Key Insights

  • Analysts at Boston Consulting Group (BCG) believe that software coding driven by generative AI is poised to benefit finance teams, but CFOs need to establish strong governance frameworks to mitigate potential operational and compliance risks.
  • "Vibe coding"—where users describe desired functionality in natural language rather than writing code themselves to create software applications—may soon permeate a wide range of finance processes, analysts at BCG's Center for CFO Excellence said in a recent report. However, they noted that without proper controls, it could quickly introduce new risks.
  • "If executed well, AI-driven [code] development will provide finance teams with a faster path to building the applications they have always needed but rarely had the resources to develop," the authors wrote.

In-Depth Analysis

The term "vibe coding" was first coined by OpenAI co-founder Andrej Karpathy on the X platform in February 2025.

Coding agents such as Claude Code and OpenAI Codex can write and execute code, process structured data, and build applications based on natural language instructions, BCG analysts wrote.

"Innovation in this space is rapidly expanding the capabilities of agent-driven coding platforms," they said. "This enables both finance analysts and IT departments to accelerate development cycles."

BCG predicts that finance organizations will increasingly adopt these tools, allowing teams to build software on their own even with little to no coding experience. This could accelerate the development of applications for tasks such as forecasting, anomaly detection, and document review.

But the authors warned that the very ease of use that makes vibe coding attractive could also introduce new risks if adoption outpaces governance.

In a March report, researchers at the Cloud Security Alliance (CSA), a nonprofit focused on cybersecurity, noted that organizations are integrating AI-generated code into production systems at scale, while governance frameworks remain in early stages.

"The security risks of AI-generated code are not random or edge cases—multiple independent research efforts have found consistent and reproducible failure patterns," the CSA report stated.

Beyond security concerns, BCG warned that vibe coding could also open the door to auditability risks and potentially trigger "AI sprawl" within finance departments, creating complexity and management challenges for CFOs.

"If CFOs allow teams to build freely without a governance framework, they could replace 'shadow Excel' with 'shadow code'—undocumented scripts and applications that exist outside official systems without proper oversight," the authors said. "Shadow code is harder to detect until something goes wrong."

BCG analysts believe that AI coding applications should not replace core platforms for accounting, planning, and reporting, but rather sit on top of them, making data and insights more accessible, usable, and interpretable.

Additionally, they advised leaders to carefully select initial use cases, prioritizing areas with manageable risk. The authors also emphasized that coding agents cannot replace human judgment.

"CFOs will still need employees who can interpret results, apply policies, and make decisions in ambiguous situations," the report stated.