an owner for each agent

Every agent needs a business owner. Not an IT owner alone, and not a vague committee.

The owner is accountable for the agent’s purpose, approved use cases, input data, review requirements, escalation path, and regular testing. For a Month-End Close Agent, this may be your outsourced accounting manager. For an onboarding workflow, it may be the client services leader.

That person doesn’t need to personally review every transaction. They do need to know how the workflow behaves and what should happen when it fails.

2. Define the agent’s permitted scope

Write down what the agent is allowed to do, and what it is not allowed to do.

For example, the Client Onboarding Agent can request documents through a guided workflow, extract account names from historical records, propose a chart of accounts, and prepare an opening trial balance. It cannot approve that trial balance, decide on a complex revenue treatment, or send a final client welcome pack containing unreviewed financial conclusions.

The Client Onboarding Agent can remove a lot of friction from a process that frequently delays revenue. Firms of this size commonly see 20% to 30% of new clients held up long enough for billable work to slide into a later quarter. The solution isn’t merely collecting documents faster. It is creating a controlled handoff from automated collection to human approval.

Scope limits protect your team and make training simpler. Staff should know exactly when they can rely on an agent and when they must stop and escalate.

3. Set approval thresholds in plain language

Do not write, “Review material items as appropriate.” That leaves too much open to interpretation during a close crunch.

Instead, specify thresholds based on your client mix. A threshold might relate to a dollar value, percentage movement, account type, or risk event. For example:

  • A preparer may approve matches that meet established rules and have supporting evidence.
  • A manager must approve any proposed entry over an agreed dollar threshold.
  • A partner reviews changes that affect financial statement presentation or tax treatment.
  • Any missing source document on a balance sheet account creates an exception that cannot be auto-cleared.
  • Any client communication that interprets financial performance requires review before release.

The numbers will differ by client. That is fine. The framework should allow client-specific thresholds without forcing your team to reinvent the rules every month.

4. Keep an audit trail that tells a coherent story

A usable audit trail should show the source, the agent action, the exception, the reviewer decision, and the final outcome.

This is not about creating a mountain of screenshots. It is about making it possible for a manager, auditor, or board reviewer to understand the chain of custody.

For each material action, retain:

  • The source system or document used
  • Date and time of the action
  • Agent workflow version or configuration
  • The recommendation or drafted output
  • The reviewer’s name and decision
  • Notes explaining overrides or exceptions
  • Links to supporting workpapers where relevant

If your current tools cannot produce this record, that should influence the design. A black-box workflow may save a few minutes this month while creating a major review burden later.

For a closer look at the operating model behind this work, see Omni for accounting and bookkeeping. The point is not to pile on technology. It is to make every handoff visible and accountable.

The control that matters most is the exception queue

Most AI-generated work will look reasonable. That is why exception design matters more than normal-path automation.

Your firm should decide what causes a workflow to stop and ask for human judgment. Good triggers are specific. They might include an unmatched payment after two matching attempts, a vendor appearing for the first time, a transaction coded to a sensitive account, a large variance against the prior period, or a missing document on a tax workpaper.

Each exception needs an owner and a service level. If nobody owns it, it becomes a hidden queue. By month-end, hidden queues turn into partner fire drills.

This is where the Month-End Close Agent earns its keep. It should not pretend that every item can be reconciled. It should organize the unresolved work, attach the evidence, explain why the item was flagged, and route it to the right person.

That is a better version of automation than a tool that simply pushes more volume onto staff. Your people should spend their judgment where it matters, not searching across inboxes and spreadsheets for the missing context.

If you want a working worksheet for mapping this process, download the Month-End AI Close Map for Accounting Firms. It helps you identify inputs, approval points, exception rules, and evidence requirements before you automate a close task.

You can also access the printable version directly at this download link.

Governance protects advisory capacity

There is a commercial reason to get this right. Your highest-value work is often the first thing crowded out when compliance delivery becomes unpredictable.

In many firms, 30% to 50% of staff time gets concentrated into roughly four peak weeks around month-end, year-end, or tax deadlines. The calendar fills with chasing information, reviewing cleanup work, correcting coding, and answering basic client questions. The advisory conversation becomes a nice idea that never gets scheduled.

That is expensive because advisory work commonly commands two to three times the billable rate of compliance work. A firm doesn’t need to convert every client into a major advisory engagement for this to matter. It needs enough dependable delivery capacity to identify opportunities, prepare useful insight, and have the conversation while it is still relevant.

The Advisory Insights Agent supports that transition. It reads each client’s monthly numbers, surfaces three things to discuss, and drafts the partner’s talking points before the meeting. But the same governance principle applies. The agent can identify patterns and prepare prompts. A qualified adviser needs to check the context, test the claim against the financial records, and shape the recommendation.

That review step is not lost productivity. It is where your firm’s judgment creates value.

If you are considering this type of agent, Omni advisory shows how the operational data can feed a more consistent client conversation. The aim is not to replace the partner. It is to make sure the partner enters the meeting prepared.

Test the framework before a deadline tests it for you

Don’t wait until December or the final week of a major filing cycle to discover that your approval process is unclear.

Choose one workflow with recurring volume and manageable risk. Month-end reconciliations are often the right starting point. Run the agent and the existing process in parallel for a defined period. Compare error rates, turnaround time, exception volume, reviewer time, and the quality of the audit trail.

Look for the practical issues:

  • Are reviewers seeing enough evidence to make a decision?
  • Are staff overriding recommendations for consistent reasons?
  • Do threshold rules create too many false positives?
  • Is the agent touching data it doesn’t need?
  • Can a manager retrieve an approval record quickly?
  • Are client-facing outputs being checked before release?

Review the workflow after 30 days, then adjust. Governance should be a working management process, not a policy document that sits in a folder.

For ideas on how firms are structuring these changes, our AI insights library is a useful place to compare operational use cases without getting lost in vendor claims.

Get a clear view of your exposure and opportunity

The firms that handle AI agents well will not be the ones with the longest policy documents. They will be the firms that can show where automation operates, how exceptions are handled, and where a human professional makes the call.

That discipline also exposes where margin is leaking today. When you map the work, you can see the repetitive collection, coding, follow-up, and review tasks that consume senior capacity. For a $1 million to $25 million firm, recovering even part of the usual $60,000 to $180,000 annual leakage band can fund a much more deliberate automation program.

An Omni Audit takes 60 minutes and produces three useful outputs: a map of the workflows creating drag, a view of the highest-value agent opportunities, and a practical first-step plan with governance requirements built in. There is no deck and no generic maturity score.

Book a 60-min Omni Audit if you want to identify where AI can reduce close pressure without weakening human oversight.

You can also review the AI audit for accounting and bookkeeping before the call. It outlines the areas we assess across close, onboarding, reporting, and advisory delivery.

The important move is to document your approval model now, while your AI use is still forming. A controlled agent can give your team capacity. An undocumented one can create a future review problem that costs far more than the time it saved.

When you are ready to map it properly, Book my Omni Audit.