This series explores how taking a portfolio-wide approach can help organizations align transformation efforts, reduce risk, and drive meaningful outcomes across business, technology, and controls.
ERP transformations have entered a new phase. AI is already being embedded directly into core finance and operational workflows, and vendors are moving quickly to roll out new capabilities. At the same time, many organizations are deploying AI platforms alongside ERP-native features, often using the same underlying ERP data.
That combination can unlock real value: faster insights, better forecasting, automation, anomaly detection, decision support. It also creates a more complex, more fragmented risk and control environment. If you want to capture that value, treat AI as a decision-making capability—not a “feature.” Unify governance across your ERP and non‑ERP AI and redesign controls for probabilistic outputs and agentic workflows. And, crucially, build auditability into your processes from Day One.
“As AI is increasingly embedded in core ERP workflows, organizations need to navigate a complex risk and control environment to capture value.”
Micah Richard, Digital Assurance and Transparency Principal, PwC USAI can show up in financial reporting in familiar ways, like producing information used in reporting, operating a control, or operating part of a process. What’s new is its scale and speed.
Through discussions with clients and leveraging PwC's proprietary transformation risks insight framework, we’ve identified some of the most common risks you can encounter with AI in your ERP transformations.
When AI influences decisions embedded in ERP workflows, organizations often struggle to define who owns the model, the data, the decision, and the outcome, particularly as usage moves from “assistive” to “relied upon.” If you don’t explicitly define reviewer accountability, monitoring expectations, and ownership in financially relevant workflows, you risk confusion, bottlenecks, and stalled transformations.
Example: During an ERP transformation, a global manufacturing company implements AI-driven invoice matching. As the company starts relying on the AI’s recommendations for payment approvals, confusion arises over who’s responsible for reviewing exceptions. The finance team? IT? The AI vendor? Without clear accountability, disputed invoices can pile up, delaying payments and damaging supplier relationships.
Traditional ERP controls, like internal control over financial reporting (ICFR), were built for deterministic systems—easily observable and tested by the ERP user, infrequently changed, and easily audited. AI introduces probabilistic behavior, rapid change, greater reliance on vendor platforms, and more complex, obfuscated audit trails. This can shift control reliance toward management review and monitoring, often without the precision needed to remain effective as scale increases.
Likewise, leaders need to explain AI-supported decisions to auditors, regulators, and boards, and they need to retain defensible evidence trails—how and why your AI collects data and makes its recommendations. These systems use signals such as logs, traces, model outputs, and data flows, which you can’t translate into metrics and alerts without transparency.
Example: A global manufacturer deploys an AI service that recommends revenue recognition, accrual, and reserve adjustments across multiple ERP instances using data from operational systems and a third-party foundation model. As the underlying model and prompts evolve through vendor updates and internal tuning, management reviewers increasingly rely on summarized AI outputs rather than validating the underlying assumptions. During a regulatory inquiry, the company struggles to reconstruct which model version, data sources, approval workflow, and governance controls supported specific financial decisions. This can lead to findings around insufficient control precision, ineffective monitoring, and inadequate evidence to demonstrate compliance with financial reporting and regulatory requirements.
AI can amplify issues in data quality, lineage, and completeness or accuracy. In order to trust your AI’s outputs, your teams need to understand how AI affects underlying data and how management should demonstrate these qualities.
Example: In a source-to-pay process, an external AI platform accesses ERP data and other systems to automate purchase order approvals. When a data quality issue in the legacy system leads to incorrect approvals, the root cause becomes hard to trace. The organization realizes it needed to map data lineage across all systems and demonstrate data completeness and accuracy, not just within the ERP.
AI capabilities also spread across ERP-native features, third-party AI platforms, and open-source or custom agent frameworks, each with a different owner, logging approach, and control pattern. Internal “technology patterns” materials explicitly show multiple paths (ERP-integrated, third-party platforms, open source) and call out the need for shared building blocks like traceability, logging, and integrated monitoring or observability across silos.
This fragmentation increases risk through misaligned data sources feeding different AI logic and outcomes; inconsistent governance and documentation across platforms, which make end-to-end oversight difficult; and a fractured audit narrative when decisions span systems but evidence is scattered or incomplete.
Example: A company uses both ERP-native AI features and a third-party AI platform for forecasting. Each system has its own logging and monitoring tools, and there’s no unified view of AI decisions. When a forecasting error occurs, it’s unclear which system’s logic is responsible, and the evidence is scattered across platforms. This fragmentation makes it difficult to reconstruct an audit narrative and delays remediation.
With the emphasis now on speed and scale, you’re going to want to move fast. At the same time, you need to think strategically and connect your data and systems with AI in a single, holistic framework that takes advantage of both. Here are a few tactical moves you can make right now as you implement AI across your organization.
AI enablement often happens outside ERP, through broader AI ecosystems, using ERP data. Taking a portfolio-wide approach can help you align transformation efforts, reduce risk, and drive meaningful outcomes across business, tech, and controls. Your teams should understand the full AI footprint, not just the parts inside their ERP suites. One approach is to inventory where AI influences outcomes across your major finance value streams (record‑to‑report, source‑to‑pay, and lead‑to‑cash), regardless of platform.
When tooling is decentralized, governance can’t depend solely on centralized registration. One internal governance model proposes keeping enterprise Trust AI as the backbone with a targeted “overlay” that activates when AI intersects with financial reporting workflows or systems within the ICFR boundary.
AI can affect business process controls, IT general controls (ITGCs) and SDLC controls, reliance on third-party tools and services, and even expose issues with your underlying data completeness and accuracy. You should design controls end-to-end around:
As autonomy increases, monitoring becomes more important. It needs to be strategically designed and easily auditable. Proactively communicate with your auditors about where AI may impact your reporting and controls—it can have major impacts for your risks and audit plans. Detailed data trails and observability can help offset common “black box” problems with auditing your AI’s reasoning. Addressing these types of governance, risks, and controls early can help you avoid downstream disruption.
At PwC, we help clients drive successful transformation by aligning strategy, program delivery, business organization, technology and data, and controls and compliance through a risk-informed approach.
Our transformation risk insights framework assesses transformations across 15 critical success factors, enabling early identification of risks and more effective execution, stronger governance, and more reliable outcomes.
We help your organization implement AI-enabled ERP quickly—without sacrificing confidence, compliance, or trust. Guided by our insights framework, we take an enterprise-wide view of risk through three focused offerings.
Powering digital progress through trust
Transformation Risk insights series