AI Governance in Audit: Wayne Banks on What Firms Must Do to Protect Trust
Chartered accountant and former global CFO Wayne Banks talks to Claudine Cassar about Big Four AI adoption, board accountability, client data and the standards needed before AI influences audit work
Key Takeaways
Boards should apply the same discipline to AI that they apply to financial reporting: provenance, assumptions, variances, controls and named accountability
Banks warns that “automation deference” can erode professional scepticism and that shared models may create correlated errors across engagements
Existing principles remain relevant, but Banks argues that the profession needs explicit and enforceable requirements for AI use
About Wayne Banks
Wayne Banks is a chartered accountant, finance executive and board adviser whose career has spanned corporate finance, technology and enterprise transformation. He has served as Global Chief Financial Officer of GHD, Chief Operating Officer of UXC Connect, and in senior finance, operating and client roles with DXC Technology and predecessor businesses. He later held enterprise roles at Workday and SAP.
In November 2025, Banks co-founded Full Measure Advisory with his son, Lawson Banks. His current work includes fractional CFO support, finance transformation and board-level AI governance. Full biography at the end of the article.
Why this conversation matters
Big Four firms are embedding AI into audit, consulting and advisory work at pace. The governance question is no longer whether these tools will be used. It is whether firms and boards can explain where an output came from, how client data was handled, who reviewed the work and who remains accountable when it is wrong.
Big4News recently examined Big Four reports containing fabricated or distorted citations, case studies and claims. At the same time, controversies involving PwC and KPMG in Australia, together with an EY-linked case involving alleged unauthorised access to banking data, have intensified scrutiny of how professional services firms protect confidential information.
These developments make AI governance inseparable from audit trust.
Banks brings experience from both sides of large-scale transformation: as a CFO and operating executive responsible for governance and controls, and through enterprise roles at technology vendors. In this interview, he argues that AI should be governed in the language boards already understand: assumptions, movements, evidence, review, risk and accountability.
Banks’s answers have been lightly edited for punctuation, clarity and house style without altering their substance.
Editor’s note on terminology: “AI” covers technologies with different risk profiles. Generative AI can produce plausible but fabricated content. Analytical and machine-learning systems raise issues such as bias, model drift, false positives and false negatives. Agentic systems add questions about authority and autonomous action. This interview focuses principally on generative AI and other model-driven systems used to produce or inform professional work.
1. From the technology team to the boardroom
You have written that AI governance is not a technology problem, but a business, finance, risk and accountability problem. Why do you think boards are still treating AI as something for the technology team rather than the boardroom?
Because that is where the comfort sits. Most directors did not grow up with AI, so the instinct is to delegate it downward to whoever sounds most fluent in it, usually someone in IT or a data team. That is a governance failure dressed up as prudent delegation.
I spent thirty-eight years moving between finance, technology and the boardroom, including as Global CFO of GHD across more than fifty countries, and the pattern is consistent. Boards are comfortable interrogating a balance sheet because they were trained to ask about assumptions, movements and controls.
AI has not yet been translated into that language, so it gets treated as a system rollout rather than a decision that changes how the organisation makes judgements, allocates capital and takes on risk. Once you frame it that way, AI stops being an IT agenda item and becomes what it actually is: a board-level accountability question.
2. The questions boards should ask
You have said boards know how to interrogate financial numbers, assumptions, variances, movements and controls, but are not yet asking the equivalent questions about AI. What should those equivalent questions be?
Start with the same discipline you would apply to a set of management accounts. Where did this number, this recommendation, this output actually come from? What was the model trained on, what data fed the output today, and has that data been verified or does it carry someone else’s assumptions baked in?
Then ask about variance. What changed between this AI-generated output and the last one, and why? You would never accept a movement in the numbers without an explanation.
Then controls: who reviewed this before it reached a client or a decision-maker, is there a named human accountable, is there an audit trail?
And finally maturity: is this initiative genuinely embedded with proper oversight, or is it still an early-stage experiment being described as more advanced than it is?
3. Client data, proprietary tools and ownership
Big Four firms are moving quickly to embed AI into audit, consulting and advisory work. What questions should clients and audit committees be asking about how their data is used, whether it feeds proprietary tools or benchmarks, and who owns the resulting insights?
The first question is simple and rarely asked with enough force: where does our data go once it enters your AI tools, and does it ever leave our engagement? Firms will often say the data is anonymised or aggregated for benchmarking purposes, but audit committees should ask to see exactly how.
Second: ownership of insight. If a firm’s AI tool learns from many clients and produces a sharper benchmark or a more valuable proprietary model as a result, who owns the commercial value created? Engagement letters do not always answer that question clearly. Where they are silent or broadly drafted, the firm may capture the upside while the client supplied the raw material.
This is not a hypothetical trust problem. PwC’s 2023 tax leaks scandal, the more recent KPMG whistleblower matter involving confidential client information being shared internally and used in connection with bids for other audit work, and the EY matter involving alleged unauthorised access to confidential banking information are clear examples of why firms’ information controls deserve much closer scrutiny.
On 1 July 2026, against the backdrop of the PwC and KPMG scandals, the Australian government released an options paper on the regulation of accounting, auditing and consulting firms, putting both operational and structural separation on the table. If firms cannot be trusted to manage confidential client information under existing controls, audit committees have every reason to ask far harder questions about what happens once that same information starts feeding AI systems.
Editor’s note: KPMG has acknowledged that client documents and other material containing client information were inappropriately shared internally. The EY matter remains before the courts. The charges are allegations and do not constitute findings of guilt.
4. What hallucinated reports reveal
In The Hallucination Trap, Big4News examined examples where Big Four reports contained fabricated or distorted citations, case studies or claims. From a governance perspective, what do those incidents reveal?
They suggest that professional scepticism, source-verification controls, or both failed somewhere between generation, review and publication. A polished AI-generated draft arrived that read like it belonged in a final report, and nobody caught before publication that a plausible-sounding case study or citation had been fabricated with total confidence and no signal that anything was wrong.
Traditional review processes were designed around familiar forms of human error: a wrong number, an outdated reference. They can catch AI-generated errors too, but only if reviewers know where AI has been used and treat every material claim and citation as something to verify rather than something to trust because it looks right.
So what those incidents really reveal is a firm that adopted a powerful capability faster than it adopted the control environment around it. That pattern shows up across almost every AI adoption failure I have studied. Capability without control is not innovation, it is exposure.
5. Where accountability should sit
If a Big Four firm produces an AI-assisted report containing false citations, fake case studies or unsupported claims, where should accountability sit: with the individual who produced the work, the partner who reviewed and signed off on it, the firm, or the AI governance function?
At what point does an AI-assisted mistake stop being an individual error and become a failure of firm governance?
Accountability should sit in layers, the same way it does in financial reporting, and none of those layers gets to point at the other and walk away. The individual who produced the work is accountable for using the tool responsibly. The partner who signed off carries the heavier obligation, because sign-off has always meant personal professional accountability, and that principle does not evaporate because a machine did some of the drafting.
But the moment a firm rolls out an AI tool across hundreds of engagements without a documented control framework or verification standard, the failure becomes structural rather than personal. One fabricated citation may be an individual lapse. A pattern of them is evidence that the firm’s control environment is not fit for purpose, and that responsibility sits with the firm’s leadership, not just the person who typed the prompt.
6. Automation deference and correlated error
In audit, the entire system depends on professional judgement, scepticism and review. Where do you see the greatest risk when AI tools are introduced into that process?
The greatest risk is what I would call automation deference: the quiet erosion of scepticism that happens when a tool consistently produces plausible, well-formatted output. Professional judgement is a muscle. It weakens the moment reviewers start treating AI output as a starting point of truth rather than a draft to be interrogated.
There is also a homogenisation risk. Audit quality has always depended partly on independent minds reaching independent conclusions and reconciling differences. If every team is drawing from the same underlying model, you can end up with consistent errors rather than independent checks catching each other’s mistakes. And the biggest risk of all is sequencing: AI tools are being embedded into audit workflows faster than firms are building the control environment to govern them.
7. The case for explicit professional standards
Should professional bodies develop explicit AI standards for accountants, auditors and advisers?
Yes. Professional bodies have begun producing research, guidance and workstreams, but AI has moved from experimental to embedded across audit and advisory work faster than explicit professional obligations have been developed.
I am based in Australia, so my immediate focus is naturally on CA ANZ. But its CEO, Ainslie van Onselen, is also Chair of Chartered Accountants Worldwide, an organisation representing more than two million members and students across more than 190 countries. That dual role gives her influence well beyond Australia and New Zealand and provides a platform from which to press for explicit standards around verification, confidentiality, disclosure and accountability.
In a February 2026 article for Acuity, van Onselen argued that accountants have repeatedly adapted to technological change, moving from the abacus to calculators and then to Excel. She described AI as transformative, but also as “simply the next step.”
I understand the historical argument, but I am concerned that this framing understates what is qualitatively different about generative AI. AI is not simply another productivity tool.
Excel never fabricated a citation with total confidence. Generative AI can. It can produce persuasive but unsupported claims, invent apparently credible sources and create new confidentiality, provenance and accountability risks when client information is entered into systems whose data-handling, training and reuse arrangements are not transparent.
The existing duties of competence, due care, confidentiality and professional scepticism still apply, but they need to be translated into explicit standards for AI use. Otherwise, every firm is left to decide for itself what adequate verification, disclosure and human accountability look like. That is not a credible basis for a profession built on trust.
8. Minimum controls before AI influences client work
What minimum controls should an audit or advisory firm be able to demonstrate before allowing AI to influence client work?
Source verification should be mandatory and documented: every material claim, citation or case study generated with AI assistance needs a traceable source that a human has actually checked, not assumed to be correct because it looked right. Named reviewers matter enormously, because anonymous or collective sign-off is where accountability goes to die.
Beyond that, a firm needs clear accountability structures, approved-use rules, proper data and model controls, verification protocols, access permissions, retention and deletion rules, vendor due diligence, testing and validation before deployment, and ongoing monitoring of output quality over time rather than a one-off implementation decision. There also needs to be a clear incident process when something goes wrong, and independent assurance that the controls operate in practice rather than only on paper.
Disclosure to clients should be honest and proportionate. A client does not need a list of every administrative use of AI, but it should be told when AI materially influenced the analysis, evidence or conclusion, or when its confidential information was processed by an AI system. A firm that can produce an audit trail and a model-use log on demand, for any engagement, at any time, is a firm that has actually built the framework rather than talked about it.
9. Is the profession moving quickly enough?
Do you think the accounting profession internationally is moving fast enough to develop credible governance standards for AI, or is it waiting for failures to force the issue?
Not fast enough. On AI-specific obligations, the profession is moving, but it is moving largely through roundtables, staff publications and non-authoritative guidance while the technology is already being embedded into client work. That matters because guidance can be useful, but it does not create the same minimum expectations or consequences as an enforceable standard.
Competence, due care, confidentiality, professional scepticism and quality management all still apply, but saying the old principles are technology-neutral is not the same as telling firms what they must actually do when a model fabricates evidence, changes after a vendor update or processes confidential client data.
The pattern in professional services is familiar: adoption first, internal guidance second, enforceable standards after something goes wrong in public. That is regulation by embarrassment.
A profession built on assurance should not need a failed audit, a leaked dataset or another fabricated government report before it decides what adequate source verification, disclosure, model governance and human accountability look like.
If international bodies do not set minimum requirements that travel across jurisdictions and firms, the firms with the greatest commercial incentive to move fastest will continue setting the practical standard for themselves, and failure will end up doing the standard setting for them.
Editor’s note on current standard-setting: IESBA’s technology-related revisions to its Code became effective in December 2024. IESBA says those revisions address most current ethical challenges arising from technology use and plans AI-specific non-authoritative material for the fourth quarter of 2026. The IAASB says ISQM 1 and ISA 220 (Revised) provide a strong principles-based foundation for managing technology-related risks and is developing additional non-authoritative material. Banks’s criticism is narrower: that these measures do not yet establish the explicit AI-specific requirements he advocates.
10. Genuine transformation or expensive theatre?
You have worked across finance, technology, ERP vendors and board roles. From that perspective, how do you distinguish genuine AI transformation from what you have called expensive theatre?
Genuine transformation changes how decisions get made and who is accountable for them. Expensive theatre changes how a slide deck looks. I saw the same distinction during the ERP and cloud waves at SAP and Workday: plenty of organisations bought the technology and declared transformation, while the operating model, the decision rights and the accountability structures stayed exactly as they were.
The tell is in the follow-up questions. Ask a leadership team what decision they now make differently because of AI, who is accountable for the output, and how they would know if it was wrong. Genuine transformation has crisp answers. Expensive theatre has an impressive dashboard and a vague answer about efficiency gains nobody can actually trace to the numbers.
I see this most clearly through my son, Lawson, who is a genuine digital AI native rather than someone who adopted AI mid-career. He does not think of AI as a bolt-on; he thinks AI-first: the starting question is not how do we add AI to what we already do, it is how would we design this from scratch today with AI as the default. That is a different posture from the one I often see in boards and professional bodies. It is also why I never romanticise adoption itself as the achievement. In the wrong hands AI is simply a way to accelerate a poor business faster toward the same poor outcome. Shallow prompting around the edges of a broken process is not transformation, it is automating your own mistakes at higher speed, and that carries real business risk.
A closing note from the interviewer
Wayne, thank you for sharing your perspective. This conversation leaves a clear challenge for boards, firms and professional bodies: AI adoption cannot be allowed to outrun the controls, standards and personal accountability on which trust in audit and advisory work depends. Whether the profession responds before another public failure forces the issue will be a test of the governance principles it asks others to follow.
Who is Wayne Banks?
Wayne Banks is a chartered accountant, finance executive and board adviser whose career has spanned corporate finance, technology, enterprise systems and business transformation for nearly four decades.
Banks began his career with Allan Hall Business Advisors in 1987 and later worked as Financial Controller at CA Technologies. From 1996, he moved into commercial finance and client leadership roles with DXC Technology and predecessor businesses. His work included due diligence, mergers and acquisitions, technology pricing, commercial modelling and the management of large outsourcing relationships.
As a senior account director, Banks managed major client relationships involving BHP and GE Money. His responsibilities included a ten-year, $400 million global IT outsourcing agreement with GE Money. Between 2005 and 2010, he held chief financial and operating responsibilities across DXC Technology and predecessor businesses and served as Chief Financial Officer and Director for Asia Pacific at Paxus.
Banks became Chief Operating Officer of UXC Connect in 2010, with responsibilities spanning finance, information technology, human resources, procurement, commercial operations and revenue management.
From 2012 to 2015, he served as Global Chief Financial Officer of GHD, an international engineering and professional services firm. His work covered finance transformation, enterprise resource planning, business intelligence, mergers and acquisitions, board reporting and stakeholder relations during a period of international growth.
After GHD, Banks founded Ignite Alliance, providing fractional CFO and advisory services to start-ups, scale-ups and professional services businesses. He later served as Independent Chair of Hatch RobertsDay, held an advisory board role at Locumate.ai, and worked in enterprise account roles at Workday and SAP.
In November 2025, Banks co-founded Full Measure Advisory with his son, Lawson Banks. The firm provides fractional CFO support, finance-function development and AI governance advice to growing businesses and boards.
Banks argues that AI governance should not be delegated solely to technology teams. His work focuses on the financial, operational and accountability questions surrounding AI adoption, including how organisations assess value, set risk appetite, verify outputs and retain human responsibility for decisions.
This article is part of the Big4News Expert Voices Series
Expert Voices
This section features candid interviews with whistleblowers, legal experts, and financial professionals who have direct experience with the inner workings of Deloitte, PwC, EY, and KPMG.
About Claudine Cassar
I’m a corporate anthropologist and former Deloitte equity partner. I sold my technology business to Deloitte in 2016 and led the Malta Consulting team for five years. I am the founder and editor of Big4News, which provides independent, clear analysis of PwC, Deloitte, EY, and KPMG — free from corporate spin.
Find me on LinkedIn, X, Instagram, or my author website.
Feel free to reply to this newsletter — I read every reply.








