AI in AP without losing control
A controller’s guide to adopting AI in accounts payable while keeping decisions, validation and accountability clear.
• Automate faster • Collaborate better
• Pay with confidence
Every AP vendor now claims artificial intelligence. Almost none of them tells controllers what they most need to know: how the technology fails, and what controls keep those failures out of the ledger.
This paper takes a controls-based middle position. "AI is too risky for financial data" ignores real evidence — top models now exceed 96% zero-shot extraction accuracy on open invoice datasets. "The vendor said it’s 99% accurate, so we’re fine" ignores equally real evidence — the same models can fabricate plausible-looking numbers, and a field returned at 0.95 confidence can still be wrong. The position throughout: the controller, not the algorithm, signs.
IN THIS WHITEPAPER
The failure modes controllers should plan for, and why a model’s confidence score is not an accuracy guarantee
How to design human oversight into the workflow: ground, validate, gate, record
What the fraud evidence says about where humans must remain — vendor-master changes, banking details, payment release
The centerpiece: a crosswalk mapping the five COSO internal-control components to concrete AP-AI controls, drawing on COSO’s 2026 generative-AI guidance, the NIST AI Risk Management Framework and ISO/IEC 42001
A fourteen-question vendor-diligence checklist and an implementation approach that keeps controls intact
STAT CALLOUTS
96%+ — zero-shot field-extraction accuracy of top multimodal models on open invoice datasets (academic benchmarks)
5 — COSO internal-control components mapped to concrete AP-AI controls
14 — vendor-diligence questions to put to any AI-AP platform
Adopt the technology, keep the signature. The controls framework is inside. Complete the form to get your copy.