KPMG's top AI executive says governance is not a brake on AI, it is how you build trust into the machine before it runs.
At the Gartner CFO Symposium, KPMG's Swami Chandrasekaran reframed governance from a review step you bolt on afterward to an engineering requirement you specify up front.
On May 26, 2026, at the Gartner CFO Symposium, KPMG's global head of AI and data, Swami Chandrasekaran, put a sentence on the record that changes how to read every governance pitch that came before it. Endorsing a finance automation framework called Governed Autonomy, he said governance is not the friction layer, it is how trust gets engineered into the operating model. Read that slowly. He is not describing a policy you write, a committee you form, or a report you file after the fact. He is describing an engineering specification: the rules an AI agent must obey are built into the system before the agent acts, not reviewed after it has already acted.
The distinction is not academic, it is commercial. For five years, governance in enterprise AI has meant compliance: what to review, what to audit, what to report once the model has produced an answer. That is a service with an end date, and you sell it again next quarter. Chandrasekaran is describing something else. He wants clear boundaries, execution tied to a verified identity, and an audit trail that records every action as it happens rather than reconstructing it later. Weeks earlier, Wipro's Ivana Bartoletti reached for the same idea from a different firm, calling trust an architectural commitment rather than a compliance label. Two firms landed on the same words without coordinating. When that happens, the words are the product.
Here is why an executive should care about the difference. A compliance review can be attached to any system after the fact. An architecture cannot. If governance is specified up front, it becomes a written thing the client can hold, inspect, and keep. If it is added afterward by the firm that built the model, the client stays dependent on that firm to explain what the system did every time a regulator or a board asks. The same sentence, delivered two ways, produces two very different balance sheets: one where the client owns the control layer, and one where the client rents it indefinitely.
The buyers are already on the wrong side of this. At a procurement summit in the same window, Hackett's Chris Sawchuk reported that fewer than half of chief procurement officers feel confident they can even monitor or control the autonomous AI they are being sold. That is not a warning, it is a market. Every executive who cannot see what the agent did is a prospective buyer of the control layer Chandrasekaran just described. The open question is who ships it as something the client owns, rather than a subscription to being told it is fine.