The finance systems & AI brief for controllers and CFOs
Bespoke consulting for finance tech stack strategy, selection, & implementation
Get a personalized roadmap for your finance tech stack. CFOLAYER partners with CFOs and controllers to design, select, and implement the right systems for your scale and business model - eliminating vendor confusion and slow time-to-value.
🏛️ Systems & Stack
Accrual buys Puzzle to add an AI-native ledger and close product (2 minute read)
Accrual, until now a tax and practice management company, is acquiring Puzzle's AI-built general ledger (the core accounting record) and month-end close products to move into client accounting services. Puzzle founder Sasha Orloff and members of his team are joining, and terms were not disclosed. What this means for your stack: another AI-native ledger disappears into a larger platform, so if you were evaluating Puzzle on its own, check what the roadmap and pricing look like under new ownership before you commit. Discuss with ChatGPT →
Eftsure, which verifies a supplier's bank details before you pay them, is buying Relish, which validates vendor data against government and third-party sources and automates invoice processing. The combined company covers 288 billion dollars of annual payments and connects to more than 35 systems including SAP, Coupa, Workday and NetSuite. What this means for your stack: payment fraud controls are consolidating into a single layer that sits between your ERP (the core accounting system) and the bank, which is worth mapping against whatever manual callback process your team runs today. Discuss with ChatGPT →
Anthropic ships a free checker for whether Claude made a file (2 minute read)
Anthropic published a tool that reads Content Credentials, a cryptographically signed note tucked into a file's metadata under the open C2PA standard, and tells you whether Claude produced the image, video or audio file. This is fundamentally different from tools like Pangram, which let you paste text to detect whether text was AI-generated. Content Credentials doesn't validate text at all, which is where most finance work actually lives. What this means for your stack: Interestingly, this is useful for a scanned receipt or an image-based invoice verification but will only identify claude-created content (think expense report fraud detection). Additionally, this will proves nothing about the source/author of a spreadsheet or a memo, so do not let it become the whole of your AI provenance policy. Discuss with ChatGPT →
Citibank settled live dollar transactions on Swift's blockchain ledger on September 3 and SoFi partnered with Payward for always-on settlement, which leaves treasury teams built around business-day liquidity managing money that now moves at 2am on a Sunday. PYMNTS research puts 62 percent of middle-market finance executives already struggling with cash forecasting before the clock changed. What this means for your stack: your approval matrix assumes a person is awake, so the work is turning fixed thresholds into rules a system can apply overnight, including when it should stop and wait for a human. Discuss with ChatGPT →
🤖 AI in Finance
KPMG had one of its AI agents pass AIUC-1, an outside certification that ran more than 900 tests for made-up answers, unsafe content and prompt injection, where an attacker hides instructions in text the agent reads. The KPMG principal who ran it said plainly that certification is evidence of rigor, not immunity from risk. What this means for your stack: when a vendor tells you their finance agent is safe, ask whether anyone outside their company tested it, and ask which failure modes were in scope. Discuss with ChatGPT →
Anthropic, OpenAI, Grok and Gemini all went down in overlapping incidents, knocking out production AI tools at Grasshopper Bank, whose chief technology officer said its multi-provider strategy is not bulletproof when the outage is broad. A former Morgan Stanley AI head argued model providers should now be managed as critical third parties, with abstraction layers and named alternates. What this means for your stack: if an AI tool sits inside a close task or an approval workflow, write down what your team does when it is unavailable, before the month you find out. Discuss with ChatGPT →
Deloitte builds a practice around open-weight AI models (3 minute read)
Deloitte launched an Open Model Engineering practice to help clients run open-weight models, which are AI models whose parameters are published and can be hosted on your own infrastructure, alongside the commercial ones. The firm will hire and certify engineers through 2027 across North America, Europe and Asia Pacific, starting with Nvidia's Nemotron models. What this means for your stack: a hosted-it-yourself model is now a supported option for finance data you cannot send to a third-party service, which changes the conversation with your security team. Discuss with ChatGPT →
⚖️ Regulation & Reporting
FASB proposes 21 clean-up changes to US accounting rules (2 minute read)
The FASB, the US body that sets accounting rules, issued a proposed update covering 21 separate issues that clarify guidance, correct errors and make minor improvements across topics that apply to every reporting entity. Comments are due November 19. Discuss with ChatGPT →
The FASB issued a proposed taxonomy update, meaning the standard data tags companies use to file with the SEC, covering the pending proposal on cash equivalents disclosures and the treatment of certain digital assets. It runs on the same November 19 comment deadline as the underlying rule LEDGER covered in Issue 032. What this means for your stack: if you file with the SEC, the tagging changes are the part your reporting team and your filing agent have to absorb, and they land at the same time as the rule itself. Discuss with ChatGPT →
🛠️ The Practitioner
A working defense against colleagues who paste AI output at you (3 minute read)
Goedecke argues that AI-generated internal documents create an effort asymmetry, cheap to produce and still expensive to read, which he compares to a denial-of-service attack on your attention. His five responses run from asking the sender to stop, to answering with your own AI summary, to moving the exchange to a call where both parties spend the same time. What this means for your stack: the cheapest fix is a length norm on internal updates, because a variance explanation nobody can get through is not documentation. Discuss with ChatGPT →
This article argues that prospects increasingly ask ChatGPT, Perplexity or Gemini to name a firm rather than working through a page of search results, which makes visibility close to binary because an assistant returns a shortlist and nothing else. The author gives five steps, starting with asking every new lead how they found you. Discuss with ChatGPT →
⚡ Quick Links
Ask HN: who is actually running MCP in production (6 min read)
A 198-comment thread of engineers describing what holds up and what breaks when Model Context Protocol servers, the connectors that let AI assistants reach your systems, run in real environments.
Billing friction delays 330 billion dollars of consumer payments a year (3 min read)
A survey of 2,566 consumers and 240 billing decision-makers found 28 billion dollars of monthly payments at risk from bad billing experiences, with 70 percent of providers saying legacy systems limit what they can fix.
🔁 ICYMI
Worth a second look.
Anthropic cuts cache read pricing 75 percent on its Fable model (5 minute read)
Anthropic released Claude Fable 5.1 and a restricted-access version called Mythos 5.1, holding standard pricing flat at 10 dollars per million input tokens while dropping cache reads, meaning the discounted rate for context the model has already seen, from 1.00 dollar to 0.25 dollars per million. Anthropic estimates that cuts effective cost about 25 percent on typical agentic workloads and up to 45 percent on persistent ones. What this means for your stack: if a finance workflow re-sends the same policy documents or chart of accounts on every run, that repeated context just got four times cheaper, so revisit any build you priced out earlier this year.
Why now: Published September 1, just outside this issue's window, and it is the clearest signal yet that the cost of running an agent against a fixed body of finance context is falling fast. Discuss with ChatGPT →

What each AI connector costs you before you type a prompt (6 minute read)
A measured study of eight Model Context Protocol servers, the connectors that let an AI assistant reach a system like a database or a file store, found their tool definitions consume anywhere from about 610 tokens to about 19,050 tokens of the model's working memory before any actual work begins. That is a spread of more than 30 times across servers that look equivalent from the outside. What this means for your stack: every connector you attach to a finance assistant costs context and money whether or not it gets used, so the number of connectors is a budget decision, not just an integration decision.
Why now: Published September 1 and mostly read by engineers, but it prices something finance teams are quietly buying by the dozen and related to a story we ran in a previous issue that outlined the differences in quality of MCP connections offered by different companies. Discuss with ChatGPT →

Building safe MCP servers for your PostgreSQL database (Issue 032, August 19)
This issue has three separate items about what AI connectors cost and how they fail. This is still the clearest write-up of the read-only and templated access patterns that keep one from reaching data it should not. Discuss with ChatGPT →
Tokenomics: as AI bill shock goes mainstream, the key cost driver becomes task complexity (Issue 032, August 19)
Worth rereading beside this week's model pricing and connector cost items, because it explains why the same tool costs different amounts on different days. Discuss with ChatGPT →
📖 Worth The Read
Gustafson published a free, book-length annual planning guide drawing on 104 interviews with finance leaders, covering zero-based budgeting, monthly reforecasting and headcount approvals. The 2026 rewrite adds continuous forecasting from scattered data sources and how token consumption, meaning what your company spends on AI usage, lands in the P&L. What this means for your stack: if AI spend is still sitting in one software line, planning season is when you decide whether it becomes its own driver with a volume assumption behind it. Discuss with ChatGPT →
Deloitte, EY, KPMG and PwC each published client or government work in the past year containing invented academic papers, fake citations or false quotes, despite formal AI governance in place at all four. The practitioners quoted argue hallucinations should be treated as an inevitable risk to be caught before delivery rather than a defect that can be engineered away. What this means for your stack: build the check into the step before the work leaves your team, and size the check to what the output touches, because a footnote in a board deck and a number in a filing do not deserve the same review. Discuss with ChatGPT →
📘 The Glossary
Terms that came up in this issue, in plain language.
Tool poisoning
Hiding instructions inside a tool's own description or metadata so that an AI agent reads them as part of its instructions and acts on them. The user never sees the injected text, and the tool looks ordinary in any interface.
Rug pull (also called tool drift)
When an MCP server or tool changes its description, schema, version or behavior after it has been authorized. The agent then runs a modified version of a tool that differs from the one the user originally approved.
Prompt injection
Text placed where a model will read it, an invoice PDF or a web page or a support ticket, written to be followed as an instruction rather than treated as content. It is the attack the KPMG certification tested against.
Model Context Protocol (MCP)
An open standard for connecting an AI assistant to a system it does not otherwise have access to, such as a database, a file store or an ERP. Each connection is called an MCP server.
Cache read
A discounted rate for context the model has already been given. If a workflow sends the same policy document or chart of accounts on every run, the repeat sends bill at the cache rate rather than the full input rate.
Open-weight model
A model whose trained parameters are published, so an organization can run it on infrastructure it controls instead of calling a vendor's service. Sometimes loosely called open source, though the training data usually is not.
Content Credentials (C2PA)
An open standard for a signed record of how a file was made, tucked into the file's metadata. It travels with the file and can be checked by anyone, which is what Anthropic's new file checker reads.
Hallucination
Output that is fluent, confidently stated and false. In practice it looks like an invented citation, a plausible number with no source behind it, or a quote nobody said.
Workslop
AI-generated work that costs almost nothing to produce and full price to read. The term is doing real work this year because the cost lands on the reader, not the sender.