Thursday, September 24 · 13 min
CFO 2030: earning the right to delegate
Transcript
Koko: Welcome to Koko Knows. I'm Koko, and with me are Sam and Max. This episode is CFO 2030: earning the right to delegate. Six topics, starting here: trust as a capacity to delegate.
Koko: Here's the conditional hypothesis. By 2030, how far a CFO can safely delegate to agents may depend on whether the organization can prove what is authoritative, who is accountable, and whether any action actually completed correctly.
Sam: I'd push on that, Koko. More control infrastructure can slow decisions and add cost. The argument has to be that trust earns speed, not that it replaces it.
Koko: That's exactly the Hackett Group's point, Sam. Sustained controls and segregation of duties are conditions for scaling AI in finance, not obstacles to it. The limit is that their guidance is practitioner synthesis, not a controlled study.
Max: From an operator's standpoint, the hard question is: can you even trace a material cash decision from evidence through approval to outcome right now? Most finance teams I'd expect struggle at the authorization boundary.
Sam: And Deloitte connects technology to operating model and governance as co-requirements, not sequentially. The implication is you can't fund the software and defer the ownership questions.
Koko: NIST's AI Risk Management Framework adds lifecycle governance—voluntary, not law, and not agent-specific. But it anchors the principle: release, monitor, change and retire decisions all need named owners.
Max: So the action is concrete: trace one material decision, name every owner, test an unauthorized attempt. The decision gate is whether the boundary holds before you expand autonomy, not after a failure surfaces.
Koko: So here is the conditional claim: reusable knowledge could be more durable than stacking agents. McKinsey's FP&A piece imagines agents anticipating performance gaps, but an agent that reaches five systems and still misreads a commercial exception from an approved policy is a connectivity win with a judgment gap.
Sam: Foundation Capital's context-graph essay is interesting, but Sam would call it what it is: an investor thesis. No verified return data. And recorded history can bake in bad decisions just as easily as good ones.
Max: Max would add: maintenance costs are real. Who owns the definitions when the policy changes mid-year? That's not a technology question.
Koko: Exactly why Dehghani's data mesh framing on MartinFowler.com matters: explicit domain ownership, data as a product, federated governance. W3C PROV-O gives you a portable vocabulary for recording who acted, on what, and when. Neither proves returns, but both give you a testable structure.
Sam: What changes the hypothesis? If a second domain has to rebuild definitions from scratch, the reuse argument collapses. That's the signal worth watching.
Max: SAP's knowledge graph direction is vendor architecture, not proof. The deployment scope still needs independent verification before any commitment.
Koko: The action is concrete: CFO and CDO co-fund one decision domain—agreed definitions, lineage, policy versions, a named product owner, outcome measures. Scale only after reuse visibly improves the economics of a second case. By 2030 you want to know which decisions depend on that layer. By 2035 it could be strategically important, or interoperability economics could make it irrelevant.
Sam: And that's the right gate. Not how big the document collection is—whether reuse actually reduces expert rework. Which brings us to where the interface is heading and what accountability looks like when the screen disappears.
Koko: Here is where the interface question gets economically sharp. Headless SaaS and agent protocols like MCP and A2A could quietly shift bargaining power toward whoever owns the context layer—definitions, permissions, decision history. A CFO might not notice until exit costs make that dependence visible and expensive.
Sam: An open protocol does not make application semantics interchangeable, Koko. SAP's architecture direction and Salesforce's API docs show what integration patterns exist, not what is deployed at scale. Neither settles what a contract actually lets you take with you when you leave.
Max: That is the operating risk. You can test the connector; what is harder to test is whether the decision record travels with you. Oliver Wyman flags portability and audit rights as procurement requirements to negotiate before dependence grows, not after.
Koko: McKinsey's agent-economics interview adds a cost dimension: measure total cost per accepted outcome, including rework. If context is a vendor's proprietary asset, switching economics could erode that unit-cost advantage quickly.
Sam: MCP's own security documentation flags authorization risks at every tool connection. A working connector is not a financial delegation policy. The ledger, approval record and reconciliation still require a design decision by someone accountable.
Max: So the practical test: run one real workflow, reconcile what the orchestrator requested against what actually posted, export the evidence and price swapping one supplier. That exercise is more informative than any architecture diagram promising universal orchestration.
Koko: The decision gate: if evidence cannot be exported cleanly, or exit costs prove material, freeze expansion until contracts address portability and audit rights. By 2030 this shapes capital allocation; by 2035 it determines whether that context layer is a reusable enterprise asset or a sunk cost.
Koko: Here is the workforce hypothesis. By 2030, finance talent could shift toward decision design, knowledge ownership and exception judgment. By 2035, the ability to supervise and account for automated work may matter more than executing it. That is a conditional view, not a forecast.
Max: The learning path is the tension. If automation removes the reconciliations and variance work that used to teach junior staff how the business works, a team could hit every productivity target and still hollow out the pipeline that develops the next controller.
Sam: Gartner surveyed 204 finance leaders and found more weight on productivity than decision quality in AI projects. That gap matters because training attendance and hours saved do not establish that judgment improved or that capacity was actually redeployed.
Koko: EY's 2026 CFO survey found a gap between value-creation ambition and leadership action across 1,610 finance leaders. The practical move is to map which tasks are changing and redesign supervised practice on real workflows before the old learning path disappears.
Max: IBM's execution research connects reported benefits to operating maturity, not software alone. So the action is concrete: map changed tasks, build supervised-judgment exercises into real workflows, and track adoption, decision quality and redeployment as separate measures.
Sam: What would change the hypothesis? If decision quality stays flat while productivity rises, or exception volume climbs as agent scope expands, the talent shift is not working and you would need to repair the learning design before extending automation further.
Koko: The decision gate ties it together: before booking any workforce efficiency benefit, name how released capacity will be used and how proficiency will be demonstrated. Without that, the CFO 2035 stranded-intelligence scenario becomes a real operating risk, not a planning abstraction.
Koko: Capital must move as evidence changes — that's the hypothesis here. Physical AI, quantum and compute are accelerating, but the CFO 2035 reading reminds us that demonstrations and deployments are different things. Fixed roadmaps may be the wrong instrument entirely.
Max: Operationally that's real. The IEA flagged that lower energy per AI task can still mean rising total consumption. If you're committing to a large physical-AI fleet, your site power assumptions could be wrong before the ink dries.
Sam: And Gartner's physical-AI abstract — we only accessed the abstract — already cautions that hype and risk outweigh business outcomes right now. A compelling demo isn't audited fleet economics.
Koko: Right, so the CFO 2035 framing separates foundation funding, bounded adoption and frontier options as distinct capital buckets with evidence-based gates — not one committed roadmap.
Max: Quantum fits that perfectly. DARPA is actively testing whether quantum systems can exceed classical cost by 2033. That's a program horizon, not a deployment date. Options, not bets.
Sam: Post-quantum security is the one piece that doesn't wait for quantum advantage. NIST says standardized algorithms are available now. That migration is a controls decision, separate from the quantum computing business case.
Koko: So the action is concrete: the CFO and CISO run a cryptographic exposure inventory now, and any physical-AI pilot must show full operating costs against a practical alternative before rollout is approved.
Max: The decision gate matters — expand, pause or exit tied to evidence, not a calendar. That connects directly to how governance has to work as an operating capability, which is where we're heading next.
Koko: Closing hypothesis for Koko Knows CFO 2030: governance could shift from a periodic review to enforcement at every material agent action. If you can't show why an action was allowed and demonstrate that a prohibited one is blocked, you haven't delegated — you've lost track. That's the CFO Future Guide test for earning the right to delegate.
Max: Vendors including Workday and Microsoft are announcing agent registries and control planes. The gap worth testing: a dashboard showing which agents exist is not the same as enforcement inside the system that actually moves money or commits a counterparty.
Sam: Sam's challenge: NIST's AI Agent Standards Initiative is a work program, not a finished regime. Voluntary frameworks aren't law. The CFO can't price future regulatory requirements from a vendor roadmap or a standards announcement.
Koko: That's exactly the caveat. The hypothesis changes if jurisdictions pass binding authorization rules with audit trails, or if independent audits confirm that vendor control planes block prohibited actions — not just log them after the fact.
Max: Hackett's practitioner synthesis treats governance as funded operations, not a launch task. So if an enterprise were scaling agent workflows, the governance cost — named owner, tested rollback, recurring review — would need its own budget line from the start.
Sam: Without that, the Stranded Intelligence scenario becomes likely: capability expanding faster than the controls behind it, and efficiency gains absorbed by unplanned review and remediation work.
Koko: The action now: one owner, an agent register with permissions and obligations, tested recovery, and a gate tied to incident evidence or obligation changes. That discipline connects 2030 to 2035. The CFO 2035 reading on CFO Future Guide lays out the four conditional scenarios where governance is the operating thread through all of them.