Guest Contributor
Michael Rasmussen
CEO, GRC 20/20 Research
Editor’s Note: This guest article by Michael Rasmussen expands on themes discussed during MindBridge’s webinar, Building Resilient Financial Risk Oversight in an Era of Constant Change.
The Pace of Financial Risk Has Changed
Financial risk does not wait patiently for the end of the month, the completion of the quarter, or the next scheduled audit. Transactions are created, approved, adjusted, reversed, reconciled, reclassified, accrued, paid, and reported continuously. Business models change, supply chains shift, third parties alter their behavior, employees adopt new tools, regulations evolve, and artificial intelligence becomes embedded in more financial processes. Finance is expected to close faster, explain faster, assure faster, and provide executives, boards, investors, and regulators with greater confidence in an environment that is moving continuously.
Yet much of financial oversight is still designed around periodic activity. Organizations perform monthly and quarterly reviews, test samples of transactions, gather evidence for annual control assessments, and rely on spreadsheets and disconnected systems to document what happened. These practices developed for understandable reasons. Data was difficult to access, computing capacity was limited, and reviewing entire populations of financial activity was impractical. Sampling was not a failure of imagination; it was a rational response to the tools and resources available at the time.
The environment has changed, and financial oversight has to change with it.
That was the central argument of my webinar, Building Resilient Financial Risk Oversight in an Era of Constant Change, hosted by MindBridge. Periodic review, traditional audit, and sample-based testing remain important, but they are no longer sufficient on their own. Financial oversight must move closer to the pace of the business. It must become more continuous, connected, explainable, adaptive, and integrated with action.
This is not simply a technology discussion. It is a governance discussion, a risk discussion, a compliance and assurance discussion, and ultimately a discussion about trust . . .
- Can the organization trust the numbers?
- Can it trust the controls and processes that produced those numbers?
- Can it trust the artificial intelligence and automated systems increasingly involved in financial activity?
- Can it demonstrate that exceptions are not only detected, but understood, investigated, resolved, and used to improve the control environment?
These are the questions that define resilient financial oversight.
The Financial Risk Environment Has Outgrown Periodic Assurance
Finance operates today in the middle of a storm of interconnected pressures. Regulatory scrutiny continues to expand, disclosure expectations are becoming more demanding, and boards and audit committees expect clearer evidence that financial controls are operating effectively. At the same time, financial processes are increasingly digital, distributed, automated, and dependent on data that resides across ERP platforms, procurement systems, payment applications, subledgers, HR platforms, operational systems, data lakes, and spreadsheets.
Fraud and financial crime risks are evolving within the same environment. Duplicate payments, vendor manipulation, unauthorized journal entries, expense abuse, payroll anomalies, revenue manipulation, procurement irregularities, and payment fraud can hide inside enormous volumes of legitimate activity. A periodic review may identify one instance, but it may not reveal the wider behavioral pattern, the relationship between anomalies, or the systemic weakness that allowed the activity to occur.
Artificial intelligence adds another layer of opportunity and uncertainty. AI can accelerate reconciliations, forecasting, planning, transaction analysis, audit testing, policy interpretation, fraud detection, and reporting. However, it also raises questions about data quality, explainability, model drift, hallucination, shadow AI, and overreliance on automated outputs. The more autonomous financial processes become, the more important it is that oversight evolves at the same pace.
The problem is not a lack of diligence among auditors, controllers, finance professionals, or risk teams. The problem is that many oversight models were designed for a slower and less interconnected operating environment. Financial activity now moves continuously, while assurance often continues to operate in periodic cycles. The gap between those two realities is where risks, control failures, errors, and fraud can remain undetected.
Financial Risk Cannot Be Understood in Isolation
One of the most important themes in the webinar was the systemic nature of financial risk. Financial issues rarely begin and end within a single department, system, control, or transaction. They move through the organization, often crossing multiple processes and ownership boundaries before becoming visible in financial reporting.
- A revenue-recognition issue may begin in sales or contract negotiation, move into order management, affect billing and collections, distort forecasting, and eventually become a financial-reporting problem.
- A vendor issue may begin during onboarding, pass through procurement and invoice processing, produce unusual or duplicate payments, and create fraud, sanctions, tax, compliance, or audit exposure.
- A payroll anomaly may involve access management, employee records, time reporting, approval workflows, and payment execution.
The organization may divide responsibility for these activities among finance, internal audit, risk, compliance, shared services, information technology, and business process owners. The risk itself does not respect those organizational boundaries.
This is why fragmented oversight produces fragmented confidence. One team may identify a control failure without understanding the data problem behind it. Another may document an audit finding but fail to see the recurring operational behavior that caused it. A remediation action may close the finding in a system while doing little to prevent the issue from happening again. A transaction may appear ordinary when viewed in isolation but become significant when connected to a pattern across users, accounts, vendors, business units, or time periods.
Resilient financial oversight requires the organization to connect the strands. Financial data, operational data, systems, processes, risks, controls, policies, ownership, investigations, remediation, and assurance evidence all have to be understood in relationship to one another. Without that context, organizations see transactions but miss patterns, document controls but miss weakness, and close issues without necessarily reducing risk.
Risk Is Our Business
Business is the undertaking of risk for reward (Judge Mervyn King, South Africa). Organizations take risk when they enter markets, launch products, extend credit, acquire businesses, adopt new systems, restructure operations, automate processes, or deploy artificial intelligence. Risk is not the opposite of business success; it is inherent in the pursuit of business objectives.
This is why I often return to Captain Kirk’s statement in the original Star Trek episode that inspired the name of my Risk Is Our Business Podcast: “Risk is our business.” Every organization is, in a sense, a starship of risk. It is pursuing objectives in an uncertain environment with limited resources, incomplete information, changing conditions, and consequences for getting decisions wrong.
The objective of financial risk oversight is not to eliminate risk. That would be neither possible nor desirable. The objective is to ensure that the organization takes the right risks, within the right boundaries, supported by the right controls, visibility, accountability, and evidence.
Weak financial oversight does not stop the organization from taking risk. It simply means the organization may take risk blindly. Control gaps remain hidden, unusual behavior goes undetected, emerging patterns are overlooked, and problems are often discovered only after they become misstatements, restatements, fraud investigations, regulatory findings, audit surprises, losses, or reputational damage.
Strong oversight does not have to slow the business down. Properly designed, it gives the business the confidence to move forward. It allows leadership to understand where risk is acceptable, where controls are required, where exceptions need attention, and where the organization may be operating outside its intended boundaries.
Oversight is not a brake on performance. It is a navigation system for performance.
Moving from Rearview Reporting to Forward-Looking Oversight
Finance has always had a strong rearview-mirror function. It records what happened, closes the books, reconciles accounts, reports results, and supports audits. These activities remain essential, and nothing in the move toward continuous monitoring diminishes their importance.
However, no one can drive safely using only the rearview mirror.
Many financial risks begin developing before they become visible in final reports. Duplicate payments occur before month-end review. Revenue anomalies emerge before the close. Manual journal-entry risks exist before an auditor selects a sample. Vendor concentration and procurement problems develop before they appear as material financial concerns. Expense-policy violations accumulate before a periodic review identifies the trend. Control failures can sit inside transaction flows for weeks or months before they become visible at the financial-statement level.
Rearview reporting explains what happened. Forward-looking oversight helps the organization understand what is happening now, what is changing, where unusual behavior is developing, and where action may be required before an issue becomes material.
That requires a different set of capabilities working together:
- Connected financial and operational data across systems and processes
- Clearly defined risk indicators, control expectations, and business rules
- Analytics capable of identifying both known issues and unknown anomalies
- Explainable outputs that show why an activity was flagged
- Workflows that route exceptions to the appropriate owners
- Evidence demonstrating what was investigated, decided, and resolved
- Feedback mechanisms that improve controls and monitoring over time
This progression takes the organization from reporting to monitoring, from monitoring to assurance, and from assurance to adaptive oversight.
Finance GRC: Connecting Performance, Risk, Controls, and Integrity
I created the GRC acronym in February 2002 while I was at Forrester Research. Since then, GRC has often been discussed as though it were one generic category, but there are distinct contexts in which governance, risk management, and compliance must be applied. There is IT GRC, third-party GRC, supply-chain GRC, data GRC, and, central to this discussion, finance GRC.
I define finance GRC (adapting the OCEG definition) as the capability that enables the organization to reliably achieve its financial objectives, address uncertainty that can affect those objectives, and act with integrity in the stewardship of financial resources and reporting obligations.
Each part of that definition matters . . .
- Governance is about reliably achieving financial objectives. It includes the ability to close accurately, report confidently, manage cash, protect margin, prevent leakage, support performance decisions, and provide trustworthy financial information to leadership and the board.
- Risk management is about addressing uncertainty that can affect those objectives. ISO 31000 defines risk as the effect of uncertainty on objectives. In finance, that uncertainty may arise from error, fraud, process breakdowns, system changes, poor data quality, regulatory developments, business disruption, third-party activity, or AI-enabled processes that introduce new complexity.
- Compliance and integrity are about acting responsibly in the stewardship of financial resources and reporting obligations. This includes transparency, accountability, control discipline, evidence, defensibility, and the ability to stand behind both the numbers and the processes that produced them.
Finance GRC should therefore not be reduced to Sarbanes-Oxley compliance, control documentation, or audit support. Those are important components, but finance GRC is broader. It connects financial performance, risk, internal controls, compliance, assurance, and integrity into a common operating discipline.
Finance as Both a Performance Engine and a Trust Engine
One of the mistakes organizations make is separating financial performance from financial control. Performance teams focus on growth, efficiency, margin, and speed. Control teams focus on compliance, evidence, and assurance. Internal audit focuses on independent assessment, while risk teams focus on uncertainty and exposure.
In actual financial operations, these objectives are interconnected . . .
- A duplicate payment is a control issue, but it is also a performance issue and potentially a fraud issue.
- A revenue-recognition anomaly may be a financial-reporting concern, but it may also expose a failure in contracting, policy adherence, system configuration, or management behavior.
- Weak journal-entry approvals create control risk, audit risk, fraud exposure, and potential financial-statement risk.
- Reconciliation failures may reveal more than an accounting error; they may expose underlying process, system, or data weaknesses.
Finance GRC is therefore both a performance engine and a trust engine . . .
- As a performance engine, it can identify revenue leakage, pricing problems, margin erosion, duplicate payments, missed discounts, inefficient close activity, late collections, and unnecessary manual effort.
- As a trust engine, it provides confidence that controls are operating, financial data is complete and accurate, exceptions are investigated, evidence is defensible, and reporting obligations are met.
These are not opposing goals. Stronger financial integrity can improve business performance, while stronger business insight can improve the design and effectiveness of controls. When organizations connect the two, finance becomes more than a recorder of history. It becomes an active contributor to performance, resilience, and strategic decision-making.
AI Is Both Part of the Risk and Part of the Solution
Artificial intelligence is not simply another feature being added to financial software. It is beginning to reshape how work is performed, how decisions are supported, how transactions are evaluated, how exceptions are identified, and how controls are monitored.
AI creates genuine opportunity. It can analyze large volumes of activity, identify patterns that humans would struggle to detect, reduce manual effort, evaluate entire populations of transactions, and focus professional attention on the areas most likely to matter. It can help finance move from reactive reporting toward more proactive insight.
At the same time, AI creates risk. Outputs may be incorrect, opaque, biased, or based on incomplete data. Models may drift over time. Employees may rely on unapproved tools. Automated recommendations may influence decisions that users do not fully understand. A poorly governed AI-enabled process can accelerate error just as easily as it accelerates efficiency.
This is why AI in finance is fundamentally a governance issue.
I used a metaphor in the webinar drawn from my friend Tony Martin-Vegue’s book, From Heatmaps to Histograms. Organizations often want AI to behave like Data from Star Trek: The Next Generation: logical, precise, transparent, reliable, loyal, and aligned with the mission. In practice, generative AI can sometimes behave more like Captain Jack Sparrow from Pirates of the Caribbean: creative, clever, surprising, occasionally brilliant, sometimes lucky, and not always explainable.
Jack Sparrow may get you out of trouble, but you would not give him unsupervised authority over financial reporting.
The mature response is neither blind trust nor blanket rejection. It is governed adoption. Organizations need to understand where AI is being used, which decisions it influences, what data it relies on, how its outputs are validated, how exceptions are monitored, and where human judgment remains mandatory.
The principle I emphasized throughout the webinar is that AI should not replace financial judgment. It should expand the field of vision so finance, audit, controls, and risk professionals can apply their judgment more effectively.
Explainability Turns Alerts into Assurance
Advanced analytics and AI can dramatically increase visibility, but visibility alone does not create confidence. A system may flag a transaction as unusual, but that alert has limited value if no one can explain why it was flagged, what risk it represents, which control is relevant, or what action should follow.
In financial oversight, explainability is not optional.
A meaningful exception should be traceable through several layers. The organization should be able to see the transaction or pattern that was flagged, the reason it was identified, the risk indicators or control logic that were triggered, the supporting data, the relevant control context, the recommended investigation path, and the final evidence showing how the matter was resolved.
A black-box alert creates confusion. An explainable alert creates the basis for investigation. A documented response creates assurance evidence.
This is particularly important as AI becomes involved in higher-risk financial activities. It is one thing to use AI to summarize a document or draft a narrative. It is another to rely on it for journal-entry analysis, fraud detection, transaction monitoring, control testing, or decisions that could materially affect financial integrity. The higher the potential impact, the stronger the requirements for validation, transparency, evidence, and human oversight.
From Sampling to Full-Population Monitoring
Sampling continues to have a valid role in audit and financial oversight, but it inevitably leaves blind spots. A sample illuminates a small portion of the ledger. It may identify issues within the area reviewed, but it cannot tell the organization what is occurring everywhere else. Risks outside the sample may remain invisible, and behavioral patterns that only emerge across an entire population may be missed.
Full-population monitoring changes the nature of oversight. It does not mean that people manually review every transaction. It means that every relevant transaction can be evaluated against risk indicators, business rules, control logic, statistical models, behavioral expectations, and known anomaly scenarios.
Professional judgment is then directed toward prioritized exceptions rather than consumed by manually searching for them.
This is an important distinction. Full-population analytics does not replace the auditor, controller, or finance professional. It strengthens their ability to focus on the transactions and patterns most likely to matter. It expands coverage while preserving the essential role of human judgment, skepticism, investigation, and context.
The objective is not to generate more alerts. It is to produce better signals.
Homeostatic Finance: Sensing, Responding, and Adapting
The metaphor I find most useful for the future of financial oversight is homeostasis. The human body does not check its temperature once a year, monitor blood oxygen once a quarter, or assess blood pressure only during an annual examination. It continuously senses, monitors, responds, and adapts to maintain stability in a changing environment.
Finance needs a similar capability.
Processes such as order-to-cash, procure-to-pay, record-to-report, hire-to-retire, and acquire-to-retire can be thought of as systems within the body. Transactions are signals flowing through those systems. Controls, risk indicators, business rules, statistical models, and behavioral analytics act as sensors.
Some signals are normal. Others represent errors, inefficiencies, unusual behavior, control violations, or fraud. The challenge is not simply to detect activity; it is to interpret what matters. The human body would be unable to function if it treated every heartbeat as an emergency. In the same way, financial oversight becomes unusable if it overwhelms teams with alerts that lack context, prioritization, and ownership.
A homeostatic financial oversight model continuously senses activity, monitors risk, identifies meaningful exceptions, routes them for action, and adapts based on what it learns. Recurring issues should lead to stronger controls. Investigation outcomes should improve models. False positives should be reduced. Emerging patterns should influence risk indicators and oversight priorities.
This is what makes the model resilient. It does not simply recover after something goes wrong. It senses stress earlier, responds more intelligently, and becomes stronger through learning.
GRC 7.0 and the Orchestration of Financial Oversight
I frame the current evolution of GRC technology as GRC 7.0: GRC Orchestrate. In finance, this means moving away from end-of-cycle compliance activity toward embedded financial governance.
Traditional financial governance often occurs after the activity. The organization closes the books, gathers evidence, tests controls, responds to auditors, documents findings, and meets reporting deadlines. That model remains necessary, but it often provides limited visibility into risks while they are developing.
GRC Orchestrate introduces a more active and adaptive model. Financial data, operational data, risks, controls, policies, analytics, investigations, remediation, and evidence are connected within a common architecture. Controls are not simply documented and tested periodically; they are monitored and refined as risks, processes, systems, and transaction patterns change.
I see five defining characteristics of this future model:
- Connected: Finance, audit, risk, compliance, controls, data teams, process owners, and leadership operate from a shared understanding of activity and risk.
- Dynamic: Oversight adapts as systems, processes, regulations, business priorities, and risk conditions change.
- Contextual: Transactions and anomalies are evaluated based on materiality, timing, ownership, account, vendor, customer, approval path, and business context.
- Autonomous but governed: Automation and AI help manage scale and identify signals, while human judgment, accountability, and validation remain central.
- Foresight-driven: Analytics, scenario modeling, and digital twins help organizations anticipate outcomes and act before issues become material.
Digital twins have an important role in this model. A financial digital twin is not simply a visual representation of a process. It is a living model of transactions, systems, controls, relationships, and dependencies. It can help the organization understand how financial activity flows, where controls operate, where exceptions concentrate, where bottlenecks exist, and how changes in systems, regulations, or business processes may affect risk.
This is the movement from static documentation to active orchestration.
The Financial Oversight Command Center
Resilient financial oversight cannot live in isolated dashboards and departmental systems. Finance may see one part of the picture, internal audit another, risk and compliance another, and process owners something else entirely. The organization needs a shared intelligence layer that connects these perspectives.
I describe this as the financial oversight command center.
The command center connects financial process families such as order-to-cash, procure-to-pay, record-to-report, and hire-to-retire with the stakeholders responsible for governance, execution, control, and assurance. It brings together unified data, risk and control mapping, prioritized exceptions, cross-functional collaboration, remediation tracking, assurance evidence, and continuous learning.
The command-center concept reinforces the homeostatic model. Signals enter from across financial processes. They are interpreted, prioritized, assigned, investigated, and resolved. The outcome becomes evidence, and the system learns from the experience.
This is not simply another dashboard. A dashboard may show that something happened. A command center connects the signal to context, ownership, action, evidence, and improvement.
Start Where Pain, Data, and Executive Attention Intersect
Organizations do not need to transform every financial process at once. In fact, attempting to boil the ocean is one of the fastest ways to undermine a continuous-monitoring initiative.
The practical approach is to begin with a focused use case where three conditions intersect: the risk or financial value is significant, the necessary data is available, and there is enough executive attention to support action.
Strong starting points often include manual journal entries, duplicate payments, vendor anomalies, revenue-recognition patterns, reconciliation exceptions, expense irregularities, payroll anomalies, and high-risk close activities. These use cases typically have identifiable risk hypotheses, available data, measurable outcomes, and clear business relevance.
The organization can then progress through a maturity path:
- Crawl: Establish data readiness, define the risk objective, and test a focused pilot.
- Walk: Build repeatable monitoring, investigation, escalation, and evidence workflows.
- Run: Expand continuous assurance across multiple financial processes.
- Orchestrate: Connect adaptive monitoring, AI-enabled insight, digital twins, controls, action, and learning across the financial environment.
The objective on day one is not to build the perfect architecture. It is to prove a repeatable approach, demonstrate value, improve the operating model, and scale with discipline.
Technology Enables; Governance Makes It Reliable
Continuous financial risk monitoring is not merely a technology product. It is an operating model built on people, processes, data, and technology . . .
- People define ownership, judgment, accountability, and escalation.
- Processes determine how exceptions are investigated, remediated, validated, and reported.
- Data provides the completeness, lineage, quality, and context required for reliable analysis.
- Technology supplies the analytics, AI, workflow, evidence, and reporting capabilities needed to operate at scale.
All four pillars are necessary. Technology without governance creates noise. Data without context creates confusion. Monitoring without ownership creates unresolved alerts. Analytics without explainability creates outputs that cannot be defended.
A resilient operating model closes the loop:
- Detect the signal
- Explain why it matters
- Assign it to the right owner
- Investigate the root cause and significance
- Remediate the issue
- Validate that the response was effective
- Learn from the outcome and improve the process
This is the difference between monitoring and assurance. Monitoring sees something. Assurance demonstrates that the organization understood it, acted on it, documented the response, and strengthened the environment.
Continuous Monitoring Strengthens Internal Audit
A question raised during the webinar was whether continuous monitoring replaces internal audit. It does not.
Continuous monitoring can identify patterns, exceptions, control signals, and unusual behavior across much broader populations of activity. Internal audit continues to provide independence, professional skepticism, judgment, root-cause analysis, assurance design, and an enterprise governance perspective.
Rather than replacing internal audit, continuous monitoring allows internal audit to focus on higher-value work. Audit can spend less time searching manually for isolated exceptions and more time understanding systemic risk, assessing control design, challenging management assumptions, evaluating root causes, and advising the audit committee on the effectiveness of the broader assurance environment.
The relationship should therefore be complementary. Continuous monitoring expands visibility and coverage. Internal audit interprets that information through the lens of independence, governance, and professional assurance.
The Questions Boards and Executives Should Be Asking
Boards and executives do not need to understand every algorithm or analytical model, but they do need to ask better questions about the reliability of financial oversight.
They should ask where the organization still relies exclusively on periodic review, which financial processes have the greatest blind spots, and whether management is analyzing full populations where the risk justifies it. They should understand how AI is being used in finance, what decisions it influences, how its outputs are validated, and whether management can explain and defend the resulting alerts.
They should also ask what evidence supports management’s confidence in the numbers . . .
- Are exceptions assigned and investigated?
- Are remediation actions validated?
- Are recurring issues leading to stronger controls?
- Is the organization learning from the signals it detects, or is it repeatedly documenting the same weaknesses?
These questions move the board conversation away from activity and toward assurance. They reveal whether the organization is merely performing control tasks or building a resilient financial oversight capability.
The End State Is Business Confidence
The purpose of finance GRC is not control for the sake of control, compliance for the sake of compliance, or analytics for the sake of analytics. The purpose is business confidence.
It is confidence that the numbers are reliable, that risks are visible, that controls are operating, that exceptions are investigated, that AI-enabled processes are governed, and that evidence is complete and defensible. It is confidence that leadership can make decisions using trustworthy financial information and that the organization can pursue objectives while addressing uncertainty and acting with integrity.
The future of financial oversight will not be defined by how much evidence an organization can gather after the fact. It will be defined by how effectively it can continuously sense, explain, act, and adapt.
Periodic assessments will remain important, but they cannot stand alone. Financial oversight must move closer to the transaction flow and the pace of business. Analytics and AI must expand visibility without becoming black boxes. Full-population monitoring must focus human judgment rather than overwhelm it. Controls and monitoring models must learn from recurring patterns. Finance, audit, risk, compliance, and process owners must operate from a shared intelligence layer rather than disconnected views.
The most mature organizations will not treat finance GRC as an administrative burden. They will recognize it as a strategic capability that protects value, supports performance, reduces surprises, strengthens resilience, and builds trust.
About the Author
Michael Rasmussen is CEO of GRC 20/20 Research and an internationally recognized authority on governance, risk management, and compliance (GRC). Widely known as the “Father of GRC,” he coined the term while at Forrester Research in 2002 and has spent more than three decades advising organizations worldwide on governance, risk, compliance, and assurance.