Traditional ITGC scoping has concentrated on access, change management, and computer operations. AI introduces financially relevant risks through data classification, model inputs, retrieval sources, training and retention practices, connected tools, and model behavior.
This finding examines which privacy and security controls may need to enter financial-reporting scope when AI becomes part of a significant process. Controls historically owned by privacy and security teams, and often outside the key ITGC population, may become directly relevant to the reliability of financial reporting.
This is an open line of work. The question is being scoped; formal drafting has not begun. The finding will be published here when it reaches a defensible form.