The CFO's AI Dilemma: Innovating Without Compromising Security
Artificial Intelligence (AI)

Summarise the article with your AI
Here you can read:
CFOs face a problem: how to use AI's power while protecting sensitive financial data. With 29% of interviewed financial executives and CFOs citing data security as their top AI concern in our survey, the race to innovate cannot outpace the need for robust protection. We look at how finance leaders can evaluate AI vendors, implement governance frameworks, and balance automation with accountability, ensuring that every efficiency gain doesn't become a security liability.
The finance team just finished another month-end close. The CFO reviews the AI-supported cash flow forecast, noting the efficiency, improved accuracy, and reduction in manual errors. Time got freed up for strategic work. Then the CISO walks in and asks: "Where exactly does that AI model send our treasury data?". Silence.
This silence can happen to any CFO pushing digital transformation without properly evaluating security and compliance. AI can completely change treasury operations, but only if the security setup can support the innovation built on top of it.
Why security comes first in AI adoption
Financial services rely on and curate some of the most sensitive personal data. Bank account details, payment patterns, liquidity positions, and debtor relationships: each data point is both operational intelligence and a potential vulnerability. When you add AI to the treasury function, it learns from the information, stores it, and makes decisions based on it.
UK regulators take an outcomes-focused approach when looking at AI in financial services. The Financial Conduct Authority's guidance makes clear that existing security obligations apply no matter what AI tools you use. The technology might be new, but the accountability still works within existing regulatory frameworks and obligations.
CFOs should not treat AI security as a separate workstream. Under the newly implemented EU AI Act, most corporate treasury systems fall outside the "high-risk" classification, which is largely reserved for systems involving credit scoring or biometric identification. Nevertheless, the legislation mandates baseline transparency. Forward-thinking organisations should therefore integrate AI risk management into their broader enterprise strategies, treating it with the same urgency as cybersecurity and privacy concerns.
An essential security checklist for AI vendors
When a firm evaluates AI-powered treasury solutions, it should demand transparency on three things: certifications, data handling, and architectural security.
Key standards and certifications
General security: ISO/IEC 27001:2022, the international standard for information security management systems. Proves the vendor has systematic approaches to managing sensitive information and incident response.
Ai governanace: ISO/IEC 42001:2023, the world's first AI management system standard. Signals responsible AI development, ethical deployment, and continuous risk assessment.
Data encryption: AES-256 or similar. Ensures institutional-grade protection of proprietary financial data at rest.
Modern treasury platforms should also show compliance with sector-specific frameworks. The FCA's Senior Managers and Certification Regime requires clear accountability for AI deployments, whilst the Consumer Duty requires evidence-based assessments of customer outcomes.
End-to-end data encryption
Data encryption protects information at rest, in transit, and increasingly during processing. When assessing vendors, CFOs should ask specific questions:
- Which encryption standards apply to data storage? AES-256 remains the most widely used standard, but other modern algorithmic standards also offer exceptional security and speed.
- Does the platform use TLS 1.3 or a similar high-security encryption standard for data transmission?
- How are encryption keys managed and rotated?
- What happens to encrypted data when contracts end?
The Bank of England and FCA's joint survey found that whilst AI delivers benefits, it also presents challenges to firm safety, consumer protection, and financial stability. Encryption serves as a fundamental control that mitigates these risks.
Get clarity on data usage and third-party model training
The question that makes many vendors uncomfortable: "Does our treasury data train your AI models?" The answer matters a lot.
Some AI vendors use customer data to improve general model performance, potentially exposing proprietary information or creating regulatory complications. Others maintain strict data segregation, training models only on anonymised, aggregated datasets or using customer data exclusively within isolated tenants.
The OECD's guidance on AI in finance emphasises the importance of data quality, governance, and risk-aligned implementation. CFOs should demand written commitments on:
- Data ownership and usage rights
- Third-party access and sub-processor arrangements
- Model training practices and data retention policies
- Geographic data residency and cross-border transfer mechanisms
When vendors cannot provide clear, auditable answers, it is prudent to walk away rather than potentially adding a security and compliance risk.
Building trust through governance
Technology alone can't deliver secure AI. Governance frameworks, human oversight, and organisational processes turn theoretical security into operational reality.
Maintain human oversight for all critical decisions
The consensus across regulators is clear: humans must keep ultimate accountability for financial decisions, even when AI generates recommendations. Regulators stress that complex AI models require more focus on testing, validation, explainability, and robust accountability backed by transparent corporate cultures.
What does meaningful oversight look like in practice? Modern treasury platforms should present AI-generated recommendations with sufficient context for humans to evaluate them. When an AI suggests reclassifying a transaction or adjusting a forecast, the CFO's team should understand the reasoning, assess the confidence level, and retain the ability to override the suggestion.
Modern treasury platforms should present AI-generated recommendations with enough context for humans to evaluate them. When an AI treasury analyst suggests reclassifying a transaction or adjusting a cash flow forecast, the CFO's team should understand the reasoning, assess the confidence level, and be able to override the suggestion.
PwC's Responsible AI framework, for example, recommends establishing dedicated AI governance structures, potentially including C-suite ownership and central technical expertise hubs. This organisational design ensures that oversight doesn't become a bottleneck whilst maintaining appropriate controls.
Demanding a clear, auditable trail from any AI platform
Audit trails serve multiple purposes: regulatory compliance, internal control, error investigation, and trust building. When AI makes or influences treasury decisions, organisations need to show what happened, when, why, and who approved it.
The FCA's Consumer Duty requires evidence-based assessments of customer outcomes, including data that supports board-level reviews. For treasury operations, this means comprehensive logging of AI recommendations and the data used to generate them, human decisions to accept, modify, or reject AI suggestions, system configurations and model version changes, access patterns and permission changes, and exception handling and override procedures.
Modern treasury platforms usually have these audit capabilities built in, but CFOs should check that logs stay tamper-proof, are accessible for regulatory enquiries, and get retained according to data protection requirements.
Combine technology with strong processes and training
The most sophisticated AI security architecture fails if employees bypass controls, misunderstand risks, or lack the skills to identify anomalies. KPMG's Global AI in Finance research found that whilst 71% of companies use AI, successful implementation requires robust governance frameworks and trained personnel.
CFOs should invest in:
- Role-based training programmes that teach finance teams how AI systems work, what their limitations are, and when to escalate concerns
- Clear escalation procedures for AI-related security incidents or suspicious behaviour
- Regular governance reviews that assess whether AI deployments continue to meet security and performance standards
- Scenario testing that validates how AI systems respond to edge cases, adversarial inputs, or system failures
UK regulators stress making AI tools accessible to staff whilst ensuring appropriate training and governance. This balance is what CFOs must strike in their organisations.
The regulatory landscape: what's coming
AI regulation in financial services continues to evolve rapidly. The European Banking Authority notes that the EU AI Act complements existing banking legislation, requiring some integration effort from financial institutions. The OECD's survey of 49 jurisdictions found that the vast majority already apply regulations to AI use in finance, following technology-neutral principles.
Forward-looking CFOs should monitor:
- Implementation of the EU AI Act and its classification of high-risk AI systems
- Evolution of the FCA's Critical Third Parties regime, which may capture systemic AI providers
- Development of AI-specific disclosure requirements for financial reporting
- Enhanced focus on algorithmic accountability and explainability standards
Selecting vendors with demonstrated regulatory awareness and adaptation capability reduces the risk of compliance gaps as requirements tighten.
Making the decision: innovation without compromise
The CFO's AI dilemma is a challenge of sequencing and discipline. Best practices are:
- Establishing security baselines before deployment, insisting on certifications, encryption, and data governance from day one
- Maintaining scepticism towards vendor claims, demanding evidence rather than accepting marketing assurances
- Building governance structures that preserve human judgment whilst enabling AI-powered efficiency
- Investing in capability building, ensuring teams understand both AI's potential and its risks
- Choosing platforms designed for transparency, where audit trails, model explainability, and control mechanisms are built into the architecture rather than bolted on afterwards
Modern treasury platforms that integrate AI responsibly show that automation, security, and governance can coexist. The same technologies enabling faster close cycles can also strengthen controls. The AI reducing manual errors can operate within encrypted environments. Innovation can proceed without sacrificing the accountability that regulators, boards, and stakeholders rightfully demand.





