The finance operating model, across the four faces of the modern CFO (after Deloitte's Four Faces of the CFO framework) — Operator, Steward, Catalyst, Strategist. For each stage the line marks what a bounded agent may do and where a named human must certify — and because finance has no tolerance for hallucination, every stage is held by a two-tier drift lock and a hard exception-to-human gate.
AI takes the collation, matching, reconciliation, continuous monitoring and multi-scenario drafting — high-volume, rule-bound, reversible work, run against verified data. The human keeps the estimate, the certification, the authorisation, the disclosure and the capital decision — anything that commits the firm, forms an opinion, or cannot be unwound. Oversight attaches to the reasoning — the inputs, the policy, the confidence — not just the final signature.
Open-ended generative AI has no place near the ledger. Every autonomous stage below runs inside a two-tier architectural lock — so the agent cannot drift, and cannot act where it is uncertain.
System prompts are bounded by standard operating procedures and a verified context window — approved policy, ledger codes, legal registries. The agent is instructed: if a data point does not match strict GAAP/IFRS parameters, do not infer — flag it. No open-ended reasoning over financial data.
The agent's output is automatically cross-checked by structured code (Python/SQL rule graphs) against live ledger rules before any entry or cash movement. The language model proposes; deterministic logic disposes. Nothing posts on the model's say-so alone.
# On any variance beyond tolerance, unmapped policy, or ambiguity: IF match_confidence < 100% OR variance > tolerance OR policy_unmapped: # do not infer, resolve, or extrapolate — stop and hand to a human OUTPUT STATUS: EXCEPTION_HUMAN_REVIEW_REQUIRED EMIT { txn_id, account, reason, evidence_pointer } ELSE: PASS to deterministic_policy_engine → validate → await named human sign-off
Eight stages across the four faces of the CFO. Open any stage for what the bounded agent does, where the human certifies, the audit-grade system prompt that keeps it from drifting, and a maturity self-check that reads your drift exposure.
Without these, every autonomy level above is borrowed against trust you don't have.
From 2 August 2026 — deferred to 2 December 2027 by the June 2026 Digital Omnibus agreement (final approval pending), EU AI Act Article 14 requires high-risk AI to be designed for effective human oversight. This applies to high-risk (Annex III) systems, while the Article 4 AI-literacy duty already applies to all deployers (since 2 February 2025). This line operationalises it in finance: a bounded prompt and a deterministic check on every stage, a named human on every certification, and a decision receipt behind every autonomous action. You are not selling an AI deployment — you are giving the CFO a blueprint to scale velocity while keeping a named human accountable for every decision that binds the firm.
How the AI Augmentation Line™ methodology maps to Regulation (EU) 2024/1689, and what this tool is and is not.