A written policy governing how your team uses AI tools: approved tools, permitted and prohibited uses, client-data rules, human review, and disclosure. Free to take and adapt.
An AI use policy is the written document that says which AI tools your firm has approved, what may and may not be put into them, who reviews the output, and what you tell clients. It is the piece almost no firm has yet, and it is the first thing anyone reviewing your practice will ask for.
You need one as soon as anybody at the firm uses AI on client work, which in most firms already happened without a decision being made. The policy is what turns scattered individual habits into something the firm can stand behind: it gives your staff a clear answer on what is allowed, and it gives you a record that the firm thought about confidentiality before the fact rather than after.
The full text is below. Read it here, or download the Word version and work through the bracketed items. Every one of them is a real decision your firm has to make, and the policy is worth nothing until they are filled in.
Template for accounting, tax, and advisory firms
This is a template and a starting point only. It is not legal or compliance advice, and adopting it as-is does not make your firm compliant with anything. Every firm is different: customize every bracketed item, delete what does not apply, add what your situation requires, and have your own legal counsel review the result before you implement it. See the full disclaimer at the end of this document.
This policy governs how personnel of [Firm Name] (the "Firm") use artificial intelligence ("AI") tools in the course of performing professional services. Its goals are to capture the benefits of AI while protecting client confidentiality, preserving data security, maintaining the quality and integrity of our work, and upholding our professional and ethical obligations.
This policy applies to all partners, employees, contractors, and interns of the Firm, and to all AI tools used for Firm purposes, whether stand-alone products, features embedded in other software, or capabilities accessed through an API.
Only tools on the Firm's approved list may be used with Firm or client information. The policy owner maintains this list and reviews each tool against the Firm's vendor due-diligence criteria before approval. Complete the list below.
Personnel must protect client confidentiality at all times. Tax return information may be used or disclosed only as permitted by Internal Revenue Code section 7216 and related regulations, which may require specific client consent. The Firm's handling of client information is also governed by its Written Information Security Plan (WISP) and the FTC Safeguards Rule, the AICPA Code of Professional Conduct, and applicable state board rules. When in doubt, do not enter the information and consult the policy owner.
AI is a tool that assists, but does not replace, professional judgment. The professional who signs or is responsible for an engagement remains fully responsible for the accuracy, completeness, and appropriateness of all work product, regardless of whether AI was used to help produce it. All AI-assisted output must be reviewed, verified against source documents and authority, and corrected before use.
AI tools can produce confident but incorrect results, including fabricated citations and calculations. Personnel must independently verify any facts, figures, citations, or authorities generated by AI before relying on them in client work.
The Firm discloses its use of AI to clients as appropriate and obtains consent where required. See the Firm's Client AI Disclosure language and engagement letter provisions. Any disclosure of tax return information to an AI service provider must comply with IRC section 7216 consent requirements.
Before any tool is approved, the policy owner evaluates the vendor's data handling, training practices, security posture, data retention, and contractual terms using the Firm's AI Tool Vendor Checklist. Approved tools are re-evaluated at least annually and whenever the vendor materially changes its terms.
All personnel receive training on this policy at onboarding and at least annually thereafter. Training covers approved tools, prohibited uses, confidentiality, and verification responsibilities.
The Firm may monitor the use of AI tools for compliance with this policy. Violations may result in disciplinary action up to and including termination, and may be reported as required by law or professional standards.
I have read, understand, and agree to comply with this Artificial Intelligence Use Policy.
A document is a start. If you want AI actually implemented in your firm, safely and with the controls this template describes, let's talk. The first conversation is free.