Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Thought leadership & research. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

Key Findings

Accounting firms need human checkpoints and rollback plans before AI agents post entries or file returns without approval.

When AI Agents Go Rogue in Accounting
Insight ai

When AI Agents Go Rogue in Accounting

Sam McKay

The real risk isn’t AI making a mistake

Every accounting firm has dealt with a software error. A bank feed duplicates transactions. A payroll integration maps a liability account incorrectly. A client uploads the wrong statement. Your team catches it, investigates, fixes the books, and moves on.

AI agents create a different risk.

An agent doesn’t just suggest an answer. It can be given permission to act. It can create entries, match transactions, clear exceptions, update client records, send requests for information, and potentially prepare or submit tax work. If the scope is unclear, an agent can make the wrong decision repeatedly and at speed.

That is what people mean when they talk about rogue AI agents. The issue isn’t that an AI system becomes malicious. The issue is that it follows an incomplete instruction, infers a rule that doesn’t apply, or keeps pursuing a goal after the business context has changed.

For an accounting or bookkeeping firm, that can mean an agent:

  • Posts a recurring accrual after the underlying contract has ended
  • Categorises related-party payments as ordinary operating expenses
  • Clears unreconciled transactions based on weak matching logic
  • Sends a client-facing report before a reviewer has checked the numbers
  • Applies a tax treatment based on last year’s facts
  • Creates journal entries across dozens of client files before anyone sees the pattern

That last point matters. One bad manual entry is a training issue. Fifty bad entries across client books can become a trust issue, a write-off issue, and a risk issue.

Before your firm deploys agents for bookkeeping, close, or tax preparation, you need a clear answer to one operational question: what happens when the agent does something it wasn’t meant to do?

The answer can’t be, “We will spot it in the review.”

Why accounting firms are exposed

Most firms don’t start by giving AI broad authority. They start with a sensible use case.

Maybe the team wants help clearing bank-feed exceptions. Maybe they want draft journals prepared during month-end. Maybe tax staff want an agent to pull data from client documents and populate a return workpaper.

The pressure is understandable. In many firms, 30% to 50% of staff time gets concentrated into roughly four weeks around month-end, year-end, or key filing deadlines. Partners want that pressure off their strongest people so they can spend more time on review, client relationships, and advisory work.

The problem starts when a trial workflow becomes a production workflow without controls.

A bookkeeper might ask an agent to reconcile transactions under $500 that match a vendor and account history. That sounds narrow. But what happens when a vendor changes bank details, a duplicated payment appears, or a client starts using one card for both business and personal purchases?

The agent may see a match. Your experienced bookkeeper may see an exception that needs context.

The same applies to tax preparation. An AI agent can extract figures from source documents, identify missing information, and draft schedules. It should not decide that a missing document is immaterial, override a warning, or treat an uncertain item as filed and final.

This isn’t a case against Omni Ops or against automation. It’s a case for setting boundaries before work begins.

The best use of agents in accounting is often not autonomous posting. It is controlled progress through a workflow where the agent does the repetitive work, records what it did, and stops at the right point for a human decision.

Identify the work that can move, and the work that must stop

A practical way to design AI workflows is to split each process into three levels of authority.

Level 1: Read, collect, and organise

At this level, the agent can gather information but can’t change the books or submit anything.

For a new bookkeeping client, it can request bank statements, payroll reports, prior financials, tax registrations, and chart-of-accounts information. It can track missing documents and prepare an opening file checklist. It can identify apparent gaps in the historical ledger.

This is a strong place to use a Client Onboarding Agent. The agent guides document collection, organises source files, proposes a chart of accounts, and produces a draft opening trial balance.

Your team still reviews the proposed structure. A construction business, medical practice, ecommerce brand, and professional services firm may all have different reporting needs even if the software setup looks similar.

The agent has accelerated preparation. It hasn’t made an irreversible decision.

Level 2: Draft and recommend

At this level, the agent can analyse data and prepare work for review. It can create a proposed journal entry, a reconciliation explanation, an exception list, or a client email draft. It still cannot post, file, send, or approve.

This is where a Month-End Close Agent can make a material difference. It pulls bank, AP, AR, and payroll feeds. It reconciles routine items, flags variances, drafts journal entries, and prepares a partner-ready close pack.

That can remove a lot of low-value assembly work from the close process. It also gives the reviewer something much better than a blank worksheet. The reviewer sees the proposed entry, support, source data, confidence level, exceptions, and the reason the agent chose that treatment.

A reviewer can then approve, edit, reject, or escalate the item.

Level 3: Act within tight rules

This level includes posting entries, updating systems of record, sending client communications, and filing returns. It is not off limits, but it needs the tightest controls.

A good rule is that an agent can act automatically only when all of the following are true:

  1. The transaction type is pre-approved.
  2. The dollar limit is defined.
  3. The confidence threshold is documented.
  4. A clear audit trail is retained.
  5. A rollback action is available.
  6. The action doesn’t create a filing, payment, or external commitment.
  7. An exception route exists when the agent is uncertain.

For example, your firm may allow an agent to post recurring rent allocations that are matched to a fixed schedule and below a set materiality threshold. You may not allow it to post manual revenue adjustments, payroll liabilities, intercompany balances, owner transactions, or tax-sensitive items without review.

The control isn’t about distrusting the technology. It is about applying the same segregation-of-duties thinking you already use in finance.

Build a rollback procedure before you deploy

If an agent posts 40 incorrect entries overnight, your team should not be designing the response from scratch at 8:30 the next morning.

A rollback procedure is a documented method for identifying, reversing, and reviewing agent actions. It should be part of the workflow design, not a document you create after an incident.

For each agent process, document five things.

1. The action log

Every agent action should carry a clear record of:

  • The client entity and accounting period
  • The source documents and systems used
  • The rule, prompt, or workflow that triggered the action
  • The proposed and final accounting treatment
  • The staff member who approved it, if approval was required
  • The time of posting or submission
  • The unique batch or transaction identifier

Without this, your team may have to reconstruct what happened from system logs, chat histories, and changing data feeds. That burns time at exactly the moment you need control.

2. The rollback owner

Name the person responsible for stopping the process. This should not be vague language like “the finance team” or “the AI lead.”

For each workflow, assign a primary owner, a backup owner, and an escalation point. In a smaller firm, that may be the bookkeeping manager, a partner, and the head of technology. In a larger firm, it may include a quality-control partner or tax director.

The owner needs authority to pause the agent without waiting for a committee.

3. The technical stop

An agent needs a kill switch. That could mean disabling its posting permission, disconnecting an integration, turning off a scheduled run, or moving it into draft-only mode.

Don’t assume a staff member can simply tell the agent to stop in a chat interface. The system needs a reliable administrative control.

Test this before going live. If it takes three hours to find the right integration setting, you don’t have a practical stop procedure.

4. The reversal process

Define how corrections occur.

For bookkeeping workflows, the process may be a reversing journal batch linked to the original agent batch. For reconciliations, it may mean reopening matched transactions and returning them to an exception queue. For tax workflows, the process may require a senior reviewer to assess whether a draft has been released, filed, or communicated externally.

Avoid deleting history where possible. A clean audit trail should show the original action, the reason it was reversed, and the person who approved the correction.

5. The client communication rule

Not every error needs a client call. Some do.

Set materiality and communication thresholds in advance. A misclassified small expense caught before reporting may need only an internal correction. A released management report, a payroll issue, a filed return, or a cash-impacting entry has a different response path.

Your firm should decide who communicates, what facts are verified first, and when the client is informed. That protects trust when pressure is high.

Put human checkpoints where judgement matters

Human review should not be a generic final step at the end of a process. It needs to sit at defined decision points.

For a month-end process, useful checkpoints include:

  • Before unusual or non-recurring journals are posted
  • Before revenue, inventory, payroll, tax, and related-party entries are finalised
  • Before material exceptions are cleared
  • Before management accounts are released to the client
  • Before an agent changes account mapping rules for future periods

For a tax process, the checkpoints are even more important:

  • Before source data is treated as complete
  • Before a position is selected where facts are unclear
  • Before a return is marked ready for signature
  • Before filing or submission
  • Before an agent sends tax advice or a client-facing conclusion

The human checkpoint should be designed around a decision, not just a click.

A partner reviewing a close pack needs to see what changed from last month, what the agent couldn’t resolve, what it posted under approved rules, and which judgments still need attention. That is much more useful than asking them to review every line again.

This is also where the Advisory Insights Agent earns its place. It reads a client’s monthly numbers, surfaces three things to talk about, and drafts the partner’s talking points before the meeting. It doesn’t replace the partner’s judgement. It makes sure the partner sees the cash trend, margin shift, debtor movement, or cost pressure early enough to discuss it.

That matters because advisory work is often billed at two to three times the rate of compliance work. If compliance workflows consume the calendar, the firm loses more than time. It loses the conversations clients will actually pay for.

If you want to map where human approval belongs in your close process, Book a 60-min Omni Audit. We will focus on the work your team does now, the permissions an agent would need, and the controls required before it acts.

What a controlled AI close looks like

Here is a practical end-to-end example for a bookkeeping client.

On day one of close, the Month-End Close Agent pulls approved data from bank feeds, AP, AR, payroll, and the general ledger. It checks that key feeds are current and identifies missing statements or disconnected accounts.

It then runs routine reconciliations. Items with an exact or pre-approved match can be prepared for posting. Items outside the policy move to an exceptions list.

The agent compares the current period with the prior month, budget where available, and recent trading patterns. It flags movements like a 35% rise in subcontractor costs, a debtor balance that has aged beyond the client’s normal pattern, or payroll costs that don’t tie to headcount data.

Next, it drafts journals for items that follow established rules. These might include prepaid expense releases, depreciation, recurring accruals, or payroll allocations. Each draft includes support and an explanation.

At the checkpoint, the reviewer sees three queues:

  1. Routine items eligible for batch approval
  2. Draft journals that require review
  3. Exceptions that need judgement or client clarification

The agent cannot post from queue three. It can draft a client question, but the firm decides whether and when to send it.

Once the reviewer approves the relevant work, the agent creates the close pack. It summarises cash, working capital, margin movements, major variances, unresolved items, and draft talking points for the client meeting.

That is useful automation. It moves data, prepares evidence, and makes the reviewer faster. It does not quietly make decisions beyond its authority.

For examples of how these operating workflows are designed, see Omni for accounting and bookkeeping. You can also review the wider Omni platform to understand how operational agents and review steps fit together.

The dollar case for controls and automation

For an accounting or bookkeeping firm doing between $1 million and $25 million in revenue, we usually see annual leakage in the range of $60,000 to $180,000 from repeated manual work, rework, delayed onboarding, and lost advisory capacity.

That number isn’t one isolated cost. It compounds.

A senior manager spends four hours each month chasing missing close information. A team member rebuilds reconciliations after a feed issue. New clients wait weeks for historical clean-up, which delays billable work. Partners spend Friday afternoon checking reports that could have been assembled and exception-coded earlier in the week.

At the same time, a poorly governed agent can add new forms of leakage. A bad batch creates write-offs. A client loses confidence after receiving unreviewed information. Staff stop trusting the workflow and return to manual checking of every item.

The goal is not maximum automation. The goal is reliable throughput.

A controlled agent should give your team more capacity while reducing the volume of work that needs a full manual rebuild. That is what makes the economics work.

Use a close map before choosing the tools

Before you approve another AI trial, map the close process as it actually operates. Include the inputs, handoffs, approvals, exception types, posting rights, and client communications.

Our Month-End AI Close Map for Accounting Firms is a practical worksheet for that exercise. Use it with your close manager and one experienced reviewer. Identify which steps should stay human, which steps can be drafted by an agent, and where a rollback would be needed.

If you prefer the printable version, you can download the close map directly.

You will probably find that your best first workflow isn’t the most ambitious one. It is the one with a stable process, clear source data, repeatable decisions, and a straightforward route back if anything goes wrong.

For more practical operating ideas, the EDNA insights library includes examples of where firms can remove repetitive work without handing over judgement.

Make the next deployment safer

A responsible AI rollout in an accounting firm should answer these questions before the agent gets access:

  • What can the agent read?
  • What can it draft?
  • What can it post or send?
  • Which actions require approval?
  • What conditions force an exception?
  • Who can stop it?
  • How do we reverse its work?
  • How will we know if it starts behaving outside the intended rules?

If you cannot answer those questions in one working session, the process isn’t ready for autonomous action.

An Omni Audit gives you 60 minutes to work through it with a practical lens. You leave with three outputs: the best workflow to prioritise, the manual leakage attached to it, and a clear view of the agent, controls, and rollout steps required. No deck. No vague automation roadmap.

See Omni for accounting and bookkeeping to understand the audit approach, or Book a 60-min Omni Audit when you are ready to map the workflow properly.