Project Finance & Financial ModellingAI-enabled analysis with governance · Lesson 19 of 20

Governing AI in financial analysis

Article · 13 min · 8 min lecture

Video lecture

Governing AI in financial analysis

9 chapters · about 8 min · full transcript

Coming soon

Chapter 1 of 9

A transposed digit and an investment committee

  • Why AI needs explicit controls in finance
  • A seven-part governance framework and risk tiers
  • Model risk management, audit trails and validation

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

Why governance matters more in finance

Financial models and reports influence investment decisions, lending, public spending and disclosures to investors. Errors can cause financial loss, regulatory issues and reputational damage. AI introduces new error types (confident mistakes, non-reproducible outputs) that require explicit controls.

Governance framework

  1. Policy: which AI tools are approved, for which tasks, with what data.
  2. Risk tiering: classify uses by impact.
  3. Human review: proportional to risk, by qualified reviewers.
  4. Audit trail: record inputs, prompts, outputs, changes and approvals.
  5. Validation: test AI-supported calculations against independent methods.
  6. Confidentiality and privacy: protect deal data and personal data.
  7. Monitoring and learning: track errors found in review and improve prompts, tools and training.

Risk tiering example

TierExampleControls
LowSummarising public market researchSpot check, cite sources
MediumDrafting variance commentary; extracting terms for internal screeningFull review against source; record changes
HighFormulas in a lender model; figures in an investment committee paper; covenant certificatesIndependent check, reconciliation to model outputs, documented sign-off
Not permittedAutonomous decisions on investments, lending or covenant waiversProhibited

Model risk management

Many financial institutions apply model risk management frameworks (in banking, supervisors in several jurisdictions have issued model risk guidance). Core practices apply to project finance models and AI tools alike:

  • Maintain a model inventory with owners and purposes.
  • Validate models independently before use in decisions.
  • Document assumptions, limitations and known issues.
  • Control changes with versioning and testing.
  • Review models periodically.

Audit trail template

Task: Draft DSCR commentary for Q3 lender report
Tool and version: [approved assistant, version]
Inputs: Model v4.2 outputs (locked), Q3 operating data (validated)
Prompt/template: LENDER-COMM-01
AI output stored: yes (link)
Reviewer: [name]   Checks: figures reconciled to model; causes confirmed with asset manager
Edits: corrected availability figure; removed speculative statement on next year
Approved by: [finance director]   Date: ______

Validation techniques

  • Recalculate key outputs (e.g., DSCR, NPV) by hand or in an independent sheet.
  • Reconcile AI-quoted figures to locked model outputs.
  • Back-test ML forecasts against actuals.
  • Reasonableness checks: does the direction and size of change make sense?

Regulatory landscape (high level)

AI regulation continues to evolve. The EU AI Act takes a risk-based approach; the UK relies on principles applied by sector regulators; the US mixes federal guidance, sector regulation and state laws; the UAE and KSA have published national AI strategies and ethics principles; Pakistan has national AI policy work. Financial regulators in many jurisdictions expect firms to manage AI and model risks within existing governance. Follow your organisation's legal and compliance guidance.

Worked example

Illustrative. An analyst at a fictional Karachi-based advisory firm used AI to draft an investment memo, which quoted an equity IRR of 14.2%. The reviewer reconciled it to the locked model output of 12.4%: the AI had transposed digits from an earlier draft. Because the firm's policy required reconciliation of every figure in high-tier documents, the error was caught before the memo reached the investment committee. The audit trail showed exactly which inputs the AI had used, allowing a quick fix to the workflow (only locked outputs are now provided to the tool).

Common mistakes

  • No distinction between low- and high-risk uses.
  • Reviewers checking wording but not numbers.
  • Feeding draft or unlocked model versions to AI tools.
  • No record of AI involvement in decision documents.

Starting small

Governance does not need to be heavy to be effective. A small team can start with a one-page policy, a short list of approved tools, a three-tier review rule and a simple log recording which documents involved AI and who reviewed them. Review the log each quarter: which errors did reviewers catch, and what change in workflow would prevent them? This continuous-improvement loop matters more than the length of the policy.

Quick self-check

Pick the last decision document your team produced. Could you show which parts were AI-assisted, which inputs were used, and who verified the figures? If not, your governance has a gap worth closing now, before a costly error finds it for you.

Hands-on: reconcile a draft to locked model outputs

import re

model_outputs = {                 # exported from the locked model (version stated in the audit trail)
    "equity_irr_pct": 12.4, "project_irr_pct": 9.1, "min_dscr_x": 1.30, "avg_dscr_x": 1.34,
    "llcr_x": 1.31, "debt_usd_m": 135.0,
}
draft = """The project delivers an equity IRR of 14.2% and a project IRR of 9.1%, with minimum DSCR of
1.30x, LLCR of 1.31x and senior debt of USD 135.0M."""

numbers = [float(n) for n in re.findall(r"(\d+(?:\.\d+)?)\s*(?:%|x|M)", draft)]
targets = list(model_outputs.items())
for n in numbers:
    name, val = min(targets, key=lambda kv: abs(kv[1] - n))
    ok = abs(val - n) <= 0.05
    print(f"{n:>7}  closest {name:16s} {val:>7}  {'OK' if ok else 'MISMATCH - check'}")

Output flags 14.2 against the model's 12.4. A human reviewer confirms every flag; the script only makes the line-by-line check fast enough to do every time.

Template: one-page AI policy for a project finance team

1 Approved tools and the data classes each may process (public / internal / confidential deal data / personal data)
2 Risk tiers: Low (spot check) | Medium (full review vs source, edits recorded) |
  High (independent check, reconcile every figure to locked model, documented sign-off) | Not permitted (autonomous decisions)
3 Inputs rule: only locked, versioned model outputs and validated data go into AI tools for Medium/High work
4 Audit fields: task, tool/version, inputs + versions, prompt/template ref, output stored, reviewer, checks, edits, approver, date
5 Validation: recalculate key outputs; reconcile figures; back-test ML forecasts; reasonableness checks
6 Inventory: models and AI tools in use, owners, purpose, last validation date
7 Quarterly review: errors caught, by type; prompt/tool/training changes made

How to measure success

  • 100% of high-tier documents have a figure-by-figure reconciliation on file.
  • Quarterly log of errors caught in review, with the process change each one led to.
  • No use of unlocked model versions or unapproved tools for medium- or high-tier work.

Key takeaways

  • Govern AI with policy, risk tiering, proportional review, audit trails, validation and confidentiality.
  • Apply model risk management: inventory, independent validation, documentation, change control, periodic review.
  • Reconcile every AI-quoted figure to locked model outputs in high-tier documents.
  • Autonomous AI decisions on investment, lending or covenant waivers should not be permitted.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. An AI-drafted investment memo quotes an IRR that differs from the locked model output. What does this show?
  2. Which use should be in the highest review tier?
  3. Which practice belongs to model risk management?

Put it into practice

Write a one-page AI policy for a project finance team, including risk tiers, required checks and the audit trail fields.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.