Digital employees – that is, AI agents – are making their way into the day-to-day operations of the finance function. The technology is ready to perform defined tasks, but this places new demands on management, responsibility and control. Because if a digital employee is to work across systems and act on behalf of the company, it is not enough to ask what it can do. You also need to know what it is allowed to do, who manages it and how you monitor its work.
Digital employees are closer than many people think
Digital employees have been high on the agenda for some time, but the discussion is changing. The question is no longer simply whether the technology has genuine potential. Increasingly, the focus is on which tasks it can take over and how it can become a responsible part of the company’s operations.
This is particularly relevant in the finance function and other support functions, where a large proportion of the work follows established processes and involves significant amounts of data, documents and system-supported controls. Digital employees can already read, sort, reconcile and formulate information, but they can also be assigned to perform actions across systems.
That last capability is what makes them interesting. At the same time, it makes them a management responsibility.
We can therefore reasonably refer to an AI agent as a digital employee. However, the term only becomes useful when we take it seriously. A digital employee needs a manager, a clear mandate and the access required to perform its task. Its work must be possible to monitor, and there must be a plan for what happens when the task, process or technology changes.
Fundamentally, this is the same discipline that applies when a human becomes part of the organisation. The difference is that a digital employee can work around the clock, repeat an error many times and act across systems without anyone necessarily seeing it happen.
Know the difference between automation and an agent
The term AI agent is currently being used to describe very different types of solutions. It is therefore important to understand what you are actually buying.
A chatbot answers questions. An assistant can also find information in the company’s own data. Traditional automation follows a sequence that people have defined in advance. An AI agent, on the other hand, can assess for itself which steps need to be taken to achieve a particular goal.
The crucial difference can be summarised in one question: Who determines the sequence of actions?
When the company itself has defined the sequence, we generally have an automated workflow. When the solution can plan for itself, choose tools and adapt its approach along the way, we are moving closer to an agent.
This is more than a technical distinction. In a fixed workflow, you know the possible routes through the process and can test them systematically. An agent may choose different routes from case to case. As a result, control cannot consist solely of testing a predefined process. Instead, you must set clear boundaries for which data the agent can access, which actions it can perform and when a human must approve the next step.
The finance function actually has a good starting point here. Access management, segregation of duties, monetary thresholds, approval hierarchies and audit trails are all well-established disciplines. The task is to apply them to a new type of actor.
Do you want your digital employees to stand up to an audit?
We built the platform we were missing ourselves and use it in Basico’s own finance function.
It is called Agentsico and gives digital employees a unique identity, defined permissions and a documented record of their work. This makes it possible to put agents into operation as a controlled part of the organisation rather than as isolated experiments.
Learn more on the Agentsico website.
Start where the process is already known
Although the market is talking extensively about autonomous agents, the most obvious value today lies in more clearly defined tasks.
This is particularly true of processes where the sequence is known, the data foundation is reasonably stable and the organisation already knows how exceptions should be handled. In the finance function, examples could include parts of procure-to-pay, order-to-cash, reconciliations, control documentation and the preparation of management reporting.
The digital employee can handle a large part of the practical work: reading documents, finding information, comparing data, assessing a case and preparing a proposal. When a case requires an important decision, or when there is significant uncertainty, it is passed on to a human for approval.
In this way, the company can use AI to get more work done without relinquishing human control. The digital employee does not always need to make the right decision on its own. It needs to be able to perform the work it is good at and know when a human should take over.
An instruction is not the same as a control
In the summer of 2025, an AI-based coding agent at the development platform Replit deleted data from SaaStr’s production database. This happened even though the agent had been instructed not to modify the production environment during an ongoing code freeze. Afterwards, the agent also provided misleading information about the incident and created fictitious data.
The story is striking, but its most important lesson is not that AI can behave unpredictably. From an auditor’s perspective, there were three more familiar problems: the agent’s access extended beyond the scope of its task, a destructive action did not require separate approval, and the agent’s own explanation was not sufficient, independent documentation of what had happened.
In other words, the only safeguard against the action was a written instruction.
An instruction is important, but it is not a technical control. If an action can have material consequences, the limitation should, as far as possible, be embedded in permissions, system configuration and approval mechanisms – not only in the message the agent has received.
Small uncertainties can lead to unstable operations
An agent that makes the right choice in 95% of cases at each individual step may initially sound reliable. But if a task consists of 20 steps and, for the sake of simplicity, the accuracy at each step is assumed to be independent, the probability of a completely error-free process is approximately 36%. The calculation is a simplification, but the point is important: Small uncertainties can grow when a task consists of many interdependent actions.
Therefore, do not only ask whether the agent can perform the task. Also ask:
How many actions does the process consist of?
Which actions could have material consequences?
How is an error detected?
Can the process be stopped and resumed?
When does a human take over?
Hire the digital employee with a clear mandate
When a new controller starts, they are not given access to every system or the ability to post, approve and pay the same transaction. There is a manager, an area of responsibility and an expectation of continuous follow-up.
The same principles should apply to a digital employee:
One person must be responsible for the agent and follow up on its work.
The tasks must be clearly described, including what the agent is not allowed to do.
The agent’s access must follow the principle of least privilege.
Actions with material consequences must be approved by a human.
It must be possible to see what the agent has done so that its work can be reviewed afterwards.
Access rights and connections to other systems must be removable when they are no longer necessary.
This is not only a matter of risk management. A clear mandate also makes it easier to measure whether the digital employee actually creates value. When the task is clearly defined, you can monitor quality, processing time, the number of exceptions and the need for human intervention. This makes it possible to improve the solution on an informed basis rather than assessing it on the basis of a convincing demonstration.
The company remains responsible
In 2024, Air Canada was ordered to compensate a customer who had acted on incorrect information from the company’s chatbot. Among other things, the airline argued that the chatbot was responsible for its own statements, but the Civil Resolution Tribunal of British Columbia rejected the argument that the company could distance itself from information provided by its own solution. The case concerned a chatbot rather than an agent capable of taking action, but the principle is relevant: a company cannot simply assign responsibility to the technology.
Read about the decision at the American Bar Association or read the decision itself in Moffatt v. Air Canada.
The technology is ready, but the organisation must be ready too
Digital employees will become a significant capability in support functions. Not as a complete replacement for professional employees, but as a new way of performing defined, data-intensive and repetitive tasks.
For the CFO, the task is therefore not to wait for the technology to become error-free. It probably never will. The task is to create the framework that makes it possible to use the technology in a way that the business, the auditors and the employees can all trust.
Start with a known process: Give the digital employee a defined mandate, the minimum necessary access and a named manager. Ensure that material actions require approval and that the work leaves a usable audit trail. Only expand the mandate once experience supports doing so. Then you have not merely bought another piece of software. You have added a new capability to the organisation and expanded your control environment so that it can accommodate it.
Six questions to ask before hiring a digital employee
Who is the immediate manager? Who defines the mandate, monitors the results and intervenes when the agent makes a mistake?
What does the job description say? Which tasks may the agent perform, and which are explicitly outside its mandate?
Which keys will it be given? Does the agent have the minimum necessary permissions, or simply the access rights that were easiest to establish?
What applies during the probationary period? For how long will you check all, or a significant proportion, of the results before giving the agent greater freedom to act?
How will you follow up? Can you see which data the agent used, which actions it performed and which approvals it obtained?
What happens on the day it leaves the organisation? Who closes access rights, integrations and scheduled runs when the process changes or the agent is taken out of service?
If you cannot answer the first and the last question, you are probably not ready to give the agent an independent mandate.
Mathias Kop Balsløw
Partner, Chief Information & Technology Officer
Where should you start with AI?
The first application must both create value and work in the reality in which your employees operate. We help identify the right process, assess the foundation and design a digital employee with clearly defined tasks, permissions and controls.