Free template · AI governance

Firm AI use policy template

A written policy governing how your team uses AI tools: approved tools, permitted and prohibited uses, client-data rules, human review, and disclosure. Free to take and adapt.

For: Any firm whose people use AI tools on client work.

An AI use policy is the written document that says which AI tools your firm has approved, what may and may not be put into them, who reviews the output, and what you tell clients. It is the piece almost no firm has yet, and it is the first thing anyone reviewing your practice will ask for.

You need one as soon as anybody at the firm uses AI on client work, which in most firms already happened without a decision being made. The policy is what turns scattered individual habits into something the firm can stand behind: it gives your staff a clear answer on what is allowed, and it gives you a record that the firm thought about confidentiality before the fact rather than after.

The full text is below. Read it here, or download the Word version and work through the bracketed items. Every one of them is a real decision your firm has to make, and the policy is worth nothing until they are filled in.

Template text · adapt every bracketed item to your firm

Artificial Intelligence Use Policy

Template for accounting, tax, and advisory firms

Firm
[Firm Name]
Effective date
[Date]
Policy owner
[Name / Title]
Version
1.0
Before you use this template

This is a template and a starting point only. It is not legal or compliance advice, and adopting it as-is does not make your firm compliant with anything. Every firm is different: customize every bracketed item, delete what does not apply, add what your situation requires, and have your own legal counsel review the result before you implement it. See the full disclaimer at the end of this document.

1. Purpose

This policy governs how personnel of [Firm Name] (the "Firm") use artificial intelligence ("AI") tools in the course of performing professional services. Its goals are to capture the benefits of AI while protecting client confidentiality, preserving data security, maintaining the quality and integrity of our work, and upholding our professional and ethical obligations.

2. Scope

This policy applies to all partners, employees, contractors, and interns of the Firm, and to all AI tools used for Firm purposes, whether stand-alone products, features embedded in other software, or capabilities accessed through an API.

3. Definitions

  • AI tool: any software that uses machine learning or large language models to generate text, code, images, analysis, or recommendations (for example, general-purpose chat assistants, AI features in tax or accounting software, and document automation tools).
  • Confidential client data: any nonpublic information about a client or its personnel, including financial records, tax return information, and personally identifiable information (PII) such as Social Security numbers and account numbers.

4. Approved Tools

Only tools on the Firm's approved list may be used with Firm or client information. The policy owner maintains this list and reviews each tool against the Firm's vendor due-diligence criteria before approval. Complete the list below.

Approved tool 1
[Tool name, approved uses, data restrictions]
Approved tool 2
[Tool name, approved uses, data restrictions]
Approved tool 3
[Tool name, approved uses, data restrictions]

5. Permitted Uses

  • Drafting internal documents, correspondence, and summaries that contain no confidential client data.
  • Research, brainstorming, and explanation of concepts.
  • Generating and reviewing formulas, code, and workpaper logic.
  • Working with client data only in approved tools that the Firm has confirmed do not train on Firm inputs and that meet the Firm's security and confidentiality requirements.

6. Prohibited Uses

  • Entering confidential client data, PII, or tax return information into any tool that is not on the approved list, including consumer or free-tier AI products.
  • Relying on AI output as final work product without professional review and verification.
  • Using AI to make a final professional judgment (for example, an audit conclusion, tax position, or assurance opinion) without a qualified professional's independent evaluation.
  • Circumventing the Firm's security controls, or using personal AI accounts for Firm work.

7. Client Data, Confidentiality, and Legal Obligations

Personnel must protect client confidentiality at all times. Tax return information may be used or disclosed only as permitted by Internal Revenue Code section 7216 and related regulations, which may require specific client consent. The Firm's handling of client information is also governed by its Written Information Security Plan (WISP) and the FTC Safeguards Rule, the AICPA Code of Professional Conduct, and applicable state board rules. When in doubt, do not enter the information and consult the policy owner.

8. Human Review and Professional Responsibility

AI is a tool that assists, but does not replace, professional judgment. The professional who signs or is responsible for an engagement remains fully responsible for the accuracy, completeness, and appropriateness of all work product, regardless of whether AI was used to help produce it. All AI-assisted output must be reviewed, verified against source documents and authority, and corrected before use.

9. Accuracy and Verification

AI tools can produce confident but incorrect results, including fabricated citations and calculations. Personnel must independently verify any facts, figures, citations, or authorities generated by AI before relying on them in client work.

10. Client Disclosure and Consent

The Firm discloses its use of AI to clients as appropriate and obtains consent where required. See the Firm's Client AI Disclosure language and engagement letter provisions. Any disclosure of tax return information to an AI service provider must comply with IRC section 7216 consent requirements.

11. Vendor Due Diligence

Before any tool is approved, the policy owner evaluates the vendor's data handling, training practices, security posture, data retention, and contractual terms using the Firm's AI Tool Vendor Checklist. Approved tools are re-evaluated at least annually and whenever the vendor materially changes its terms.

12. Training

All personnel receive training on this policy at onboarding and at least annually thereafter. Training covers approved tools, prohibited uses, confidentiality, and verification responsibilities.

13. Monitoring and Enforcement

The Firm may monitor the use of AI tools for compliance with this policy. Violations may result in disciplinary action up to and including termination, and may be reported as required by law or professional standards.

14. Acknowledgment

I have read, understand, and agree to comply with this Artificial Intelligence Use Policy.

Name
_______________________________
Signature
_______________________________
Date
_______________________________
Disclaimer. This template is provided by Charles J Barmore CPA PC for general informational and educational purposes only. It is a starting point, not legal, tax, or compliance advice, and neither downloading nor using it creates a client, advisory, or professional relationship. It is provided "as is," without warranty of any kind, express or implied, and Charles J Barmore CPA PC disclaims all liability arising from its use. Using this template does not by itself make your firm compliant with the FTC Safeguards Rule, IRS requirements, professional standards, or any other law or regulation; compliance depends on how your firm adapts, implements, and maintains it. Laws, regulations, and professional standards change and vary by jurisdiction. Review and adapt this document to your firm's facts and have your own legal counsel and advisors review it before relying on it.

Want help putting this to work?

A document is a start. If you want AI actually implemented in your firm, safely and with the controls this template describes, let's talk. The first conversation is free.