Most finance teams never waited for permission to start using generative AI. Today, analysts paste reconciliation data into ChatGPT. Controllers’ draft memos with Copilot. No one approved a rollout plan; it just happened, one browser tab at a time, and it continues to expand the same way.
This is the adoption gap sitting inside most finance functions today.
Generative AI in finance is spreading through informal, everyday use, well ahead of any real fluency in how to govern, document, or trust what it produces. Organizations that deploy agentic AI directly inside Sarbanes-Oxley (SOX) controlled processes, where the margin for error is thin, keep finding the same pattern.
Adoption is not the hard part. Fluency is.
Closing that gap requires more than better tools or stricter policies. It requires finance professionals who understand precisely where AI belongs inside a controlled process and where it does not. That kind of judgment does not come from general AI awareness; it comes from function-specific AI training that connects AI capabilities to the realities of financial reporting, SOX compliance, and audit readiness.
What is the generative AI adoption gap in finance, and why does it matter?
The AI adoption gap is the distance between organizations using AI and those capturing real value from it. The value comes from the operating model, not the technology itself.
- Adoption is widespread, but value is not. According to McKinsey’s State of AI 2024 research, 72% of organizations have adopted AI in at least one business function.
- People and process drive the real return, not the technology. BCG’s 10-20-70 rule holds that successful AI transformation is 70% people, process, and operating model change; 20% technology and data; and only 10% algorithms.
- Only 6% of companies have made enterprise AI genuinely work at scale. Scale AI’s Six Percent Report, a 2026 study of nearly 500 senior AI decision-makers conducted with Reuters Insights, found that most organizations are still far from realizing enterprise-wide impact.
For finance, this gap carries a compliance dimension that most functions have not fully reckoned with. Every general ledger entry, reconciliation, and management judgment touched by an AI tool is within the scope of SOX Section 404 and internal control over financial reporting (ICFR). An analyst using an ungoverned tool to draft a journal entry memo creates a control gap for the moment output enters the record, regardless of whether anyone intended it that way.
CrossCountry’s research, conducted in partnership with the Financial Education and Research Foundation (FERF) found that nearly half of organizations (46%) lack formal AI governance structures, and only 7% of finance leaders report being “very confident” in interpreting AI outputs. Widespread use, minimal governance: that combination is adoption without fluency.
Why does ungoverned AI use create SOX risk?

Ungoverned AI adoption fails in recurring ways, each with a distinct SOX exposure.
- Unvetted outputs enter the financial record.
- No audit trail for AI-assisted judgment.
- Inconsistent tool use across a shared process.
None of these failures happened because of negligence or a bad tool. They happen when adoption outpaces governance. “Our team is already using AI” is not the same statement as “our AI use is under control.”
What can governed agentic AI deliver in finance?
Governed agentic AI produces measurable, auditable results, not just efficiency anecdotes. The difference shows up clearly when AI is built into the control environment from the start, rather than layered on top of it.
Across recent SOX-focused agentic AI deployments, success metrics include:
- 500 hours recovered annually through automated control execution and testing
- 100% detection accuracy on targeted control exceptions
- 60% reduction in manual document preparation time
- 95% consistency in documentation output across control cycles
- 8% reduction in overall process tim
Source: CrossCountry Consulting AI Innovation Lab, SOX IT testing engagement.
These outcomes were a result of work in the AI Innovation Lab where CrossCountry operates multiple specialized agents on an internally built orchestration layer that functions as a command center across all agent tasks. An agent that flags an exception and logs its reasoning is fundamentally different from a chatbot and an analyst that consults. One is a controlled process. The other is a liability waiting for the next audit cycle.
The technology was not the variable that separated a 6% enterprise success rate from a 100% detection rate. Workflow design, governance, and the people running the process were.
Why fluency, not tools, separates finance functions that get AI right
The gap between AI adoption and AI value is, at its core, a judgment gap. Finance professionals operate inside some of the most controlled, highest-stakes workflows in any organization, where every output has an auditor, regulator, or board waiting behind it. General AI awareness does not equip them for that environment.
Knowing that a tool can summarize a document is not the same as knowing whether that summary belongs in a workpaper, who is responsible for verifying it, and how to document that verification in a way that holds up under ICFR scrutiny.
This is why function-specific AI fluency has become an operational priority, not a training initiative. Finance teams that develop genuine AI fluency are better positioned to govern existing tool usage, reduce control gaps created by informal adoption, and make credible decisions about where AI should be embedded. For a deeper look at why AI fluency has become a strategic competency for finance leaders, QuantumRise outlines the business case.
Elevate your finance team’s AI fluency with training solutions
The organizations closing the adoption gap are not simply deploying better tools. They are building the institutional judgment to use those tools responsibly.
CrossCountry and QuantumRise built the Applied AI Fluency for Business workshop to close that specific gap. This one-day program takes finance, accounting, and risk professionals from AI foundations through hands-on workflow redesign, with SOX governance built in from the start.
- AI foundations: how large language models (LLMs) and agents work, and where they fail.
- Hands-on lab: real finance workflows applied inside a persistent AI project.
- Agentic workflow redesign: mapping a live process, identifying where AI fits, and building SOX governance in from the start.
Participants leave having redesigned one of their own workflows, with governance considered from the outset instead of retrofitted later.
The gap between finance functions that get AI right and those that don’t will not close through better tools. It closes through people who know precisely where those tools belong. Give your team the foundation to use AI with confidence.
About this series: This article is part of a joint thought leadership series developed by CrossCountry Consulting and QuantumRise. Together, the two firms offer AI for the Office of the CFO, a practical AI workshop designed specifically for professionals in Finance, Accounting, and Risk Management. To learn more, visit crosscountry-consulting.com/ai.
Frequently asked questions
What is the difference between AI adoption and AI fluency in finance?
AI adoption means employees are using AI tools, often informally. AI fluency means the organization understands where those tools fit inside controlled processes, has documented that usage, and can defend the outputs under audit. Adoption without fluency is where compliance risk concentrates.
Does using generative AI in finance create SOX compliance risk?
Yes, when AI touches a process inside ICFR scope without a defined review step, audit trail, or consistent usage standard across the team performing the control. The risk comes from the absence of governance, not from AI itself.
What results has CrossCountry achieved with agentic AI in finance?
In SOX-focused deployments, our agentic AI solutions have recovered 500 hours annually, reached 100% detection accuracy on targeted control exceptions, cut manual document preparation time by 60%, and improved documentation consistency to 95%. Learn more about our AI Strategy and Transformation capabilities.
The internal audit function most valuable to leadership does more than report problems after the fact. It helps management see risk while decisions can still be shaped. That is the real test of a modern internal audit strategy, and it is a different test than conformance.
The 2024 Global Internal Audit Standards raised the bar for the profession. Across 15 principles, the Standards define the purpose of internal auditing as strengthening an organization’s ability to create, protect, and sustain value through independent, risk-based, and objective assurance, advice, insight, and foresight.
Three principles are especially relevant to that ambition: Principle 9, Plan Strategically; Principle 11, Communicate Effectively; and Principle 12, Enhance Quality. Conformance with them establishes a strong foundation. The real opportunity lies in how functions can use this foundation to deliver even greater strategic value.
What the Global Internal Audit Standards require
The Global Internal Audit Standards are the professional framework of the Institute of Internal Auditors (IIA). They require chief audit executives (CAEs) to align assurance activities with organizational strategy, risk, and governance, and the 2024 update raised expectations across ethics, board reporting, and quality management.
Meeting those requirements is meaningful and reflects genuine professional rigor. But conformance is most valuable as a foundation, not a finish line. A function can satisfy every Standard and still leave real opportunity on the table if it has not translated that foundation into strategic relevance, proactive risk coverage, and insight leadership can act on.
Why is this a leadership issue, not just an audit issue?
Internal audit’s scope has grown well beyond financial controls. Technology risk, third-party exposure, ESG reporting, and AI governance are core areas of coverage, each carrying real strategic weight for finance, operations, and risk leadership alike.
That makes the design of the assurance function a concern that reaches well beyond the audit team, because it shapes what leadership sees, and when.
Audit committees feel this too: they are asking harder questions about coordination across audit, risk, compliance, and cyber teams, not just about individual findings.
Five moves that turn assurance into foresight
Two internal audit functions may both conform with the Standards yet differ significantly in how strategically they operate. The difference shows up in five behaviors, each one an expression of what the Standards make possible when a function commits to building on its foundation rather than resting on it.

- Align.
Keeping the audit plan aligned to current and future business priorities is one of the clearest ways internal audit demonstrates strategic value. Standards 9.2 and 9.4 reinforce this directly: planning should reflect the organization’s strategic objectives, key initiatives, and evolving risk profile. Functions that build their plans around where the business is headed, rather than where it has already been, are better positioned to provide insight when it matters most.
- Connect.
Independence is essential; isolation is not. Standard 11.1 recognizes that ongoing communication is foundational to an effective internal audit function. That means staying connected to business and functional leaders throughout the year, not only during the annual risk assessment, or at the start of individual audits. Regular engagement lets internal audit see change as it forms, and adjust coverage before risk crystallizes into a finding.
- Evolve.
The same discipline applied to auditing the business should be applied to the audit function itself. Quality and maturity assessments create natural opportunities to evaluate whether the function is keeping pace, but so do strategy shifts, leadership changes, transformation initiatives, and new risk categories. Evolving also means asking whether the operating and resource models still fit: whether internal capabilities are being developed, whether technology is enabling the team, and whether the right mix of subject-matter specialists, guest auditors, co-sourcing, or targeted external expertise is in place.
- Integrate.
Coordination across assurance providers is the foundation, reinforced by Standard 9.5, but integrated assurance is the broader goal. That means actively connecting risk intelligence, coverage decisions, reliance opportunities, and identified gaps across internal audit, risk, compliance, cyber, and other assurance providers. When those views are integrated rather than parallel, leadership gets a clearer picture of where the organization stands and where blind spots remain.
- Anticipate.
The Standards’ emphasis on insight and foresight is not about predicting every risk before it arrives. It is about building the habits and connections that let internal audit recognize signals early and adjust assurance as the business changes. Stakeholder conversations, regulatory developments, and technology roadmaps all carry information about where risk is moving. Functions attuned to those signals reorient coverage proactively, giving leadership a view of what is coming, rather than an accounting of what has already occurred.
Together, these five moves shift internal audit from a rear-view mirror to a forward view. That gives management and the board a function that can inform decisions as they are being made, and provide greater insight into what lies ahead.
What a foresight-driven function looks like day to day
Management, board, and audit committee stakeholders should expect specific, observable differences from a foresight-driven function:
- Dynamic planning tied to current strategy, emerging priorities, and evolving risk, rather than a static annual document.
- Ongoing business connectivity with management and functional leaders throughout the year.
- Integrated assurance across audit, risk, compliance, and cyber functions, with coverage gaps and overlaps actively identified and addressed.
- Enterprise-theme reporting that surfaces patterns and risk signals across engagements, not just findings from individual audits.
- Quality management embedded throughout the year, not only at scheduled review time.
Certain moments naturally invite this kind of evolution: a new corporate strategy, a leadership transition, an acquisition, a major transformation, or a scheduled external quality assessment. Each is a chance to ask a harder question than “are we in conformance?” The better question is whether the assurance model is sound enough to trust with new technology, new risk, and new strategic bets.

The foundation, and what gets built on it
The Standards give internal audit a foundation. The strategic value comes from what the internal audit function builds on top of it. Functions that stay connected to the business, evolve as the risk landscape shifts, integrate assurance across the enterprise, and anticipate risk early do more than produce clean assessments. They help management navigate change and make better decisions while there is still time to act.
CrossCountry Consulting works with internal audit functions at every stage, whether the need is to evolve the operating model, strengthen assurance integration, or position internal audit to support leadership through strategic change.
This is the first article in a three-part series on building a foresight-driven internal audit function. Part two examines integrated assurance in depth. Part three explores where AI fits, and where it does not.
Coupa Release 46 is rolling out, and three items in this release carry real consequences if ignored. Two are hard compliance deadlines with no grace period. The third affects nearly every Coupa InvoiceSmash customer and triggers a permanent, irreversible configuration change if you wait too long.
It is a short window to act before Coupa acts for you.
To ensure your team is prepared for these critical deadlines, watch our webinar for an in-depth walk-through of the necessary actions.
R46 at a glance: what you need to know
| Chart of accounts validation | No impact in R46, but mismatches between custom field lookup values and requisition line COA will block submissions when Release 47 goes live. Start the audit now. |
| France e-invoicing clearance | French VAT ID registration and clearance invoice retrieval activation required by September 1, 2026. |
| InvoiceSmash to SuperSmash migration | Mandatory by September 2026. Coupa auto-migrates any customer who has not self-migrated, and the configuration is permanent with no rollback. |
What does Coupa Release 46 mean for your organization?
Coupa Release 46 (R46) is the platform’s scheduled software update, rolling out across three test and production waves between August 17 and September 18, 2026. It touches procurement, invoicing, mobile, Navi AI agents, supplier management, expenses, and inventory.
Three items require action before or shortly after upgrading: a chart of accounts validation coming in Release 47, a set of international e-invoicing mandates, and a mandatory InvoiceSmash to SuperSmash migration. The rest of the release is feature enhancement focused.
InvoiceSmash to SuperSmash: a mandatory migration with no rollback
InvoiceSmash in Core, also called SuperSmash, moves invoice extraction directly into Coupa Invoicing instead of a separate interface. Migration becomes mandatory by September 2026.
This affects nearly every Coupa invoicing customer, not just those with international operations. If you have not self-migrated by the deadline, Coupa upgrades your environment automatically during this release. Any invoices mid-process at the time of transition get reprocessed. Once enabled, the configuration is permanent. There is no rollback.
The action required: plan and execute your migration before September 2026. Do not wait for Coupa to do it for you. Need support? CrossCountry can support this migration for you so your team is not caught off guard by the auto-upgrade.
Chart of accounts validation is coming; start the audit now
Release 47 will introduce a hard validation rule: custom field lookup values must match the chart of accounts (COA) assigned to the requisition line, or the system will block submissions outright.
That rule does not take effect in this release, R46, but the preparation work should start now. Coupa Support can temporarily bypass the block, but that workaround only exists through Release 46.7, meaning it will not be available once Release 47 is live.
Two things need attention before that happens:
- Audit custom field lookup values across every requisition form.
- Update lookup value COA scope or adjust defaulting rules anywhere a mismatch could occur.
If you skip this audit you will find out about mismatches through blocked requisitions. There will not be any warning emails or notifications.
E-invoicing mandates and updates: three deadlines requiring immediate action

Prepare for release management, don’t just react
R46 includes some meaningful enhancements, including landed cost visibility at the line level, PO PDF snapshots for stronger audit support, and a GenAI-powered PO auto-pairing capability that can automatically match invoices with a high degree of confidence and multiple AI agents. For organizations already progressing through their Coupa AI adoption roadmap, these capabilities are natural next steps and worth evaluating as part of future optimization efforts.
What stands out the most is not any single feature; it’s the continued pace of change. Coupa is advancing invoice processing controls, data validation requirements, and compliance obligations all at the same time. That creates real value but also reinforces why organizations need a deliberate release management strategy rather than a reactive approach.
The companies that get the most from the platform are not the ones scrambling to understand release impacts after they arrive. They’re the ones reviewing upcoming changes early, assessing business impact, aligning stakeholders, and building release activities into their roadmap.
R46 is another reminder that release planning is not just about adopting new features. It’s about staying ahead of operational, compliance, and integration changes before they become urgent. The deadline dates will arrive whether an organization is ready or not, which makes proactive planning just as important as the functionality itself.
Next steps
Polling from a recent Coupa release briefing showed most attendees were unsure when their organization last ran a health check or regression test against a new release. That’s a gap organizations should be focused on closing.
The risk comes from not knowing they exist until something breaks, or until Coupa auto-migrates your environment. A structured Coupa release management process, supported by a partner with deep platform experience, is the most reliable way to close that gap. Organizations investing in Procurement & Cost Transformation initiatives will also want to factor these deadlines into any active workstream timelines.
To assess your readiness for Coupa Release 46 and build a plan around the deadlines that matter most, contact CrossCountry today
Frequently Asked Questions
What is the Coupa InvoiceSmash (Super Smash) migration?
InvoiceSmash in Core, also called Super Smash, moves invoice extraction directly into Coupa Invoicing instead of a separate interface. Migration becomes mandatory by September 2026, Coupa automatically upgrades any customer who has not self-migrated by then.
What happens if I miss the chart of accounts validation audit?
Nothing breaks in Release 46 itself. However, once Release 47 is deployed, any mismatch between the chart of accounts associated with a custom field lookup value and the chart of accounts on the requisition line will prevent the requisition from being submitted. Consider Release 46 your grace period to identify and correct any discrepancies, as this validation will be enforced in the next release and no proactive alerts will be provided.
Does the InvoiceSmash migration affect customers without international operations?
Yes. This migration affects every Coupa invoicing customer regardless of geography. It is not limited to organizations with international e-invoicing requirements.
Most asset management organizations are past the question of whether to adopt agentic AI. The real question sitting in front of CFOs, COOs, and CTOs right now is narrower and harder: can the organization prove the reliability of its AI-assisted work when an auditor, examiner, or investor asks how a number was produced?
What is agentic AI, and why does it matter to asset managers?
Agentic AI differs from traditional automation. While the traditional approach executes a single rule or answer a single prompt, an agent can carry out a multi-step task, such as validating NAV inputs, flagging exceptions, and drafting a variance memo, while routing judgment calls to a qualified person at defined checkpoints.
That distinction matters because asset management operations are full of multi-step, judgment-heavy processes. NAV calculation pulls from fund administrators, pricing services, and portfolio systems, then requires a human to explain what moved and why. Portfolio valuation requires normalizing inconsistent data before a committee can even review it. These aren’t single-click automations. They’re workflows that agentic systems are built to manage.
Adoption is accelerating, but most organizations haven’t crossed into production. Mercer’s 2026 AI in Asset Management Survey found 55% of asset managers have AI integrated into at least one investment process. However, 27% are still in the pilot stage, and 18% haven’t started.
The gap between experimenting and scaling is where real opportunity lies, but it’s also where governance determines whether AI initiatives succeed, stall, or create unintended risks.
Why governance is the real barrier to scale
Most AI efforts stall between the demo and production. Data is worse than promised. Controls arrive late, if at all. No one can quantify the value of the pilot. For a regulated asset manager, that’s not just an inconvenience. It’s a liability.
The pressure is concrete. An auditor wants the evidence chain behind a reported NAV or a hard-to-value mark. A limited partner presses on how a fee was allocated. An examiner asks for documented controls over any AI agent touching a material process. The SEC has already brought several “AI washing” cases against advisers who marketed AI capabilities they didn’t have, resulting in enforcement actions and billions of dollars in penalties since 2021.
Organizations that plan for governance from the start see a different pattern. Portfolio risk and value become visible in real time. Audit readiness comes from a documented AI inventory instead of a scramble. Governance, done well, is not a brake on adoption. It’s what makes adoption defensible enough to scale.
Build AI Agents with Governance
In most organizations, adoption has consistently outpaced oversight. The better approach builds controls into the first agent rather than bolting them on after go-live. Every cluster keeps a qualified person in the loop at defined checkpoints, because a NAV, a valuation, or a filing still must be defended by a person when the auditor, examiner, or investor asks.
This approach follows the National Institute of Standards and Technology (NIST) AI Risk Management Framework and the governance guidance from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). For a regulated manager, that’s the difference between a demo and a capability that holds up in an SEC exam, an external audit, and investor diligence.
How an AI Jumpstart proves value
Rather than launching a multi-month program, a Jumpstart serves as a proof of value to deploy a single agent on an organization’s own data and systems and produces a concrete deliverable in the first few weeks. That might be a data quality scorecard, a NAV variance memo explaining what moved and why, or a valuation lineage report tracing every mark back to its source.
You see real output before committing to anything larger. From there, the agent expands into a full cluster, sequenced by an orchestrator that decides what runs and in what order. A cleanup that used to happen once becomes a standing process. In portfolio valuation, for example, normalization that consumes days of manual work becomes a step that runs on demand, with a documented trail behind every number.
The AI Field Guide for Asset Managers
To help asset managers build AI into their operations, CrossCountry created the AI Field Guide for Asset Managers. This resource provides a map of where operations break down across the fund lifecycle and how a risk-tiered governance model turns AI adoption into a defensible, repeatable advantage, rather than a compliance afterthought.
The AI Field Guide maps 12 agentic clusters across three areas of the operating model:
- Revenue, valuation, and data integrity: NAV calculation, fee and expense allocation, portfolio valuation, and the data foundation underneath all of it.
- Reporting, performance, and liquidity: the close, investor and board reporting, portfolio monitoring, and capital planning.
- Governance, compliance, and treasury: controls monitoring, investor and legal obligations, regulatory operations, and treasury.
Each cluster is built for how asset managers operate, including legal entity hierarchies, investor agreements with bespoke terms, and the audit and regulatory rules layered onto every process. The fixes are specific because the operational breaks are specific.
To understand how a Jumpstart fits within a broader AI Strategy & Transformation roadmap, the field guide maps the full sequence from pilot to production.
Get started
Most organizations begin with a short discovery session, select one or two clusters tied to the outcome that matters most, and stand up a Jumpstart in weeks. The agents are aimed at the numbers that decide a fund’s standing: NAV accuracy, the returns investors underwrite, operating margin, regulatory readiness, and the length of the close.
The question is no longer whether agentic AI belongs in asset management operations. It’s which break to fix first, and whether the output can hold up when it’s challenged.
For asset managers, the next step is not another pilot. To launch your own Jumpstart, contact CrossCountry today.
CrossCountry Consulting recently hosted a webinar on Coupa AI that drew registrations from 147 companies. Of those, 83% were already live on Coupa. When we polled attendees on where their organization stood on AI maturity, most selected a familiar answer: manual processes.
That response is worth pausing on. Coupa AI and Navi agents lie dormant inside most Coupa environments, available and ready to work. The interest is genuine. The activation is not. Most finance and procurement teams have the capabilities available but aren’t yet putting them to use.
That gap, between AI availability and AI activation, is the real challenge. If your team is live on Coupa but hasn’t engaged the AI features already in your environment, you aren’t behind. You’re in good company, and the path forward is more accessible than it may appear.
What is Coupa AI, and why does it matter now?
Coupa AI is the set of embedded artificial intelligence capabilities built directly into the Coupa platform, branded collectively as Coupa Compose.
It includes Navi agents, Agent Studio for building custom agents, and tools to connect Coupa to external AI solutions like Tonkean. Tonkean serves as an intake and orchestration layer, applying AI to capture procurement needs and orchestrate workflows and systems across the source-to-pay process
This matters now because the features are no longer theoretical. Navi agents and broader set of Compose capabilities were demonstrated broadly at Coupa’s Inspire conference. Most established Coupa customers already have access. The question has shifted from “does this exist” to “why haven’t we turned it on.”
Industry data backs up what CrossCountry sees in the field: McKinsey research on agentic AI in procurement found that organizations can move from prototype to pilot in weeks and from pilot to scale in under a year, once activation actually starts.
A Navi agent in Coupa performs a specific task using a language model, memory, and, as needed, direct access to your Coupa data, knowledge documents and external tools. Conversational agents respond when a user asks something in the chat window, similar to asking a question and getting an answer that may include documents, links, etc.
Autonomous agents run on their own, on a schedule or trigger, with no prompting required.
Why are most Coupa customers not using these features yet?
The barrier isn’t curiosity, and it isn’t the technology. It’s not knowing where to start. Given the multitude of AI options available and the rapidly changing landscape, many companies have been unsure about where to start. Coupa presents a practical way to quickly start the journey and expand in scope and sophistication over time.
Procurement, AP, and IT teams are the ones exploring Coupa AI today, often as small, self-organized groups. Executive sponsorship remains rare, a pattern that lines up with EY’s 2025 Global CPO Survey finding that 80 percent of CPOs plan to deploy generative AI within three years, while only 36 percent have a meaningful implementation today. That gap between intent and execution changes where adoption actually begins: with the people running day-to-day workflows, not a top-down transformation mandate.
A few patterns show up consistently in the field:
- Teams don’t know what’s already available. Navi agents ship inside the Coupa UI, but many admins haven’t explored Agent Studio or the out-of-the-box agent library.
- Governance questions stall momentum. Approval thresholds, audit trails, and “what is this agent allowed to do” are common blockers, and they’re reasonable ones. Gartner research shows that 74 percent of procurement leaders say their data isn’t yet AI-ready, so this hesitation is widespread, not unique to any one organization.
- Early experiments don’t get past the pilot. A team tries one agent, doesn’t see immediate lift, and moves on.
None of these are technology problems. They’re sequencing problems.
How should you sequence Coupa AI adoption?
Treat activation in three stages: crawl, walk, and run. Each stage builds on the trust and familiarity established in the one before it.
- Crawl: Turn on out-of-the-box Navi agents. This is the lowest lift available. Conversational agents like the Analytics Agent, Document Discovery Agent, and Supplier Discovery Agent work entirely inside the Coupa UI with no custom build required. Every agent action generates an activity log, so your team can see exactly what the AI did and why, before trusting it with more.
- Walk: Build one or two custom agents in Agent Studio. Once your team trusts the audit trail, use the low-code Agent Studio platform to build agents tied to a specific workflow. A Sourcing Consolidation Agent can scan open requisitions, group overlapping demand, and draft a sourcing event for buyer review. A Discount Optimizer Agent can evaluate early-payment terms against a defined hurdle rate and flag which invoices are worth paying early.
- Run: Connect to external AI and Orchestrate across workflows. Tonkean chains multiple agents into a single end-to-end process, passing context between steps instead of routing everything through email or manual triage. Tonkean can also extend beyond Coupa to orchestrate across wider eco-system of S2P systems and AI solutions connected via Coupa’s Model Context Protocol that connects Coupa to your broader enterprise AI stack, when that need arises.
- This orchestration discipline is the same approach CrossCountry Consulting applies in its Auto Accrual AI solution, which uses the same Coupa data foundation to automate month-end accruals. This removes manual effort at one of the most time-sensitive points in the financial close.
Most organizations stall at step one, not because step three is too hard, but because nobody took step one.
How does CrossCountry approach Coupa AI activation?
CrossCountry Consulting has been a Coupa Premier Partner since 2014, with practitioners who have worked inside the platform since release six. As the highest-volume Coupa implementer, CrossCountry brings unmatched depth to AI activation: this is a hands-on challenge, not a documentation problem.
The approach starts inside your actual Coupa instance, not a generic sandbox. During a recent client session, a Requisition Creation Agent was built and tested in under a day, a timeline that reflects how quickly these tools move once someone has done it before.
Every agent recommendation ties back to a specific value lever: e.g., sourcing effectiveness, spend control, supplier compliance, or payment timing. That link between the agent and the metric it moves is what turns a demo into a business case.
What should you look for in an activation partner?
Look for a partner who works inside your live Coupa environment, not just around it in slide decks. The right partner should be able to show you a working agent, not just describe one.
Prioritize partners who can map each Navi agent or Agent Studio build to a measurable outcome, whether that’s spend savings, cycle time reduction, or working capital release. This kind of mapping is core to CrossCountry’s Procurement & Cost Transformation approach: activation without a value connection is just a feature tour.
Confirm the partner trains your internal team as part of the engagement. The goal isn’t a one-time build. It’s an admin team that can maintain and expand the agent library after the engagement ends.
Frequently asked questions
What Coupa AI features are available right now?
Existing Coupa customers already have access to Navi agents, both conversational (like the Analytics Agent and Supplier Discovery Agent) and autonomous (like the Discount Optimizer Agent). Agent Studio, for building custom agents, and Tonkean, for orchestration, are also generally available..
What is a Navi agent, and how do I use it?
A Navi agent is a task-specific AI tool built into Coupa. Conversational agents respond when you ask a question in the chat window. Autonomous agents run automatically on a schedule or trigger, such as creating a payment batch every Monday, with no prompting needed.
Do I need IT to enable Coupa AI features, or can procurement and AP do it ourselves?
Out-of-the-box Navi agents typically require no IT involvement and can be activated directly by procurement or AP admins inside the Coupa UI. Business users can build custom agents using the low code Agent Studio, though more complex builds (e.g., incorporating API connections) benefit from technical support
Which Coupa AI features are worth turning on first?
Start with out-of-the-box conversational Navi agents, since they carry the lowest implementation lift and build trust through visible audit trails. From there, move to one or two custom agents tied to a specific, high-value workflow like sourcing consolidation or discount optimization.
How do we address governance concerns before scaling adoption?
Start with agents that generate a full activity log, so approvals, audit trails, and agent permissions are visible from day one. Governance is easier to build into a small, contained pilot than to retrofit later.
To activate the Coupa AI already sitting in your instance, contact CrossCountry today.
Q2 2026 brought one of the most active regulatory quarters in recent memory. Federal and state agencies issued final rules, proposed frameworks, and executive orders in rapid succession, some revising supervisory standards that had stood for decades. Two areas demand immediate attention: how examiners evaluate financial institutions, and what the GENIUS Act now requires of stablecoin issuers.
Why did regulators rewrite three foundational supervisory frameworks in one quarter?
Three foundational frameworks changed in a single quarter: CAMELS ratings, model risk management guidance, and the supervisory treatment of reputation risk. Together, they signal a clear shift toward demonstrated financial risk management over procedural compliance. Institutions that have relied on strong process scores should reassess their supervisory standing now.
FFIEC proposes first CAMELS overhaul in 30 years.
The Federal Financial Institutions Examination Council’s proposed revision shifts examiner focus on material financial risks rather than policies and documentation. Key changes remove special consideration for the Management component in composite ratings, set a material financial risk threshold before a Management rating of 3 or worse can be assigned, and limit the influence of specialty examination findings to those affecting overall financial condition.
Interagency model risk management guidance replaces SR 11-7 for the first time since 2011.
The FDIC, OCC, and Federal Reserve issued updated, principles-based guidance tailored to each institution’s size, complexity, and model risk profile. Noncompliance alone will not trigger supervisory criticism. Notably, generative and agentic AI systems fall outside the formal scope but still require governance under existing model risk policy, a distinction that matters for institutions building AI governance frameworks.
OCC and FDIC eliminate reputation risk as a supervisory category.
A final rule now prohibits examiners from criticizing institutions on reputational grounds, prompting the Federal Reserve, OCC, and FDIC to remove reputation risk references from 15 interagency guidance documents. This change runs alongside the FTC’s debanking warning letters, which preserve a parallel federal exposure for viewpoint-based account decisions. Documented, objective rationale for account decisions remains essential.
Institutions should assess each change against their specific exposure, rather than treat the quarter’s deregulatory signal as blanket relief.
What does the GENIUS Act mean for stablecoin compliance right now?
The GENIUS Act triggered multiple agency rulemakings this quarter covering prudential standards, BSA/AML, sanctions compliance, and customer identification. Each rule comes from a different regulator on its own timeline. Institutions planning stablecoin activities should treat each as an independent obligation with its own preparation timeline, rather than waiting for a single final rule.
Treasury proposes framework for state-level stablecoin oversight.
Issuers with $10 billion or less in outstanding stablecoins may elect state regulation if the state regime is deemed “substantially similar” to federal standards. States retain some discretion on calibrated requirements, but uniform requirements must align with federal standards. Institutions near the $10 billion threshold should monitor how individual states develop their frameworks, since the “substantially similar” determination will govern whether state regulation remains a viable option.
FinCEN and OFAC propose the first federal sanctions compliance program requirement for stablecoin issuers
The joint proposal creates a standalone sanctions obligation for Permitted Payment Stablecoin Issuers, built specifically for the sector rather than adapted from Money Services Business (MSB) requirements. Institutions that assumed MSB registration was sufficient will find this a material compliance gap.
Five agencies propose Know Your Customer standards for stablecoin issuers.
The Federal Reserve, OCC, FDIC, NCUA, and FinCEN jointly proposed a customer identification program rule bringing Permitted Payment Stablecoin Issuers under bank- and broker-dealer-equivalent standards. Reliance on parent institution programs are permitted, but require a formal contract, annual certification, and compliance responsibility stays with the issuer.
Waiting for a single final rule before building out digital asset compliance will compress timelines and create real execution risk.
How should compliance teams prioritize their response?
The right move this quarter is targeted action, not a pause. Map each development against your institution’s charter, size, and activity mix, then prioritize changes with defined compliance dates ahead of those still in comment periods. Learn more about how CrossCountry’s Banking and Capital Markets team helps financial institutions translate regulatory shifts into practical program updates.
For a detailed look at the Q2 regulatory updates, please view our reference document.
Frequently Asked Questions
What is the FFIEC’s proposed CAMELS overhaul?
The FFIEC’s proposal shifts examiner focus from process and documentation toward demonstrated financial risk management, requiring a material financial risk threshold before a management rating of 3 or worse can be assigned.
Does the new model risk management guidance cover AI systems?
Generative and agentic AI systems fall outside the formal scope of the updated guidance, but institutions must still govern them under existing model risk management policies and state-specific guidance.
Can stablecoin issuers choose state regulation over federal oversight?
Issuers with $10 billion or less in outstanding stablecoins may elect state regulation, but only if the state regime is deemed “substantially similar” to federal standards.
Is MSB registration sufficient for stablecoin sanctions compliance?
No. FinCEN and OFAC’s joint proposal creates a standalone sanctions compliance requirement for Permitted Payment Stablecoin Issuers, separate from MSB registration.
Fraudulent invoices, manual billing corrections, and messy fixed asset journals cost finance teams hours every month and expose them to real risk. Sage Intacct’s 2026 Release 3 (R3) directly targets these gaps with new fraud detection, batch processing, and audit-readiness features. Here’s what finance leaders should prioritize and why it matters.
R3 gives AP teams an earlier read on high-risk transactions
Sage Intacct 2026 R3 adds AI-driven anomaly detection to AP automation, surfacing potentially risky invoices before payment. This matters now because payment fraud is not a fringe risk. According to the Association for Financial Professionals’ 2025 Payments Fraud and Control Survey, 79% of organizations experienced attempted or actual payments fraud last year.
The feature analyzes vendor billing patterns and submission details, flagging invoices with unusual transaction amounts – say, a vendor that typically bills under $1,000 suddenly submitting a $10,000 invoice or unrecognized vendor email addresses. Anomaly indicators surface in the Automated Transactions list, helping reviewers focus on the invoices that warrant a second look instead of reviewing every transaction manually. R3 pairs this with related administrative and security upgrades:
- Blocked email address lists stop suspicious senders from generating draft bills or expenses in the first place, closing a gap across AP Automation, Sage Expense Management, and e-invoicing.
- Email verification for user accounts confirms that new or updated email addresses belong to the intended user and periodically prompts users to reverify (every 12 months), reducing the risk of unauthorized account changes without interrupting sign-in, SSO, or MFA.
- Email domain validation now inherits across console hierarchies, so organizations managing multiple companies through a console structure can validate a sender domain once at the parent level instead of repeating the setup at every subsidiary
Together, these upgrades give finance teams a smarter detection layer for suspicious invoices and tighter control over which senders can generate transactions automatically.
Smarter automation cuts transaction overhead across AP, AR, and billing
R3 expands batch processing across purchasing, order entry, and accounts receivable. AP teams using enhanced lists can now post up to 20 bills at once, instead of one at a time, and AR teams gain the same bulk-posting capability for invoices and adjustments. Order Entry picks up a multi-document convert function first introduced in Purchasing last year: teams can combine multiple sales orders or specific line items pulled from them into a single transaction, useful for consolidating a quarter’s worth of monthly service orders into one customer invoice.
With customer refund processing, vendors and bills created from customer refunds can now flow through standard AP vendor and bill approval workflows, and new filtering and visibility options in Pay Bills make refund payments easier to identify and process. Teams that don’t need to review can configure refund vendors and bills to skip approvals entirely, though payment approvals still apply and can’t be bypassed.
Billing Groups, Sage Intacct’s hub for managing recurring invoice schedules, gains a Preview Invoices capability in this release. Before starting an invoice run, teams can preview billing details, invoice amounts, and charges to catch issues before posting. For organizations using Revenue Management, invoices can generate in Draft state, giving finance teams a chance to assign revenue recognition details before anything posts.
Organizations billing on usage also gain a smaller but practical upgrade: contract invoices can now show quantity used and average price directly on the invoice, useful for any subscription or consumption-based revenue model.
Fixed assets, GL, and reporting get real upgrades
R3’s fixed asset changes target a specific pain point: correcting mistakes without breaking the audit trail. Previously, a disposed asset could only be reverted, which deleted the original journal entries. Now, users can reverse full or partial disposals instead, creating offsetting journal entries that restore the asset and its depreciation history while preserving the original posted activity. This matters in regulated or audited environments, where deleting a record erases history that auditors need.
A related update lets teams summarize depreciation postings under the Revert correction treatment, not just Reverse as before, reducing General Ledger volume while still allowing individual depreciation entries within a summarized posting to be reverted. Previously, choosing Reverse used to be a permanent, one-way decision. R3 lets teams switch between the Revert and Reverse treatments at any time, without affecting anything already processed.
The Roll Forward report now includes dimensions and additional asset fields like tag, serial number, and GL account IDs directly in the report. Therefore, financial amounts and asset attributes live in one place, instead of requiring reconciliation across several reports.
General ledger and reporting picked up smaller usability wins that add up over a full close cycle:
- Journal entry approvals and delegation moved into their own main-menu section, consolidating approval sequencing and delegate management in one place.
- Journal entry templates are now directly accessible from the General Ledger main menu.
- Dashboard performance cards now support period-over-period comparisons for cumulative reporting ranges, like current-year-through-current-month against the prior period, making trend and seasonality tracking easier at a glance.
- Financial Report Writer can now exclude blank pages for dimension values with no data, cutting manual PDF cleanup after month-end.
Leverage Sage Intacct 2026 R3 Updates Now for Immediate Impact
Start by auditing which R3 features touch your existing configurations. A few, including Billing Groups’ Preview Invoices and the AP anomaly detection column, require specific permissions or list-view setup that your system admin may need to configure before your team can see or use them.
Prioritize based on risk and volume. If your organization processes AP at scale, anomaly detection and blocked email lists should move to the top of the list. If recurring billing drives a meaningful share of revenue, build the new invoice preview step into your next invoicing cycle. If your fixed assets have had rigid disposal corrections, the new reverse/revert flexibility is worth testing right away.
Release management is a recurring need, not a one-time event. Every Sage Intacct release brings changes that affect configurations, permissions, and workflows differently depending on how your instance is set up.
CrossCountry Consulting’s Sage Intacct Post Production Support team walks organizations through release management, system health checks, and enhancement projects year-round, not just when a new version ships. For context on what shipped in the prior release, see the Sage Intacct R2 2026 recap.
Frequently Asked Questions
What is the biggest change in Sage Intacct 2026 R3?
The most significant update is AI-driven anomaly detection in AP Automation, which flags invoices with unusual amounts or unrecognized vendor email addresses for reviewer attention. It’s an informational flag, not an automatic block, but paired with blocked email address lists; it gives finance teams an earlier layer of defense against invoice fraud.
Do I need new permissions to use R3 features?
Yes, for several features. Billing Groups’ Preview Invoices page and the AP anomaly detection view both require an admin to configure specific permissions or list-view settings before your team can access them. If a feature doesn’t appear in your instance, check with your system admin before assuming it’s unavailable.
What’s new with Billing Groups in R3?
Billing Groups isn’t a new feature, it’s Sage Intacct’s existing hub for managing recurring invoice schedules. R3 adds a Preview Invoices page, where teams can review billing details, invoice amounts, and charges before starting an invoice run. Organizations using Revenue Management can also generate invoices in Draft state, so they can assign revenue recognition details before posting.
What happened to the old, fixed asset disposal process?
Deleting a disposed asset via Revert is still available, but R3 adds the option to reverse disposals instead, creating offsetting entries that preserve the audit trail, and the ability to switch between the two correction treatments at any time. This matters in regulated or audited environments where full deletion removes history auditors need.
To get the most value from the Sage Intacct 2026 R3 release, contact CrossCountry today.
AI has moved from experimentation to early production across asset management. Most companies CrossCountry Consulting has worked with have embedded some form of AI into at least one investment process, and most of the rest are piloting one now.
Governance has not kept pace compared to adoption.
That gap is expensive in both directions: initiatives stall when approval paths are unclear, and ungoverned use creates regulatory, operational, and reputational exposure.
AI governance is the set of policies, controls, and oversight processes that determine how AI tools are approved, monitored, and documented across an organization. Done poorly; it functions as a brake. Done well, it is what lets AI adoption scale safely in a market that shifts every quarter.
Why has AI adoption outpaced governance in asset management?
Most companies are deploying generative AI faster than they can build structured oversight around it. Investment teams reach for tools that were never formally approved, and few companies have centralized visibility into what their AI tools and agents are doing, returning, or getting wrong.
The pressure this creates is concrete. An auditor wants the evidence chain behind a reported net asset value or a hard-to-value mark. A limited partner presses on how a fee or expense was allocated. An examiner asks for documented controls over any AI agent that touches a material process. Meanwhile, shadow AI carrying material nonpublic information seeps into the research and idea generation workflows where adoption is heaviest, often outside any information barrier.
This is not a new enforcement territory. In March 2024, the Securities and Exchange Commission (SEC) brought its first “AI washing” cases against two investment advisers, for marketing AI capabilities they did not actually have. The companies paid a combined $400,000 in civil penalties.
Separately, the SEC’s broader recordkeeping sweep has reached more than 100 companies and over 2 billion dollars in penalties since 2021, and its Asset Management Unit has charged advisers for misallocating fund expenses, from broken-deal costs to shared overhead. AI accelerates these exposures. The longer the governance gap persists, the harder it becomes to close.
Companies that close this gap early see the opposite pattern. In our experience working with clients, companies that operate under a risk-tiered AI life cycle tend to move use cases through intake and approval more quickly, gain clearer visibility into risk and value across their AI portfolio, and stay audit-ready through a documented AI inventory. Governance, structured correctly, accelerates adoption instead of competing with it.
What should every AI use case answer before moving forward?
Every AI use case should answer three questions before it scales: what the tool is doing, how much the company relies on it, and whether the work can be proven. These three questions turn governance from an abstract principle into a practical checkpoint.

Agentic systems raise the same three questions one level down: what the agent is and how it authenticates, what it can access and execute, and who owns it through to decommissioning. Together, the answers define accountability from the individual use case to the underlying infrastructure.
Where does AI risk actually live?
AI risk is broader than security. Security dominates most conversations about AI risk, but it is one of three exposures that need active governance, alongside operational and data risk.
A program built to address only one of these three exposures leaves the other two open.

How do you build an AI governance program in phases?
No company needs a complete governance program on day one, and the ones that try to build everything at once usually stall. A phased build works better than an all-at-once rollout.
- Foundation. Build a use case inventory, a responsible AI policy, and review workflows that a person can keep up with.
- Automation. Add tiered routing based on risk, a model registry, and command center visibility across the AI portfolio.
- Optimization. Layer in real-time alerting, drift detection, and incident playbooks once the first two phases are running smoothly.
Routing should be tiered by risk from the start. An internal productivity tool with a person reviewing every output can clear a fast track measured in weeks. Anything touching investor money, sensitive data, or a regulatory obligation earns testing, legal review, and audit documentation on a longer timeline. Approved use cases should accumulate into a pattern library, so the second valuation workflow does not repeat the full review of the first.
This sequence is typically benchmarked against the NIST AI Risk Management Framework and COSO’s guidance on internal controls; two frameworks built specifically to make AI oversight defensible to auditors and regulators.
How do you know an AI governance program is working?
A working AI governance program can answer four questions: whether people are following the process, whether controls catch issues, whether the models are performing, and whether measurable value is showing up. Standard system and activity logging (who signed in, what data moved) is not enough on its own.
Governing AI well requires a deeper record: what the model decided and why, what was performed across connected systems, and whether guardrails fired when they were supposed to. Across the asset managers we work with, gains so far sit mostly in operational efficiency. Few companies can yet tie AI directly to investment returns, and that is fine. A program that cannot answer all four questions above is still a pilot, no matter how long it has been running.
For asset managers, the question is no longer whether to implement AI. It is whether every use case can answer what the AI is doing, how much the firm relies on it, and whether that work can be proven when someone asks. Companies that can answer all three moves faster, not slower than the ones still treating governance as an afterthought.
Building this out often connects directly to broader AI Strategy & Transformation work, since the governance layer and the adoption roadmap need to be designed together, not in sequence. It also overlaps closely with Integrated Risk Management, particularly where AI touches controls that are already subject to audit or regulatory review.
To fully capitalize on the value a well-governed AI program can bring to your organization, contact CrossCountry today.
Frequently asked questions
What is AI governance in asset management?
AI Governance is the set of policies, controls, and oversight processes that determine how AI tools are approved, monitored, and documented. For asset managers, it covers everything from intake and approval to ongoing monitoring of any AI tool touching investment decisions, financial and client data, or regulatory reporting.
What are the regulatory risks of deploying AI without governance?
Companies face SEC enforcement risk, including “AI washing” charges for misrepresenting AI capabilities, along with recordkeeping violations and expense misallocation of charges. Ungoverned AI also raises the risk of shadow AI exposing material nonpublic information outside proper information barriers.
How does a risk-tiered AI life-cycle work in practice?
Each AI use case moves through intake, approval, build, and monitoring, with a governance checkpoint at every stage. Low-risk tools clear a fast track in weeks, while anything touching investor money or regulatory obligations goes through testing, legal review, and audit documentation.
What does an AI governance program look like in phases?
Programs typically build in three phases: foundation (use case inventory, policy, review workflows), automation (tiered routing, model registry, command center visibility), and optimization (real-time alerting, drift detection, incident playbooks).
How should asset managers document AI use for auditors and LPs?
Documentation should trace what the AI was asked, what it produced, who reviewed it, and what decision resulted, generated automatically by the workflow rather than reconstructed after the fact. This creates an audit-ready inventory before an examiner or limited partner asks for one.
Auto Accrual AI is CrossCountry Consulting’s solution for automating accruals for service POs, material POs, and invoices pending approval. It pulls Coupa purchase orders, goods receipts, and invoice data to predict accruals, validates predictions with PO owners via Microsoft Teams, and produces a configurable export file with auto-reversal included. It is designed for finance teams still spending valuable hours on manual accruals each close.
CrossCountry’s Coupa practice recently walked attendees through a live demo of Auto Accrual AI, end-to-end. Here are the highlights, and why your close process is worth 45 minutes of your time.
Why Month-End Accrual Automation Matters
Finance teams grinding through manual accruals each close are not outliers. That reality represents the average, according to benchmarks referenced during the webinar. The process typically involves tracking down purchase order (PO) owners via email, building accrual workbooks in Excel, posting journal entries, reversing those entries, and then hunting down source documents to prove the numbers when an auditor asks.
The core problem is structural. Nothing in that process learns from the previous close. The same steps produce different results each month, the same mistakes carry forward, and there is no audit trail when assumptions are questioned. Auto Accrual AI is built specifically to replace that cycle.
How Accrual Automation Works in Coupa Environments
The Auto Accrual AI demo walked through six steps, from Coupa data pull to ERP journal entry posting.
- A unified view of your full accrual population.
The session opened with a single dashboard showing all POs and invoices subject to accrual: services, materials, and non-PO. No more pulling reports from multiple systems or reconciling spreadsheets after the fact.
- AI predicting accruals for services POs, with confidence scores.
The system analyzes PO metadata, invoice history, milestones, and notes to generate a prediction for each services PO. It shows its reasoning: a confidence level, green/yellow/red indicators, and the specific inputs that drove the number.
In the demo, a straightforward software license PO received a 98% confidence rating; a staff augmentation PO with a “slow start” note on the requisition received a 72% rating; and a legal services PO with no invoice history received a 61% rating with a straight-line estimate.
- One-click PO owner validation via Microsoft Teams.
Auto Accrual AI sends PO owners a Teams message that includes the prediction, PO details, and confidence indicators. Owners can approve with one click or submit an adjustment with a note. The demo showed exactly what that experience looks like from the PO owner’s side, including how adjustments feed back into future predictions.
- A full audit trail, built in.
Every prediction, approval, and adjustment is logged. The demo walked through the audit trail view, showing what was predicted, what was accepted, what was changed, and by whom. Administrators can also act on non-responses: approving, adjusting, resending, or escalating items where no PO owner feedback was received.
- Accuracy that improves over time.
The demo included real learning data from a live environment. That environment started at 68% accuracy in October and reached 94% accuracy by June, after nine months of use and continuous feedback from PO owners.
- Journal entry posting to your ERP, with auto-reversal.
The final step showed the complete journal entry, across services POs, materials POs, and non-PO invoices, posting to the ERP. Auto-reversal is scheduled automatically. The solution is ERP-agnostic and supports either a file-based transfer or direct API integration, depending on your environment.
What’s Next for Accrual Automation
The roadmap includes Slack and email validation as alternatives to Teams, support for recurring accruals such as rent and insurance, and the ability to incorporate contract data into AI predictions. Each of these is targeted for a subsequent release.
For organizations interested in exploring the solution, CrossCountry’s engagement path begins with a data assessment to understand your current PO and invoice landscape, followed by pilot design, a two-month proof of concept, and then full deployment with ERP and Coupa integration.
Frequently asked questions
What types of accruals does Auto Accrual AI handle?
Auto Accrual AI handles three categories: services POs (using AI prediction), materials POs (using automated straight-line math), and non-PO invoices (using automated calculation for pending approvals). Recurring accruals such as rent and insurance are on the product roadmap for a future release.
Does Auto Accrual AI work with any ERP?
Yes. The solution is designed to be ERP-agnostic. CrossCountry pulls data from Coupa via API and posts journal entries to your ERP either through direct integration or a file-based transfer, depending on your system and requirements.
How does Auto Accrual AI support an audit?
Every prediction is logged alongside its inputs, confidence score, and PO owner response. All source transactions trace back to the original Coupa records. Administrators have a full audit trail showing what was predicted, what was accepted or adjusted, and by whom, at every step of the close.
How customizable is the solution for different accrual methods?
The current release supports configuration for amortized accruals, reversing entries versus delta true-ups, and custom Coupa field mapping. Organizations can also bring their own large language model (LLM) in place of CrossCountry’s default model.
What does the engagement process look like?
CrossCountry’s standard path includes a data assessment, pilot design, a two-month proof of concept, and full deployment with ERP and Coupa integration. Teams can reach the CrossCountry Coupa practice directly to discuss specific requirements.
To learn more about how Auto Accrual AI can reduce manual effort and improve close accuracy in your organization, watch the full demo recording or contact CrossCountry’s Coupa practice to begin a requirements discussion.
The recent CrowdStrike incident sent shockwaves through the global IT landscape, causing widespread disruptions and highlighting the delicate balance between cybersecurity, system stability, and business resiliency.
If your organization was affected by the outage, you’ve likely recovered or are restoring your systems to full normal operations. It’s critical to adhere to the guidelines provided by Microsoft and CrowdStrike to reverse the problematic update and ensure that any vendors or service providers you depend on do the same. While the next disruption may be unpredictable, you can plan ahead to respond effectively.
What Exactly Happened?
On July 19, 2024, a routine content update from CrowdStrike, a leading cybersecurity provider, inadvertently triggered a massive outage affecting millions of Windows computers worldwide. CrowdStrike’s Falcon platform, designed to protect organizations from cyber threats, uses a kernel-level driver to monitor system activities. However, a defect in a recent update caused Windows hosts to crash, resulting in blue screen errors and system failures affecting various industries. This seemingly small change had cascading effects, demonstrating how deeply integrated security software can become a single point of failure for many organizations.
It’s important to note that this was not a cyberattack, but rather an unfortunate technical glitch, and CrowdStrike quickly identified the issue, isolated it, and deployed a fix. However, the process of recovering affected systems proved challenging for many organizations, especially those with large numbers of endpoints.
Preparing for the Next Disruption
This CrowdStrike incident is a stark reminder of the complexities involved in managing modern IT infrastructure and the potential risks associated with widely deployed security solutions. Specifically, the incident brings into sharp focus the often-overlooked domains of third-party risk management, business resiliency, and security architecture. These are not just buzzwords but critical IT capabilities that require urgent attention and action.
Here are some actionable strategies to proactively prepare your organization for the next disruption:
Third-Party Risk Management
- Conduct vendor risk assessments: Regularly evaluate the security posture of third-party vendors through risk assessments and security questionnaires. Continuous monitoring and detailed reporting can help identify and mitigate risks associated with third-party vendors.
- Enhance third-party collaboration: Work closely with third-party vendors to ensure they adhere to robust security practices and are prepared to respond effectively to incidents. This collaboration is crucial for maintaining overall security and compliance.
Business Resiliency
- Develop alternate recovery procedures: Work closely with business functions to identify critical processes and dependencies. This will allow you to develop alternate procedures for maintaining business continuity during and after a cyber or IT incident.
- Test business continuity and disaster recovery plans: Conduct regular tabletop and failover exercises to identify vulnerabilities in the existing resiliency plans. This should include regular testing of backup systems and data recovery procedures.
Security Architecture
- Develop operational technology security architecture blueprints: Within the security architecture review process, ensure OT security requirements and secure-by-design considerations are implemented into deployments. This ensures that critical OT systems should not be affected by third parties or external actors without going through the secure channels enabled by the organization.
- Enhance network segmentation to critical assets: Critical assets identified by the organization should be isolated from the internet and external entities. Updates or maintenance to these assets should go through a more rigorous process to ensure downtime is minimized.
The CrowdStrike incident is more than just a cautionary tale – it’s a directive for proactive change in the way we approach cybersecurity and resiliency programs. While it’s important to enhance your strategy around these domains, IT and business leaders must continue to work closely to identify business risks. This involves considering new threats, various disruption scenarios, and existing IT infrastructure, all while striving to implement best practices for cybersecurity and risk mitigation.
The next disruption may be unpredictable, but being well-prepared can enable your organization to maintain business continuity. To enhance your risk management capabilities and threat readiness, contact CrossCountry Consulting.
Vendor risk is no longer a side concern for organizations relying on third parties. As businesses expand their vendor networks, manage increased regulatory demands, and respond to real-time threats, a proactive approach to vendor risk management (VRM) has become essential.
It’s time for risk, IT, and procurement leaders to align vendor oversight with organizational strategy and collaborate on productive vendor risk management strategies that protect and create value.
Why Vendor Risk Management Matters Now
Vendor risk management governs organizations’ understanding, framework, and management of all risks resulting from relationships with vendors, third parties, service providers, and suppliers. Key risk types include cybersecurity attacks, noncompliance, financial and reputational penalties, data breaches, supply chain disruption, and more.
With global business ecosystems more interconnected than ever, the average organization works with dozens or hundreds of vendors, many of whom have direct or indirect access to sensitive systems and data.
Recent studies highlight just how pressing these risks are:
- 61% of organizations have experienced a third-party data breach or security incident in the past 12 months.
- 98% of companies worldwide have at least one vendor with a documented security breach.
- A single vendor failure, like 2024’s Crowdstrike outage, can ripple through critical sectors including airports, hospitals, financial markets, and government.
Understanding and managing vendor risk is crucial for ensuring compliance and safeguarding business continuity and reputation.
Demystifying Vendor Risk
Not all vendors pose equal risk.
- Critical vendors: Directly impact operations, financial stability, or corporate security. Examples include cloud service providers, key software developers, or payment processors. Failure in these relationships can result in data loss, extended downtime, or customer dissatisfaction.
- Non-critical vendors: May impact operational efficiency but are easier to replace without major disruption. Examples include office supply companies, marketing agencies, or local contractors.
Classifying your vendor base with a risk lens helps focus resources on oversight where it matters most.
The Expanding Scope of Vendor Risk Management
Modern VRM extends far beyond traditional contract reviews. Today’s risk surface includes:
Key Risk Domains
- Cybersecurity: 62% of organizations rank this as their top VRM focus.
- Geopolitical threats: 33% see growing exposure due to global supply chains.
- Operational resilience: 32% prioritize continuity and disaster recovery.
- Data privacy: 29% highlight rising data protection laws and compliance obligations.
Emerging factors such as AI risk, subcontractor risk, and concentration risk (over-reliance on a small number of core vendors) further complicate the picture.
Proliferation of Regulations
Organizations must comply with established frameworks like GDPR, CPRA, and HIPAA, but also anticipate new laws such as DORA, EU AI Act, and NIS2. This means VRM must evolve quickly to stay ahead of shifting compliance expectations and cross-border data obligations.
Top Challenges in Vendor Risk Management
Even seasoned teams encounter common pitfalls:
Contractual Complexity
Many organizations struggle to maintain consistency in vendor contracts. Missing or inadequate clauses related to cybersecurity, termination rights, or data access can leave organizations exposed.
Visibility Gaps
70% of risk managers feel they lack full visibility into their supplier risk landscape. This makes it difficult to track evolving risks, especially as vendor networks grow large and complex.
Supply Chain Complexity
End-to-end monitoring remains a challenge, particularly in diversified or global supply chains where risk signals can be hard to aggregate.
Dynamic Risk Profiles
Vendor risks are not static. Changes in market health, regulatory environment, or even vendor leadership can alter a provider’s risk posture overnight.
Accountability and Governance
Disconnected protocols, unclear ownership, and ad hoc communication hamper effective vendor oversight and incident response.
Key Metrics for Vendor Risk Insights
Data-driven VRM relies on meaningful metrics to inform strategy and prioritize action. Consider these KPIs:
- Percentage of major cyber incidents traceable to vendors: Quantifies external attack surface risk.
- Number of vendors at financial risk (e.g., bankruptcy or major distress): Exposes resiliency or operational vulnerabilities.
- Count and percentage of vendors violating regulatory requirements: Helps spot compliance weak points.
- Percentage of critical vendors performing unique (non-redundant) functions: Reveals single points of failure.
- Vendor access to critical assets such as crown jewels: Exposes points of failure from which it’s difficult to recover.
- Growth in vendor population and the share of critical vendors in that group: Demonstrates vendor sprawl and risk surface expansion.
Regular tracking of these metrics gives compliance leaders early warning signals and a concrete basis for executive reporting.
The Continuous Monitoring Imperative
Modern organizations recognize that vendor risk is not a one-and-done exercise. Risk profiles change as vendors grow, merge, or adapt to new markets.
- Threat actors evolve strategies and exploit fresh vulnerabilities in vendor ecosystems.
- Regulatory pressure intensifies, requiring demonstrable, real-time monitoring capabilities and documented response protocols.
- Automated risk platforms, third-party ratings solutions, and deep-dive audits are increasingly essential to maintain visibility and resilience across the vendor landscape.
Strategies to Strengthen Your VRM Program
For a practical approach to enhanced vendor risk management, leaders can take the following steps:
- Centralize vendor inventory: Build and maintain a live register of all vendors, their roles, risk ratings, and criticality.
- Standardize contracts and controls: Adopt contractual frameworks that include clear obligations, incident disclosure, audit rights, and defined offboarding procedures.
- Invest in technology and automation: Use AI-enabled solutions for risk assessments, automated questionnaires, and continuous monitoring.
- Embed cross-functional governance: Draw on compliance, IT, procurement, and legal teams to create a governance model with defined ownership and escalation paths.
- Cultivate executive support: Ensure executive sponsorship for VRM by framing risk management as an enabler of growth and resilience.
- Leverage data and analytics: Use dashboarding and regular risk reviews to inform business decisions and report progress to stakeholders.

Building a Resilient Vendor Risk Management Program
Vendor risk will keep rising as organizations deepen reliance on external partners and as regulatory obligations expand. The organizations that thrive will move beyond reactive approaches and instead build integrated, proactive VRM programs anchored by real-time data, cross-functional collaboration, and smart automation.
The result is not just improved compliance, but a more resilient business with increased strategic agility. To collaboratively build a vendor risk management program that’s right for your organization, contact CrossCountry Consulting.
The Institute of Internal Auditors (IIA) announced its Cybersecurity Topical Requirement, the first in a series of mandated frameworks under its International Professional Practices Framework (IPPF). The move signals a shift from cybersecurity audits being a discretionary or ad-hoc exercise to a standard approach for all audit plans.
Standardizing Audit
The requirement mandates a baseline approach for internal audit functions assessing cybersecurity. Key scope areas include:
- Governance: Clear roles for cybersecurity oversight, aligned with strategic objectives.
- Risk management: Dynamic risk assessments to counter evolving threats.
- Controls: Rigorous evaluation of technical and procedural safeguards of data and assets.
This means standardized audits will replace inconsistent practices with a unified methodology tied to frameworks like NIST CSF 2.0 and COBIT 2019.
Breaking Down Silos
A standout theme of the requirement is collaboration. The IIA explicitly pushes auditors to partner with InfoSec teams, bridging a historical conflict and divide. The requirement’s User Guide even maps controls to NIST 800-53, offering a shared language for both functions. This is a win for organizations aiming to elevate beyond reactive, siloed responses to breaches and a callout to the DevSecOps approach brought to many organizations.
Additionally, if IT leadership is not open to cyber audits, it’s a red flag. Internal audit should work to build their credibility, add expertise where needed, and address hesitation from IT. Cybersecurity awareness should be embedded into all areas of the organization, including internal audit.
Challenges Ahead
While the requirement is a leap forward, implementation hurdles remain:
- Timeline: Conformance is mandatory by February 2026, but smaller internal audit functions may struggle with resource constraints and subject matter expertise.
- Scope flexibility: Audits are not required, but if cybersecurity is scoped, the framework applies. This balances rigor with adaptability but could lead to avoidance of cybersecurity in some organizations’ audit plan. Internal audit teams should assess cyber risk on an annual basis and, given this has been a top risk for all industries for the past several years, there is no reason not to include cyber in the audit plan.
- Privacy balancing act: Continuous monitoring must align with employee privacy norms, a tension the framework acknowledges but doesn’t resolve. Cross-training team members in privacy areas and collaborating with privacy experts is increasingly becoming more important.
What’s Next?
The IIA plans follow topical requirements for third-party risk, culture, and resilience. For now, cybersecurity takes center stage, reflecting its rank as the No. 1 global risk in the IIA’s 2025 survey.
This requirement isn’t just about compliance; it’s a call to action. Internal audit should partner with cyber leadership to:
- Review the Topical Requirement and User Guide to ensure they have a plan to meet the baseline requirements.
- Evaluate their internal audit teams’ cybersecurity expertise and provide training or seek third-party expertise as needed for support.
- Ensure current process supports formal cybersecurity strategies, standard board-level reporting, and clear roles and responsibilities for cyber risk management.
- Prioritize continuous risk management by maintaining ongoing risk assessments, updating incident response plans, and measuring awareness program effectiveness.
- Implement continuous monitoring, effective third-party/vendor management, and regular independent control evaluations.
- Promote cross-functional collaboration, alignment, and communication between audit, InfoSec, and senior management to drive a unified cybersecurity approach.
Organizations leveraging the new requirement will gain stronger cyber resilience and standardization, empowering audit and InfoSec teams to address cyber risk and report it effectively to the board. For internal auditors, the message is clear: Cyber audits are here to stay. For InfoSec teams? It’s time to welcome audit as an ally, not an adversary.
To better understand and apply the rule at your organization, contact CrossCountry Consulting.
As the global economy reacts to recently announced tariffs, the ripple effects are extending far beyond traditional trade dynamics. For business leaders, CISOs, and risk managers, the implications are reshaping the way we think about third-party risk and cybersecurity.
Macroeconomic policies like tariffs can introduce vulnerabilities in the digital infrastructure of organizations, a reality to which leaders must respond. Below are major cyber risk impacts resulting from tariff disruption and how your company can strategically address them.
1. Nation-State Cyber Retaliation
Economic pressure and geopolitical tension are likely to escalate nation-state activity in cyberspace. Historical patterns suggest increased critical infrastructure attacks from adversarial actors in response to tariffs.
What this means for your organization: Organizations need updated threat models that account for sophisticated threat actors, especially those targeting critical sectors like finance, defense, technology, and other critical supply chain industries.
2. Supply Chain Disruption Exposes New Cyber Vulnerabilities
Tariff-affected regions – like China, a major player in semiconductors and mineral production – are foundational to global IT infrastructure. As companies seek out alternative suppliers, several trends are emerging:
- Shortcuts in third-party due diligence, as companies may bypass certain security due diligence when looking for new vendors.
- A rise in counterfeit components, due to a rush to reduce costs related to affected hardware.
- Extended lifespans for outdated security infrastructure, leaving legacy systems and potential vulnerabilities in place.
What this means for your organization: With these newly imposed tariffs, many organizations will aim to reshore their workstreams in the U.S. from overseas. Every vendor transition or hardware delay introduces new opportunities for threat actors. Integrating rigorous third-party risk management into your organization is not only a best practice but a business necessity.
3. Climbing Cloud and Cybersecurity Costs
The global nature of cybersecurity tooling and public cloud infrastructure means tariff-induced costs don’t stop at the border. As U.S.-based companies seek domestic infrastructure and software alternatives, they may soon encounter higher subscription prices for cybersecurity tools and cloud services, potentially pushing some toward cheaper (and potentially less secure) alternatives. Due to the limited availability of critical hardware materials, hardware-based security tools may become less accessible.
Consequently, vendors might shift toward software-based solutions, which may not adequately align with the unique risk appetite of every organization. Hardware-based security tools may also become less accessible depending on the availability of critical hardware materials.
What this means for your organization: The true cost of cybersecurity is measured in resilience, readiness, and risk exposure. Cutting corners in the short term could open the door to costly breaches down the road.
4. Risk of Isolated Threat Intelligence
Tariffs and economic tensions can erode international trust, which has become a foundational element in effective cyber threat intelligence. We anticipate:
- Decreased cross-border collaboration, reducing the sharing of large-scale threat intelligence.
- Lack of consistency across national security standards, opening new attack surfaces as one-size-fits-all regulations become less applicable.
What this means for your organization: Organizations in both the public and private sectors must proactively build trusted threat intelligence networks to stay up to date on global threats.
5. Insider Threats and Budget Constraints
Tariffs are likely to drive up labor costs and service/subscription prices. In response, many organizations tighten their cybersecurity budgets, delaying critical upgrades and leaving defenses more vulnerable. Simultaneously, layoffs and hiring freezes are prone to insider risk, as financially stressed or disgruntled employees are more likely to become threat actors.
What this means for your organization: It’s essential to invest in employee awareness training, insider threat monitoring, and secure offboarding processes to mitigate insider risk.
Next Steps
When organizations rush through security decisions, it often leads to bigger problems down the line. Business and security leaders must avoid impulsive reactions when changing vendors, cutting costs, or de-prioritizing long-term security.
CrossCountry Consulting’s Integrated Risk Management team targets these challenges by contextualizing the security implications of business decisions, enabling leaders to make informed decisions that balance risk with desired outcomes. Now’s a great time to build resilience by:
- Maintaining up-to-date threat models that account for evolving threat actors.
- Conducting comprehensive and timely third-party risk assessments.
- Mapping and securing vulnerable segments of the supply chain.
- Enhancing cybersecurity strategy so that it appropriately balances cost, compliance, and readiness.
For expert support, contact CrossCountry Consulting.
As the head of U.S. Cyber Command and the National Security Agency (NSA) recently stated, the Defense Industrial Base (DIB) sector is “is being actively targeted by our adversaries and competitors.” These attacks routinely target intellectual property and sensitive information. They also disrupt military operations and threaten the U.S. Department of Defense (DoD) supply chain, which includes hundreds of thousands of domestic and foreign companies. In response, the DoD has emphasized the need for stringent cybersecurity requirements for contractors within its supply chain to maintain national security.
The Cybersecurity Maturity Model Certification (CMMC) is a mechanism developed to protect unclassified information, such as Federal Contract Information (FCI) and Controlled Unclassified Information (CUI), that resides on DIB systems and networks. The CMMC measures an organization’s cybersecurity hygiene, in alignment with industry standards outlined in the NIST SP 800-171 rev2 and NIST SP 800-172 frameworks.
The latest evolution of CMMC requires DIB organizations to reconsider risk and compliance practices.
Importance of CMMC 2.0 in 2025
The Pentagon budget for FY25 is $849.8 billion. Achieving the required CMMC level is essential to qualify for DoD contracts and provide trust and credibility within in the DoD supply chain.
The DoD published the CMMC 2.0 rule in October 2024, which is streamlined to three maturity levels:
- Foundational – Focuses on basic cyber hygiene practices. It includes 17 practices that are required to protect FCI.
- Advanced – Aligns with the security requirements in NIST SP 800-171. It includes 110 practices aimed at protecting CUI.
- Expert – Aligns with a subset of the requirements in NIST SP 800-172. This level focuses on advanced and progressive cybersecurity practices to protect CUI from Advanced Persistent Threats (APTs) and is required for high-priority DoD programs.
Initial implementation is already underway. The table below outlines each phase of the implementation timeline:
| Phase | Timeline | Details |
|---|---|---|
| Phase 1 | December 2024 | Where applicable, solicitations require Level 1 or 2 Self-Assessments. |
| Phase 2 | December 2025 | Where applicable, solicitations will require Level 2 Certification. |
| Phase 3 | December 2026 | Where applicable, solicitations will require Level 3 Certification. |
| Phase 4 | December 2027 onwards | All solicitations and contracts will include CMMC Level requirements as a condition of contract reward. |
Considerations for Organizations in the DIB Sector
To prepare for upcoming deadlines, organizations should ask themselves:
What type of data do we hold?
CMMC 2.0 places greater scrutiny on DIB organizations handling CUI, which involves information about DoD contracts, sensitive but unclassified information, information under protections from federal laws, and information related to national security or law enforcement. Specific examples include:
- Personally Identifiable Information (PII).
- Protected Health Information (PHI).
- Export-controlled or International Trade Data.
- Contractor sensitive information.
- Unclassified Controlled Technical Information (UCTI) – sensitive but unclassified military information including operational plans, development of military technology, and surveillance methods.
DIB organizations with any form of CUI MUST be Level 2 Advanced CMMC-compliant, and those handling CUI for high-priority DoD programs MUST be Level 3 Expert CMMC-compliant.
How long will CMMC compliance take, and how much will it cost?
Achieving and maintaining CMMC compliance has time and cost implications, which vary significantly due to:
- The size of the organization.
- The level of certification required.
- Complexity of existing systems.
- Existing gaps in cybersecurity posture.
- Implementation of necessary controls.
- Employee training and awareness.
- Third-party certification.
For many organizations, the upfront costs and effort can be substantial, but they are outweighed by the long-term benefits of improved security posture, access to government contracts, and mitigating cyber risk. On average, organizations should expect to spend several months to a year achieving initial compliance, with ongoing maintenance and periodic audits required after that. Planning, allocating sufficient resources, and being aware of any contractual deadlines will help in meeting CMMC requirements on time.
Are the organization-defined NIST SP 800-171 and NIST SP 800-172 controls aligned with our risk management policies and procedures?
When preparing for CMMC compliance, security controls from NIST SP 800-171 and NIST SP 800-172 should align with the organization’s risk management policies and procedures. This ensures that cybersecurity posture is both compliant and suitable for the organization’s operational environment. Organizations should:
- Conduct a gap analysis of cybersecurity and risk management measures to determine areas lacking compliance or requiring enhancement.
- Map NIST SP 800-171 and NIST SP 800-172 controls to the organization’s risk management policies and procedures.
- Implement tailored controls, such as creating and updating policies and procedures, deploying necessary technologies (e.g. encryption, access controls), and continuously reviewing controls to ensure ongoing compliance.
- Document and communicate the risk management strategy across the entire organization.
CMMC 2.0 expands on NIST 800-171’s 14 security domains with three new domains (for a total of 17). These new domains emphasize cybersecurity asset protection, breach recovery, and how CUI data held within their environment is impacted. These new domains include:
- Asset Management.
- Recovery.
- Situational Awareness.
Are our subcontractors and third parties aware of CMMC requirements?
Subcontractor compliance is also a key consideration, and by October 2025, it will be the prime contractor’s responsibility to ensure all subcontractors meet the appropriate CMMC requirements.
A subcontractor’s required certification level is based on the information that will flow to the sub-contractor or supplier during fulfillment of the contract. This means there could be differing requirements for CMMC compliance between prime contractors and subcontractors. For example, a prime contractor handling high-priority CUI data requires CMMC Level 3 compliance, and only passes FCI data to its subcontractors, requiring them to only be CMMC Level 1-compliant.
Featured Insight
Achieving CMMC Compliance
To achieve CMMC compliance, organizations are advised to conduct the following initiatives:
CUI Boundary Analysis
Understanding the type of data handled by an organization is key in determining the level of certification required. For example, Advanced Level 2 compliance is not necessary for all organizations and is solely required for organizations handling CUI.
To help navigate the compliance requirements within the CMMC, a CUI boundary analysis can determine whether organizational information is classified as CUI, identify and map CUI data flows, and define clear distinctions between CUI and non-CUI data.
Cyber Gap Analysis and CMMC Self-Assessment
A cybersecurity maturity assessment is the first step in identifying gaps in existing practices, controls, and documentation. Based on the results of the gap analysis, focus on key CMMC domains that need improvement, which can include data protection, access control, or incident response, etc.
The CMMC self-assessment is required annually to achieve Foundational Level 1 compliance. This level focuses on the protection of FCI aligned with Federal Acquisition Regulation (FAR) Clause 52.204-21.
Mock Audit
Ensuring all required documentation, such as system security plans (SSPs), policies, and training records, is ready can greatly speed up the formal assessment process. This can be achieved by conducting mock audits to verify that all requirements are met.
For Advanced level compliance, an official assessment conducted by a CMMC Third-Party Assessor Organization (C3PAO) is required, and for Expert level compliance a DoD governing body will conduct the assessment.
Third-Party and Subcontractor Engagement
As mentioned earlier, prime contractors have the responsibility to ensure all subcontractors are CMMC compliant based on their required level. Engaging with subcontractors and third parties early to identify information flows can ensure a seamless certification process.
Due to the nuanced set of requirements in the CMMC, acting early will give organizations a competitive advantage by prioritizing their cybersecurity maturity. To plan and navigate the complexities of your organization’s CMMC compliance in 2025, contact CrossCountry Consulting.
The rapid adoption of artificial intelligence (AI) is unlocking unprecedented value for organizations that can effectively harness its potential. However, as AI continues to evolve, so does the need for robust risk management to ensure its ethical and transparent use. With forthcoming oversight from industry, government, and international bodies, maintaining trustworthy AI is critical to unlocking its full value while ensuring safety and accountability. Here’s where to start on the journey toward building AI that can be trusted, valued, and guided responsibly.
8 Principles for Trustworthy AI
Organizations should establish an AI governance framework that’s grounded in the concept of “Trustworthy AI” principles that guide people, processes, and technology throughout the development and deployment of AI. The core principles of trustworthy AI principles include:
- Accountability: The obligation and responsibility to ensure systems operate ethically, fairly, transparently, and compliantly (e.g., traceable actions, decisions, outcomes).
- Contestability: Ensuring system outputs and actions can be questioned and challenged.
- Explainability (XAI): The ability to describe AI’s output and decision-making.
- Fairness: Relatively equal treatment of individuals and groups.
- Reliability: Ensuring systems behave as expected (e.g., perform intended functions consistently and accurately, especially with unseen data).
- Robustness: Systems maintain functionality and perform accurately in a variety of circumstances (e.g., new environments, unseen data, against adversarial attacks).
- Safety: Minimizing potential harm to individuals, society, and the environment.
- Transparency: Ensuring information about the system is available to stakeholders.
While it may not be possible to maximize all characteristics of trustworthy AI, organizations still need to determine and accept tradeoffs in a risk-based manner. Effectively balancing risk and implementing trustworthy AI is key to:
- Improved decision-making.
- Stronger competitive advantage.
- Preparation for regulatory compliance.
- Enhanced security and privacy.
- Mitigation of bias and harm.
- Sustainability and long-term viability.
AI in Focus
Discover how finance leaders can use practical, human-centered AI to optimize operations, enhance decision-making, and position their companies for growth.
In the first episode of CrossCountry Consulting’s podcast, Field Notes, we explore how audit-ready AI works in the real world and why smarter AI starts with your people.
Implementing Trustworthy AI
So where do you start? Organizations struggling to operationalize trustworthy AI or seeking a health check on their existing framework may benefit from a baseline risk assessment or audit. A few relevant assessment/audit types are program assessments, development workflow assessments, and model assessments.
Program assessments provide organizations an enterprise-wide analysis of the culture of AI governance. A formal assessment (e.g., performed using the NIST AI Risk Management Framework) will reveal overall program maturity, gaps, and recommendations to achieve trustworthy AI.
Development workflow assessments provide organizations a targeted report on their AI development lifecycle. A formal assessment of the AI development lifecycle will reveal strengths, weaknesses, and potential risks associated with the AI dev workflow (e.g., plan, design, development, and deployment).
Model assessments, or “conformity assessments,” may be required for organizations subject to the EU AI Act developing or deploying high-risk systems. A model assessment may include verifying and/or demonstrating that a “high-risk AI system” complies with the requirements of the EU AI Act, including by evidencing:
- The organization’s risk management system.
- Implementation of effective data governance (bias mitigation).
- Maintenance of up-to-date technical documentation and logging.
- Testing of systems for cybersecurity resiliency.
- Other requirements around human oversight and transparency.
Transforming AI Risk Into Opportunity
Few organizations will get every aspect of AI right on their own. As with many emerging technologies, the instinct to move quickly often outweighs caution. However, by adopting a thoughtful, strategic approach to AI, companies can mitigate risks, maximize value, and outpace competitors.
To start a conversation on building a foundation of trustworthy AI, contact CrossCountry Consulting.
Family offices manage extraordinary wealth, making them prime targets for cybercriminals seeking high-value payouts. Recent data reveals that 43% of family offices globally have experienced cyberattacks within the past 12-24 months, with 25% suffering three or more incidents. These attacks represent more than financial losses – they threaten family privacy, reputation, and generational wealth preservation.
Understanding these risks and implementing robust protection strategies has become essential for family office leadership. Below is an outline of critical threats facing family offices and actionable cybersecurity frameworks to safeguard valuable assets.
The Growing Threat Landscape
Cybercrime represents the largest transfer of economic wealth in history, with costs projected to reach $10.5 trillion annually by 2025 – up from $3 trillion in 2015. This staggering 15% year-over-year growth rate demonstrates why cybersecurity must be a top priority for family offices.
The financial sector faces particularly sophisticated attacks. Half of all family offices know another office that has been compromised, indicating the widespread nature of these threats. More concerning, attacks are now specifically tailored to family offices, with threat actors targeting deal data, credentials, and sensitive family information for maximum impact.
Primary Cyber Threats Targeting Family Offices
AI-Powered Social Engineering
Modern attackers leverage artificial intelligence to craft convincing phishing emails and impersonation schemes. AI analyzes public and private data rapidly, creating targeted communications that bypass traditional security measures. These attacks often feature:
- Deepfaked video calls mimicking trusted executives.
- AI-generated documents that appear legitimate.
- Automated reconnaissance gathering detailed intelligence about family members and staff.
Over 60% of family offices have reported phishing attacks, with 45% experiencing direct impersonation attempts targeting senior leadership.
Sophisticated Ransomware Operations
Ransomware attacks against family offices involve multiple extortion tactics beyond simple data encryption. Attackers threaten to leak sensitive information on dark web platforms, sell stolen credentials to other criminals, and freeze critical assets during deal closures.
These coordinated attacks specifically target periods of heightened activity, such as mergers and acquisitions, when information exchange increases vulnerability. The impact extends beyond immediate financial losses to include costly system rebuilds, privacy violations, and lasting reputational damage.
Third-Party Vendor Vulnerabilities
Family offices rely heavily on external service providers, creating complex vendor ecosystems that expand attack surfaces. Research indicates that 98% of organizations globally work with at least one vendor that suffered a breach within the past two years.
Portfolio companies present additional risks, particularly smaller entities lacking mature cybersecurity defenses. A breach at one portfolio company can compromise the entire family office network, creating cascading security failures across investment holdings.
Why Family Offices Face Unique Vulnerabilities
Family offices operate with characteristics that make them particularly attractive targets for cybercriminals. Limited cybersecurity resources combined with heavy reliance on third-party providers create multiple entry points for attackers.
The interconnected nature of family office operations means a single vendor compromise can expose portfolio-wide data. High-value assets and trust-based operations make these organizations lucrative targets, while smaller office structures often lack the sophisticated security infrastructure found in larger financial institutions.
Additionally, the concentration of wealth and sensitive family information creates opportunities for targeted attacks that can have devastating financial and reputational consequences from a single successful breach.
Essential Protection Strategies
Implement Comprehensive Security Frameworks
Adopt industry-standard cybersecurity frameworks tailored to family office operations. Regular risk assessments should evaluate both internal systems and third-party vendor security postures. These frameworks must address AI governance, given the increasing use of artificial intelligence in both attack vectors and defensive strategies.
Strengthen Identity and Access Management
Deploy multi-factor authentication across all systems and implement robust access controls limiting data exposure. Regular credential audits ensure former employees and contractors cannot access sensitive information. These controls become critical when managing complex vendor relationships and portfolio company integrations.
Develop Incident Response Capabilities
Create detailed incident response plans that address various attack scenarios, from ransomware to data breaches. Regular tabletop exercises prepare teams for real-world incidents, while clear communication protocols minimize confusion during actual emergencies.
Establish relationships with cybersecurity partners and legal counsel before incidents occur. Understanding how these partnerships function during crisis situations prevents delays in critical response activities.
Invest in Employee Training
Implement comprehensive cybersecurity awareness programs addressing current threat landscapes, including AI-powered attacks and social engineering tactics. Regular phishing simulations help staff recognize suspicious communications, while ongoing training ensures awareness of evolving attack methods.
Training should extend beyond technical staff to include family members and senior leadership who may be targeted in spear-phishing campaigns or social engineering attacks.
Building Cyber Resilience for the Future
Consider partnering with cybersecurity experts who understand the unique challenges facing family offices. To ensure your security investments address the most critical risks while supporting your family’s long-term wealth preservation objectives, contact CrossCountry Consulting.
Family offices are increasingly reliant on digital tools to manage wealth. While these tools offer efficiencies in the way of financial automation and real-time portfolio visibility, they also introduce new cybersecurity risks.
In a recent presentation from CrossCountry Consulting’s Cameron Over, Partner, Integrated Risk Management, and Kevin Alvezi, Director, Sage Intacct, the duo discussed some of the most prominent cyber threats family offices should be defending against as well as best practices to implement.
View the video below for key insights.
The Allure and Vulnerability of Family Offices
Family offices manage significant amounts of sensitive data – financial records, personal information, client information – making them prime targets for cybercriminals.
This data is subject to strict regulations, yet many family offices are highly exposed to various threats like social engineering, phishing scams, ransomware, and other internal/external attacks. Without the right kinds of cybersecurity investments, the damage from a cyberattack goes beyond just financial losses.
Built on a foundation of trust accumulated over generations, family offices are more than just financial institutions – there’s a human, emotional connection to what the family office represents. A successful cyberattack can erode this trust within the family and damage the office’s reputation, and ultimately the legacy of the family business.
In the last decade or so, social media has added another layer of complexity. Family members – young and old alike – sharing personal information online can be exploited in social engineering attacks. And more recently, the rise of artificial intelligence (AI) has enabled bad actors to quickly compile personal family information from across the web to make social engineering attacks more effective and at greater scale. Plus, AI deepfake technology makes it easier to impersonate voices over email or phone call, creating a false sense of trust.
So how can family offices avoid and mitigate evolving risks?
Building a Resilient Cybersecurity Posture
There are several key steps family offices can take to improve their cybersecurity:
- Cybersecurity education: Educate family members and staff about cybersecurity best practices. This includes security awareness training to recognize phishing scams and social engineering tactics.
- Strong, unique passwords: A simple, relatively low-cost password management tool can ensure personal and business passwords are separated.
- Multi-factor authentication: Add an extra layer of security with multi-factor authentication (MFA), which requires a second verification step beyond just a password.
- Encryption: Utilize virtual private networks (VPNs) to encrypt internet traffic, especially when using public Wi-Fi networks and home networks shared with family.
- Incident response plan: Develop a clear plan outlining how to respond to a cyberattack. This should address steps to contain the attack, minimize damage, and notify legal teams, insurance providers, forensics teams, and if necessary, the authorities.
- Cybersecurity insurance: Consider cyber insurance to help offset the financial burden of a cyberattack. Talk to an insurance broker about gaps in any existing insurance plans and where supplemental insurance can be leveraged for optimal coverage.
Technology-Enabled Cyber Expertise
Cybersecurity is an ongoing process and a top business risk, not a single action or investment. Staying informed about the latest threats and updating defenses accordingly is crucial for protecting your wealth and your family’s legacy. To better understand your cyber risk profile and strategize practical cyber solutions designed for family offices, contact CrossCountry Consulting.
Before entering into a business agreement with another entity, organizations must identify incompatible business processes, potential integration problems, or unexpected liabilities through a due diligence process.
Traditionally, due diligence focused on business operations, legal concerns, and financial statements; however, with companies increasingly reliant on data and technology and cyber risks proliferating, it’s imperative to the security and reputation of an organization that cybersecurity posture, governance, and practices also be regarded.
Consider the following framework and questions when evaluating an acquisition or merger target. Depending on the nature of the business, some areas may pose a larger threat than others and require greater scrutiny.
Cyber Risk Management
What digital assets are we protecting, and what are the greatest risks to those assets?
Organizations should possess a clear understanding of critical digital assets, top cyber threats and risks, and all legal and regulatory requirements impacting the company. They will also maintain documented formal processes and leverage systems and automation where possible to identify and monitor threats and vulnerabilities.
Due diligence questions to consider:
- Digital assets “crown jewels” identification
- What are the most business-critical data, systems, and digital assets?
- Is there an inventory of these critical digital assets and is it maintained?
2. Cyber risk identification, prioritization, and reporting
- Have they identified and prioritized the top cyber threats and risks to the company?
- How are cyber risks documented and reported to the C-Suite and Board?
3. Cyber regulatory compliance
- What cyber-related regulations is the company subject to?
- What is the process for maintaining regulatory compliance?
Cyber Governance
Does the organization have the right baseline cyber plans, policies, and behaviors?
Organizations must maintain documented and well-communicated cybersecurity policies and procedures, with mandatory training for all users and role-based training for their cyber professionals. Cybersecurity roles and responsibilities are established, coordinated, and aligned with internal employees and third-party stakeholders (suppliers, customers, partners). All cybersecurity projects and initiatives align with the organization’s goals and aim to continually strengthen their security posture.
Due diligence questions to consider:
- Cyber strategy and planning
- Does the company have any major cyber-related priorities/initiatives/activities planned over the next year?
- Have any major initiatives been recently completed? How were these initiatives determined and managed?
2. Cyber budget and staffing
- What are the key organizational roles with cyber-related accountability or responsibility?
- Approximately how many full-time equivalent (FTE) resources work cyber?
- What is the annual spend on cybersecurity, and how is the cyber budget determined?
3. Cyber policies and procedures
- What formal, documented cyber-related policies exist?
4. Cyber awareness and training
- Do employees undergo security awareness training?
- What is the frequency/scope of trainings, and to what extent is role-based training utilized?
Cyber Controls
What key technical controls are in place to secure our data, systems, and networks?
Organizations adhering to best practices utilize multifactor authentication (MFA) integrated into all authentication workflows and maintain automated monitoring and enforcement of encryption and data protection configurations for all servers and devices. Automated processes are implemented for monitoring and alerting of vulnerability/security threats, non-compliant devices, and application code scans. The organization will also maintain recurring, scheduled penetration testing and formalized assessments of its technical security controls.
Due diligence questions to consider:
- Overall protective controls
- What processes, tools, and vendors are utilized? Responses should cover:
- Identity and access management (including role-based access control), multifactor authentication, and password rotation.
- Network and endpoint security: EDR, VPN, firewalls, anti-virus, content filtering, email security, device encryption, and mobile device management.
- Vulnerability management and patch management.
- Data protection, data lifecycle management, and data loss protection.
- Application security, security of custom-built (in-house or customer-facing), and third-party applications.
2. Controls testing
- Does the company utilize penetration testing or other technical security controls testing? If so, what is the frequency and scope?
Cyber Response and Resilience
Can the organizations effectively respond to and recover from a cyberattack?
Organizations should maintain well-documented continuity and disaster recovery plans, including supporting scenario playbooks and communication templates, which are tested and revised on a scheduled basis. Additionally, it’s vital to procure right-sized insurance coverage and sign cyber incident response retainers with at least one external firm.
Due diligence questions to consider:
- Business continuity and disaster recovery
What plans, procedures, and playbooks exist to ensure business continuity and rapid recovery from a cyber (or other adverse) event, and to what extent and how are these tested?
2. Incident response
- What cyber incident response plans, procedures, and playbooks exist, and to what extent and how are these tested?
- Does the company have retainer agreements with cyber incident response firms and if so, what firm(s)?
3. Cyber insurance
- Does the company have cyber insurance and if so, who is the underwriter, what is the extent of coverage, and what are the main exclusions?
Failing to assess the cybersecurity risk posture of an M&A target can expose companies to tremendous financial, data, and reputational damage. By asking these questions during the diligence process, organizations will better understand the threats and vulnerabilities of the M&A candidate. For expert cybersecurity and M&A due diligence, contact CrossCountry Consulting.
Amid continuous technological, regulatory, and financial transformation, the internal audit function is evolving into more of a strategic advisor to management and boards, as opposed to a pure assurance function.
This shift has come more naturally to organizations on the forefront of risk management, technology adoption, and talent upskilling but has been a steeper curve for more conventional leaders who’ve kept internal audit siloed. In conversations with regulators, auditors, and risk leaders in financial services at 2024’s RMA Annual Internal Audit Conference, CrossCountry Consulting’s Integrated Risk Management experts discussed and delivered some of these central themes driving the internal audit function of the future.
Explore takeaways for 2025:
Harnessing AI’s Impact and Influence
For companies able to capture the value potential of AI, it can be deployed strategically within internal audit as an accelerator while still preventing the introduction of undue risk. For example, internal auditors can leverage AI for analyzing large inventories of documents and preparing summaries.
But the path to adoption hasn’t been smooth to date. Although an estimated 55% of businesses are implementing AI, just 2-4% of internal audit teams have made any AI progress at all.
Additionally, AI requires large amounts of computing power, data, and access, which companies may not have established to date. This cloud infrastructure, however, is the foundation for experimenting with AI-powered data analytics at a scale needed to deliver tangible cost and labor savings within internal audit. On the personnel side, without the right talent and training, AI adoption won’t occur organically or add any strategic value. Auditors must grapple with immediate audit demands while remaining ahead of the AI curve.
Cybersecurity’s Critical Points of Exposure
Particularly with the additional risk exposure of GenAI, a tenuous geopolitical landscape, and recent election cycles potentially changing policy, cyber threats continue to be a key theme. During opening remarks, the IIA Global BoD Chairwoman noted that the 2025 Risk in Focus study performed by the IIA indicates cybersecurity continues to be the No. 1 risk worldwide, with digital disruption (including AI) and climate change/environmental risk both climbing year over year. These study results indicate that for audit teams to build proficiency and perform more strategic audits, they may require a different way of approaching audits. Moving forward, this might also require different talent and skill sets.
Similarly, during the Operational Resilience discussion jointly presented by Deloitte and CrossCountry’s Cameron Over, Risk Advisory Partner and National Cyber Leader, conversations focused on:
- The increasing regulatory landscape.
- The proliferation of cyber threats to organizations, largely through vendors or third parties.
- The need for organizations to consider key resilience and reliance gaps for their trusted vendors in the wake of the CrowdStrike software update failure.
- The consideration of deeper testing rigor, including scenario-based testing using insights from threat intelligence.
Emerging Regulatory Trends and Risks
Regulators in attendance at RMA provided critical insights into the trends they’re seeing and how businesses can adjust their perspectives accordingly. For instance, internal audit faces a more complex role with global footprints expanding, and they must decide which type of auditing program is most efficient: continuous monitoring or scheduled audits.
Because regulators are talking to first, second, and third lines of defense, it’s imperative that non-auditor experts are also involved in high-level risk management discussions. This reality emphasizes the need for greater collaboration across lines of defense and between corporate functions to ensure a systematic approach to risk and audit.
Other key themes included:
- Evolve risk assessments from qualitative to quantitative.
- Understand third- and fourth-party risks to ensure adequate monitoring and audit coverage.
- Auditors must be curious about new and emerging risks and leverage technology to identify these risks. A few ways to uncover emerging risks are to coordinate with all lines of business, establish a common nomenclature, and read risk publications, speeches, and public orders.
- Internal audit must be involved in M&A due diligence and the implementation of automation and GenAI systems.
- Practice the story and the delivery of audit findings with executives and key stakeholders to ensure the right message, recommendations, and angles are being communicated. When sharing results, have an open dialogue with core groups to make audit findings more impactful.
Aligning 3 Lines of Defense
Sometimes referred to as “connected risk” or “threelignment,” the more integrated and collaborative the three lines of defense are, the more positive the outcomes. Some of the best ways organizations can establish and enhance these points of connectivity are by:
- Having all teams provide feedback early and often in support of the enterprise at large. Risks, threats, and opportunities should be openly communicated and workshopped so that risk, compliance, and audit functions aren’t just designed to protect value but to create value as well.
- Prioritizing units under regulatory scrutiny so that attention is focused where it can have the most impact.
- Using IT as an enabler and accelerator to aligning three lines of defense across teams, systems, and processes. This includes the adoption of comprehensive GRC platforms and data aggregation tools.
As these groups collaborate more effectively, they provide a more consistent, repeatable audit experience that will become the norm in 2025 and beyond.
To ensure your organization’s internal audit function is driving value creation in 2025, contact CrossCountry Consulting.
As the Cybersecurity Risk leader for CrossCountry Consulting and a longtime Chief Information Security Officer (CISO) advisor at a leading consulting firm, I’ve witnessed firsthand how the digital threat landscape has fundamentally transformed the way private equity firms approach investments and portfolio management. The stakes have never been higher: cyberattacks now routinely target PE funds and their portfolio companies, seeking to exploit vulnerabilities for financial gain, corporate espionage, or simple disruption.
Now more than ever, cyber threat evaluation and cyber diligence are not just prudent best practices – they’re cornerstones for PE success.
The Evolving Threat Landscape for Private Equity
PE firms and their portfolio companies are uniquely attractive targets for cyber adversaries. Attackers know that PE-backed organizations often undergo rapid change – acquisitions, integrations, and divestitures – which can create security gaps. The sensitive nature of deal data, intellectual property, and personal information handled by PE firms only increases the risk.
Moreover, attackers are increasingly sophisticated. Ransomware gangs, nation-state actors, and organized cybercriminals all recognize the potential payoff of breaching a PE firm or its portfolio. The interconnectedness of today’s business ecosystems means a compromise in one company can quickly cascade across the entire portfolio.
Why Cyber Diligence Must Be Integral to M&A
Cyber diligence is the process of rigorously assessing a target’s cyber risk profile during M&A. This capability is now a non-negotiable element of any deal. As a CISO advising PE clients, I’ve seen deals derailed or dramatically repriced due to undisclosed breaches, regulatory non-compliance, or the discovery of systemic vulnerabilities during diligence.
Critical Reasons Why Cyber Diligence Is Vital During M&A
- Valuation accuracy: Hidden cyber risks can significantly erode a company’s true value. Unaddressed vulnerabilities or a history of past breaches may lead to extensive remediation costs and regulatory fines, which was the case when Yahoo’s purchase price famously fell by $350 million after it failed to disclose two cyberattacks to its acquirer, Verizon.
- Regulatory compliance: Evolving regulations, such as SEC rules and global data privacy laws, mean acquirers could inherit serious liabilities if diligence is superficial.
- Operational continuity: Overlooked cyber weaknesses can derail business operations after acquisition, delaying integrations or tarnishing reputations.
- Exit strategy: Buyers in secondary transactions increasingly scrutinize cyber posture. A comprehensive cyber program can mitigate risk and enhance a portfolio’s attractiveness during secondary transactions.
What Comprehensive Cyber Diligence Looks Like
CrossCountry Consulting’s approach to cyber diligence is holistic and risk-driven. We move beyond basic checklist assessments to deliver actionable insights that inform investment decisions and post-close planning.
- Threat landscape assessment: Gain an in-depth understanding of sector-specific threats and recent attack trends relevant to the target.
- Technical vulnerability scanning: Leverage best-in-class tools (e.g., Tenable, Rapid7) to identify weaknesses in infrastructure, applications, and endpoints.
- Policy and governance review: Assess the maturity of cybersecurity governance, incident response planning, and regulatory compliance frameworks.
- Third-party risk evaluation: Scrutinize the exposure stemming from key suppliers and partners, which are often the weakest link in any security chain.
- Historical incident review: Examine prior breaches, the effectiveness of responses, and lessons learned.
- Remediation roadmap: Quantify the cost, timeline, and complexity associated with closing identified gaps, information that is crucial for both negotiation and integration.
Ongoing Cyber Risk Management: Beyond the Deal
Cyber diligence is not a one-time activity. The threat environment continues to evolve as portfolio companies grow, digitize, and adopt advanced technologies. Leading PE firms now require continuous cyber risk management across their portfolios.
Core Elements of Effective Portfolio Cybersecurity
- Baseline security controls: Adoption of enterprise-grade controls, such as multi-factor authentication, endpoint detection and response, and data loss prevention, is standard practice.
- Centralized monitoring: Dashboards and managed services provide real-time visibility over the cyber health of portfolio companies.
- Incident response readiness: Develop and test incident response plans to ensure rapid and coordinated action in the event of an attack.
- Ongoing training: Given that human error remains a leading cause of breaches, security awareness programs (e.g., KnowBe4) are an indispensable component of risk reduction across the portfolio.
- Regulatory and compliance tracking: Staying on top of global regulations is vital to avoiding fines, sanctions, and reputational damage. Tools like OneTrust help automate privacy and compliance management.
The Business Case for Proactive Cyber Risk Management
Embedding cyber diligence and ongoing risk management into PE operations yields undeniable benefits:
- Value preservation: Preventing catastrophic breaches preserves investment value, avoids costly remediation, and ensures operational continuity.
- Competitive advantage: Demonstrating a robust cyber program differentiates firms during deal sourcing and creates value at exit.
- Regulatory confidence: Proactive compliance instills confidence among regulators and reduces the risk of fines, sanctions, and reputational damage.
- Investor assurance: Limited partners (LPs) are increasingly demanding greater transparency and demonstrable assurance around cyber risk management.
Case Study: Turning Cyber Risk into Portfolio Value
A PE client responsible for a global portfolio of mid-market companies faced recurrent ransomware attacks that threatened operations and company valuations. By instituting a centralized cyber risk management program combining technical controls, continuous monitoring, and incident response readiness, they not only reduced the frequency and impact of incidents but also enhanced the attractiveness of their portfolio to future buyers. This case underscores that proactive cyber risk management is not just about damage control – it’s a robust value-creation strategy.
Recommendations for PE Leaders
Drawing on decades of experience as a CISO and cyber advisor, my advice to PE leaders is clear:
- Make cyber diligence mandatory: Integrate cyber risk assessment into every stage of the M&A process.
- Standardize security across the portfolio: Establish and enforce minimum security standards for all portfolio companies.
- Invest in talent and technology: Leverage top-tier cybersecurity tools and collaborate with experienced consultants who understand the nuances of the PE landscape.
- Foster a culture of cyber awareness: Regular training and executive engagement are essential to maintain vigilance.
- Prepare for the inevitable: Assume incidents will occur; readiness and rapid response are your best defenses.
Cyber Resilience as a Strategic Imperative
PE firms that integrate cybersecurity throughout their investment lifecycle will be best positioned to protect and grow value, satisfy regulators and investors, and forge resilient, future-ready portfolios. As cyber professionals, our role is to help PE firms use cybersecurity as a lever for growth rather than just a shield against threats.
If you’re a PE leader seeking to strengthen your approach to cyber risk, now is the time to act. With the right strategy, partners, and a commitment to continuous improvement, cyber risk can be managed – and even harnessed – to drive lasting value creation. Contact CrossCountry Consulting to get started.
In the current economic environment, risk leaders are being asked to find additional savings, create efficiencies, or stay “budget neutral,” limiting their ability to make significant investments in the very technologies that could enable long-term incremental savings. The wish lists of “must haves” and “nice to haves” are likely being pruned to include only “must haves” at this point.
For risk leaders, this challenging budgeting and planning dynamic is compounded by:
- Increased auditor and regulatory scrutiny.
- New regulatory requirements and SEC rules.
- Evolving risk and market conditions.
- Increased non-financial risk, including third-party risk.
- High employee turnover.
- Poor organizational data management practices.
Amid these obstacles emerges, the time for integrated risk management has come.
What Is Integrated Risk Management?
Integrated risk management (IRM) is a comprehensive approach to managing all risks within an organization. This approach ties together the high-level risk pillars of the organization – enterprise-wide risk, technology risk, financial and compliance risk, and operational and strategic risk – enabling the creation of a common set of practices and processes that drive standard business operations and procedures cross-functionally.
Featured Content
How to Implement Integrated Risk Management
IRM allows leaders to prioritize where time and resources should be invested. This prioritization will be unique to the demands, strategies, and goals of each organization.
While there are numerous ways organizations can commit to and execute IRM, the below mechanisms are generally productive, agnostic starting points:
- Creating a risk-aware culture: The crucial first step to effective IRM is to ensure the tone at the top of the company is set and a risk-aware culture is being implemented across the organization. This involves training employees to understand and manage risks within their roles and promoting a mindset that prioritizes risk identification and mitigation. Employees should understand not only why they are performing controls but how to identify whether controls are operating as intended.
- Enhancing cross-functional collaboration: IRM requires collaboration across different departments within an organization like finance, IT, compliance, legal, and operations to help identify, assess, and mitigate risks. Many organizations are adopting IRM technologies or tools that consolidate various risk-related processes into a single platform. This allows for a holistic view and better management of risks. It also avoids duplication of efforts and creates better accountability.
- Leveraging data analytics, automation, and AI: Risk management is an ongoing process. With data and predictive analytics tools, organizations can analyze large volumes of data to identify potential risks and trends and surface risks before they escalate. Automation and artificial intelligence (AI) platforms can simultaneously streamline and expedite highly manual processes and controls, improving the reliability and accuracy of data and decision-making.
- Performing dynamic risk assessments and scenario planning: Unlike traditional risk assessments, which are typically conducted annually, dynamic risk assessments acknowledge that risks change and new hazards arise. They emphasize the importance of adaptability and flexibility in addressing risks effectively. Conducting dynamic risk assessments and scenario planning exercises on an ongoing basis empowers organizations to formulate appropriate responses to variable risk scenarios. This proactive approach to risk management helps to mitigate the impact of potential risks that would otherwise likely be more severe or entirely unexpected.
- Keeping pace with evolving regulatory compliance: Staying abreast of changing regulations and ensuring compliance is a key aspect of IRM. With changes such as SEC Cybersecurity Disclosure Requirements or SEC Climate Risk Disclosure Organizations, organizations must stay ahead of what’s coming so they’re prepared to comply when regulations are released. Companies should invest in tools and processes to monitor regulatory changes and ensure adherence across the organization.
- Increasing Board and leadership involvement and education: Boards and senior leadership play a critical role in IRM. They set the tone for risk management strategies, oversee the implementation of IRM frameworks, and ensure that risk management is integrated into the organization’s overall strategy. It’s critical to ensure that all members of the Board and senior leadership are educated in critical areas of risk, such as cybersecurity. It’s also critical that the Board and senior leadership are provided with accurate data to ensure they’re making informed decisions.
- Focusing on resilience planning: One huge lesson that many organizations learned during COVID and with the recent CrowdStrike incident was the importance of focusing on business continuity and resilience. Building organizational resilience to bounce back from unforeseen events involves not only identifying risks but also preparing strategies to recover swiftly from potential disruptions.
By incorporating these strategies, organizations can create a more robust and proactive approach to managing risks across all facets of operations. To implement IRM strategically, contact CrossCountry Consulting.
Navigating the uncertainty of the SEC’s latest changes to cybersecurity and ESG rules has been a challenge to risk management leaders. At all stages of risk maturity, companies must contend with ongoing litigation around the rules and continuously shuffle priorities among everything else on their plate, including year-end audit requirements, the introduction and application of AI, and various internal transformation initiatives.
During a panel at AuditBoard’s 2024 Audit & Beyond Conference entitled “Checklist for Success: Best Practices for Compliance with New SEC Rules for ESG and Cybersecurity,” CrossCountry Consulting’s Steve Coppolino led a discussion with two seasoned experts, Kristina Wyatt and Manju Mudé, who provided valuable insights into the new SEC rules governing ESG and cybersecurity disclosures. These regulations, aimed at promoting transparency and protecting investors, highlight the evolving compliance landscape and underscore the importance of strategic governance for organizations across all sectors.
Below are some of the key takeaways, challenges, and best practices discussed during the session.
ESG Disclosure Rules
- Challenges: Kristina Wyatt, Deputy General Counsel & Chief Sustainability Officer at Persefoni AI and a former Senior Counsel at the SEC, highlighted the importance of transparency in the ESG domain. Although some aspects of the rule, such as Scope 3 emissions reporting, are still under debate and likely to be scaled back, companies are encouraged to prepare for an increase in required disclosures. There is a need for consistency in reporting regardless of the SEC rule finalization as found across other released guidance (inclusive of Corporate Sustainability Reporting Directive (CSRD) and California SB 253 and 261). Climate-related risks are truly shaping how companies think about sustainability,
- Best practices: To prepare for ESG disclosure requirements, companies should integrate climate risk into their overall governance and reporting frameworks, conduct thorough assessments, and develop strategies to address potential risks.
Cybersecurity Disclosure Rules
- Challenges: Manju Mudé, Chief Information Security Officer, formerly Splunk and Oportun, emphasized that the new cybersecurity rules require timely incident reporting, creating a need for companies to balance transparency with confidentiality. Organizations are grappling with several challenges in meeting the new cybersecurity disclosure requirements, including identifying material incidents, striking a balance between transparency and business risk, and operationalizing incident reporting. Mudé explained that organizations face challenges in disclosing security incidents without compromising sensitive information that could further expose them to risks.
- Best practices: To comply with cybersecurity disclosure requirements, organizations should implement robust governance and risk management frameworks, conduct regular assessments, and have clear incident response plans in place.
Integrating ESG and Cybersecurity Compliance
- Alignment: A key theme that emerged was the intersection of ESG and cybersecurity within corporate governance. Both disclosures emphasize the need for robust risk management, reinforcing the importance of elevating these areas to the board level. By integrating ESG and cybersecurity reporting into their broader integrated risk management approach, organizations can streamline compliance efforts, enhance overall governance, and demonstrate a commitment to sustainability and resilience. Depending on the size and industry of the business, teams responsible for compliance may already be stretched thin, so approaching ESG and cyber domains as an integrated effort can avoid silos and redundancies.
- Navigating uncertainty: Given the ongoing litigation and potential changes to the rules, organizations should adopt a flexible approach, monitor developments closely, and be prepared to adjust their compliance strategies as needed. Reporting teams should develop templates and repeatable playbooks that are responsive to further SEC changes, empowering them to think about compliance proactively and efficiently without introducing additional complexity once their companies must effectively comply.
For expert support complying with evolving SEC rules, contact CrossCountry Consulting.
Pervasive economic volatility, technological innovation, and regulatory change call for an advanced, forward-thinking approach to risk management.
The necessity of a new risk management framework is evidenced by the Institute of Internal Auditors (IIA) refreshing its Global Internal Audit Standards and the Committee of Sponsoring Organizations of the Treadway Commission (COSO) releasing a newer edition of its Fraud Risk Framework.
These updates are in response to the complexity and volume of dynamic risks modern organizations continuously face. The updates also support and inform the creation of new risk management strategies and perspectives that shift the way risk, financial, and operational leaders are thinking.
What if risk could be harnessed as a strategic ally for business success in 2025 and beyond? How can current and future risk universes be transformed into real business drivers?
What Is Risk Transformation?
Risk transformation prompts organizations to seamlessly align enterprise-wide risk management practices to overarching business strategies. Doing so enables risk practitioners to inform and lead business decision-making on how to best navigate risk complexity and how to view risk not as a challenge but as an opportunity that can drive strategic success.
Organizations that take a risk transformation approach can turn holistic risk anticipation and mitigation into differentiators and create new enterprise and market value.
Additionally, by positioning risk as a strategic driver of success, the future of risk management becomes much more data-driven and technology-enabled by the latest advancements in progressive automation, analytics, cloud, artificial intelligence (AI), and machine learning (ML) technologies. This tech-forward approach is supported by standardized processes, sustainable controls, and timely insights that streamline and elevate decision-making.
Unlocking Value: The Benefits of Risk Transformation
Embarking on a risk transformation journey might initially seem daunting, but the realized value can be significant, as demonstrated by the benefits outlined below:
- Enhanced risk visibility across the organization: By leveraging data and advanced technologies, organizations can better understand and act on their risk landscape. This increased visibility enables agile, real-time risk management that adapts to evolving risks and empowers risk leaders to make decisions that are optimized for value creation – not just risk remediation.
- Risk as a strategic ally: No longer viewed as just a challenge, risk is pivotal to strategic decision-making. Enterprise-wide risk management practices and corporate business strategies inform and align with each other, allowing functional and business leads to preemptively look for ways to transform operations now that risk is perceived as a strategic ally.
- Proactive risk management: An agile approach to risk management means organizations can proactively anticipate emerging risks rather than just responding to them. This forward-thinking perspective ensures better preparedness and resilience in the face of uncertainties.
- Streamlined internal control framework: Prevention and mitigation of risk is simplified with best-in-class controls embedded in business processes, data, and technologies. Controls are designed with standardization and automation, driving excellence and consistency in the control environment and reducing the burden and cost of compliance.
- Improved employee experience: With a reduced compliance burden, employees can focus on efforts that drive strategic objectives and add value to the organization, opening up meaningful career paths to staff.
The Risk Transformation Maturity Model: A Roadmap to Success
The first step toward successful risk transformation is for organizations to understand their maturity and define what success looks like to them. The risk transformation maturity model below illustrates the advancement of risk management practices across data, processes, technology, and people:

After understanding their current position in the risk transformation journey and the desired future state, risk leaders can develop an actionable roadmap to achieve a new, transformed risk function. Considerations on the roadmap may include:
- Aligning risk practices with overarching business strategies.
- Implementing dynamic risk assessments.
- Developing an approach to anticipate and adapt to emerging risks, including non-financial risks.
- Evaluating and streamlining the control environment.
- Deploying continuous monitoring and automated testing.
- Enabling innovative technologies.
Building a Resilient Future
Risk transformation isn’t just a trend; it’s a necessity for organizations looking to thrive in a rapidly evolving world, and it’s the clear future of risk management. With streamlined processes, centralized data, and leading technology, organizations can enhance risk management practices to see around corners, drive growth, and achieve sustainable success.
For expert support in navigating a successful risk transformation, contact CrossCountry Consulting.
Most finance leaders can describe their sales tax process in a single sentence: “We use AvaTax, it works, we move on.” Use tax on the purchase side rarely earns that same confidence. It tends to be fragmented, applied inconsistently, and handled after the fact, introducing risk and inefficiency into everyday operations.
That disconnect shows up consistently across Coupa and finance transformation engagements, and it’s exactly the gap Cross Connect for AvaTax was built to close.
Learn what it means to embed tax into procure-to-pay, why purchase-side tax quietly becomes a liability, and how leading finance organizations are moving tax upstream in the process.
The challenge: Tax isn’t embedded in the process
Across organizations, a familiar pattern emerges. Tax on purchases isn’t determined at the point of decision. Responsibility is spread across teams with no clear owner, and issues surface late, usually during reconciliation or audit prep, when options are limited and pressure is high.
The financial impact is real:
- Overpaid tax that’s rarely recovered
- Underaccrued tax that creates audit exposure
- Operational drag across accounts payable and tax teams
This isn’t simply a tooling problem. It reflects a broader gap in how tax is built into procurement. When tax sits outside the process, it becomes something you reconstruct rather than something you control. This challenge isn’t unique to any one organization.
A recent Avalara survey found that 53% of finance, tax, and procurement leaders cite complex, ever-changing tax rules as one of their most significant challenges, and more than half said better integration with purchasing systems would meaningfully improve their compliance posture.
A shift is already underway
Leading finance organizations are addressing this by moving tax upstream, from a downstream reporting activity to a transaction-level control. The change reshapes how teams operate:
- Finance gains visibility into total cost before commitment.
- Accounts payable sees fewer exceptions and smoother processing.
- Tax teams shift from reconciliation to proactive risk management.
Embedding tax earlier is no longer a “nice to have.” It’s becoming a requirement for maintaining control, compliance, and efficiency at scale. The organizations getting ahead treat tax as part of the decision, not a problem to clean up later.
This mirrors a broader trend across procurement technology, where teams are increasingly building governance and controls directly into transaction workflows rather than layering them on afterward, a theme we’ve also explored in the context of AI-enabled accounts payable.
Where Cross Connect fits
Cross Connect integrates Avalara’s AvaTax directly into Coupa’s procure-to-pay process. Rather than addressing tax after the fact, it embeds tax determination into the flow of transactions.
Instead of reconstructing tax positions at month-end, your organization can:
- See tax earlier in the purchasing process
- Validate tax in real time
- Maintain a consistent, audit-ready position across spend

The result is a more transparent, efficient approach to managing indirect tax, without disrupting how your teams already work inside Coupa.
What this means for finance teams
The day-to-day impact is meaningful and measurable:
- Tax teams spend less time on reconciliation and more on planning and exposure management.
- Accounts payable experiences fewer exceptions and faster cycle times.
- Procurement gains clearer visibility into total cost at the point of decision.
- Finance leadership holds a more defensible, audit-ready tax position.
In short, you trade reactive cleanup for proactive control and free your teams to focus on higher-value work like strategic sourcing and supplier management, an area covered in more depth in our Procurement & Cost Transformation work.
Looking ahead
Tax shouldn’t be something you reconstruct at the end of the month. It should be part of the transaction itself.
Cross Connect is designed to make that change practical, bringing tax into the process where it belongs, with the control and confidence finance leaders expect.
If your purchase-side tax still lives outside the transaction, it’s worth a closer look. To see how Cross Connect for AvaTax can close the use tax gap inside your Coupa environment, contact CrossCountry today.
Custom separately managed accounts (SMAs) are not new, but the delivery standard needed to compete is. Institutional-grade controls, data architecture, and operating discipline are now the baseline for any manager trying to scale in the managed account market which is projected to reach almost $25 trillion by 2030.
Custom SMAs Are Entering Their Next Phase
Custom SMAs are converging toward institutional standards. The accounts stay separately managed, and personalization keeps expanding. What is changing is the delivery model.
The largest managers already apply governed, risk-aware, account-by-account portfolio management to institutional mandates. That same discipline is now expected in the SMA market.
The managed account market is growing fast and getting more complex. Assets reached $13.7 trillion in 2024 after two consecutive years of roughly 20% growth. SMA programs have compounded at about 18% annually over the past five years. The asset base is also shifting: equity-only strategies remain the largest segment, but their share is declining. Multi-asset, derivative-heavy, and alternative SMAs are growing, and with that growth comes a delivery problem.
The flexibility that once defined the SMA value proposition becomes a liability without institutional-grade controls. The largest managers already apply governed, risk-aware portfolio management account by account across their institutional mandates. That same discipline is now the expectation in the SMA market, and the delivery model must catch up.
Capability Gaps Are Already Binding Growth
Most older SMA platforms were built for single-asset strategies with limited customization. They struggle with diversified, multi-asset portfolios that carry varied tax, risk, and restriction profiles at full scale. For many managers, this is not a future problem. It already limits growth.
The main demand drivers are tax-loss harvesting, direct indexing, lower minimums, and service reaching a broader client base. Each pulls investment, distribution, and operations in competing directions. The complexity is increasing operational risk and stretching existing teams.
Personalization will not scale without an institutional-grade platform.
Institutionalizing does not mean copying every institutional process. It means using the ones that matter:
- Governed portfolio construction with repeatable processes
- Clear segmentation that drives operational differences
- Data built into the operating model from the start
- Risk and compliance built in at every step
- Technology that performs consistently across thousands of varied accounts
Manage the Full Account, Not Separate Pieces
A single direct-indexed SMA may hold taxable fixed income, completion overlays, structured exposures, and options-based risk management. Managing these as separate strategies bolted together afterward breaks down operationally and adds risk.
The fix is to manage the account as one unit: unified cash management, consistent tax policy, shared restrictions, and centralized exception handling.
At scale, personalization runs on complex rules. Client preferences become set parameters: restrictions, factor tilts, tax budgets, ESG constraints, tracking-error targets, and liquidity buffers. Institutional managers already work this way because it is the only way to deliver consistent results across institutional custom mandates. The SMA market is reaching the same point, often before it has the technology infrastructure to deliver it.
Single-Contract vs. Dual-Contract Programs
Program structure shapes the delivery challenge.
In single-contract programs, the manager controls more of the process, which allows tighter standardization across onboarding, restrictions, tax logic, trading, and reporting. That control also puts more responsibility on the manager to integrate across custodians and sponsors.
In dual-contract programs, the sponsor plays a larger role in client relationships, policy, and operations. That creates fragmentation: multiple sponsor rule sets, differing data standards, and variable operational boundaries. Translating each sponsor’s policies becomes a core skill. Firms that treat dual-contract delivery as just another channel struggle at scale, because they underestimate how much sponsor variation fragments their operations.
Sponsor Variation Is the Real Constraint on Scale
Portfolio construction gets most of the attention. In practice, variation across sponsors and custodians is one of the main limits on scalable customization.
Sponsor-custodian combinations determine:
- Account opening workflows and onboarding timelines
- Tax-lot accuracy and corporate action processing
- Restriction implementation and trade communication protocols
- Reporting timeliness and exception ownership
Integration governance, not portfolio design, drives growth. Firms that scale operate like institutional mandate onboarding teams: standardized controls, formal testing, data certification, disciplined cutovers, and post-launch stabilization, run repeatedly across sponsor and custodian environments.
This is where data transformation capabilities matter most. They hold a complex, multi-sponsor delivery model together.
Delivery Decides Who Captures Share
The market is growing, the client base is expanding, and strategies are becoming more complex. The firms that capture the most share will not be those with the most sophisticated investment process, but those that rebuilt their delivery models to meet the institutional standard the market now demands.
For asset managers competing at scale, the question is no longer whether to institutionalize the separately managed account (SMA) operating model, but whether to do it before platform constraints force the decision.
CrossCountry Consulting’s Asset Management practice can help redesign the delivery model that makes institutional-grade personalization scalable. To explore what that transformation could look like for your company, contact us today.
Government contracting M&A is accelerating. According to The McLean Group, Q1 2026 was the strongest single quarter for Defense M&A, with 104 closed transactions. This increase is partly influenced by the US General Services Administration’s procurement consolidation, which is reshaping how federal spending flows through managed vehicles.
But what buyers are really acquiring is not just revenue. It is permissions: permissions to bid on set-aside work, use contract vehicles, handle sensitive data, and recover costs. Six converging changes in 2026 threaten to strip those permissions away at the moment of transaction.
For private equity buyers in particular, where deal models often underwrite revenue stability and set-aside transferability, the stakes are significant.
1. DOGE Terminations and the Government Shutdown Are Distorting Financials
By February 2025, DOGE had terminated more than 2,400 contracts and issued stop-work orders on 200+ more, with professional services hit the hardest. The 43-day government shutdown that followed delayed payments, stalled awards, and created unusual accounts receivable patterns across the industry.
Standard Quality of Earnings (QoE) normalization removes isolated one-time items. It is not built for overlapping disruptions affecting revenue, backlog, collections, and pipeline simultaneously. Buyers treating DOGE terminations as a simple add-back exercise miss the bigger question: is the remaining revenue base stable?
What this means for diligence:
- Civilian services revenue and defense technology revenue now carry different forward-risk profiles and should be modeled separately
- Shutdown-driven AR aging is a timing issue; pre-existing aging may signal credit or collection risk
- Backlog tied to affected agencies or vehicles requires separate sensitivity analysis, not a blended haircut
2. FY2026 NDAA Changes to CAS and TINA Thresholds Create Hidden Exposure
The FY2026 National Defense Authorization Act (NDAA) raised thresholds for Cost Accounting Standards (CAS) coverage and certified cost or pricing data requirements under the Truthful Cost or Pricing Data Act (formerly TINA). In plain terms, the bar moved up, so fewer contracts trigger these rules than before

Defense contracts certified under the previous $2.5 million pricing threshold may continue to present defective pricing risk after a transaction closes. While the threshold has since increased, potential liability tied to contracts awarded under the earlier requirement may still remain.
Most buyers ask whether the target is CAS-covered today. The better diligence question is what gets triggered after close. If the combined company’s award profile crosses the new CAS thresholds, future CAS-covered awards may trigger Disclosure Statement obligations, FAR Part 30 notices, and changes to established cost accounting practices.
Nontraditional defense contractor (NDC) status is now a key diligence item. NDCs generally have not performed full CAS-covered DoD work during the relevant one-year look-back period, and new FY2026 NDAA exemptions may reduce their cost, pricing, and business-system compliance burdens. Because NDC status is tied to the entity that will hold or perform DoD work, buyers must confirm whether NDC-based exemptions remain available under the deal structure before building them into margin forecasts.
3. SBA Recertification Rules Have Reduced the Transferability of Set-Aside Revenue
Buying a small government contracting firm can put its future set-aside revenue at risk.
Effective January 16, 2025, the Small Business Administration (SBA) changed its recertification rules, which now limit when acquired small businesses can continue competing for set-aside work after losing small business status.
The impact is not the same for every contract type. Use the colors below as a quick guide. Red means eligibility ends right away. Yellow means it may end soon or depends on the details. Green means a narrow path may still exist.

For private equity platform transactions, this is a big deal. Set-aside revenue often gets valued as if it would turn into open, unrestricted revenue over time. Do not value it that way unless you have confirmed eligibility through a vehicle-by-vehicle review.
These rules encourage small-to-small business M&A because they may preserve set-aside vehicle eligibility that a large-buys-small transaction would lose after recertification.
4. CMMC 2.0 Puts Revenue and Deal Value at Risk
Defense contractors that handle Controlled Unclassified Information (CUI) need a credible path to Cybersecurity Maturity Model Certification (CMMC) 2.0 readiness. Beginning November 10, 2026, applicable DoD solicitations may require Level 2 certification by a CMMC Third-Party Assessment Organization (C3PAO) as a condition of award. Without one, they may carry revenue at risk on DoD solicitations, options, and recompetes that require CMMC status. This process can take nine to 18 months. So any target without an active CMMC plan is already behind.
There is a second risk that is just as serious. False Claims Act (FCA) exposure for past cybersecurity misstatements does not disappear when the deal closes. The Department of Justice has actively pursued these cases through its Civil Cyber-Fraud Initiative. Treat CMMC status as a critical diligence item, not something to fix after close.
For a deeper framework, read Assessing Cybersecurity During M&A Due Diligence.
5. The Shift to Firm-Fixed-Price Contracts Is Increasing Post-Close Margin Risk
On April 30, 2026, the White House issued an Executive Order making fixed-price, performance-based contracting the default and preferred approach for federal procurement. Agencies now need written justification and, above certain thresholds, written approval to use non-fixed-price contracts. For buyers, this shift pushes cost risk straight onto the contractor.
Why does that matter after a deal? Under firm-fixed-price (FFP) contracts, integration costs, added overhead, new management layers, and platform expenses come out of the contractor’s margin. The government does not pick up the tab. So, a target can look stable in historical financials while carrying far more forward margin risk than the QoE shows.
The fix is straightforward. Track the contract type mix over at least three years. Then model what happens to margins if indirect costs rise after closing, as they often do in a combined company.
6. Contract Vehicle and AI Capability Premiums Require Deeper Diligence
Some of the highest premiums in government contracting M&A today are tied to two things: contract vehicle access and AI capability. Access can include OASIS+, Alliant 3, SEWP, and Other Transaction Authority (OTA) agreements. Winning comparable positions organically can take years. Buying them is often faster.
But the premium only holds if the value survives the deal. The FY2026 defense budget request includes $13.4 billion for autonomy and autonomous systems, which keeps buyer appetite for AI-ready targets strong. These deals often surface problems that standard diligence was never built to catch:
- Government data baked into AI models
- Gaps in FedRAMP or DoD Impact Level authorization
- Open-source, model, or data license limits in restricted environments
- Data rights that are unclear or tied up
Before you set a valuation, pull the transfer provisions, OTA assignment clauses, model and training data licenses, AI capability documentation, and key employee agreements. The premium you pay should match the value that actually transfers.
The 2026 Bottom Line for Buyers
The deals that win in 2026 will be the ones where buyers look past the backlog. The real work is to confirm what survives the deal: contract access, compliance standing, margin durability, and key talent. Each of the six changes above can quietly drain value from a transaction if you miss it during diligence. With deal activity climbing, the cost of getting it wrong is climbing too.
This is where specialized guidance pays for itself. CrossCountry’s M&A Advisory team helps buyers spot the risks that standard diligence overlooks, so you protect every dollar of the price you pay.
Ready to pressure-test your next government contracting deal? Contact CrossCountry today and move forward with confidence.
RLM versus CPQ: That’s one of the hottest topics in the Salesforce world these days, but it’s also one of the most confusing.
Revenue Lifecycle Management (RLM) rolled out this spring to provide a seamless end-to-end sales experience for businesses, including product catalogs, pricing logic, quoting, order management, asset lifecycle, and a CLM—all with a layer of Einstein AI capabilities on top.
RLM originally existed under the Salesforce Revenue Cloud umbrella alongside CPQ and Salesforce Billing. Now, RLM itself has been rebranded as Revenue Cloud and stands separately from CPQ and Billing, but for the purposes of this article, we will still refer to it as RLM for clarity.
What does RLM mean for current CPQ users or those considering implementing it? We’ll shed some light on that in this post.
What is RLM?
You can think of RLM as an enterprise version of CPQ but with some major differences.
- While CPQ is installed as a Managed Package, RLM is built directly on the Salesforce platform so it works well with Flows, Lightning Web Components, and native page layouts.
- Much like CPQ, RLM has a Product Catalog, but it is managed through Product Catalog Management and uses the Business Rules Engine instead of clunky Product Rules and bundle configurations.
- RLM manages pricing as well, but through the very generically named Salesforce Pricing set of tools. RLM’s CPQ portion (yes—RLM has its own CPQ that is separate from the original CPQ) includes a Product Configurator, Quotes and Orders, and Contracts.
- In addition, RLM boasts a much more spreadsheet-like experience, which is ideal for rev ops teams that are clinging to their pressing tools built in Excel.
Other cool features in RLM include:
- a native Document Generation tool
- full CLM functionality
- Pricing Waterfalls that show when you hover over any price in the Quote UI
- a Dynamic Revenue Orchestrator, which puts Orders and Fulfillment on the same screen.
Does CPQ offer any advantages over RLM?
Yes!
- Standard CPQ has usage-based pricing whereas RLM currently does not. (Note: We figure RLM will eventually go to usage-based pricing, but Salesforce has not announced it yet.)
- RLM relies on Salesforce’s Standard Approvals while CPQ can be used with standard and its own Advance Approvals engine. If complex, matrixed approvals are a sticking point for your organization, the original CPQ is the better option (at least, for now).
Where is CPQ going?
In the short term: Nowhere, according to announcements at Dreamforce in September. Salesforce is planning to sell and support both products. But you can expect that Salesforce’s primary focus will be on RLM when it comes to new enhancements and functionality.
Is one easier to implement than the other?
Because RLM operates with native Salesforce functionality, Salesforce claims it provides a more intuitive way of working. That may be true, but mastering the interface is the easy part; getting your business logic to conform to rules in a system is harder. RLM still requires someone with a high level of Salesforce expertise to set up a complex Product Catalog with complicated pricing, and to build Renewal and Amendment logic.
Should we upgrade to RLM or stay with CPQ?
Like many Salesforce-related decisions, the answer is: “It depends.”
- If your organization already uses CPQ and it’s working well, there’s no need to rush to RLM. RLM implementation is a significant investment and it may not deliver the return on investment your organization is looking for right now.
- If you have not seen any ROI with CPQ—perhaps because of the product’s limitations or an ineffective implementation—RLM is worth a look. After reviewing your CPQ setup, you may find that RLM’s functionality meets your needs better.
A key determining factor to consider in your RLM vs. CPQ decision is how much of your Quote-to-Cash process you need to manage within Salesforce versus your existing systems, such as an ERP. If you need Contract Lifecycle Management, Billing, Subscription Management, and CPQ all in one system, RLM has you covered. But if you have other systems managing these aspects of your business well, investing in RLM may not be worth the up-front costs.
DCS’ Salesforce experts can help assess your current CPQ setup and walk through the ways RLM may (or may not) be a good fit for your business. If you’re having trouble navigating the RLM vs. CPQ question, we’re here for you: Contact us to start a conversation.
Yes, you can now connect an LLM like Claude or ChatGPT to your Salesforce instance. But why would you want to do that?
Here are four use cases that make this a worthwhile endeavor from a revenue operations perspective.
- Claude can handle your Complex Reporting needs. How many times have you had to create multiple reports in Salesforce, downloaded them as Excel files and then married them up using vlookup formulas? How many times have you said, “I wish I could outsource that?” That’s where Claude comes in. All you need to do is set up a Salesforce MCP Server and connect it to the Claude desktop app. The sobject-reads server will suffice. This gives Claude access to whatever records and objects that you (your Salesforce user) have access to. From there you can run any report you like just by typing in a prompt such as “Show me how all of the sales reps are performing vs. sales target for Q2.” It will give you something like the below screenshot depending on how your org is set up and what additional instructions that you may have given it before.

If you want to make changes to the format to the data that is included, just tell it!

No more tweaking reports from inside of Salesforce. And you are no longer limited by what charts in Salesforce reports can do. Claude can handle any chart or graph that you can think of.

- How a sales rep is performing against his or her target has always been something that was tricky to do in Salesforce, especially if you had a complex compensation model. In the above example we merged datasets from two completely separate objects (Targets and Opportunities). But what if you want to add your compensation model into this? Ideally you would have a document that spells out what counts toward a sales target for each type of sale and sales role, and then combine that with your Salesforce opportunity data(or orders or quotes or assets). With Claude connected to Salesforce records and a detailed commission structure document loaded into Claude as a Skill you can do just that.
According to Claude itself, Skills are “curated, environment-specific playbooks that keep Claude’s output accurate and consistent for defined task types” (yes, technically I used AI to generate that sentence). Skills can be any type of document that you would use to maintain anything that Claude would need to know in order to generate accurate and relevant answers to your prompts. This is where you state things like how to calculate ARR, what your fiscal year is, your terms and conditions, color schemes and of course a detailed commission plan.

Once you run your prompt you can readjust as needed.

- Claude can handle document creation. You probably already know that Claude (like many AI tools) can create PDFs, Word Docs, and of course spreadsheets. When you add Salesforce data to this mix that means you can create a quote document right from within the chat. Just tell it which quote or opportunity record to look at and what you would like on the quote. This is one place where the documents you have in Claude’s’ Skills become extremely important; you want your quote docs to be consistent and follow your business’s rules. You certainly don’t want AI randomly generating Terms and Conditions for you. In the example below I have done much of that upfront work – Claude knows the specifics on our docs to be generated – so we get a reasonably consistent output every time (this is a demo org… you’ll want it to be better than “reasonably” consistent so spend the time prepping).

- Last but certainly not least, entire PowerPoint decks can be built from your Salesforce Data! This one takes a bit of work and you’ll want a lengthy prompt that works consistently over and over. Once you have that you can just copy and paste it into the chat any time you want to run it again. Or better yet, save it as a Skill with details on each of your reporting metrics spelled out. In the example below we have a quarterly board deck for the board. Once you have all of the details in Claude you can just ask it to create the deck, tell it which quarter, and let Claude do the heavy lifting.

Some (pretty important) caveats:
I have used the word “just” in a few of the examples in this post but this is a gross oversimplification of what goes into making sure this works right every time. I should say “once you have Claude set up properly” then you can “just type in your prompt” and expect a reasonable answer. Remember that LLMs use statistical patterns to guess what the answer to your question is. The less room for guessing that you give them, the better.
To ensure that Claude is going to give you the results that you are looking for:
- Create documents with all of your business logic and have these set up as Skills in Claude
- Test heavily. Claude will often give slightly different answers to the exact same question so you want to know where your variances are and then adjust and standardize your instructions.
- Have clean data. Dirty data is just going to add to the guesswork that Claude has to do with each prompt and thereby decrease the chance of producing useful information.
Agentforce is undoubtedly Salesforce’s “new shiny object,” but it first requires a significant investment in your Salesforce instance. Before jumping right in with Agentforce, it’s worth looking into the many AI aspects in Salesforce that are easier to take advantage of without having to buy any new licensing.
But let’s take one more step back: Before looking at Salesforce’s AI tools—or, really, any AI tools—you need to figure out what problems you’re trying to solve. Where are your employees spending a lot of their time doing mundane, repetitive things? Where could AI help save time in that work? Adding AI to existing flawed processes won’t make your company more efficient or effective, but understanding how AI fits into your overall workflow will.
Once you know your pain points, you can start looking at how Salesforce’s AI tools can help relieve them. Here’s a list of some options in Sales Cloud and Service Cloud.
AI Tools in Sales Cloud
Einstein Lead Scoring
This tool looks at different attributes of past leads stored in your Salesforce instance and their outcomes. Then, it creates a predictive model that can suggest or predict the likelihood of a new lead to convert.
For example, it might say “Your leads in Massachusetts have a more than 80% conversion rate, so this lead in Boston is likely to convert.” Perhaps the model learns that certain industries convert better, or leads in a certain dollar range do.
Whatever the details, Einstein Lead Scoring will find those indicators and suggest the leads you should spend most of your time on. It’s important to note that Salesforce will make a recommendation on what you should do next, but it will not do the work for you.
Einstein Opportunity Scoring
This tool follows a similar process as Einstein Lead Scoring—Salesforce will look at historic opportunities to create predictive models. The model will say, “These attributes typically result in a closed sale, so based on what you’ve put in, this opportunity has a high likelihood of closing.”
Einstein Opportunity Scoring may make additional recommendations, such as “Including this product in the pitch will increase your likelihood of closing,” or “Changing the dollar amount from X to Y will increase your chances of closing.”
Sales Emails
This tool helps you write the next email in response to the customer. It will look at previous emails you’ve written in this Opportunity and draft an appropriate email to send to the prospect.
The Sales Emails tool is a great way to accelerate your prospecting with follow-ups and outreach. But remember: Although it will write the email for you, it will not send it.
Call Explorer
Depending on the telephone service you use, Salesforce can listen in on your phone calls and understand what’s being discussed. It can gauge the sentiment of the phone call (i.e., was it positive or negative?) and use that information to suggest your next actions.
For example, if the tool reports “It seemed that this person was very price-sensitive in the call,” that could inform how you approach that topic in your next conversation.
Sales Summaries
This tool allows a sales representative to understand the state of any deal given all the information available and predict whether it will close. It’s also useful for sales managers to quickly check on how different opportunities are progressing.
AI Tools in Service Cloud
Service Replies for Email
This is similar to the Sales Emails tool listed above. It will look at all of the information related to the case and draft an appropriate email response.
As with Sales Emails, this tool will write the email, but the user must send it.
Einstein Reply Recommendations
This tool uses natural language processing to analyze common replies in historic chats. It then creates a catalog that can shorten the time agents spend answering service questions. You can train the model to personalize those messages in your feedback.
Call Explorer
This is similar to the Sales Cloud Call Exploration tool in that, depending on your telephone provider, Salesforce can listen to your call. But instead of providing feedback after the fact, Call Explorer can give an indication of the conversation temperature and make suggestions for the agent’s response as the call is happening. Call Explorer draws not only from the call’s content, but also any other information in the system about the case, including other calls, emails, and bot chats.
Work Summaries for Voice, Email, and Chat
These tools summarize an active conversation when accepting a case from a bot or during a transfer from an agent. Supervisors can respond to escalations faster thanks to real-time summaries directly in the flow of work. This saves agents and supervisors time so they can focus on delivering high-quality, personalized service.
Case Classification and Routing
This tool reviews the contents of an email or call from a customer to determine the type of case and to whom it should be routed. For example, if the email involves language about pricing, the Case Classification and Routing tool would route it to the billing department. If the email focused on a technology issue, the tool would route it to the user support team.
Einstein Article Recommendations
This tool leverages machine learning to review a case’s details and find relevant knowledge articles. It can then recommend the right articles for an agent to review to understand how to respond to a case.
Einstein Case Wrap-Up
This tool allows users to easily set up and deploy a predictive model that can produce summary reports of all cases. These are useful for service managers who need to get a quick grasp of what happened over the course of a case.
Which Tools Are Right for Your Company?
There are a few things to keep in mind when considering these tools:
- Although these tools do not require you to have Data Cloud or Agentforce, they may require other features such as Activity Capture, Knowledge, or Service Cloud Voice.
- Some of these features are available through Foundations, but not all.
- These tools must also be properly configured in your Salesforce instance—which may or may not be something your company can do on your own.
If the AI features of Salesforce are tools your company is looking to leverage better in 2025, we’d love to have a conversation with you. Our DCS team is knowledgeable about each of these tools and can help you determine which features and configurations can best meet your goals.
OBJECTIVES
Dupont Circle Solutions (DCS) was hired by a 500+ employee Cyber Security SaaS company for a variety of Salesforce improvement projects, including supporting the integration strategy for an acquisition of an organization double their size. The company being acquired had an established 10+ year old Salesforce system. Faced with the challenge of how to best integrate the two distinct Salesforce systems, DCS led the system design across Marketing, Sales, Service and Customer Success.
APPROACH
- Discovery & Design: Conducted a complex discovery and design engagement across two legacy entities with the focus on whether to merge, connect or integrate their two Salesforce instances with a focus on keeping both instances operational.
- Data Migration & Transformation: Designed the integration blueprint and led the data migration process, which included a significant amount of data cleanup and optimization efforts across both Salesforce instances to ensure streamlined operations post integration.
- Reporting: Established new dashboards and reports for multiple executive stakeholders across both systems that increased the accuracy of combined operations, forecasting, and performance.
- Training & Support Documentation: Provided training and support through the project phases, including building comprehensive documentation to ensure the team could understand and navigate the new systems seamlessly.
OUTCOMES
- Established two connected Salesforce systems, with accurate data flow, reporting and business processes.
- Created new reporting and forecasting, including a new CPQ to streamline pricing and onboard Sales reps.
- Reduced Salesforce license count, leading to cost savings.
We’ve written about the limitations of Salesforce’s Revenue Cloud Advanced several times now, but those gaps are slowly being addressed with each release. We firmly believe this product will continue to improve and eventually become the enterprise-level, all-in-one quoting platform of choice. Here are some much-needed updates from Winter ‘26 — including a few we didn’t even know we needed.
Ramp Deals for Groups
One major pain point in both CPQ and RCA has been the inability to use bundled products with multi-dimensional quoting. That may finally be solved in Winter ‘26 with the introduction of Ramp Deals for Groups. This feature allows you to break down a multi-year deal into time-based ramp segments, each with different products, quantities, discounts, and uplifts. It claims to support both usage-based and bundled products — something we’ve never seen before. We’re looking forward to diving deeper into this one.
CSV Quote Line Imports
Another new feature is the ability to import quote lines from a CSV file. Many organizations rely on complex pricing spreadsheets and hesitate to fully migrate that logic into Salesforce. Now, they can continue running calculations offline and then import results directly into Salesforce. Ultimately, yes — the goal should be to streamline pricing within Salesforce — but this provides a strong middle-ground solution while making the transition.
Asset Amendments
Assets also received attention in Winter ‘26. Unlike CPQ, which manages renewables through subscriptions, RCA manages all sold products through Asset records. One of CPQ’s biggest pain points is the lack of “amend and extend” functionality. In CPQ, extending an end date requires a clunky cancel-and-replace process. Revenue Cloud now allows you to simply amend an asset’s term by pushing out the end date, while handling the amendment logic automatically — as the sales gods intended.
CPI-Based Price Adjustments
And here’s a surprise: you can now automatically adjust prices based on the Consumer Price Index (CPI). This lets you manage price uplifts monthly, quarterly, or annually. It appears to address another long-standing CPQ shortcoming — the inability to update a price on an amendment without a cancel and replace. Now you can. We have a lot of questions about how this works in practice, but the use cases seem endless.
These are just a few highlights from a packed release. The real question is: what will Dreamforce bring to Revenue Cloud?
Revenue Cloud Advanced: Thoughts and Updates
We’ve covered Revenue Cloud Advanced several times, and each time Salesforce ships new features that instantly make our last post feel outdated. Here are a few recent updates, ongoing limitations, and some broader thoughts on CPQ projects.
Approvals
Advanced approvals were addressed in Winter ‘25, which feels like a lifetime ago in RCA time. You can now create serial and parallel approval processes through Flow Orchestrator, assigning approvals to users, groups, or queues. Summer ‘25 also introduced Smart Approvals, which allow users to resubmit requests without restarting the entire process — and annoying everyone in the chain.
Cloning Quote Lines
Cloning quote lines and groups of lines might feel like table stakes, but RCA now supports it on par with CPQ as of Summer ‘25. One feature we’d still like to see is the ability to clone an entire quote and save it as a new version. Sure, you can write Apex for that — but it really should be native.
Amendments
Amendments have always been a clunky, unintuitive experience in CPQ. RCA improves this by allowing direct amendments to Assets. Until Summer ‘25, you were limited to 10 asset action source records per asset — not helpful if, for example, you were adjusting user counts monthly. That limitation is now gone.
The Real Challenges: Process and Change Management
No matter how good RCA or CPQ becomes, technology can’t fix poor change management or messy business processes. The number-one reason CPQ projects fail is lack of change management. You can build the most elegant system, but if your sales team isn’t engaged — or worse, excluded — it won’t matter.
Strong business processes lead to strong CRM experiences. If you’re coding for every edge case, every “special” client scenario, or every one-off product, you’re inviting complexity into your catalog, quotes, and data.
Looking Ahead
Salesforce has announced that CPQ is at end of sale (not end of life). At the same time, they continue to invest in Revenue Cloud Advanced, addressing long-standing shortcomings and introducing features we never saw in CPQ.
Our prediction: it won’t be called Revenue Cloud Advanced in six months. Any guesses?
Salesforce’s native forecasting tool is a valuable feature that enables sales teams to predict future revenue and manage pipelines effectively. Although it is a fairly simple tool, it does not get used nearly as much as it should. Here, I’ll go through the pros and cons of the Salesforce forecasting tool to help you determine whether and how it can contribute to your company’s overall goals as well as some its shortcomings.
[If you’re new to Salesforce, you can skip to “The Pros.” For longtime Salesforce users: Please note that this article addresses Collaborative Forecasting, not Customizable Forecasting. Customizable Forecasting was completely retired in the Summer 2020 release and is no longer supported.].
The Pros:
It is included with your Salesforce license.
It’s “free”—why not spend a couple of hours getting familiar with it and setting up the tool to see how it works for you?
It can help inform any future custom forecasting tools you need.
Say you set up the native forecasting feature and it only covers 70% of your needs. This experience will help you figure out what your exact needs are in a custom forecasting tool, which can help you achieve your goals faster. Think of it as a free starting point.
Most major elements are customizable.
Out of the box you can choose what to forecast on, how to slice it and you roll up the numbers. The tool allows you to predict based on any custom type of revenue field, not just the standard amount field. You can also make forecasts based on industry, product family, territory and revenue category. Lastly, the forecasting hierarchy can function completely independent of your company’s reporting structure.
It allows for true forecasts, not just pipeline reports.
You can use what is in your pipeline as a starting number, but you can edit that up or down. This means you can include a placeholder number for deals that aren’t yet ready to be in the pipeline. This means your sales reps won’t be putting bogus opportunities into the system just to get their numbers right!
You don’t need to worry about maintaining it.
Because forecasting is a native tool, Salesforce is constantly upgrading it, whereas with a custom tool the maintenance and grades are totally on you. Although Salesforce prioritizes upgrading some products over others, forecasting has been getting a lot of love over the past year, and we feel that this trend should continue for some time.
The Cons:
Forecast Category Rollups don’t always make sense.
One way to set up forecasting categories is so that they build on each other: Closed Won is just your closed opportunities, Commit includes Closed Won plus the likely ones, Best Case adds mid-stage opportunities, and Pipeline includes everything that could possibly close. The other option is not to combine categories: Commit only includes likely sales, Best Case only includes mid-stage opportunities, etc. The strange part is that each category shows a percentage of the quota. It is clear why Closed Won vs. Quota makes sense, but why show Best Case vs. Quota without including Closed Won? This seems odd and not especially useful for sales managers.
Forecasting is limited to Opportunities.
You can’t use custom objects or even other standard ones for forecasting. However, as stated above you can use custom fields within Opportunities, so you’re not limited to just the standard Amount field.
Forecasting doesn’t account for manager quotas.
Salesforce assumes that managers do not carry an individual sales target and only worry about the quotas of their direct reports. In the real world, managers often carry their own quotas in addition to their teams’. Unfortunately, Salesforce only allows one total quota for a manager, which includes their team’s targets. A manager’s own sales count toward this total, but there’s no way to see their individual performance separately.
Quotas don’t work like most objects.
Quotas do not have much in the way of customization. It has no ability to add custom fields, no history tracking and you can’t trigger automations such as flows off of them. And for time period you can only use monthly or quarterly but not annually for some reason.
All timing metrics depend on the close date.
An opportunity owner’s performance is based on the total amount at the time that the opp closes. Yet a company will often pay out (and recognize revenue) based on when an invoice is paid (e.g., monthly) or performance (e.g., when an ad runs or when a service is completed). Realistically, the forecast should be not on a close date but when the revenue actually hits the books. Out of the box Salesforce has no way to handle this.
Salesforce’s forecasting tool may not be perfect, but it is certainly worth considering if your organization is looking to either start or optimize their forecasting capabilities. If you need some help getting started, we are here to help! – please reach out to us!
At this point you have probably heard about the big TDX announcements related to Headless 360 and the Agentforce Experience Layer. Salesforce describes this as giving you the ability to build on Salesforce “any way you want.” This is partly true. You still need the Salesforce platform to handle the backend (business logic and data layers) but your frontend can be in a variety of different places. With Salesforce’s new MCP Servers you could theoretically have Salesforce users who never need to use the actual Salesforce UI ever again.
What is MCP?
Model Context Protocol (MCP) is a new (ish) open-source standard created by Anthropic that allows AI models to connect with other tools. There is what’s called an MCP Server which exposes data, and an MCP Client (like an AI tool) that connects to it. This allows you to connect your AI chat tool (such as Gemini, Claude, or ChatGPT) to anything that supports MCP. This means booking flights on Expedia, planning a hike on AllTrails, editing your trip pictures in Photoshop, and, of course, working in Salesforce can all be done from AI chat tools.
Currently Salesforce has eight different MCP servers that allow connections to various data and metadata. You can think of these like pipelines into your org for AI tools. You can connect them to external tools just like you would with an integration between Hubspot and Salesforce for example, except without all of the data mapping.
So, yes, your sales reps can close opportunities, update accounts, and create tasks all from ChatGPT. Your admins can audit custom fields that aren’t being used. Your managers can use a prompt to run reports on any piece of data that their permissions allow them to access and then have AI spit out a pretty chart or graph to their specifications.
But it’s not magic of course. For things like running reports you have to treat the tool like an intern that has a lot of data but doesn’t know much else. You will need to get good at writing prompts in order to be successful at getting exactly what you want. I had ChatGPT run a report of ARR by account and it told me that there was no ARR field on the Account. Once I explained that ARR was on the Opportunities and that it could just sum by Account it was off to the races, creating ARR reports every which way I could think to tell it. It also came back with suggestions of other related data points that it could analyze. Some were very good suggestions, some were less than useful. The key benefit here was that I did not have to create a single static Salesforce report. I would simply type in my request in natural language.
What will this cost?
Outside of your usual licenses for Salesforce and whatever platform you are using there is no hard cost to using MCP servers. However, all calls the MCP servers do use up API requests so if you go over your limit that will certainly be an added cost. This depends heavily on how often you will be pinging Salesforce from the external service as well how many integrations are already doing the same thing. This is something you certainly want to pilot first and monitor closely.
The bigger issue here is that once you hit your 24-hour API limit Salesforce just shuts you off. This can throttle systems with which you have frequent (and important!) syncs. But Salesforce will certainly be happy to increase your API limits for a price. Note that if you have Enterprise edition you get 100,000 daily API requests plus 1,000 per user. Moving to Unlimited gets you 5,000 per user. Again, there is no harm in piloting this and testing actual usage metrics.
Can we trust it?
I’d be remiss if I did not mention security here. Obviously you do not want to give an LLM the keys to your entire Salesforce org. A couple of things help with this. First when you use MCP and connect to Salesforce you are using your own login credentials, so whatever your user has access to limits what you can access through the AI tool. Second, each MCP Server has its limitations. Some connect only to records with read-only access. Others can give edit or delete access. Some give access to object schema which could be useful for an admin. The recommendation is for you to only set up connections with the subset of things in Salesforce you want to expose to the tool on a user by user basis. In addition, an MCP Server connection uses Oauth so it works like most other integrations with Salesforce. Lastly, most major LLMs like Claude and ChatGPT will give you the option of not having your data used for training purposes.
The jump to using AI to control aspects of your Salesforce org is not a trivial decision. The thing to remember is that agents and LLMs in general are probabilistic, not deterministic. They don’t behave in the exact same way every time, and can potentially reason their way to what Salesforce calls “unexpected outcomes.” So if you are in a heavily regulated industry or absolutely need scripted answers and static outcomes every time then you’ll need to determine if that outweighs the extreme flexibility provided by an AI layer on top of Salesforce.
Although artificial intelligence (AI) seems to headline every article about business trends these days, the technology has been around for quite a while. Salesforce introduced its AI-powered Einstein tools eight years ago, in 2016.
What’s new about AI since then, though, is its ability to do more than enable predictive analytics. Now, AI can automate customer service and sales development tasks that have traditionally been a drain on a company’s time and human resources.
Salesforce introduced a new AI tool, Agentforce, in a recent earnings call. Agentforce is a low-code, AI-driven platform that allows businesses to create custom AI agents. These agents are NOT the chatbots we all remember in the early days of this technology. Think about much smarter “bots” that are trained on extensive real-world data sets, far beyond simple if/then programming. These AI agents take a proactive approach and operate autonomously within the Salesforce ecosystem. Agentforce’s agents can anticipate customer needs before they escalate, resulting in faster, more accurate responses to customers’ concerns. Here’s what you need to know about Agentforce and how it can make life for your business much easier.
The evolution of AI at Salesforce
Before Agentforce, Salesforce’s “intelligent” features were limited. There was Einstein, which embedded AI into the Salesforce customer relationship management (CRM) platform. Einstein bots were easy to- use but simplistic, offering fixed, pre-designed decision trees that required substantial up-front effort to define and implement. While the bots can query info, they cannot understand customer intent. Although they provide some value, they are essentially enhanced versions of the interactive voice response phone menus we’ve all dreaded for years, deflecting cases instead of resolving customer issues.
Other Salesforce “AI” tools like Lead Scoring and Opportunity Insights have been useful but are, again, limited. Both require large sets of your own data to derive insights because they are statistical models using pre-identified fields. They cannot analyze emails or call transcripts to understand a customer’s sentiment or a salesperson’s approach and how those can affect lead quality or opportunity outcome.
The building blocks of Agentforce
Salesforce has been building its AI capabilities, initially focusing on predictive analytics for data-driven decisions. As AI technology evolved, Salesforce’s approach changed. They introduced advanced AI-driven solutions, including generative and autonomous AI. Recently, they acquired Airkit, which brought a data-driven generative AI approach to customer service.
Until now, predictive AI has worked to find patterns in historical data to forecast future outcomes and aid in decision-making. Generative AI, on the other hand, creates entirely new and original content – whether it’s text, images, or other media – by learning from existing data patterns. This enables it to handle complex tasks without human intervention. For businesses, generative AI brings significant benefits by automating creative and cognitive tasks that previously required manual effort. It can dynamically generate tailored responses, marketing materials, or even proposals based on customer interactions and company data.
This capability powers Agentforce, which operates similarly to ChatGPT but is specifically trained on your company’s unique data. Agentforce’s generative AI allows it to interact directly with customers and prospects in a highly personalized way. Unlike older AI models that relied on extensive pre-programming or training, these agents don’t need to be manually set up with templates or scripted responses. They generate personalized replies in real time, ensuring fast, efficient customer service that feels natural and conversational.
Using retrieval-augmented generation (RAG), these AI agents access trusted business data—such as product FAQs, sales plays, and case studies—to provide accurate, contextually relevant answers. This makes them more versatile than traditional chatbots, which are limited to responding to pre-programmed questions. In fact, these agents can be trained on scripts from your best customer service agent or sales representative, allowing them to engage in conversations that mirror those interactions. They can interpret and process this information, enabling intelligent, personalized conversations that reflect the expertise and style of your top-performing employees.
What makes Agentforce different?
Agentforce represents a significant leap in how Salesforce can help businesses leverage AI to enhance customer service and sales processes.
Consider a customer service scenario where an AI agent autonomously manages a customer’s journey—from initial contact to resolution—without human intervention. The agent can access previous interactions, understand the context, and provide real-time assistance. This service improves the customer experience and frees up human agents for more complex tasks.
Agentforce enhances the sales process by providing tools to close deals faster. Sales Development Representative (SDR) Agent, for example, supports sellers by autonomously answering questions from inbound leads, handling objections, and booking meetings. Sales Coach Agent helps sellers develop skills by simulating a buyer during discovery, pitch, or negotiation calls. These AI-driven agents analyze customer data, predict buying behavior, and tailor interactions to maximize conversion rates.
Agentforce uses predictive analytics to identify potential sales opportunities and recommend the best approach by analyzing customer data. This includes suggesting the right product to upsell, timing to follow up with a lead, or predicting a customer’s purchase. Agentforce also automates routine tasks for sales teams, like data entry, lead scoring, and follow-up emails, allowing them to focus on building relationships and closing deals.
Agentforce’s key tools
Agentforce has a variety of powerful components, including:
- Generative AI for Customer Support: This is how Agentforce can generate personalized responses to customer inquiries. It understands the context of a query and crafts a human-like reply efficiently and quickly using advanced natural language processing.
- Predictive Analytics and Insights: Agentforce predicts customer needs and suggests actions, from recommending the next best offer to proactively addressing potential issues, building on Einstein’s predictive capabilities.
- Omni-Channel Support: Agentforce works across email, chat, social media, or phone, ensuring customers receive a consistent experience across interaction methods.
- Automated Workflows: Businesses can create automated workflows for routine tasks like ticket routing, follow-up emails, and data entry, saving time and reducing the likelihood of human error.
- Real-Time Customer Insights: Real-time insights into customer behavior Agentforce agents to make informed decisions quickly. Agents have the data they need to upsell a product or resolve an issue.
- Scalability and Flexibility: Like all Salesforce products, Agentforce is scalable to fit businesses of any size. You can tailor Agentforce to meet your needs, whether you’re a small startup or a large enterprise.
- Data Security: Agentforce uses Salesforce’s Einstein Trust Layer, which provides guardrails for the use of AI technology. The Einstein Trust Layer ensures the ethical and secure use of AI within Salesforce, including data protection, regulatory compliance, and transparency in all AI decisions. This means that customer information is shared securely, but not retained.
Applying Agentforce to serve your needs
Agentforce can simplify many of a business’ most important tasks, including:
- Autonomous Operation: AI agents can function independently to handle routine customer service tasks, such as answering inquiries, troubleshooting issues, and processing sales orders. This frees up human staff to handle bigger, more complex issues.
- Customizable AI Agents: Agentforce’s agents can be customized based on a business’ unique workflows, ensuring the AI works seamlessly within their existing systems.
- Seamless Salesforce Integration: Because Agentforce integrates directly with Salesforce, its AI agents can access and utilize all of a business’ Salesforce CRM data, providing a more informed and effective customer interaction experience.
- Multimodal Capabilities: Agentforce agents can understand and process text, images, and video content, making Agentforce a versatile tool for businesses, handling complex customer interactions across multiple channels.
This is just the beginning for Agentforce
With Salesforce consistently investing in the expansion of its AI capabilities, you can bet that Agentforce’s power and use cases will increase over time. Already, Salesforce is working on agents designed for the healthcare, finance, and retail sectors. These sectors will provide Agentforce with a deeper understanding of industry-specific regulations and customer needs. In addition, Salesforce is focused on enhancing the accuracy of its AI agents by refining Agentforce’s underlying AI models, which will benefit businesses in all sectors
With Agentforce, businesses can transform how they approach customer service and sales. They can improve efficiency, reduce costs, and enhance service quality through a powerful, customizable, and scalable solution.
Whether you’re a small business or a large enterprise, now is the time to explore Agentforce to automate and optimize your business’s most cumbersome customer support and sales processes. As we at DCS learn more about Agentforce and how it’s benefiting our clients, we’ll share many of those lessons here on our Insights page. But if you’re ready to jump in now, we’re on board: Contact us today to start transforming your business through Salesforce Agentforce!
Introduction
If your sales team has ever groaned about the Configure-Price-Quote (CPQ) tool being clunky or time-consuming, you’re not alone. Many companies implement Salesforce CPQ expecting a seamless quoting process, only to find frustrated reps and slow adoption. As a CFO, you might hear complaints about too many clicks, confusing options, or quote errors creeping in. These common frustrations boil down to one thing: user experience. And user experience isn’t just a “nice to have” – it directly affects sales efficiency and quote accuracy. In fact, a poor CPQ interface can lead to low usage, higher training costs, and more mistakes in pricing or product selection.
On the flip side, an intuitive CPQ experience helps your team quote faster and more accurately, speeding up sales cycles and boosting confidence in revenue numbers.
The good news is that you can dramatically improve the Salesforce CPQ user experience with a few best practices. In this post, we’ll explore CPQ best practices focused on making life easier for your sales reps (and improving your bottom line as a result).
Guided Selling Enhancements: Making Quoting Easier
One of the quickest wins for user experience in Salesforce CPQ is improving guided selling. Guided selling is an out-of-the-box feature that walks reps through a few targeted questions and then suggests the best products for a customer. For example, in Salesforce CPQ you might ask the rep “What type of product is the customer interested in?” or present a series of dropdown questions (as shown in the guided selling pop-up above). The rep’s answers (e.g., selecting a product category, desired features, or customer size) dynamically narrow down the available products. If only one product matches the criteria, CPQ can even auto-select it for them.
However on the back end the standard guided selling is really just a glorified set of filters on the product selection screen. This can get fairly limited rather quickly. To take guided selling to the next level what you really need is a button that launches a Screen Flow that walks a seller through a series of real questions related to product use cases. From this you can do much more robust queries that help the seller narrow down base products, suggest relevant addons and create various custom product combinations.
And yes you can build a screenflow into the QLE! With a screenflow the sky is the limit as to how many questions you ask and what data you can pull in. For example you can have it branch into different questions based on previous answers, suggest complementary add-ons on the fly, or handle complex product configurations. Imagine a flow that, after a rep selects a base product, automatically asks if they’d like to add the most common accessories or service package for that product – all in one smooth sequence. Or you can have it query the account’s Assets and Subscriptions to recommend products related to what they have already bought. This level of smart guided selling not only improves the user experience but can also increase deal size (through consistent cross-sells and upsells) without additional effort from the rep.
Best Practices for Guided Selling:
- Keep it Short and Relevant: Only ask the minimum number of questions needed to refine the quote. Every prompt should have a purpose. Too many questions can frustrate users, so stick to the high-impact ones (e.g. the customer’s industry, product category, or key requirements).
- Use Language Sales Reps Understand: Phrase questions in business terms, not internal jargon. For example, use “Customer Size” instead of a technical field name. This makes the guided process feel natural and quick.
- Preconfigure Common Bundles: If certain products almost always go together, guided selling can automatically include them. For instance, if a rep selects Product A, the system can automatically suggest Add-On B 90% of similar customers buy. This saves the rep a step and ensures no revenue is left on the table.
- Allow Manual Bypass if Needed: Sometimes reps know exactly what they need so don’t force them to go through an unneeded process. Provide an option to skip the questionnaire and go straight to the product catalog when appropriate. This keeps your most experienced reps happy while still guiding those who need it.
By beefing up the guided selling experience with these enhancements, you simplify the quoting journey allowing salespeople to spend more time building relationships and less time navigating the system. As a CFO, you’ll appreciate seeing more accurate, consistent quotes – which means more predictable revenue and fewer surprises.
Intuitive Upgrades and Replacements: Streamlining Amendments
Another area where user experience can make or break CPQ adoption is handling upgrades, downgrades, cross-sells and addons to existing products (often referred to as contract amendments in Salesforce CPQ). For businesses with subscription models or repeat sales, this process is critical. However, out-of-the-box Salesforce CPQ doesn’t make initiating an amendment quote as straightforward as we might like so reps end up doing extra manual steps or making mistakes like selling an upgrade without properly retiring the old subscription or giving invalid addon products.
The solution is to introduce guided screen flows for the amendment process as well. Think of it as an “upgrade wizard.” When a customer wants to change or expand what they’ve bought, the rep could launch a custom Upgrade Flow from a button in the QLE. This flow would present the rep with the customer’s current subscriptions (so nothing gets overlooked) and then guide them through selecting the new product or edition that replaces the old one. Behind the scenes, the flow can handle all the CPQ heavy lifting – adjusting quantities, zeroing out lines, adding the new products on specific start dates – all with just a few clicks by the sales rep.
Why go through this trouble? Because it reduces errors and saves time. With a guided process, the rep is less likely to forget to set the old service’s quantity to zero or accidentally double-bill. Automating large parts of the amendment process will save time for your sales team, and it leverages CPQ’s native capabilities so you maintain data integrity. In other words, a well-designed flow ensures that the quote coming out the other end of an upgrade is clean and accurate – which means contracts stay up-to-date and your revops team will do much less manual mistake fixing.
Consider a scenario: a customer with a basic plan wants to upgrade to premium. Without a guided flow, the sales rep might have to manually clone quote lines, zero out old lines with the right end date, update the start dates of the new lines, manually set something that indicates that this is an upgrade, and so on – a process prone to mistakes if the rep is hurried or not deeply familiar with CPQ. With an intuitive flow, the rep could simply pick the current subscription product, choose “Upgrade to Premium” from a menu, pick a date, and the system would handle the rest. Fewer steps for the user, fewer headaches waiting to happen.
Tips for Streamlining Upgrades, Cross-sells and the like:
- Clear Visibility of Current Assets: Make sure the rep can see what the customer currently has. The flow might list all active subscriptions (with quantities and end dates) before asking what needs to change. This acts as a checklist so nothing is missed.
- One-Click Actions: If the customer just needs more of the same product (upsell), provide a quick option to increase quantity. If they need a newer version of a product, offer a one-click “replace with new version” action. The less manual data entry, the better.
- Pre-validate Pricing and Terms: Your flow can include business logic to ensure the upgrade follows company rules – for example, auto-calc any prorated charges or enforce that the new product has an equal or greater term length. This removes the guesswork for reps and prevents revenue leakage.
- Automate the Paperwork: When the flow finishes, have it automatically generate the amendment quote and even the draft order/contract in Salesforce. Reps shouldn’t have to remember extra steps like creating a renewal opportunity or linking records – the system should do it, so all data is properly tied together.
By making upgrades and addons virtually foolproof, you not only make your sales team’s job easier but also ensure your recurring revenue is managed correctly. As a CFO, you can trust that upgrades aren’t slipping through cracks or being done incorrectly. Your contracts and billing will align with what was actually sold, and reporting becomes more reliable.
Customizing the Quote Line Editor for a Better UX
When it comes to daily usability, the Quote Line Editor (QLE) is where your sales reps spend a ton of time. This is the screen in Salesforce CPQ where reps configure and customize the products on a quote. Out-of-the-box, the QLE does the job, but it can look cluttered or confusing, and it might not highlight the information your team cares about most. The good news is Salesforce CPQ allows customizing the QLE’s appearance and layout, so you can make it far more user-friendly and even tailor it to your company’s branding or workflows.
One powerful (if somewhat hidden) feature is CPQ Themes, which let you inject custom CSS (styling rules) into the QLE UI.This means you can change colors, fonts, spacing, and more to make the quote editor easier on the eyes and aligned with your internal style. For example, you might use a CSS template to color-code different product types or highlight bundle components. If your quote has multiple levels (bundles and options), you could apply subtle background shading or indentation for child products, making the hierarchy clear at a glance.
Maybe it’s important for your reps to see the profit margin or stock availability for each item while quoting – consider adding a calculated field for margin or an inventory status indicator right in the QLE. The CFO in you will appreciate that reps are more informed when adjusting quotes (e.g., they might think twice about giving an extra discount if they see the margin turning red in real-time).
Beyond colors and fonts, think about which fields are visible and how they are arranged in the QLE. The goal is to present just what the rep needs to see to work efficiently. Anything else is a distraction. Salesforce CPQ allows administrators to configure the quote fields that appear at the top of the QLE. In addition you can control which fields appear in the columns and make them dependent on the quote type, account type, deal type or any picklist of your choosing. You can even make these user-dependent – keep the cluttered, information heavy views for the rev ops team and streamline them down to essential sales fields for the sellers. This kind of tailoring ensures the interface “speaks the user’s language” for the task at hand.
QLE Customization Best Practices:
- Prioritize Key Info: Identify the 3-5 fields that are most critical during quoting (e.g. product name, quantity, price, discount). Make those prominent. Less-used fields can be moved to the drawer (below the line, accessed via the down arrow) or removed entirely from the line editor view.
- Use Visual Cues: Leverage styling for clarity. If something requires attention or is an exception (like an excessive discount or an expired promo), make it stand out with color or an icon. Conversely, de-emphasize non-editable fields by graying them out, so users focus only on what they can change.
- Test with Real Users: Before rolling out a new QLE layout or theme to everyone, get feedback from a few sales team members. What makes sense to an admin might not be as intuitive to a rep in the field. Small tweaks based on feedback (like increasing font size or reordering columns) can make a big difference in comfort and speed.
By customizing the quote line editor, you turn Salesforce CPQ from a generic tool into a tailored platform for your business. The easier it is to use, the more your salespeople will embrace it – and that means more quotes going out faster and again, with fewer mistakes.
Conclusion
Investing in Salesforce CPQ is ultimately an investment in accelerating and safeguarding your revenue. But the true returns on that investment depend on user adoption and efficiency. By focusing on these CPQ best practices to improve user experience – from enhanced guided selling that lead your reps straight to the right products, to intuitive workflows for upgrades that eliminate errors, and a user-friendly QLE that’s customized to your needs – you empower your sales team to work smarter, not harder. An intuitive CPQ means quicker quotes, more accurate proposals, and happier sales reps and customers. And for the revops or finance team, that means more predictability and confidence in the data.
Remember, enhancing user experience in CPQ is not just cosmetic. It reduces friction in your sales process and lets the technology do the heavy lifting so your people can focus on selling. Small tweaks can yield big wins: fewer clicks here, an automated suggestion there, a clearer screen to work on – it all adds up to a faster sales cycle and fewer revenue leaks due to mistakes or slow processes.
We hope these tips inspire you to take a fresh look at your Salesforce CPQ setup and identify opportunities to make it more user-friendly. The payoff will be evident in your sales metrics and the feedback from your team. If you have any questions about implementing these best practices or want to explore how to tailor CPQ to fit your organization even better, feel free to reach out if you have questions. We’re happy to help you get the most out of your CPQ investment.
Finance teams do not struggle with consolidation because they lack tools. They struggle because complexity scales faster than their processes can keep up. As organizations grow across entities, geographies, and ownership structures, traditional approaches to financial consolidation quickly become unsustainable, even when a platform like Sage Intacct is already in place.
The challenge is not platform capability. It is aligning how you use the tool to where your organization actually stands in its consolidation maturity. According to APQC benchmarking data, top-performing finance teams complete the monthly close in 4.8 calendar days, while median performers take 6.4. If your team is spending more time reconciling the past than informing the future, your consolidation process deserves a closer look.
Why does consolidation complexity grow faster than finance teams expect?
Consolidation complexity is not a technology problem; it is a maturity alignment problem. What begins as a manageable set of manual journal entries and spreadsheets often evolves into a fragmented, time-consuming close cycle that limits visibility and delays decision-making.
Common symptoms that indicate a misalignment between process maturity and platform use include:
- Manual intercompany eliminations completed outside the system
- Inconsistent data across entities that requires repeated reconciliation
- Lack of standardization in account structures or chart of accounts
- Heavy reliance on spreadsheets to supplement or replace system outputs
- Limited auditability and difficulty tracing entries back to source transactions
If any of these are familiar, the issue is rarely the platform itself. It is how the platform is configured and used relative to the organization’s current structure and growth stage.
Understanding Consolidation Maturity in Sage Intacct
Consolidation maturity is not one-size-fits-all. There is no single “right” model. There is only the model that aligns with an organization’s current stage and future trajectory.
1. Foundational: Manual (Core Financial System Only)
At the most basic level, organizations operate without formal consolidation tools. While this approach provides flexibility, it also introduces challenges:
- No automation of eliminations
- No multi-entity or multi-currency consolidation
- Heavy reliance on manual journal entries
In practice, teams often create separate entities and post elimination entries manually. Some even maintain separate user defined books to record elimination entities for easier reporting. This approach becomes difficult to scale as complexity increases.
While every organization is different, those aligned to this maturity level often involve one parent or trust company who owns 100% of all entities.

2. Domestic Consolidations: Standardization and Speed
As organizations expand within a single currency, the next stage is typically domestic consolidation. This stage introduces:
- Automated intercompany eliminations
- Real-time consolidation reporting
- Improved audit trails and transparency
While the structure of your entity may match that of the above image, the key difference is technology enablement. Instead of manually recreating entries each month, Sage Intacct handles the processing, allowing finance teams to focus on review and analysis.
Success depends on disciplined design. Without consistent intercompany account structures, even month end reconciliations can still be a challenge.
3. Global Consolidations: Managing Currency Complexity
When organizations operate across multiple currencies, consolidation becomes significantly more complex.

Global capabilities enable:
- Currency translation into a single reporting currency
- Auto-generated entries to record currency translation gains and losses
- Multiple reporting views, such as local and global
At this stage, finance teams gain a more complete view of performance. At the same time, policy decisions, such as foreign exchange treatment, become critical to maintain consistency and trust in reporting.
4. Advanced Ownership: Reflecting Real-World Structures
Organizations with partial ownership or multi-level hierarchies require more sophisticated consolidation approaches. Advanced Ownership functionality within Sage Intacct supports:
- Partial ownership calculations
- Multi-tier entity roll-ups
- Equity method accounting
- Dynamic ownership structures over time
These capabilities are essential for accurately reflecting complex organizational structures, particularly in private equity-backed or multi-generational family offices. CrossCountry has explored how these structures apply specifically to family offices using Sage Intacct.

How should finance teams approach consolidation improvement?
The most effective consolidation improvements share a common pattern: they address process design before configuration changes. Automation accelerates what already works; it amplifies what does not. High-performing finance teams consistently do the following:
- Standardize intercompany structures early to reduce downstream reconciliation complexity
- Use repeatable journal frameworks instead of rebuilding entries from scratch each period
- Establish a defined month-end close process with clear ownership and documented steps
- Use reporting tools intentionally to validate consolidation outputs, not just display them
When organizations align their Sage Intacct configuration to their actual consolidation maturity stage, close cycles accelerate, data becomes more reliable, and finance leadership gains faster access to the insights that drive decisions. The goal is not just a faster close; it is a more useful one. CrossCountry Consulting can help you get there.
While demand for alternative investments is largely established, the path to delivering them is complex. Disciplined operating model design, rigorous vendor selection, and implementation precision will determine which retail private asset launches succeed and which quietly fail at scale.
The challenge is no longer whether retail demand for private assets exists. It is whether firms have the operating model discipline to deliver these products at scale without compromising control.
Distribution appetite exists, but operating model readiness is the constraint
Retail access to private markets is no longer theoretical. Large asset managers are actively launching interval funds, tender offer funds, and evergreen vehicles holding private equity, private credit, and alternative investments.
The strategic rationale has been settled for years: investors want differentiated return streams and diversification beyond public markets. Capital is available, and distribution is interested.
What remains unsolved, and what most program leaders underestimate until it is too late, is the operational question. Demand is rarely the binding constraint. Scalable infrastructure is.
Firms that recognize this distinction early and design for it deliberately can scale distribution without compromising risk, control, or credibility. Those that do not will discover their problems at scale rather than at launch, which is a considerably more public and expensive place to find out.
How retail private asset vehicles change operating behaviors
Retail vehicles holding private assets are not traditional funds with new exposures. They introduce structural changes to how time, liquidity, and certainty function within an operating model.
Private assets bring valuation latency, episodic cash flows, and constrained liquidity into an ecosystem built for daily pricing, predictable settlement, and continuous redemption. As a result, Net Asset Value (NAV) becomes a governed process rather than a mechanical output. Liquidity shifts from an assumed market outcome to an explicit promise that must be designed, monitored, and defended. Client service must accommodate delayed information, revised marks, and formal valuation committees without eroding trust.
Operations become part of the product
Capital calls, distributions, eligibility controls, documentation, and bespoke lifecycle events are not edge cases. They are core workflows. Firms that treat operations as overhead rather than product infrastructure encounter breakdowns not at launch but as volumes scale, precisely when reputational exposure is highest.
Cross-functional risks emerge at the seams, not the center
The dominant risks in retail private assets (liquidity mismatch, valuation accuracy, stress testing, suitability, and disclosure) do not sit cleanly within any single function. They emerge at the intersections of investments and operations, product and compliance, and technology and distribution.
Successful programs behave less like product launches and more like integrated operating model builds. When these domains are designed independently, friction is inevitable. When they are designed together, complexity becomes manageable.
This is why retail private asset initiatives fail most often during stabilization, not conception. A strategic vision without cross-functional integration discipline rarely survives contact with scale.
Vendor ecosystem complexity: Modularity is not simplicity
There is no dominant end-to-end platform for retail private assets, and this is not a market failure. Product structures vary widely: interval funds, tender offer funds, evergreen vehicles, non-traded Real Estate Investment Trusts (REITs), and Business Development Companies (BDCs) each function and trade differently. Distribution models differ further.
The market has converged on modular, function-specific vendor ecosystems. Specialist providers are advancing capabilities across fund administration, transfer agency, liquidity management, valuation governance, data observability, compliance automation, and client experience.
The primary differentiator is no longer just which vendor is selected. It is how coherently the ecosystem is assembled, integrated, and governed once vendor decisions are made. Firms that mistake modularity for simplicity consistently underestimate the challenge of launch readiness. Modularity rapidly increases the importance of architectural clarity and well-defined ownership.
Launch readiness and speed to market come from rigor, not shortcuts
Commercial pressure to distribute quickly is real. Programs that meet aggressive timelines do so by front-loading rigor, not by skipping it. To ensure success, leaders must take practical steps:
- Define the target operating model before selecting vendors.
- Translate product terms into executable operational requirements, particularly around liquidity, valuation, and suitability.
- Test vendors against real workflows and stress scenarios, rather than relying solely on polished demonstrations.
- Embed controls into the workflow, industrialize exception management, and establish data lineage from day one.
This discipline does not slow delivery. It prevents rework, remediation cycles, and reputational risk once assets scale past the point of easy fixes. The firms that win will not be those that move fastest in theory. They will be those that implement best in reality.
CrossCountry Consulting helps clients do exactly that: grounding strategy in what is operationally and regulatorily executable, running vendor selections rigorous enough to eliminate rework, and delivering implementations that meet aggressive timelines without compromising control.
Whether you are navigating the complexities of Private Equity, leading transformation within the Office of the CFO, or driving broader Finance Transformation, our team is here to help you build a resilient, scalable infrastructure.
Contact CrossCountry Consulting to get started on your retail private asset strategy.
Nine out of ten finance leaders agree the CFO should own AI outcomes. However, only two in ten actually do today (CrossCountry Consulting / FERF Evolution of the Finance Function, 2026). Whatever the reason, whether IT owns the initiative, risk leaders have not signed off, or the underlying data is not ready, that gap will not close by itself. Every quarter you wait, your competitors who close that gap pull ahead.
AI is not just a tool. It is a catalyst for delivering better experiences and driving sustainable growth. But AI will not transform finance on its own. Modern CFOs must own the enterprise AI strategy, the data foundation, and the risk posture to lead the next decade of finance. The CFO who steps up to own the value thesis can transform the finance function, optimize costs effectively, and drive strategic value across the enterprise.
Strategic convergence across finance, data, and risk
Most AI initiatives stall because they are treated as isolated technology upgrades rather than holistic business transformations. To truly unlock efficiency and growth, leaders must shift their perspective. All three critical components must be brought into the same room: AI transformation, data readiness, and risk governance.
- The AI leader wants to move fast and prove value.
- The risk leader demands that every output be auditable, controlled, and defensible.
- The data leader warns that you cannot build intelligent agents on broken data.
When these three functions operate in silos, initiatives fail. But when you converge AI innovation, risk governance, and data strategy, the trade-off between speed and control disappears. You create a unified front that delivers rapid, measurable outcomes.
- Building the foundation for trust and scale
To deploy AI safely and effectively, you must establish a rigid foundation. This foundation ensures that your intelligent agents operate on accurate information, respect compliance boundaries, and augment your human workforce.
2. Validating the data foundation
We cannot build agents on broken data. Many finance transformations stumble because data readiness is assumed rather than validated. To succeed, treat your general ledger and subledgers as operational assets. Implement a structured data architecture that moves information through deliberate stages. Start with raw ingestion from your financial systems. Next, cleanse, normalize, and resolve intercompany discrepancies. Finally, curate specific tables that your AI agents can query with absolute confidence. When your AI only touches governed, lineage-tracked data, every output becomes fully traceable. This ensures you can stand behind the numbers you present to the board.
3. Risk governance as an accelerator
Governance is not a constraint; it is the foundation for sustainable AI adoption. Trust, compliance, and security are non-negotiable in AI initiatives.
Instead of treating governance as a bottleneck, build it into the design from day one. Implement risk-based triage to evaluate what the AI is doing, how much the business relies on it, and how you will prove it works. An AI agent handling high-impact financial forecasting requires a full council review and a rigorous audit trail, while a simple policy summarizer can move through a lighter approval path. By designing controls that scale with the risk, governance accelerates your ability to deploy safe solutions.
Empowering the finance team
Only a small fraction of finance leaders feel highly confident interpreting AI outputs. This is not a technology gap; it is a leadership gap. True digital transformation requires a human-centered approach. AI is an enabler, not the destination.
To unlock the true strategic value of AI, you must train your people to work alongside advanced systems. Persona-driven design confirms that AI aligns with human priorities, empowering, not replacing, human expertise. When you upskill your workforce to leverage real-time analytics and interpret agent outputs, you foster a culture equipped to innovate continuously.
Delivering measurable value through targeted use cases
Flashy pilots that never leave the testing phase do not create enterprise value. To secure buy-in, you must ground AI in end-to-end workflows that drive outcomes.
Consider the challenge of a 13-week cash flow forecast across dozens of entities. Historically, this is a lengthy process that requires analysts to pull manual exports, reconcile aging reports, and consolidate spreadsheets. By deploying an orchestrated cluster of specialized AI agents, you can ingest financial data, reconcile historical collection patterns, and flag discrepancies in real time.
This approach delivers value you can verify immediately. You drastically reduce the time to close, elevate forecast accuracy, and lower operational costs. More importantly, when you can trust your cash position weekly, you can confidently redeploy capital to fund strategic growth.
Lead the AI transformation
The integration of artificial intelligence is the leadership mandate for the modern CFO. Leaving this transformation to chance means your organization will quickly fall behind in a rapidly evolving market. Integrate seamlessly, optimize costs, and elevate your enterprise by taking ownership of your data, risk, and AI strategy today.
To jumpstart your AI transformation journey and build a resilient, forward-thinking finance function, reach out CrossCountry Consulting to define your leadership moment.
Today’s CFO is expected to perform multiple jobs at once. They’re asked to run the close, own the controls, and keep the operational engine humming, while simultaneously being expected to architect enterprise strategy, champion AI adoption, and translate data into decisions that move the business. This is not new as most finance leaders have been feeling the pressure for a while. But the pace of change is accelerating. What they’re still working out is how to do both without one job quietly starving the other.
To understand where the finance function is headed, CrossCountry Consulting partnered with the Financial Education & Research Foundation (FERF) on Evolution of the Finance Function, a research initiative surveying and interviewing 197 finance executives across private, public, nonprofit, and government organizations. Through this work, we define how today’s CFO is emerging as a strategic architect, championing technology adoption, spearheading enterprise transformation, and delivering long-term business value well beyond traditional financial stewardship.
AI is a catalyst for that transformation, but the findings make one thing clear: the organizations pulling ahead are the ones treating AI, talent, governance, and process as a single agenda rather than four parallel initiatives.
Highlights from Evolution of the Finance Function
- Interpreter capacity is the differentiator. Talent is the defining variable for future-ready finance functions. Yet 87% of finance teams report that only 25% or fewer of their members have formal training in data analytics or AI. Only 7% of finance leaders express strong confidence in interpreting AI outputs, demonstrating a significant upskilling gap.
- Strategic bandwidth is constrained. 77% of CFOs are deeply involved in enterprise-wide strategic decision-making, but 68% spend 40% or less of their time on strategic work due to operational demands.
- Automation and AI are reshaping the operating model. More than 80% of organizations are investing in automation and AI, but the majority cite persistent obstacles, including manual processes (81%), legacy system limitations (49%), and data quality challenges (38%) in their financial close and core activities.
- Governance and accountability must mature. 46% of organizations report no formal AI governance in place, even while 89% agree CFOs are ultimately accountable for AI outcomes. Joint ownership between CFO, CIO, and additional executive stakeholders is essential for scalable, compliant transformation.
- Operational excellence is the new benchmark. The month-end close exemplifies the convergence of process discipline, automation, and insight-driven analysis. While 62% are planning automation investments, only 15% have successfully implemented partial automation to date.
The path forward: Transforming the finance function with confidence
The research underscores a new mandate for CFOs and finance leaders: lead with vision, invest in talent and technology, and embrace continuous transformation anchored in robust governance. Success now depends on equipping teams with the skills to interpret and act on AI-driven insights, establishing transparent decision rights, and coordinating across functional boundaries to accelerate measurable results.
Finance organizations that build interpreter capacity, prioritize responsible AI adoption, and standardize processes will set the standard for operational agility and strategic influence. The ones that treat these as separate workstreams may still be explaining why last year’s AI investment hasn’t moved the needle.
The evolution of the finance function is no longer a future aspiration. It is a current imperative for organizations determined to lead.See how leading finance teams are bridging these gaps and maximizing AI-driven value. Download the full FEI Research Report
Sage Intacct’s R2 2026 release introduces a wide range of enhancements designed to improve visibility, streamline workflows, strengthen controls, and expand automation capabilities across the platform. Here’s a recap of the key updates included in this release.
Ready to maximize the value Sage Intacct can deliver to your business? View our demo of key updates:
Administration, Import Service, and AI
Several key R2 updates focus on improving administrative visibility, data management, and AI-driven workflows.
Roles and Permissions Reporting
One of the most practical additions in R2 is the new standard Roles and Permissions Report. Previously, administrators often had to cross-reference multiple screens or build custom reports to review role access across Sage Intacct.
The new report consolidates all assigned permissions into a single point-in-time snapshot, making it easier to validate user access, support audit preparation, and confirm both standard and custom permissions across modules.
Expanded Import Service Functionality
Sage Intacct continues investing in its modern Import Service, which centralizes and simplifies data imports with validation, preview, rollback, and AI-assisted mapping capabilities.
R2 introduces two new beta import options:
- AR Advances imports for creating and updating AR Advances
- Ownership Structure imports for consolidation ownership structures and periods
These enhancements are especially valuable for organizations managing complex multi-entity or advanced consolidation environments. (Note: Beta features are available through opt-in programs. Sign up for Beta access here.)
AI Gateway and AI Connectivity
A major innovation in this release is the introduction of the AI Gateway, a secure connectivity layer that allows organizations to connect Sage Intacct data with external AI tools and large language models (LLMs).
Using REST APIs and Model Context Protocol (MCP) connectivity, organizations can securely connect platforms like ChatGPT or Claude to Sage Intacct in a governed, permission-based framework. This enables users to query financial data using natural language and build custom AI-driven workflows and dashboards outside the native Sage Intacct environment.
AP Automation Improvements
R2 also includes several usability improvements for AP Automation.
Users can now switch between summarized bill entries and detailed line-item views directly while reviewing AP bills, rather than being locked into a format selected during upload.
Organizations using both AP Automation and Purchasing Automation can also now manage uploaded transactions from a single automated transaction list, simplifying workflow management and exception handling.
Accounts Receivable, Cash Management, and Order Entry Updates
AR Refunds Processed Through AP
One of the standout AR enhancements is the ability to process customer refunds directly through Accounts Payable.
Instead of issuing refunds offline, organizations can now generate AP bills tied directly to AR refunds, credit memos, or advances. This strengthens separation of duties by allowing AR teams to initiate refunds while AP teams manage disbursements and approvals.
Multi-Currency Payment Visibility
R2 also improves visibility into multi-currency transactions by displaying transaction, base, and bank currencies throughout posted payments, registers, and ledgers in both AP and AR.
Cash Management Controls
Additional cash management enhancements include:
- Expanded entity-based restrictions for bank transaction visibility
- Validation rules preventing duplicate debit and credit account usage
- Improved reconciliation workflows by removing automatic default transaction dates
Order Entry and Billing Group Improvements
Building on the Billing Groups functionality introduced in R1, Sage Intacct added several enhancements in R2:
- New billing frequencies, including semi-monthly and end-of-month schedules
- Improved navigation for Billing Groups
- New individual charge functionality for one-time charges within recurring billing groups
- Enhanced customer visibility into assigned billing groups
These updates help organizations manage recurring billing arrangements more flexibly and efficiently.
Fixed Assets Management Enhancements
Fixed Assets Management saw some of the most significant updates in the R2 release.
Key enhancements include:
- Splitting a single asset into multiple assets directly within the asset record
- Reverting partial disposals without manual journal entries
- Adding capitalization dates for CIP assets
- Reverting capitalization transactions
- Reversing depreciation postings while maintaining audit history
- Summarized depreciation journal entries to reduce GL volume
Organizations should pay particular attention to the new Correction Treatment configuration setting, which determines whether the system uses “revert” or “reverse” functionality for corrections and impacts feature availability.
Purchasing, Projects, and Inventory Updates
R2 also delivers updates for organizations managing purchasing workflows, project reporting, and inventory operations.
Enhanced Three-Way Matching
Purchasing Automation now supports enhanced three-way matching capabilities with line-level validation between purchase orders, receivers, and invoices. Users can review quantity and price variances directly within automated transactions before posting.
Project Currency Visibility
Organizations using project accounting can now display project summaries in alternate transaction currencies instead of only viewing balances in the base entity currency. This provides additional visibility for multinational and multi-currency operations.
Inventory Transfer Changes
Sage Intacct also announced that legacy inventory transfer-in and transfer-out transaction definitions will be deprecated. Organizations still using those legacy workflows are encouraged to transition to the newer warehouse transfer functionality, which simplifies processing and improves efficiency.
Looking Ahead
The R2 2026 release continues Sage Intacct’s focus on automation, auditability, AI connectivity, and operational efficiency. Review the release notes and evaluate how these features align with your organization’s priorities. CrossCountry Consulting’s Sage Intacct experts can help you assess impact, manage adoption, and maximize the value of your investment. Contact us today to get started.
Regulatory and compliance risk continues to evolve in both scope and complexity, requiring financial institutions to move beyond reactive approaches and toward more structured, forward-looking programs. As expectations shift and scrutiny intensifies, compliance functions are being asked not only to manage risk, but to demonstrate how effectively they govern and adapt.
Building resilient, future-ready compliance programs requires a coordinated approach across governance, risk identification, testing, and remediation—supported by enabling technologies and integrated operating models. The eight areas below highlight how institutions are strengthening compliance infrastructure and meeting evolving regulatory expectations.
________________________________________
How financial institutions can build resilient, future-ready compliance programs
- Compliance program management
A mature compliance program is the foundation of everything else. Leading institutions are assessing compliance programs, identifying gaps against regulatory expectations, and strengthening frameworks, governance structures, and policies that underpin effective risk management. This includes organizational resourcing assessments, compliance technology and systems reviews, Law, Rule, and Regulation (LRR) and obligation mapping—giving institutions a clear picture of where they stand and a credible path forward. - Risk and control self-assessments (RCSAs)
Effective RCSAs are more than a compliance checkbox. Leading practices standardize the process of identifying and evaluating risks, assessing control effectiveness, and documenting gaps while developing remediation roadmaps. This includes RCSA framework and methodology reviews, business process mapping, and the ability to scale resources in response to accelerated timelines or evolving demands. - Compliance testing
Independent, evidence-based compliance testing is essential for validating control effectiveness and identifying high-risk areas before regulators do. As regulators shift their focus from process compliance towards measurable risk reduction, the bar for what “good” testing looks like has risen. Leading compliance programs implement targeted compliance testing including control testing execution, transactional testing, and outcomes-based testing with rigorous QA/QC and a scalable delivery model. Testing is increasingly tied directly to the enterprise’s risk posture and risk appetite, ensuring resources are deployed where they matter most and that results are clear and defensible. - Regulatory relations center of excellence (CoE)
Exam readiness and regulator engagement are disciplines in their own right. Leading institutions are establishing regulatory relations CoEs that standardize regulatory responses, define clear governance and communication protocols, and enable timely, accurate regulator engagement. This includes support for regulatory interactions and inquiries, exam readiness, exam management, and executive board and regulatory reporting, as well as independent testing and remediation support for Matters Requiring Attention (MRAs), Matters Requiring Immediate Attention (MRIAs), consent orders, and supervisory commitments. - Regulatory change management
Keeping pace with regulatory change requires more than monitoring—it requires the capability to translate regulatory shifts into operating model adjustments before gaps become findings. Recent changes across the Office of the Comptroller of the Currency (OCC), Federal Deposit Insurance Corporation (FDIC), Federal Reserve, and Consumer Financial Protection Bureau (CFPB)—including evolving supervisory expectations and enforcement priorities—signal not reduced risk, but redirected risk, requiring compliance programs to continuously adapt or remain exposed. Leading programs are adopting agile, governance-led approaches to regulatory change by aligning risk, delivery, and cross-functional teams to drive efficient, scalable outcomes. This includes regulatory change assessments, remediation consolidation, technology implementation and dependencies (including ERM and AML system implementations), and structured reporting to support sustained compliance. - Consumer protection and fairness
Institutions must consistently demonstrate that they treat customers fairly across their products, services, and customer interactions. Leading institutions are enhancing consumer protection capabilities through compliance readiness assessments, product lifecycle reviews, consumer regulatory protection reviews across the full regulatory A-to-Z scope, fair banking and fair lending program reviews, and disputes, complaints, and fraud management. - Issues management
In a regulatory environment that increasingly demands evidence of measurable risk reduction, unresolved or poorly tracked issues create regulatory and reputational exposure, and a weak issues management program is itself a finding risk. Effective issues management programs establish clear governance, quality control, and consistent remediation across all lines of defense. This includes structured issue identification and assessment, monitoring and remediation management, reporting, oversight, and advisory—and AI-enabled approaches to accelerate issue management and address large remediation backlogs. - Digital banking compliance
As institutions expand digital banking capabilities and deploy AI across customer-facing and risk management functions, compliance must remain foundational. Regulators across the Securities and Exchange Commission (SEC), Financial Industry Regulatory Authority (FINRA), and Financial Stability Oversight Council (FSOC) have identified AI governance, model explainability, data lineage, and auditability as key examination priorities. Institutions that accelerate AI adoption without corresponding governance frameworks carry material regulatory exposure. Leading institutions are embedding compliance into digital transformation by integrating regulatory requirements into product design, deployment, and governance frameworks. This includes strengthening LRR mapping, aligning risk and control inventories, and ensuring that innovation and oversight evolve together.
Together, these eight areas reflect how leading institutions are strengthening compliance infrastructure to stay ahead of evolving regulatory expectations.
Meeting the regulatory compliance challenge head on
Across the industry, several principles consistently separate high-performing compliance programs from those that struggle:
- Governance before tools: Technology accelerates compliance only when supported by clear governance, defined roles, and documented obligations. Institutions that invest in tools before governance often find themselves with expensive infrastructure and persistent risk and compliance gaps.
- Evidence-based testing: Regulators increasingly expect institutions to demonstrate control effectiveness through rigorous, defensible testing across multiple lines of defense—not just attestations. A testing program tied to risk appetite and supported by independent QA/QC is a meaningful differentiator in regulator exam outcomes.
- Integrated change management: Regulatory change that is tracked in isolation—disconnected from business lines, technology teams, and product owners—creates implementation gaps that regulators will find before you do. Institutions that treat regulatory change as a cross-functional discipline are better positioned to implement requirements accurately, on time, and with documentation that holds up under scrutiny.
- Proactive exam engagement: The institutions that fare best in regulatory exams are those that engage proactively with regulators and treat exam preparation as continuous discipline rather than a pre-exam sprint. Implementing regulatory relations CoE with clear governance, pre-exam preparation protocols, and structured communication practices reduces exam risk meaningfully.
These principles reflect observable differentiators in how institutions perform under regulatory scrutiny.
The compliance imperative: Building for what’s next
The regulatory environment will continue to evolve, and institutions best positioned to navigate it are those that build compliance programs with the governance, infrastructure, and testing rigor to stay ahead of risk and scrutiny, particularly as AI-driven processes introduce new regulatory expectations. The opportunity for compliance leaders is to shift from reactive oversight to proactive, strategic enablement of the business.
Institutions that take this approach position compliance as a strategic enabler rather than a reactive function. To start transforming your institution’s approach to regulatory and compliance risk, contact CrossCountry Consulting
Regulatory and compliance risk has never been more consequential for the financial services industry. From sweeping consumer protection mandates to escalating exam scrutiny and rapid-fire regulatory change, compliance leaders are being asked to do more than ever before with greater accuracy, speed, and transparency. For chief compliance officers, chief risk officers, regulatory relationship leaders, and their teams, the pressure is not simply to keep pace. It’s to build compliance programs that are resilient, defensible, and ready for what comes next.
In this two-part blog series, part one explores the key drivers of regulatory compliance risk, while part two outlines how to build more resilient, future-ready compliance programs.
________________________________________
Why regulatory compliance risk is at the top of the agenda
Financial institutions must innovate at speed while effectively managing regulatory compliance risk and strengthening operational resilience. For global financial services providers and adjacent institutions, this challenge is compounded by the need to align compliance frameworks across jurisdictions.
Several converging forces have elevated regulatory and compliance risk to a board-level concern across the financial services industry:
- A reorientation of regulatory focus – not a relaxation: The current regulatory environment reflects a recalibration toward lighter-touch regulation and a risk-based approach, but compliance leaders should not mistake this for reduced scrutiny. The Office of the Comptroller of the Currency (OCC), Federal Deposit Insurance Corporation (FDIC), and Federal Reserve have each signaled a renewed emphasis on material risks and consumer “safety and soundness” execution—with Matters Requiring Attention (MRAs) framework revisions and supervisory rating changes designed to concentrate regulatory attention where it matters most. Institutions that respond by loosening compliance infrastructure rather than re-prioritizing it are misreading the moment.
- Rapid regulatory change and new entrants: The volume and velocity of new rules, guidance, and enforcement actions have made regulatory change management a strategic capability rather than an administrative function. Consumer protection regulations (Unfair, Deceptive, or Abusive Acts or Practices (UDAAP), fair lending, Fair Credit Reporting Act (FCRA)), digital banking requirements, and emerging rules around AI-driven products are creating compliance obligations that cut across every business line. Fintechs, BaaS investments, and tech-driven financial services are driving demand for guidance on meeting U.S. regulatory marks. The Consumer Financial Protection Bureau’s (CFPB) recent de-prioritization of certain BNPL enforcement in payments is a case in point: the underlying consumer protection risk hasn’t gone away—it has simply shifted, and compliance programs that don’t track and respond to that shift remain exposed.
- AI governance as a regulatory imperative: Rapid AI adoption across financial services is outpacing existing risk and compliance frameworks, prompting heightened scrutiny of AI-driven functions. Regulators across the Securities and Exchange Commission (SEC), OCC, Financial Stability Oversight Council (FSOC), and Financial Industry Regulatory Authority (FINRA) have each named AI governance as a top 2026 examination and supervisory priority. Expectations are specific: model explainability, robust data lineage, auditability of technology-driven decisions, and evidence that AI-assisted processes are accurate and fair. Institutions that have deployed AI in customer-facing or risk management functions without a corresponding governance framework are carrying material regulatory exposure.
- Consumer protection focus: The regulatory spotlight on fair banking, fair lending, and transparency in customer interactions has intensified. Federal fair lending deregulation is shifting enforcement to states attorneys general who are helping to bridge the regulatory oversight gap. Institutions must demonstrate that their products, services, and customer-facing processes treat consumers fairly—across the entire product lifecycle. Regulators are placing particular emphasis on marketing practices, fee transparency, investment suitability, and oversight of digital and influencer-driven channels.
- Intensifying exam scrutiny and remediation backlogs: Regulators have sharpened their expectations for compliance program maturity, documentation quality, and management accountability as evidenced by recent enforcement actions and supervisory guidance from the OCC, FDIC, CFPB, and Federal Reserve. Additionally, many institutions are managing legacy findings from prior exams alongside emerging risk areas, creating competing demands for compliance resources and increasing the risk of chronic, unresolved issues. Institutions that cannot demonstrate a robust, evidence-based compliance infrastructure that prioritizes timely remediation face heightened risk of MRAs, Matters Requiring Immediate Attention (MRIAs), consent orders, and supervisory commitments.
- Digital assets and financial crime enforcement: Recent regulator activity continues to signal that digital asset compliance is firmly in enforcement territory and under heightened scrutiny. Across the Financial Crimes Enforcement Network (FinCEN), Commodity Futures Trading Commission (CFTC), and OCC, regulators are scrutinizing AML program effectiveness, SAR quality, sanctions controls, and the compliance readiness of institutions engaging with crypto intermediation, tokenized collateral, and digital payment platforms. For institutions with any digital asset exposure, digital asset risk must be identified, prioritized, and remediated before implementation.
Taken together, these pressures mean that compliance is no longer a back-office function. It is a core operational discipline that demands dedicated leadership, scalable infrastructure, and a commitment to building future-ready compliance organizations.
Stay tuned for part two, where we’ll explore how to address these pressures and build resilient, future-ready compliance programs.
To start transforming your institution’s approach to regulatory and compliance risk, contact CrossCountry Consulting
For decades, moving business processes overseas was the default play for optimizing the bottom line. The business case for offshore outsourcing seemed practically undeniable. You moved accounts payable processing to Manila, routed vendor inquiries to Hyderabad, and sent data entry work to Kraków. The labor arbitrage was enormous, and for many companies, it delivered measurable savings.
But that calculus is rapidly changing. The same wave of artificial intelligence currently reshaping knowledge work is quietly dismantling the foundation on which traditional offshore models were built.
In this post, you’ll discover why the traditional offshore model no longer delivers the savings it once did, how AI automation can restructure your back-office operations and accelerate your close, and which strategic moves will position you to adapt your operating model for continuous growth and enterprise agility.
The Shrinking Arbitrage of Offshore Outsourcing
The original promise of offshore outsourcing was straightforward: pay significantly less for the same output. However, over the past decade, that cost gap has narrowed as wages have increased and competition for skilled talent has intensified. Managing distributed teams introduces hidden operational costs – coordination overhead, quality control, data security compliance, and the friction of distance. What once appeared as a 60-70% cost reduction on paper often results in only 30-40% savings in practice, and sometimes even less when accounting for vendor selection, transitions, knowledge loss, and management overhead. Given these inefficiencies and escalating compliance demands, finance leaders must look beyond labor arbitrage to ensure sustainable long-term growth.
How AI Automation Changes the Math
Now, layer in the rapid advancement of artificial intelligence. Tools capable of processing invoices, handling routine vendor inquiries, generating financial reports, and flagging transactional anomalies are no longer experimental. They are available, increasingly affordable, and highly reliable.
The scale of this shift is already showing up in the data. Approximately 40% of jobs now contain tasks that are automatable with current AI agents and robots a category that maps directly onto the same back-office and administrative work historically sent offshore. Organizations leveraging AI are already seeing tangible results, cutting up to 7.5 days from their monthly close cycles and delivering significant improvements in efficiency and financial accuracy. And the implications stretch well beyond individual finance teams. Looking ahead, the global BPO market, valued at over $300B, is on track to experience widespread AI-driven disruption by 2030.
Repatriating Work: The Enterprise Strategy
For large companies with mature technology stacks and dedicated IT capabilities, the strategic direction is becoming clear. These organizations are investing heavily in AI automation and repatriating work that was previously sent overseas.
This shift does not necessarily mean massive overnight transformations or immediate structural upheaval. Rather, it means that the next contract renewal with a legacy business process outsourcing vendor will face intense scrutiny. Finance leaders are evaluating whether they can achieve better accuracy, faster financial closes, and stronger risk management by bringing processes back in-house and powering them with intelligent automation.
For large enterprises, the ROI is compelling. Their scale and in-house expertise make implementing AI-driven insourcing a financially realistic path to gaining greater strategic value and control.
Managed Services: The Mid-Market Solution
The narrative becomes much more nuanced when we look at the mid-market. Smaller and mid-sized businesses often utilized offshore outsourcing because they lacked viable alternatives. They simply did not have the internal headcount to run a comprehensive finance department, nor could they afford to hire a full team of dedicated data analysts.
For these companies, the path forward is not immediate self-sufficiency through proprietary AI. They lack the IT infrastructure to deploy enterprise software, the internal expertise to train and manage models, or the time to become experts in a technological landscape that changes every quarter.
What many of these agile businesses are discovering is that the modern managed services model provides a highly compelling middle path. Rather than owning and operating AI-driven financial processes themselves, they collaborate with strategic partners who execute these functions on their behalf.
These partnerships combine deep process expertise with advanced AI automation to deliver optimized outcomes, not just billable labor hours. You can think of it as the natural evolution of outsourcing itself. The conversation is shifting from finding cheaper overseas labor to utilizing the right technology through a trusted partner who remains fully accountable for the financial results.
A Structural Shift for the Office of the CFO
It is tempting to frame this transition as a short-term trend driven by recent technological hype. It is not. The underlying economics of global labor and automation are changing in ways that will not reverse.
Labor costs in offshore hubs will continue their upward trajectory. Simultaneously, AI capabilities will only continue to improve, analyze data more effectively, and integrate more seamlessly with existing ERP systems.
Crucially for the Office of the CFO, the risk appetite for sensitive financial data traveling across international borders is sharply declining. In an era of heightened regulatory scrutiny, complex compliance requirements, and escalating cybersecurity threats, maintaining direct oversight of your financial data is paramount. Advanced AI tools provide comprehensive risk assessment capabilities that traditional offshore outsourcing models often struggle to match.
Companies that treat this moment as an opportunity to genuinely rethink their operating models will be better positioned than those who simply ride out the current contract and defer the harder decisions. Deferring these harder strategic decisions will only compound future risks. That doesn’t mean every business needs to invest in an AI center of excellence tomorrow. But it does mean the strategic conversation regarding cost optimization and digital transformation has to start now.
Where CrossCountry Consulting Fits
CrossCountry partners with leaders end-to-end shaping the target operating model, deploying AI Transformation and focused AI-Powered Solutions, and standing up AI Enablement and AI Governance programs. And when clients want us to run it, we can manage delivery and operations on their behalf, bringing the right SMEs to execute, scale, and sustain the model.
Discover how CrossCountry designs, deploys, and runs AI, embedding it into live operations with enterprise‑scale orchestration and governance.
Coupa Release 45 (R45) centers on three clear priorities: greater user control, increased configurability, and a more modern experience across the platform. From expanded AI capabilities and Coupa Navi enhancements to meaningful AP and Coupa Pay updates, R45 introduces improvements that deliver both operational efficiency and strategic value for procurement, accounts payable, and finance leaders.
For teams planning ahead, understanding where these updates have the most impact is essential. Below, CrossCountry Consulting’s Coupa implementation and transformation specialists highlight the R45 changes that matter most and how organizations should prepare. Want to explore all things R45 in more detail? Watch our recent webinar.
Key Dates and Release Waves
Coupa has structured the R45 rollout across three specific waves for production environments.
Production release schedule
- Wave 0/1: Live in test environments as of late April 2026
- Wave 2: Test begins May 4; production rollout May 22, 2026
- Wave 3: Production rollout June 5, 2026
If your organization is unsure which wave applies to its environment, a support ticket with Coupa can confirm the assignment. CrossCountry Consulting recommends using the two‑week test window to validate workflows, regression‑test integrations, and intentionally configure opt‑in features before they reach end users. Our post‑production team also supports release management to help organizations deploy updates smoothly.
Platform Security and AI Highlights
R45 advances Coupa’s investment in AI‑enabled productivity while strengthening platform security and cost controls. As AI usage grows, administrators gain greater visibility and governance through configurable alerts that notify users as they approach AI credit thresholds. Usage can automatically pause when limits are reached, helping prevent unplanned consumption.
The release also introduces true last‑activity tracking, which provides clear, reportable insight into a user’s most recent intentional activity. This visibility supports more effective license optimization and cost management.
From a security standpoint, R45 enhances protection with OAuth IP whitelisting. By validating the source IP address of each API request and blocking traffic outside approved ranges, organizations can reduce risk exposure.
Coupa Navi also receives productivity‑focused upgrades, allowing users to generate AI‑guided supplier risk profile snapshots and perform sanction list screening within their workflow. Administrators can further extend capabilities by creating custom AI agents in Agent Studio using company‑specific knowledge.
Procurement and Sourcing Enhancements
R45 introduces new capabilities that give procurement teams greater control over catalogs, spend visibility, and supplier data. Landed cost can now be captured directly at the requisition header, allowing charges and discounts to be applied more flexibly (opt‑in required). Buyers can now build preferred items while continuing to leverage punch‑out pricing (opt‑in required). In addition, a redesigned supplier UI replaces static pages with configurable, insight‑driven dashboards, and demand aggregation enables scheduled purchase orders to be consolidated by supplier, site, and item.
Invoicing, AP, and Coupa Pay Efficiency
Many R45 updates focus on accounts payable efficiency and payment governance. For streamlined invoice processing, AP teams can bulk edit invoices and download attachments from a single page view, match amount‑based purchase orders to quantity‑based invoices, and leverage default e‑invoicing compliance updates for Brazil and France.
For advanced payment controls, Coupa Pay enhancements include Brex connectivity, required supporting documentation, supplier‑level payment configuration, and the ability to withdraw submitted payment batches for edits.
Stay Informed and Prepare
With multiple R45 features designated as opt-in, proactive planning is critical to maximize value. Confirm your release wave, test updates in your sandbox, and enable new features intentionally to ensure operational integrity. We recommend migrating to the enhanced Coupa experience well in advance of the Invoice Smash Core transition, which completes in September 2026.
To explore how Coupa Release 45 may impact your roadmap and priorities, connect with CrossCountry Consulting.
The path to procurement modernization is littered with stalled initiatives. Studies show that at least 70% of digital transformations fail, and an estimated 95% of Generative AI initiatives fall short of their initial promise. Why? Because too many organizations treat AI as a mere technology upgrade rather than a holistic business transformation. To truly unlock efficiency and growth, leaders must shift their perspective – from AI as a tool to AI as a catalyst for better experiences and sustainable growth in spend management.
Building a Foundation That Scales
The high failure rate of AI initiatives often stems from a lack of foundational rigor. Many organizations rush to deploy tools without first establishing value alignment or governance. To integrate AI in spend management successfully, leaders must first align people, processes, and technology.
This begins with a human-centered approach. The goal is to empower, not replace, human expertise. By grounding AI in end-to-end value streams, such as Source-to-Pay or Record-to-Report, technology serves the business strategy, not the other way around. A thoughtful foundation also includes robust governance to manage risk, ensuring that trust, compliance, and security are non-negotiable parts of the procurement AI roadmap.
From Tools to Teammates: The AI Agent
To understand the potential of AI in procurement, leaders must redefine their relationship with technology. An AI agent is not just a piece of software; think of it as a virtual colleague to delegate to and trust.
Unlike a static script, an AI agent possesses “corporate knowledge.” It understands standard operating procedures, learns from feedback instantly, and operates within strict guardrails. For example, modern AI-native platforms like Rossum can ingest documents in over 275 languages, validate data against master records in real-time, and act autonomously to resolve exceptions. Beyond the hype: See how CrossCountry Consulting and Rossum leveraged AI to achieve 90% data accuracy and 64% touchless processing for a leading procurement team.

Specialized, domain-specific AI models are critical. They provide the accuracy and “confidence scores” necessary for procurement teams to trust the output and focus only on the exceptions that truly require human judgment.
Combating Fraud and Accelerating Efficiency
The risks of AI inaction are rising. This is where AI in accounts payable can be a real value-add and a formidable line of defense. Platforms like Coupa use AI to analyze spend patterns across trillions of dollars of transactional data. They can flag high-risk anomalies that human auditors might miss, such as a sudden spike in invoices just below approval thresholds or duplicate payments across different business units.
Beyond risk mitigation, the efficiency gains are tangible. By automating manual tasks, procurement leaders can reallocate their teams to high-value activities, such as strategic sourcing and supplier relationship management.
A Practical Path Forward
Transforming spend management doesn’t require a multi-year overhaul before results are realized. Instead, we use a “Jumpstart” approach, a lightweight, focused proof of value that delivers early impact and learning while laying the groundwork for a scalable, longer-term solution. Jumpstarts accelerate alignment, design, and delivery in weeks, not months.
Organizations can categorize their AI journey into three streams:
- Embedded AI: Leveraging AI features already present in platforms like Coupa or Workday.
- AI-Native Software: Implementing specialized tools designed with AI at the core, such as Rossum for document processing.
- Bespoke AI Solutions: Building custom agents for unique challenges, such as comparing invoice amounts to purchase orders across accounting and settlement processes.
Embracing a Future of Intelligent Spend
The future of procurement is augmented by agents, powered by data, and guided by humans. AI offers a unique opportunity to gain total visibility into org-wide spend, ensuring every dollar is accounted for and strategically aligned with corporate goals.
Start with a clear vision, prioritize value streams, and let AI be the catalyst that transforms procurement from a cost center into a strategic engine for growth. Contact CrossCountry Consulting to get started.
OneStream has become a cornerstone platform for modern FP&A organizations, enabling integrated planning, forecasting, and reporting at enterprise scale. Yet many finance teams still struggle to unlock its full value, not because of limitations in the technology, but because the assumptions feeding their models are incomplete, outdated, or disconnected from how the business actually operates.
As volatility increases and planning cycles compress, FP&A leaders are rethinking how assumptions and operational drivers enter OneStream in the first place. The next frontier of OneStream value creation sits at the intersection of process design, intelligent data ingestion, and continuous planning.
Who This Is For
This perspective is designed for FP&A leaders and finance transformation teams who have already selected or implemented OneStream and are focused on accelerating time to value, improving forecast relevance, and scaling planning capabilities beyond static annual cycles.
For teams earlier in their CPM journey, see our guide on maximizing your CPM investment across Finance and IT.
Below are five proven best practices FP&A organizations are adopting, supported by CrossCountry Consulting and Sensible AI, to move from static planning to adaptive, insight driven decision making within OneStream.
1. Treat Unstructured Data as a Strategic Planning Asset
Many of the most critical planning assumptions don’t originate in financial systems. They live in contracts, pricing schedules, vendor agreements, and headcount files that sit outside OneStream.
Leading FP&A teams design OneStream models around true business drivers and establish scalable ways to transform unstructured source data into inputs that are ready for system use, reducing reliance on spreadsheets and increasing confidence in planning assumptions.
2. Anchor Driver-Based Planning in Real-World Business Signals
Driver based planning is only as effective as the relevance of its drivers. Updating assumptions on a fixed cadence, regardless of how the business changes, limits responsiveness.
High-performing teams connect drivers to commercial and operational signals such as pricing terms, renewals, volume thresholds, and cost escalators, ensuring financial impact is reflected as the business evolves.
3. Make Scenario Modeling Fast, Repeatable, and Scalable
Scenario modeling is essential for executive decision-making, yet many FP&A teams limit scenarios due to the effort required to gather and validate assumptions.
By standardizing scenario frameworks in OneStream and reducing friction in assumption ingestion, FP&A teams can run more best, base, and worst case scenarios per cycle and respond faster to leadership questions.
4. Eliminate Manual Effort to Reinvest in Strategic Analysis
Even mature OneStream environments often rely on manual extraction and spreadsheet-based workarounds that slow planning cycles and introduce risk.
Automating assumption ingestion and standardizing planning workflows frees FP&A capacity for higher-value activities such as variance analysis, business partnering, and strategic storytelling.
5. Shift from Periodic Forecasting to Continuous Planning
Annual planning and static forecasts are no longer sufficient in dynamic business environments.
Leading organizations operationalize continuous planning in OneStream through rolling forecasts supported by continuously refreshed inputs, improving forecast accuracy and decision relevance throughout the year.
What Leading FP&A Teams Measure
FP&A leaders embracing these practices typically track improvements in forecast accuracy, time to update forecasts after assumption changes, number of scenarios modeled per cycle, and manual hours eliminated. More importantly, they see FP&A repositioned as a strategic partner delivering timely, trusted insight when it matters most.
Ready to Unlock More Value from OneStream?
If you’re looking to accelerate OneStream outcomes, modernize your planning operating model, or move toward continuous, driver-based planning, we’d welcome a conversation.
Meet with our team of OneStream and FP&A transformation experts to discuss your goals and identify practical next steps.
Contact us to schedule a conversation.
Regional banking institutions evaluating new ERP or EPM systems often focus on improving how transactions are captured, closed, and consolidated within the Record-to-Report process. When the emphasis centers on general ledger design and system implementation, reporting strategy is frequently addressed too late in the process.
Yet the largest consumers of financial information are rarely considered early in technology design and implementation. Reporting strategies must support regulatory reporting across agencies such as the FDIC, Federal Reserve, and SEC, while also enabling internal management reporting across financial performance and operational activity. When implementations focus primarily on ledger design and transaction processing, the needs of these reporting stakeholders are often addressed too late.
This raises an important question: how should financial institutions design reporting architecture that meets the needs of all stakeholders from the beginning, rather than retrofitting solutions after an implementation is already underway?
The answer is to anchor system design in reporting requirements from the start. Instead of treating reporting as a downstream output of the general ledger or EPM platform, institutions must first define the reports they need to produce—from regulatory filings to board materials and profitability analyses—and then design the supporting data architecture accordingly. While formats may differ, all reporting should be drawn from consistent, multi-dimensional, and governed source data. Without that foundation, even the most advanced platforms simply accelerate existing fragmentation rather than resolve it.
Neglecting Reporting During Implementation
Across institutions, as much as 75% of resource time is spent gathering, reconciling, and validating data rather than analyzing it. Instead of enabling insight and automation, finance teams devote significant effort to manual processes across fragmented data sources simply to produce required reporting.
This misallocation of effort begins with a single misstep: treating reporting as an afterthought. When reporting requirements are not defined upfront, “shadow reporting” is developed to fill the gap. Regulatory, management, and statutory outputs evolve along separate paths, creating data silos without a single version of the truth producing unreliable data and increasing operational reporting risk.

Reversing this pattern requires more than incremental fixes. It requires designing reporting architecture deliberately, with clear multi-dimensional structure, governed data foundations, and defined methodologies from the outset. Only then can institutions redirect effort away from reconciliation and toward insight.
Crafting a Holistic Reporting Strategy
Institutions must also support multiple categories of reporting, including regulatory reporting (SEC, FINRA, FDIC/Federal Reserve), management reporting (business reviews, board reporting, ALCO), and other internal reporting across accounting, tax, credit risk, and operations. While these reports serve different audiences, they are largely derived from the same underlying data at varying levels of granularity.
The starting point for these institutions is to catalog the full inventory of required reporting and define the data outputs necessary to support each use case, with a clear focus on delivering value to the end user. Once defined, the reporting strategy becomes a north star, guiding the evolution of reporting capabilities as well as supporting data and technology infrastructure. When aligned properly, this foundation enables institutions to meet all reporting needs from a single version of the truth, driving consistency, efficiency, and more meaningful insight.
When planning a reporting strategy, it is important to consider the different timing scenarios that may arise. An example of common situations and related strategies include:

It’s not uncommon for institutions to define target and interim states to deliver value on an incremental and manageable basis. Typical timelines range from 3-24 months, delivering notable functionality on a quarterly/semi-annual basis.
Single Version of The Truth
Achieving a single version of the truth begins with rethinking the data foundation. While the general ledger is essential for financial reporting, it is inherently too summarized to support deeper strategic insight.
The path forward is to establish an instrument-level foundation that captures transaction detail at its natural level of granularity, including loans, deposits, securities, and other financial products. From there, dimensions must be harmonized across the enterprise so that regulatory and management reporting draw from the same governed data source.
When reporting frameworks originate from a common foundation, reconciliation becomes embedded in the architecture rather than dependent on manual effort. The result is a reporting environment that supports statutory requirements while remaining flexible enough to generate meaningful business insight.
Optimizing Reporting for Strategic Insights
Once the data foundation is in place, the focus shifts from assembling numbers to generating insight. For regional banks and diversified financial institutions, this means moving beyond static P&L statements toward multi-dimensional reporting.
The most meaningful insights emerge when performance can be evaluated across consistent enterprise dimensions. At a minimum, institutions should be able to analyze activity by Customer or Client, Product, Account, Organization, at the Instrument level, and at intersections across enterprise dimensions. By examining these dimensions, leaders not only gain insight into the numbers themselves but also uncover the reasons behind their changes and identify where genuine value is generated.
Achieving this requires more than layering attributes onto the general ledger. Each dimension must be defined, governed, and structured hierarchically so that activity rolls consistently from instrument to product, product to line of business, and into enterprise reporting without manual reclassification. When that structure is in place, finance, risk, treasury, and regulatory reporting can view the same activity through different lenses.
That is what transforms reporting from a compliance obligation into strategic analytics that drive business objectives.
The Reporting Landscape
Financial institutions operate in one of the most complex reporting environments of any industry. Regulatory filings, statutory financials, and internal management reporting each impose distinct structural requirements and levels of granularity, and none map cleanly across reports or to the general ledger. Regulatory reports such as the Federal Reserve Y-9C or FDIC Call Report require highly specific classifications and cross-report integrity, while management reporting demands flexible views across clients, products, segments, and business lines.
These requirements rarely align naturally with the structure of the general ledger chart of accounts. Without intentional design, institutions typically resort to developing parallel reporting processes for regulatory, statutory, and management outputs, increasing reconciliation effort and operational risk.
The objective of a modern reporting architecture is not to eliminate multi-dimensional reporting differences, but to anchor them to a common data foundation. When reporting frameworks draw from the same governed source of instrument-level data, institutions can satisfy multiple reporting obligations while preserving transparency, consistency, and reconciliation across report outputs. The same loan can satisfy a Call Report schedule, an FRB submission, or an SEC maturity bucket disclosure simply by applying the right attribution logic — no separate pipelines required.
This foundation becomes especially important when management reporting evolves beyond financial statements into profitability and performance analytics.
The Role of Management Accounting Methodologies
With a consistent reporting architecture in place, institutions can move beyond producing numbers to understanding performance. This is where management accounting methodologies become critical.
Multi-dimensional profitability and planning are only as credible as the methodologies that support them. When poorly designed or inconsistently applied, business lines lose confidence in the numbers, and management reporting stops driving decisions. Four areas consistently distinguish institutions that generate meaningful insight from those that do not.
Funds Transfer Pricing (FTP)
Without a disciplined FTP framework, business lines appear more or less profitable than they actually are. FTP transfers interest rate and liquidity risk to a central function where it can be properly managed, leaving business lines with a stable, comparable margin that reflects true commercial performance.
Expense and Cost Allocation
When costs are not allocated to the deal or instrument level, product profitability becomes guesswork and accountability breaks down. A well-designed allocation model assigns costs based on actual consumption and rolls them into meaningful product and business-line views. Whether an institution allocates fully or excludes corporate overhead matters less than making that decision deliberately and applying it consistently.
Revenue Sharing and Allocation
In relationship-driven institutions, deals frequently involve multiple teams. When attribution rules are not defined upfront, disputes inevitably follow. Upfront sharing, ongoing splits, and double-counting each create different behavioral incentives and reporting outcomes. Establishing clear governance around revenue attribution is therefore as much a cultural decision as a technical one.
Capital Allocation
Business lines that do not bear the cost of capital have little incentive to use it efficiently. Allocating regulatory capital to products and lines of business, and measuring returns against that cost, allows institutions to evaluate performance in terms of shareholder value rather than revenue alone. As with other management accounting methodologies, capital allocation must balance analytical precision with decision-making value and long-term maintainability; excessive granularity can add complexity without improving insight.
Governance and Transparency
The fastest way to undermine any of the accounting methodologies is opacity. When business lines cannot explain how allocations are calculated, they quickly stop trusting the results. Tying charges to understandable activity drivers—accounts serviced, transactions processed—transforms allocation from a political debate into a practical tool for running the business.
Technology-Enabled Reporting Done Right
The journey to optimized reporting and analytics is not simply a technology upgrade. By building reporting frameworks rooted in instrument-level data, governed multi-dimensional structures, and disciplined management accounting methodologies, regional banking institutions transform how the finance function operates and delivers value to the organization.
Teams that once spent as much as 75% of their time gathering and reconciling data can redirect that effort toward generating insight and informing decisions. For institutions seeking to scale, this shift represents a meaningful and sustainable competitive advantage.
The institutions that define their reporting and analytics strategy at the beginning of a transformation position themselves to extract far greater value from ERP and EPM investments. CrossCountry Consulting helps financial institutions develop these strategies to deliver scalable insight, stronger governance, and long-term business value.
Migrating off SAP ECC and on to S/4HANA in the near future? SAP maintenance of ECC is sunsetting in 2027, with some support available into 2030. Don’t underestimate the time and complexity involved.
Most organizations materially under-budget and under-plan their S/4HANA transformations because they anchor on software and system integrator costs while underestimating internal effort, data complexity, and operating model change. Now’s the time to set up your organization for success and lay the foundation for an efficient, profitable transition.
Here’s where to begin.
Phase 1: Strategic Planning, Project Budgeting, and Migration Planning
Timeline: 3–6 Months
Goal: Define the “What,” “Where,” and “How Much.”
1. SAP Readiness Check (Technical Foundation)
Before you budget, run an SAP Readiness Check. It provides:
- Simplification items: Which ECC functions are deprecated or changed in S/4HANA.
- Custom code impact: An automated scan of your custom “Z” objects to identify incompatibilities with S/4HANA and expose embedded technical debt that must be remediated, retired, or redesigned.
- Sizing recommendations: The HANA memory requirements (this dictates your cloud/hardware costs).
- Data readiness assessment: Existing database and data structures can have a big implication on the transition timeline, data strategy, and transition options. If data isn’t in a unicode format, doing a Brownfield RISE conversion is more complex compared to a Greenfield GROW conversion where there is no impact.
2. Architecture Decision and Hosting Model
Decide between SAP RISE versus GROW. Each has public vs private cloud options and slight functionality differences. From there, various kinds of bundling, licensing, and management options are available.
Note: With GROW, you can only do Greenfield implementations; with RISE, you can do Greenfield, Brownfield, or Bluefield (see below).
Featured Insight
3. Selection of Migration Strategy (The ‘Big Three’)
You must choose your path now, as it can change the budget by millions:
- Greenfield (new implementation): Best if your ECC processes are “broken” or highly customized. Start fresh by adopting “Clean Core” and standard best practices.
- Cost profile: Higher upfront consulting; lower long-term maintenance.
- Brownfield (system conversion): A technical “lift and shift.” Best if your current processes work well, you want to preserve historical data, and you’re under a tight timeline. It’s not ideal, but in certain situations, it’s the most feasible.
- Cost profile: Lower upfront; carries over technical debt.
- Bluefield/selective data transition: Carve out specific data or company codes.
- Cost profile: High complexity; requires specialized third-party tools (e.g., SNP or Natuvion).
4. Budgeting: Beyond the Software
A common mistake is budgeting only for licenses and the system integrator. Ensure your budget includes:
- Backfill costs: Budgeting for temporary staff to cover the “day jobs” of your SMEs while they work on the project.
- Data cleansing: SAP won’t fix your “bad data.” You may need a dedicated data project before the migration starts.
- Third-party integrations: Budget for updating tax engines (Vertex/Avalara), EDI, and WMS systems.
Phase 2: Implementation Planning and Resource Allocation
Timeline: 2–4 Months
Goal: Define the “Who” and “When.”
1. Assembling the Dream Team
You cannot rely solely on external consultants. Your internal team must include:
- Executive sponsor: A C-suite leader who can break ties when departments disagree on process changes.
- Process owners (SMEs): Your best people from finance, supply chain, and sales. If they aren’t “too busy” to be on the project, they probably aren’t the right people.
- Global process leads: Empowered individuals who can authorize moving from “custom” back to “SAP Standard.”
- Project Management Office (PMO): A PMO is a critical cross-functional team that can design and enforce a governance model and manage the execution of tasks, resources, deadlines, budgets, and change. An implementation is not just an IT project; it’s an integrated business transformation. A PMO can help remove blockers, secure approvals, and streamline global versus local decisions.
2. System Integrator Selection
Don’t just pick the lowest bidder. Evaluate partners based on:
- Conversion experience: Ask for references specifically for ECC to S/4 migrations, not just Greenfield builds.
- Accelerators: Do they have proprietary tools to automate custom code remediation or data transformation?
3. The ‘N+1’ Landscape Strategy
Planning your environments is a major cost and resource driver.
- Project landscape: You will need a sandbox, development, and QA environment for the S/4 project.
- Maintenance landscape: You still need to support your existing ECC system for 18 months.
- Strategy: Define how you will “double-maintain” (dual entry) transports between the old ECC world and the new S/4 project.
4. Data Purging and Archiving (The ‘Weight Loss’ Phase)
HANA is memory-intensive.
- Action: Implement an archiving strategy now. Identify “cold data” (7+ years old) that can be moved to a low-cost archive rather than the high-performance HANA database. This can reduce your infrastructure costs by 20–40%. It’s important to note that this action introduces its own level of cutover complexity.
5. Change Management Strategy
S/4HANA introduces the Fiori UI, which is a radical departure from the “Blue Screens” of ECC.
- Planning: Budget for a dedicated change management lead. This isn’t just training; it’s the strategy for how you will convince users that a new way of working is better, preventing shadow IT and resistance.
With the 2027 deadline fast approaching, your migration strategy should be a top priority. For expert planning, support, and implementation advisory, contact CrossCountry Consulting.
The 2026 Sage Intacct R1 release delivers high-impact enhancements designed to elevate automation and precision for finance departments. For administrators and power users leading digital initiatives, these updates streamline core operations, bolster internal controls, and significantly accelerate the month-end close.
Ready to maximize the value Sage Intacct can deliver to your business? View our demo of key updates:
Cash Management: Streamlined and Accurate
- Simplified check printing: Check printing is now easier to configure with a context-driven interface that eliminates unnecessary fields and streamlines setup for company address and logo. Key features include:
- Dynamic field display based on selections.
- Address fields only appear when selecting “Use a different address”.
- One-click logo uploads.
- Improved bank reconciliation with document numbers: A new Document Number field on Bank Interest and Charges now links fees with related transactions for better traceability. This improves bank reconciliation by matching payments and fees with shared identifiers, saving time, and improving audit trails.
- Unified transaction management: Imported bank transactions via Bank Transaction Assistant now flow directly to the Banking Cloud tab, consolidating all banking activity in one place and simplifying reconciliation workflows.
- Multi-entity bank register enhancements: Bank register report now auto-populates entity location filter within entities, saving time and reducing errors in multi-entity environments.
General Ledger: Advanced Reconciliation Capabilities
Organizations can now reconcile balance sheet accounts, tracking debit and credit activity systematically. High-value use cases include prepaid expenses, payroll clearing, accrued expenses, and fixed assets. The GL Account Reconciliations Activity report provides visibility into matched and unmatched transactions, improving accuracy and audit readiness.
Accounts Receivable: Better Customer Insights
Three new fields added to the customer record – health score, health status, and churn risk – allow teams to track customer account health. Use these insights for renewal risk identification, credit risk assessment, and prioritizing collections to improve revenue retention.
Additionally, new billing groups streamline recurring invoicing by allowing organizations to group customers with similar billing needs and automate invoice generation on a defined schedule. Teams can set start dates, limit occurrences, review invoices before posting, and monitor run results, including detailed errors. The feature supports non‑inventory items, requires future‑dated schedules, and includes new permissions for access control, reducing manual work while preserving flexibility.
Fixed Asset Management: Full Lifecycle Tracking
- Construction in Progress (CIP) support: CIP functionality tracks asset acquisition costs from initial spending through capitalization, streamlining visibility and transitions to active asset status.
- Asset cost adjustments: Teams can now adjust asset costs post-service using AP memos, addressing errors, capital improvements, or revaluations, with full transparency in the cost adjustments tab.
- Roll-forward reports: New roll-forward reports provide clear visibility into asset cost, depreciation, and net book value changes over periods, supporting GL to sub-ledger reconciliation.
- Flexible GL account assignment: Organizations can now assign the same GL account to multiple asset classifications, simplifying chart of accounts management.
End-to-end Sage Intacct value creation with an expert implementation and advisory partner
Simplify and transform financial management processes, automate key workflows for scale, and generate real-time enterprise insights for faster decision-making.
Tax Management: Simplified Reporting
- Enhanced VAT/GST display: Order entry and purchasing transactions now consolidate net amounts and tax totals into a single line for better clarity.
- Custom tax reports: Organizations can create tailored tax reports using configurable detail boxes and rules, streamlining compliance for jurisdictions with complex tax requirements.
Automation and Efficiency: Smarter Tools
- AI-powered import tools: Enhanced import capabilities include automated field mapping, data transformation, and preview functions, reducing manual data prep and improving accuracy.
- Predictive tax details: AP automation predicts tax details at the line level using historical trends, speeding up invoice processing and reducing errors.
- Secure email enhancements: A new allowed email addresses list strengthens security by ensuring outgoing emails originate from approved sources, reducing phishing risks.
- AP automation improvements: Improvements include auto-forwarding, broader file format support, and predictive text-based transaction creation, streamlining AP processes for high-volume operations.
- Bulk-update projects: Users can bulk‑update multiple projects at once, adjusting shared fields via a background job with email confirmation. Additionally, projects can link directly to CIP assets, automatically connecting transactions to streamline capitalization tracking and reduce reconciliation effort.
- Dynamic allocations: In the GL, a single allocation definition can now cover an entire account group and automatically include newly created accounts, minimizing maintenance for organizations managing large, multi‑entity expense structures.
Purchasing and AP: Advanced Tools
- Multi-currency close automation: Close automation is now supported for multi-base currency organizations, enabling faster, more reliable reconciliations globally.
- Line-level PO matching: Three-way matching now works at the line level for purchase orders, receivers, and invoices, improving accuracy and reducing manual intervention.
- Centralized AP advances: Multi-currency organizations can now manage AP advances at the top level, simplifying workflows and improving consistency.
- Recurring transaction notifications: Automatic email alerts notify teams of failed recurring transaction schedules, ensuring timely issue resolution.
Moving Forward
Sage Intacct R1 updates empower CFOs to optimize operations, improve controls, and gain strategic insights. Review the release notes and align features with your priorities in 2026 and beyond. CrossCountry Consulting’s Sage Intacct implementation experts can help you capitalize on the latest updates to maximize your investment. Contact us today to get started.
Private equity (PE) margin plans rarely fail because the math is wrong. They fail because the organization lacks a shared, operationally grounded view of how margin is created and destroyed – day to day, SKU by SKU, customer by customer.
As SKU economics become visible, leaders often realize that margin targets rely on price increases the market will not accept. In many situations, this leads the organization to debate assumptions rather than address root causes.
There is a practical way out: Make contribution margin the common economic language across finance, operations, and sales – then embed it into a contribution-driven KPI framework that refreshes at the pace of decisions.
The Trap: When the Model Is ‘Right’ but the Business Can’t Execute
Many manufacturing portfolio companies set margin targets at the top of the P&L (gross margin, EBITDA) ahead of SKU‑level cost and pricing visibility.
As soon as a reliable cost foundation is built – grounded in accurate bills of material, routings, labor standards, and overhead logic – the required price to hit the target can jump to levels customers simply won’t take. At that moment, the margin plan turns from a target into a source of internal friction.
This is the PE margin trap: Pricing is expected to close a gap that is largely driven by operational behavior and portfolio mix – not by commercial execution alone.
Why Pricing Gets Blamed
Pricing becomes the focal point because it appears to be the fastest lever. But when SKU‑level costing is transparent, pricing is effectively used to pass operational inefficiencies – overtime, low efficiency, scrap, and overhead – on to customers.
Sales teams can’t defend increases customers don’t value. Operations teams can’t change fundamentals overnight. Finance teams can justify the math, but the business still stalls.
The result is predictable: Leaders debate assumptions (OEE, labor rates, overhead burdens) instead of aligning on what must change and where it matters most.
Springing the Trap: Contribution Margin as an Operating Signal
The breakthrough is to treat contribution margin not as a finance output, but as an operating signal.
Contribution margin sits at the intersection of price, material, labor, and efficiency. It’s close enough to operations to be actionable and clean enough financially to guide decisions.
When contribution margin becomes the shared language, finance and operations stop debating who is “right” and start focusing on the few constraints and behaviors that actually move EBITDA and cash.
A Contribution-Driven KPI Framework (What It Is and What It Changes)
A contribution‑driven KPI framework makes clear how day‑to‑day operational decisions create or destroy economic value. Contribution margin reflects what remains after direct materials, direct labor, and variable manufacturing costs – showing how pricing, efficiency, and execution combine at the SKU and customer level.
Instead of optimizing activity metrics in isolation, teams use contribution margin to see where value is actually created: at constrained resources, within specific products, and across customers.
Optimally, the framework is delivered through near-real-time KPI dashboards (e.g., Power BI) that connect financial outcomes directly to operational drivers.
Characteristics of an effective framework:
- Clear, drillable views that flow from enterprise → plant → product family → SKU → customer.
- Explicit contribution margin components, showing how price, material cost, labor, and operational performance combine to drive contribution (in dollars and percent).
- A margin bridge that explains changes in contribution through price, volume, mix, and cost drivers.
- Operational KPIs translated into contribution‑based measures, so shop‑floor priorities align with economic impact rather than activity alone.
- Direct traceability to ERP and source‑system data, ensuring the insights are credible, explainable, and trusted.
Translating Plant KPIs Into Contribution-Lens KPIs
| KPI Area | Traditional KPI | Contribution-Lens KPI |
|---|---|---|
| Equipment | OEE% | Contribution per Machine Hour |
| Labor | Efficiency % / Utilization % | Contribution per Direct Labor Hour |
| Quality | Scrap % / FPY | Scrap Cost at Contribution |
| Throughput | Units per Hour | Contribution per Constrained Hour |
| Inventory | Turns / DIO | Cash Tied in Low-Contribution SKUs |
| Complexity | SKU Count | Contribution per SKU |
How the Framework ‘Springs the Trap’
Once contribution margin becomes visible and explainable, the margin plan becomes executable because leaders can sequence decisions instead of applying blunt force.
Here’s what a practical sequencing looks like:
- Short term: Protect contribution margin with targeted pricing actions and mix decisions where the economics are structurally strong.
- Medium term: Focus continuous improvement on the handful of drivers that destroy the most contribution at constrained resources (yield, labor, changeovers, downtime).
- Long term: Hardwire contribution margin insights into portfolio choices (rationalization, product innovation/PLM discipline, and capital allocation).
The Questions That Separate Aspiration From Execution
Instead of asking “Why can’t we hit the margin target?” leaders can ask questions that force clarity:
- Where is contribution margin being destroyed: price, material, labor, or overhead behavior?
- Which SKUs/customers consume constrained capacity but contribute the least value?
- Which operational improvements move the most contribution per constrained hour?
- What portion of the margin plan depends on improvements we have not yet made – and how will we measure progress weekly?
Strategic Value Creation From the Start
You don’t spring the private equity margin trap by pushing harder on price. You spring it by giving finance and operations a shared, contribution-margin view of reality – current enough to matter, clear enough to act on, and grounded enough to be trusted.
When contribution margin becomes the operating language, operational excellence stops being “efficiency theater” and becomes value creation.
CrossCountry Consulting helps sponsors and portfolio companies overcome the margin trap by restoring clear, actionable margin insight. Connecting SKU‑ and customer‑level economics to operational KPIs and working capital helps teams move from reactive financial analysis to proactive decisions that drive sustained improvements in margin and cash flow.
Contact CrossCountry Consulting to get started.
With audit season occupying so much time for financial reporting and audit teams, it’s easy to lose momentum after audits wrap up. But planning for a strategic, successful debrief is imperative. By making the most of this valuable opportunity, the post-audit debrief can be a productive, transformative exercise for the future, rather than just a review of past results.
Today’s Audit Progress Is Tomorrow’s Audit Efficiency
Even the most meticulous audits can benefit from a debrief. The best debriefs happen soon after the audit is completed, when pain points and ideas for future efficiencies are top of mind for everyone. Plus, a timely debrief allows financial reporting and audit teams to make investments over the traditionally slower summer months.
This time of reflection, ideally conducted between both internal management and your external audit team, allows you to identify areas for improvement and implement the types of technology and workflows needed to proactively avoid and address audit issues.
Using this time wisely can look differently for every organization. In addition to working through audit findings and implementing remediations, management teams should do the following:
- Gather feedback from all levels involved in the audit. Create an open and honest environment that allows everyone involved in the audit to provide their point of view. What worked? What didn’t? Take extensive notes and ask questions to understand the root cause of the issues. Analyze the volume, timing, duplication, and clarity of PBC requests. Streamlining requests and aligning them to the close calendar can significantly reduce audit fatigue and rework.
- Identify themes. Inefficiencies in an audit can typically be narrowed down to a few key themes. Are there communication issues that would benefit from a clearly defined schedule or standing status calls? Do certain processes or departments need dedicated attention?
- Develop an action plan. What are some of the top change priorities in the next several months? Who should own specific responsibilities and tasks moving forward? What are some benchmarks and milestones you’d like to achieve ahead of the next audit cycle? Make a plan with clear ownership, and then hold all parties accountable.
In our experience, here are three highly effective ways to capitalize on this phase of the audit journey:
1. Focus on Technology-Enabled Enhancements
As audit firms look to improve audit quality and efficiency amid rising regulatory scrutiny, there’s immense opportunity for management teams to proactively implement a modern data architecture to help achieve those very goals. While there’s obvious appetite for better use of technology in the audit process, it all starts with the quality of data. Adding more cloud-based systems or automation tools without addressing data concerns will add more IT bloat and potentially create more challenges.
To start, consider the source systems and flows of data. Tools like Snowflake can simplify data architectures and create a clean foundation for automating inefficient audit workflows and data compilation while maintaining traceability. Other platforms, like AuditBoard and Workiva, can help automate, visualize, and manage audit processes and enable decision-makers to surface risks before they reach the level of a deficiency.
Incorporate AI-Enabled Support
Many organizations are also now piloting GenAI and advanced analytics tools to accelerate audit readiness. These tools can help summarize supporting documentation, identify anomalies in large datasets, track PBC requests, and draft variance explanations.
During the debrief, teams should evaluate where AI reduced manual effort, where outputs required significant review, and what governance controls are needed (documentation standards, model validation, access controls) before expanding use in the next audit cycle.
By reducing reporting timelines now and going through several test runs of new technology-enabled reporting or audit workflows, the audit process at year-end can be less siloed, more flexible, and more enjoyable. Plus, the labor and time savings can help ease bandwidth and burnout concerns.
2. Implement a Control Rationalization Program
It’s often the case that, over time, auditors may recommend additional controls to be implemented. Sometimes, it’s healthy to step back and reassess the entire control environment to ensure the continual addition of controls isn’t causing more problems than it’s solving.
Control rationalization streamlines and validates controls to remove redundancies, overhead, and outdated frameworks. Building a rationalized control structure is a one-time investment that can save time in perpetuity for every future audit cycle – and the post-audit filing period is a prime opportunity to execute on this investment since tangible rewards will become evident in a matter of months and there’s more bandwidth to work on a project like this sooner versus later.
Rationalizing controls isn’t just a matter of adding or subtracting controls where necessary. It’s critical to deeply understand the process and risks of material misstatement, and then consider the types of controls necessary and how they can be organized more effectively and with less effort. For example, increasing your reliance on IT controls can reduce reliance on a number of manual controls; however, close attention must be paid to IT general controls.
Control rationalization will ultimately save labor and time in the long run but necessitates an investment today, along with proper implementation, training, and change management for maximum effect. Additionally, organizations should consider whether controls adequately address emerging risk areas such as cybersecurity, third-party/vendor oversight, and nonfinancial reporting processes (e.g., ESG metrics). These areas are increasingly reviewed by auditors and regulators and may require new or enhanced controls.
3. Conduct Interim Testing
In an audit, when you do the work matters. If aspirational audit projects from the summer are backlogged indefinitely, these tasks will only add to the mounting pile of work to complete during the end of the year. When optimizing the audit experience, the work should start months in advance of crunch time. While this may be standard for public companies with robust audit support, private companies may need to place added emphasis on a fast start, especially if this is their first time working this way.
Interim testing is a good practice for every firm to adopt. By evaluating and testing the company’s controls in advance, teams gain early insights into the effectiveness of the control environment.
This allows internal staff to potentially detect early control deficiencies and take corrective action before the actual audit. It also means, ideally, that auditors can spend less time doing detailed transaction testing at a later date, further reducing the risk of misstatements and improving the audit experience.
As David Moore, Co-Founder and CFO of MidCap Financial, noted in the video, it’s important to work with a strategic audit advisor on key projects to understand the latest thinking in the accounting industry, which can enhance audit process efficiency internally and when approaching external audit partners at a later date.
Interim testing requires both management and the audit team to plan in advance, which may include acceleration of certain processes and reallocating resources on both sides. Dedicated resources and accountability are key to making interim testing worthwhile – and additional external resources may be required to alleviate any internal workload concerns.
Leading organizations are also moving toward continuous control monitoring and rolling testing throughout the year rather than relying solely on traditional interim procedures. This approach distributes workload, reduces year-end pressure, and enables earlier identification of control gaps.
Maintaining Audit Agility
By making some of these enhancements in the coming months, it’s possible to execute every future audit more efficiently and with greater confidence in the outcome. Additionally, as evolving risks and regulations emerge, the tools and processes you put into place today should be adaptable.
When preparing action plans from the debrief, organizations should account for several shifts shaping audit readiness today:
- Expanded use of automation and AI in finance and audit workflows.
- Heightened focus on cybersecurity and data governance controls.
- Increased expectations around ESG and other nonfinancial reporting.
- Ongoing accounting and internal audit talent constraints.
- Hybrid and distributed work environments requiring stronger coordination.
Addressing these factors early can prevent recurring issues and position teams for a more efficient audit next year.
CrossCountry Consulting’s unique position as a technology-enabled audit advisor means our accounting advisory, risk advisory, and business transformation teams work cross-functionally to design, build, and deploy leading technologies that meet the objectives of auditors and management. Our audit specialists speak the language of auditors and take the burden off management teams by driving value at all points in the process before, during, or after an audit – wherever support is needed, we plug in.
To maximize your audit debrief period, contact CrossCountry Consulting.
Across finance organizations, automation and AI have shifted from experimental pilots to a strategic necessity. The leaders making real progress aren’t “doing AI” for its own sake – they’re building fluency, anchoring change in business goals, and starting with targeted, low‑risk processes that show results fast.
When leaders align the three pillars of people, process, and data with the appropriate governance, AI ROI can be visible in days or weeks, not years. To accelerate AI adoption and manage risks along the way, finance teams must evolve to be AI-fluent.
From Noise to Fluency
The most effective finance teams cut through AI hype by building organizational fluency first: a shared understanding of what automation is (and isn’t), how it will be used, and why it matters to the business right now. Fluency lowers resistance to change, encourages experimentation, and clarifies where automation can remove low‑value work so people can focus on higher‑value analysis and decisioning.
Fluency isn’t a one‑time training – it’s an ongoing practice. Leaders who communicate purpose early, invite feedback often, and celebrate quick wins create a durable change curve that outlasts any single tool or project.
Start Small, But Start Now
The best AI and automation programs begin with three to five low‑risk, high‑impact processes (for example, a repetitive reconciliation, a recurring reporting package, or a manual review task). Teams automate it, measure the outcome, and share the story internally to build momentum. This is CrossCountry’s Jumpstart AI methodology, and the approach compounds over time: each small win lowers the barrier for the next wave of improvements, which eventually lead to a larger finance transformation where clusters of agents can be created and deployed across common business processes. See it in action here: Jumpstart AI Adoption in Record-to-Report: A Practical Path for CFOs
In practice, this includes:
- Clear objectives and ROI analysis before technology selection.
- Process mapping to remove inefficiency prior to automation.
- Stakeholder alignment across finance, accounting, IT, and compliance teams.
- Phased rollouts with defined guardrails and KPIs.
What ‘Good’ Looks Like in 2026: People, Process, Data
- People: Upskill teams in analytics and AI literacy, and foster adaptability and critical thinking. Empower front‑line users to learn, test, and propose improvements. Recruit for curiosity and systems thinking as much as for tool‑specific experience.
- Process: Standardize and streamline before you automate. Design for controls, auditability, and compliance from day one. Treat AI projects with the same rigor as ERP or close‑accelerator implementations: objectives, owners, and measurable outcomes.
- Data: Treat the general ledger and subledgers as operational assets, not just reporting repositories. Push for transaction‑level granularity and consistent data models so AI can orchestrate workflows on the front end and surface insights on the back end. Invest in data governance and permissions from the start to reduce risk and speed audits.
Real‑World Momentum: Practical Use Cases
Leaders are already unlocking value by pairing targeted training with pragmatic pilots:
- Close and reconciliation automation: By connecting bank data and the GL, teams are achieving high match rates and substantially faster cycle times, and using AI to propose and refine rules. The human stays in control while throughput and consistency increase.
- Knowledge enablement behind the firewall: Organizations are consolidating SOPs and tribal knowledge into secure, searchable assistants that accelerate onboarding, reduce rework, and protect sensitive data.
- Natural‑language access to structured data: Instead of wrangling spreadsheets and dashboards, teams are asking direct questions of billing, customer care, and finance systems (“Who are our top 10 customers by December billings?”) and getting instant, governed answers.
The throughline: measurable efficiency gains without compromising control. When AI is positioned as an orchestrator – routing, proposing, and enforcing business rules – finance teams free capacity for analysis, business partnering, and scenario planning.
Explore strategic AI solutions that solve real-world problems
Align your AI strategy to business drivers, implement purpose-fit systems, and enable predictive analytics capabilities with the right governance, use cases, and technologies.
Managing Risk Without Slowing Down
Security and privacy concerns are valid and manageable. There are two complementary tracks:
- Enable safe experimentation: Provide enterprise‑licensed tools with clear data‑handling guidance (what’s in‑bounds vs. out‑of‑bounds), plus short “master class” sessions to help teams try, learn, and de‑risk.
- Productionize with governance: When pilots prove value, harden the solution: enforce role‑based access, integrate with source systems via supported connectors, and embed controls/monitoring in the workflow. The right vendor/partner should help make permissions and auditability first‑class citizens.
This balanced approach keeps velocity high while protecting sensitive information and preserving audit trails.
The Payoff: Better Decisions, Faster Scaling
With a clearer data foundation and AI‑assisted workflows, organizations can:
- Accelerate closes and audits with standardized, explainable outputs.
- Improve forecast quality by connecting operational drivers to accounting outcomes.
- Reinvest capacity from manual tasks into pricing, margin, and growth analyses.
- Scale efficiently without linear headcount increases while improving employee engagement by removing repetitive, low‑value work.
The Path Toward Org-Wide AI Fluency
Plan, pilot, and scale automation with confidence:
- Readiness and roadmap: Rapid assessments to prioritize use cases aligned to strategic goals, risk posture, and regulatory requirements.
- Process and control design: Standardize workflows and embed guardrails to ensure audit‑ready outcomes.
- Secure enablement: Stand up governed, behind‑the‑firewall AI capabilities and connect them to your finance tech stack.
- Change leadership: Build fluency with targeted training, communications, and a “start small, scale smart” playbook.
Bottom line: Automation is about progress, not perfection. Start with three to five processes, measure the impact, and build a culture that continuously looks for the next improvements. The organizations that cultivate fluency and align people, process, and data will lead the next wave of finance transformation.
To jumpstart your AI transformation journey, contact CrossCountry Consulting.
Defense programs in 2026 are advancing at unprecedented speed, and government officials continue to press contractors to increase production capacity and deliver more units faster. Networked satellites monitor assets in orbit. Autonomous systems and drones compress development timelines. Supply chains span advanced manufacturing, software, and hardware at scale.
In this environment, automation of back-office processes is no longer optional. As regulated technologies evolve, tolerance for supplier risk, manual controls, and fragmented data is eliminated.
Coupa’s FedRAMP-authorized spend management platform reduces risk by delivering a compliant, scalable way to onboard suppliers quickly, enforce three-way match consistently, and maintain regulatory controls without slowing the business. Manual, error-prone workflows are replaced with validated data, audit-ready records, and end-to-end automation from requisition through invoice, enabling companies to achieve compliance without sacrificing speed or agility.
Today’s Procure-to-Pay
CrossCountry Consulting combines deep experience implementing Coupa with hands-on knowledge of regulatory requirements for companies doing business with the government. Experience navigating FAR, CMMC, DFARS, purchasing system audits, and related requirements is applied during implementation to align procurement and finance operations with scalable, secure processes.
This platform-and-services combination is built for defense organizations that must scale procurement at mission speed while maintaining uncompromising compliance.
What defense leaders gain from modernizing Procure-to-Pay:
- Faster supplier onboarding without compliance tradeoffs.
- Standardized procurement across the business.
- Improved spend management with greater visibility into direct purchases across contracts and indirect spend, and the ability to track purchases by assigned categories.
- Improved cash flow with fewer invoice exceptions.
- Ability to maintain audit-ready documentation in a centralized, controlled repository.
- Better capacity utilization and working capital control from faster procurement and onboarding.
- A FedRAMP-ready foundation that scales with mission growth.
Explore expert Coupa solutions that solve real-world problems
Execute efficient Coupa deployments, enhance procurement and supply chain ROI, and minimize risk with Integration-as-a-Service offerings.
The Secret to Scaling Supply Chains: Automating the Mundane
Hypersonics and autonomous systems can seem easy with elite engineering talent. The ability to match parts to approved vendors, purchase orders, and invoices is where many programs slow down.
Defense innovation depends on controlling risk across suppliers, purchases, and payments. Back-office speed must match the pace of innovation, but speed without control introduces exposure.
Coupa’s FedRAMP-enabled platform allows companies doing business with the government to scale procurement and accounts payable without breaking controls. Integrations with PLM, CAD, MRP, and ERP systems ensure supply chain and manufacturing remain tightly governed while vendor onboarding and invoice matching move from manual to automated. Manual processes become systematic workflows with traceable audit trails, reduced rework, and faster cycle times. Compliance stops being a drag on execution and becomes part of how the mission is delivered.
The Real Bottleneck: Supplier Onboarding
Sometimes it seems easier to design an aircraft than to onboard a new supplier. This critical first step can involve numerous forms, approvals, and validations. Each day a supplier remains stuck in review, production slows, capacity utilization costs rise, and contracts face risk.
Coupa automates supplier onboarding through a single workflow driven by need, sourcing events, or integrated bills of materials. That workflow:
- Standardizes intake for banking, tax forms, and certifications.
- Automates approval routing to eliminate inbox bottlenecks.
- Ensures clear access controls for sensitive data.
- Creates a complete compliance record in one system on day one.
Coupa’s FedRAMP solution keeps data secure while accelerating onboarding timelines. Faster supplier activation directly supports mission execution.
Reducing Exposure by Eliminating Match Errors
Three-way match remains one of the strongest financial controls for companies doing business with the government. When purchase orders, receipts, and invoices align consistently, exceptions shrink, audits run smoother, and confidence in contract compliance increases.
Coupa’s automated FedRAMP solution applies built-in rules and logic that business users can maintain without IT involvement. Common exceptions are handled consistently and with accountability.
Coupa’s automated matching provides government contractors with:
- One version of the truth across purchasing, receiving, and invoicing.
- Fewer disputes and faster payment cycles.
- Reduced manual effort and rework.
- Reports and audit trails to ensure compliance at every step.
Small improvements within AP compound into real operational stability to ensure innovation isn’t slowed down by paper pushing.
Fast-Tracking Procure-to-Pay in Government Contracting: Case Study
CrossCountry’s implementation model, developed from more than 900 Coupa projects, is designed to help clients move quickly while navigating complex compliance requirements.
One of our high-tech defense clients helps companies analyze and act on complex data in high-stakes situations, but internally, they struggled with slow supplier onboarding, frequent AP errors, and compliance challenges. By implementing Coupa’s FedRAMP-authorized platform, the company:
- Cut supplier onboarding time.
- Reduced AP cycle times and disputes.
- Achieved centralized, audit-ready compliance records.
Finance teams shifted focus from paperwork to mission priorities, helping the organization innovate and grow.
Why FedRAMP Matters for Scale
With increased emphasis on cybersecurity compliance, government contractors can’t compromise on security. With FedRAMP authorization, Coupa provides a cloud platform designed for regulated environments and capable of handling covered defense information.
From Day 1, Coupa brings the level of control expected in regulated environments.
- FedRAMP-authorized cloud infrastructure.
- Security roles aligned to data sensitivity and access eligibility.
- A single, auditable record across procurement operations.
For organizations operating at extreme speed, retrofitting security can stall growth. With Coupa, security is foundational rather than reactive.
Getting the Implementation Right
Government contractors operate under different constraints. Governance is rigorous. Risks must be addressed early.
CrossCountry Consulting focuses on the practical details that make automation work in regulated environments, including:
- Matching alignment between Coupa and ERP.
- Clear definition and distinction of direct and indirect purchasing workflows.
- Restricted material rules embedded in process stages.
- Supplier compliance integrated at onboarding.
- Structured change management, RAID discipline, and decision ownership.
What Fast-Growing Contractors Gain
When procurement is automated with the right structure, growth accelerates.
- Suppliers onboard in days, not weeks.
- Audit readiness becomes continuous.
- Working capital improves through faster invoice processing.
- Teams focus on mission priorities instead of administrative work.
The organizations defining the future of defense aren’t waiting for supply chain friction to slow them down. They’re modernizing now, not after they stall.
Coupa provides the platform built for mission speed. CrossCountry Consulting ensures it’s designed to thrive in the realities of government contracting. Contact CrossCountry Consulting today for a Coupa readiness assessment.
The software/system development lifecycle (SDLC) has taken on even greater significance in recent years due to the proliferation of digital tools used in virtually every facet of modern work. Today, finance, accounting, risk, operations, HR, IT, and customer-facing functions, for example, are powered by an ecosystem of cloud-based platforms, automated technologies, and digital assistants.
As a result, system development projects have evolved from isolated IT initiatives into business-critical, compliance-sensitive efforts that impact every corner of the organization. With AI and digital transformation investments accelerating, the stakes for getting system implementations right have never been higher. However, roughly 70% of large-scale transformations fail to achieve their intended outcomes.
The Internal Audit Opportunity
Increasing regulatory demands, especially around SOX compliance, mean that failures can have material impacts on financial reporting and reputation. At the same time, the pace of innovation driven by AI, automation, and new development methodologies creates both opportunity and risk.
Internal audit teams are uniquely positioned to help organizations navigate this complexity. By moving from a traditional, post-mortem assurance role to a proactive, strategic partnership, internal audit can embed risk management and controls throughout the SDLC. To drive better outcomes, reduce surprises, increase business alignment, and provide transparency for senior leadership, internal audit has a critical role to play.
The New SDLC Reality: Rapid Change and Increasing Complexity
Adding value to the SDLC requires a forward-looking approach that anticipates complexity and addresses risk across these essential areas:
- Dynamic tools and technology: Organizations are navigating an expanding ecosystem of technology and tools to support every phase of digital transformation and SDLC initiatives. This environment increases the need for a strong data foundation, centralization, and reporting to deliver meaningful analytics, KPIs, and metrics to key stakeholders.
- AI and automation: Teams are expected to deliver more with less and faster. Automation and AI can accelerate innovation, but they also introduce new risks if control design isn’t keeping pace. To capture value safely, organizations need a clear AI strategy that embeds governance, control design, and ethical considerations into every stage of development.
- Tailored methodologies: The starting point should never be yesterday’s waterfall, agile, or DevOps playbook. It should be a deliberate decision informed by governance, risk, and value realization. By treating methodology as a strategic choice rather than a default, companies can ensure that technology investments drive transformation outcomes, not just project completion.
- Third-party risk: Whether you’re leveraging external tools to build or implement purchased software, third-party risk often goes under the radar during project execution. Organizations must move beyond ad-hoc vendor checks and embed third-party risk considerations into an integrated risk management framework. This means assessing vendor security, compliance, and operational resilience alongside internal controls, ensuring that external dependencies don’t compromise project outcomes.
Effective assurance requires aligning technology strategy to business activities within the organization. Controls should be designed and tested to fit the real-world process, not just the theoretical model.
‘Shift Left’: The Case for Early and Continuous Internal Audit Engagement
The earlier internal audit is involved in the SDLC, the greater the impact. Waiting until implementation means missed opportunities to influence design, governance, and risk mitigation. Internal audit’s value is maximized when it “shifts left,” engaging early and often and becoming a trusted strategic partner to management and the executing teams in risk identification and control implementation. Visualized below are some of the key opportunities and best practices for internal auditors to make a demonstrable impact during each phase of the SDLC:

Elevate the Impact of Your Internal Audit Function
Internal audit’s expanded role in the SDLC is a strategic advantage. By engaging early, embedding controls, and partnering with stakeholders, internal audit can drive project success, strengthen compliance, and deliver measurable business value.
Ready to shift left? Connect with CrossCountry Consulting to learn how your internal audit function can become a true partner in system development.
The Coupa R44 release brings a mix of platform-wide enhancements, procurement efficiencies, and critical security updates that every administrator and power user needs to know. Want to explore all things R44 in more detail? Watch our recent webinar.
And for more information on some of the key changes in R44, CrossCountry Consulting’s Coupa implementation and transformation experts have distilled several to focus on:
Key Dates and Release Waves
Coupa has structured the R44 rollout across three specific waves for production environments.
Production Release Schedule:
- Wave 1: January 16, 2026
- Wave 2: January 23, 2026
- Wave 3: February 6, 2026
Understanding this schedule is vital for ensuring your team has adequate time to test new features in sandboxes before they hit live environments. For enterprise clients with Premier support, Wave Zero (December 8, 2025) offers an early preview in test environments. This “early access” group helps vet features before broader release. For most organizations, however, we recommend targeting Wave 1 for test environments and Wave 3 for production. This strategy provides the longest runway to validate workflows and troubleshoot any potential issues before they impact daily operations.
Maintenance and Daily Updates
Beyond the major release waves, Coupa is more aggressively including features in its maintenance updates. These updates, occurring every two weeks after a major release, often include smaller but impactful features. Additionally, daily updates provide regular bug fixes.
To stay on top of these frequent changes, ensure your user record has the Upgrade Administrator role assigned. This role guarantees you receive direct notifications from the environment regarding when these specific updates will land, complete with links to detailed release notes.
GPG File Transfer Encryption Cipher Deprecation
Security remains a top priority in R44. A critical update in this release involves the deprecation of older, less secure encryption ciphers for GPG file transfers. Starting with the January 2026 release, Coupa will exclusively support AES256 or stronger ciphers.
Why this matters: This change specifically impacts file-based integrations. If your organization relies on older encryption methods for exchanging files with Coupa, those integrations may fail if not updated. Note that this generally does not affect corporate card integrations (like Visa or Mastercard), as those providers typically already adhere to higher security standards. However, for other custom file-based integrations, it’s imperative to verify your encryption settings now to avoid service disruptions.
Explore expert Coupa solutions that solve real-world problems
Execute efficient Coupa deployments, enhance procurement and supply chain ROI, and minimize risk with Integration-as-a-Service offerings.
Multi-Factor Authentication Support
As part of Coupa’s rollout of the Coupa Identity Provider, R44 introduces support for Multi-Factor Authentication (MFA) for users logging in via username and password (Non SSO/SAML login).
While this rollout is managed and currently limited to a small number of customers, it signals a broader shift toward tighter security protocols. Once enabled, users accessing the platform directly will be required to enroll in MFA using applications like Google Authenticator or Microsoft Authenticator. This is distinct from the step-up authentication used for high-risk actions (like changing payment details) and focuses specifically on the initial login process.
Procurement and CSP Enhancements
R44 isn’t just about backend maintenance. It also delivers tangible improvements for procurement teams and suppliers.
Workbench Tasks
New tasks in the Unified Workbench bring visibility to issues that previously required digging into specific tables. You can now resolve Purchase Order transmission failures (both email and cXML) and cXML ASN errors directly from the Workbench. This centralization streamlines troubleshooting and ensures critical documents don’t get stuck in limbo.
AI Suggestions for Requisitions
Building on R43, R44 enhances the “Pending Buyer Action” stage. When enabled, AI can suggest missing field values, such as commodity or contract, based on historical data. This allows buyers to apply updates individually or in bulk, significantly speeding up the requisition approval process without consuming AI credits.
Supplier Portal Controls
For suppliers, R44 introduces tighter controls within the Coupa Supplier Portal (CSP). New permissions allow supplier admins to restrict who can manage payment methods. Additionally, the “Remit-To Address” has been removed as a standalone payment method option during onboarding, forcing a cleaner data structure under Legal Entities. This change reduces confusion and prevents the creation of duplicate or erroneous remit-to records.
Stay Informed
With the pace of updates increasing, proactive management is key.
- Check your wave: If you’re unsure which wave your production environment is assigned to, open a ticket with Coupa support.
- Review integrations: Audit your file-based integrations for compliance with the new encryption standards.
- Enable key features: Many enhancements, such as the Workbench tasks and AI suggestions, are “opt-in” and require configuration in the Company Information setup.
A proactive approach today will prevent disruptions and unlock the full potential of the new release. For hands-on Coupa expertise and maximum value from R44, contact CrossCountry Consulting.
ESG’s New Reality
ESG reporting has shifted from voluntary, narrative-driven disclosures to regulated, data-focused disclosures. New rules, like California’s SB 253 and the EU’s CSRD, along with increased stakeholder scrutiny, now require sustainability information to be complete, consistent, and reliable.
Limited assurance is evolving to the baseline standard for sustainability-related data, providing users with greater confidence in the reported data. This trend is particularly evident in climate-related disclosures. California’s SB 253 mandates large companies to report greenhouse gas emissions (Scopes 1, 2, and 3), with assurance requirements phased in over time, as summarized below.
| GHG Emissions Scope | Reporting Deadline | Assurance Requirement |
|---|---|---|
| Scope 1 (direct) | 20261,2 | – Limited assurance expected by 20273 – Reasonable assurance expected by 2030 |
| Scope 2 (indirect from purchased energy) | 20261,2 | – Limited assurance expected by 20273 – Reasonable assurance expected by 2030 |
| Scope 3 (indirect upstream and downstream across the supply chain) | 2027 | – Without assurance in 2027 – Limited assurance by 2027 |
1As of 2025, and following stakeholder feedback, CARB is proposing a first-year-only reporting deadline of August 10, 2026.
2CARB clarified that entities with fiscal year-ends between January 1, 2026, and February 1, 2026, will report on data from the fiscal year ending in 2026, while entities with fiscal year-ends between February 2, 2026, and December 31, 2026, will report on data from the fiscal year ending in 2025.
3CARB has clarified that it will exercise enforcement discretion for first-year reporting in 2026, meaning companies may submit Scope 1 and Scope 2 emissions data based on the information they already had or were collecting when the enforcement notice was issued, even if that data has not undergone limited assurance.
What Does Limited Assurance Actually Mean?
Limited assurance is a moderate level of confidence provided by an independent assurer over the sustainability-reported data and quality of reporting. In practice, this means the assurer performs targeted procedures such as analytical reviews, interviews, and selective testing to determine whether anything suggests the information is materially misstated.
Unlike reasonable assurance (think: full financial audit), the work is narrower in scope but still requires transparent, well-defined processes. However, “limited” does not mean “light.” Assurance providers still expect structured processes, defensible methodologies, clear ownership, and effective governance, along with clearly documented assumptions, consistent calculation methods, and evidence that management can confidently substantiate how each metric was developed and whether the resulting metrics are reasonable. Although controls are generally not tested during limited assurance, a strong control environment plays a critical role in supporting the completeness and accuracy auditors look for in the reported information.
Essential Steps for Assurance Readiness
With a practical, step-by-step approach, organizations can strengthen assurance readiness. The steps below define a clear path to limited assurance preparation:
1. Clarify Scope and Ownership
Clear roles and scope help prevent reporting errors and increase auditor confidence in ESG oversight.
- Identify which ESG disclosures fall under limited assurance (e.g., GHG emissions, workforce metrics, value-chain data).
- Clearly define boundaries to avoid gaps or ambiguity in what must be reported.
- Assign ownership across sustainability, finance, risk, internal audit, IT, and operations to ensure accountability and active governance.
2. Assess Current Maturity
Early discussions with SMEs and auditors help identify high-risk areas and remediation priorities before formal assurance begins.
- Review current data collection processes for completeness, consistency, and auditability.
- Evaluate existing documentation, calculation methods, assumptions, and controls to understand your true readiness level.
Explore expert ESG Reporting solutions that solve real-world problems
Integrate sustainability reporting best practices and build an ESG framework that meets current and emerging regulatory requirements.
3. Strengthen Governance and Controls
Effective governance frameworks allow ESG information to withstand independent scrutiny.
- Establish formal ESG policies, procedures, process documentation, and oversight mechanisms that mirror the rigor of financial reporting.
- Align ESG controls with SOX-like principles like segregation of duties, documented review and approval processes, evidence retention, and escalation protocols to ensure consistency and reliability.
4. Test, Refine, Prepare
Early testing reduces surprises during the formal assurance engagement and accelerates readiness.
- Conduct mock or dry-run assurance reviews to identify weaknesses early.
- Use findings to develop targeted remediation plans, refine data, enhance documentation, strengthen methodologies, and improve audit trails before auditors arrive.
These four steps establish the foundation for credible, repeatable ESG reporting under assurance. While limited assurance may be the starting point, the disciplines required to achieve it set organizations up for longer-term regulatory resilience, and as ESG reporting matures, limited assurance will eventually evolve into reasonable assurance. By approaching assurance readiness as a journey rather than a one-off exercise, organizations can reduce audit friction, build stakeholder confidence, and position themselves for the increasing scrutiny that lies ahead.
Accelerate Readiness Today
Translating assurance requirements into operational reality is where many organizations encounter complexity. ESG data cuts across functions, systems, and geographies, often without the benefit of mature controls or standardized processes.
CrossCountry Consulting is uniquely positioned to guide organizations through the complexities of ESG assurance readiness. Our team delivers:
- Deep expertise in sustainability, financial reporting, and risk advisory.
- Tailored solutions that meet both regulatory requirements and strategic objectives.
- Targeted training for management and internal teams, fostering ESG awareness and embedding compliance into daily operations.
- Technology enablement for data management and evidence trails, helping automate and streamline ESG processes.
To accelerate your ESG assurance readiness with the partnership of a strategic ally, connect with CrossCountry Consulting.
Sage Intacct is designed to evolve alongside your business. With quarterly product releases and continuous innovation, organizations that actively manage and optimize their Sage Intacct environment consistently realize greater efficiency, stronger reporting, and a higher return on investment.
Yet many organizations still approach Sage Intacct reactively – adopting new features sporadically and relying on legacy configurations that no longer reflect how the business operates. Ensure your Sage Intacct ERP scales with your organization with these best practices:
1. Establish a Quarterly Sage Intacct Release Management Process
Sage delivers new functionality every quarter across financial management, reporting, automation, and integrations. Without a structured review process, valuable enhancements often go unused.
Best practice: Implement a formal quarterly release review that includes:
- Reviewing Sage Intacct release notes relevant to your modules.
- Evaluating new features against current pain points.
- Identifying process, reporting, or automation opportunities.
- Assigning clear ownership for adoption and change management.
Organizations with a defined release management process are better positioned to reduce manual work, avoid unnecessary customizations, and stay aligned with Sage’s product roadmap.
End-to-end Sage Intacct value creation with an expert implementation and advisory partner
Simplify and transform financial management processes, automate key workflows for scale, and generate real-time enterprise insights for faster decision-making.
2. Ensure Your Sage Intacct Configuration Reflects Today’s Business
Most Sage Intacct implementations are designed for a specific moment in time. As companies grow and evolve, the original configuration may no longer support current operational needs.
Common triggers for misalignment include:
- New revenue models or pricing structures.
- Mergers, acquisitions, or new legal entities.
- Increased reporting, audit, or compliance requirements.
- Expanded use of automation and third-party integrations.
Best practice: Periodically reassess whether your chart of accounts, dimensions, workflows, and reports still reflect how the business actually operates, not how it operated at go-live.
3. Define Clear Ownership and Governance for Your ERP
Sage Intacct often sits at the center of finance, operations, and leadership decision-making. Without defined governance, enhancements stall and inefficiencies compound over time.
High-performing organizations clearly define:
- ERP strategy ownership versus day-to-day administration.
- A structured intake and prioritization process for enhancements.
- When to leverage external Sage Intacct advisory support.
Best practice: Treat ERP governance as an ongoing discipline so the platform continues to deliver value as the business scales.
4. Get a Sage Intacct Health Check
Even well-managed environments benefit from an independent review. A Sage Intacct Health Check provides an objective assessment of how effectively your system is configured, utilized, and integrated within the broader business ecosystem.
Best practice: Conduct a Health Check every 2-3 years, or following major events such as:
- Rapid growth or organizational change.
- M&A activity.
- Leadership or strategy shifts.
- Persistent close, reporting, or data challenges.
A comprehensive Sage Intacct Health Check goes beyond core configuration and includes a holistic review of how Sage Intacct supports end-to-end business processes.
This often includes assessing:
- Core configuration and dimensional structure to ensure scalability and reporting flexibility.
- Reporting, dashboards, and data accuracy, including executive and operational visibility.
- Automation opportunities and manual workarounds that impact close, billing, or reconciliations.
- Customizations, integrations, and technical debt, with a focus on long-term maintainability.
- How Sage Intacct interacts with upstream and downstream systems, such as CRM, billing platforms, payroll, AP automation, or data warehouses.
- Cross-system business processes that traverse Sage Intacct, including Order-to-Cash (O2C), Procure-to-Pay (P2P), revenue recognition, and financial close.
In many cases, inefficiencies are not isolated to Sage Intacct itself but arise at the intersections between systems, where data handoffs, ownership, or controls may be unclear or outdated.
The outcome of a Health Check is a prioritized optimization roadmap, helping organizations address immediate risks while positioning Sage Intacct and the surrounding systems to support future growth.
5. Embed a Culture of Continuous Optimization
Organizations that get the most from Sage Intacct view optimization as continuous rather than episodic.
Best practice: High-performing finance teams consistently improve efficiency, strengthen reporting, and avoid costly re-implementations by combining:
- Quarterly release management.
- Intentional ERP governance.
- Periodic Sage Intacct Health Checks.
To integrate the latest best practices in your Sage Intacct environment, contact CrossCountry Consulting.
For decades, the Record-to-Report (R2R) process has been marked by late nights, manual work, and a scramble to finalize financial reporting by month-end. Despite significant investments in ERPs and planning/reporting tools, many accounting and finance teams still wrestle with inefficiencies like lengthy month-end closes, extended budgeting and planning cycles, and financial data that doesn’t provide real-time visibility. The result? An accounting and finance function that’s more reactive than strategic.
Today, a fundamental shift is underway. AI systems, particularly agentic AI, are transforming the R2R process. By moving beyond basic automation to intelligent systems, finance leaders can finally unlock a real-time close, enabling faster turnaround on financial reporting, enhanced compliance, and improved process accuracy.
Ready to optimize financial data management and elevate the role of accounting and finance as a strategic business partner? View CrossCountry Consulting’s latest Field Notes video podcast here:
The Current State of Record to Report: Friction and Fatigue
Traditional R2R cycles are burdened by inefficiencies that bog down financial reporting and delay actionable insights. Accounting and finance teams often spend weeks preparing financial data, reconciling accounts, and ensuring compliance before generating financial statements. Key issues include:
- Batch processing: Financial data is often processed in overnight or mid-month batches, delaying visibility into key financial statements and metrics.
- Reactive reporting: Variance analysis and flux reporting are typically completed after the books are closed – sometimes as late as 20 days post-month-end.
- Manual effort: High volumes of manual journal entries, reconciliations, and adjustments waste time and reduce overall process accuracy.
- Regulatory compliance risks: The reliance on manual processes and disconnected systems increases the risk of errors, non-compliance, and audit complications.
- Skill gaps: Modern financial reporting demands both traditional accounting expertise and data fluency, a combination many teams still lack.
These inefficiencies not only slow down financial reporting but also prevent accounting and finance teams from delivering the timely insights businesses need to make strategic decisions.
AI in Record-to-Report: From Automation to Intelligence
Agentic AI and other AI systems are revolutionizing R2R by automating repetitive tasks and introducing intelligence to financial data analysis. This shift allows accounting and finance teams to focus on strategy, compliance, and accurate, real-time financial and management reporting.
Orchestrating the Budget With AI
Budgeting is one of the most time-consuming parts of the R2R process. But AI systems can significantly reduce this burden by automating data orchestration and preparation. Agentic AI can summarize meetings, generate documentation, and stage financial data sets automatically. This can cut budgeting cycles from 60 to <30 days and improve accuracy by eliminating manual errors.
The Real-Time Close: Fact or Fiction?
The real-time close is rapidly becoming a reality for organizations leveraging AI systems. Instead of waiting for month-end, AI enables continuous monitoring of financial data and reporting in real time.
- Continuous controls: AI systems can flag unapproved transactions or unusual financial entries on day five of the month, rather than waiting until month-end.
- Automated accruals: AI agents can analyze contracts, scrape terms from PDFs, and automatically generate accruals, eliminating delays in financial reporting.
- Instant flux analysis: AI can draft flux explanations as variances occur, allowing teams to focus on reviewing and ensuring compliance rather than generating reports from scratch.
This level of automation and intelligence ensures financial statements are not only accurate but also delivered faster, driving better decision-making.
Enhanced Forecasting and Financial Data Insights
AI systems excel at ingesting diverse data sets, from daily cash flows to market trends, to generate rolling forecasts. While these forecasts may not be perfect immediately, they provide “directionally correct” insights that help CFOs make agile decisions without waiting for finalized financial statements. This capability bridges the gap between historical reporting and forward-looking strategy.
Explore strategic AI solutions that solve real-world problems
Align your AI strategy to business drivers, implement purpose-fit systems, and enable predictive analytics capabilities with the right governance, use cases, and technologies.
The New Finance Skill Set: Storytelling With Financial Data
As automation through AI systems takes over manual tasks, finance professionals are shifting their focus toward interpreting financial data and crafting compelling narratives. The future finance analyst must be both a data storyteller and a strategic thinker.
Key skills include:
- Data literacy: Understanding how to stage and analyze financial data in platforms like Snowflake or Databricks.
- Prompt engineering: Using agentic AI and Large Language Models (LLMs) effectively to generate financial reports and insights.
- Compliance expertise: Ensuring AI-driven processes and financial reporting meet regulatory standards and remain audit-ready.
- User experience: Presenting financial data through dashboards and reports that are easy to understand and act on.
This evolution empowers finance teams to deliver strategic value while maintaining compliance and accuracy in all financial processes.
Getting Started: The ‘Jumpstart’ Approach to AI in Finance
Many CFOs hesitate to adopt AI systems, believing that messy data or immature processes will hinder success. However, perfect data is not required to begin reaping the benefits of AI in R2R. A “Jumpstart” approach can help finance teams integrate AI incrementally:
- Start small: Identify one high-friction process, such as cash flow forecasting or contract review, to automate first.
- Focus on manual efforts: Apply AI systems to transactional tasks while leaving strategic judgment to humans.
- Iterate with existing tools: Many ERP, EPM, and data platforms include built-in AI capabilities that can enhance financial reporting and process efficiency immediately.
- Integrate AI as a coworker: Treat agentic AI like a member of your team, with governance, access controls, and compliance protocols to ensure audit-ready outputs.
This approach allows organizations to build confidence in AI models while delivering tangible improvements in financial reporting and process accuracy.
Embrace the Shift: AI as an Enabler for the Office of the CFO
By introducing automation and intelligence, accounting and finance teams can reduce risk, improve accuracy, and focus on strategic objectives. The real-time close is no longer a dream – it’s a competitive advantage waiting to be realized.
Don’t let perfection hold you back. Start small, build momentum, and see how AI can revolutionize your R2R process, delivering faster, more accurate financial reporting and unlocking the full potential of your financial data. Contact CrossCountry Consulting to get started on your AI transformation journey.
Family offices managing diverse investment portfolios, intricate entity structures, and the sensitive dynamics of generational wealth are limited by traditional, spreadsheet-heavy accounting methods. Every manual process takes time and resources away from strategic decision-making and creates unnecessary risk.
That’s why family offices are modernizing their financial tech stack, moving from outdated systems like QuickBooks to robust platforms like Sage Intacct. CrossCountry Consulting’s Megan Smith recently joined leaders from Sage Intacct, Spyglass Capital, and Scott Holdings to discuss how family offices are approaching this transition and the value they’re generating along the way.
View the on-demand webinar here:
Navigate Complexity With Confidence
Sage Intacct empowers family offices with real-time visibility, automated consolidations, and key systems integrations. This enables investors and managers to transform the finance function from reactive cost center to proactive strategic partner, providing clarity in a world of complexity.
The true power of Sage Intacct lies in its ability to handle complicated ownership structures and sophisticated reporting requirements.
As a multi-entity, cloud-based accounting solution that scales with organizational growth, Sage Intacct offers dimensional reporting, which allows for granular analysis across various metrics, family members, and trusts. This flexibility is crucial for family offices that often manage dozens, or even hundreds, of entities.
“We actually have 151 entities on the platform today,” noted Keith Varney, CFO at Scott Holdings, on transitioning to Sage Intacct. “We have saved so much time in this process of being able to come up with an allocation method to take the complex ownership structures that are in place and get these results each month, and we’ve cut down significantly our time in our closing process.”
Handling this volume in a system like QuickBooks involves tedious, error-prone manual work. With Sage Intacct, the process is streamlined into a single login, providing access to all entities and automating intercompany transactions.
Modernizing Your Financial Tech Stack
Implementing a solution like Sage Intacct is more than a software upgrade; it’s a fundamental transformation of financial operations. The benefits are immediate and far-reaching, enabling a new level of strategic insight and operational efficiency.
Gain Real-Time Visibility
The most significant advantage of a modern financial platform is access to real-time data. Dashboards in Sage Intacct can be customized to provide key stakeholders – from the CEO to trustees – with instant visibility into the metrics that matter most.
Kristen Brugos, Director of Accounting and Finance at Spyglass Capital, highlights this benefit: “Our CEO actually logs into Sage and looks at the different dashboards. I’ve also created a profits interest dashboard. Previously, that was all done in Excel.” This shift empowers leadership with the confidence that they’re making decisions based on accurate, up-to-the-minute information.
Automate Complex Consolidations
Family offices often deal with layered ownership structures that make consolidations a nightmare in spreadsheets. Sage Intacct’s Advanced Ownership Consolidations and Dynamic Allocations modules are purpose-built to automate these complex processes. This automation saves time and significantly improves the accuracy of financial reporting, which is critical to fulfilling fiduciary responsibilities.
Create an Integrated Technology Ecosystem
An effective financial tech stack operates as a connected ecosystem, not a collection of siloed applications. Sage Intacct is built with an open API, allowing seamless integration with other critical systems like investment management software (e.g., Addepar), bill pay solutions (e.g., Bill.com), and document management platforms (e.g., SharePoint).
This integration eliminates redundant data entry and creates a single source of truth for financial data. The result is a more efficient workflow and more reliable reporting, which enhances collaboration with external partners like auditors and tax providers.
The Path to Financial Clarity
Modernizing your family office’s financial operations with Sage Intacct provides the tools necessary to manage complexity, drive efficiency, and deliver strategic value. The ability to automate processes, gain real-time visibility, and create a connected tech stack transforms the finance function, allowing you to focus on growth and strategy rather than manual data entry.
With a dedicated practice of Sage Intacct implementation experts, CrossCountry Consulting helps family offices maximize the value of their investment and achieve strategic objectives. To get started, contact us today.
Are you still managing multi-tiered ownership structures, intercompany eliminations, and partnership payouts with spreadsheets and manual calculations? For family offices contending with increasing complexity in their entity structures, the traditional approach to partnership accounting is inefficient and a strategic liability.
To navigate multi-generational wealth structures, private equity investments, and evolving regulatory requirements, leaders are turning to Sage Intacct, which offers the ability to accurately and efficiently allocate partnership income.
To remain ahead of the complexity curve, how effectively can you modernize allocation processes and implement scalable systems?
The Partnership Accounting Challenge: Beyond Traditional Methods
Consider this typical scenario: A family office manages 15 different partnership entities across three generations, with ownership percentages that change quarterly based on new investments and distributions. Each entity generates income from multiple sources – rental properties, private equity investments, and liquid securities – all requiring precise allocation to partners with varying ownership stakes.
The traditional approach of manual calculations and static allocation methods breaks down quickly. More concerning, it introduces significant risk exposure through calculation errors and compliance gaps that can have material financial and reputational consequences.
Strategic Framework: 3 Pathways to Allocation Excellence
1. Transaction-Level Allocation: The Foundation Strategy
Transaction allocation serves as the cornerstone for partnerships with stable ownership structures. This method applies allocation percentages at the individual transaction level, making it ideal for entities where ownership changes infrequently and transparency is paramount.
Strategic Applications:
- Single-tier partnerships with consistent ownership.
- Real estate ventures with fixed partner percentages.
- Investment vehicles with established profit-sharing agreements.
Key Benefits:
- Complete audit trail for every allocated transaction.
- Real-time visibility into partner distributions.
- No additional licensing costs (part of core ERP functionality).
End-to-end Sage Intacct value creation with an expert implementation and advisory partner
Simplify and transform financial management processes, automate key workflows for scale, and generate real-time enterprise insights for faster decision-making.
2. Dynamic Allocation: The Scalable Solution
For organizations managing multi-tier structures with frequently changing ownership percentages, dynamic allocation provides the automation and flexibility necessary to maintain accuracy while reducing administrative burden.
This advanced approach enables CFOs to establish allocation rules based on various criteria – statistical accounts tracking ownership percentages, fair market value calculations, or financial account balances – and automatically apply these rules across multiple entities and time periods.
Strategic Applications:
- Multi-generational family office structures.
- Private equity funds with diverse investor bases.
- Partnership entities with quarterly ownership adjustments.
Key Benefits:
- Automated journal entry generation with full audit trails.
- User-defined books for allocation tracking are separate from operational accounting.
- Batch processing capabilities for multiple partnerships simultaneously.
- Real-time validation and error checking.
3. Advanced Ownership Consolidations: The Reporting Revolution
Advanced ownership consolidations address the critical need for comprehensive wealth reporting across complex entity structures where partial ownership interests create consolidation challenges.
This functionality enables family offices to generate accurate net worth statements that reflect proportional ownership across multiple tiers of entities, providing the strategic visibility required for wealth planning and investment decision-making.
Strategic Value Propositions:
- Complete family wealth visibility across all entity levels.
- Accurate proportional consolidation for minority interests.
- Automated validation and reconciliation processes.
- Enhanced due diligence capabilities for external stakeholders.
Implementation Strategy: Aligning Technology with Business Requirements
Assessment Framework
The selection of appropriate allocation methodologies requires careful analysis of your organization’s specific requirements:
Complexity Indicators:
- Number of partnership entities under management.
- Frequency of ownership percentage changes.
- Reporting requirements for external stakeholders.
- Volume of transactions requiring allocation.
Strategic Considerations:
- Growth trajectory and anticipated entity additions.
- Regulatory compliance requirements.
- Integration needs with existing systems.
- Resource allocation for implementation and maintenance.
Best Practices for Implementation Success
Phase 1: Foundation Building
Establish clear entity structures within your ERP system, ensuring proper dimension setup for partners, investments, and allocation tracking. This foundation work is critical for all subsequent allocation processes.
Phase 2: Allocation Rule Configuration
Develop and test allocation definitions based on your partnership agreements and ownership structures. Utilize statistical accounts for tracking ownership percentages that change over time.
Phase 3: Process Automation
Implement automated workflows for periodic allocation processing, whether monthly, quarterly, or annually. Build in validation checkpoints to ensure accuracy before posting allocation entries.
Phase 4: Reporting Integration
Configure reporting tools to provide clear visibility into allocation results, partner equity balances, and distribution requirements. Ensure reports support both internal management needs and external stakeholder communications.
Technology Integration: Maximizing Efficiency Through Automation
Modern partnership accounting extends beyond standalone ERP functionality to encompass integrated ecosystems that automate data flow from investment management systems, custodial platforms, and external data sources. Middleware tools, such as KnowLedger, leverage Sage Intacct’s open API to integrate investment data to enable streamlined, high-level reporting directly within your ERP system.
KnowLedger Integration Capabilities:
- Automated transaction import from investment management systems.
- Real-time application of allocation rules to incoming transactions.
- Consolidated journal entry creation with full allocation detail.
- Exception handling and validation processes.
This integration approach eliminates manual data entry, reduces processing time, and ensures consistent application of allocation rules across all partnership entities.
Risk Management: Ensuring Accuracy and Compliance
Audit Trail Requirements
Modern allocation systems must provide comprehensive audit capabilities that trace every allocation from source transaction through final partner distribution. This includes:
- Complete transaction lineage documentation.
- Allocation calculation validation and verification.
- Partner notification and approval workflows.
- Regulatory reporting compliance features.
Error Prevention and Detection
Automated validation processes should include:
- Mathematical accuracy verification for all allocations.
- Ownership percentage reconciliation against legal documents.
- Distribution calculation validation before processing.
- Exception reporting for transactions requiring manual review.
The Strategic Imperative: Future-Proofing Your Partnership Accounting
As partnership structures continue to evolve and regulatory requirements increase, the organizations that thrive will be those that have invested in scalable, automated allocation systems.
Key Success Metrics:
- Reduction in month-end close time for partnership entities.
- Elimination of allocation calculation errors.
- Improved partner satisfaction through timely and accurate reporting.
- Enhanced audit readiness and compliance confidence.
- Scalability to support organizational growth without proportional resource increases.
Taking Action: Your Path to Allocation Excellence
Ready to transform your partnership accounting processes and eliminate the risks of manual allocation methods? Discover how Sage Intacct’s comprehensive allocation capabilities can streamline your operations while ensuring accuracy and compliance. Contact CrossCountry Consulting to learn more.
The private lending and private credit industry has experienced rapid growth as institutional investors and borrowers seek alternatives to traditional bank financing. Within this market, collateral underpins lending structures, acting as both a risk mitigant and a liquidity enhancer. However, the bespoke nature of private credit transactions introduces challenges that require robust collateral management frameworks.
This sentiment has been reinforced with major investment by a number of leading banking institutions all participating in the HQLAx collateral mobility initiative, which seeks to improve the speed and accuracy of collateral management, while reducing costs and risks – risks that have driven the demise of First Brands and Tricolor.
With collateral being the foundation of most lending structures, effective management in private credit and lending provides the strategic function that protects lenders, enhances investor confidence, and supports long-term portfolio growth. Given the bespoke and often illiquid nature of collateral in this space, collateral plays a crucial role in protecting investors, enhancing transparency, and supporting portfolio resilience.
The Management of Collateral in Private Lending and Credit
With the U.S. Lending Market amounting to $12.5 trillion and growing 2-3% annually, the industry’s requirement for effective collateral management has become a key requisite for success.
Not only does effective management form an integral part of treasury and liquidity functions, but having a robust collateral platform can deliver significant enhancements to businesses’ compliance in adhering to collateral-related regulations (e.g., FR 2052a and Regulation YY (12 CFR part 252)).
Challenges in Collateral Management
The nature of transactions within private lending and private credit are highly nuanced and negotiated. As a result, effective collateral management presents great challenges in accurately allowing a business to monitor the performance of its portfolio and its underlying assets. This in turn can present operational and financial risks for the business:
- Valuation and monitoring: Illiquid or bespoke assets are difficult to value accurately, and market shifts can erode protection quickly.
- Operational risks: Manual processes and fragmented systems increase the risk of oversight.
- Transparency limitations: Investors and stakeholders often lack visibility compared to traditional markets.
- Poor deal structures: Poor understanding of collateral can lead to unfavorable loan terms and expose organizations to deal risk from the inception of the transaction.
- Increased recoverability risk: Without an effective way to evaluate collateralized assets, significant risks around viability and recoverability of the transaction are introduced.
- Ineffective analysis capabilities: The inability to analyze and monitor the performance of collateral means businesses can’t perform the necessary scenario modeling or anticipate the need to trigger their margin call.
Why Effective Collateral Management Matters
Optimizing collateral is fundamental for liquidity, capital, return, cost reduction, and risk management. By prioritizing effective collateral management, business lending operations can significantly improve:
- Risk mitigation: Protect lenders and investors against borrower defaults.
- Investor confidence: Strong governance and transparency are essential for institutional capital.
- Liquidity and flexibility: Well-structured collateral supports refinancing and secondary financing.
- Regulatory alignment: As scrutiny grows, lenders must adopt practices aligned with evolving compliance requirements.
- Performance enhancement: Proper oversight improves recovery rates and portfolio resilience.
Best Practices for Collateral Management
As market complexity, asset diversity, and cross-jurisdictional exposures increase, institutions must adopt robust frameworks that balance operational efficiency with transparency and legal certainty. The following best practices outline a comprehensive approach to strengthening collateral governance, enhancing asset quality oversight, and safeguarding financial stability throughout the collateral lifecycle.
Standardized Valuation and Reassessment
Implement consistent valuation methodologies across all asset classes and conduct periodic reassessments. For illiquid or complex assets, incorporate third-party appraisals and scenario-based valuation models to ensure precision, transparency, and comparability.
Risk-Based Haircuts and Margining
Adopt haircut and margining frameworks that reflect each asset’s volatility, liquidity, and credit profile. Thresholds and margins should be dynamically adjusted in response to changing market conditions, borrower behavior, and asset performance metrics.
Covenant Monitoring and Additional Trigger Events (ATEs)
Continuously monitor financial covenants and define ATEs – such as management turnover, reputational issues, or repeated margin calls – to trigger proactive margining, collateral reassessment, or escalation procedures.
Legal Enforceability and Jurisdictional Mapping
Conduct comprehensive legal due diligence to confirm collateral enforceability across jurisdictions. Employ clear lien structures, perfected security interests, and escrow mechanisms to strengthen legal certainty and recovery potential.
Collateral Liquidity Scoring
Assign quantitative liquidity scores based on factors such as time-to-liquidation, bid-ask spreads, and historical trading activity. These scores should guide collateral eligibility decisions and inform liquidation strategies.
Stress Testing and Value-at-Risk (VaR) Modeling
Perform regular stress tests and VaR analyses to evaluate collateral resilience under extreme but plausible market conditions, helping identify vulnerabilities and capital adequacy requirements.
Collateral Substitution and Cross-Collateralization Protocols
Enable controlled asset substitutions and structured cross-collateralization to mitigate concentration risk, enhance flexibility, and improve overall portfolio recoverability.
Custodial Oversight and Counterparty Risk Assessment
Assess custodians’ operational robustness, legal status, and creditworthiness. Recognize and manage custodian-related risks, as these can significantly influence collateral protection and recovery outcomes.
Collateral Lifecycle Auditing
Ensure complete traceability of collateral from onboarding through release. Comprehensive lifecycle records support transparency, dispute resolution, compliance verification, and audit readiness.
Technology as an Enabler
With the use of collateral engines, either in existing platforms such as Oxane and Broadridge CollateralPro, or the internal development of bespoke solutions, companies can identify opportunities to optimize collateral. To capitalize on the full benefits of these tools, companies must prioritize modeling efforts, validation of clean data, and streamlining business processes.
AI, as one example, can significantly enhance the automation of collateral management in private lending by streamlining valuation, monitoring, and risk assessment processes. Machine learning models can continuously reassess asset values, detect early warning signals, and recommend margin adjustments based on real-time market data. Additionally, AI-driven document processing and smart contract systems can automate collateral onboarding, verification, and release, reducing operational friction and improving accuracy across the collateral lifecycle.
Provided the aforementioned is achieved, technology will play a central role in modernizing collateral management and supporting key outcomes, such as:
- Real-time monitoring and optimization: Enables dynamic tracking of asset values, exposures, and margin thresholds, which allows entities to optimize their collateral.
- Centralized data management: Improves transparency, reduces operational risk, and supports audit readiness.
- Compliance and controls: Flags regulatory breaches and enforces policy adherence automatically.
- Integration with custodians: Facilitates secure asset handling and real-time reconciliation with third-party custodians.
- AI-leveraged automation: Streamlines operational workflows such as valuation, margin calls, substitutions, and reporting (e.g., activating AI capabilities within existing platforms such as Copilot, ChatGPT, etc.)
By combining disciplined risk management with smart technology, institutions can transform collateral management from a back-office function into a strategic advantage, driving portfolio growth, enhancing efficiency, and protecting lenders.
How CrossCountry Can Help
CrossCountry Consulting delivers tailored collateral management solutions to overcome common industry challenges.
In-House Platform Design and Integration
Design and implement in-house collateral management solutions with centralized document capabilities, while overseeing large-scale projects, integrating client systems into custom technology architectures, and managing end-to-end delivery from testing through post–go-live support.
Vendor Implementation
Lead the selection and implementation of vendor solutions, ensuring seamless integration with existing systems and business architecture, while coordinating across functions and managing testing, go-live, and post-implementation support.
Operating Model Frameworks
Develop and operationalize business frameworks – including SOPs, risk controls, and process flows – while defining roles and responsibilities and executing change management programs to drive adoption of the target operating model.
Business Analytics and Scenario Modeling
Build dynamic dashboards and custom reporting tools that enable users to simulate market scenarios, analyze risk, and review performance, while implementing security controls for customized, role-based access.
Reporting and Compliance
Develop business and regulatory reporting capabilities, including compliance with industry standards (e.g., 2052a, FRB, Regulation YY), and enhanced document management systems that improve visibility into counterparty compliance, liquidity, and debt covenant monitoring.
Collateral management is not an administrative afterthought – it’s a core function that determines portfolio performance, investor trust, and the long-term credibility of the private lending industry. Lenders and credit managers must prioritize frameworks, adopt technology, and embrace transparency to ensure sustainable growth in 2026 and beyond. To get started, contact CrossCountry Consulting.
The final Sage Intacct release of 2025, R4, delivers a powerful suite of enhancements designed to accelerate financial close, strengthen data integrity, and boost team efficiency – critical factors as we head into year-end planning.
This release focuses on smarter automation, faster reconciliation, and more flexible reporting across key modules. Ready to maximize the value Sage Intacct can deliver to your business? View our demo of key updates:
Training and Collaboration Enhancements
The Help Center now features an expanded, easy-to-search video library, offering both short-form guides for quick fixes and longer-form tutorials. This is an ideal resource for onboarding new team members and supporting ongoing education. Additionally, Sage Collaborate officially replaces Intacct Collaborate in November 2025. While the interface remains familiar, this update is a strategic foundation for future communication and feature enhancements.
Import Service Upgrades
Users can now update key dimension IDs – including GL accounts, classes, and vendors – via the new Import Service. This eliminates the need for manual workarounds for simple ID changes. The new Import Service provides a massive time-saver by allowing for real-time error handling and fixing import issues directly within the import interface without needing to re-upload the file multiple times.
Cash Management Improvements
A major update allows users to combine debits and credits in reconciliation matching rules. This is particularly useful for transactions split between a main payment and an associated fee (like bank charges), enabling a much higher rate of accurate and automated bank reconciliations.
1099 Tax Reporting Updates
Ensure compliance ahead of the 1099 season with necessary form adjustments. Sage Intacct has implemented the IRS change moving Golden Parachute Payments from Box 14 to Box 3 on the 1099-NEC form. Also, to ensure proper printing and compliance, entity-specific 1099s now require an assigned contact with a valid address. This simple check prevents common printing and mailing errors.
Accounts Payable and AP Automation
Gain better control and traceability over vendor activity and payment processing. The AP Ledger report now supports multi-vendor filtering and custom vendor groups, significantly enhancing your reporting flexibility for focused analysis on specific vendors. Additionally, the introduction of unique payment IDs for AP advances improves financial traceability across reports, making it easier to reference and track prepayments. Also, AP automation benefits from a new email domain (@AISage.com), facilitating highly requested features like setting up auto-forwarding, receiving bounce-back notifications, and supporting expanded file formats.
Accounts Receivable Enhancements
Customer statements now offer more granular transaction filtering options. Users can tailor statements to show all transactions, only open invoices, or show invoices with associated credits providing greater clarity and customization to your customers.
Fixed Asset Management and General Ledger
Reduce manual entries with Sage Fixed Assets Management (SFAM) and gain deeper visibility into your financial status. Users can now partially dispose of assets, create multiple assets from a single bill line, or skip asset creation. Dimension edits no longer require asset transfers within the same entity, eliminating unnecessary journal entries. In addition, the General Ledger report now includes unposted transactions and a new “Transaction State” column. This provides immediate, real-time visibility into draft and adjusting entries, significantly aiding your close process.
Contracts, Purchasing, and Consolidations
Contract renewal management is now more efficient, benefiting from automated bulk actions and new tracking reports for enhanced visibility into recurring revenue. In Purchasing, you gain greater control and quicker resolution thanks to an exception summary for match tolerances. Furthermore, AP Automation for Purchasing now supports more detailed line-level matching. Finally, for complex corporate structures, Advanced Ownership Consolidation has been expanded to include crucial equity consolidation methods.
Overall, Sage Intacct R4 delivers meaningful improvements that enhance efficiency, accuracy, and user control across financial operations. CrossCountry Consulting’s Sage Intacct implementation experts can help you capitalize on the latest updates to maximize your investment. Contact us today to get started.
While institutional investors have long dominated the alternatives landscape, a fundamental shift is underway as leading asset management firms recognize the untapped potential of high-net-worth individuals and family offices.
Alternative investments currently account for less than 3% of high-net-worth individual portfolios, yet industry projections suggest this allocation could expand dramatically over the next decade. This presents a compelling opportunity for asset managers willing to adapt their infrastructure, products, and go-to-market strategies for the private wealth sector.
The transformation extends beyond simply creating new products – it requires a comprehensive reimagining of operations, technology, compliance frameworks, and client service models.
The Strategic Imperative for Private Wealth Expansion
Several market forces are converging to make this expansion necessary for long-term competitiveness:
- Massive market opportunity: The global high-net-worth individual population holds combined assets of approximately $90.5 trillion. Meanwhile, the mass-affluent segment represents roughly $21 trillion in assets, with 80% having never worked with a financial planner, creating a significant greenfield opportunity for scalable wealth management services.
- Structural market changes: Recent regulatory developments are opening 401(k) and retirement plans to private market strategies, potentially unlocking a $10 trillion defined contribution market. The traditional 60/40 portfolio model faces increasing challenges as public markets become more concentrated and correlation increases during market stress. Owning competitive advantages in both institutional and individual markets enhances market positioning.
- Revenue model advantages: Private wealth offers asset managers the opportunity for more predictable, fee-based revenue streams compared to traditional carry structures. This recurring revenue model provides stability and can boost firm valuations. Additionally, with 84% of wealth managers expecting alternative allocations to rise over the next 12 months, the demand-side momentum is clearly building.
By capitalizing on these opportunities, asset managers can devote more resources toward individualized relationships that can lead to higher client lifetime value and increased referral opportunities.
Industry Leaders Setting the Standard
The top alternative asset managers have moved aggressively into private wealth, each taking distinct approaches based on their strengths and target markets.
- Top-tier firms (>$100B AUM) have established dedicated private wealth platforms designed to serve individual investors directly while maintaining institutional-grade investment quality.
- Mid-tier managers ($50-$100B AUM) are pursuing acquisition strategies, creating business development companies (BDCs), and offering private credit products for high-net-worth individuals.
- Smaller managers (<$50B AUM) are forming strategic partnerships to access established distribution networks without building comprehensive in-house capabilities.
Infrastructure Requirements
Successfully entering private wealth requires addressing six critical areas, each presenting both obvious needs and potential blind spots.

1. Product and Service Design
While product adaptation seems straightforward, the real challenge lies in understanding the distinct needs of individual investors versus institutions. Entrepreneurs seek liquidity and growth opportunities, family offices prioritize legacy and governance structures, and retirees focus on income generation and capital preservation.
The key is developing tailored offerings that address these distinct client personas while maintaining operational efficiency. This might include concepts such as hybrid portfolios for diversification, BDCs for high dividend yields, trust structures for estate planning optimization, and product wrappers like interval, evergreen, and tender offer funds.
2. Distribution and Strategic Partnerships
Selecting optimal distribution channels requires balancing control with reach. Direct-to-client models offer brand consistency but require significant investment in marketing and client acquisition. Partnerships with RIAs, independent broker-dealers, and wirehouses provide access to established client bases but may dilute brand control.
Strategic alliances with custodians, fintechs, and white-label solution providers can accelerate market entry while reducing operational complexity. The most successful firms often pursue a multi-channel approach, tailoring their strategy to different market segments.
3. Operating Model and Technology Enablement
The shift from institutional to retail clients demands fundamental operational changes. Institutional clients typically require quarterly reporting and can tolerate complex onboarding processes. Individual investors expect more real-time access to information, intuitive digital interfaces, and responsive customer service.
Technology infrastructure must support digital onboarding with e-signatures and automated KYC processes, provide secure client portals for reporting and account management, and integrate CRM systems for relationship tracking and segmentation. Many firms underestimate the complexity of building scalable, client-centric operations.
4. Regulatory Compliance and Risk Management
Private wealth introduces new regulatory and licensing requirements, including FINRA and SEC oversight, enhanced AML and KYC procedures, and jurisdiction-specific compliance for cross-border investments. Risk frameworks must be adapted for retail clients, incorporating stress testing and scenario analysis tailored to individual portfolios rather than institutional mandates.
Governance structures become critical, with oversight committees and escalation protocols ensuring appropriate suitability assessments and ongoing client monitoring. Many firms find that their institutional risk management frameworks require significant modification for individual investor protection.
5. Talent and Cultural Transformation
Success in private wealth requires different skill sets than institutional asset management. Teams need professionals with CFP, CFA, and CPA credentials who understand financial planning, estate strategy, and behavioral finance. Equally important is developing soft skills for client interaction and building the high-touch service culture that individual investors expect.
Performance metrics must shift from purely quantitative measures to include client satisfaction and retention indicators, which impact compensation plans. Collaboration becomes essential as clients often require coordinated solutions across investment management, tax planning, and estate strategy.
6. Brand Positioning and Pricing Strategy
Messaging must resonate with individual aspirations while maintaining professional credibility. Pricing strategies should balance perceived value with client preferences, often requiring tiered service models that provide flexibility and scalability (e.g., flat fee, basis points, or subscription). Many firms find that their institutional pricing models don’t translate directly to individual clients, necessitating comprehensive pricing strategy overhauls.
Proactively Addressing Transformation Challenges
Entry into private wealth can be streamlined with the support of an advisor who can help navigate several key workstreams.
- Regulatory compliance represents perhaps the greatest challenge, requiring new licenses, disclosure procedures, and reporting obligations.
- Client education becomes essential as individual investors often need significant guidance to understand alternative investments and their role in portfolio construction.
- Operational complexity increases dramatically when serving individual clients rather than institutional investors. Cost management becomes critical as serving high-net-worth clients requires higher per-client service levels while fees face downward pressure, particularly at higher AUM tiers.
- Technology integration issues are common, as firms must connect institutional-grade investment platforms with retail-oriented client service systems.
Successfully entering private wealth requires a phased approach that builds capabilities while managing risk and complexity.
- Phase 1: Focus on market assessment and product development, understanding target client segments, and adapting existing investment strategies for individual investors. Strategic partnerships with established wealth management platforms can provide valuable market insights while building initial distribution capabilities.
- Phase 2: Develop infrastructure, including technology platform integration, regulatory compliance framework establishment, and initial team hiring. Many firms benefit from pilot programs with select client segments to test operational capabilities and refine service models.
- Phase 3: Execute full market launch with comprehensive marketing strategies, expanded distribution partnerships, and ongoing optimization based on client feedback and market response.
Positioning for Future Growth
The expansion into private wealth is a fundamental transformation that positions asset managers for long-term success in an evolving market landscape. However, success requires commitment to comprehensive infrastructure development, cultural transformation, and ongoing innovation in client service delivery.
The window for competitive advantage in private wealth is narrowing as more firms enter the market. Asset managers who begin their transformation now, with careful planning and phased implementation, will be best positioned to capitalize on this significant growth opportunity.
To execute on a structured transformation roadmap in service of institutional and individual investors, contact CrossCountry Consulting.
Closing the books doesn’t mean you’re ready for an audit. True audit readiness goes beyond financial statements – it ensures internal controls, documentation, and disclosures can withstand scrutiny from auditors and regulators.
Gaps in accounting, controls, or disclosures can lead to restatements, material weaknesses, and regulatory inquiries. Many organizations don’t discover these issues until an audit or regulatory review brings them to light.
As year-end approaches, finance and accounting teams must focus on key areas that drive audit success, including common risks, why they matter, and practical steps to address them before they become costly.
The Regulatory Lens
The Public Company Accounting Oversight Board (PCAOB) and the Securities and Exchange Commission (SEC) are two key bodies that shape the audit and reporting landscape for public companies. Their insights and priorities provide a roadmap for where companies need to focus.
PCAOB Inspections: Persistent Deficiencies
While PCAOB inspections target audit firms, many findings, especially around internal control, stem from client-side weaknesses. Auditors frequently cite poorly designed client controls, insufficient documentation, and incomplete management review evidence as key drivers of recurring deficiencies.
Despite improvements in audit quality, issues persist year after year. From 2022 to 2024, two areas continue to stand out:
- Controls with a review element: Auditors often find client review procedures and supporting evidence lacking, particularly for complex estimates like business combinations or goodwill impairment.
- IT and system-generated data and reports: Reports and data extracted directly from ERP or financial systems aren’t automatically reliable. Auditors expect evidence of completeness and accuracy. Without validation controls, accounting and finance teams risk relying on inaccurate data, a common misconception because these processes feel “automated.”
Featured Insight
SEC Comment Letters: Disclosure Under the Microscope
The SEC reviews filings for compliance and issues comment letters when disclosures are unclear or incomplete. In 2025, the most frequent focus areas include:
- MD&A: Companies often fail to explain why results changed, not just that they changed.
- Non-GAAP measures: Issues with prominence, reconciliations, and misleading adjustments.
- Segment reporting: New ASU 2023-07 rules require disclosure of significant segment expenses and management’s use of reported measures.
- Revenue recognition: Disaggregation and clarity on performance obligations.
- Goodwill and intangibles: Transparency on impairment testing, assumptions, and sensitivity analyses.
- Emerging risks: Cybersecurity, AI, and crypto asset disclosures.
These comments often go beyond presentation. They challenge technical accounting conclusions, such as how revenue is recognized, how segments are defined, or how impairment is assessed. Addressing these areas requires both strong internal controls and robust technical accounting expertise.
Material Weaknesses: The Hidden Risk
Material weaknesses (MWs) remain a growing concern, even for companies not preparing for an IPO. A recent study found that in FY24, 8% of companies disclosed MWs, and 31% had recurring issues across multiple years.
A material weakness occurs when internal controls cannot reasonably prevent or detect a material misstatement. Common causes include inadequate documentation and policies, insufficient accounting expertise, IT and access control gaps, poor segregation of duties, and weak disclosure controls. The most impacted areas are nonroutine or complex transactions such as M&A and restructurings (72%), financial close and reporting processes (31%), and the control environment (48%), which reflects weak oversight and tone at the top. These weaknesses are not just technical; they appear in filings, affect investor confidence, and drive higher audit costs.
Connecting the Dots: How These Issues Intersect
PCAOB findings, SEC comment letters, and material weaknesses share a common thread: technical accounting, internal control, and disclosure quality. Weaknesses in these areas often emerge when processes and accounting judgments fail to keep pace with complexity, growth, or regulatory change.
It’s not just about control. Many SEC comments relate to accounting conclusions, such as revenue recognition, segment reporting, and impairment testing. These areas require both strong documentation and sound technical analysis.
If you’re thinking, “We’ve never had a material weakness, so we’re fine,” consider this: Many companies didn’t know they had issues until auditors identified them.
Explore expert Technical Accounting & Financial Reporting solutions that solve real-world problems
Anticipate, understand, and respond to accounting and reporting changes with agility and accuracy.
Practical Steps for Audit Readiness
Here’s how finance teams can take control:
- Strengthen ICFR design and documentation: Review controls for financial close, revenue, and nonroutine transactions. If using manual spreadsheets, implement documented reviews and version control. Validate IT controls and user access. If AI assists with reconciliations, document oversight and logic checks.
- Enhance disclosure quality: Go beyond boilerplate in MD&A and quantify drivers of change. Instead of “Revenue increased due to demand,” disclose “Revenue grew 12% from a 15% volume increase and 3% price adjustment.” If AI drafts MD&A, ensure human review and compliance checks.
- Resource planning: Confirm your team has expertise for complex areas like business combinations and impairment testing. Engage technical accounting specialists for purchase accounting. AI can assist with valuation modeling or scenario analysis, but finance teams must confirm that AI outputs align with GAAP.
- Focus on high-risk areas: Nonroutine transactions need tailored controls. For business combinations, controls should extend to the valuation specialist calculations. If AI is used to identify anomalies or predict risk areas, document how these insights are incorporated into control design and ensure they don’t replace required manual reviews.
- Prepare for emerging risks: Address cybersecurity and AI in risk assessments and disclosures. Example: If using AI for forecasting, disclose governance policies and validation processes. Regulators expect transparency on AI usage and its financial impact.
How CrossCountry Consulting Can Help
CrossCountry Consulting helps finance teams close gaps before auditors find them, through ICFR readiness assessments, technical accounting support, remediation planning, and guidance on new standards like ASU 2023-07. Our approach is practical, collaborative, and focused on reducing risk while enabling confidence.
Ready to strengthen your audit readiness? Contact us today to get started.
Mainstream maintenance of SAP ERP Central Component (ECC) ends in 2027, with extended support available until 2030. While that might seem like plenty of time to plan your next move, including a potential migration to SAP S/4HANA, the reality is far more urgent than most organizations realize.
With average ERP implementations (bringing in entirely new systems) taking 12-18 months and system migrations (moving from one existing system to another) often extending even longer due to complexity, the clock is already ticking. The tens of thousands of organizations still running on SAP ECC, including a high percentage of Fortune 500 companies, face a critical decision point that will define their technology strategy for the next decade.
The Time Crunch: 2027 Is Closer Than It Appears
System end-of-life (EOL) transitions are deceptively complex undertakings. What appears to be a straightforward technical migration quickly reveals itself as a comprehensive business transformation touching every corner of your organization.
Consider the typical timeline breakdown:
- Strategic planning, budgeting, and system selection: 3-6 months.
- Implementation planning and resource allocation: 2-4 months.
- Core implementation and testing: 12-18 months.
- User training and change management: 3-6 months ongoing.
Even starting today, organizations are looking at implementation windows stretching into 2026 and beyond. Factor in the inevitable scope creep, resource constraints, and integration challenges that plague most ERP projects, and the 2027 deadline becomes a very real constraint.
The Complexity Challenge: Why System EOL Requires Strategic Expertise
EOL system migrations carry unique risks that standard implementations don’t face. Most SAP ECC environments have evolved over 10-15 years, accumulating layers of customizations, integrations, and workarounds that have become mission-critical to daily operations.
These heavily customized systems present several strategic challenges:
- Legacy integration complexity: Years of acquisitions and system additions create interconnected webs that must be carefully untangled and rebuilt.
- Knowledge transfer risks: The institutional knowledge required to understand current system configurations often resides with a small group of employees, creating significant project risk.
- Compliance and control gaps: Existing manual controls and compliance processes may not translate directly to new system architectures, requiring comprehensive redesign.
- Business continuity concerns: Unlike greenfield implementations, EOL migrations must maintain full operational capability throughout the transition.
The Strategic Advantage of Independent Advisory
Most organizations attempt system migrations with internal resources and direct vendor relationships. However, this approach often falls short when facing the strategic complexity of an EOL transition.
The most successful migrations leverage independent implementation advisors who bring several critical advantages:
- Unbiased system selection: Unlike vendors who are incentivized to sell specific solutions, independent advisors can objectively evaluate whether SAP S/4HANA, Oracle Cloud, Workday, or other platforms best align with your strategic requirements.
- Proprietary selection methodologies: Experienced advisors utilize structured evaluation frameworks that consider technical requirements alongside business strategy, implementation complexity, and total cost of ownership.
- System integrator support: Rather than replacing your chosen system integrator, independent advisors work collaboratively to ensure successful project delivery while providing an additional layer of project governance and risk mitigation.
- Cross-platform expertise: With deep knowledge across multiple ERP platforms, independent advisors can identify the best-fit solution for your specific organizational needs and growth trajectory.
Building Your Strategic Roadmap
The first step in any successful SAP migration is developing a comprehensive technology architecture strategy that extends beyond the immediate EOL challenge. This strategic foundation should address:
- Business alignment assessment: Understanding how your technology investments will support broader business objectives over the next 5-10 years.
- Integration architecture planning: Designing a scalable technology ecosystem that can adapt to future acquisitions, divestitures, and business model evolution.
- Risk management framework: Establishing controls and governance structures that will protect your organization throughout the transition and beyond.
- Change management strategy: Building organizational capability to successfully adopt new systems while maintaining operational excellence.
Organizations that invest in this strategic foundation early in the process consistently achieve better outcomes, shorter implementation timelines, and higher user adoption rates.
Taking Action: Your Strategic Next Steps
The window for strategic SAP migration planning is narrowing rapidly. Organizations that begin their evaluation process now will have the luxury of thorough analysis and measured decision-making. Those who delay will find themselves forced into reactive decisions with compressed timelines and limited options.
The most effective approach starts with engaging an independent advisor who can provide unbiased guidance through the complex landscape of modern ERP solutions. This strategic partnership ensures you select the platform best aligned with your business objectives while building the implementation roadmap that delivers maximum value with minimum risk.
Don’t let the 2027 deadline catch your organization unprepared. The time to begin strategic planning is now. Contact CrossCountry Consulting to get started.
For decades, private equity has used financial engineering and cost reduction as primary levers of value creation. More recently, operational transformation and digital enablement became the new playbook. Today, AI represents the next frontier, offering efficiency, growth, and competitive advantage – but also complexity and risk.
For sponsors and their portfolio companies, the question is no longer if AI should be part of the value-creation strategy but how to adopt it responsibly and at scale.
From Deal to Exit: A Picture of AI-Enabled Value Creation
Consider the trajectory of a successful AI-enabled PE deal:
- Deal sourcing and diligence: AI-driven market scans and sentiment analytics reveal a target overlooked by competitors. AI-enabled diligence surfaces revenue drivers, operational risks, and synergies, enabling sharper pricing and accelerated underwriting.
- Post-close transformation: The portfolio company invests in a holistic AI capability model, building data infrastructure, embedding AI into core functions, and cultivating a workforce confident in AI-enabled tools.
- Key transformations include AI-powered forecasting, dynamic pricing, supply chain optimization, and automated finance processes, all governed by a consistent risk and compliance framework.
- Exit and value realization: Over the hold period, revenue accelerates, margins expand, and AI maturity itself becomes a differentiator, with data and AI-enabled processes boosting buyer confidence and valuation multiples.
The result is not just a successful deal, but a repeatable playbook for portfolio-wide advantage.
Laying the Groundwork for Sustainable AI Value Creation
Portfolio companies have different levels of AI maturity. Some are still building basic digital and data capabilities, while others are piloting advanced models. Sponsors must meet each company where it is, while keeping an eye on a future where AI is a core capability.
Holistic AI adoption cannot be solved purely from the top down. Leadership sets the vision and governance, but real value often comes from engaging those closest to the work: line-level staff who know the daily bottlenecks and friction points. Their input ensures AI solutions address real problems, generate practical efficiency gains, and are embraced by those who use them.
Without a roadmap, companies risk “pilot purgatory” – where projects never scale – or creating vendor sprawl that increases cost without impact. Poorly governed AI can also expose companies to reputational, ethical, and regulatory risk.
The lesson: AI adoption is about building capability, with governance, risk awareness, and alignment to value-creation goals driven by insights from leadership and frontline staff.
A Framework for Responsible AI Implementation
CrossCountry Consulting evaluates companies using a simple framework to determine where they are on their AI journey and how they can most effectively execute on an implementation roadmap:

A clear roadmap is critical to ensuring the right foundation is in place and that investment is focused on high-value, scalable initiatives.
A human-centered approach ensures AI solutions are shaped by the actual people who will use them every day. By engaging CFOs, functional leaders, and frontline staff, technology investment aligns with real-world business problems, improving adoption and accelerating impact. This holistic model promotes four key AI capabilities for PE:
- Strategic transformation toward an AI-powered organization: New operating models, innovation hubs, process design, cross-functional command centers, and digital workers.
- AI solutions that solve business challenges: AI use case development, system selection, intelligent AI agent orchestration, and embedded AI for greater organizational insights, predictive modeling, and ROI quantification.
- AI enablement that ensures successful employee adoption: Playbooks, starter packs, templates, training toolkits, and hands-on enablement programs tailored to organizational maturity. This can also include upskilling, certifications, and end-to-end change management.
- Governance, security, and risk for enterprise AI: AI governance frameworks, risk monitoring, cybersecurity assessments, continuous agentic oversight, and compliance with ethical and regulatory standards.
The Next Lever for PE Value Creation
AI is not a plug-and-play solution; it’s a strategic capability that requires intentional investment, governance, and cultural alignment. For PE sponsors, holistic AI deployment is poised to become the next big lever for value creation, much like lean operations or shared services in past decades.
The opportunity is clear: Sponsors who adopt responsible AI practices today will enjoy sustainable competitive advantage, stronger portfolio performance, and potentially higher exit multiples.
Ready to take the next step? Contact CrossCountry Consulting today.
Modern CFOs face unprecedented challenges as they lead organizations through digital transformation, growth initiatives, and complex regulatory landscapes. From accelerating the financial close process to managing risk and AI investments, the demands on financial executives have never been greater. Amid these pressures, organizations often overlook one of their most valuable strategic assets: operational accounting.
Operational Accounting Today
Operational accounting refers to the hands-on, day-to-day management of financial processes such as month-end, quarter-end, and year-end closes, as well as financial controls, reporting, and compliance. But today, operational accounting goes far beyond bookkeeping tasks. It integrates with corporate strategy and other functional areas to optimize processes, provide actionable insights, manage risks, and ultimately empower the Office of the CFO to focus on growth and innovation.
No longer just recording transactions and reconciling accounts, operational accounting has evolved into a strategic function that can drive efficiency, enhance decision-making, and enable competitive advantage when aligned with enterprise goals. An experienced operational accounting partner acts as an extension of companies’ finance teams, serving as a catalyst for transformation and delivering expertise to meet strict audit deadlines, implement new standards, and navigate periods of transition.
Leveraging advanced technologies like AI and automation, operational accounting professionals create an efficient foundation for controllership operations, special CFO projects, project management, systems implementations, and core accounting acceleration.
Overcoming Common Challenges in Finance and Accounting Operations
Operational accountants are uniquely positioned to address many of the key challenges CFOs face, including:
- Complex accounting standards and regulations: Keeping up with changing SEC, PCAOB, EU, and IFRS rules can strain existing processes and resources, leading to reporting errors and compliance risks. With deep backgrounds navigating these requirements, operational accountants serve as trusted advisors to executives, boards, audit partners, tax, legal, and compliance.
- Demand for data-driven decision-making: Organizations must move beyond reactive reporting to provide forward-looking insights that inform strategy, including predictive analytics, dynamic scenario planning, and transaction readiness. Operational accountants sit at the nexus of data and strategy and can help connect the dots between historical financial information and future planning, utilizing expertise in AI and automation tools and technologies.
- Inefficient financial processes: Inefficient workflows, manual tasks, and bottlenecks can stretch close times into weeks, limiting the finance function’s agility. By re-engineering and automating key workflows, operational accountants eliminate close fatigue and increase job satisfaction.
- Technology integration and AI adoption: Integrating new technology, including AI-enabled solutions, requires expertise to ensure smooth implementation and maximize ROI. With expertise in project management, human capital management, and SaaS platforms, operational accountants have the perspective and insights to support technology initiatives.
- Talent development: Upskilling financial staff to be data-savvy and AI-ready is crucial for maintaining efficiency and competitive advantage. As the accounting industry undergoes significant change, professionals with the greatest tech literacy can open up more career opportunities.
How an Operational Accounting Partner Adds Value
Partnering with an experienced operational accounting provider offers specialized benefits that empower the Office of the CFO:
1. Accelerated Financial Close Process
Best-in-class organizations complete the financial close in four days, while many companies take weeks. An operational accounting partner evaluates your current processes, identifies bottlenecks, and implements tailored solutions to streamline workflows and reduce the time-to-close. A faster close enables CFOs to access financial data sooner, empowering them to make timely, informed decisions.
2. Enhanced Reporting Accuracy
Operational accountants bring deep expertise in accounting principles and standards, ensuring compliance and accuracy in financial reporting. They work alongside your internal audit teams to prepare for smoother audits, reduce errors, and enhance credibility with stakeholders.
3. Optimization Through Technology
By leveraging AI and automation, operational accounting professionals eliminate manual errors and inefficiencies, freeing up resources for higher-value tasks. For example:
- AI tools can reduce data entry during the close process. As the market for accounting AI technology is expected to reach $37 billion by 2030 (up from $6 billion in 2025), a partner that integrates AI with accounting keeps finance teams ahead of the curve.
- Advanced analytics platforms provide real-time insights that enable proactive decision-making.
Common accounting-specific tools include Sage Intacct and FloQast.
4. Integrated Financial Functions
The modern operational accountant provides more than just controllership services. They seamlessly integrate across FP&A, systems, procurement, and transformation initiatives to create cohesion within the finance function. This holistic approach ensures that operational goals align with enterprise-wide objectives.
5. Strategic Partnership
An operational accounting partner doesn’t just execute tasks; they provide strategic guidance to help financial leaders achieve their broader objectives, from IPO readiness to M&A activities. By acting as a trusted advisor, they enable CFOs to focus on long-term enterprise value.
Expertise That Makes the Difference
Not all operational accounting providers are created equal. The right partner will bring a combination of technical skills, industry experience, and strategic insights to the table. Here’s what to look for:
- Comprehensive expertise: Professionals with CPA qualifications or equivalent credentials ensure compliance with rigorous reporting standards. Their experience spans industries and business scenarios, making them adaptable to various challenges. With 75% of CPAs nearing retirement age, an accounting partner that can still staff and train high-quality public accountants is critical.
- Proven track record: Operational accountants with hands-on experience in controllership, audit readiness, and ERP implementations are better equipped to drive efficiency and accuracy.
- Holistic approach: Look for a partner with knowledge in technical accounting, FP&A, AI implementations, and data integration. This ensures they can lead cross-functional initiatives and create value in more ways than one.
- Focus on transformation: Best-in-class operational accountants go beyond managing processes. They identify areas for improvement, implement technology solutions, and develop your team’s skills to future-proof your organization.
Building Operational Accounting Excellence
Ready to experience the benefits of operational accounting at its best? For expert operational accounting support, contact CrossCountry Consulting to get started.
When external auditors discover control deficiencies, especially those that rise to the level of a significant deficiency or material weakness, the remediation process can quickly tie up substantial internal resources public and private companies often lack. Persistent accounting and audit staffing shortages in the last three years have compounded the matter further.
If there’s no one (or no team) on the bench with the required skills and capacity to make remediation their top priority or even full-time job, what’s the next step?
To navigate the maze of remediation efficiently, management should look to strategic audit advisors capable of:
- Filling gaps immediately as a flexible extension of management.
- Leveraging deep technical expertise and technology solutions free of conflict.
- Structuring remediation efforts around proven program management methodologies and frameworks.
- Designing strategies to solve near-term issues while simultaneously establishing proactive best practices and audit-readiness infrastructure for use in every future audit cycle.
- Aligning cultures of all parties engaged in the audit process to promote seamless execution, productive collaboration, and ultimate confidence in the results.
A World of Difference: Audit Support That Frees Up Key Staff for Value-Add Activities
Remediation will stretch internal capacity, prompt the reallocation of resources, and force management to make difficult decisions on whether to delay or abandon core business objectives. In fact, 71% of organizations believe they don’t have the talent or bandwidth to manage emerging risks – when an audit identifies deficiencies that need urgent attention, this gap will widen further.
Plus, the Public Company Accounting Oversight Board (PCAOB) notes that companies typically take 6-18 months to fully address a material weakness. That’s valuable time companies will never get back.
Featured Insight
Will the months or yearslong remediation effort overlap with enterprise digital transformation programs, systems implementations (AI, ERP, etc.), complex transactions (IPO, M&A, etc.), or expansion into new markets? These high-value initiatives are vital to current/future growth and competitive advantage – and will themselves take years of work and investment to orchestrate.
Balancing these activities with the regulatory and investor demands resulting from an audit report represents a serious fork in the road for even the largest enterprises at a time when PCAOB-identified deficiencies are on the rise.
There’s a real opportunity cost involved with how these concurrent efforts are shepherded – not to mention the total “true” cost on the balance sheet.
Beyond Root Cause Analysis: An Audit Liaison
Material weaknesses rarely stem from a single, isolated issue. They often involve intricate interdependencies between processes, people, systems, and data. Identifying the root cause of each deficiency is time-consuming and requires a meticulous, well-trained team.
CrossCountry Consulting, a strategic audit advisor with extensive Big 4 audit experience, can manage all aspects of an audit, including remediation of deficiencies, significant deficiencies, and material weaknesses. This work entails:
- Total immersion in the issue, including a full understanding of the root cause of the deficiency.
- Defining a clear path to remediation as urgently and effectively as possible, including preparation of all necessary documentation.
- Training internal staff on what to look for, avoid, and better understand in future remediation efforts.
- Auditor communications, including responding to auditor questions and inquiries.
- Executive reporting of issues, remediation progress, results, and opportunities, including board and audit committee communications.
- Other operational enhancements, including automation, technology systems deployment, or process re-design, within Finance, Accounting, IT, and Risk functions.
Audit support tackles all the issues dropped in the lap of management and impacted stakeholders without sacrificing critical ongoing initiatives outside of the audit process.
That means:
- Devoting full-time focus to the remediation without unnecessarily distracting internal staff with complex requests.
- Propelling forward momentum daily so remediation is wrapped up on time and on budget.
- Reducing staff burnout and low morale during a high-pressure period.
- Removing information silos within the organization, which generates enduring downstream benefits even after remediation.
Audit Impact Where It Counts
As much as companies, auditors, regulators, and investors would appreciate remediation being a one-and-done housecleaning, the truth is that remediating deficiencies is often a multi-year process. A strategic audit advisor can assist management in architecting a control environment that prevents recurring issues and anticipates future risks, in addition to realizing long-term cost savings that avoids increased audit fees, regulatory sanctions, and loss of investor trust.
As a firm built with Big 4 pedigree, CrossCountry Consulting’s audit-readiness specialists speak the language of auditors and take the burden off management teams. We drive value at all points in the process, with the ability to get involved before, during, or after an audit – wherever support is needed, our team plugs in.
To get started on your remediation journey, contact CrossCountry Consulting.
An integral component of the divestiture process is the Transition Services Agreement (TSA). A well-crafted TSA can make the difference between a seamless transition and a chaotic handover. Explore how to minimize operational risks and business disruptions during the transition while maximizing deal value.
Understanding the TSA
A Transition Services Agreement is a contract between the buyer and the seller (or divesting parent, RemainCo, and the new organization, NewCo, in the case of a spin-off), where RemainCo agrees to provide certain services to NewCo for a specified period post-divestiture. In some cases, although less common, NewCo will agree to provide services back to RemainCo for a period of time, called a Reverse TSA.
Common services in TSAs include IT infrastructure and systems support, access to historical data, system cutover assistance, HR and people services, and finance and accounting assistance. Whether due to accelerated deal timelines or strategic priorities while executing the separation, an effective TSA ensures business continuity while NewCo establishes its own capabilities and/or successfully integrates into a buyer’s operations.
Key Elements of a TSA
- Scope of services: Clearly define the services to be provided. This includes detailed descriptions of the service, expected outcomes, and any specific service requirements. Ambiguity in service descriptions can lead to misunderstandings and disputes, so precision is crucial.
- Duration: Specify the duration for which services will be provided. This period should be realistic, giving NewCo enough time to set up its own processes and systems while being reasonable and minimizing undue pressure on RemainCo’s ongoing business operations. A process for service extensions and/or early terminations should also be addressed in the TSA. It’s critically important to consider divestiture tax goals when contemplating service durations, as the IRS considers TSA services in its tax treatment rulings.
- Service levels: Establish clear service level agreements (SLAs) to set expectations for performance. This includes reasonable response and resolution timelines as well as quality standards. Well-documented SLAs ensure the services provided meet the service recipient’s needs and minimize potential conflicts.
- Exit criteria: Include language on what “completes” the required service and an understanding of the service recipient’s plan to exit. A clear understanding of how the TSA is ultimately satisfied will ensure both parties are aligned on expectations post-close. Termination clauses may also be relevant to define conditions of early termination of the service, contemplating scenarios such as breach of contract, changes in business circumstances, or mutual agreement.
- Pricing and payment terms: Outline the cost of services and the expected invoice and payment schedules. Consider the costs associated with providing the service, the headcount required to deliver on the service, and any recurring or ongoing charges associated with technology or other infrastructure required to support the service. Companies should also contemplate whether penalties for late payments or escalating pricing are appropriate; transparency in pricing helps avoid financial disputes.
- Confidentiality and data security: Address how confidential information and data will be handled. This includes data protection measures, access controls, and protocols for data transfer. Ensuring data security is paramount, especially when dealing with sensitive business information.
- Governance and management: Define the governance structure for managing the TSA. This includes appointing key contacts, determining individual service owners from both parties, and establishing a schedule to review the execution of the TSA and resolve issues after launch. An effective governance model ensures that both parties remain aligned and conflicts are resolved promptly.

Best Practices for Crafting a TSA
- Define TSA strategy early: An upfront expectation of a company’s approach to TSAs will aid in decisions around operational readiness and set the stage for day 1. Does the organization wish to minimize continuing commitments and services and avoid TSAs? Then additional work pre-deal is required to accelerate stand-alone operations and/or immediate day 1 integration plans. Alternatively, will the organizations accept more services provided through the TSAs, allowing for a quicker deal timeline but likely creating a longer timeline to separation and/or integration?
- Conduct thorough due diligence: Understand NewCo’s needs and RemainCo’s capabilities to align on a TSA that’s realistic and achievable. Involving key stakeholders across functions early and leveraging their expertise is invaluable in identifying critical services. Subject matter experts can help simplify potential complexities and challenges that, with proper planning, can be solved.
- Consider impact of Bi-Lateral or Reverse TSAs: While most TSA services are typically provided by RemainCo, there may be situations in which key personnel or technologies are part of, or go with, the divested business. RemainCo must plan and schedule the definition of its service needs to avoid disruption to existing business processes.
- Remember atypical or irregular services: Some TSAs will be required to deal with activities that occur on irregular or infrequent schedules. Examples like rebates, benefits or expense reimbursements, and tax or audit services fees are important to capture, although they may not occur as frequently as recurring processes.
- Coordinate with the pro forma financials process: Arrangements under the TSA are often a component of NewCo’s autonomous entity adjustments in the pro forma financial statements. To ensure the accuracy of amounts disclosed in pro formas, close collaboration is required by finance, accounting, and investor relations during the TSA process.
- TSA processing and management: A TSA will require a new process to manage execution and billing related to the defined services. Evaluate both organizations’ ability to perform the services and meet the SLAs. How will you measure expectations, collect costs, establish a process to bill for the services rendered, and assess service winddown progression?
Delivering Value in the Deal and Beyond
Alignment of all impacted parties during a divestiture creates the conditions for a smooth transition, faster time-to-value, and reduced risk. TSAs lay an important foundation for post-divestiture success and should be supported with strategic planning, clear communication, and ongoing collaboration.
CrossCountry Consulting aids organizations across the deal lifecycle and helps drive toward maximize exit value. Contact us today for expert support in your next transactions.
Divestitures and demergers are complex transformations that require more than just financial and operational restructuring. A successful separation strategy includes plans to effectively manage employee entanglements, including considerations for the interconnected contracts, roles, responsibilities, and compensation structures that link employees between the existing organization (RemainCo) and the newly formed entity (NewCo).
What Are Employee Entanglements?
Employee entanglements occur when workforce responsibilities, reporting lines, compensation structures, or operational dependencies are not fully separable between RemainCo and NewCo. Employee entanglements can create complexity across any deal size. Consider:
- Cross-functional roles: Employees who support multiple business lines may have unclear responsibilities in NewCo or RemainCo.
- Compensation and benefits complexities: During separation, salary structures, incentive plans, equity programs, and benefits must be carefully considered and aligned where possible to keep employees whole.
- Legal and regulatory dependencies: Employees in different jurisdictions may require specific entity structures, corporate sponsorship, visas, or other third-party employment solutions when their employer is changing.
- Retention and operational risks: Either RemainCo or NewCo could lose key talent that supports their organization in the current state. “Stranded work” (unassigned business-critical responsibilities) or “stranded cost” (retaining employees no longer essential to the business) can increase separation challenges.
Failure to proactively address entanglements can lead to employee attrition, business disruption, financial misalignment, and regulatory non-compliance, jeopardizing the success of the transition.
Key Considerations for Managing Employee Entanglements
1. Lead With Legal and Regulatory Compliance
Divestitures and demergers often involve employees working across multiple jurisdictions, each with distinct legal requirements. Organizations must:
- Ensure compliance with local employment laws: Review contracts, severance obligations, and work council requirements in each geography.
- Evaluate legal entity needs: Determine whether NewCo requires new legal entities or if third-party Employer of Record (EoR) or Professional Employer Organization (PEO) solutions can reduce complexity and cost.
- Address cross-border regulatory challenges: Navigate visa sponsorships, tax implications, and payroll compliance.
Explore expert Divestiture & Carve-Out solutions that solve real-world problems
Maximize shareholder value, ensure a profitable path forward, and proactively manage complex accounting, risk, and systems implications for RemainCos and NewCos.
2. Create a Plan for Change Management and Communications
Employee uncertainty is one of the biggest stressors during workforce transition. Poor communication can lead to change resistance, disengagement, and attrition. A well-managed employee transition should include:
- A structured communication plan to provide employees with clear, consistent, and transparent updates on their roles, benefits, and timelines.
- Aligned messaging from leadership and HR teams to deliver a unified story and address employee concerns proactively.
- An understanding of cultural expectations and implications, especially in cross-border transactions where employment expectations and corporate values may differ.
3. Focus on Talent Retention and Workforce Transition Planning
Divestitures often create talent uncertainty, making it crucial to retain key employees and ensure workforce continuity for both RemainCo and NewCo. When navigating a divestiture, organizations should:
- Identify and secure mission-critical employees early (through retention incentives, where needed) by mapping workforce needs against business objectives.
- Develop structured transition and knowledge transfer plans to prevent gaps in leadership, expertise, or operations.
- Mitigate the risk of stranded work and stranded costs by regular reviews of key business processes, ensuring RemainCo is not left with operational shortfalls due to unexpected gaps in human capital.
4. Ensure Compensation and Total Rewards Alignment
Any misalignment in benefits and compensation structures can create legal or compliance risks, increase the risk of retention challenges, and impact overall company culture. Organizations should aim to:
- Analyze total compensation packages, including salary structures, bonuses, and equity programs, to ensure employees remain whole post-separation.
- Review and harmonize benefits programs and offerings across healthcare, retirement, allowances, and leave policies to prevent employees from losing core benefits, wherever possible.
- Develop an accurate, standalone financial budget that accounts for total rewards transition costs and ensures NewCo has a sustainable compensation and benefits model.
5. Program Management and Day 1 Readiness
Ensuring operational stability on Day 1 requires meticulous planning, execution, and risk management through project planning and governance. An effective program management office will:
- Establish a regular governance cadence and mechanism for tracking workforce transitions, mitigating employee risks, and managing dependencies across the organization.
- Ensure operational continuity for both RemainCo and NewCo by preventing disruptions in HR, payroll, IT, tax, and finance by increasing cross-functional collaboration.
- Capture lessons learned to refine best practices for future organizational changes.
Ready for a Divestiture or Demerger?
CrossCountry Consulting is a trusted advisor and divestiture execution partner with deep expertise in workforce transition planning, program management, and change leadership. Resolve employee entanglements with minimal disruption by navigating workforce separations, ensuring Day 1 operational readiness, transitioning talent, and prioritizing organizational stability. Contact CrossCountry Consulting to get started.
Enterprise Resource Planning (ERP) implementations promise significant operational improvements and better decisions, yet research reveals a stark reality: 75% fail to stay on schedule or within budget, and two-thirds deliver negative ROI. The reasons are rarely technical. They’re usually design and governance issues that surface late because of a fundamental oversight in how organizations approach complex implementations.
One root cause lies in neglecting risk and control during the implementation phase. While system integrators focus on technical deployment and meeting go-live deadlines, critical elements like risk mitigation, internal controls, and compliance frameworks often take a back seat. The result is costly rework, inefficient manual processes, and audit challenges that can undermine the business case for the system.
A successful ERP implementation treats controls as design requirements, not afterthoughts. When you integrate risk management and control frameworks from day one, you lower total cost, reduce audit pain, and accelerate value realization.
The Hidden Pitfalls That Stall ERP ROI
Leading With Technology
When IT configures the system without a clear link to business objectives, you end up with a technically sound platform that may not match how the business operates. This disconnect leads to costly post-implementation modifications, extended timelines, or users working around the system. Misaligned requirements are one of the most common failure drivers.
Insufficient Upfront Focus on Risk and Control
Many teams defer risk, control, and compliance requirements to post-design. Instead of embedding them into the system, they’re handled reactively, often through manual detective controls and late-stage fixes. This reactive approach adds unnecessary cost and compliance burden.
Change Management Limitations
Underestimating the importance of effective change management is a major reason ERP implementations fail. It’s more than training and communication. It requires clear ownership and defined handoffs so that people, processes, and technology stay aligned. Assign a process owner and a control owner for each key process, with handoffs documented in the runbook.
Strategic Advantages of Early Risk and Control Integration
Lower Cost of Compliance
Identifying risks early prevents costly remediation later. When controls are designed alongside system configuration, they become seamless parts of daily operations instead of bolt-ons. With effective IT general controls, automated and preventive checks built into the workflow are far less expensive to operate than manual detective steps added after go-live.
Less Audit Friction
Teams that integrate risk and control from the start demonstrate greater audit readiness. A documented control framework embedded in business processes leads to faster, smoother audits and fewer findings. It also builds confidence with leadership and stakeholders.
Scalable Control Architecture
Modern ERP systems support global operations with complex structures. Control frameworks designed during implementation can scale as the organization grows, supporting future expansions, acquisitions, and regulatory changes without major redesign.
How to Integrate Risk and Control Early
Early Implementation Priorities
- Define process outcomes. For each key process, set measurable goals (for example, 98% three-way match compliance).
- Map risks to controls. Identify potential process risks and start defining automated, preventive controls where practical.
- Design roles and segregation of duties (SoD) early. Build a role catalog and SoD rulebook before user provisioning.
- Include control validation in testing. Test both business outcomes and control functionality during UAT.
- Treat data migration as a control activity. Define ownership, reconciliation rules, and sign-offs for all data loads.
Quick examples:
- Configure three-way match tolerances at purchase order approval, not after invoice posting.
- Design user roles with least-privilege access and run SoD analysis on both roles and users before go-live.
An Integrated Risk and Control Approach to ERP Success
Strong implementations address organizational, process, risk, and data needs alongside technical ones. A capable risk and control partner brings process, security, data, and compliance expertise together, and holds themselves accountable to measurable KPIs such as:
- Automated control coverage.
- Preventive control coverage.
- SoD conflicts at go-live.
- Control pass rate.
Achieving these outcomes requires more than a checklist. It takes a team with the right blend of process, technology, and control expertise working in sync. The partner you choose should combine deep functional knowledge with technical and compliance strength.
Cross-Functional Expertise
- Regulatory environment: Deep knowledge of SOX and other regulations that apply to your business.
- Technology, data, and security: Hands-on experience with integrations, data migration, cybersecurity, privacy, and governance.
- Program and change management: Clarity on dependencies and decision impacts that affect adoption.
- IT general controls: A solid foundation in identity and access management and change control.
- Functional business perspective: Real experience in core business processes like Record-to-Report, Order-to-Cash, and Source-to-Pay.
A well-rounded team with these capabilities can guide the program from design through stabilization, maintaining control integrity and business alignment through every phase of the implementation.
Transforming Risk into Strategic Advantage
Early investment in risk and control integration pays off throughout the system’s life. Making risk and control a core part of your implementation strategy ensures compliance, strengthens governance, and helps your ERP deliver on its promise.
To get started, contact CrossCountry Consulting.
The 2025 overhaul of the Global Internal Audit Standards (GIAS) provides far more than a checklist for compliance. It offers a framework for internal audit leaders to set strategy, govern their functions, and deliver measurable value.
The Standards emphasize purpose, ethics, independence, governance, management, and performance – but more importantly, they invite internal audit teams to move beyond compliance and demonstrate how assurance can accelerate risk responsiveness, enhance stakeholder trust, and integrate with enterprise value creation. These expectations coincide with rapid advances in technology and AI, creating both the requirement and means for internal audit to modernize.
AI’s Expanding Role
AI has fundamentally shifted how internal audit, risk, and compliance leaders strategize, prioritize, and operate. Rather than a bolt-on tool, AI now informs risk sensing, testing depth, reporting speed, and continuous improvement, forcing a redesign of operating models, talent mix, and assurance approaches.
Yet adopting AI alone is not enough; success depends on embedding these tools within a strategy anchored to leading professional practices and the Standards themselves. This requires a quality management system, supported by enabling technologies such as GRC platforms and AI. Equally important is connecting those capabilities to integrated risk management and a broader model of organizational assurance, positioning internal audit as a coordinated partner across the enterprise rather than a siloed reviewer. This begins with the foundation – modernizing internal audit’s mandate, strategy, and governance structures.
Modernizing Strategy
Internal audit teams are updating policies, charters, and escalation protocols to align with new expectations around independence, oversight, and risk tolerance. The Standards require clear documentation of the audit mandate and formal acknowledgement of the CAE’s reporting line to the board. And, many organizations are digitizing these policy updates through AI-enabled technologies that promote real-time escalation and greater transparency in how internal audit responds to fast-evolving threats.
The Standards also call for a published internal audit strategy (Principle 9.2), linking assurance priorities directly to enterprise objectives. Leading functions are formalizing this process by building audit strategies that not only reflect the organization’s risk appetite but also demonstrate how internal audit optimizes its resource model, integrates with other assurance providers, embeds feedback loops, and strengthens stakeholder relationships.
Dashboards, AI-driven analytics, and real-time engagement tools are increasingly common mechanisms to ensure this alignment. Some strategies now explicitly reference enabling technologies, including AI, as part of how internal audit sustains agility, transparency, and responsiveness. But strategies only gain credibility when paired with robust quality systems.
Quality and Continuous Improvement
At the heart of the new framework is the requirement for a Quality Assurance and Improvement Program (QAIP). This program is not just a periodic exercise; it must operate as a system, incorporating ongoing monitoring, periodic self-assessments, and a 5-year external quality assessment cycle. The Standards emphasize transparency, requiring boards to receive regular reporting on quality results, remediation actions, and continuous improvement initiatives.
In practice, technology and AI are redefining quality by standardizing execution, surfacing exceptions earlier, and shortening review cycles. Functions are adopting workflow tools such as AuditBoard and Workiva to standardize workpapers, automate documentation, and accelerate reviews. Some are deploying AI agents for routine audits, continuous monitoring, and anomaly detection – not replacing judgment, but freeing human auditors to focus on higher-risk and more judgment-intensive areas.
Over time, these tools also support the maturity journey outlined in the Standards: moving from “Initial/Reactive” practices to “Optimizing/Strategic Value” functions that contribute directly to organizational success.
Advancing Internal Audit Maturity
The GIAS outlines a path for how internal audit functions evolve in maturity – from ad-hoc activities to fully optimized, AI-enabled value creators. This model illustrates the progression and provides leaders with a tool to assess where they stand today and what capabilities are needed in the future.

Internal audit leaders can use this model as both a diagnostic and a roadmap for transformation. And as functions progress along this maturity journey, transparent and timely communication with the board becomes essential.
Reporting, Transparency, and Board Communication
The Standards also raise expectations for how internal audit communicates with boards. Reporting is no longer about delivering static documents. Instead, audit leaders are adopting dynamic, digital-first approaches:
- Dashboards that consolidate findings, remediation status, and value metrics in real time.
- Generative AI tools to prepare draft summaries, automate trend analyses, and shorten reporting cycles.
- Scorecards to highlight risk coverage, issue aging, closure velocity, and stakeholder feedback.
Boards gain not only visibility into issues but also confidence in how internal audit drives accountability. Independence remains paramount: While AI accelerates analysis, conclusions must always be owned and signed off by human auditors. Alongside improved reporting, the Standards expand what must be reported on through the introduction of Topical Requirements.
Topical Requirements as Strategic Inputs
One of the most significant evolutions in the Standards is the addition of Topical Requirements. These are mandatory when a subject is part of the audit plan, identified during fieldwork, or requested ad hoc by management or the board. Internal auditors must not only assess applicability but also document the rationale for excluding a requirement.
This approach ensures consistent, high-quality coverage of critical themes such as cybersecurity, third-party risk, organizational culture, and business resiliency. For example, the Cybersecurity Topical Requirement – effective February 5, 2026 – provides structured evaluation criteria and aligns directly with frameworks such as NIST and COBIT. By embedding these requirements into the audit plan, CAEs can show their function’s relevance to the most pressing organizational risks.
Meeting these new requirements at scale depends on technology and, increasingly, AI.
Technology and AI as Enablers
Innovation is an explicit objective of the GIAS. The Standards encourage internal audit functions to maximize the use of technology, enhance coordination, and expand value delivery. Teams are increasingly leveraging GRC platforms to automate workflow, manage documentation, and centralize assurance provider inputs.
AI is rapidly becoming indispensable. Advanced analytics expands scope through full-population testing and anomaly detection, and predictive models allow proactive risk identification. Generative AI, meanwhile, is being used to automate documentation, accelerate draft reporting, and benchmark continuous improvement efforts. These technologies must be governed within the same principles of objectivity, competence, and confidentiality that underpin the Standards. Many organizations are already aligning their AI programs with external frameworks such as the NIST AI Risk Management Framework to safeguard against bias and preserve independence.
With these opportunities come risks, making governance and guardrails essential.
AI Guardrails for Quality and Independence
As AI becomes embedded in audit processes, clear safeguards are essential to preserve independence, transparency, and trust. Leading functions are putting the following controls in place:

Of all the guardrails, the most critical are people themselves – supported by skills development and collaboration.
People, Skills, and Collaboration
Another critical dimension of strategy is people. The Standards require that internal audit functions demonstrate adequate financial, human, and technology resources. Forward-thinking functions are using competency frameworks tied to the Standards, with training delivered through platforms like Workday and tracked through formal attestations. AI is also being used to identify skill gaps, optimize staff deployment, and match resources to complex audits.
Collaboration with other assurance providers is a key component of the new framework. Cross-functional teams are increasingly using shared GRC platforms to streamline communication, coordinate findings escalation, and avoid duplication. This integration reinforces the value of internal audit not just as an independent assurance provider but as a strategic partner in enterprise risk management.
Together, strategy, quality, technology, and people move internal audit beyond conformance into a true value driver.
From Conformance to Value
The new Global Internal Audit Standards set a higher bar, but they also provide a clear roadmap. Audit leaders who act now are realizing measurable benefits:
- Accelerated QA cycles and earlier risk detection.
- Deeper insights enabled by analytics and AI-driven monitoring.
- Meaningful continuous improvement metrics that strengthen the QAIP.
- Real-time board communication through dashboards and interactive reports.
The next era of internal audit will be defined not just by compliance, but by how effectively these elements – strategy, quality, technology, and people – come together to drive resilience and enterprise value. Ready to transform your internal audit function in the age of AI? Contact CrossCountry Consulting to get started.
How different could audit life be if you had the resources to move a significant amount of audit effort from January and February 2026 up to October or November this year instead?
Suddenly, you can:
- Allocate time to socialize critical accounting conclusions with various impacted parties, allowing them to consider audit’s impact on planning and budgeting cycles.
- Manage workloads, burnout, and stress that often occur in Q1.
- Improve the quality of deliverables and drive audit efficiencies.
- Reduce last-minute surprises and create capacity to collaboratively work through issues.
As is the case every year, the year-end audit process presents significant challenges and resource demands for companies and their auditors. That’s why it’s critical to proactively address certain accounting tasks during the interim period. So how do you make this a reality?
Why Now? Key Interim Activities for Maximum Audit Value and Time Savings
Management may not have the bandwidth to frontload audit work. But the challenge grows more pronounced the longer they wait. The sooner auditors can start their work, the better the outcome for all parties: public and private companies, auditors, regulators, and strategic audit advisors that may be introduced to the project.
By taking a “help us help you” approach to interim accounting activities, management teams can generate more lift and value at this point in the audit cycle. Four functions in particular are critical to making this happen: Controllership, FP&A, Internal Audit, and IT.
Get started on:
- Goodwill Impairment: Assess goodwill, identify potential impairment indicators, and gather necessary documentation.
- Long-Lived Asset Impairment: Evaluate the value of long-lived assets and conduct impairment testing.
- Acquisitions: Address post-acquisition accounting considerations, including purchase price allocation, intangible asset valuation, and revenue recognition.
- Internal Controls: Review and strengthen internal controls to ensure accurate financial reporting, especially if changes to control strategy were recently implemented. The evaluation of material weaknesses or significant deficiencies can also occur as they’re identified rather than letting them pile up.
- Going Concern: Assess the company’s ability to continue operations and address any potential concerns, especially those that may push out filing dates. Testing of projected financial information used in the going concern analysis is getting more and more attention from auditors and the Public Company Accounting Oversight Board (PCAOB).
- Financial Reporting: Begin drafting disclosures and pro-forma financial statements (Form 10-K).
- Third-Party Valuation Experts: Engage valuation experts in advance to avoid delays, lock in the scope, document rationale for any anticipated changes in methodology, and ensure timely completion of valuations.
- Projected Financial Information (PFI): Scrutinize PFI used for valuations and impairment testing to ensure its reasonableness. When the PFI is overly optimistic, it’s helpful to “sensitize down” starting in Q3.
- Technology: Ensure accounting systems and data extraction processes are efficient and compatible with audit requirements. The cleaner and more accessible the data is now, the faster the audit process. Be particularly careful with AI deployments across the firm, as auditors must be able to understand explainability, traceability, and audit implications of companies using AI systems.
- Financial Statement Close Process: Improve the quality of account reconciliations and analysis (common auditor-identified pain points) now since close capabilities are a routine issue.
The cascading effects of an intense audit period can negatively impact operational accounting, FP&A, and other key finance cycles, which will need to be considered and guarded against ahead of time. By accelerating the above activities – either in total or individually – management can get ahead of the audit curve, enhance their ongoing ability to meet audit responsibilities, and spare other teams from being pulled into fire drills.
Practical Tips for Implementing an Interim Focus
Management teams and their advisors can help streamline and advance interim accounting by:
- Establishing a dedicated interim review process or governance structure to maintain a coherent approach to the pre-audit period.
- Assigning resources to specific accounting areas, with process owners and milestones guiding progress.
- Developing checklists and templates for efficient data gathering to free-up staff from manual compilation work.
- Leveraging technology such as Oracle, NetSuite, SAP, or another ERP of record for more effective reporting, data analysis, and automation.
- Fostering collaboration between accounting and other departments to facilitate information-sharing and accountability.
- Creating AI risk management and governance documentation around the company’s use of AI systems within key functions like accounting.
CrossCountry Consulting’s audit specialists speak the language of auditors and take the burden off management teams by driving value at all points in the process before, during, or after an audit – wherever support is needed, we plug in.
To maximize your interim audit period, contact CrossCountry Consulting.
Are you confident you know where your employees are using AI? If you answered yes, you’re likely wrong – and that overconfidence could expose your firm to unprecedented audit risk.
AI in accounting, financial reporting, operations, HR, and legal is happening faster than most management teams and auditors realize. Consider: Agentic AI use in finance is projected to increase 6X in the next year; AI in recruitment is up nearly 500% since 2023; and 96% of legal professionals are using AI daily.
While leadership focuses on traditional risk areas, staff have been deploying AI solutions across critical processes, from accounts payable (AP) and contracts to revenue recognition and technical accounting. The problem isn’t just that they’re using AI – it’s that they’re often doing it without proper governance and audit awareness, likely rapidly increasing risk in numerous areas of the business.
The Hidden AI Adoption Crisis
Companies are increasingly implementing AI solutions in areas that directly impact financial statements, yet auditors remain largely unaware of these implementations when they occur. This knowledge gap creates a perfect storm of audit risk that threatens the accuracy of financial reporting and the credibility of audit reports while simultaneously introducing cyber and data risks.
Consider this scenario: In Q4, a manufacturing company implements an AI-powered contract analysis system to automate revenue recognition decisions at a subsidiary. The AI processes thousands of contracts, making materiality judgments and revenue timing determinations. HQ was never made aware of this implementation, and it never came up in quarterly review inquiries. Auditors discover this during fieldwork – not through disclosure, but through observation. How do you assess the completeness and accuracy of a quarter’s worth of AI-driven revenue decisions when you have no understanding of the system’s parameters, training data, or error rates?
Too often, AI deployments are done by individuals who likely aren’t authorized to use specific tools or aren’t aware of the policies and risks associated with them. Because some AI tools don’t follow typical software deployment processes, it’s virtually impossible for management to grasp the company’s AI inventory. Still, when AI tools are implemented in compliance with firm policies, they may be the first of their kind, thus creating inevitable risk. Management’s process for evaluating and addressing relevant ITGC risks may not be mature.
Accounting AI Deployment Without Auditor Awareness
AI adoption is most prevalent in these financial reporting areas:
Document Processing and OCR Technology
The lowest-hanging fruit for AI implementation includes automated processing of invoices, contracts, and supporting documentation using optical character recognition (OCR) software and intelligent document processing (IDP) tools. While seemingly routine, these systems directly impact:
- AP accuracy and completeness.
- Contract liability recognition.
- Revenue timing and measurement.
Common platforms include UiPath, Klarity, and Rossum.
Revenue Recognition Automation
Companies are leveraging AI to interpret contract terms, determine performance obligations, and calculate revenue allocation. This is particularly complex for AI solution providers themselves, who face intricate revenue recognition challenges under ASC 606 due to varied monetization models, including flat fees, token-based pricing, and usage-based billing.
Trullion, HighRadius, and FloQast in particular are commonly leveraged for enhanced revenue recognition capabilities.
Predictive Analytics for Estimates
AI systems are making increasingly sophisticated estimates for allowances, reserves, and fair value measurements – areas traditionally requiring significant auditor judgment and testing.
The Governance Gap: Why AI Controls Are Failing
The fundamental issue isn’t AI adoption itself – it’s the absence of appropriate AI governance frameworks. Most organizations implementing AI solutions lack:
- Explainability requirements: Finance teams often cannot articulate how their AI systems reach conclusions, making audit trail reconstruction impossible.
- Traceability standards: Without clear documentation of data inputs, processing parameters, and output validation, auditors cannot assess the reliability of AI-generated financial information.
- Quality control measures: The distinction between Large Language Models (LLMs) with high hallucination rates and Small Language Models (SLMs) with better accuracy is lost on most teams, leading to inappropriate tool selection for critical processes.
- Centralized AI inventory: Many organizations fail to maintain a comprehensive catalog of all AI systems in use, leading to fragmented oversight, redundant tools, and blind spots in risk management.
- Model risk assessment and monitoring: Continuous evaluation of AI models for performance degradation, bias, and unintended consequences is often overlooked, leaving organizations vulnerable to risk.
- Ethical and legal compliance: Teams frequently deploy AI without ensuring adherence to ethical guidelines or regulatory requirements, exposing the organization to potential lawsuits, fines, and public backlash.
- Third party/vendor AI controls: Companies often rely on external AI solutions without thoroughly vetting vendor practices, data security measures, or compliance with industry standards, creating hidden vulnerabilities in their operations.
Modern AI governance frameworks such as NIST AI RMF and ISO/IEC 42001 will require these types of controls for comprehensive risk management.
The Materiality Assessment Challenge
When AI is deployed without auditor knowledge, stakeholders are forced into reactive assessment mode. The key questions become:
- Where has AI been used in processes affecting financial statements?
- What is the materiality of AI-generated or AI-influenced transactions?
- What additional audit procedures are necessary to validate AI outputs?
This reactive approach is inherently risky and inefficient. With the support of management, auditors should be positioned ahead of their clients’ AI adoption, not behind it.
AI in Focus
Discover how finance leaders can use practical, human-centered AI to optimize operations, enhance decision-making, and position their companies for growth.
In the first episode of CrossCountry Consulting’s podcast, Field Notes, we explore how audit-ready AI works in the real world and why smarter AI starts with your people.
Building an AI-Aware Audit Readiness Approach
Organizations should implement comprehensive AI assessment protocols that include:
Current-State Analysis
Inventory all existing AI tools across the organization, including:
- System parameters and functionality.
- Documentation facilitating the audit of the AI tool or function being used.
- Data sources and quality controls.
- Output validation procedures.
- Human oversight mechanisms.
- Number of controls to ensure completeness and accuracy of input data.
- Expanded attack surface.
- Model positioning/data integrity.
- Role-based access and privilege controls.
- Audit trail/forensics.
Future Roadmap Review
Management must rationalize and align future AI implementation plans to proactively understand potential audit implications. This strategic approach allows for proper control design and testing methodology development before systems go live, which auditors will be looking for. Recommendation: Plan for data privacy impact assessments and cyber testing aligned with ISO/IEC 42001 and NIST AI RMF.
Enhanced Risk Assessment
Develop AI-specific risk assessment procedures internally that evaluate:
- Completeness and accuracy of AI training data. Which corporate function or group of stakeholders is best positioned to lead this effort?
- Appropriateness of AI model selection for financial processes. How are AI-enhanced operational processes subsequently feeding into and impacting financial reporting?
- Adequacy of human oversight and exception handling.
- Effectiveness of AI output validation controls.
- Vulnerability scanning.
- Incident response for AI-driven processes.
Specialized Skill Development
Accounting and IT teams need enhanced technical capabilities to evaluate AI systems effectively. It’s not enough for staff to deploy AI in line with corporate policy; they must be capable of ongoing maintenance, monitoring, and testing of AI system performance. This includes understanding different AI model types, their appropriate applications, their inherent limitations, and cybersecurity literacy for audit and AI teams.
As audit scrutiny of AI increases, additional third-party audit support will likely also be needed to augment the lack of internal capabilities in this space.
Summary Action Plan
Management should codify and communicate a high-level summary AI action plan that steers the governance and implementation of AI systems. This plan should address:
- Adoption of formal AI governance frameworks.
- Integration of cybersecurity risk management.
- Expanded documentation to include both AI and security controls.
- Cross-functional collaboration recommendations.
This approach can also support audit efficacy and employee satisfaction.
A Call to Action: Embrace AI Advisory
AI transformation of financial statement reporting requires organizations to collaborate with strategic partners who understand both the opportunities and risks of AI adoption in financial processes.
Ready to transform your firm’s AI audit capabilities? CrossCountry Consulting helps management teams and their auditors understand, assess, and validate AI implementations in financial reporting. For the strategic insights and technical expertise needed to maintain audit quality while enabling innovation, contact CrossCountry Consulting today.
Finance and accounting teams spend countless hours on manual variance analysis, yet critical decisions still get made without proper review. The infamous “3-day scrub for a 5-minute review” has become an all-too-familiar reality in corporate finance departments worldwide. This inefficient process not only wastes valuable resources but also undermines the strategic potential and critical control of financial analysis.
AI is increasingly proving capable of automating routine, time-consuming, and repetitive tasks that once required significant human capital within the accounting function. Through automation, AI empowers finance professionals to focus on what truly matters: data-backed strategic analysis and decision-making. This transformation is shifting teams from tactical preparers to strategic reviewers, unlocking critical thinking and professional judgment.
The Hidden Problems in Traditional Financial Analysis
Modern finance teams face a fundamental challenge: outdated workflows that misallocate talent and create unnecessary risk. Consider the typical monthly variance analysis process in which teams spend days extracting data, building spreadsheets, and formatting reports – only to have executives review the results in minutes.
This workflow gap reveals several critical issues:
- Time misallocation: Finance professionals dedicate the bulk of their time to data preparation and formatting rather than analysis. This manual process consumes resources that could be better spent on strategic initiatives.
- Data reliability: Manual workflows hinder the ability to extract consistent, reliable, and strategic insights. Without trusted data, organizations struggle to uncover trends or opportunities that can add meaningful business value.
- Talent underutilization: In an era of lean teams, talent shortages, and the constant pressure to “do more with less,” organizations cannot afford to use skilled analysts as data processors. Yet that’s exactly what happens when manual workflows dominate.
- Compromised quality: Rushed preparation leads to errors, incomplete analysis, and missed opportunities. The pressure to deliver on time often overrides the need for a thorough review.
- Lost professional judgment: When teams focus on correctness rather than analysis, they lose sight of the bigger picture. Strategic insights get buried under operational tasks.
How AI Addresses Core Financial Analysis Problems
AI transforms financial analysis by automating the manual work that traditionally consumes most of the process. Rather than replacing human judgment, AI provides more time for it by handling the routine tasks and surfacing meaningful insights.
- Automated data processing: AI systems can extract, clean, and organize financial data from multiple sources in minutes rather than days. This automation eliminates the manual export-and-pivot workflows that plague traditional analysis. Learn more: CrossCountry Consulting’s AI-powered data automation accelerator reduces processing times by 80% at 99% accuracy.
- Intelligent variance detection: Advanced algorithms identify significant variances and anomalies automatically, flagging items that require human attention while filtering out routine fluctuations.
- Dynamic reporting: AI-powered platforms generate real-time reports with interactive dashboards and drill-down capabilities, allowing stakeholders to explore data rather than waiting for static presentations.
- Pattern recognition: Machine learning algorithms identify trends and correlations that might escape human notice, providing deeper insights into financial performance.
Featured Insight
Driving Strategic Solutions Through AI Enhancement
The true value of AI in financial analysis extends beyond efficiency gains. By leveraging AI tools such as FloQast for flux and variance analysis, finance teams can focus on high-value activities that drive business results.
- Enhanced decision-making: With AI handling the data processing, analysts can spend more time interpreting results and developing recommendations. This shift from reactive reporting to proactive analysis significantly improves decision quality.
- Improved accuracy: Automated processes reduce human error while maintaining consistency across reporting periods. AI systems also provide audit trails and validation checks that enhance assurance over data integrity.
- Real-time insights: Traditional monthly cycles give way to continuous monitoring and real-time alerts. Finance teams can identify issues as they emerge rather than discovering them weeks later.
- Strategic focus: When tactical preparation becomes automated, entire teams can elevate to reviewer status. This transformation unlocks critical thinking and strategic perspective across the organization by adding an additional layer of review from those closest to the data and best equipped to provide the analysis.
The Future of AI-Powered Finance
The evolution from manual analysis to AI-enhanced decision-making represents more than a technological upgrade. It’s a fundamental reimagining of the finance function’s role within organizations.
Forward-thinking CFOs recognize that AI doesn’t threaten finance jobs; it enhances them. By automating routine tasks, AI creates opportunities for finance professionals to become strategic business partners rather than data processors.
The organizations that embrace this transformation will gain competitive advantages through faster decision-making, improved accuracy, and better resource allocation. Those that cling to manual processes will find themselves increasingly disadvantaged as AI adoption accelerates across the industry.
The question isn’t whether AI will transform financial analysis, it’s whether your organization will lead or follow this transformation. Ready to maximize the value AI can bring to your finance and accounting operations? Contact CrossCountry Consulting today.
Traditional approaches to balance sheet planning are often mired in siloed operations and reactive measures. The time for a fundamental re-evaluation of your balance sheet planning process is now.
For too long, the pursuit of enhancing earnings while managing credit, capital, interest, and liquidity risks has been a high-wire act, often addressed in isolation. To make matters worse, the aftermath of the 2023 banking crisis saw many institutions preoccupied with remediating Matters Requiring Attention (MRAs) within individual treasury risk stripes, further entrenching this fragmented approach.
Additionally, the 2023 regional banking crisis and the 2024 collapse of Synapse Financial Technology prompted greater scrutiny from regulators in the areas of KYC/AML and financial risk management. The current regulatory environment, far from inviting complacency, presents a unique chance to adopt a truly holistic approach to balance sheet planning.
Forces at Play: What’s Driving This Imperative?
Several powerful drivers are promoting this shift:
- Changing regulatory outlook: While the immediate post-crisis focus was on addressing specific regulatory gaps, the current environment allows for a more strategic, integrated view of risk management. Given the rapid increase in rates in 2022 and 2023, coupled with changing capital rules (i.e., Basel endgame), banks are identifying ways to proactively integrate balance sheet planning to maximize earnings while robustly managing all financial risks in concert.
- Rise of new entrants and channels:
- Private credit: This is a double-edged sword. While private credit offers avenues for earnings diversification with limited impact to bank capital ratios, the growing off-balance sheet exposure introduces new liquidity risks and an elevated need for sophisticated collateral management. Planning processes must be equipped to fully understand and model implications of on- and off-balance sheet exposure.
- Fintech charters: As regulators champion a competitive banking environment, technology organizations that once served as partners in balance sheet growth are now applying for their own charters. This signals a fundamental shift in the competitive landscape, demanding that financial institutions be more innovative in their business models and agile in their planning processes to continue to drive shareholder value.
- Threat of disintermediation: The emergence of stablecoins, despite ongoing regulatory uncertainties, demands immediate attention. Financial institutions must proactively model various scenarios and assess the potential impact on their balance sheets and earnings. Some questions to consider include:
- What if your bank acts solely as a custodian for stablecoins?
- What if stablecoins appear on your balance sheet?
- What if both scenarios unfold? Crucially, what is the impact on liquidity, capital, and interest rate risk under each scenario, and how does your cost model adapt? Ignoring these questions is no longer an option.
Key Focus Areas for Integrated Balance Sheet Planning
Banks must prioritize the following to truly integrate balance sheet planning with the rest of the functional areas across finance, including the various risk stripes:
- Rethink the planning process:
- Break down silos: The legacy siloed approach across different Asset Liability Management (ALM) and risk disciplines must be dismantled. A truly integrated planning process fosters collaboration and a comprehensive understanding of risk and opportunity. This includes reducing the number of offline models in use from disparate data sources and re-committing to fully leveraging the capabilities of existing platforms.
- Embed cash flow-based planning: To genuinely pursue balance sheet optimization, move beyond traditional accounting-based planning. Embrace detailed cash flow-based planning to gain granular insights into funding strategy, liquidity risk management, interest rate sensitivity, and capital utilization.
- Integrate next-generation performance management: Implement methodologies that support advanced performance management and enable timely, sophisticated analytics. This means moving beyond basic reporting and fire drills to predictive modeling and scenario analysis that takes hours instead of days.
- Data strategy and governance:
- The adage “garbage in, garbage out” remains profoundly true. As the use cases for AI become more advanced and discussions around governance frameworks intensify, the need for clean, structured, and well-governed data is paramount. Without it, even the most sophisticated models will yield unreliable results.
- Optimize your technology stack:
- Bridging ALM and CPM: Integrated balance sheet planning starts with clear objectives and constraints that dictate reporting needs. The ALM modeling process plays a critical role, but the question is how it integrates with your broader corporate performance management (CPM) framework. Consider these approaches:
Technology Stack Options
Noted below are organizations’ approaches to integrated balance sheet planning and how they incorporate components such as pricing, credit loss modeling, and capital and liquidity planning. Each is unique to company ‘DNA.’
ALM-Heavy Process
- Illustrative example: In this model, cash flows for both existing and new business are primarily generated via ALM systems. Funds Transfer Pricing (FTP) rates are also derived from the ALM system. Driver-based models within a CPM tool like OneStream handle non-interest income and expense, with multi-dimensional reporting (cost center, legal entity, department, etc.) also managed within the CPM.
- Observed benefits: This approach provides a single source for all forecasted cash flows and FTP assignments. It also fosters better alignment between treasury and interest rate risk (IRR) modeling and the application of behavioral assumptions on products.
- Observed drawbacks: A significant downside is the elongated timeline, as planning and forecasting are heavily reliant on treasury/ALM subject matter experts to generate cash flows. Data management and governance can become more involved due to multiple hierarchies and assumption sets across different solutions, potentially leading to a cumbersome “back and forth” management process.
Hybrid Approach (ALM/CPM Tool)
- Illustrative example: By no means a linear process, this approach strikes a balance between ALM and a CPM tool. Conceptually, cash flows for the current book are generated via ALM, while cash flows for new business are generated within the CPM tool. FTP rates still come from the ALM system, but allocation methodologies are modeled in the CPM. Consolidations and multi-dimensional production are also handled by the CPM tool.
- Observed benefits: This hybrid model gives FP&A/planning teams greater flexibility with cash flows from new originations. It reduces reliance on treasury/ALM SMEs for forward-looking views and enables better strategic planning through well-defined workflows within the CPM. FP&A gains a clearer “line of sight” into financials ahead of the close, with cleaner alignment and linkage between driver-based models and balance sheet planning.
- Observed drawbacks: Building cash flows for new business in a CPM tool can be complex and lengthy, depending on the scope of products and assumptions. The reporting process can be more involved due to the need to merge existing and new cash flows. Crucially, this approach does not eliminate the need for a dedicated ALM tool to measure and monitor interest rate risk.
End-to-end OneStream value creation with an expert implementation and advisory partner
Simplify and transform corporate performance management processes like financial consolidation, reporting, planning, and analytics across the portfolio.
CPM-Heavy Process
- Illustrative example: In this model, cash flows for both existing and new business are exclusively driven from the CPM tool. FTP rates are still sourced from the ALM system, but allocation methodologies, consolidations, and multi-dimensional reporting are all managed within the CPM.
- Observed benefits: This approach offers the least reliance on treasury/ALM SMEs for forward-looking views, simplifying coordination.
- Observed drawbacks: Similar to the hybrid approach, building comprehensive cash flows directly within the CPM can be complex and time-consuming depending on the breadth of products and assumptions. It also doesn’t replace the fundamental need for an ALM tool for granular interest rate risk measurement and monitoring. Furthermore, it requires strong coordination and alignment between IRR and planning assumptions.
The sweet spot often lies in a hybrid approach, leveraging the strengths of both ALM systems for granular risk modeling and CPM tools for comprehensive financial planning, forecasting, and multi-dimensional analysis. This minimizes reliance on siloed expertise and streamlines the planning cycle, offering greater flexibility and line of sight into financial performance.
The Path Forward
The future of financial services demands a proactive, integrated, and data-driven approach to balance sheet planning. Banks that embrace this transformation will unlock new opportunities for growth, efficiency, and sustained profitability. The time to rethink your balance sheet planning process is now.
To get started, contact CrossCountry Consulting.
As public and private companies accelerate their efforts to comply with SB 253 and SB 261, one thing is clear: Climate disclosure is no longer a theoretical exercise. Regulatory expectations are months away.
The California Air Resources Board (CARB) has provided early-stage flexibility, stating “best faith efforts” will be sufficient in the first year of reporting. While this provides some relief, it also underscores the importance of using this initial period to lay a strong foundation for credible, long-term compliance.
Based on our ESG reporting experience supporting companies with SB 253 and SB 261 compliance, several key lessons have emerged.
Lesson 1: Establish a Foundation With a Forward-Looking Plan
Companies making the most meaningful progress understand the first year is not the finish line – it’s the starting point. Success in year one depends on both foundational action and a clearly articulated plan for future compliance.
Several core activities have proven essential:
- Conduct an initial climate risk assessment to assess any financial material impacts on your organization. For many companies, full quantification or climate scenario analysis won’t be feasible right away. A thoughtful qualitative review throughout your operations and company strategy still demonstrates that you’re asking the right questions and making best faith efforts.
- Document a forward-looking roadmap. Codify how you’ll advance your risk analysis and other disclosures over time.
- Establish Scope 1 and 2 greenhouse gas emissions baselines. These are often the most accessible metrics, as well as the most critical metrics to guide future action.
- Build institutional readiness. Set up basic reporting workflows, establish a cross-functional team to represent the interests of internal and external stakeholders, and develop accountability structures now to avoid scrambling later. This work lays the foundation for year two, year three, and beyond.
For companies subject to SB 261, the 2-year period following initial disclosures presents a unique opportunity to demonstrate progress. Capitalizing on that timeframe requires structured planning now, not later.
Lesson 2: Governance and Strategy Are Critical Enablers
Disclosure isn’t just about data; it’s about ownership, strategy, and decision-making.
Establishing clear governance early helps avoid confusion and rework later. Basic questions matter: Who owns climate risk? How are decisions made? How often is progress reviewed? Do we have mitigation plans?
Your strategy should also link directly to business value:
- Risks: Commodity price volatility, supply chain disruptions, customer demands.
- Opportunities: Energy efficiency, greenhouse gas emissions reductions, cost savings.
When climate considerations are integrated into core business strategy, the benefits go beyond compliance. Companies see greater efficiency, stronger cross-functional collaboration, and clearer prioritization of resources, ultimately spending less time on reactive disclosures and more time on value-generating activities.
Explore expert ESG Reporting solutions that solve real-world problems
Integrate sustainability reporting best practices and build an ESG framework that meets current and emerging regulatory requirements.
Lesson 3: Don’t Let Perfection Get in the Way: Start with What’s Practical and Use the Right Tools
For many companies, this is the first formal climate reporting requirement they’ve encountered. While gaps and uncertainties are expected, delaying action until everything is fully resolved isn’t effective.
CARB’s “best faith” flexibility in year one is intended to encourage action, not inaction. What matters most is taking the first step – even if every element isn’t yet fully developed – such as making reasonable and supportable assumptions, clearly documenting your current state and any known gaps, and outlining a realistic and phased plan for improvement over time.
For companies building disclosures from scratch or looking to create greater efficiencies in their regulatory compliance process, AI tools can be a valuable accelerator. AI-enabled platforms can support:
- Data collection and extraction.
- GHG calculations and analytics based on accepted methodologies.
- Drafting disclosures and narrative reporting aligned with regulatory frameworks.
Used appropriately, AI can help reduce manual lift and allow lean teams to meet their obligations with greater confidence and speed.
Lesson 4: Resource Allocation
Climate disclosure requirements are evolving, not just in California, but globally. With CSRD shifting following the Omnibus legislation and the SEC dropping its defense of its climate disclosure rules earlier in the year, many companies are struggling to plan and resource appropriately.
This uncertainty is placing additional pressure on already lean teams. Legal, finance, and operations leaders are being asked to take on sustainability reporting responsibilities, often without added capacity or expertise. That’s why effective resource allocation is a strategic enabler that can help organizations meet regulatory requirements, enhance transparency, build stakeholder trust, and reduce compliance risk
Taking the Next Step to California Climate Compliance
CrossCountry Consulting empowers companies to adapt swiftly and strategically. Whether you’re building a climate risk program from the ground up or enhancing existing processes, we provide the structure, insight, and support needed to move forward with clarity and confidence.
For private companies, we offer tailored guidance to navigate California’s climate legislation while maintaining discretion and honoring internal context. Our approach meets you where you are – ensuring compliance without overexposure.
To establish and execute a climate reporting roadmap aligned with California’s Climate Bills, connect with CrossCountry Consulting.
Preparing for an exit – whether public or private – requires more than strong financials. It demands a clear, credible story about business performance, told through the right key performance indicators (KPIs). For organizations looking to maximize value, developing and refining KPIs is not a last-minute task; it’s a strategic discipline that starts early and evolves with the business.
Define Outcomes Before Selecting KPIs
Successful KPI development starts by clarifying what matters most to the business and its stakeholders. Instead of tracking every possible metric, focus on those that directly reflect strategic outcomes. Ask: “If these goals are achieved, will customers and stakeholders view the company as successful?” This approach ensures KPIs are relevant and actionable, not just numbers on a dashboard.
- Identify the business’s most important goals.
- Align KPIs with these goals so they communicate value to potential buyers or investors.
- Evaluate which metrics your peer group shares with investors.
- Prioritize clarity and relevance over quantity.
Build KPIs With Accountability and Balance
Once outcomes are clear, translate them into measurable targets. Each KPI should have a single point of accountability, even if it reflects cross-team efforts. This builds trust and transparency qualities that both public investors and private buyers value.
- Assign ownership for every KPI to ensure follow-through.
- Balance leading indicators (predictive) with lagging indicators (results).
- Regularly review and refine KPIs as the business evolves.
Featured Insight
Start Early: Timeline for KPI Readiness
The best time to prepare KPIs for an exit is now. Organizations that operate with “exit-ready” data every day are better positioned to act quickly and confidently when opportunities arise. Waiting until a transaction is imminent can lead to rushed, incomplete, or inconsistent data, potentially eroding value or delaying the process.
- Begin KPI development as soon as exit is a consideration, ideally one to three years in advance.
- Maintain consistency in tracking and reporting to build a credible performance narrative.
- A strong data governance model ensures data remains accurate and consistent for reporting KPIs.
- Use periodic reviews to adapt KPIs as market conditions and business strategies shift.
Customize KPIs for Industry and Growth Stage
While standard financial metrics are essential, industry-specific and non-GAAP (generally accepted accounting principles) KPIs often provide a more accurate picture of value. For example, software companies may highlight customer retention or annual recurring revenue (ARR), while manufacturers might focus on operational efficiency.
- Identify which non-GAAP or industry-specific KPIs matter most for your sector.
- Ensure these metrics are calculated consistently and transparently.
- Stay informed about evolving regulatory expectations, especially as standards for KPI disclosure continue to develop.
Distinguish Between Public and Private Exit KPI Needs
Public and private exits share some KPI requirements, but there are key differences.
| Public exit (IPO) | Private exit (acquisition/PE) |
|---|---|
| – Emphasize transparency and regulatory compliance | – Focus on operational efficiency and growth |
| – Prioritize predictable, sustainable growth metrics | – Highlight cash flow and customer concentration |
| – Prepare for detailed, standardized disclosures | – Tailor KPIs to buyer’s investment thesis |
Public markets demand rigorous, standardized reporting and clear benchmarking against peers. Private buyers often seek more granular, operational KPIs that reveal near-term value-creation potential.
Take Action: Make KPI Development a Strategic Priority
Organizations that treat KPI development as an ongoing, strategic discipline, not a one-time project, are best positioned for a successful exit. Start early, focus on what matters, and build a culture of accountability around your metrics. The result is a compelling, credible story that resonates with buyers and investors, no matter the exit path.
Ready to take the next step in your exit-readiness journey? Contact CrossCountry Consulting today.
The Coupa R43 release delivers powerful updates designed to transform procurement workflows, enhance visibility, and improve efficiency across your organization. Whether you’re focused on simplifying approval workflows, optimizing analytics, or leveraging AI for smarter decision-making, these changes deliver tangible benefits for procurement leaders and their teams.
Want to explore everything you need to know in more detail? Watch our recent webinar.
And for more information on some of the key changes in R43, CrossCountry Consulting’s Coupa implementation and transformation experts have distilled and selected several for users to focus on:
Time-Based Triggers in Process Automator
One of the most exciting updates in R43 is the introduction of time-based events for Process Automator. This enhancement allows you to create time-sensitive workflows, such as sending contracts to sourcing before they expire. With this advanced scheduling capability, procurement teams can automate critical processes rather than relying on manual follow-ups.
Improved Scheduled Reporting
If your team relies on scheduled reports, Coupa R43 has extended the duration before report confirmations expire. For example:
- Daily reports now extend from 45 to 70 days.
- Weekly reports cover 15 weeks instead of 10.
- Monthly reports last for 15 months instead of 10.
These changes reduce the risk of report disruptions and ensure a seamless flow of critical data.
Smoother Approval Workflows
Approval chains have received a critical upgrade to prevent unnecessary escalations. Now, if a valid approver exists within a delegation, the workflow won’t skip approval nodes or get stuck.
Additionally, approvers now see enhanced notification banners, which summarize the key details of pending approvals, including supplier name, requester, total value, and approval dates. This feature allows for quicker, more informed approval decisions.
Enhanced Document Access
Document visibility has been streamlined for mentioned users. When tagging a colleague in a comment, you’ll see a pop-up giving you the option to add them as a document watcher, provided they already have access permissions. This enhancement simplifies collaboration, ensuring everyone involved has the necessary context without infringing on content grouping rules.
Smarter Requisitions With AI
Procurement professionals know that incomplete requisitions can disrupt workflows. With R43, Coupa introduces AI-driven suggestions for missing fields, such as commodity codes, contract details, supplier sites, and payment terms. This means less back-and-forth for approvals and faster requisition submission.
Explore expert Coupa solutions that solve real-world problems
Execute efficient Coupa deployments, enhance procurement and supply chain ROI, and minimize risk with Integration-as-a-Service offerings.
Bulk Upload of Billing Codes
Managing expense reports with split billing lines has been simplified. The ability to bulk upload billing codes means more efficiency when dealing with complex expense allocations. This update is especially useful for teams managing numerous billing accounts or extensive split billing scenarios.
Virtual Payments with Coupa Card
R43 introduces Coupa Card, a new virtual payment feature integrated directly into the Coupa platform. Accessible via the Coupa Mobile app, Coupa Card supports tap-to-pay functionality and is ideal for prepaid expenses like work trips. This feature is currently in limited rollout through the remainder of 2025 and will be generally available in 2026.
Requisition Scheduling for Purchase Orders
Another significant enhancement is the ability to schedule purchase order (PO) issuance directly from requisitions. This ensures that orders are sent at precisely the right time, helping manage inventory levels and avoid premature delivery. Need to adjust? The unschedule feature makes it easy to override original dates as business needs change.
Key Financial Updates
Financial workflows get a performance boost through features such as:
- Daily $2M TransferMate direct debit limits for improved payment visibility and control.
- Autofill for payment instructions, saving time for repeat transactions by copying information from previous successful payments.
These updates aim to streamline financial approvals and minimize processing errors.
Actionable Insights With Enhanced Health Views
Coupa has expanded its health insights functionality across various documents, including POs, invoices, expense reports, and contracts. This provides real-time visibility into where workflows may be experiencing delays, enabling teams to identify and resolve bottlenecks quickly.
Empower Your Team With Coupa R43
The R43 update offers significant upgrades across Coupa’s platform, from smarter automation to improved user experiences and advanced analytics.
Are you ready to harness the full potential of Coupa R43? Contact CrossCountry Consulting today to get started.
Overall transaction volumes in the first half of 2025 remained stagnant, consistent with M&A trends since 2023. While continued interest rate pressure, geopolitical conditions, and increased market uncertainty have materially impacted the market for exits, many shareholders and boards are becoming increasingly eager to divest underperforming assets, rationalize their portfolios, or complete corporate restructuring initiatives.
Maintaining an Exit-Ready Posture
Increased uncertainty has led business leaders to adopt a more conservative approach to deals. As the corporate transaction markets turn, companies should start preparing now so they can act decisively when an exit opportunity arises. Executing a successful carve-out sale, a promising deal option in today’s market, requires meticulous planning and execution with the support of experienced internal resources and third-party advisors.
To deliver on an effective and efficient path to separation, meet necessary milestones, and maximize value, the critical steps below merit careful consideration:
Evaluate Tax and Legal Strategy
- A company’s tax function, or outside advisor, should be engaged to evaluate the tax implications of a proposed carve-out sale ahead of any final decision to proceed with the transaction, as tax impacts may influence deal structure and timing.
- The deal perimeter should also be clearly defined at a legal entity level and mapped to the company’s ERP system to ensure the book and tax bases match appropriately. Establishing these connections beforehand can accelerate the carve-out sale process and ensure the right legal and tax infrastructure is in place before proceeding.
Establish the Separation Management Office (SMO)
- Establishing an SMO ensures effective cross-functional coordination during a critical initiative for the company. Carve-out sale execution is an all-hands-on-deck effort requiring significant expertise in project and change management, stakeholder management, and structured transformation governance.
- An effective SMO also augments the ability of key stakeholders to navigate the deal timeline and assess the impact of cross-functional dependencies. By tackling the day-to-day details of the carve-out sale – proactively removing roadblocks and maintaining change momentum – the SMO allows senior leaders to maintain focus on the underlying business, condensing their involvement to only critical path issues.
- The SMO can empower functional leaders to quickly de-risk roadblocks and deliver value in real time. A strong SMO equips leaders with the tools and information to be agile while they meet the needs and realities of the transaction process.
An SMO manages execution against a structured roadmap, which is a path of matrixed activities across the company and key third parties, both internally and externally, as illustrated below:

Prepare Deal-Basis Financials
- In addition to carve-out financials, deal-basis financials may be required to facilitate due diligence procedures by prospective buyers. Deal-basis financials should be prepared in collaboration with management along with corporate development teams to ensure all due diligence and pro-forma adjustments are identified.
- In addition to quantifying and planning for any stranded costs, organizations should prepare working capital analysis, quality of earnings, and stand-alone costs to reflect the future state of the for-sale business.
Begin Preparation of Carve-Out Financials
- Engage advisors and align with auditors on the approach to carve-out financials and periods required. Note, divestitures can take many forms, with corresponding impacts on financial statements and audit readiness.
- Align on an approach for allocating commingled accounts and entities to the carve-out income statement and balance sheet, and determine if the transaction qualifies as “Significant” for a potential buyer (e.g., requires SEC 3-05 financials).
- Ensure the carve-out results bridge to historical financial information as well as any deal-basis financials for a sale.
- Support basis of presentation with appropriate technical documentation to facilitate an efficient audit of carve-out information.
The base system and management reporting information are the same for all types of carve-out financial information. It’s critical to be able to explain, reconcile, and bridge the various pieces of carve-out information as laid out in the graphic below:

Prepare Operations for Separation
The structure of the sale for the carve-out entity will determine the timeline and complexity of pre-transaction readiness activities. In addition to the expected disentanglement of operations, separating a business intended to operate independently requires a robust systems architecture roadmap, clear process transition strategies, well-defined stand-up activities, and a draft of potential organizational hiring needs.
Alternatively, selling a business intended to be integrated into a buyer’s existing business will require planning and analysis around the RemainCo’s ability and willingness to support Transition Services Agreements (TSAs). Critical activities of focus, regardless of sale type, include:
- Reviewing inter-company entangled services/processes, employee matters, contracts, and systems, and developing separation strategies to limit the impact of the transaction on continuing operations.
- Understanding required novation/disposition and communication requirements related to vendor, customer, and commercial contracts impacted by the transaction.
- Considering employee transfer requirements and communication strategies for both impacted and remaining employees.
- Determining which core business processes require independent operations and which may require a TSA. Additionally, prepare the business to support TSAs and determine scope, cost, service level, duration preferences, and exit criteria.
- Define any stranded costs associated with remaining operations. Companies should review and plan for stranded costs, likely stemming from contracts, technologies, and other shared services like IT infrastructure, marketing, or human resources that are not fully allocated (100%) to the divested or remaining business.
Go to Market
- Engaging the right banking and legal counsel partners is a critical decision for management to facilitate the sales process, prepare the offering memorandum, and support the negotiation of the sales terms and conditions, including TSAs.
- Diligent preparation of roadshow materials, talking points for fireside chats, and seamless management of the data room will further support the due diligence process, allowing the company to support its equity story and increase value in the eyes of potential buyers.
- As part of the Go to Market playbook, many buyers today expect visibility into KPIs, operating trends, and margin drivers of the business. Preparing to tell the exit story will accelerate the diligence process and expand potential
Explore expert Divestiture & Carve-Out solutions that solve real-world problems
Maximize shareholder value, ensure a profitable path forward, and proactively manage complex accounting, risk, and systems implications for RemainCos and NewCos.
Taking the Next Step
CrossCountry Consulting provides a suite of accounting, risk, compliance, systems, and deal expertise that empowers sellers to confidently and profitably navigate divestitures and carve-outs. To establish and execute a divestiture roadmap at your organization, contact CrossCountry Consulting.
This information is for general knowledge and informational purposes only and does not constitute legal or professional advice. A comprehensive spin-off strategy requires careful planning and consideration of various factors, which is why consulting with legal, financial, tax, and other relevant experts is crucial.
Preparing for an exit, such as an IPO, M&A, or other strategic transaction, offers a prime opportunity to optimize your risk and control environment. This is no longer a “check the box” exercise; it’s about using this period as a catalyst to innovate, streamline operations, and build a more resilient, valuable company.
A strong, efficient risk and control framework enhances optionality and value, irrespective of the chosen path:
- Initial Public Offering (IPO): Readiness hinges on demonstrable SOX compliance, adherence to PCAOB audit standards, and rigorous disclosure controls. Early, efficient preparation shortens IPO timelines.
- Mergers & Acquisitions (M&A): Buyers place high value on companies with mature risk management. This can increase deal value and reduce diligence-related delays or price adjustments.
- Future-proofing: Adapt controls for evolving ESG demands and leverage AI for ongoing efficiency enhancements.
Why Optimize? Strategic Value Beyond Compliance
Designing this fit-for-purpose framework is part art: thoughtfully tailoring to your company’s unique risk profile and appetite, operating model, growth stage, and transaction goals. And part science: applying proven methodologies and technologies.
A proactive, tailored approach offers compelling benefits for companies heading toward an exit:
- Accelerate due diligence and boost investor confidence: Efficient, well-documented controls significantly smooth the diligence process for potential buyers, private investors, or underwriters.
- Protect and enhance valuation: Demonstrating operational maturity, reliable financial reporting, and effective risk management directly supports and can increase valuation.
- Catalyze scalable operations and technology adoption: The rigor of reviewing processes and designing controls often drives re-engineering of inefficient workflows and implementation of better technology (ERP, GRC, automation) fit for future growth.
- Drive long-term efficiency and lower compliance costs: Designing controls with automation and integration in mind from the outset substantially lowers the ongoing effort and cost associated with compliance post-exit.
- Ensure reliable financial information: Accurate, timely reporting is vital for stakeholder trust, capital access, and informed strategic decisions.
- Sharpen management focus on key risks: Allows leadership to concentrate efforts on strategic and operational priorities, rather than firefighting control issues.
- Simplify M&A integration: A well-controlled and documented environment makes your company easier for an acquirer to integrate.
Maximize Value: Avoid the Check-Box Mentality
To truly leverage this as a strategic opportunity, shift your mindset:
- Focus decisively on material risks and impactful process improvements.
- Integrate controls seamlessly into redesigned, efficient processes.
- Automate relentlessly where it adds value and reliability.
- Communicate the strategic value and efficiency gains to all stakeholders.
- Aim for a sustainable, efficient control environment that supports business objectives long after the exit.
Core Controls: Efficient and Scalable by Design
Control design starts with several fundamental building blocks that help produce strong corporate governance and enhance valuation at exit. Where possible, these key controls should be designed to be scalable, efficient, and automated:
- Entity-level controls: Include a dynamic risk assessment process and clear “tone at the top.”
- Financial integrity (ICFR-ready): Robust and reliable financial reporting processes should leverage system capabilities and automation. For IPO candidates, early SOX 404 readiness is crucial.
- Preparing for SOX 404(a) and 404(b) compliance requires careful planning and coordination. While both focus on internal controls over financial reporting (ICFR), they differ in scope and level of scrutiny, particularly when transitioning from management’s self-assessment under 404(a) to external auditor attestation under 404(b).
- IT and cyber controls: Implement efficient IT General Controls (ITGCs) and a comprehensive cybersecurity framework, leveraging automation and modern tooling. This is essential for all exits and a consistent PCAOB hot topic.
- Data governance and privacy: Integrate controls efficiently within data lifecycle processes.
- Streamlined operations: Embed effective controls directly within core business processes to ensure operational reliability.
The Approach: Innovative and Efficient Implementation
- Data-driven risk assessment: Utilize process mining, data analytics, and periodic robust risk assessments to rapidly identify and scope material risks and automation opportunities.
- Design for automation and scalability: Embed controls during ERP or key system implementations before go-live to prevent costly rework. Use control design as a trigger for impactful process re-engineering. Evaluate automated functionality as part of this process.
- Leverage technology strategically: Implement scalable GRC tools early for centralized visibility, documentation, and ongoing monitoring. Explore how AI, automation, and analytics can enhance continuous monitoring, fraud detection, and audit procedures.
- Strive for automated assurance: Explore continuous control monitoring (CCM) opportunities to reduce manual testing burdens and gain real-time insights.
Investing in a robust, fit-for-purpose risk and controls program is far more than a compliance exercise – it’s a strategic enabler of business value. For companies pursuing IPOs or other strategic transactions, this investment differentiates them in the market, builds stakeholder trust, and supports a smoother journey through transformational change.
To accelerate exit readiness and build an optimized control environment, contact CrossCountry Consulting.
The latest Sage Intacct R3 release delivers powerful enhancements designed to accelerate finance transformation initiatives while reducing operational complexity. These updates provide CFOs with the strategic tools needed to drive efficiency, enhance decision-making capabilities, and maintain competitive advantage now and in the future.
To see how your organization can maximize the value of your Sage Intacct instance, view the demo of key updates from CrossCountry Consulting’s Sage Intacct implementation experts.
Key Strategic Enhancements in Sage Intacct R3
AI-Powered Operational Intelligence
“Search Help with Copilot” is an AI-powered support feature that makes it faster and easier to find answers in the Sage Intacct Help Center. It reduces repetitive searches and offers intelligent suggestions for related topics, helping users gain deeper insights and work more efficiently.
Enhanced Email Security and Reliability
To ensure continued email delivery through Sage Intacct, all customers using a custom email domain must authenticate and validate their domain with the enhanced email delivery service. This is a required step that improves deliverability, protects against phishing, and aligns with email security best practices. Please have your Sage Intacct administrator work with your email administrator to complete the necessary DNS setup as soon as possible.
Efficient AP Processing Through Delegated Approvals
Advanced delegation capabilities for accounts payable (AP) approvals eliminate bottlenecks in your approval processes. This feature enables continuous operations even when key approvers are unavailable, supporting business continuity while maintaining proper financial controls. The system automatically manages AP bill approval routing, reducing manual intervention and associated delays.
Advanced List Management and Data Visualization
Enhanced list views with split-screen functionality and dynamic column management enable faster data analysis and decision-making. These improvements reduce the time your team spends navigating between screens and provide more intuitive ways to access and analyze critical financial information.
End-to-end Sage Intacct value creation with an expert implementation and advisory partner
Simplify and transform financial management processes, automate key workflows for scale, and generate real-time enterprise insights for faster decision-making.
Streamlined Vendor Payments with MineralTree Integration
Sage Intacct has partnered with MineralTree to offer a more seamless way to pay vendor bills directly. The integration with MineralTree provides a comprehensive solution for payment processing, offering multiple payment methods including ACH, check, and virtual card options. If you use AP Automation, you can add Vendor Payments to your existing automated transaction and approval workflows for a complete end-to-end automation solution.
Simplified Payments and Credit Application from Lists
You can now pay vendors and customers directly from their respective lists, eliminating extra navigation and improving team efficiency. Additionally, credits can also be applied directly from the AR Adjustments and AR Advances lists, further reducing processing time and manual effort for routine transactions.
Accounts Receivable and Cash Flow Optimization
R3 introduces customer refund functionality that streamlines cash management processes and improves working capital efficiency. This enhancement eliminates manual journal entries and provides better audit trails for refund transactions, supporting both operational efficiency and compliance requirements.
New filtering capabilities in AR Ledger reporting enable more sophisticated cash flow analysis, allowing CFOs to quickly identify trends and potential issues across customer groups and payment patterns.
Fixed Assets and Capital Management
Sage Fixed Asset Management enhancements include bulk update capabilities and more flexible historical depreciation handling. These improvements support more efficient asset lifecycle management and provide better data accuracy for financial reporting and tax compliance.
The new cumulative depreciation reporting feature enhances visibility into asset values and depreciation trends, supporting more informed capital allocation decisions.
Smarter Purchasing Workflows and New eProcurement
This release brings key enhancements to purchasing and procurement workflows. You can now consolidate multiple purchasing documents into a single transaction, automate vendor invoice processing without purchase order (PO) matching, and access clearer match tolerance exception histories. The new eProcurement product also simplifies procurement by integrating vendor catalogs and automating purchase order creation directly within Sage Intacct.
Enhanced Contract Management and Flexibility
Users can now reassign dimensions (e.g., department, class) for in-progress contracts with posted transactions, eliminating the need for journal entries. Reversal dates for accounts receivable (AR) payments can also be edited, offering greater flexibility for corrections. These updates exclude contracts with revenue recognition or specific statuses like canceled or renewed.
Improved Project Task Management and Revenue Recognition
Standard tasks can now be added to projects in bulk, reducing manual effort. Enhanced revenue recognition features allow users to preview and update percent-complete schedules before posting, improving control and accuracy. These updates streamline project management and ensure better visibility into financial progress.
Preparing Your Organization for R3 Implementation
System Preparation Steps
- Configuration review: Assess current system settings and identify areas where new features can be implemented.
- User training planning: Develop training programs to ensure team members can leverage new capabilities effectively.
- Process documentation: Update existing procedures to incorporate enhanced workflows.
- Testing protocol: Establish testing procedures for new features before full deployment.
Team Readiness
Successful R3 adoption requires coordinated change management across your finance organization. Focus on identifying power users who can champion new features and provide peer-to-peer training. Consider the impact on existing workflows and plan for gradual feature adoption to minimize disruption.
Next Steps: Strategic Implementation
To fully capitalize on the R3 release benefits, CrossCountry Consulting’s certified Sage Intacct specialists can help you identify which features align with your strategic priorities and develop an implementation roadmap that maximizes value while minimizing disruption.
Contact CrossCountry Consulting today to get started.
Companies that have decided to spin off divisions of their business must quickly execute on other key transaction-readiness initiatives, in close succession or in parallel. To ensure timelines are met and that all business units, processes, and technologies are successfully separated to operate independently, it’s time to achieve the next big milestone on the critical path: preparing the operating model for Day 1.
Establish the Separation Management Office (SMO)
With more transaction expertise and industry-specific practices than traditional PMOs or TMOs, the SMO is the driving force and governing body throughout the spin-off process. When preparing for a Day 1 operating model, the SMO is the most effective channel through which to accomplish this.
The Role of the SMO
An SMO leads effective cross-functional communication and coordination during the divestiture and helps develop/manage project timelines, mitigate risks, and maintain momentum toward a successful transaction.
Key Functions of the SMO
- Project management: Develop and oversee the divestiture timeline and ensure all milestones are met. This includes proactively removing blockers, clearing milestones, and maintaining change momentum.
- Stakeholder management: Enable connection and communication between leaders and key functional and third-party stakeholders to navigate the deal timeline and the impact of cross-functional dependencies.
- Risk mitigation: Identify and address potential risks and issues in real time, empowering functional leaders to mitigate risks and issues quickly. The SMO also identifies value-driving synergies, which can increase project velocity and accelerate time-to-market.
- Resourcing: Leading up to the spin closing date, critical staff will be wearing many hats on top of their daily responsibilities. As such, the reallocation of resources and priorities will be critical to ensuring consistent team performance before, during, and after separation. Evaluate the need to support these teams with additional resources to enable them to successfully execute separation activities and meet transaction deadlines (e.g., HR, IT, Treasury).
Featured Insight
Design the Day 1 Operating Model
Designing a robust Day 1 operating model ensures both the SpinCo and RemainCo can operate independently and successfully post-separation. Here’s what the SMO should be targeting:
Key Components of the Day 1 Operating Model
- Target operating model: Determine the required systems, processes, and policies (e.g., benefits plans, insurance, etc.) to support the standalone business, including the standalone cost budget. This plan will chart the future success of the SpinCo, so it’s imperative that months of Day 1 preparation are conducted ahead of the official separation.
- Inter-company entanglements: Review inter-company entangled services/processes, employee matters, contracts, and systems, and establish disposition and cut-over plans to take action on required novation/disposition and communication requirements related to vendor, customer, and commercial contracts.
- Employee transfers: Create a robust employee transfer strategy and clearly document and communicate this strategy to all impacted personnel in multiple formats (via email, individual meetings, company town halls, etc.). The strategy should address transfer mechanisms, handling of compensation and benefits discrepancies, processing of visas and work permits, and the continuity of HR systems.
- Transition Services Agreements (TSAs): Define which activities must be covered by a TSA and for how long, such as IT, real estate, HR, and accounting services in the event that separation before day 1 is not achievable. TSAs should be developed at a granular level, with specific activities, cost to deliver, and a strategy/timeline to exit the TSA.
- Change management: Implement robust change management activities to ensure the NewCo is prepared to operate independently on Day 1, including stakeholder impact assessments and training plans.
With an effective SMO, you can build a structured, efficient spin-off process while focusing on a comprehensive Day 1 operating model. This model sets the foundation for future success while minimizing disruptions and maximizing value.
Taking the Next Step
CrossCountry Consulting provides a suite of accounting, risk, compliance, systems, and deal expertise that empowers RemainCos and NewCos to confidently and profitably navigate a spin-off. To establish and execute a divestiture roadmap at your organization, contact CrossCountry Consulting.
This information is for general knowledge and informational purposes only and does not constitute legal or professional advice. A comprehensive spin-off strategy requires careful planning and consideration of various factors, which is why consulting with legal, financial, tax, and other relevant experts is crucial.
Every business runs on cash generation. But what if your process is quietly draining profits, delaying deals, and frustrating customers?
The lead-to-cash (L2C) process – covering everything from customer identification, opportunity development and refinement, quoting, contracting, billing, revenue recognition, collections, and credits/refunds/concessions – is the heart of how companies manage and grow their revenue, profitability, and cash flow. It should be a seamless flow, yet too many companies are stuck with broken workflows, manual bottlenecks, and disconnected data.
The result? Lost opportunities. Slower growth. Lower margins.
The Hidden Challenges Holding Companies Back
L2C may be the most important business process because it touches every operational department and impacts the bottom line. Forward-thinking organizations are embracing advanced technologies to streamline workflows, from customer acquisition to customer billing and collections, thus accelerating and maximizing revenue realization.
But despite major advancements in automation, businesses continue to struggle with inefficient lead-to-cash workflows.
- Manual workflows and “death by a thousand spreadsheets” have become the norm, slowing down invoicing and creating data confusion. Fragmented CRM, CPQ, operating systems, ERP, billing platforms, and order management systems prevent smooth operations, leading to time-consuming billing issues – especially when handling complex pricing structures and varied contract terms.
- Collections often lag due to inaccurate AR aging reports and detail, making it difficult to track outstanding balances and enforce timely payments. Meanwhile, customer frustration grows as errors in quoting, billing, and contract execution create friction, eroding trust and driving churn.
- Many companies develop processes that don’t scale. They work well initially, only to realize later that their systems can’t keep pace with growth. For example, SaaS companies increasingly have usage-based products that make it more complex to integrate operating systems that were not developed to focus on back-end reporting and connecting to adjacent systems. Compliance risks pile up, auditability becomes a headache, and operational inefficiencies threaten long-term success.
So, how are leading companies turning this chaos into cash flow?
The Blueprint for Lead-to-Cash Success
Leading organizations aren’t just fixing problems – they’re reinventing the way revenue flows through the business. A key enabler is standardization: standardizing contracts, processes, metrics, and workflows. It all starts with a foundational data strategy, ensuring clarity in key metrics, governance frameworks, and integration across platforms.
From there, a fully integrated system architecture connects CRM, CPQ, CLM, OMS, billing, and ERP, leveraging solutions like Salesforce, NetSuite, and Coupa alongside middleware like Fivetran and Tray.ai to enable real-time data exchange and automated workflows.

Touchless contracting and billing are quickly becoming industry standard. Rather than manual negotiations, companies are shifting to automated agreements, enabling customers to digitally accept standard contract terms and be billed directly through ACH or credit card payments.
Meanwhile, centralized data warehouses like Snowflake and Databricks are reshaping analytics and reporting. Businesses can aggregate historical and real-time data effortlessly, empowering CFOs with insights that drive smarter forecasting and customer strategies. The data warehouse is the central repository to collect subscription and user data for SaaS, or fulfillment data for complex manufacturing and inventory, and facilitates the integration between other systems, as the warehouse can “normalize” the data to the format required.
Finally, deal governance (“deal desks”) ensures companies minimize excessive customizations and enforce standardized pricing and approvals, streamlining negotiations and reducing complexity.
The Business Impact: Why Automation is a Game Changer
By embracing automation, CFOs are transforming L2C processes into revenue-generating powerhouses. The results?
- Faster revenue recognition: Automating journal entries and reducing manual accounting work.
- Greater sales efficiency: Freeing up reps to focus on customers instead of administrative tasks.
- More accurate forecasting: Giving FP&A teams better visibility into customer trends and financial projections.
- Enhanced customer experience: Eliminating billing errors and seamless contract execution.
AI: The Future of Lead-to-Cash Optimization
Artificial intelligence is revolutionizing the way companies manage their revenue processes. AI-driven pricing models suggest optimal discounts based on customer behavior, while machine learning algorithms predict payment risks, prompting proactive collection strategies.
AI-powered contract data extraction identifies key renewal clauses and compliance requirements, helping businesses optimize revenue streams and reduce financial risk. And as predictive analytics grow more sophisticated, finance leaders can anticipate demand trends, forecast revenue with pinpoint accuracy, and automate invoicing like never before.
How We Can Help
At CrossCountry Consulting, we specialize in transforming lead-to-cash workflows through some of the following ways:
- Accelerated future-state design and roadmap (setting the stage for transformation): Leveraging CrossCountry’s rapid assessment methodology, gaps are identified in current-state process flows, future-state workflows are designed, a roadmap sets the stage for transformation, and stakeholders quickly align.
- Quick-win reporting and analytics (generate immediate cash and value): Utilize data transformation tools (e.g., Alteryx) to link data across systems regardless of current architectural gaps and build live dashboards (e.g., billing amounts, AR) to find missing dollars and facilitate collections.

- End-to-end system and data architecture integration (automate revenue recognition): Implement technologies, optimize configurations, or integrate core systems and workflows (e.g., CRM, CLM, Billing, ERP) through built-in connectors or middleware, and automate revenue recognition calculations and logic.
- Role and organization optimization (enable future scalability): Clarify roles and responsibilities across the new process, optimize and centralize positions as applicable, train users in new ways of working, manage change, and institutionalize documentation.
Ready to optimize your process and accelerate cash flow? Contact CrossCountry Consulting today.
As firms strive to grow Assets Under Management (AUM) without a proportional increase in headcount, the relationship and value received from their third-party administrator (TPA) becomes a key consideration for future growth.
Many firms are reassessing their current TPA relationships against potential alternate providers. It’s imperative that firms approach this assessment strategically, considering a selection and migration process. Key considerations to keep top of mind are included below.
Key Trends and Challenges with TPAs
The TPA technology landscape is undergoing significant evolution, driven by several key trends:
- Focus on integration and interoperability: Seamless integration between the TPA’s systems and the asset manager’s internal technology infrastructure is make or break, as everyone wants access to their data. This ensures efficient data flow, reduces reconciliation efforts that can slow financial reporting cycles, and provides a holistic view of operations.
- Focus on data and analytics: Asset managers require TPAs that can provide robust data analytics capabilities, offering deeper, context-aware insights into fund performance, investor behavior, and operational efficiency. This includes completing or assisting managers with standard compliance reporting, such as Form ADV or Form PF, through automated reporting engines.
- Increased demand for automation: Asset managers expect greater automation in core operational processes handled by TPAs to enhance efficiency, reduce manual errors, and lower costs. In addition to core fund accounting, asset managers are seeking automated and AI-enabled solutions to streamline issuing quarterly Partner Capital Statements (PCAP) and the processing and dissemination of Capital Calls and Distributions.
- AI innovation: To maximize the cost benefit of the relationship, many firms are looking for partners who are using automation and GenAI to increase accuracy and reduce manual reconciliation efforts. Intelligent document processing (IDP) – through the combined power of optical character recognition (OCR), natural language processing (NLP), and computer vision – enhances data extraction, source linking, and auditability. AI can also support anomaly detection, report generation, and more.
- Cybersecurity and data privacy: With increasing cyber threats and stringent data privacy regulations, asset managers are prioritizing TPAs with robust security protocols and data protection measures.
These trends present both opportunities and challenges. While TPAs have scaled with automation and intelligence tools, selecting the right provider requires a formal and deliberate evaluation approach.
TPAs in the Market
There’s a rich market of TPAs, each with its own strengths and focus areas. These providers can broadly be categorized as:
- End-to-end providers: These comprehensive providers offer a wide array of functionalities, covering core administration tasks, investor relations, accounting, reporting, treasury, and compliance. They aim to provide a unified platform for managing fund operations across all strategies.
- Specialized providers: Some providers choose to focus on specific fund strategies (e.g., PE, Credit) or client size based on AUM (e.g., <$10B). Asset managers might benefit from a more specialized approach these providers offer and consider their solutions to complement existing TPA arrangements or address specific pain points.
To recoup the investment, asset managers must thoroughly research the market and identify providers that align with their specific needs and operational model.
Selecting the Right TPA
TPA selection involves assessing the overall service model, operational capabilities, and the underlying technology platforms. For a systematic evaluation of potential providers and alignment with the asset manager’s long-term goals, consider the following:
- Defining business and technology requirements: Clearly articulate the firm’s strategic objectives, operational needs, service needs, and specific technology requirements. This includes identifying critical capabilities the TPA must deliver, such as data accessibility, timely reporting, and integrations through their technology platform.
- Developing a Request for Proposal (RFP): Create a tailored RFP that captures both functional and service-level requirements. The RFP template is a vital tool for ensuring potential providers submit their proposals in a way that allows for efficient evaluation of capabilities and alignment with the organization’s requirements. This ensures vendors present their offerings, including platform capabilities, service model, and support structure, in a standardized approach that facilitates a fair and meaningful comparison.
- Evaluating potential providers: Utilize a consistent scoring matrix to evaluate, assess, and compare the capabilities and performance of TPAs. This tool transparently evaluates TPAs, their operational model, platform scalability, client service approach, fees, and ability to support future growth and regulatory change to ensure the selected provider aligns with the company’s operational needs.
- Conducting comprehensive due diligence: Thoroughly assess the shortlisted providers’ technological infrastructure, security protocols, service-level performance, and client references. This step ensures the vendor’s platform is not only technically sound but also operationally resilient.
- Onboarding and transition planning: Ensure the selected provider has a proven transition roadmap and project management approach that includes onboarding milestones, platform configuration, integration planning, and finalization of contract details. Early collaboration with the fund administrator ensures a smooth path to go-live and long-term partnership success.
The selection process flows into the migration phase to ensure the complete alignment of people, process, technology, and data within the TPA environment.

Transitioning to a New TPA
A comprehensive migration plan outlining key milestones, delivery workstreams, activities, tasks, and roles for the TPA selection and implementation is essential for a successful transition. Key considerations include:
- Data migration strategy: Develop a comprehensive data migration plan for securely and accurately transferring data from the incumbent provider or internal systems to the new TPA technology platform. This includes data mapping, cleansing, validation, and governance to ensure integrity throughout the migration process.
- Integration planning: Coordinate closely with the incoming TPA to align on integration points with the asset manager’s internal systems, ensuring seamless data flow and operational continuity.
- Testing and validation: Conduct thorough testing of the new system and migrated data to ensure accuracy and functionality.
- Training and change management: Equip internal teams with the knowledge and tools to work effectively with the new TPA, their systems, and processes. Effective and proactive change management strategies are essential to drive adoption and minimize disruption.
- Project management: Establish a project governance structure with clearly defined roles and responsibilities across internal teams and the incoming administrator. Strong program and change management practices are critical to enable teams to navigate the complexities of the implementation.
Migration timelines and activities may vary based on the asset manager’s operating model and the complexity of services being transitioned.
TPA Next Steps
Selecting and onboarding the right TPA is a strategic imperative for asset management firms seeking to enhance operational efficiency, improve data insights, and navigate the evolving regulatory landscape. CrossCountry Consulting stands ready to guide asset management firms through this transition, ensuring a smooth selection process and successful migration of a TPA that aligns with unique needs and long-term business goals.
To get started, contact CrossCountry Consulting today.
From the early stages of spin planning, the CFO and finance team must be engaged in five core financial reporting areas to enable long-term spin-off success:
- Preparation of carve-out financials: These documents will form the “F-pages” within the Form-10 registration statement. Annual periods will be subject to audit procedures.
- Carve-out audit considerations: There are important distinctions from the parent audit that must be strategically addressed in relation to a spin.
- Assembling the Form-10: Subject to SEC review, compilation of the Form 10 involves close stakeholder coordination to appropriately present the SpinCo to investors.
- Investor roadshow process: The investor roadshow process will include financial information, which often differs in certain areas from what was presented in SEC filings, and a linkage between the financial information is critical to manage.
- Post-spin reporting matters: Plan for the post-spin SEC reporting requirements of both the SpinCo and RemainCo.
Preparing for a spin-off? Each of these critical finance activities is discussed in detail below:
1. Preparation of Carve-Out Financials
- Deal perimeter alignment: Close collaboration with management, corporate development teams, and strategic advisors helps inform how historical financial information will be compiled in a manner consistent with the deal perimeter of SpinCo.
- Carve-out methodology: Consider the level of complexity in compiling the carve-out financial information and determine the methodology for compiling the financial information of the SpinCo by evaluating the following:
- Approach for specific identification of assets, liabilities, revenues, and expenses related to the carve-out entity within the company’s ERP system.
- Identification of commingled accounts and application of appropriate allocation methodologies to each account, which is consistent with guidance from Big Four accounting firms (e.g., headcount, revenue).
- Carefully consider historical audit differences, which may be material to the carve-out financial statements.
- Reconciling bridges: Ensure carve-out results bridge to historical financial information. Expect to explain, reconcile, and bridge various pieces of carve-out information.
2. Carve-Out Audit Considerations
- Auditor liaison: Involve auditors early in the process to establish alignment on the basis of presentation, carve-out approach, and cadence of touchpoints to proactively address audit issues.
- Technical documentation: Support the basis of presentation with appropriate technical documentation and audit-ready bridge files for the carve-out to facilitate an efficient audit. Separate analysis related to impairment, segments, intercompany, stock compensation, and other areas specific to the carve-out financials will likely be required for the audit file.
- Additional resources: Evaluate the need for dedicated audit assistance to ensure the carve-out audit is completed in accordance with the deal timeline. Subsidiaries may require additional support when subject to different audit requirements and materiality for a carve-out audit, further requiring hands-on expertise.
3. Assembling the Form 10
- Ownership: The Form-10, similar to other registration statements, requires input from a range of stakeholders and external parties. Assigning ownership of each section (and in some cases subsections) can help ensure a complete document is prepared efficiently and by the most appropriate stakeholder(s).
- MD&A: Preparation of a Management, Discussion & Analysis (MD&A) section will be required for inclusion in the Form-10. While the Parent’s MD&A may be an appropriate starting point, the specific dynamics of the SpinCo’s business must be reflected to present and discuss period-over-period variances accurately. Additionally, it’s common for SpinCo MD&As to include more granular information on variances compared to a Parent’s MD&A given the document is subject to SEC review.
- Pro forma statements: Compile adjustments to present pro forma income statements and balance sheets under Regulation S-X, Article 11. Preparers must be aware of the different classifications of potential pro-forma adjustments (e.g., autonomous entity adjustments), so SpinCo pro-formas are consistent with SEC guidelines, including disclosures around standalone and one-time costs.
- Peer benchmarking: Review and understand recently prepared Form-10s to gain an understanding of the structure of the document and the standard disclosures contained within. Performing this review before preparing the SpinCo’s Form-10 can ensure broad awareness among stakeholders of the information required.
- SEC comments: Maintain vigilance for potential areas of SEC comment within the Form-10 to facilitate a more efficient comment letter response process. Reviewing published SEC comment letter trends and comment letters issued to peer companies can provide valuable insights. Proper planning will contemplate the anticipated SEC review process and timing, and the periods required for amendments.
By preparing accurate and comprehensive financials, supported by a seamless audit process, you can enhance the attractiveness of the Spin-Off and ensure a smooth transaction process.
Featured Insight
4. Investor Roadshow Process
- Roadshow process: The investor roadshow process is an opportunity for the management team to communicate the value of the SpinCo to potential investors. The materials will include financial information, including historical and projected.
- Linkage to SEC filings: The financial information included in the roadshow materials will often have certain differences compared to what’s presented in SEC filings, including Non-GAAP presentations of historical information and projections. It’s critical to have a linkage to what’s reported in SEC filings and the projections based on historical information.
- Communication: The team involved in preparing the roadshow materials will include various stakeholders across the company and its external advisors. Communication and project management are crucial for consistent messaging and managing the required inputs and outputs.
5. Post-Spin Reporting Matters
- RemainCo: RemainCo will have reporting requirements as a result of the spin-off, including discontinued operations and Form 8-K reporting after the spin-off.
- SpinCo: SpinCo must maintain quarterly SEC filings as an independent public company after the effective date of the spin-off (Form 10-Q and Form 10-K).
Taking the Next Step
CrossCountry Consulting provides a suite of accounting, risk, compliance, systems, and deal expertise that empowers RemainCos and SpinCos to confidently and profitably navigate a spin-off. To establish and execute a divestiture roadmap at your organization, contact CrossCountry Consulting.
This information is for general knowledge and informational purposes only and does not constitute legal or professional advice. A comprehensive spin-off strategy requires careful planning and consideration of various factors, which is why consulting with legal, financial, tax, and other relevant experts is crucial.
It’s hard to believe that July 2025 marks the 23-year anniversary of the Sarbanes-Oxley Act (SOX).
On the heels of the dot-com boom in the early 2000s, companies changed the way they operated and incentivized senior leaders: Financial fraud became rampant.
Flagship financial fraud cases of the era included Enron (overstated revenue and concealed debt obligations), WorldCom (inflated earnings by $11 billion), and Tyco (inflated company income). These events helped catalyze more rigorous financial reporting and internal control requirements created under SOX.
The bipartisan law, sponsored by U.S. Senator Paul Sarbanes and U.S. Congressperson Michael Oxley, has had lasting impacts on public companies of all sizes, helping to create strong control environments, standardize processes, and mitigate financial reporting risks.
SOX Milestones
Below is a timeline of some of the biggest milestones related to the evolution of SOX over the past 23 years:

While many organizations and their auditors have grown accustomed to annual compliance requirements, they must still remain vigilant toward further rule changes and emerging trends. SOX programs must adequately provide insight to stakeholders and regulators as the market and regulatory landscape continue to evolve.
SOX Today and Tomorrow
As organizations consider going public and seek to establish a SOX program of their own, numerous, more recent trends are influencing the design, scope, and urgency of reporting standards and control environments.
Some of the most prominent emerging factors include:
Innovation: AI, Automation, and Data Analytics
In tight labor markets, organizations are increasingly leveraging innovative technologies to enhance efficiency and focus on value-added activities. Automation, data analytics, and, more recently, AI transform how companies and auditors manage processes and controls. For example, financial reporting tools and governance, risk, and compliance (GRC) platforms use robotic process automation (RPA), data analytics, and AI-driven solutions to reduce manual errors, streamline evidence collection, and proactively detect fraud and anomalies.
These technologies enable SOX teams to analyze larger volumes of structured and unstructured data, improve real-time monitoring, and optimize the efficacy of SOX testing programs. By reducing the overall cost of compliance and minimizing the burden of audit seasons, these advancements empower professionals to concentrate on tasks that require expert judgment and strategic insight.
Environmental, Social, and Governance (ESG)
More public companies than ever are disclosing sustainability data, both voluntarily and for regulatory purposes. This enhanced reporting requires companies to design and implement relevant financial reporting controls over ESG data, much of which is non-financial data outside of the general ledger. As companies incorporate testing of their ESG-related data into their overall SOX program, these new disclosures must stand up to regulatory scrutiny.
Cybersecurity Requirements
The rapid evolution of technology continues to shape the scope and rigor of SOX compliance. In 2024, the SEC adopted enhanced cybersecurity disclosure rules that are now fully in effect for public companies. These rules require:
- Disclosure of material cybersecurity incidents within four business days via Form 8-K.
- Annual reporting on cybersecurity risk management, strategy, and governance under Regulation S-K Item 106.
- Clear articulation of the board’s oversight and management’s role in assessing and mitigating cyber risks.
As a result, cybersecurity controls are now being evaluated alongside traditional IT general controls (ITGC) during SOX testing. Companies must ensure their incident response protocols, data governance frameworks, and cyber risk assessments are operationally sound and aligned with financial reporting requirements. The SEC’s enforcement actions underscore the importance of accurate and timely cyber disclosures, making cybersecurity a central pillar of modern SOX compliance.
For SOX cybersecurity compliance best practices, start here:
- Continuous monitoring of controls and risks.
- Automated identity and access governance.
- Zero-trust architectures for sensitive systems.
- Active incident response drills (e.g., red team exercises focused on financial systems).
- Ongoing vendor risk reviews and robust documentation of security controls and incidents.
A Profitable, Compliant Future
Twenty-three years later, the legacy of SOX stands as a powerful testament to the enduring value of transparency, accuracy, and accountability in financial reporting. While regulatory requirements will continue to evolve, the core principles that safeguard trust in our capital markets remain as vital and unshakeable as ever.
For expert SOX advisory support, contact CrossCountry Consulting.
An effective strategy to generate shareholder value, streamline operations, and focus on core competencies can be accomplished through a corporate spin-off. Recent headlines included planned spin-offs at Honeywell, Medtronic, and Warner Bros. Discovery as these companies look to create agile businesses focused on revenue growth and earnings leverage.
A spin-off is a type of corporate restructuring in which a company creates a new, independent company by separating part of its operations, assets, or divisions. The new entity, often referred to as a “SpinCo,” builds its own management team and operates independently from the parent company, known as a “RemainCo.” Spin-offs can be executed in a tax-free manner if structured and executed properly.
Spin-offs are often used to enhance shareholder value and provide greater strategic flexibility, including capital allocation, for both the parent company and the new entity.
A Closer Look at the Market for Spins
Historically, the “sum of the parts” value pre-spin often exceeds the parent’s consolidated value over an 18-24 month period. Companies facing activist investor pressure or regulatory scrutiny may find spin-offs an attractive option. Similarly, companies hoping to unlock new value creation by separating under-performing assets from value-creating assets may be able to achieve faster growth and return to the types of activities they do best.
In recent months, industry experts and market participants have signaled 2025 as the “year of the spinoff,” reflecting the increasing value of U.S. corporate spin-offs and the size of established corporations that have displayed interest in undertaking a spin this year.
- Key characteristics of a spin-off: The new company operates independently with its own management and decision-making processes.
- Ownership: Shareholders of the parent company receive shares in the new company, maintaining their investment in both entities.
- Strategic flexibility: The spin-off allows both the parent company and the new entity to focus on their core businesses and strategic goals.
- Market value: Spin-offs can unlock value by allowing the market to better assess and value the separated entities individually.
Benefits of a Spin-Off
- Enhanced focus: Both companies can concentrate on their specific business areas without the distractions and capital allocation competition of non-core operations.
- Improved performance: Independent management teams, with specific industry skillsets, can drive performance improvements tailored to their entity’s business needs.
- Increased transparency: Investors gain clearer insights into the financial health and performance of each entity.
Navigating the Spin-Off Process
To gain clarity on an effective and efficient path to separation, achieve key milestones throughout the process, and prepare to operate successfully post-close, explore the critical steps below:

Taking the Next Step
A successful spin-off requires meticulous planning and execution, with the support of experienced RemainCo and SpinCo stakeholders and third-party providers.
CrossCountry Consulting provides a suite of accounting, risk, compliance, systems, and deal expertise that empowers RemainCos and SpinCos to confidently and profitably navigate a spin-off. To establish and execute a divestiture roadmap at your organization, contact CrossCountry Consulting.
This information is for general knowledge and informational purposes only and does not constitute legal or professional advice.
Companies are facing unprecedented uncertainty and challenges in the market, driven by a combination of macroeconomic, strategic, and regulatory factors. These forces are prompting executives to more closely manage and evaluate their portfolios, including divesting non-core assets.
Considering a divestiture in the near future? Here’s what’s top of mind for today’s leaders:
- Portfolio management: The most successful companies actively analyze their portfolio, which may result in divesting non-core or underperforming assets.
- Macroeconomics and geopolitics: Rising interest rates, geopolitical tensions, tariff volatility, and changes in valuations are motivating companies to consider portfolio optimization. Divestitures are a key path to optimizing capital allocation strategies and focusing on core capabilities.
- Regulatory and political pressures: Regulatory scrutiny around mergers and acquisitions (M&A) may require divestitures to ease antitrust concerns.
Finding and Executing the Right Exit Opportunity
Amid a robust market for companies considering divestitures, including tax-free spin-offs, split-offs, carve-outs, asset sales, joint ventures, and Reverse Morris Trust exits, there are an array of critical topics and decisions to take into account. Decisions today will set the future trajectory of the transaction roadmap and influence ultimate exit value.
Explore expert Divestiture & Carve-Out solutions that solve real-world problems
Maximize shareholder value, ensure a profitable path forward, and proactively manage complex accounting, risk, and systems implications for RemainCos and NewCos.
Based on market analysis, client conversations, and decades of experience, CrossCountry Consulting’s team of Divestiture & Carve-Outs experts has compiled a series of core themes and discussion points that are integral to companies exploring divestitures as an exit strategy:
- Mastering the Spin: Understanding Your GTM Path: Explore strategies for effectively navigating a corporate spin-off. Understand recent market dynamics, benefits, and a roadmap for success.
- Mastering the Spin: 5 Finance Focus Areas During a Separation: Understand the steps involved in preparing carve-out financial statements, pro-forma models, and filing with the SEC. Gain insights into audit requirements and how to ensure a smooth audit process for carve-out financials.
- Mastering the Spin: Day 1 Operational Readiness: Discover the importance of a separation management office (SMO) in managing cross-functional communication and driving the divestiture process forward. Explore a proven approach to creating a robust operating model that supports the standalone business post-separation, including considerations for Transition Services Agreements (TSAs).
- Mastering the Carve-Out Sale: Create a comprehensive roadmap for successfully navigating the complexities of carve-out sales, with valuable insights and practical steps for a smooth and profitable transition. From strategic planning to valuation and financial analysis, learn how to ready your organization for Day 1 and beyond.
- Navigating Employee Entanglements in Divestitures and Demergers: Prepare for complex transitions that must factor in legal compliance, effective communication, talent retention plans, compensation structures, cultural integration, and strategic decisions on legal entities. Learn more about the crucial activities required for smooth transitions and operational excellence.
- A Seller’s Guide to Crafting Effective Transition Services Agreements: Ensure a smooth business transition with an effective TSA. Gain insight into the TSA process, best practices, how to minimize risks, and how to maintain business continuity throughout the transition process.
Maximize Exit Value
Aiming to leverage a divestment strategy that’s right for your organization and its corporate objectives?
CrossCountry Consulting provides a suite of accounting, risk, compliance, systems, and deal expertise that empowers RemainCos and SpinCos to confidently and profitably navigate a divestiture. To establish and execute a divestiture roadmap at your organization and to stay current on the latest valuation-enhancing strategies, contact CrossCountry Consulting.
This information is for general knowledge and informational purposes only and does not constitute legal or professional advice.
Asset managers are under increasing pressure to harness the power of artificial intelligence – not just to stay competitive, but to lead. Yet the journey from experimentation to enterprise-wide transformation is anything but straightforward.
At CrossCountry Consulting, we’ve seen firsthand how asset managers can move beyond point solutions and pilot projects to build scalable, strategic AI capabilities. Here’s what we’ve learned from working with leading firms across the industry.
AI Maturity Is a Journey, Not a Destination
Many firms begin their AI journey to increase productivity, crafting specific use cases to address manual processes, fragmented data, and isolated tools. However, to unlock true value, organizations must evolve toward a proactive, enterprise-wide AI strategy. This means embedding AI into core business processes, aligning it with strategic goals, and driving continuous improvement with human-in-the-loop models and integrated data platforms.
Organizations have seen implementation success by using an AI strategy maturity model, which outlines five stages of evolution that reflect increasing levels of automation, data trust, and strategic alignment: Performed → Managed → Defined → Measured → Optimized

AI Roadblocks Are Real, But So Are Opportunities
AI adoption in asset management presents its own set of challenges. From legacy systems and fragmented data to regulatory uncertainty and ethical concerns, firms must navigate a complex ecosystem. Key barriers include:
- Integration with legacy technologies that lack the power or flexibility to support AI tools.
- Data immaturity is often present in environments with siloed systems and inconsistent governance.
- Security and privacy risks are heightened and must be addressed when deploying generative AI and LLMs.
- Cultural resistance occurs as employees become fearful of job displacement and place low trust in AI outputs.
But these challenges also present opportunities. With the right strategy, firms can modernize infrastructure, enhance controls, and generate operational efficiencies that drive real business outcomes.
A Structured Approach to AI Transformation
CrossCountry’s approach to AI maturity is grounded in practical, phased execution:
- Discovery: Assess current tools, governance, infrastructure, and readiness.
- Prioritize and prepare: Define use cases, evaluate vendors, and align with business strategy.
- Deploy: Implement pilots, operationalize governance, and scale based on impact.
This structured roadmap ensures AI investments are not only technically sound but also strategically aligned and culturally adopted.
Explore strategic AI solutions that solve real-world problems
Align your AI strategy to business drivers, implement purpose-fit systems, and enable predictive analytics capabilities with the right governance, use cases, and technologies.
Real-World AI Use Cases in Private Markets
AI is already delivering value across the asset management value chain. Some high-impact use cases include:
- Unstructured data extraction for fund documents and due diligence.
- Generative analytics to visualize trends and support decision-making.
- Deal sourcing through automated research and third-party data ingestion.
- Compliance and legal reviews that accelerate contract analysis and reduce risk.
- Relationship intelligence that personalizes LP communications and enhances CRM insights.
These applications demonstrate that AI is not just a back-office tool. It’s a front-line enabler of growth, efficiency, and insight.
Next Steps With AI
AI is no longer a futuristic concept – it’s a present-day imperative. For asset managers, the question is no longer if to adopt AI, but how to do so in a way that’s scalable, secure, and strategically aligned.
To maximize the value AI delivers to your organization, contact CrossCountry Consulting today.
Since 2002, the Sarbanes-Oxley Act (SOX) has been the cornerstone of corporate accountability, ensuring robust internal controls over financial reporting. As business priorities evolved and pressures mounted, many SOX programs quietly shifted into autopilot. Consequently, internal controls became outdated, inefficient, and misaligned with today’s strategic goals. The result? Governance is a burden rather than a value driver.
Why a Future-Ready SOX Program Matters More Than Ever
Today, transformation isn’t a choice – it’s a necessity. The traditional approach to SOX compliance – characterized by extensive manual testing and documentation – is proving unsustainable in a world of AI and automation. Modernizing your SOX program ensures it remains relevant, agile, and future-ready while aligning with strategic priorities.
To do more than just check compliance boxes, a SOX program should:
- Align with strategic priorities: Ensuring that internal controls support – not hinder – business agility and growth.
- Drive operational efficiency: Leveraging automation, analytics, AI, and risk-based approaches to reduce manual effort and increase insight.
- Enhance stakeholder confidence: Demonstrating a proactive commitment to transparency, accountability, and long-term value creation.
- Support resilience and adaptability: Enabling organizations to respond quickly to emerging risks and regulatory changes.
By reimagining your SOX program as a strategic enabler, you can unlock new value, reduce risk, and position your organization for sustainable success.
Important Strategies for Updating Your SOX Program
Industry leaders have identified several key strategies for optimizing SOX compliance programs. Here are four strategies to help you transform your SOX compliance into a forward-looking, value-driven function:
1. Modernize the Risk Assessment and Optimize Control Structure
A critical component of optimizing your SOX program is right-sizing it to focus resources on the most significant risks. The risk assessment process involves validating your SOX scope aligns with the company’s most significant risks and prioritizing testing and remediation efforts based on the severity and likelihood of risks. Risk assessment factors for modernization should include:
- Back to basics: Quantitative and qualitative risk factors remain the foundation on which the SOX risk assessment should be built. These factors – such as financial statement impact (e.g., materiality), complexity, volume of transactions, and susceptibility to fraud – help ensure the control environment is aligned with the areas of greatest exposure and business relevance. Aligning with the external auditor on this view will ensure control assessments are focused on the most significant areas of the company.
- Cybersecurity and data privacy: As cyber threats and data breaches become increasingly sophisticated, it’s crucial for organizations to integrate cybersecurity and data privacy assessments into their SOX programs. This includes evaluating IT general controls (ITGCs) related to access management, change management, and data integrity, which are foundational to protecting financial systems and sensitive information. Additionally, ensure your IT and Legal teams have sufficiently defined “material breach” for your organization and have a clear process for assessing whether a cyber breach needs to be disclosed.
- Incorporate data analytics: Leveraging advanced analytics can significantly enhance the detection and identification of anomalies in financial transactions. By incorporating data analytics into the SOX program, organizations gain deeper insights, improve oversight, and make informed decisions based on data-driven findings. Common areas where data analytics can be leveraged include user access reviews, change management, Order-to-Cash and Procure-to-Pay cycles, and manual journal entries.
Once you’ve ensured your focus is on the most material risks and accounts, the next step is to streamline your control environment. This involves reducing the number of key controls by identifying redundancies and reclassifying those that are no longer critical. Over time, key controls often accumulate in response to specific issues, leading to an over-engineered control framework. Each year, management should critically assess whether each key control is truly essential and confirm the associated risk isn’t already effectively mitigated by other controls. Additionally, organizations should prioritize replacing manual controls with automated ones wherever feasible, as automation enhances consistency, reduces human error, and improves testing efficiency.
2. Technology and Automation
One of the most impactful opportunities to optimize a SOX program lies in leveraging technology and automation across both control execution and testing. The integration of AI can significantly enhance multiple stages of the SOX lifecycle, such as identifying transaction anomalies during risk assessments, automating control testing documentation, and compiling results for streamlined SOX reporting. By embedding AI and automation, organizations can reallocate resources from repetitive, manual tasks to more strategic, value-added analysis.
- In management’s control environment, organizations are focusing on designing and implementing automated application controls within enterprise systems to reduce reliance on manual controls. These embedded controls – such as automated approval workflows, system-enforced segregation of duties, and configurable exception alerts – help ensure consistent execution and reduce the risk of human error. Additional areas for automating finance controls include account reconciliations, generating journal entries, evidencing review of close schedules, and other close activities.
- For the testing of SOX controls, automation tools and data analytics streamline evidence collection and exception reporting, significantly reducing manual effort and increasing the coverage over transactions. Generative AI tools assist in drafting process documentation, mapping risks to controls, and analyzing control effectiveness.
- Finally, in project managing the SOX program, cloud-based workflow tools and robotic process automation (RPA) are being used to coordinate tasks, track progress, and ensure timely compliance, while also facilitating collaboration among cross-functional teams. These innovations are transforming SOX compliance from a reactive, labor-intensive process into a strategic, tech-enabled function.
To fully realize these benefits, management should assess and maximize the capabilities of existing technology. This includes thoroughly evaluating current tools, engaging with vendors to understand recent enhancements, and ensuring available features are fully utilized before pursuing new investments.
3. Fostering Collaborative Relationships
Collaborative working relationships among key stakeholders remain one of the most powerful drivers of SOX compliance success. Even the most advanced technologies cannot replace the human element – true compliance excellence is led by people, not platforms.
- Control owners play a pivotal role by fostering transparency and embracing a mindset of continuous improvement. When they proactively share control challenges and potential gaps, it minimizes year-end surprises and allows sufficient time for remediation. Their deep operational knowledge also positions them to identify opportunities for control efficiency and risk mitigation – insights that become actionable when shared with internal audit.
- External auditors carry significant responsibility in issuing opinions on internal control effectiveness. Management can strengthen this relationship by understanding the expectations auditors must meet – both from the PCAOB and their own firm’s standards – and collaborating on streamlined approaches that meet compliance goals without overburdening control owners. Moreover, external auditors bring a broad perspective from working across industries and can offer valuable insights to enhance control design and execution.
- Internal audit serves as a strategic partner in SOX programs, supporting control owners through process updates, independent testing, training, and remediation efforts. With their objective lens, internal auditors are well-positioned to identify emerging risks and control weaknesses early, before they escalate into significant issues.
Ultimately, SOX compliance thrives when these stakeholders operate as coordinated team – communicating openly, aligning on expectations, and working toward a shared goal of strong, sustainable internal controls.
4. Monitor Continuous Improvement with KPIs
Drive continuous improvement in your SOX program by defining and monitoring a set of well-aligned KPIs that go beyond compliance and reflect operational and strategic value. By establishing clear metrics, organizations gain actionable insights into the effectiveness and efficiency of their internal controls. KPIs may include:
- Control failure rate over time, including repeat findings.
- Average time to remediate a control deficiency.
- Automated vs. manual controls ratio, including trend over time.
- Timeliness of control execution.
- Deficiencies identified by management or internal audit vs. external audit.
- SOX hours per FTE, or total SOX hours year-over-year trend.
- Total key controls year-over-year trend.
- Percentage of external auditor reliance, year over year.
Regularly tracking these KPIs enables proactive identification of gaps and promotes accountability among control owners. Moreover, integrating business-value KPIs, like cost per control and stakeholder satisfaction, helps demonstrate the broader impact of the SOX program on organizational performance. This continuous feedback loop fosters a culture of improvement, enhances risk management, and ensures the SOX program evolves in step with business priorities.
Looking Ahead: Value Creation and Strategic Alignment
As organizations continue to evolve their SOX programs, the focus will increasingly shift toward value creation and strategic alignment. The most successful programs will be those that can demonstrate clear business benefits while maintaining robust compliance capabilities. This requires ongoing investment in technology, process improvement, and talent development. To modernize your SOX program and maximize the value of your investment, contact CrossCountry Consulting.
When risks are increasingly interconnected, rapidly evolving, and often vague, fragmented approaches to risk management aren’t sustainable. Organizations are facing rising pressure – from regulators, boards, and the broader market – to not just demonstrate control but to inspire confidence. That confidence stems from alignment across people, processes, systems, and, most critically, the lines of defense.
Evolving Risk Frameworks Toward Integration
The IIA’s “Three Lines Model” reimagines how organizations define and coordinate risk and control responsibilities. It moves beyond the rigid hierarchy of the traditional “three lines of defense” and promotes collaboration, integration, and a shared vision of performance and assurance. Similarly, the COSO ERM Framework underscores the importance of embedding risk into strategy, decision-making, and culture – an approach that relies on coordinated, enterprise-wide engagement.
Despite the clarity offered by these frameworks, many organizations continue to operate in silos. Roles are defined but not connected. Efforts are made in parallel, not in partnership. As a result, critical risks fall through the cracks or are assessed three times over.
Understanding the Lines: Roles and Risks
To better understand the disconnect, consider the distinct but complementary roles of each line of defense:
First Line: Business and Operations
- Owns and manages risk as part of daily activities.
- Designs and executes controls embedded in processes.
- Focuses on achieving objectives while maintaining compliance.
- Challenge when isolated: Lacks visibility into enterprise-wide risk priorities and may undervalue broader governance needs.
Second Line: Risk Management and Compliance
- Develops policies, frameworks, and risk methodologies.
- Provides oversight and guidance to the first line.
- Monitors emerging risks, regulatory changes, and control effectiveness.
- Challenge when siloed: Viewed as enforcement rather than enablement; may duplicate efforts or misalign with operational realities.
Third Line: Internal Audit
- Provides independent, objective assurance to executive leadership and the board.
- Leverages risk and compliance data to inform a dynamic, risk-based plan.
- Assesses the effectiveness of governance, risk management, and control processes.
- Reports directly to the board or audit committee.
- Challenge when disconnected: May operate in hindsight, be seen as a policing function rather than a strategic partner, and react to risks that could have been addressed through earlier engagement.
Each line plays a vital role. But when their work isn’t aligned – when responsibilities aren’t rationalized, or insights aren’t shared – the organization loses the opportunity to leverage risk oversight as a strategic capability.
Enabling Alignment: From Theory to Practice
What does alignment look like in practice?
- Establishing shared objectives across risk, compliance, and audit functions.
- Defining a unified risk taxonomy to ensure consistent language and categorization.
- Coordinating planning and reporting across the three lines for efficiency and clarity.
- Leveraging integrated GRC technology to provide a real-time, enterprise-wide view of risk.
Integrated risk management (IRM) frameworks and modern GRC technologies provide a single source of truth, enabling real-time insights and driving efficiency across assurance functions.
Forward-thinking organizations are embedding risk monitoring into frontline systems, implementing integrated planning cycles, and leveraging GRC platforms to enhance visibility across the enterprise. Internal audit is also evolving – acting as both evaluator and facilitator – convening stakeholders to close assurance gaps and ensure resources are deployed where they matter most.
As an example, internal audit is stepping into a more strategic, collaborative role, leaning into risk management or compliance advisory when needed, while maintaining its independence and adding strategic value. This may include:
- Rationalizing control frameworks.
- Counseling on policy effectiveness.
- Facilitating risk workshops to align stakeholders.
- Advising on governance around new processes or system implementations.
The benefits go far beyond compliance. Aligned assurance empowers agile responses to disruption, supports smarter decisions, and builds greater trust with boards and stakeholders. As oversight expands into areas like cybersecurity, ESG, and third-party risk, those organizations that can tell a unified, data-informed risk story will differentiate themselves.
Leading with Confidence Through Alignment
To unlock true value from assurance functions, leadership must embrace an integrated mindset – fostering cross-functional coordination, enabling tools, and a culture of shared accountability. Risk shouldn’t be managed in isolation but embedded in how the organization operates and grows. When the lines of defense are aligned and supported by smart GRC solutions, organizations move beyond compliance to build resilience, enable smarter decisions, and lead with greater confidence.
To maximize the full value of a three lines model, contact CrossCountry Consulting.
Finance leaders in manufacturing are under pressure to stretch limited resources further than ever as they contend with evolving investor expectations, supply chain disruptions, talent sourcing, rising costs, tariff volatility, and the urgent need to improve cash flow. To do so, they need real-time insights for smarter decision-making.
But one of the biggest roadblocks to finance transformation in manufacturing is cost. Unlike higher-margin industries like tech, manufacturers must justify every dollar spent on systems and automation.
Yet, many middle-market manufacturers still rely on disjointed systems and spreadsheet-heavy reporting, resulting in delays, inefficiencies, and heightened risk due to inaccessible, outdated data.
While it’s tempting to think a new ERP is the silver bullet, that’s not always the answer, especially for businesses in which margins are tight and disruption must be minimized. Today’s manufacturing CFOs need practical, cost-effective ways to modernize finance without huge expenditures.
Why It’s Time to Upgrade Your Finance Function
Finance teams at manufacturing companies face unique structural challenges that make technology transformation imperative: the complexity of physical operations, distributed facilities, and high volumes of transactions relative to other industries. These challenges force CFOs to address:
- Economic headwinds and policy uncertainty: Rising input costs, global supply chain turbulence, and shifting U.S. trade policy make it harder for teams to forecast, manage costs, and plan with confidence. Want in-depth analysis and actionable recommendations for today’s economic environment? Explore the full CFO report here.
- Inaccurate costing methods: Many manufacturers rely on outdated or overly simplistic costing models, leading to distorted margin analysis and misinformed pricing decisions.
- Financial reporting bottlenecks: With data spread across production, inventory, and various ERP systems, it can take weeks to close the books and generate reports. By then, insights are already stale.
- Lack of visibility: Siloed systems make it challenging to view performance by product line, customer, or plant, which blurs operational decisions and pricing strategy.
- Manual data entry and reconciliation: Finance teams spend hours gathering and cleaning data from spreadsheets and disconnected tools, leaving little time for value-added analysis.
Building a Finance Function That Scales: Where to Start in Manufacturing
So how can CFOs modernize their finance functions while capturing the critical metrics quickly and with minimal disruption?
The key is to focus on targeted, incremental improvements that deliver insights today. These quick wins lay a scalable, de-risked foundation for a potential future ERP, BI, or CPM implementation when the time is right.
1. Simplify Trackable KPIs
Before investing in new tools or automation, it’s critical to first define what you need to measure. One of the biggest mistakes is trying to track everything. Complexity doesn’t scale. Simplicity does.
Here is what matters most:
- Cash conversion: How efficiently are you turning revenue into cash? Track days sales outstanding (DSO), inventory turns, and payables.
- Cost structure visibility: Understand fixed vs. variable costs, labor efficiency, material usage, and how overhead is being allocated.
- Product and customer profitability: Know which products, customers, or plants create value and which are a drag on margins.
- Forecast accuracy: Are your revenue, margin, and cash flow projections consistently reliable? Misses here ripple through the business.
- Working capital trends: Monitor shifts in inventory, receivables, and supplier terms that may indicate liquidity challenges ahead. Early visibility into where cash is tied up is critical for proactive management.
By focusing on the metrics that matter – and ensuring the underlying data is accurate and accessible – finance leaders can drive sharper insights without overwhelming their teams or systems.
2. Optimize Your Costing Methodology Before Automating Anything
Does the current costing methodology obscure rather than reveal insights into drivers of profitability? A successful costing methodology should be tailored to mirror the firm’s specific manufacturing activities, without being overly complicated or burdensome. If these costing methodologies are too simplified or complex, reporting will always suffer.
- Evaluate current costing methodology: Standard, actual, or hybrid? What’s working and what’s not? Small adjustments can go a long way.
- Ensure accurate overhead allocation: Are labor, materials, and indirect costs properly assigned? Are you over- or under-absorbing costs?
- Pressure-test margin accuracy: If you can’t trust margin by SKU, customer, or plant, it’s nearly impossible to steer the business.
- Integrate costing and operational data to financial planning & analysis: Operational data is often a leading indicator into financial performance. Does the operational data you capture enable you to speak to the drivers of financial performance? Learn more: CrossCountry Consulting’s proprietary reporting and analytics framework integrates key financial and operational data from across the enterprise and surfaces insights into business drivers, new value-creation opportunities, and prescriptive analytics.
Accurate costing information is the foundation for decision-making. If it’s wrong, even the best dashboards won’t lead to better decisions – just faster bad ones.
3. Develop Manufacturing-Specific Reporting
In manufacturing environments, operations often span across facilities, systems, and shifts, making access to timely, accurate data critical but elusive. Many manufacturers operate with fragmented systems that separate financial, production, and inventory data, proving a challenge to CFOs trying to get a clear view of performance.
While fragmented data spread across various systems might suggest that a complete tech overhaul is necessary, a data warehouse strategy can offer a cost-effective, scalable, near-term solution.
This approach consolidates data from various sources and enables real-time reporting while minimizing disruptions. CFOs can then focus on improving and stabilizing processes, which will set the company up for success if the decision is ultimately made to upgrade and consolidate systems.
- Maximize existing applications: Leverage your current systems to maintain consistency, reducing the need for additional investments and the hassle of implementing a new application.
- Integrate financial and operational data: Seamlessly combine information from multiple systems to create a single source of truth.
- Automate reporting: Implement automated dashboards and reports that transform raw data into actionable insights, allowing your team to focus on analysis rather than compilation.
- Real-time performance tracking: Utilize real-time production data to monitor performance by product, production line, or shift.
By automating data transformation and reporting, finance teams can shift from manual data management to strategic analysis, driving better business decisions with timely, accurate information.
Future-Proof Finance in Manufacturing Without Incurring More Overhead
CFOs can modernize finance while controlling costs by:
- Identifying the key drivers of your business and ensuring you’re measuring what truly matters.
- Prioritizing costing before investing in reporting or new systems.
- Implementing data integration to leverage existing systems instead of replacing them.
- Using automation tools to free up finance team capacity and reduce manual work.
- Leveraging outsourced expertise to build scalable solutions without full-time hires.
CrossCountry Consulting specializes in scalable finance transformation for manufacturing and industrial companies without draining cash flow or creating more complexity. For support with costing, reporting, implementing technology, or gaining real-time data visibility, contact CrossCountry Consulting today.
You’re launching a new product suite, redesigning internal processes, or building innovative operating models and team structures to generate value.
Immediately you run into:
- Change resistance, misunderstanding, and employee strife.
- Unclear or poorly envisioned roles, responsibilities, and communication.
- Delays, false starts, and incomplete stakeholder buy-in.
- Unexpected risks (third-party risk, legal and regulatory implications, technology systems, etc.).
If not managed proactively, even the most well-intentioned transformation can introduce a complex web of potential risks that can erode value creation. The key is to embed practical risk management strategies into operational change management initiatives.
Modern Operational Change Management
Operational change management is a systematic approach to planning, executing, and monitoring new transformations within the business to ensure a smooth transition and successful adoption. For many organizations, this approach is applied to specific operational initiatives, such as re-engineering workflows, integrating technology systems, and bringing to market a new offering.
Each of these transformations represents a significant operational shift designed to enhance efficiency, expand market reach, or improve customer experience. While the benefits are clear, it can be difficult to keep stakeholders aligned and progress on track, which is where risk management comes into play.
Risk Management’s Role in Change Management
For risk professionals, the critical question isn’t if change will happen, but how effectively the associated risks will be identified, assessed, and managed. Bringing risk into the conversation early and often is paramount. The goal is to minimize disruptions to operations and prevent adverse consequences that can impact financial performance, regulatory standing, or reputational integrity.
Consider a new product offering or a significant process update. The inherent risks are multifaceted and demand a comprehensive review. For instance:
- Third-party risk: Does this change necessitate new relationships with vendors, suppliers, or partners? What are the associated due diligence requirements and ongoing monitoring obligations? Read more: Navigating Third-Party Risks: Best Practices and Questions Answered for Today’s Businesses
- Technology risk: Is new technology required? What are the cybersecurity implications, data privacy concerns, and integration challenges?
- Strategic risk: Does this change align with the company’s long-term strategic vision, or could it inadvertently pull resources away from core objectives?
- Legal and regulatory risk: Are there any new legal or regulatory obligations that arise from this change, particularly in highly regulated industries or in public markets. What are the compliance implications?
Failing to address these questions proactively can lead to costly remediation, reputational damage, and even regulatory penalties.
Common Pitfalls in Assessing Change-Related Risk
Implementation of risk-informed change management practices often faces significant hurdles. More often than not, risk is an afterthought, which can lead to several issues:
- Too late: Risk teams are often engaged too late in the product or change lifecycle, leading to a perception that they are “slowing time to market” rather than enabling informed decisions.
- Inconsistent: Risk assessment processes often vary across different business units, leading to a lack of centralized visibility and a fragmented understanding of enterprise-wide risk exposure.
- Repetitive: Stakeholders often find themselves answering the same questions from multiple risk groups, creating frustration and inefficiency. This signals a failure to leverage existing risk management programs effectively.
- Opaque: Unclear accountability and ownership structures for risk management throughout the change process can lead to gaps and unaddressed exposures.
- Point in time: Assessments are often one-off events, failing to provide for ongoing monitoring or visibility into the evolving risk profile throughout the new product or service lifecycle.
Explore expert Risk Management solutions that solve real-world problems
Understand emerging threats, changing regulations, and evolving technologies – then formulate actionable, pragmatic strategies to reduce risk across the enterprise.
Keys to Success: Modernizing Risk Assessment for Change
Overcoming these challenges requires a deliberate and strategic shift in how risks are assessed within the change management process. The path to success involves:
- Early embedding of risk stakeholders: Integrate risk management actions at the earliest possible point in product or change development. This shifts risk from a bottleneck to a strategic partner, enabling proactive management.
- Consolidate risk assessments: Develop a product and process assessment methodology that leverages existing risk program components, covers risks within a company’s taxonomy, and is central for change stakeholders to populate throughout the change management process.
- Tool enablement: Move beyond manual processes to leverage robust Governance, Risk, and Compliance (GRC) platforms or specialized risk assessment tools. This improves efficiency, consistency, and data capture.
- Centralized reporting and visibility: Establish mechanisms for centralized reporting and transparent visibility into risk management decisions across all change initiatives. This fosters a holistic view of organizational risk.
- Ongoing monitoring and key indicators: Design a program that includes continuous monitoring and the establishment of key risk indicators (KRIs) to track the evolving risk profile of new products, services, and processes.
What Good Looks Like: A Structured Approach
A truly effective risk management program for operational change is built on a clear, structured framework.
1. Design the Program:
This phase involves establishing the foundational elements of your risk assessment framework specific to new products and services that are going through the change management process. This program should align with the enterprise risk management framework (ERM) and include:
- Visioning session: Identify the requirements of the program and key stakeholders.
- Pain point identification: Understand current specific pain point and improvement opportunities.
- Initial design: Create initial processes to address pain points
- Feedback and documentation: Solicit feedback from stakeholders to ensure design complements existing process and document details of new process.
2. Build the Program:
Once the design is complete, the focus shifts to building and operationalizing the program. This entails:
- Developing playbooks and tools: Creating standardized templates, questionnaires, assessment processes, and potentially leveraging technology solutions to streamline the assessment process.
- Integration with existing frameworks: Ensuring the new program seamlessly integrates with existing ERM frameworks, compliance programs, and internal audit functions to avoid duplication and leverage existing controls.
- Governance and metrics: Develop the program’s governance documentation (operating model, program standard, etc.) and program success metrics.
- Maturity roadmap: Develop roadmap to continuously mature the program (staffing model to run the program, upgrading tools, etc.) over time.
3. Pilot the Program
- Training and awareness: Educating stakeholders across the organization on the new risk assessment process, their roles, and the importance of early engagement.
- Pilot program: Running a pilot with select change initiatives to test and refine the process before full-scale rollout.
- Lessons Learned: Incorporate lessons learned from the pilot program to feed into the overall program to promote continuous improvement. Add items to the maturity roadmap.
As illustrated below, CrossCountry Consulting provides a comprehensive set of customizable operational change management deliverables, tools, and templates tailored to each organization’s project needs:

Transform Change Management Threats into Opportunities
Navigating complex operational changes while effectively managing risk requires specialized expertise and a pragmatic approach. CrossCountry Consulting’s Integrated Risk Management experts support organizations at every stage of their change journey with programs configured to unique needs and risk appetites. This includes developing frameworks, methodologies, and supporting documentation.
Beyond the technical aspects of risk, successful change hinges on effective people management via a proven 3-step approach:
- Preparing for change: Assessing organizational readiness, identifying potential resistance, and developing communication strategies.
- Managing the change: Implementing detailed action plans, providing training, and ensuring effective stakeholder engagement throughout the transition.
- Reinforcing the change: Establishing mechanisms for ongoing monitoring, feedback, and continuous improvement to ensure the new operational paradigm is sustained and delivers intended benefits.
To proactively integrate risk management into your operational change initiatives, contact CrossCountry Consulting.
The game has changed for CFOs. The traditional way of running a Finance organization is not going to work in 2025. In fact, 66% of CFOs say they need to rewrite the organizational playbook to remain competitive. Why?
The role of the CFO is expanding beyond FP&A and Accounting into a cross-enterprise role. 43% of CFOs are leading enterprise strategy and transformation initiatives. And the CFO is often leading Procurement and IT/Data teams – or at least has oversight of the key decision-maker for respective departments. This all comes in parallel to the traditional CFO roles of managing the company’s investments, balancing risk, and leading M&A activity. Doing all of this in an uncertain economic climate, and it’s a lot for the CFO and his/her leadership team.

At the same time, most CFOs (59%) say that cost reduction is currently their top strategic priority. But CFOs must balance cost improvement with investments in value creation given board and competitive pressure to adopt generative AI and ESG and avoid putting the company at risk. So how can today’s CFOs thread the needle?
Consider zero-basing the structure of the company.
What Is a Zero-Based Organizational Structure?
The term “zero-base” traditionally applies to budgeting and managing third-party spend – often abbreviated as “ZBB.” It’s a great tactic to generate material EBITDA improvement. However, CFOs can extrapolate on this concept and leverage it across the enterprise to achieve similar, compounding results.
To apply ZBB to building a zero-based organization structure, you simply take a blank sheet of paper and start from scratch. Forget about what roles and key personnel you have today; draw the structure that you need to win based on company strategy and priorities, how transactional tasks could best be completed, and where technology could make efficiency gains. You’ll be amazed how different the new drawing will look versus your current structure.
Benefits of Zero-Based Organizational Design
- Lower cost: Companies adopting ZBB report up to 25% SG&A improvement. CrossCountry Consulting’s teams have seen similar, and sometimes greater, results by applying ZBB to organizational design. Median Finance organizations are 1% of revenue today – tomorrow they could be even leaner, or work can be more balanced in favor of value-driving FP&A and BI.
- Faster output: Blank-sheet organizations usually have fewer management layers, allowing teams to move with higher velocity.
- Higher integration: Newer structures blur the lines between different departments. Instead, workflows and responsibilities are tailored around end-to-end processes, not traditional job specs and hierarchical structures, which enables greater cross-functional collaboration and communication.
Approach to Building a Zero-Based Finance Organization Structure
- Start with strategy: Be clear about the company’s enterprise strategy and what type of structure will best support that vision. For example, if the company is in high-growth mode and may be acquisitive, invest in FP&A to proactively identify and evaluate growth targets.
- Know what core vs non-core is: Talk to key leaders about what their employees are doing day-to-day. Understand what you really need to do versus tasks that are nice to have. Design a structure that focuses on core activities, automates transactional activities, and eliminates wasteful activity.
- Let data inform but not become your path: Benchmark your costs and headcount against industry peers and assess the number of management spans and layers. Use these data points to inform your new organization size and structure, but don’t let those numbers become the answer. Every company is different.
- Take a blank sheet and draw your new organization: It’s time to take a pencil and draw your new value-focused structure (boxes and wires) bottom-up. Start unconstrained with what could be (art of the possible) then seek cross-functional input from IT, Procurement, Businesses/Operations, etc. and iterate until you get it right.
- Don’t forget about process: Your new structure only works if you optimize the processes, people, technology, and data around the structure – otherwise you’re just doing the same work with different or fewer people in different roles.
What Types of Finance Organizations Are Going to Win in 2025?
Be bold. Go big with your new structure. To join the modern CFO community with leading practices, here are the attributes to fuel progress:

- Speedy, data-driven FP&A: Separate strategic from corporate FP&A activities. Strategic FP&A contains embedded data and analytics personnel and capabilities and is immersed in the business units or functions it serves. The team is powered by a modern reporting and analytics framework.
- Plan-to-Pay FP&A-Procurement integration: Closely integrate Procurement with FP&A to build a coordinated financial plan and budget that drive spending decisions throughout the year. Sourcing-related savings should tie back to the financial budget to enable immediate cash flow savings and allow dynamic budgeting.
- Transformation Management Office: CFOs increasingly are responsible for enterprise transformation and should have a business transformation arm in their organization. This team is responsible for continuously prioritizing and executing operating model improvements, operating in an agile way to maximize velocity. Done right, this function is a weapon that can be applied across function and process, allowing Finance to serve as the steward for change across SG&A.
- Low-cost automation-powered shared services: Functions like Accounts Payable, General Accounting, Payroll, Tax, and Treasury can be highly automated if companies invest in data integration tools. Remaining tasks that require human touch should be pooled in low-cost centralized service locations. It’s important to incentivize management of these functions to find the gains and dive roadmap to efficiency.
As the company’s zero-based transformation lead, the CFO must architect change starting with Finance and then carry those practices and designs outward to other functions. To get started on a strategy zero-based org structure roadmap, contact CrossCountry Consulting.
Midway through 2025 and already looking toward 2026, owners of private companies are increasingly eager to exit their investments as prolonged holding periods and fluctuating market conditions impact the market for sales and public offerings.
Interest rates, inflation, tariffs, and geopolitical developments, among other factors, have introduced uncertainty into the timing, type, and value of exits.
Fortunately, leaders have several exit options to choose from.
Determining the Appropriate Exit Strategy
In the current environment, multiple exit strategies are available for consideration. Owners must carefully evaluate their options and select the exit strategy that best aligns with their goals.
This evaluation often begins with an understanding of the dual-track exit, which encompasses both a Sale or Merger and Public Offering strategies. A dual-track approach allows organizations to remain flexible while maximizing their options. This approach helps ensure the company is always in a state of readiness, prepared with the agility to pivot based on market conditions, stakeholder priorities, and evolving business objectives.

Sale/Merger Track
- Full Enterprise Sale: Selling the company in its entirety to a corporation or another private equity firm. Real-world example: See how a PE-backed OSH company was sold on an accelerated timeline and cut its time spent on accounting and financial reporting in half.
- Carve-Out Sale: Based on a Sum-of-the-Parts valuation, it may be advantageous to sell specific units separately to maximize overall value.
- Continuation Sale: To circumvent holding period restrictions, a company may be “sold” from one fund to another within the same private equity firm.
Public Offering Track
- Initial Public Offering (IPO): Shares of a private company are offered to the public for the first time on a regulated market. Learn more: Amid Unpredictability, Now’s the Time to Get Ready for an IPO Rebound
- SPAC: Merging with a SPAC can be a faster process with fewer requirements than a traditional IPO, though recent SPAC regulations should be considered with legal counsel.
- Carve-Out IPO: This involves the same preparatory steps as a carve-out sale with additional requirements for public registration.
Regardless of the exit type, companies transitioning to the next stage of their lifecycle require thorough exit preparation and potentially significant infrastructure investment. Fortunately, that transformation is consistent across exits, as the shift to a more efficient, de-risked operating model smooths the path toward a successful transaction. This preparation typically begins with an exit-readiness assessment, which is critical for determining the optimal exit strategy.
The Value of an Exit-Readiness Assessment
An exit-readiness assessment involves a comprehensive review of current business functions, historical performance, and future projections. Conducting this assessment well before initiating the exit process allows for the development of strategic roadmaps aimed at increasing value, addressing issues, and implementing necessary upgrades.
It’s a moment of self-reflection for corporate leaders: Do they have what they need and what it takes to execute a successful transaction?
The assessment documents the gaps in current-state operations relative to the future state and provides a roadmap for bridging those gaps, often in the form of upgrading or implementing technology, standing up a more effective process architecture, and aligning talent and investments to necessary areas of the business.
An exit-readiness assessment delivers numerous benefits applicable to all types of exits, such as:
- Developing an exit-ready timeline across functions.
- Identifying potential exposures and mitigating risks before a transaction.
- Developing a plan to address any identified exposures, including hiring strategy.
- Ensuring compliance with all applicable laws and regulations.
- Increasing chances of a successful transaction.
- Strategizing for deal synergies and realizing the investment thesis, including potential carve-out opportunities.
- Accounting for integration challenges and how to overcome them.
For public offerings, the assessment requires more time and regulation, necessitating an evaluation of timelines, stakeholders, costs, and the transformation required to meet higher reporting standards, including:
- Improving internal controls over financial reporting.
- Communicating effectively with investors.
- Evaluating quality and required effort of financial statements.
- Improving corporate governance practices.
While these stringent requirements may not apply to a sale, process improvements can still facilitate a successful sale at a higher valuation. When exploring a dual-track exit approach, it’s advisable to differentiate between “requirements,” “needed solutions,” and “nice-to-haves.” After conducting a successful exit-readiness assessment, companies are prepared to move into the next stage of their exit, as shown in the diagram below:

Making the Exit-Readiness Transition
The transition from a private company to being exit-ready involves documenting operational gaps relative to the future state and creating a roadmap to bridge these gaps.
The graphic below illustrates common differences between a typical private company and one that is exit-ready. These activities represent core areas (Accounting Close, Finance, Accounting Policies, Finance Systems and Controls, Tax, and Human Resources) of the business that must be high-functioning and high-performing prior to an exit.

Focusing on these core areas is a good practice for aligning transformation priorities. However, as shown below, there are other areas of the business, including Cybersecurity, Internal Controls, Investor Relations, and External Audits, that should be established or optimized, especially when considering an IPO.

Planning for an Efficient Exit Process
Companies or funds planning an exit event in the near future should begin implementing operational enhancements well in advance to ensure consistency and success. To take the next step in the investment lifecycle and select the appropriate exit track, consider partnering with an advisor who can provide guidance across all stages and outcomes of exit-readiness planning.
Contact CrossCountry Consulting to strategically position your organization for a value-maximizing exit.
Amid evolving government priorities – including the methods by which goods and services are acquired – contractors are adapting to provide customers with more products/services at less cost. One particularly valuable tool to accomplish this is to enhance the organization’s indirect rate structure for a more agile and cost-effective methodology to recover costs on government contracts.
Optimizing your indirect rate structure delivers key advantages, including:
- Costs aligned to the functions and contracts utilizing the activities.
- Consistent, best-in-class practices across the business.
- Reduced administrative requirements associated with maintaining and monitoring indirect rates, and preparing numerous Incurred Cost Proposals (ICP) and Forward Pricing Rate Proposals (FPRP).
When making these changes, government contractors are subject to regulatory requirements. However, these rules shouldn’t prevent you from implementing enhancements that ultimately improve the business and drive competitive advantage.
Regulatory Hurdles of Changing Indirect Rate Structure
For contractors subject to the Cost Accounting Standards (CAS), several regulatory requirements must be addressed when changing the indirect rate structure.
First, contractors must identify whether each of the changes will be considered a cost accounting practice change (CAPC). This is where the complexities begin because not all changes are considered a CAPC. For example, combining indirect cost pools that use the same method or technique (allocation base) to allocate costs would not be considered a CAPC. This determination is important because only changes that are a CAPC will require a general dollar magnitude (GDM) or detailed cost-impact (DCI) proposal (or potentially both), which informs the government of the prospective change in costs on CAS-covered contracts.
Once changes that are a CAPC are determined, the complexities continue with the onerous and complex requirements for preparing GDM or DCI proposals.
Recent court cases and regulatory changes have added even greater confusion to these requirements. For example, the Defense Contract Audit Agency’s (DCAA) 2023 guidance on unilateral cost accounting practice changes reignited a debate stretching across four decades on how fixed-price contracts should be accounted for in these cost impacts.
Additionally, forthcoming court decisions will determine whether changes made to FAR 30.606 in 2005 (yes, over 20 years ago) that prohibit offsetting multiple, simultaneous CAPCs are valid. Navigating these requirements and accurately preparing GDM or DCI proposals are essential because the calculations identify whether contractors might owe the government money for increased costs on CAS-covered contracts.
For government contractors that were recently part of a merger or acquisition, evaluate the pros and cons of preparing an external restructuring proposal. One of the main pros of this approach would be to avoid the GDM and DCI requirements.
Steps to Assess and Implement Indirect Rate Structure Changes
Regulatory hurdles and implementation complexity shouldn’t prevent companies from pursuing cost efficiencies. The following are key steps that can be used to evaluate the indirect rate structure that’s appropriate for your company:
- Identify your go-to-market strategy: Changes to your indirect rate structure will be made on a prospective basis, so it’s important to not just look at the structure of your company today but understand what you want to be in the future. Identifying whether your strategy includes being a service or software provider, a software developer, a manufacturer, an integrator that relies on subcontractors, or a combination of all of these, is an important step in determining the appropriate allocation methodology for indirect costs and whether a single rate segment or multiple rate segments is most appropriate.
- Centralized vs. decentralized organization: A decentralized organizational structure could be desired to segregate your commercial and government business or to drive decision-making and accountability at a lower level in your business. However, decentralization can often prevent the proper scaling of certain functions and impede consistent practices being used throughout the company. Conversely, a centralized structure can flatten the organization and allow leadership to ensure consistent practices are implemented throughout the entire organization. Evaluating the pros and cons of a centralized or decentralized structure and analyzing how indirect cost pools can be used to implement a centralized structure are key aspects of identifying the indirect rate structure appropriate for your company.
- Understand your backlog: Understanding the impact to your backlog, as well as to outstanding proposals and key upcoming pursuits, should be an integral part of the decision-making process when evaluating changes you might implement. To properly identify this impact, ensure the data in your backlog is accurate. This includes information such as the estimated costs by cost element for your contracts, whether the contract is subject to CAS, and the contract type. This information is needed to prepare not only the GDM and DCI proposals discussed previously but also to ensure you have an accurate understanding of the financial ramifications of any changes to both CAS and non-CAS-covered contracts.
- Identify cost reduction opportunities: Implementing changes to your indirect rate structure is an optimal time to determine if cost reduction initiatives could also be implemented. Utilize a blank sheet approach that includes benchmarking headcount and costs against competitors and identifying specific savings targets across every layer of the business, which can allow you to resize the organizational structure to realize cost savings.
Next Steps
Administrative requirements shouldn’t prevent CFOs from making changes that could result in agile, efficient cost structures. CrossCountry Consulting’s team of integrated government contracting experts enables organizations to understand and integrate regulatory requirements and industry best practices. With the right tools, technology, and advisory support, your company can identify the appropriate indirect rate and cost structure to minimize administrative effort and fulfill regulatory requirements associated with these changes.
To get started, contact CrossCountry Consulting today.
Procurement and finance teams face increasing pressure to optimize spending, streamline operations, and drive greater efficiency, especially in response to ongoing economic turbulence. Among all the other responsibilities piled on their desks, achieving full visibility into direct and indirect spend feels like a distant dream they hope to accomplish eventually.
The good news is that there’s an achievable solution within reach right now: the combined power of Coupa and NetSuite.
To transform fragmented procurement and finance processes into a unified, productive spend management engine, the integration of these two tools provides a clear path forward.
Bridging the Gap Between Direct and Indirect Spend
Traditionally, managing direct procurement – the raw materials and components critical for production – has presented unique challenges. Unlike indirect spend, which supports operational needs, direct spend is intrinsically linked to the cost of goods sold (COGS) and revenue generation. Maintaining quality, ensuring continuity of supply, and fostering strong supplier collaboration are paramount to keeping production lines running smoothly.
The integration of Coupa and NetSuite directly addresses these complexities. By leveraging Coupa’s robust capabilities in areas like supplier collaboration, negotiation, and advanced analytics, organizations can gain unprecedented control over their direct spend. Simultaneously, NetSuite’s strengths in inventory planning and financial management provide a solid foundation for managing the financial aspects of procurement.
Explore expert Coupa-NetSuite Post Production Support services that solve real-world problems
Seamlessly integrate and optimize your finance and procurement processes to enhance accuracy, streamline operations, and strengthen controls in a unified Coupa-NetSuite architecture.
Key Benefits of a Unified Approach
Capturing the full value of unified procurement and finance delivers a number of key advantages, such as:
- Streamlined procurement workflows: Imagine a world where purchase orders flow seamlessly, and invoicing is centralized. This integration makes it a reality, optimizing operational efficiencies without disrupting your end users.
- Enhanced spend visibility: Break down silos and gain a holistic view of all your spend categories. Centralized reporting through Coupa and NetSuite provides advanced analytics, enabling you to identify opportunities for savings and improve decision-making.
- Faster and more accurate invoicing: Integrating purchase orders accelerates the invoicing process, reduces errors, and improves cash flow management. Below is an illustrative example of collaborative invoicing and PO management between the two tools:

- Optimized direct spend management: Coupa’s features for supplier collaboration and advanced analytics, combined with NetSuite’s inventory planning, empower you to optimize direct spend for better quality, continuity, and cost savings.
- Improved supplier collaboration: Foster stronger relationships with your suppliers through centralized communication and real-time interaction within Coupa, leading to fewer errors and faster processing.
- Real-time responsiveness: The deep integration between Coupa and NetSuite allows for real-time data synchronization, enabling quick adjustments to ensure production lines remain active and supply chains are agile.
- Maintaining existing automation: A well-planned integration ensures that your existing automated processes are not disrupted but rather enhanced by the combined power of the two platforms.
- Actionable insights through advanced analytics: Unlock the power of detailed spend reporting across both direct and indirect categories, providing you with the insights needed to drive strategic improvements.
Best Practices for Maximizing Integration Value
To truly harness the potential of Coupa and NetSuite, consider these best practices:
- Choose an experienced integration partner: Selecting a partner with deep expertise in both Coupa and NetSuite is crucial for a smooth and successful implementation. As 2024’s North American Regional Partner of the Year for Coupa and 2024’s North American Solution Provider Partner of the Year for NetSuite, CrossCountry Consulting’s integrated technology teams are the go-to option for leading organizations today.
- Leverage NetSuite for direct PO origination: Utilize NetSuite’s core strengths in managing the initial stages of the procurement process for direct materials.
- Empower supplier collaboration with Coupa: Utilize Coupa’s dedicated tools to centralize communication, manage negotiations, and enhance overall supplier relationships.
- Automate routine tasks with Coupa: Free up your team’s time by automating PO generation, invoice matching, and ASN tracking within Coupa.
- Enhance planning and forecasting with Coupa: Integrate Coupa with demand planning or NetSuite systems for smarter ordering based on inventory levels and production schedules.
- Address issues proactively with Coupa’s PO collaboration: Utilize Coupa’s PO Collaboration features for real-time interaction with suppliers, allowing for immediate resolution of quantity or delivery date issues. When working with direct suppliers, PO collaboration also delivers enhanced profitability and other benefits:

The Bottom Line
The integration of Coupa and NetSuite offers a powerful solution for organizations striving for greater productivity, visibility, and control over their direct and indirect spend. By breaking down silos, automating processes, and leveraging advanced analytics, procurement and finance teams can move beyond transactional tasks and become strategic drivers of business value.
Ready to unlock unprecedented productivity for your organization? Contact CrossCountry Consulting for a free Coupa Healthcheck or estimate the cost of licensing, implementing, or configuring NetSuite for your business here.
As firms expand globally, managing legal entities across multiple jurisdictions has become increasingly complex and costly. Legal entity management (LEM) generally involves multiple teams – accounting, tax, investor relations, compliance, and legal counsel – and requires navigating intricate legal frameworks, tax laws, and regulations, while handling large volumes of dynamic data.
Today, about 67% of firms manage entities across three or more jurisdictions, emphasizing the scale and scope facing asset managers. Fortunately, the right combination of technology, data, and process can efficiently overcome LEM challenges and provide real-time visibility to all key stakeholders, as explored below.
Common LEM Challenges and Solutions
Disparate and Inaccurate data
Firms often employ complex and heavily manual processes, such as offline spreadsheets, email chains, approvals, and disjointed data repositories. These labor-intensive practices not only introduce operational inefficiencies but also increase the risk of disruptions, non-compliance, and penalties. Additionally, firms commonly encounter situations in which their entity data is outdated or does not align with the records of their registered agents, both domestically and internationally.
Solution: Centralization and Validation
An effective approach to mitigating this challenge is centralizing entity data so that accurate information is accessible across all teams. To avoid paying unnecessary fees or working with inaccurate information – such as mixing dissolved entities with active ones – it’s important to collaborate with Registered Agents to maintain up-to-date and accurate records in a central repository.
Before centralizing to a system of record, validate that the data is current, complete, and accurate. Next, conduct a cross-functional audit by engaging each internal stakeholder group – finance, tax, legal, and compliance – to gather their spreadsheets, formation documents, tax information, and dissolutions. This process ensures you uncover critical data points that may be missing or outdated.
For example, the tax team might have initiated the dissolution of an entity, while the credit finance team may not yet reflect this change. By consolidating all inputs and comparing them to reports from your Registered Agent, you can identify and reconcile inconsistencies. This manual “data wrangling” phase will paint a comprehensive picture of your entity landscape before moving forward with an LEM solution.
Lack of Automated Business Processes and Workflows
Entity management built on manual business processes and workflows can create confusion for the business functions involved. Teams may have difficulty locating up-to-date documentation to support their business processes, leading to bottlenecks and potential errors. Likewise, correspondence and updates to entities through email can become problematic due to a lack of visibility. Often, key stakeholders may not be informed of changes, or, more often, it’s far too late in the workflow.
Solution: Define and Automate Processes and Workflows
Automated workflows for entity creation, modification, and liquidation streamline the lifecycle process, allowing all teams to access source data when needed. To implement automation, start with holding discovery sessions with relevant internal team members to draw a current-state process for each workflow.
This enables the team to identify how current-state processes can be transformed into the optimal target operating state within the system of record. These sessions are critical to understanding the pain points and opportunities to enhance the process to complement a new system.
Automating business processes related to LEM requires aligning with the broader enterprise governance agenda of an organization. Asset managers must navigate complex stakeholder dynamics, reconcile disparate data sources, and establish clear data stewardship responsibilities. Success depends on fostering strong collaboration between legal, compliance, operations, and data governance teams to ensure that automation efforts are scalable, auditable, and aligned with the firm’s strategic data policies.
An example of how to accomplish this can be conducting recurring touchpoints with designated data stewards from each stakeholder group. This consistent approach helps keep the data governance team informed of key updates, enabling them to assess and manage the broader impacts on enterprise-wide data policies, strategy, and governance frameworks.
For organizations looking to automate their process and workflow, it’s the right time to evaluate a software solution. For LEM, firms may choose to buy a third-party solution with specific entity-management capabilities or they may consider developing an in-house custom solution to meet their exact needs.
Tech-Enabled Legal Entity Management: Buy v Build
Introducing technology to the entity management process is an opportunity to centralize data, increase accuracy, and automate workflows, creating a unified platform for internal teams. Companies gain the ability to adapt quickly to regulatory changes, promptly notify stakeholders of updates, and proactively enhance their legal entity risk posture.
Further, centralizing legal entity data in a technology solution allows it to be more easily integrated and shared across other business systems, like accounting and CRMs, or into a data lake to increase visibility.
For teams considering which kinds of software to prioritize and how to invest, a closer look at the technology market can shed light on which path to take: buy vs build.
Buy
Buying LEM software is often more cost-effective than building a custom solution, as it reduces upfront development costs and lowers the total cost of ownership. Many off-the-shelf solutions such as Athennian, Diligent, and hCue are specifically designed to meet the complex needs of asset managers, including efficient management of organizational charts and workflows. These platforms have teams dedicated to long-term technology enhancements and the deployment of upgrades and AI. These strategic resources help internal teams focus on daily operational tasks while the vendor supports the implementation roadmap and delivery.
Off-the-shelf solutions can also provide strong support teams, active user communities for guidance, and easily defined workflows that are regularly updated and managed on customers’ behalf. By choosing a ready-made solution, firms benefit from ongoing improvements and scalability without the resource-intensive process of custom development.
Build
Building a custom LEM system allows for greater flexibility and customization for specific business needs and requirements. Asset managers may want to create a system that integrates seamlessly with existing platforms to ensure consistent data flow and real-time data availability. However, building and maintaining a system requires significant time, resources, and technical expertise. Leveraging an existing platform as a foundation for development can help reduce these costs and operational constraints.
Regulatory Compliance and Reporting
Regulations like KYC, AML, FATCA, CRS, and FinCEN are evolving, increasing the difficulty of maintaining accurate, updated compliance data. This becomes more complex when managing cross-border reporting, where different jurisdictions impose varying requirements.
Solution: A Robust LEM System
An LEM system enables faster and more efficient regulatory compliance that teams would otherwise find difficult to manage. These systems track evolving regulatory requirements, update business rules accordingly, and include reporting capabilities to verify compliance. The net effect is timely reporting and the mitigation of filing errors or penalties.
Organizations ready to advance technology-enabled LEM capabilities can contact CrossCountry Consulting to get started.
Private equity-backed companies face a unique challenge: scale fast, integrate bolt-on acquisitions, and produce investor-grade reporting – often with lean internal teams and high expectations from sponsors.
To meet these demands, NetSuite is frequently the ERP of choice due to its flexibility, speed to deploy, and cloud-native foundation. But in a PE-backed environment, going live isn’t enough. There’s a full lifecycle of holistic implementation support needs that determine success, with the ultimate goal being a scalable, reporting-ready, and M&A-capable platform that supports value creation from Day One.
Here’s what defines a successful target operating state for portfolio companies implementing NetSuite.
Supports the Investment Thesis
Whether the goal is rapid expansion, roll-up integration, or margin improvement, NetSuite must be configured with the endgame in mind.
That means building not just for today’s needs, but for future scale and value creation. A well-architected NetSuite environment serves as the foundation of a broader technology platform, enabling process standardization, data visibility, and seamless integration across the finance stack. In a Buy & Build scenario, this scalability is critical. Each add-on should plug into a system that’s ready, not one that has to be rebuilt with every acquisition.
Want to estimate the cost of licensing, implementing, and configuring NetSuite for your business? Access our custom pricing calculator.
Scalable Chart of Accounts and Segmentation
A future-proof COA and segment structure is essential for consolidating entities, analyzing performance, and onboarding acquisitions with minimal friction. Align current-state charts and segments to best practices while tailoring them to the company’s unique model and investor expectations. This ensures the design supports strategic reporting needs across platforms, regions, product lines, and acquisitions.
End-to-end NetSuite value creation with an expert implementation and advisory partner
Streamline operations, improve financial visibility, build customer relationships, and more with full-lifecycle certified NetSuite solutions designed for PE firms.
Integrated Data Across the Stack
NetSuite is most powerful when connected with other adjacent enterprise systems like Salesforce, payroll providers, procurement tools, and BI platforms, creating a single source of truth.
The result: real-time visibility, fewer manual reconciliations, and a tech stack that works as a platform for growth and not a collection of disconnected tools.
Real-world example: See how a PE-backed compensation SaaS generated significant time savings and streamlined operations through a custom-developed NetSuite implementation.
Reporting Built for the Boardroom
Traditionally, ERP implementations follow a “record to report” mindset. Today, that’s reversed.
Start with “report to record”: define what leadership and investors need to see, then build the system to capture data accurately and efficiently. From board decks to operational dashboards, reporting is built into the system’s DNA, eliminating manual workarounds and enabling confident, fast decision-making.
Learn more: CrossCountry Consulting’s proprietary reporting and analytics framework surfaces hidden insights, generates prescriptive analytics, and visually integrates cross-functional dashboards to empower leaders and boards to make rapid value-creation decisions.
M&A-Ready Infrastructure
In the PE space, ERP implementation and M&A often happen simultaneously, which can lead to disjointed, frustrating, and lengthy integrations. That’s why an agile, phased approach that balances urgency with control is imperative.
The goal is to deliver value quickly while laying the groundwork for long-term scale. Whether it’s a comprehensive rollout or a focused implementation for core entities, success is an evolution, not a revolution. Each phase builds momentum while maintaining business continuity. This approach also eases pressure on employees and enables change agents the latitude to properly communicate the advantages of the new system and the importance of speedy adoption.
Management and sponsors should work closely to develop a tailored implementation roadmap that aligns with the company’s growth strategy, integration cadence, operational goals, and investment thesis. This way, the system grows with the business without creating friction or technical debt.
Featured Insight
Change Management Embedded from Day One
A successful implementation lands technically and culturally.
Change management must be embedded throughout the project by aligning early with key stakeholders, setting clear expectations, and providing hands-on training. Through the use of AI-powered tools to rapidly generate tailored SOPs and walkthroughs, companies can also help their teams adopt the new system faster and with less overhead. When users understand how NetSuite supports their day-to-day work, adoption becomes organic and sustainable.
Final Word: From ERP to Exit Value
A successful NetSuite implementation in private equity views go-live as a starting point, not the finish line. When NetSuite is designed as an integrated platform, rather than a siloed system, it accelerates integration, improves reporting, and strengthens financial controls across the business. As an exit opportunity comes into focus, CFOs can proceed confidently knowing they’ve maximized the hold period and built tangible value for a sale or IPO.
It creates operational leverage, supports smarter decisions, and lays the digital foundation investors expect at exit. In a competitive M&A landscape, this kind of infrastructure supports the business and enhances valuation.
Ready to turn NetSuite into a value-creation engine for your portfolio? Contact CrossCountry Consulting today to get started.