Modernizing Procurement and Financial Controls Without Replacing Legacy ERP: A Governance-First AI Architecture
Main Article Content
Abstract
There is a fundamental architectural barrier to organizations in regulated industries using artificial intelligence for procurement and finance functions: regulation makes it extremely difficult‚ if not impossible‚ for organizations to change legacy enterprise resource planning systems․ Governance frameworks in regulated industries demand accountability, traceability, auditability, and explainability of decision-making. Customary digital transformation approaches that assume the ability to adapt or replace the legacy systems are not fit for that purpose․ We propose a governance-first reference architecture that applies non-intrusive external integration patterns, governed data planes, and AI service components to legacy ERP systems while treating auditability, traceability, explainability, and human oversight as cross-cutting architectural properties rather than as a compliance or ethical tier. The reference architecture does not consider governance only as a post-process step but rather as a design principle that governs all of the data flows, model lifecycles, and decision flows. Use cases in procurement and financial control, such as vendor risk scoring, invoice anomaly, and spend classification, illustrate the role of AI in risk detection, decision quality improvement, and process efficiency. They also show that AI does not replace decision-making concerning material matters: the architecture includes risk mitigation strategies against issues such as model drift‚ algorithmic bias‚ lack of model explainability‚ and data privacy․ This phased approach to deployment is consistent with the enterprise's readiness for adoption and the concept of digital transformation as controlled augmentation․ It provides regulated organizations with a realistic, compliance-friendly approach to developing and deploying the AI capabilities they need into an existing enterprise architecture without sacrificing control, regulatory defensibility, or institutional trust.