AI & Finance

What is MCP? A guide for finance teams: how AI assistants safely access your figures (2026)

1 September 2026 · Karel Gonzalez Hulshof

MCP is popping up everywhere — in AI tools, in product announcements, and increasingly in a colleague’s question: “do we have an MCP?” What the Model Context Protocol is, why it exists and what it concretely gets a finance team — without the jargon.

A background graphic.
1 standard
one open protocol for all AI assistants — no connection per tool
2024-2026
from introduction to a broadly supported standard in the major AI tools
Read-only
a finance MCP should read, never write
SUMMARY

What is MCP: the open standard through which AI assistants like Claude and ChatGPT safely query external data — for finance: asking questions of your consolidated Finstack figures (from EUR 39/month).

What is MCP? A guide for finance teams: how AI assistants safely access your figures

One plug between your AI assistant and your data sources — and why that changes more for finance than yet another integration.

TL;DR
MCP (Model Context Protocol) is an open standard through which AI assistants can safely retrieve data from external systems — one protocol that works in Claude, ChatGPT and every other tool that supports it, instead of a separate connection per assistant. For finance it means: asking questions of your own figures in plain language, without exports or copy-paste. The condition is a data layer that offers the figures analysis-ready — consolidated, structured, read-only — the way the Finstack MCP does with the reporting data, from EUR 39/month.

What is MCP (Model Context Protocol)?

MCP stands for Model Context Protocol: an open standard that describes how an AI assistant can safely retrieve information from external systems — databases, applications, data sources. The protocol was introduced in late 2024 by Anthropic (the company behind Claude) and broadly embraced since: the major AI tools, including ChatGPT, now support the standard, and the ecosystem of connections is growing fast.

The idea behind it is simple. An AI assistant knows a lot, but it does not know yóur data: your figures, your customers, your systems. Before MCP there were two ways to solve that: pasting data into the chat window by hand (with all the drawbacks that brings), or building a dedicated integration per AI tool — a hopeless task in a market where new tools appear every month. MCP replaces both with one agreement: a system offers its data once through the protocol, and every assistant that speaks the standard can work with it from then on.

The common comparison is the plug: just as USB offered one connector for devices that each used to have their own cable, MCP offers one connector between AI assistants and data sources. Whoever works with Claude today and another assistant next year keeps the same connection — nothing has to change on the data side.

Technically, an MCP connection consists of a “server” on the data side — the counter that answers the assistant’s requests — and a client in the AI tool. For the user that is invisible: you add the connection to your assistant once and simply ask questions from then on. What that concretely delivers for finance is the rest of this article.

Why does MCP exist — what problem does it solve?

The problem is older than AI: valuable data sits locked inside systems, and every place you want to use it requires its own route out. For finance teams that route was the export, for years — and the rise of AI assistants did not make it better, just more visible. Whoever wants to ask their assistant something about the figures first has to export, paste and hope the file is complete. Every question starts with manual work, the data goes stale from the moment of exporting, and sensitive figures drift through chat histories.

The classic solution — a custom integration — does not scale in the AI era. Building a connection for one assistant means starting over as soon as the team uses a second tool or switches; and AI tools change fast. That is exactly what makes an open standard valuable: the investment sits on the data side, once, and works for every assistant afterwards — including the tools yet to appear.

There is a security argument too. Copy-paste knows no permissions: whoever has the file has the data. An MCP connection, by contrast, is a managed access point: the data side determines whát can be queried and who has access, can enforce read-only, and can switch access on and off per user. The data stays in the source system; per question the assistant retrieves only what that question needs — no full exports.

For finance there is a third layer the protocol itself does not solve, but does make possible: the quality of what flows through the plug. That is the next section — because that is where the difference is made between an AI that chats and an AI that is right.

What does MCP concretely get a finance team?

The short answer: you ask your questions of your assistant instead of your export folder. “Where do my figures deviate from budget this quarter?”, “How is the margin developing per cost center?”, “Which entity is behind on the forecast?” — with an MCP connection to the figures, the assistant retrieves the current data itself and answers the question with the calculation included.

But the honest answer has a condition, and for finance it matters more than the protocol: the quality of the data source. MCP is a plug — what comes out depends on what sits behind it. A connection to raw general-ledger data per administration gives the AI the same problem as an export: adding up across entities itself, double counts through uneliminated intercompany flows, guessing which accounts together form “margin”. Exactly the multi-step arithmetic where language models demonstrably make the most mistakes.

That is why a finance MCP belongs on a data layer that offers the figures analysis-ready. The Finstack MCP is such an implementation: it opens up the consolidated reporting data — with filters per entity, general ledger account and cost center, with or without eliminations, in every configured reporting structure, and with actuals and forecast (including the budget) side by side. The AI does not have to calculate, only retrieve and interpret — and every answer aligns with the definitions of the monthly report.

What then becomes possible is worked out in the deep-dives of this cluster: preparing the management report with AI, forecasting with AI and building financial dashboards with AI — all on the same connection.

How secure is an MCP connection for financial data?

More secure than the practice it replaces — provided it is set up well. The comparison that counts is not MCP versus nothing, but MCP versus what teams do today: emailing exports, pasting files into chat windows, copies on drives. Against that background, a managed connection brings three improvements.

Read-only by design. A well-configured finance MCP can deliver figures, but change nothing: no bookings, no mappings, no reporting setup. The Finstack MCP is built that way — the administration and the reporting remain untouchable, whatever the assistant asks.

Access as a switch. The connection has its own permissions: switchable on and off per user. Whoever has access to the Finstack MCP can query the full reporting data — in this version the access cannot be sliced further per entity — so the practical rule is: grant it only to those who may see the consolidated figures anyway, typically the finance team itself. Sharing with other readers stays with the dashboards and their per-user rights.

A minimal data flow. Per question the assistant retrieves only the figures that question needs — no complete exports lingering around. What the AI vendor then does with that conversation data is determined by your subscription and settings: the business variants of Claude and ChatGPT do not train on conversation data by default; with free consumer versions it is a setting to check yourself.

The full trade-off — including the advice on business licenses and the permissions policy — sits in the main article on connecting AI to your accounting software. The core for here: the protocol makes managed, minimal and revocable access possible — three things the export practice never had.

Which AI tools support MCP?

The standard started with Claude — Anthropic introduced the protocol and built support first — but the strength of MCP is precisely that it did not stay there. ChatGPT now supports the standard as well, and the broader market of AI tools is moving the same way: for tool builders, one supported protocol is just as attractive as it is for data sources, because every supported connection makes their assistant more valuable without custom integration work.

For the Finstack MCP that concretely means: tested with Claude and ChatGPT, and working with every AI interface that supports the standard. The connection is deliberately built general — not an integration per tool, but one counter for all of them. If your team uses a different assistant next year, the connection simply moves along: add it in the new tool, done.

That future-proof character matters more for the tool choice than the question of which assistant is best today. The AI market moves fast; nobody knows which tool does the work in two years. A connection on an open standard makes that question unimportant for the data side — there is no lock-in to one vendor, and the investment in the data layer keeps its value whichever logo sits on the chat window.

And for whoever wants an AI route without MCP: the Excel and Google Sheets add-in from the same Integrator pack delivers the same reporting data in the spreadsheet, where AI assistants like Claude in Excel work with it directly. Both routes, one data basis — the choice is work preference, not a functionality question. The practical side of connecting sits in the next sections and in the main article.

MCP, API or add-in: what is the difference?

Three terms that get mixed up in this conversation — and a mnemonic that keeps them apart: the API is for software, the MCP is for AI assistants, the add-in is for spreadsheets.

An API is a system’s generic interface, built for developers: powerful, but it takes programming work and knowledge of the data structure. Accounting packages have APIs for software vendors — that is how Finstack connects with Exact, AFAS, Twinfield, Xero, QuickBooks and MS Dynamics 365 BC — but an AI assistant cannot use them independently.

An MCP connection is the AI-friendly counter on top: the data source describes in the protocol whát can be asked, and the assistant queries that on its own — no programming on the user’s side, in plain language.

An add-in brings the same data to where much finance work already happens: the spreadsheet. The Finstack Excel and Google Sheets add-in keeps the own model filled with current figures through a 2-way sync — budget and forecast keep living in the model, the actuals land next to them automatically. And whoever uses an AI assistant ín the spreadsheet, like Claude in Excel, combines both worlds: the add-in keeps the figures fresh, the assistant analyzes them on the spot.

At Finstack the latter two sit together in the Integrator pack: one add-on, two routes to the same data basis. That is no coincidence but the core of the design — it does not matter whére the team works (chat, spreadsheet or dashboard), as long as every route delivers the same consolidated figures. The routes trade-off sits in more detail in the main article.

How do you use an MCP connection in practice?

The use is deliberately unspectacular — that is the point of a standard. Set up once: switch on the access in the Finstack environment for the users who may have it, and add the connection in the AI tool — Claude, ChatGPT or another assistant that supports the standard. No technical project involved; it is a setting, not an implementation.

After that the connection is simply present in every conversation. Ask your assistant something about the figures, and it does the groundwork itself: first querying which reporting structures, entities and cost centers exist in the environment, then retrieving the right figures — current at that moment, in the layout of your reporting. You notice the connection mostly by what disappears: no more exports to run, no files to supply, no doubt whether the figures are still right.

A few usage habits make the difference between toy and instrument. Work on the reporting structure, so the definitions align with the monthly report. Start with questions you know the answer to, and verify important outcomes in the reporting environment — the same figures sit there, clickable through to the source. And capture recurring analyses as a fixed working instruction, as worked out in creating management reports with AI.

What it costs: the Finstack MCP sits in the Integrator pack, the add-on that also contains the 2-way spreadsheet sync; Finstack itself starts from EUR 39 per month for the first entity, with no implementation fees and a 14-day free trial. On top you need a business license for your AI assistant. For the wider landscape: the overview of the best reporting software for SMEs lines up the tools.

finstack tip

Judge a finance MCP not on the protocol but on the data source behind it: is it consolidated, structured and read-only? The plug is standard — what flows through it determines whether your AI answers are right.

Explore Finstack.
Free trial for 14 days.

Access to all features. No credit card required.

No credit card needed
Live within 5 minutes
Forecasting and Consolidation
A design element side_graph

The 3 most common mistakes around MCP and finance data

Three patterns we keep seeing now that MCP is entering finance conversations. Each costs trust or security; each is avoidable.

Judging an MCP on the protocol instead of the data source

“We have an MCP” says about as much as “we have a plug”. The question that counts: what sits behind it? Raw general-ledger data per administration gives the AI the same problems as an export — adding up itself, double counts, its own definitions. Judge every finance MCP on the data layer: consolidated, structured, read-only.

Handing out MCP access like a view link

Whoever may use the connection can query the full reporting data — it is data access, not a dashboard link. Handing access to readers who should only see part of the picture bypasses the permissions structure. Keep the MCP with the finance team and let sharing run through the dashboards with rights per user.

Waiting or building custom because the standard feels new

Some teams postpone until “it has proven itself”, others build a custom connection for one specific assistant in the meantime. Both lose: the standard ís broadly supported by now, and custom work goes stale at the first tool switch. One connection on the open standard works today and moves along.

Frequently asked questions

Can't find your question? Let us know

What does MCP stand for?

An arrow down icon.

MCP stands for Model Context Protocol: an open standard that describes how AI assistants safely retrieve data from external systems. One connection built on the protocol works in every assistant that supports the standard — the way one USB port works for every device, instead of a cable per brand.

Who created MCP and is it really open?

An arrow down icon.

The protocol was introduced in late 2024 by Anthropic, the company behind Claude, and released as an open standard — the specification is public and any party can build connections or support for it. That makes it a shared agreement rather than a vendor product, by now broadly supported by the major AI tools.

Which AI tools support MCP?

An arrow down icon.

Claude supported the standard first; ChatGPT followed, and the broader market is moving the same way. The Finstack MCP is tested with Claude and ChatGPT and works with every AI interface that supports the standard — it is deliberately one general connection, not an integration per tool.

Is MCP safe for financial data?

An arrow down icon.

Safer than the export practice it replaces, provided it is set up well: read-only access, per-user rights you switch on and off, and per question only the required figures instead of complete files. Also use a business AI license without training on company data; see the main article for the full framework.

What is the difference between an MCP and an API?

An arrow down icon.

An API is the interface for software developers: powerful, but it takes programming work. An MCP connection is the AI-friendly counter on top: the data source describes what can be asked, and an AI assistant queries it independently, in plain language — without the user having to build anything.

What do I need to use MCP with my accounting figures?

An arrow down icon.

A data layer that offers the figures analysis-ready through the protocol — like Finstack, which opens up the consolidated reporting data with actuals and forecast through the Integrator pack — plus an AI assistant with MCP support and a business license. Setting up is a matter of switching on access and adding the connection.

What does an MCP connection to my figures cost?

An arrow down icon.

At Finstack the MCP sits in the Integrator pack, the add-on that also contains the 2-way Excel and Google Sheets add-in; Finstack itself starts from EUR 39 per month for the first entity, with no implementation fees and a 14-day free trial. There is no implementation project — it is a setting.

Karel Gonzalez Hulshof

CFO turned Founder - Finstack

LinkedIn

Sources and provenance

Last reviewed: 1 September 2026 · Next review: December 2026