Transformation Risk insights series

A practical use case for AI transformation risk in ERP

  • August 25, 2026

This series explores how taking a portfolio-wide approach can help organizations align transformation efforts, reduce risk, and drive meaningful outcomes across business, technology, and controls.

Key takeaways:

  • Embedding AI in ERP and finance workflows creates new opportunities for automation and insight, but introduces a more complex risk and control environment that extends beyond the ERP itself.
  • Organizations should treat ERP and non-ERP AI as a single risk landscape, with governance, controls, and accountability designed to address AI-driven decisions, evolving models and cross-platform processes.
  • Key AI transformation risks span workforce ownership, regulatory compliance, data quality, and technology fragmentation—making transparency, monitoring, and traceable evidence increasingly important.
  • Taking a portfolio-wide, risk-informed approach can help organizations align AI governance with ERP transformation goals while supporting stronger execution, compliance, and confidence as AI adoption grows.

ERP transformations have entered a new phase. AI is already being embedded directly into core finance and operational workflows, and vendors are moving quickly to roll out new capabilities. At the same time, many organizations are deploying AI platforms alongside ERP-native features, often using the same underlying ERP data.

That combination can unlock real value: faster insights, better forecasting, automation, anomaly detection, decision support. It also creates a more complex, more fragmented risk and control environment. If you want to capture that value, treat AI as a decision-making capability—not a “feature.” Unify governance across your ERP and non‑ERP AI and redesign controls for probabilistic outputs and agentic workflows. And, crucially, build auditability into your processes from Day One.

“As AI is increasingly embedded in core ERP workflows, organizations need to navigate a complex risk and control environment to capture value.”

Micah Richard, Digital Assurance and Transparency Principal, PwC US

What are the biggest AI transformation risks in ERP?

AI can show up in financial reporting in familiar ways, like producing information used in reporting, operating a control, or operating part of a process. What’s new is its scale and speed.

  • ERP vendors are integrating AI fast and expanding capabilities through frequent releases.
  • AI enablement often occurs outside the ERP through external AI ecosystems that use ERP data and functionality.
  • Decentralized tooling makes visibility harder, and governance can lag adoption if you don’t design it to activate where and when reliance occurs.

Through discussions with clients and leveraging PwC's proprietary transformation risks insight framework, we’ve identified some of the most common risks you can encounter with AI in your ERP transformations.

PwC's Transformation risk insights framework

Organizational risks

When AI influences decisions embedded in ERP workflows, organizations often struggle to define who owns the model, the data, the decision, and the outcome, particularly as usage moves from “assistive” to “relied upon.” If you don’t explicitly define reviewer accountability, monitoring expectations, and ownership in financially relevant workflows, you risk confusion, bottlenecks, and stalled transformations.

Example: During an ERP transformation, a global manufacturing company implements AI-driven invoice matching. As the company starts relying on the AI’s recommendations for payment approvals, confusion arises over who’s responsible for reviewing exceptions. The finance team? IT? The AI vendor? Without clear accountability, disputed invoices can pile up, delaying payments and damaging supplier relationships.

Control and compliance risks

Traditional ERP controls, like internal control over financial reporting (ICFR), were built for deterministic systems—easily observable and tested by the ERP user, infrequently changed, and easily audited. AI introduces probabilistic behavior, rapid change, greater reliance on vendor platforms, and more complex, obfuscated audit trails. This can shift control reliance toward management review and monitoring, often without the precision needed to remain effective as scale increases.

Likewise, leaders need to explain AI-supported decisions to auditors, regulators, and boards, and they need to retain defensible evidence trails—how and why your AI collects data and makes its recommendations. These systems use signals such as logs, traces, model outputs, and data flows, which you can’t translate into metrics and alerts without transparency.

Example: A global manufacturer deploys an AI service that recommends revenue recognition, accrual, and reserve adjustments across multiple ERP instances using data from operational systems and a third-party foundation model. As the underlying model and prompts evolve through vendor updates and internal tuning, management reviewers increasingly rely on summarized AI outputs rather than validating the underlying assumptions. During a regulatory inquiry, the company struggles to reconstruct which model version, data sources, approval workflow, and governance controls supported specific financial decisions. This can lead to findings around insufficient control precision, ineffective monitoring, and inadequate evidence to demonstrate compliance with financial reporting and regulatory requirements.

Technology and data risks

AI can amplify issues in data quality, lineage, and completeness or accuracy. In order to trust your AI’s outputs, your teams need to understand how AI affects underlying data and how management should demonstrate these qualities.

Example: In a source-to-pay process, an external AI platform accesses ERP data and other systems to automate purchase order approvals. When a data quality issue in the legacy system leads to incorrect approvals, the root cause becomes hard to trace. The organization realizes it needed to map data lineage across all systems and demonstrate data completeness and accuracy, not just within the ERP.

AI capabilities also spread across ERP-native features, third-party AI platforms, and open-source or custom agent frameworks, each with a different owner, logging approach, and control pattern. Internal “technology patterns” materials explicitly show multiple paths (ERP-integrated, third-party platforms, open source) and call out the need for shared building blocks like traceability, logging, and integrated monitoring or observability across silos.

This fragmentation increases risk through misaligned data sources feeding different AI logic and outcomes; inconsistent governance and documentation across platforms, which make end-to-end oversight difficult; and a fractured audit narrative when decisions span systems but evidence is scattered or incomplete.

Example: A company uses both ERP-native AI features and a third-party AI platform for forecasting. Each system has its own logging and monitoring tools, and there’s no unified view of AI decisions. When a forecasting error occurs, it’s unclear which system’s logic is responsible, and the evidence is scattered across platforms. This fragmentation makes it difficult to reconstruct an audit narrative and delays remediation.

How do you tackle AI transformation risks in ERP?

With the emphasis now on speed and scale, you’re going to want to move fast. At the same time, you need to think strategically and connect your data and systems with AI in a single, holistic framework that takes advantage of both. Here are a few tactical moves you can make right now as you implement AI across your organization.

Treat ERP and non‑ERP AI as one risk landscape

AI enablement often happens outside ERP, through broader AI ecosystems, using ERP data. Taking a portfolio-wide approach can help you align transformation efforts, reduce risk, and drive meaningful outcomes across business, tech, and controls. Your teams should understand the full AI footprint, not just the parts inside their ERP suites. One approach is to inventory where AI influences outcomes across your major finance value streams (record‑to‑report, source‑to‑pay, and lead‑to‑cash), regardless of platform.

Establish governance that activates automatically

When tooling is decentralized, governance can’t depend solely on centralized registration. One internal governance model proposes keeping enterprise Trust AI as the backbone with a targeted “overlay” that activates when AI intersects with financial reporting workflows or systems within the ICFR boundary.

Redesign process and controls for AI realities

AI can affect business process controls, IT general controls (ITGCs) and SDLC controls, reliance on third-party tools and services, and even expose issues with your underlying data completeness and accuracy. You should design controls end-to-end around:

Example: If you want to rely on AI-generated journal entries, confirm that your model uses only reconciled financial data sources and that finance can trace outputs back to the underlying records.

Example: If you want to prevent unexpected control gaps, monitor vendor-driven AI updates and assess whether changes to underlying logic could affect access rights, segregation of duties, or financial reporting processes.

Example: If you want to use AI-generated accruals rather than simply accept them, you should define who’s accountable for validating outputs and how reviewers will challenge recommendations.

Example: If you want to prevent reconciliation issues across ERP and downstream systems, first confirm that AI-driven classifications and calculations are applied consistently and that supporting evidence can be traced across platforms.

Align early with auditors: Logs, evidence, and observability

As autonomy increases, monitoring becomes more important. It needs to be strategically designed and easily auditable. Proactively communicate with your auditors about where AI may impact your reporting and controls—it can have major impacts for your risks and audit plans. Detailed data trails and observability can help offset common “black box” problems with auditing your AI’s reasoning. Addressing these types of governance, risks, and controls early can help you avoid downstream disruption.

How can PwC help?

At PwC, we help clients drive successful transformation by aligning strategy, program delivery, business organization, technology and data, and controls and compliance through a risk-informed approach.

Our transformation risk insights framework assesses transformations across 15 critical success factors, enabling early identification of risks and more effective execution, stronger governance, and more reliable outcomes.

We help your organization implement AI-enabled ERP quickly—without sacrificing confidence, compliance, or trust. Guided by our insights framework, we take an enterprise-wide view of risk through three focused offerings.

  • Enterprise AI‑in‑ERP risk assessments identify where AI influences outcomes across both your ERP and non‑ERP systems, including split AI environments.
  • Cross‑platform control design assessments aligned to SOX and ICFR expectations, extending foundational ITGCs with AI-specific considerations around data, validation, transparency, and monitoring.
  • Ongoing governance and monitoring assessments operationalize Trust AI practices within your ERP and where it overlaps with external platforms—an area where many organizations still struggle to scale principles into repeatable processes.

Digital Assurance and Transparency

Powering digital progress through trust

How is AI—inside and outside ERP—influencing your end-to-end processes?

Transformation Risk insights series

Contact us

Jill Pavlus

Jill Pavlus

Principal, PwC US

Micah Richard

Micah Richard

Principal, Digital Assurance and Transparency, PwC US

Errol Ramdarie

Errol Ramdarie

Partner, PwC US

Gena Sullivan

Gena Sullivan

Partner, PwC US

Follow us