A recurring bank transaction arrives. The matching rule fires. The ledger is updated. No one decides anything in the moment; the decision was made when the rule was written.
An unusual residual appears. An AI system reads the description, looks at history, and suggests three possible explanations. A human still chooses the next step.
A third system receives the same residual. It searches prior periods, pulls related invoices from another application, checks the vendor master, decides the most likely explanation, drafts an adjusting entry, and either posts it or routes it for approval. The system chose the sequence of actions.
The third case is what changes the control problem.
The important difference is not that the software is “smarter.” It is that the software can decide what to do next and, in some designs, execute that decision through tools. Decision authority moves.
Related: Can AI Do Bookkeeping? What It Can Automate, Where It Fails, and What Still Needs a Bookkeeper
What actually makes something agentic
Deterministic automation follows a predefined path. It may include conditional branches written in advance (if amount exceeds threshold, route to review; if vendor matches an existing rule, post). Given the same inputs and the same environment, it still produces a known sequence of steps. RPA and ordinary API integrations belong here. They are mature, predictable, and still the correct tool for high-volume structured work.
AI-assisted workflows add reading, classification, drafting, or exception triage inside a sequence that remains under human or fixed-process control. The model may propose; the workflow or the accountant still decides the next action.
An agentic system can plan, select tools, maintain intermediate state, and adapt the sequence based on what it finds. The defining feature is not language ability. It is the capacity to choose among actions in pursuit of a goal with limited step-by-step instruction.
Many products currently marketed as “AI agents” sit closer to the middle category. They wrap extraction, classification, and fixed orchestration in agent language. That does not make them useless. It does mean the firm should examine the actual decision authority rather than the label.
Where additional autonomy can earn its complexity
Additional autonomy is most plausible where the work already requires a human to act as the integration layer across systems and exceptions: residual investigation after deterministic matching has finished, multi-source document packets with high format variation, continuous monitoring that packages evidence for review, or close tasks that currently depend on someone remembering to chase the next dependency.
In those cases the potential value is reduced human coordination cost, not the elimination of judgment. The agent can gather, compare, and propose. The accountant still decides material treatment.
For stable, high-volume, structured work—clean bank matching, scheduled report distribution, fixed-format recurring journals—deterministic automation remains cheaper, more predictable, and easier to audit. Adding an agent here usually increases cost and supervision without improving the result.
What changes when the system can act
Once software can choose and execute actions, several control problems intensify.
Cascading errors become possible. An early incorrect classification or tool choice can shape every subsequent step. The failure may not announce itself with a crash.
Permissions and segregation of duties require explicit design. An agent that can read across clients or write to the general ledger collapses boundaries that professional standards expect to remain separate unless deliberately engineered.
Approval gates must be defined by consequence, not by convenience. Routine, reversible actions can stay automated. Material adjustments, unusual items, changes to closed periods, voids, deletions, and any action that moves money or creates lasting legal exposure still need human authorization.
Reversibility matters. Many accounting actions are harder to unwind than they are to perform. An agent that posts first and explains later creates a different risk profile than one that only proposes.
Accountability does not transfer. The firm and the responsible individual remain answerable for the outcome. Observable records of what the system did—inputs used, tools called, actions taken, and any human approvals—are the practical minimum for review and audit. Claims of complete internal model reasoning traces are stronger than what most current systems reliably provide and should not be treated as a settled control requirement.
The wrong starting question for a small firm
“Where can we deploy agents?” is the wrong first question.
The better question is: what decision authority does this workflow actually need?
If the work is stable, structured, and high-volume, start with deterministic automation.
If the work involves reading messy inputs, drafting, or triaging exceptions inside a known sequence, AI assistance is usually sufficient.
Only when the workflow genuinely requires the system to choose among multiple investigative or execution paths based on changing conditions does the extra complexity of an agent become a candidate.
Most 5–30 person firms will extract more value, with less risk, by strengthening the first two layers before introducing open-ended agents. When agents are introduced, the economic test includes the control cost of additional autonomy: the incremental expense of permissions design, monitoring, approval gates, exception handling, reversibility mechanisms, and sustained human review. The autonomy is justified only when the measurable savings or quality improvement exceeds that full control cost.
A practical test
Ask one question of any proposed “agent” workflow:
Does this process require the system to decide, on the basis of intermediate results, which tool or action to take next?
If the answer is no, you probably do not need an agent. You need better rules, better extraction, or better human review design.
If the answer is yes, the next questions become operational rather than technological: what actions is it allowed to take, what must it escalate, how is every consequential step recorded, who owns the output, and how is the arrangement reversed if it goes wrong?
Those are accounting control questions. They existed before agents. Agents simply make them harder to ignore.
Primary / source references supporting factual claims
- Distinction between RPA / deterministic automation, AI-assisted workflows, and agentic systems
- Comparative analyses of RPA vs AI agents vs AI automation (2026 industry breakdowns emphasizing decision authority and failure modes).
- Thomson Reuters technical commentary on RPA (rule-based, no LLM decision-making) versus agentic AI (LLM-supported decision-making and adaptation).
- Maturity and continued suitability of RPA for high-volume structured work
- Multiple 2026 practitioner and vendor-neutral comparisons stating RPA remains preferred for stable, high-volume, structured processes (bank matching, fixed journals, report distribution).
- Maintenance-cost observations (e.g., Forrester-referenced figures on RPA program maintenance share).
- Early agentic deployments and marketing inflation in accounting
- Product announcements and field reports from BlackLine, FloQast, Genpact R2R Suite, Puzzle, Ramp, Digits, Thomson Reuters, Wolters Kluwer, and related close/AP/tax agents (2025–2026).
- Practitioner commentary (e.g., Automaton Agency, Jason Staats / Future Firm) distinguishing true multi-step agents from AI-assisted orchestration marketed as agents.
- Control and risk issues specific to agentic systems
- KPMG guidance on agentic AI workflows in financial reporting (novel risks, segregation of duties, human accountability, treating agents as privileged actors).
- CPA Practice Advisor / COSO-related commentary on agent inventory, named control owners, and replayable evidence (2026).
- Forbes Finance Council and related control pieces on agent authority, mandate, and approval thresholds for consequential actions.
- FRC generative and agentic AI guidance (human-in-the-loop, deficient-output risks, accountability).
- Practitioner accounts of “rogue agent” behavior and the need for plan-first / human-validation layers (Accounting Today, Karbon).
- Accountability remains with the firm / individual
- Consistent professional-position statements across AICPA-related, KPMG, FRC, and practitioner sources that AI does not transfer professional responsibility.
- Observable action/tool logs versus internal reasoning traces
- Control literature emphasizing inputs used, tools called, actions taken, and human approvals as the practical audit minimum; stronger claims of complete internal model reasoning traces treated as not yet a settled or universally available control requirement.
These references support the factual backbone of the article. They do not convert vendor performance claims into established results.




[…] is the same distinction GraphAccount has drawn elsewhere. High transaction automation does not equal completion of the bookkeeping function. Automating work inside the month-end close […]
[…] guidance on agentic systems in the close emphasizes the same controls that apply elsewhere: inventory of what the system is […]