Title card: AI for accounting firms: what to govern before the first client file. Account type, Client consent, Human approval, Ledger record, Engagement letter.

AI for accounting firms: what to govern before the first client file.

Short answer. Govern three things before AI touches a client file. First, know which account any AI tool runs on, personal or firm-provisioned. Second, require a named person to confirm every AI-proposed change before it posts to a ledger. Third, tell clients what your engagement letter says about AI. Get those three right first. Which specific tool you use is easier to fix later than a data leak or a wrong posting.

A 10 to 200 person practice does not need a research paper before it starts. It needs three decisions made once, written down, and applied to every engagement from that point on.

Where does AI already touch a small accounting practice?

Three places, whether or not a partner signed off on any of them.

Client communication drafting comes first: emails, status updates, engagement notes written with AI help and then sent under a staff member’s name. Bookkeeping proposals come second: categorisation suggestions and reconciliation matches an AI tool offers before a person confirms them. Research comes third: tax positions, standards questions, and client-specific queries staff put to an AI tool before checking the answer against a primary source.

We covered the wider set of AI options available to financial firms in the wider AI options for financial services. This piece narrows that down to what a mid-sized practice governs before any of those three uses reaches a client file.

What is the account-type question, and why does it come first?

Before any client detail goes into an AI tool, ask whose account receives it. A personal, free account belongs to the individual staff member, runs under the vendor’s consumer terms, and may let the vendor store or reuse what is typed into it. A firm-provisioned account runs under a contract your firm negotiated, with settings your firm chose.

The two accounts can run the exact same AI model underneath. The difference is who controls what happens to the data afterwards, and that difference decides whether client information just left the firm’s control. We set this out in full in before client data enters ChatGPT, identify the account. Ask the account-type question before any other AI question, because every other answer depends on it.

Why does a ledger change need a human hand on it?

An AI tool can propose a categorisation, a reconciliation match, or a journal entry. Proposing is not the same act as posting. The moment a proposal becomes a change in the client’s books, a different kind of authority applies.

We cover the distinction in in an AI-assisted close, who holds posting authority. The rule is short: no ledger entry posts on an AI proposal alone. A named person with posting authority checks the proposal against the source document and confirms it themselves. The record that follows should show three things: the proposal as the AI tool displayed it, the identity of the person who confirmed it, and the ledger entry that resulted.

This is not extra work bolted onto AI. It is the same control a well-run practice already applies to a junior bookkeeper’s first month of postings, extended to a tool that never gets more senior.

What should the client engagement letter say about AI?

Four things belong in plain language near the top of the letter, where a client will actually read them.

  • A plain statement that the firm may use AI tools as part of its work, under the firm’s supervision.
  • A statement that a qualified person at the firm reviews and approves every deliverable before the client receives it, whether or not AI helped draft it.
  • A statement that client data only enters a firm-provisioned AI account, never a personal or free one.
  • An open invitation for the client to ask which tasks involved AI assistance on their engagement.

None of this needs to read as a warning. Most clients read it as the opposite: proof the firm thought about the question before they had to ask it.

Which use carries which risk, and what closes the gap?

The table below pairs each of the three uses with its main risk and the control that answers it.

AI use Main risk The control and its record
Client communication drafting AI states something as fact that is not true, or a draft goes out before a person reads it A named reviewer reads every AI-drafted client message before it sends; the record is the reviewer’s name and the sign-off time
Bookkeeping proposals AI miscategorises a transaction or matches the wrong invoice A person with posting authority checks the proposal against the source document; the record is the proposal, the approver, and the resulting entry
Research on tax and standards questions AI states an outdated rule, or invents a citation that does not exist Staff verify every citation against the primary source before it reaches a client answer; the record is the source checked and the date checked
Client data entered into a personal AI account Client information leaves the firm’s control and the vendor’s consumer terms now govern it Only firm-provisioned accounts receive client data; the record is the account type used, tied to the engagement

What does a realistic first quarter look like?

  1. Weeks 1 to 2: name one partner or director as the AI governance owner for the practice.
  2. Weeks 1 to 3: list every AI tool currently touching firm work, and mark each one personal or firm-provisioned.
  3. Weeks 3 to 4: write the one-line posting rule, no AI proposal posts without a named person confirming it, and add it to the firm’s quality-control document.
  4. Weeks 3 to 5: draft the engagement-letter language on AI and start using it on every new engagement.
  5. Weeks 5 to 8: pick one draft-heavy task, such as client update emails, and require a named reviewer’s sign-off on every AI-assisted one for the rest of the quarter.
  6. Weeks 6 to 9: check every research citation staff hand to a client that quarter against its primary source.
  7. Weeks 9 to 12: pull the records described in the table above for one sample week, and fix whatever is missing.
  8. Weeks 12 to 13: report to the partners on what is approved, what is contained, and what is retired, and set the next review date.

What do the professional bodies expect, at the time of writing?

At the time of writing, ICAEW’s page on AI and accountants says it has updated its Professional Conduct in Relation to Taxation guidance to address AI use directly. The update reads five existing fundamental principles through an AI lens. It does not write new rules. Integrity requires a firm to be transparent about how AI supported its work. Objectivity requires staff to challenge an AI suggestion instead of accepting it as given. Professional competence requires staff to understand a tool’s limits well enough to review its output properly. Confidentiality requires client data to stay out of uncontrolled AI environments. Responsibility for the result stays with the accountant. The tool carries none of it.

AICPA publishes a small-firm generative AI policy template addressing the ethical use of publicly available large language models. Its existence signals where the professional bodies have moved: past general principles, toward a written policy a small practice can actually adopt.

CPA Canada’s AI pages take a broader advocacy position; they are guidance, not binding rules. It has not issued a binding AI rulebook. It supports responsible adoption and governance of AI, and it positions CPAs as playing a role in building trust in AI systems. It points members back to the existing CPA Code of Professional Conduct as the standard that already applies.

None of the three bodies replaces your own compliance reviewer. Confirm what applies in your jurisdiction before you rely on any summary, including this one.

Questions buyers ask.

Can we let staff use free AI chat tools for client work?

Not for anything containing client-identifiable data. A free consumer account runs under the vendor’s consumer terms, with no contract behind it protecting confidentiality. Check those terms before a client file goes in. Move any client-facing use to a firm-provisioned account first, whichever specific tool you choose.

Does an AI categorisation tool need the same approval control as a person doing the categorising?

Yes, and arguably a tighter one. A person who miscategorises a transaction can explain their reasoning afterwards. An AI proposal needs a human check against the source document every time, with a record of who confirmed it and when.

Do we need client consent to use AI on their file?

Check your own jurisdiction’s rules and your engagement letter wording, since this is not a universal answer. At minimum, disclose that AI may be used and that a qualified person reviews the output before the client sees it.

Is a professional body’s AI policy template enough on its own?

It is a starting point. It is not a finished control. A template states principles. Your firm still has to say which tools run on which accounts, who holds posting authority, and how you would show an auditor the record behind one client file.

This is the method behind the twelve tests in the Agentic AI Procurement Handbook, and it is the starting conversation I have with a practice owner before we discuss any specific tool. It is an evaluation method. It is not legal advice. Write the posting rule down this week, even before you pick a tool to apply it to.

Josh Olayemi · Founder, Handvantage · September 2026 · About the author

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *