Skip to content

29.9.2026 | Last updated: 29.9.2026

5 min read

Why treasury AI needs guardrails

 

Can AI agents act autonomously in treasury?

The appropriate level of autonomy depends on the control model. In Nomentia’s current design, AI supports assisted and augmented work: it can retrieve information and propose certain actions, while changes require confirmation and module-level approvals remain human-led.

more

 

AI changes the speed of treasury before it changes the responsibility

AI is quickly changing what finance teams expect from software. Instead of opening several screens, setting filters and exporting data, users increasingly expect to ask a question directly and receive an answer in seconds.

That is particularly attractive in treasury. The questions are frequent, the teams are lean and the information is spread across cash positions, payments, bank accounts, entities, deals and other financial processes. A faster route to the answer can remove a significant amount of routine work.

The responsibility behind the answer, however, does not disappear.

Treasury decisions affect real cash, payment execution, liquidity, financial risk and reporting. An AI-generated answer may be used in a funding discussion, an approval decision or a conversation with the CFO. Speed is valuable only when the control model is strong enough to support it.

This is why treasury AI needs guardrails from the beginning.

The risk is rarely one dramatic AI failure

When people discuss AI risk, the conversation often jumps to the most visible concern: hallucination. That matters, but treasury has a broader set of risks to manage.

An answer can be numerically correct and still be wrong for the user because it covers the wrong entities or time period. A user can ask for information they are not authorised to see. A generated calculation can appear precise even when the model has no business calculating it. An AI-supported action can move too quickly from suggestion to execution. A useful answer can become difficult to defend later if nobody can see how the interaction was handled.

None of these risks requires the AI to behave dramatically. They emerge when normal treasury controls are missing from the interaction.

The practical objective is therefore to make AI inherit the discipline already expected from treasury systems.

Permission boundaries must remain permission boundaries

A natural-language interface should make a treasury system easier to use. It should not make the underlying access model easier to bypass.

If a user is authorised to see only specific entities, accounts or modules, an AI answer should operate within exactly that scope. Asking a broader question should not create broader access.

This becomes especially important as AI moves beyond an assistant embedded in one application. Approved AI clients and agents may increasingly interact with financial systems on behalf of users. The same user identity, role-based permissions and entity boundaries need to remain in force regardless of whether the request starts from a screen, a chat interface or an external AI client like Copilot/Claude.

For treasury, convenience cannot become a parallel permission model.

Financial calculations need a deterministic source

Large language models are useful at interpreting questions and composing clear answers. That does not make them the right place to calculate a cash position, aggregate payments or convert a financial amount.

Treasury needs a repeatable calculation basis. The same inputs should produce the same financial result, and the result should come from the system services responsible for the underlying data and logic.

A safer architecture separates those jobs. The AI interprets what the user is asking, selects the appropriate governed service and explains the result. The financial platform retrieves the authorised data and performs the calculation.

This distinction matters because a fluent answer should never be mistaken for a calculation method.

A suggestion and an action need a visible boundary

The value of AI increases when it can do more than retrieve information. It may help draft an administrative change, prepare a report or propose the next step in a workflow.

That is also where governance becomes more important.

A useful guardrail is explicit confirmation before a proposed change is applied. The system should show what is about to happen and give the user a real review moment. The confirmation is not a technical formality; it keeps accountability with the person authorised to make the change.

The same principle applies to existing treasury approvals. AI may help a user understand why a payment is blocked or what requires attention. It should not become an alternative route around segregation of duties, four-eyes controls or module-level approval processes.

Auditability has to follow the interaction

Treasury already expects critical system activity to be traceable. AI interactions should be held to the same standard.

Teams need to know who asked the question, which permissions applied, what system services were called and what action was confirmed. When AI is used through another approved client, the audit trail should not disappear simply because the interface changed.

This is particularly important as AI becomes part of everyday work rather than an occasional experiment. A treasury team may eventually conduct hundreds of small interactions through an AI layer. Governance needs to scale with that volume.

Auditability turns the conversation from a black box into part of the controlled operating environment.

Guardrails also protect against shadow AI

There is another governance problem treasury teams increasingly need to consider: employees already have access to general-purpose AI tools.

When the official treasury environment does not provide a practical AI route, users may create their own. An export is copied into a public chatbot because it is faster than building another report. A payment list is pasted into an assistant for analysis. A user asks an external model to summarise sensitive information because the internal system cannot answer the question conversationally.

The attraction is understandable. The governance problem is equally clear.

A controlled AI channel gives finance teams a safer alternative: the convenience users are seeking, while keeping access, data handling and auditability inside a defined model.

Human review should sit where judgement actually matters

Guardrails should not turn AI into another slow workflow full of unnecessary confirmations.

The objective is to place human judgement at the points where it adds value. Users still need to scope the question, review whether the answer addresses what they intended, decide what the information means and confirm proposed changes. Existing financial approvals remain where policy requires them.

The rest can be accelerated. Intent interpretation, data retrieval, system calculations, answer composition, chart generation and help searches can happen in the background once the user has asked.

Good governance therefore does not mean putting a manual checkpoint after every technical step. It means being precise about which steps require accountability.

Treasury AI is becoming a governance question for CFOs

Nomentia’s Treasury Trends Report 2026 found that surveyed companies see AI as potentially applicable to 93% of organisations’ treasury operations over the coming years. At the same time, a third of treasury teams reported that they lack standardised and consistently enforced controls, and only 15% reported automated controls with real-time monitoring and exception-driven alerts.

These findings highlight an important tension. Interest in AI is moving quickly, while the governance maturity underneath it varies considerably.

For CFOs, the AI discussion therefore needs to cover more than use cases. Leadership should understand what the AI can access, where calculations come from, what it is allowed to change, which decisions remain human-led and how the interaction is recorded.

Those questions determine whether AI becomes a controlled part of treasury or another source of uncertainty.

The best guardrails make AI easier to trust

Treasury professionals do not need AI to appear fearless. They need to know where its boundaries are.

Clear permissions make the access boundary visible. Deterministic platform services provide a reliable source for financial calculations. Explicit confirmation separates a proposed action from an applied change. Existing approvals preserve segregation of duties. Audit trails make the interaction traceable.

These controls do more than reduce risk. They make the capability easier to use because treasury professionals know what the system is responsible for and where their own judgement begins.

AI can then do what it is particularly good at: shorten the distance between a question and the evidence needed to make a decision.