Get accounting insights delivered directly to your inbox!
This is part of a series of posts on the new capabilities FloQast announced at TakeControl 2026. For the full picture — including new Transform building capabilities, journal entries reviewed by the AI Assistant before they post, Detect, and Operational Audits — check out the complete TakeControl 2026 announcement here.
The accounting profession spent decades building consensus around how to govern internal controls. The answer, if you work in audit or compliance, is something you've known since your first day on the job: COSO. The 1992 Internal Control — Integrated Framework, updated in 2013, became the de facto standard against which auditors measure whether a company's controls are real. SOX compliance, audit committee presentations, external audit sign-offs — COSO sits underneath most of it.
Now, accounting teams are deploying AI agents, and the same question is surfacing in audit planning meetings: how do we govern these things? COSO has an answer. Earlier this year, they published their generative AI governance framework — a structured approach to risk assessment, control environment, control activities, information and communication, and monitoring as they apply specifically to AI systems. The five components look familiar if you know the original framework. That's the point.
Most accounting teams haven't worked through what COSO's GenAI guidance actually requires. That's not a criticism — it was published recently, the space is moving fast, and there's a real gap between "we use AI" and "we've documented how our AI is controlled." That gap is going to matter to your auditors.
The phrase "AI governance" gets thrown around by every software company right now. Usually it means a settings page. COSO's framework is something else: a rigorous, auditor-recognized methodology for documenting that you've assessed the risks your AI systems introduce, defined the controls that address them, and set up ongoing monitoring to know if those controls are working.
That rigor is exactly why it's hard to implement. The framework is comprehensive — 17 principles across five components, and that's before you get into the GenAI-specific considerations that the new guidance layered on top. Building this yourself, from scratch, while also running a monthly close, is a significant lift. Most teams will need help.
At TakeControl 2026, FloQast announced the COSO GenAI Module — a capability being built directly into the platform to operationalize COSO's AI governance framework for accounting teams. The goal is to let teams wrap their AI agents in COSO-compliant governance — risk assessment, control environment and activities, ongoing monitoring and assurance — without building the scaffolding themselves.
The connective tissue is already in place. FloQast Transform generates AI agents from your existing workflows and produces the documentation that shows an auditor exactly how each agent was built, tested, and approved. FloQast Risk and Compliance manages the evidence. The COSO GenAI Module, as it comes to the platform, is designed to bring structure to all of that — mapping your AI activities to the framework components and generating the audit evidence to support them.
This isn't compliance theater. The design principle here is that governance should be a byproduct of the work, not a separate project your team does after the fact.
FloQast's commitment here goes beyond the module itself. We’re investing at the standard-setting level to make sure what gets built reflects what auditors will actually require — not a simplified version of the framework, not a creative interpretation of it. That's what makes the COSO GenAI Module worth watching as it comes to the platform.
What you can do now: read COSO's GenAI framework. It's publicly available, and working through it with your compliance and internal audit teams will give you a head start on the conversations your auditors will eventually have with you. The five-component structure will feel familiar. The AI-specific questions layered on top — about model risk, data quality, algorithmic accountability, and monitoring — are where most teams will need to do fresh thinking.
The auditor question isn't coming eventually. For teams already running AI agents in their close, it's already here. COSO has the framework. FloQast is building the infrastructure to run it.
FloQast's COSO GenAI Module is in development and will be available to customers in the coming months. Learn more about FloQast's AI governance capabilities at FloQast.com.