Home | Resource Center | Articles
Key Takeaways

COSO’s guidance gives organizations a familiar framework for managing the risks and opportunities of generative AI. By integrating AI into existing governance, risk assessment, control and monitoring processes, organizations can support responsible adoption without slowing innovation.

 

Generative AI is rapidly changing how organizations work, from drafting content and summarizing data to supporting customer service, software development, finance, compliance and operational decision-making. But as the use of generative AI expands, so do questions about governance, risk management, accountability, data quality, privacy, cybersecurity, transparency and internal control.

For many organizations, the challenge is not simply whether to use generative AI. It is how to use it responsibly, consistently and in alignment with established risk and control practices. COSO’s updated guidance helps organizations think about generative AI through a familiar lens: governance, risk assessment, control activities, information and communication and monitoring.

 

Purpose of COSO’s Updated Guidance

COSO’s updated guidance is intended to help organizations apply existing COSO principles to the evolving risks and opportunities associated with artificial intelligence, including generative AI. Rather than presenting generative AI as a completely separate risk discipline, COSO encourages organizations to integrate AI considerations into established governance, enterprise risk management and internal control processes.

This includes building on COSO’s publication, Realize the Full Potential of Artificial Intelligence: Applying the COSO Framework and Principles to Help Implement and Scale Artificial Intelligence, as well as COSO’s more recent generative-AI and internal-control guidance. Together, these resources help organizations understand how AI can be implemented and scaled while maintaining appropriate oversight, accountability and control.

At a high level, the guidance is designed to help organizations:

  • Identify where AI and generative AI create new or heightened risks
  • Align AI adoption with strategy, values and risk appetite
  • Establish clear governance and accountability for AI-enabled processes
  • Design practical controls around AI use, outputs, data and third-party tools
  • Monitor AI performance, risk and control effectiveness over time

 

High-Level Takeaways for Organizations

1. Governance: Set the Tone and Define Accountability

Generative AI should be subject to clear governance. Organizations should define who is responsible for approving AI use cases, setting policies, evaluating risks and monitoring performance. Leadership should also communicate expectations for responsible use, including acceptable use, data handling, human oversight and escalation of concerns.

A strong governance model helps ensure generative AI is not adopted in an ad hoc or inconsistent manner. It also supports alignment between AI initiatives and the organization’s broader strategy, values and risk tolerance.

2. Risk Assessment: Understand How AI Changes the Risk Profile

Generative AI can introduce or amplify risks related to inaccurate outputs, bias, confidentiality, intellectual property, cybersecurity, regulatory compliance and overreliance on automated content or recommendations. COSO’s guidance emphasizes the importance of assessing these risks in the context of specific use cases.

Not every AI use case carries the same level of risk. For example, using generative AI to brainstorm internal meeting topics may require different oversight than using it to support customer communications, financial reporting activities or operational decisions. Organizations should evaluate AI risks based on purpose, data sensitivity, business impact and the extent of human review.

 

3. Control Activities: Build Practical Safeguards Into AI Use

Controls should be designed to address the risks associated with generative AI use. These controls do not need to be overly complex, but they should be intentional and fit for purpose.

Examples may include:

  • Approval processes for higher-risk AI use cases
  • Restrictions on entering confidential or sensitive information into public AI tools
  • Human review of AI-generated outputs before use
  • Documentation of key AI-enabled decisions or processes
  • Vendor due diligence for third-party AI tools
  • Access controls and usage guidelines
  • Periodic testing of AI outputs for accuracy, consistency and bias

The key point is that generative AI should be incorporated into the organization’s internal control environment, particularly where AI is used in important business processes.

 

4. Information and Communication: Promote Transparency and Responsible Use

Effective communication is essential to responsible AI adoption. Employees should understand what tools are approved, how those tools may be used, what information should not be entered and when human review is required.

Organizations should also consider how AI use is communicated to customers, business partners, regulators, boards and other stakeholders where appropriate. Transparency can help build trust and reduce confusion about when and how generative AI is being used.

 

5. Monitoring: AI Risk Management Is Not a One-Time Exercise

Generative AI tools evolve quickly. Models change, vendors update functionality, users find new applications and risks may shift over time. As a result, monitoring is a critical part of the control framework.

Organizations should periodically evaluate whether AI-related policies, controls and governance processes remain effective. Monitoring may include reviewing AI usage, tracking exceptions or incidents, reassessing high-risk use cases, evaluating vendor changes and updating training as tools and expectations evolve.

 

6. Responsible Adoption: Balance Innovation with Control

COSO’s guidance does not suggest that organizations should avoid generative AI. Instead, it supports thoughtful adoption, encouraging organizations to pursue the benefits of AI while managing the associated risks.

Responsible adoption means balancing innovation with appropriate oversight. Organizations that establish clear expectations and controls are better positioned to use generative AI confidently, consistently and in a way that supports long-term value creation.

 

What Organizations Should Do Next

Organizations considering or already using generative AI can take several practical steps:

  • Inventory current AI use. Identify where generative AI is already being used across the organization, including informal or department-level use.
  • Define governance roles. Clarify who is responsible for AI strategy, risk assessment, policy setting, approval, and monitoring.
  • Assess risks by use case. Evaluate AI risks based on business purpose, data sensitivity, reliance on outputs, and potential impact.
  • Update policies and controls. Establish practical guidelines for acceptable use, data protection, review requirements, and third-party tools.
  • Train employees. Provide clear, accessible guidance so employees understand how to use generative AI responsibly.
  • Monitor and adapt. Revisit AI risks, controls, and governance practices regularly as tools and use cases evolve.

 

Closing Thoughts

Generative AI presents significant opportunities for innovation, efficiency and insight, but it also requires thoughtful governance and control. COSO’s updated guidance provides a practical way for organizations to apply familiar risk and internal-control principles to a fast-moving technology environment.

By embedding generative AI into existing governance, risk management, and control processes, organizations can move beyond experimentation and toward responsible, scalable adoption.

 

Resources

For readers who would like to explore COSO’s guidance in more detail, consider reviewing the official COSO publications below:

 

Frequently Asked Questions
  • What is COSO’s role in generative AI governance? COSO helps organizations apply established governance, risk management and internal control principles to AI use.
  • Do all AI use cases require the same controls? No. Oversight should reflect the purpose, data sensitivity, business impact and level of human review involved.
  • What controls can support responsible AI use? Common controls include approval processes, data restrictions, human review, vendor due diligence and periodic testing.
  • How often should AI governance practices be reviewed? They should be reviewed regularly as tools, risks, vendors and business uses evolve.