Financial controls rarely fail in steady state. They fail during transformation.
Jacob James Kahn's working thesis is short: financial controls rarely fail in steady state. They fail during transformation. A board that understands why can ask for the evidence that matters while there is still time to act on it.
Why controls are most exposed during system change
In steady state, a key control runs every month. Its owner knows it, its exceptions are familiar, and auditors have tested it more than once. A large system change disturbs all of that at the same time. Processes are redesigned, data is migrated, roles and access are re-provisioned, interfaces are rebuilt, and controls are retired from the old system before their replacements have run through a full close. Each design decision can be reasonable on its own. Together they can quietly take apart the controls the audit committee signs off on every quarter.
The exposure is also uneven in time. It concentrates in the weeks around cutover, when temporary workarounds, elevated access and manual journal entries are most common, and when the people who know the old controls best are busiest with the new system.
What boards typically see, and what they need
Most boards receive program updates as status colors, milestone percentages and budget burn. Those measures describe schedule and cost. They rarely describe whether the numbers will still be right after go-live. What a director needs is closer to the controls themselves:
- A controls inventory that maps each key control from the old process to the new one, with an owner and a date it will be tested.
- A view of temporary access: who holds elevated or emergency access during cutover, why, and when it expires.
- Leading indicators such as reconciliation breaks, defect trends in finance processes, mock-conversion results and open segregation-of-duties conflicts.
AI repeats the pattern
AI follows the same path. When AI tools enter finance, procurement or reporting, they change who, or what, performs a step that a control depends on. The questions are the same ones a board should ask about an ERP program: which decision moves, which control now covers it, and what evidence shows that the control still works.
Questions he would ask as a director
- Which key controls change in this program, and who owns each one through cutover?
- What will the board see before go-live besides a status color?
- Who has temporary or elevated access during the transition, and when does it end?
- Which leading indicators would tell the board the controls are slipping before the quarter closes?
- Where is AI now performing or supporting a control step, and how is that step tested?