Open table of contents
Key takeaways
- Draw hard boundaries around payments, filings, closes and professional judgments.
- Never let confidence substitute for missing evidence.
- Give reviewers source context, alternatives and the ability to reject.
- Test whether human oversight is real rather than ceremonial.
Decisions that need a hard stop
| Decision | Why AI alone is unsafe | Appropriate assistance |
|---|---|---|
| Release a supplier payment | Fraud, duplicate and authorization risk | Surface invoice, bank and approval evidence |
| File a VAT return | Legal responsibility and incomplete exceptions | Prepare reconciliations and unresolved list |
| Close a period | Downstream reports may rely on it | Show completion and blocker status |
| Decide ambiguous VAT | Missing contract/place-of-supply facts | Frame the question and relevant evidence |
| Create a missing receipt | Produces false evidence | Request a valid replacement or explanation |
The boundary concerns the use, not a mystical property of a model. A deterministic rule can also be unsafe if it hides exceptions; AI can be useful when it exposes them.
Four reasons to escalate
- Missing facts: purpose, contractual role, performance location or document authenticity is unknown.
- Conflicting evidence: invoice, bank and platform report disagree.
- Material consequence: money, filing, close or external report would change.
- Required authority: only an owner, authorized employee or professional reviewer can decide.
When one applies, the workflow should stop, describe the issue and route it. It should not quietly choose a default merely to complete the queue.
Five practical DeinHans boundaries
| Case | Hans can prepare | Hans must stop and route |
|---|---|---|
| Bank payment without invoice | Link the payment, prior supplier context and missing-evidence task | Do not reuse an old invoice or invent the current purchase |
| Unknown payout row | Preserve the row, surrounding payout components and bank settlement | Do not force the row into revenue, fee or balance movement |
| Possible reverse charge | Extract supplier, country, service and invoice wording | Do not decide VAT treatment while contract or place-of-supply facts are missing |
| Payment release | Present invoice, duplicate warnings and approval evidence | Do not initiate or authorize the payment |
| Period close | Show source coverage, reconciliations and unresolved cases | Do not file, sign or declare professional completion autonomously |
The safe next state is concrete: ask the owner for a business fact, keep the exception visible, or route a professional question to the accountant. “Hans prepares” never means “Hans silently decides.”
Example: plausible but unsafe
An AI sees a €4,760 foreign software payment and a past invoice from the same brand. It proposes matching the payment to that old invoice and applying the previous VAT treatment. The amount and name look plausible, but the current contract, entity and invoice are missing. Approval would hide both a missing document and a potentially changed cross-border fact. The correct action is a request for current evidence, not a more confident guess.
Design genuine human oversight
The reviewer needs the original evidence, the proposed action, reasons, uncertainty, alternatives and downstream impact. They need enough time and permission to reject, ask a question or defer. Measure reversals and missed exceptions, not just throughput. Repeated approvals without opening evidence are a control warning.
Important: This is an operational boundary, not a legal classification of every AI system. Assess applicable AI, data-protection, security and professional requirements for the real deployment.
A practical policy sentence
“AI may collect, compare, summarise and propose; it may not fabricate evidence, authorize money movement, submit a filing, close a period or make an unresolved professional judgment.” Add named owners and escalation routes. Then test the policy with realistic cases, including pressure to finish a month with missing data.
Prevent automation by workaround
A hard boundary can be bypassed if users copy AI output into another system and approve it there. Design the complete operating process: restrict high-impact actions, show origin and review status in exports, and train users that retyping a suggestion does not convert it into verified evidence. Review logs and correction cases for signs that uncertainty is being cleared outside the intended workflow.
Stop and recovery procedure
Define who can pause AI-assisted processing, how affected cases are identified and how the team returns to a manual or deterministic fallback. Keep last known-good configuration and test data. After a quality, confidentiality or authorization incident, preserve evidence, assess the population exposed and require re-approval where the downstream result may be affected.
Board or owner questions
- Which decisions can move money, file externally or close a period?
- Can AI output reach those actions without an authorized reviewer?
- What evidence does that reviewer see?
- How are missing facts distinguished from model uncertainty?
- Who monitors overrides, incidents and provider changes?
- Can the business operate safely if the AI feature is unavailable?
These questions keep governance tied to business consequences rather than model marketing language.
Sources
Sources were checked on 21 July 2026. This article provides orientation and is not tax, legal, or accounting advice.
Related resources
See how DeinHans supports this workflow
Explore the product flow without confusing automation with professional approval.
View product