Skip to content
AIAC AI ASSURANCE COUNCIL

AI in finance and accounting

IESBA Code R220.8 — Using the Output of Technology

R220.8 has been mandatory since 15 December 2024 and binds every professional accountant in business who uses the output of technology. It answers the question finance teams keep asking about AI in the close — and it never once says “artificial intelligence”. It says technology, which is why almost nobody has found it.

§ 1 — Who it binds

Who this binds, and where

Accountant in business

Any professional accountant in business who intends to use the output of technology in preparing or presenting information: a controller running an AI reconciliation tool, an FP&A lead generating a forecast, a shared-services team using automated coding. The Code takes effect through each IFAC member body that has adopted it, so read it as adopted in your jurisdiction. US CPAs are governed by a separate instrument, whose contents this page does not characterise.

§ 2 — In practice

A judgement, not a checklist

Section 220 governs the preparation and presentation of information, and R220.8 sits inside it as a mandatory provision — an “R” paragraph rather than application material. Its operative words are that the accountant “shall exercise professional judgement to determine the appropriate steps to take” when using the output of technology, whether that technology was developed internally or supplied by a third party. Two things follow that summaries routinely lose. The duty is triggered by the *intention* to use the output, so it bites before the figure reaches a working paper rather than at review. And what it requires is a judgement about which steps this particular use needs, not the performance of a fixed verification procedure — a harder duty to discharge, and a much easier one to leave no trace of.

The application material at 220.8 A1 sets out eight factors bearing on that judgement, and they read better as the questions an assessor will ask than as steps to perform. In our own words: what the technology is being asked to do; how heavily the output will be relied on; whether the accountant can understand, use and explain it, or reach someone who can; whether it has been tested and evaluated for this purpose; prior experience of that use and how generally accepted it is; the employing organisation’s oversight of the technology across its lifecycle; the controls over who may access and use it; and the appropriateness of the inputs, including the data and the decisions people take while using it. That last factor is the one that reaches prompting. A prompt is an input and a human decision taken during use, so the wording already covers the part of generative practice that most finance functions treat as personal style — the same territory Article 14 approaches from the other end, by asking what the person overseeing a system has been equipped to do.

The reason a mandatory ethics provision on this exact question has stayed invisible is stateable in one line: R220.8 never uses the words “artificial intelligence”. It says “technology”, which is the right drafting choice for a code that has to survive the next tool as well as this one, and it is also why the provision does not surface for the searches it answers. Someone asking whether they may let a model draft the flux commentary is served by firm blogs and vendor material, almost none of which cites the paragraph that governs the question. The same shape of gap sits under Standard 14.1 on the assurance side, where the governing text is about evidence rather than about AI and is missed for the same reason.

R220.8 is not free-standing: it discharges into R220.4, the mandatory provision on how information must be prepared and presented, which supplies the standard the output has to meet. That structure decides what the judgement is *for*. The question is never whether a tool is good, but whether this output, used this way, lets the accountant meet a duty already owed — so the answer moves with materiality, audience and reversibility rather than with the technology. The Code states the duty a second time at R320.11, for the accountant in public practice, and the two are deliberately not identical. Read in summary, R220.8 looks like general good practice. Read in place, it is what makes an unexamined reliance on a model a breach of Part 2 rather than an operational lapse.

§ 3 — What a weak answer looks like

The AI use policy as the judgement

The AI use policy produced as the judgement. One page circulated to the finance function — check outputs before use, keep sensitive data out, remember the tool is not a substitute for professional scepticism — with a completion log showing everyone read it. It is a perfectly sound policy and it discharges nothing, because the provision attaches to a person using an output on an occasion. The policy reads identically for a summarised board paper and a fair-value estimate, and the paragraph exists precisely because those two uses need different steps.

§ 4 — What discharges it

What the judgement has to leave behind

The artefacts an assessor asks to see, and what makes each one sufficient rather than merely present.

  1. 01

    A technology-use judgement record, one per material use

    Names the tool and version, what it produced, which steps the accountant decided this use needed, and the reasoning. Without a contemporaneous note, nothing separates a considered decision from an unexamined one.

  2. 02

    Fitness-for-purpose evidence for the task actually performed

    Supplier testing or internal evaluation covering that task, not the product in general. Where neither exists, the memorandum recording the absence is itself what an assessor asks to see.

  3. 03

    A named route to someone who can explain the output

    Who inside the employing organisation understands how this tool produces what it produces, and whether that person was reached before reliance. A supplier support desk is not that person.

  4. 04

    The input record: data supplied, configuration and prompts

    Kept with the deliverable rather than in a chat history nobody can retrieve. Inputs and the human decisions taken during use bear directly on the judgement, so they belong in the file with it.

  5. 05

    Evidence of lifecycle oversight and access control

    Who approved the tool’s introduction, who may operate it, and what governs it when it changes. Two of the eight factors turn on the organisation’s arrangements rather than on any individual’s care.

§ 5 — Worked example

Worked example — the accrual nobody can explain

A group financial controller uses a licensed AI assistant that reads the ledger, drafts the month-end variance commentary, and proposes an accrual for an open supplier dispute. The assistant is configured by the group’s finance systems team; the model behind it belongs to a vendor and is updated on the vendor’s schedule. The controller reads the commentary, agrees the two largest movements back to the trial balance, and files it. The accrual is posted as drafted, because the amount is immaterial to the group.

Has the controller discharged R220.8?

Partly, and the gap is the record rather than the work. Agreeing the two largest movements is a real step and a proportionate one, so a judgement was in fact made — but nothing in the file says so, and the provision requires the judgement, not merely a good outcome. The accrual is the harder half. Immateriality is a reason to take fewer steps; it is not a reason to take none, and the factors that bite here are the ones the controller cannot answer. Nobody in the function can explain how the assistant reached that estimate. Nobody has asked the systems team whether it was evaluated for estimation work rather than for summarising. A vendor update inside the period means the commentary and the accrual may not have come from the same system at all. None of this makes the posting wrong. It makes the reliance unevidenced, which is the state the file will be in if the dispute later settles at a materially different number.

§ 6 — Elsewhere

The same output under other duties

Where another instrument addresses the same obligation. These are correspondences, not comparisons — the Council does not rank one framework against another.

  • EU AI Act

    Article 14 requires a provider to build a high-risk system so that people can oversee it, and reaches the deployer’s assignment of that role. R220.8 sits on the person doing the overseeing and asks what is owed before relying on what they see.

  • Auditing AI systems

    Standard 14.1 governs what an auditor may conclude from what an auditor holds. R220.8 governs what the preparer decided before relying on the output, which is frequently the file the auditor is later handed.

A correspondence indicates that two instruments address the same underlying obligation. It is not a mapping endorsed by either body, not a statement that one satisfies the other, and not a judgement about which is more demanding.

§ 7 — When it applies

An effective date, not a deadline

  1. 15 December 2024

    The date the Technology-related Revisions to Parts 1 to 3 became effective. An effective date for a code provision, not a statutory compliance deadline: it marks when the paragraph entered the Code, and it binds a given accountant only through the member body that adopted the revised text.

§ 8 — Exposure

What a breach actually costs

No fine under the Code; a disciplinary matter for the member body that adopted it

The Code is issued by IESBA and has force through adoption by IFAC member bodies. IESBA runs no disciplinary process of its own, and no regulator enforces the Code as such. A member body that has adopted it investigates alleged breaches and may reprimand, fine, impose conditions, or withdraw membership and the practising certificate. It does not reach a person who is not a member of an adopting body.

§ 9 — Where this is assessed

Where this is assessed

Examined in one credential, in the domains named on each card.

AIAC-FNAFPractice

Certified AI in Finance & Accounting — Fundamentals

Verifying AI output before reliance · 20% of the paper

For finance and accounting professionals who use AI in analysis, close and reporting work — and verify the output before the numbers are relied on.

Financial servicesEnrolment open

Certification

Examined on this standard of evidence

What this page sets out is examined, on work the candidate has not seen, in the credential beside it. Every script is marked by an AI assessor first and an independent human assessor second, and every result is on the public register.

AIAC-FNAF

Certified AI in Finance & Accounting — Fundamentals

2 hours · remote, proctored · valid 2 years

Enrol