The one-page AI policy every accounting firm needs (write it this week)
Nearly every accountant is already using AI, but only about one in five firms has a written policy governing it, which means the real policy is whatever each person quietly decides at their desk. This walkthrough gives you a complete one-page AI policy in seven sections, with model wording you can copy, adapt, and ship this week.
Trent McLaren · 22 July 2026 · 10 min read
In this article
- Why a one-pager beats an AI committee
- The policy: seven sections, ready to adapt
- 1. Approved tools
- 2. What data may (and may never) go in
- 3. Tier requirements: business tiers only for client data
- 4. Human review: nothing reaches a client unreviewed
- 5. Disclosure stance
- 6. Who approves new tools
- 7. Review cadence
- Rolling it out without the eye-rolls
- When to revisit it
- Frequently asked questions
- Does my firm legally need an AI policy?
- What should an accounting firm's AI policy ban?
- Can I use free AI tools with client data?
- Do I have to tell clients we use AI?
- How often should we update the policy?
Part of our AI in accounting coverage. See the full AI for accounting firms guide →
Two numbers that should not be able to coexist: 98% of accounting professionals already use AI in some form, and only about 21% of firms have a written AI policy. We covered that gap in 98% of accountants already use AI: only 1 in 5 are doing it on purpose, and the response was a lot of firm owners quietly admitting they're in the 79%.
Be clear about what "no policy" means. It doesn't mean your firm isn't using AI. It means your firm's AI policy is whatever each team member has individually decided at their desk, on whatever account they signed up with, pasting whatever they felt like pasting. That's not a documentation gap. It's an unmanaged risk with your clients' financial data attached.
The fix is not a working group. It's one page, seven sections, written this week. Here's the wording.
One caveat, stated once and plainly: this is practical guidance, not legal advice. Obligations vary by jurisdiction and by what your firm does. Adapt the wording below, and where your work touches regulated data, check it with your professional body, insurer, or lawyer.
Why a one-pager beats an AI committee
The instinct, when firms finally decide to "do something about AI," is to do too much: form a committee, commission a 20-page framework, schedule a quarterly steering meeting. Six months later there's still no policy, and the team has spent six more months pasting client data into free chatbots.
A one-page policy wins because it ships. The perfect framework you'll write next quarter protects nobody today. Because people actually read one page, and a policy nobody reads is a policy nobody follows. And because AI tools change monthly, so a short policy you revisit twice a year stays accurate longer than a long one you wrote once and framed.
The professional bodies broadly agree. The AICPA doesn't tell firms to ban AI or embrace it indiscriminately: its guidance centres on governance, documentation, and professional judgment. ICAEW says treat AI output with the same professional scepticism you'd apply to a junior colleague's work. CPA Australia and CA ANZ point members to APES 110, whose technology revisions fold AI into the fundamental principles of competence, due care, and confidentiality. None of them require a 20-page document. All of them require that you've actually thought about it, and can show you have.
So here is the policy. Seven sections. The blockquotes are model wording: copy them, replace the bracketed bits, delete what doesn't apply, and put a partner's name at the bottom.
Prefer it assembled for you? There's a free AI policy generator built for accounting and bookkeeping firms, sponsored by Vinyl and Strategic Group, that walks you through the same decisions and produces a ready-to-adapt document. (Disclosure: Vinyl is a commercial partner of The Firm.) Use it as a starting point, then tailor the result with the sections below.
The policy: seven sections, ready to adapt
1. Approved tools
Name the tools your firm has actually vetted, and the specific accounts. "We use ChatGPT" is not a policy; "we use ChatGPT Business under the firm's workspace" is. Everything not on the list is not approved, an easier rule to enforce than a ban list you'd update weekly.
Team members may use the following AI tools on firm-managed accounts only: [e.g. ChatGPT Business, Claude for Work, Copilot under our Microsoft 365 tenant, and AI features built into our practice software]. Any tool or account not on this list is not approved for client work, including personal accounts for the same products. Requests to add a tool go through the process in section 6.
2. What data may (and may never) go in
This is the section your professional obligations hang on. The AICPA Code (section 1.700.001) prohibits disclosing confidential client information without consent, and submitting client data to a third-party AI platform is a disclosure. APES 110 imposes the same principle on CPA Australia and CA ANZ members; CPA Australia's ethics centre has said flatly that uploading client data into a public AI tool that doesn't guarantee confidentiality is a breach, and ICAEW's guidance says the same in spirit.
Client-identifiable information (names, financials, TFNs/SSNs/NI numbers, payroll data, ledger extracts, correspondence) may only be entered into approved tools on firm business-tier accounts (section 3). It may never be entered into free or personal AI accounts under any circumstances. When a task doesn't need client identity, de-identify first: "a hospitality client with $2m revenue" instead of the client's name.
If you handle personal information in Australia, the Privacy Act and the APPs sit on top of this: obligations around use, disclosure, and security of personal information. In the US there's no single federal equivalent, but state board rules, state privacy statutes, and IRS rules on taxpayer data can all bite. This is the paragraph where "get proper advice" genuinely applies.
3. Tier requirements: business tiers only for client data
Here's the distinction most firms miss, and it's the most important line in this policy. Consumer AI accounts can use your conversations to train future models by default; business and enterprise tiers don't. The product looks identical in the browser. The data handling is not. (The full vendor-by-vendor terms are in Is AI safe for client data?, and what these tools get wrong lives in the limitations of AI in accounting.)
Client data may only be processed through business or enterprise tiers of approved tools, where the provider's terms state that inputs are not used for model training by default. Free and consumer-tier accounts may be used for generic tasks only (drafting a job ad, explaining a concept, tidying an internal email), never anything containing client or firm-confidential information.
4. Human review: nothing reaches a client unreviewed
No AI is ever going to jail for you. It won't front your professional standards board, and it won't be named on the PI claim. ICAEW's framing is the right one: review AI output as if a less experienced junior prepared it, because it hallucinates, invents references, and gets confidently, fluently wrong.
No AI-produced work (advice, calculations, correspondence, workpapers, anything) reaches a client without review by a qualified team member who takes responsibility for it. AI output is treated as a first draft from a junior, not a finished product. The reviewer's name goes on the work, and the reviewer owns it.
5. Disclosure stance
Do you tell clients you use AI? No universal rule requires it. The AICPA's position is that disclosure depends on how AI is used, what data is involved, and client expectations. What a policy needs is a stance, so nobody improvises one under pressure.
Our position: we use approved AI tools to improve efficiency, under the data and review rules in this policy, and we answer honestly and specifically when clients ask. Where AI use is material to an engagement [or where an engagement letter, regulator, or standard requires it], we disclose proactively. No team member should ever deny or obscure our use of AI.
6. Who approves new tools
New tools will appear weekly and your team will want to try them. Good: that curiosity is an asset. It needs a doorway, not a wall.
[Named partner/manager] approves new AI tools. To propose one, send: what it's for, what data would go into it, which tier we'd buy, and what the provider says about training and data retention. Approval or rejection within [one week]. Until approved, don't use it for client work.
7. Review cadence
A policy with no review date is a policy with an expiry date: it just doesn't tell you when.
This policy is reviewed every six months by [name], and immediately if: a provider changes its data terms, we adopt a new tool, an incident occurs, or regulation or professional-body guidance changes. Current version: [date]. Questions go to [name]. Asking is always the right move.
Rolling it out without the eye-rolls
The rollout matters more than the document. If this lands as "compliance has found a new hobby," your team will nod in the meeting and change nothing at their desks.
So lead with amnesty: "Most of us are already using AI, including on things this policy now covers. Nobody is in trouble for anything before today." Without that, everyone hides their current usage and you've written a policy for a firm that doesn't exist. Then frame the policy as what it actually is: permission. Staff using free chatbots on the quiet aren't reckless. They're unguided, and a policy that says "here are the tools, here are the paid tiers the firm provides, here's the line you don't cross" hands them better tools than the ones they were hiding. Walk it through in one 30-minute meeting, take questions, and have everyone confirm in writing that they've read it. Small ceremony, but it's the paper trail your insurer will one day be glad exists.
When to revisit it
Put the six-month review in the calendar now, but treat these as immediate triggers: a provider changes its training or retention terms (it happens, quietly, in terms-of-service updates); you adopt a new tool, or your practice software bolts on AI features you didn't ask for; anything goes wrong, even mildly (a near-miss paste of client data into the wrong account is a review trigger, not just a quiet word); or your professional body updates its guidance. The review will usually take twenty minutes and change three lines. That's the point: a living one-pager beats a dead framework.
The gap between 98% usage and 21% policy is the most closeable gap in the profession, and closing it costs one page and one team meeting. For the broader playbook (tools, workflows, and where AI actually pays off), start with our guide to AI for accounting firms.
Frequently asked questions
Does my firm legally need an AI policy?
No statute says "accounting firms must have an AI policy." But your existing obligations (confidentiality under the AICPA Code or APES 110, privacy law where it applies, engagement terms, PI insurance conditions) already govern what happens when client data goes into an AI tool. A written policy is how you show you're meeting them on purpose rather than by luck. Legally optional; professionally, the cheapest risk control you'll implement this year.
What should an accounting firm's AI policy ban?
Keep the ban list short and absolute: no client-identifiable data in free or consumer-tier AI accounts, ever; no unapproved tools for client work; no AI-produced work reaching a client unreviewed; and no denying the firm's AI use if a client asks. Resist banning categories of tasks: "no AI for tax research" ages badly and pushes usage underground. Ban the data flows and the unreviewed output, not the curiosity.
Can I use free AI tools with client data?
No. Free consumer tiers of major AI tools can use your inputs for model training by default, and the professional bodies treat putting client data into a public AI tool that doesn't guarantee confidentiality as a breach. If the data belongs to a client, it goes through a business or enterprise tier of an approved tool, or it doesn't go in at all.
Do I have to tell clients we use AI?
There's no blanket requirement from the major professional bodies. The AICPA makes it a judgment call based on how AI is used, what data is involved, and what clients would reasonably expect. The practical standard: never hide it, answer honestly when asked, and disclose proactively when AI use is material to the engagement or a letter, regulator, or standard requires it.
How often should we update the policy?
Every six months on a fixed date, and immediately when any trigger fires: a provider changes its data terms, you add a tool, an incident or near-miss occurs, or professional-body guidance changes. Most reviews will be twenty minutes and a couple of edited lines. If a review comes around and nothing needs changing, that's not wasted time. That's the system working.
AIPractice Technology