Short answer: the policy that works isn't a ban and isn't a free-for-all. It's five rules, written in plain language, that draw a bright line around client data and give staff a sanctioned way to get their work done.
Here's what's happening at firms right now: leadership, spooked by confidentiality obligations and IRS Publication 4557, WISP requirements, and headlines about leaks, prohibits AI entirely. Meanwhile, a staff member who's behind on a deadline pastes a client's numbers into a free chatbot — because the tool they were told not to use is the only tool they were given. The ban didn't stop the behavior. It just drove it into the shadows where you can't supervise it.
The policy skeleton
1. What may touch AI: work products with client data removed, or data inside systems the firm has approved and connected. The gray zone is the enemy. Give staff a bright line: approved systems only, listed by name.
2. Nothing generated goes to a client without human review. Every summary, draft, and memo is reviewed by the preparer's reviewer, same as any workpaper. This mirrors what the profession already does — AI output gets the same treatment as work from a first-year.
3. Client data never enters unapproved public tools. Name the tools. "Public AI tools" means the free chatbots on personal accounts. Say it plainly; assume nothing.
4. Confidentiality obligations travel with the data. Tax return details, payroll records, and financial statements are confidential everywhere, including inside an AI tool. If a client has restricted handling, that restriction applies.
5. Say something when something's weird. Wrong figures, hallucinated citations, data that appeared where it shouldn't — staff report it, no punishment. The firms that learn fastest are the ones whose people aren't afraid to raise a hand.
The infrastructure question under the policy
A policy is only as good as its easiest path. If the sanctioned way to use AI is harder than pasting into a chatbot, the policy loses. That's why the deployment matters as much as the document:
- An assistant connected to the firm's actual systems gives staff a better option than the shadow one — it knows the client, it cites the workpaper, and it never sees data the firm hasn't approved.
- Firms with hard confidentiality requirements — or a WISP that reads strictly — can run the whole thing on hardware in the office, so the policy question "where may data go?" has a short answer: nowhere.
- Review is built into the tooling: drafts, never autonomous sends, same as the policy demands.
Writing it down
One page. Five rules. Named systems. A named person to ask. Review it at hiring and once a year. The IRS "Security Six" mindset already lives in your firm — this document is its AI chapter, not a new religion.
If you want a second pair of eyes on the policy — or a deployment that makes the policy easy to follow because the safe path is also the convenient one — talk with us. We'll also tell you honestly if your firm's too small to need one yet.
More: our approach for accounting firms · what on-premises AI actually means · will AI replace bookkeepers and staff accountants?
