AI Governance for Treasury Teams
The regulators published the rulebook. Your treasury team is already using AI. Close the gap.
- 01The U.S. Treasury FS AI RMF and the ECB view, through a treasury lens
- 02The 4 adoption stages and the 3 controls every AI use case needs
- 03Treasury-specific PII, sanitization, concentration risk and SOX mapping
- An AI inventory template
- An AI usage log template
- A PII classification guide
- A 30-day action plan
Why now: two regulators, one week
Released with the Cyber Risk Institute, alongside an AI Lexicon. 230 control objectives across the AI lifecycle, an adoption stage questionnaire, and implementation guidance. The first finance-specific AI governance toolkit. It is voluntary guidance, not a binding regulation.
Closer supervisory scrutiny of generative AI in banks, with a focus on third-party dependencies: most GenAI models come from a handful of large, mostly non-EU providers.
The message: document what you are running, who owns it, and what happens when it fails. These texts are aimed at financial institutions, but they are the clearest rulebook available, and corporate treasury can adopt the same logic.
The reality in your treasury department
Pasting bank statement data into a free chatbot to categorize transactions.
PII exposure: IBANs, amounts and counterparty names sent outside your control.
Using an AI assistant to draft hedge recommendations for management.
No audit trail: if the hedge goes wrong, 'AI told me' is not a defense.
Running an AI model against the 13-week forecast to spot errors.
Undocumented model dependency: if the model changes, the process breaks and nobody knows why.
Using Copilot in Excel for board pack data analysis.
Embedded AI in existing tools: invisible to your control matrix.
None of this is documented. None of it shows up in your control matrix. And all of it is happening right now.
The FS AI RMF: four components
A self-assessment that places your organization in one of four stages: Initial, Minimal, Evolving, Embedded.
230 control objectives mapped by adoption stage, covering governance, data, model development, monitoring, third-party risk, fairness and consumer protection, explainability.
The implementation manual: how to run the assessment and prioritize controls for your stage.
Examples of effective controls and evidence: what "good" looks like for each objective.
You do not need all 230 objectives on day one. You need to know which stage you are in and which controls apply to your workflows.
Where is your treasury team?
Pick the description that matches your team today. Everything else follows from this answer.
230 control objectives, through the treasury lens
What the framework's risk areas mean for a treasury team, in questions you can answer.
Who approves AI use in treasury? Who owns the cash flow AI model? Is there a policy for using AI with bank data?
MT940 data quality before AI processing. FX rate source validation. Counterparty data lineage.
Forecast accuracy monitoring. Hedge recommendation validation. Output drift detection.
What happens when the AI misclassifies a payment? Alert thresholds for anomaly detection errors.
ChatGPT, Claude, Copilot: each is a third-party AI dependency. Concentration risk if you rely on one.
A human checkpoint before any AI output goes into a board pack, covenant calculation or payment instruction.
Build your Treasury AI Inventory
The most important step. One row per AI use case in your team. It takes about 30 minutes, and it is the foundation for everything else.
| Treasury workflow | AI tool used | Data sensitivity | Owner | Control status |
|---|---|---|---|---|
| Cash flow forecasting | Claude / ChatGPT | HIGH: actuals, balances | [Name] | No control |
| MT940 parsing | Claude Code | HIGH: IBANs, amounts | [Name] | No control |
| FX hedge analysis | ChatGPT Plus | MEDIUM: exposures | [Name] | No control |
| Board pack narratives | Copilot in PowerPoint | MEDIUM: KPIs | [Name] | Embedded, invisible |
| Supplier payment review | Claude | HIGH: payment details | [Name] | No control |
| Covenant compliance check | ChatGPT | HIGH: financials | [Name] | No control |
| Bank fee analysis | Copilot in Excel | LOW: aggregated | [Name] | Embedded, invisible |
| Intercompany netting | Claude | HIGH: entity data | [Name] | No control |
Every cell marked "No control" is a gap the framework expects you to close. Not a judgment: a to-do list.
TREASURY AI INVENTORY Treasury workflow | AI tool used (+ tier) | Data sensitivity (HIGH/MEDIUM/LOW) | Owner (named person) | Control status Cash flow forecasting | [tool, tier] | HIGH: actuals, balances | [Name] | [No control / Owner only / Owner + checkpoint / Full: owner + checkpoint + evidence] MT940 parsing | [tool, tier] | HIGH: IBANs, amounts | [Name] | [status] FX hedge analysis | [tool, tier] | MEDIUM: exposures | [Name] | [status] Board pack narratives | [tool, tier] | MEDIUM: KPIs | [Name] | [status] Supplier payment review | [tool, tier] | HIGH: payment details | [Name] | [status] Covenant compliance check | [tool, tier] | HIGH: financials | [Name] | [status] Bank fee analysis | [tool, tier] | LOW: aggregated | [Name] | [status] Intercompany netting | [tool, tier] | HIGH: entity data | [Name] | [status] [Your workflow] | [tool, tier] | [sensitivity] | [Name] | [status] Remember embedded AI: Copilot in Excel/PowerPoint/Outlook counts too.
Enterprise vs personal tier: the line you cannot cross
- ✓ SOC 2 Type II compliant
- ✓ Data not used for model training
- ✓ Data processing agreement
- ✓ Audit logs available
- ✓ SSO and access controls
- ✓ Regional data residency options
OK for: IBANs, amounts, counterparty names, financial data, with appropriate controls.
- ✕ May use data for model training
- ✕ No enterprise data agreements
- ✕ No audit logs or access controls
- ✕ Personal account = personal liability
- ✕ No data residency guarantees
NEVER for: IBANs, payment data, counterparty names, pre-release financials, board materials.
If your analyst pastes an IBAN into a free chatbot, that data is outside your control framework. Full stop. This is not paranoia; it is knowing where your data goes and having a contractual basis for it.
Three controls for every AI use case. Not 50. Three.
A specific person, not 'the team', accountable for this AI use case. They approve inputs, validate outputs and respond when it breaks.
ExampleMaria, Senior Treasury Analyst, owns the 13-week cash flow AI forecast. She validates every weekly output against the trial balance before the Thursday liquidity meeting.
Every AI output that touches a deliverable passes a human check against source data before it goes anywhere.
ExampleNo AI-generated variance commentary goes into the board pack without reconciliation against GL actuals. The Treasurer signs off the final version.
A log of what went in, what came out, which model was used and who reviewed it. If an auditor asks, the answer exists in a system, not in someone's memory.
ExampleEach AI-assisted FX hedge recommendation is logged with the prompt, model version, exposure data, output, analyst review notes and Treasurer approval.
Apply the three controls to every row in your inventory. That moves you from Initial toward Minimal in a week.
Treasury-specific PII: what you cannot feed to AI
Replace real values before pasting. IBAN DE89… becomes [IBAN_001]; Company XYZ becomes Company A. Amounts stay real: the AI needs them.
+ Simple, no tools
− Slow, error-prone, does not scale
Initial / Minimal
Tools such as Microsoft Presidio, regex patterns or a master data lookup detect and replace PII before AI processing.
+ Scalable, consistent, auditable
− Needs setup and maintenance
Evolving
A SOC 2 compliant enterprise AI with a data processing agreement: encrypted in transit, not used for training, contractual guarantees.
+ Most data can stay un-redacted
− Cost, vendor dependency
Evolving / Embedded
Third-party concentration risk
The ECB flagged it explicitly: most GenAI tools trace back to a handful of foundation model providers.
100% of your treasury AI runs on one provider. It changes pricing or terms. Now what?
→ Test critical workflows on 2+ models. Module 6 gives you the method.
Providers retire model versions on their own schedule. Your prompts behave differently, or stop working.
→ Document model versions. Retest outputs when models update. Keep your prompt library current.
The AI tool is down during your Thursday liquidity call. No forecast.
→ Keep a manual fallback for critical workflows. AI augments, never replaces.
The provider changes its data retention policy. Your historical prompts are now stored differently.
→ Review terms quarterly. A DPA overrides standard terms. Legal sign-off on changes.
Start a usage log today
Before you build a governance framework, start a log: one row per AI use, about 30 seconds each. When governance formalizes, you go from "shadow user" to "documented champion". This log is the raw material for your inventory.
TREASURY AI USAGE LOG Date | AI tool + tier | Workflow | Data in | Output used for | Reviewed by 03 Mar | Claude (business tier) | 13-week forecast | Weekly actuals (sanitized) | Liquidity meeting | Maria T. 03 Mar | ChatGPT Enterprise | FX hedge recommendation | Net exposures by currency | Treasury memo | John S. 04 Mar | Copilot in Excel | Fee analysis | Bank fee statement | Cost report | Ana P. 05 Mar | Claude (business tier) | Board pack draft | KPI summary (no PII) | CFO review | Director 06 Mar | Free chatbot | General research | Public FX data only | Internal note | Self (no PII) [date] | [tool + tier] | [workflow] | [data in] | [used for] | [reviewer]
For SOX-compliant organizations: mapping AI to ICFR
If you already run SOX 404 and ICFR documentation, you have most of the scaffolding. Add three elements per AI use case to what you already have.
| AI use case | Existing SOX controls | + AI-specific controls |
|---|---|---|
| Cash flow forecast (AI-assisted) | Monthly variance review · CFO sign-off · TB reconciliation | Named owner for the AI model · Checkpoint: forecast vs actuals · Evidence: prompt log + model version + output + review |
| FX hedge recommendation | Hedge policy compliance · Board-approved limits · MTM valuations | Named owner for the AI hedge analysis · Checkpoint: recommendation vs policy · Evidence: exposure data + AI output + approval |
| Board pack narratives | Director review · CFO approval · Audit committee access | Named owner for the AI draft · Checkpoint: narrative vs source data · Evidence: AI draft + manual edits + final version |
| Payment anomaly detection | 4-eyes approval · Dual authorization · Bank confirmation | Named owner for the AI flagging · Checkpoint: every flagged item reviewed · Evidence: transaction log + AI flags + resolution |
Same pattern every time: existing controls plus owner, checkpoint and evidence.
Your 30-day treasury AI governance plan
Determine your adoption stage. Build the Treasury AI Inventory. Identify enterprise vs personal tier usage.
Map each use case to PII sensitivity. Identify which workflows touch SOX-relevant processes. Flag every "No control" item.
Assign a named owner for each use case. Define the human review checkpoint per workflow. Start the usage log for the team.
Set evidence trail requirements per use case. Draft the AI section of your treasury policy (Module 4). Present findings to the CFO or Treasurer with a remediation timeline.
By day 30, you have a documented, defensible AI governance posture. Not perfect. Documented. That is the difference between "we are working on it" and "here is what we have".
The regulators published the rulebook. Your team is already using AI. Close the gap.
Seven modules, from where AI works in treasury to prompts, workflows, tools, model evaluation and governance.
The only thing left is execution. Start this week. Not next quarter.
Optional: the Advanced track (Modules 8–10). Light, fully guided technical work: prepare treasury data with Python and SQL, build a 13-week forecast model, and keep it running in production. AI writes most of the code; every script is tested.
References: U.S. Department of the Treasury, Financial Services AI Risk Management Framework (19 Feb 2026); ECB Banking Supervision, "Technology is neutral, governance is not: AI adoption in the banking sector" (24 Feb 2026); NIST AI RMF; Cyber Risk Institute.
Built by a treasurer, for treasurers. · treasuryease.com