Robotic Process Automation (RPA) continues to proliferate in organizations. Responding to governance challenges and impacts on financial reporting, the Committee of Sponsoring Organizations of the Treadway Commission (COSO) recently issued a guidance publication, “Achieving Effective Internal Control Over Robotic Process Automation.” Per the press release accompanying the guidance’s issuance, it “presents an RPA governance framework designed to help organizations maximize RPA benefits while mitigating risks through an effective internal control framework. Drawing from extensive research and professional feedback, the framework identifies key governance areas and control requirements to address common challenges associated with RPA, including security vulnerabilities, process knowledge loss, and uncontrolled bot proliferation” (https://tinyurl.com/3p5pm5n5).

No matter the level of their organization’s involvement with RPA, many financial professionals could benefit from this COSO publication, as it also highlights risks and related management strategies for a number of technological challenges. With businesses facing increased pressure to enhance financial performance, it is no surprise that many use emerging technologies such as RPA to drive efficiencies and to begin to initiate more advanced technologies, including artificial intelligence.

The purpose of RPA is to automate repetitive tasks. RPA has already been implemented throughout some larger organizations. With many repetitive tasks and functions, finance organizations have also implemented RPA to streamline their operations and enhance profits through better analysis of data or gaining cost efficiencies. Regarding internal corporate politics, with its impact on external financial reporting, COSO introduced guidance related to the consideration and governance of RPA, especially in financial reporting, in December 2024.

Guidance is Needed

Since the introduction of RPA, some CPAs have relied upon their ability to adapt existing frameworks and literature to properly assess RPA’s impact on the internal control environment. This created challenges and risks for all involved when RPA is used to produce financial statement information that are subject to regulatory mandates. Practically, this method included brainstorming potential ideas based on one’s ability to integrate their knowledge of RPA with COSO ICIF expectations; in other words, the method used individual or team brainstorming activities to derive risk mitigation expectations by interpolating ideas, rather than referring to a recognized standard or framework. Attention is paid to transaction activities, and governance is an afterthought, which frequently happens when the focus is on the technology that produces this information. This audit prejudice is similar to the tension of understanding and evaluating general controls that can occur when the team performing the financial statement audit is most interested in the results of application controls rather than also considering IT general controls, as required by the standards.

CPAs previously had to leverage professional journal articles and reputable firm whitepapers to justify their approach in assessing internal controls over RPA-produced information—not an envious position, given the importance of RPA in producing financial statement data. Much early guidance focused on the future effectiveness and efficiency possibilities in the accounting, audit, and tax fields. Some of the possibilities relating to advisory services, such as assisting clients in automating their processes, were also discussed. For example, representative The CPA Journal RPA-related articles include “How Robotic Process Automation Is Transforming Accounting and Auditing” (https://tinyurl.com/42j2zb5u) and “Exploring the Use of Robotic Process Automation (RPA) in Substantive Audit Procedures” (https://tinyurl.com/2fjy46b2).

One prominent publication to help the public better understand the implications of RPA on financial reporting was issued by Deloitte in 2018, “Internal Controls Over Financial Reporting Considerations for Developing and Implementing Bots,” (https://tinyurl.com/3xmcj899). This publication was not only helpful to potential prospects of Deloitte services, it also explained risks and controls related to an organization’s implementation and governance process. Interestingly, the publication encouraged organizations to consider the impact of external audits as part of the RPA implementation process: “In addition to management’s annual assessment of the company’s ICFR, it is important to keep external audit requirements in mind” (p.7).

As with many emerging technologies, some in the profession continued to use the “black-box” approach to auditing, failing to recognize the dramatic impact that RPA has had on their audited financial information. This approach was comparable to assessing internal control while ignoring the impact of information technology. It was not so much the failure to adapt RPA to perform the audit, but rather the failure to consider the impact of the auditee’s use of RPA on financial information used for reporting and decision making. As a result, the guidance provided by COSO is needed and welcomed.

The risks remain the same regardless of technology, but the controls needed to manage the risk will differ.

ICIF-Aligned Practical Guidance

Not surprisingly, as COSO published its guidance, it has aligned with its Internal Control-Integrated (ICIF) framework. It does this by presenting an “RPA Bot Governance Framework” comprising four areas: bot usage decision, access and authorization management, managing RPA process changes, and IT operations (https://tinyurl.com/mjmcufx2). Each of these areas consists of two to five specific control requirements, and a brief narrative focusing on RPA risks explains each of the areas.

The bulk of the document focuses on aligning the governance framework with the COSO-ICIF. Control requirements are identified for each component, and a summary paragraph is provided with just enough clarification that readers can effectively implement the guidance. This clarity is especially important for testing internal controls, so the guidance is critical for accountants and financial managers. Too often, we are presented with technology-related risks and controls without communicating how financial reporting is directly impacted. This leads to inefficient testing, scope questions, challenges to relevancy, and conflict between external auditors and their auditees. By specifying expectations, performance is communicated.

CPAs sometimes question the practicality of frameworks and guidance, citing implementation challenges and questioning the cost-effectiveness of the guidance, especially for small and midsize businesses (SMB). One of the most practical features of the document is the appendix. Per the guidance, “the appendix provides a comprehensive set of checklists designed to guide practitioners in implementing effective governance aligned with the COSO-ICIF” (pg. 19). The twopage checklist can be easily converted into an internal control questionnaire or control matrix to facilitate internal control assessments.

End User Computing (EUC) Reflections

In many ways, the risks and controls related to RPA reflect an ongoing challenge for the accounting profession. Many CPAs may recognize that RPA has governance and internal control challenges comparable to end-user computing (EUC) technologies. This includes decentralized ownership, reduced involvement from central technology functions, uncontrolled inventory, and a lack of understanding of how financial statement information is impacted. EUCs are also known for creating additional security and privacy risks that may not directly impact financial reporting.

Mitigating these risks for RPA will require more effective diligence than what was initially used for EUCs when they were introduced. Hopefully, the profession has learned from the governance mistakes relating to EUC and can prevent similar challenges with RPA. The COSO guidance is an important step in managing the risks. Many of COSO’s risk mitigation actions are familiar to those CPAs specializing in the technology risk management discipline. It is often said that the risks remain the same regardless of technology, but the controls needed to manage the risk will differ. RPA again presents the challenge of obtaining and maintaining board and executive management support. Hopefully management is not blinded by technology’s benefits without fully understanding its risks.

Joel Lanz, CPA, CISA, CISM, CISSP, CFE is a lecturer at SUNY–Old Westbury and an adjunct professor at NYU-Stern School of Business, New York, N.Y. He provides infosec advisory services through Joel Lanz, CPA, P.C., Jericho, N.Y. He is a member of The CPA Journal Editorial Advisory Board.