A reflection

The CFO and AI: The Leadership Opportunity

A reflection from Kristin Stubbins AM FCA on the leadership opportunity for the modern CFO, based on 30 years of experience in understanding and reviewing businesses and 2 years of diving into AI and the “Art of the Possible”.

7 August 2026

The lessons from the past 20 years

This article has been written after a period of extensive reflection. I started exploring how CFOs should respond to the opportunities and challenges presented by enterprise usage of AI about 18 months ago. I was prompted to consider this topic following the work my firm, KSIB, had done with large complex organisations seeking to implement ‘AI First’ strategies across all aspects of their business (from customers through to operations). This work gave us some insight into what is likely to drive successful AI adoption, including business model change, and what is likely to result in sub-optimal outcomes. Unsurprisingly, the lessons of the past 20 years of technology implementations are highly relevant to the transformative change presented by AI. The challenge is actually a leadership one – how to do things differently. The CFO has a unique role to play in this as he or she sits at the centre of the organisation focusing on risk management and costs.

I have had countless discussions with CFOs over the past 20 years focused on technology implementations not delivering the promised outcomes, cost overruns and often poor adoption rates. The lessons we all learned from these implementations are easy to describe in hindsight but culturally seem hard to fix. At least it seems that way to me, given the continuing complaints and repeated instances of technology implementation failure (sometimes with big asset write downs).

I wrote an article in May 2024 that summarised key lessons from KSIB’s experience with hundreds of transformations and IT implementation over the past 20 years. This focused on the need to understand and learn from what others are doing globally, assessing and being honest about your current situation and implementation readiness, leading the program of work in a way that recognises the culture of your organisation and ensuring that governance and discipline underpin everything.

These high-level lessons are still highly applicable and still seem incredibly hard to implement, even after all of the experiences that we have had with the transition to cloud and other seismic technology shifts.

The challenge is actually a leadership one – how to do things differently

The new risks

The opportunities for enterprises to adopt AI are more than significant – they are transformative and industry structures are starting to change in response. The risk landscape has also increased exponentially. Most people are aware of the significant risks that Generative AI introduces including the potential for bias and hallucinations. There are a number of other risks that are prevalent, particularly when established or mature organisations are seeking to adopt AI solutions at enterprise scale.

One area that has not been well understood historically by executives or Boards other than technology risk specialists, are the technology risks that need to be monitored and controlled at scale in legacy systems. There has been a lot of focus on User Access Management (UAM) and Privileged Access Management (PAM) in large regulated institutions in recent years, but the rest of the market has lagged financial services in investment in capability and controls in this area. Categories of IT controls that are often not well understood by the broader executive team but are critical to the operation of systems already underpinning your organisation include:

01

IT General Controls

Access controls, change management, program development/system development, computer operations

02

IT Application Controls

Input controls, processing controls, output controls

03

Security Controls

Network security, data security, endpoint security, physical/environmental security

04

Governance and Management Controls

IT Governance, Third Party/Vendor Management, Business Continuity and Disaster Recovery Planning

05

Interface and Data Integrity Controls

Interface controls between systems, data migration controls, end user controls (including controls over workarounds and user developed applications – read complex excel spreadsheets!!)

These legacy technology risks and the controls that need to be in place to manage them are already complex, this then gets even more complex once AI systems are “layered” in and business models start to change. The external cyber threat is also now at a level never seen before given the capability of some of the new large language models.

Methodology

KSIB has done a lot of thinking in this space that we have put into practice now with several large organisations. In addition to the overall methodology we use to help clients implement AI at enterprise level, or to assess implementations from a risk perspective (AI Unleashed), we have developed and used a detailed methodology to test the overall risk management and efficacy of specific use cases. This methodology is summarised below:

GovernanceLeadership oversight, accountability, policy compliance
Operating modelAgile ways of working, cross-functional teaming
RegulatoryCompliance testing, proactive engagement
ResilienceBusiness continuity, staff training, rollout strategy
TechnologyCyber risk, IT controls, authentication, 3rd party risk
DataStructured data stores, privacy, records management
Data sciencePrompt design, intent detection, model configuration
Gen AI specificTransparency, bias, hallucination, explainability
Preventative controlsTesting, change management, controls by design
Detective controlsQuality monitoring, trend analysis, AI-augmented review

Managing AI costs

“How are you managing costs and tokens?”

Understandably this is the new question that is being asked by Boards and Executives. The opportunity for CFOs is to answer this question in terms of the benefits that are being derived, and how they are ensuring that these are being achieved. This links back to CFOs needing to be in the centre of all things AI – the office of the CFO is the “kitchen” of the organisation.

4 key steps for the finance team to consider when managing AI costs

1

Do an AI audit

Across the organisation – who is using what, who is accountable, what are the controls?

2

Agree what counts as an AI cost

Direct AI spend, Embedded AI (SaaS products with AI uplifts, per seat AI add ons), Enabling costs (data readiness, security and controls, compliance and assurance), People and change (upskilling, change management, role redesign and management)

3

Business case approval process

If you do not have a business case approval process that is adapted for AI, create one

4

Make every dollar visible and measured

Create the reporting, put controls in place including approval gates, start a monthly rhythm to review unit economics and benchmark ROIs. Consider establish a joint forum with relevant executives but at a minimum CFO, CIO to manage the costs.

How the CFO can lead

The CFO has a significant leadership role to play in the AI revolution. To get you thinking more about this, I have summarised some key questions and considerations below:

Foundations

How well do you understand the strategic opportunities for your business? How are you personally positioned to drive these?

  • The CFO is a strategic partner to the CEO and the finance function sits in the centre of the organisation (it is effectively “the kitchen”)
  • The strategy of all modern businesses will be driven and optimised in some way by AI
  • The CFO should be positioned as the sensible strategic adviser and risk manager. AI implementations will be successful if: the people issues are managed well; the risk issues are understood and well managed; the data and technology is optimised. The CFO plays a unique and central role in all of these areas.

Readiness and current state

How well do you understand the technology itself and your readiness from a broader organisational perspective?

  • Understanding the opportunities and risks, and how to manage these in an organisational system is critical for the CFO
  • Many of the lessons regarding IT implementations and transformations over the past 20 years will be highly relevant

Risk management (beyond governance)

What are the key controls that exist in the entire system (legacy + AI) to mitigate risks? How are you testing these controls to ensure they are working?

  • Managing the risks from a system perspective means the difference between success and failure
  • Many legacy IT risks remain and are often not well understood. New risks that are present with AI systems expand and amplify the risk landscape
  • The CFO can operate a control centre that considers risk and ROI across the whole organisation

ROI

How will costs and ROI be managed going forward? Do you understand the costs you have today?

  • Costs need to be thought of differently and the lessons learned from the transition to cloud are relevant
  • ROI needs to be considered holistically – what is the relevant benchmark and how are you redeploying human effort?

People opportunities and challenges

How is the CFO understanding the work of the CPO in terms of role clarity, change management and workforce planning?

  • Managing the strategic workforce planning, human motivational and fear issues and well as change management and transition issues are complex.

The CFO’s opportunity is to act as the enterprise control centre for AI adoption and transformation. This means owning the business objectives and economics, understanding and managing risk, holistically and collaborating with executive colleagues, particularly the CTO/CIO and the CPO.

To discuss how to get started on this leadership opportunity, contact us at www.ksib.com.au or email Kristin directly at kristin@ksib.com.au.

KSIB