Regulators Across the Globe Aligning on AI Policy
In February, the U.S. Treasury published its AI risk management framework for financial services. Two hundred thirty control objectives aimed at one question: How much should an AI finance system be allowed to do on its own? This month, Singapore’s central bank published a very similar framework.
Two regulators on opposite sides of the world drew the same boundary. That kind of convergence suggests the boundary is structural, and it’s the exact question I recently worked through live on a webinar with Agicap’s Brandon Barnes: not whether AI can run treasury, but how much of it has earned the right to run without a human watching.
The Monetary Authority of Singapore’s new SAFR framework sorts agent activity into three buckets: payments and treasury, wealth advisory, and client engagement. Each gets its own mandate, real-time validation, and audit log. Notice that MAS didn’t ask whether the model is smart enough. It asked what happens when the agent is wrong … and how fast someone can catch it. That’s the same test I’ve been running with clients for a year (minus the government letterhead).
On the call, Brandon asked me the question every CFO eventually asks: How do you decide what AI runs on its own vs. what it should collect and hand to you? One easy framework is to think of it as a simple binary boundary: collect vs. decide.
I have a client that runs more than a dozen QuickBooks Desktop entities (I know, right?), and consolidation used to eat a day every month. Now an agent pulls it, ties out the intercompany eliminations, and hands over a finished workbook.
That’s “collect.”
Nobody’s moving money. If the number’s off, I’ll catch it in the time it takes to open the file.
Payment execution doesn’t get that same leash. An agent can match the invoice to the PO, flag the vendor that doesn’t reconcile against the master file, and stage the wire, but it stops there. Our workflow requires a human to releases it. I think of it the way I’d think about a smart, eager intern in their third year of college: I’ll let them touch almost everything, but I’m not handing them the checkbook.
Three things to incorporate into your next planning meeting:
Score two variables, not one. What happens when the model is wrong, and how fast can a person verify the output? (Note that model quality isn’t a key factor here.)
Consolidation and variance analysis are autonomy’s easiest win. They’re read-heavy, reversible, and reconcilable against known numbers.
Regulators are converging on the same architecture finance teams already use informally. MAS’s three-bucket sort tracks closely to collect, stage, and gate.
Bonus: What The AI-Ready CFO Says About Letting Agents Near the Cash
On the surface, treasury might look like the easiest sell in the whole finance function. The data’s structured, the workflows repeat, and half the vendors in this space already built the tooling. My book, The AI-Ready CFO (Wiley, September 29, 2026), spends a full chapter arguing the opposite.
The book scores any AI-enabled workflow on three dimensions instead of two:
Magnitude: how bad is it if this fails.
Frequency: how many chances does the system get to be wrong.
Recoverability: can you catch and reverse the damage before it lands.
Plot magnitude against frequency, layer recoverability on top, and most finance workflows sort themselves pretty cleanly.
Cash forecasting and liquidity planning are high magnitude and low frequency. The errors are rare, but when one shows up, it’s impactful … and depending on the magnitude, potentially existential. The guidance for that quadrant is specific: model the downside scenarios instead of assuming them away, carry a risk-adjusted contingency reserve in the project cost, and get board sign-off and legal review before anything launches. AI has its place, but only as decision support. The go/no-go call stays with a person who can be held accountable for it.
Segregation of duties is the first control to break when an agent starts touching more than one step. A system that processes a transaction, codes it, and routes it for payment can’t also approve and release that same payment; and automation doesn’t get an exception to that rule because it’s efficient. It makes the violation harder to spot. One agent spanning four steps looks like a clean workflow, until an auditor asks who reviewed what. The fix isn’t clever. Keep processing, approval, and release in separate hands, set conservative thresholds on any auto-approval logic, and test those rules on a schedule to confirm they still work the way they were built.
None of this keeps treasury manual forever. Instead, it tiers oversight by risk. Routine sweeps and low-value intercompany transfers clear on their own and get sampled after-the-fact, anything mid-risk gets dual review, and anything material reaches a person — every time. The CFO’s job is setting those thresholds and making sure the evidence survives the audit.
Which is the theme I keep coming back to across the whole book: AI Recommends, but humans approve.
The AI-Ready CFO publishes September 29 from Wiley.
The pro edition walks through the full scorecard I use with clients, the actual near-miss that changed how I think about who builds these agents, and why the token bill is the wrong thing to be arguing about right now. The full session, Agentic AI in Finance: Where to Automate and Where to Stay in the Loop, ran live with Agicap earlier this month. It’s built for CFOs, controllers, and FP&A leads who already have AI in their stack and are working through how much of it to trust. If you were on the call, you already have some of this. If you weren’t, the recording is here: https://event.agicap.com/webinar/agentic-ai/.
Unlock the full model and templates:


