Here’s an uncomfortable truth: if your firm has more than two people, someone is already using AI for client work. They’re pasting transactions into ChatGPT. They’re drafting emails with Claude. They’re running research queries on their personal accounts.
They’re doing this without a policy, without approved tools, and without a clear understanding of what’s safe and what isn’t.
I know because I was that person six months ago. And the only reason it didn’t become a problem is luck, not process.
This article gives you a practical AI policy you can implement this week. Not a 30-page legal document. A one-page framework that answers the three questions every accountant in your firm needs answered: What tools can I use? What data can I put in? How do I verify what comes out?
Three things changed in the last 6 months that make an AI policy urgent:
1. Consumer AI plans train on your data. ChatGPT Plus and Claude Pro — the $20/month plans most people use — can use your conversations to improve future models. If your staff is pasting client financials into these tools, that data is potentially entering training sets that other people’s queries will draw from. This is a confidentiality issue that doesn’t surface until it’s too late.
2. Enterprise clients are asking. More RFPs and client onboarding questionnaires now include questions about AI usage: “Does your firm use AI tools? How do you protect our data?” The firms that can answer clearly will win engagements. The firms that can’t will lose them.
3. Regulation is coming. The current administration is pushing for unified national AI standards. State-level proposals are already in play. Whatever framework emerges will almost certainly include data handling requirements for professional services. Having a policy in place now means you’re ahead of compliance, not scrambling to catch up.
Your policy needs to answer exactly three questions. Everything else is secondary.
Create a simple three-tier list:
Approved for client work:
Approved for internal use only (no client data):
Not approved:
This list takes 10 minutes to create and answers 80% of the questions your team has.
Use the tri-tier system:
NEVER put into any AI tool:
ANONYMIZE before putting into approved tools:
SAFE to use in approved tools:
Print this on a single page. Pin it next to every monitor in your office. It takes 30 seconds to check before every prompt.
Every piece of AI output used in client work must pass these checks:
Before using any AI output:
The verification step is what separates “using AI responsibly” from “gambling with your license.” It takes 5-15 minutes per task. It’s the price of admission.
Add a clause to your engagement letters that covers AI use. This protects you and sets client expectations. Here’s a starting point:
“Our firm may use AI-assisted tools for certain analytical and administrative tasks, including but not limited to transaction categorization, research starting points, document drafting, and data analysis. All AI-generated output is reviewed and verified by a licensed professional before incorporation into client deliverables. Client data is anonymized before processing through any external AI system. We use enterprise-grade AI platforms with contractual data privacy protections that prohibit the use of client data for model training.”
This is a starting point, not final language. Have your attorney review and customize it for your practice. The key elements: disclose AI use, confirm human review, confirm anonymization, confirm enterprise-grade tools.
The biggest mistake firms make with AI policies is treating them like compliance documents. You send a 10-page PDF, nobody reads it, nothing changes.
Instead:
Week 1: Announce and educate. 15-minute team meeting. Show the one-page policy. Walk through one example of the anonymization workflow. Answer questions. That’s it.
Week 2: Set up approved tools. Get ChatGPT Team or Claude Team accounts. Set them up with firm email addresses. Cancel any personal subscriptions being used for client work.
Week 3: Monitor and adjust. Ask your team what’s working and what’s friction. The policy should make their work easier, not harder. If the anonymization step is too cumbersome, find ways to streamline it. If the verification checklist is too long, pare it down to the essentials.
Ongoing: Review quarterly. AI tools and policies change fast. Review your approved tools list every quarter. Update the policy when new tools or regulations emerge.
Let’s be honest about the investment:
Compare that to the cost of one confidentiality breach, one E&O claim, or one lost enterprise client who asked about your AI policy and got a blank stare.
The math is not close.
If you’re a one-person shop, you still need a policy. Not for compliance theater — for your own discipline.
Write a half-page version that answers the same three questions. Pin it where you work. Follow it every time, even when you’re in a rush. Especially when you’re in a rush — that’s when shortcuts happen.
Add the engagement letter clause to your standard engagement letter. This protects you and signals to clients that you’re thoughtful about technology.
If you’re handling any client data in AI, upgrade to a Team plan. $25/month. You’ll spend more than that on coffee this month.
The risk isn’t that AI will make a mistake. AI will definitely make mistakes. The risk is that when it does, you have no documentation showing you used it responsibly.
“I was careful” is not a defense. “Here is our AI usage policy, here are our approved tools with contractual privacy protections, here is the verification checklist we follow, and here is the engagement letter clause that disclosed AI use to the client” — that’s a defense.
Build the policy. It takes an afternoon. It protects your career.
The free PDF includes a Data Safety Quick Guide with the complete tri-tier system, a 10-point Verification Checklist, and 50 prompts with built-in safety features. Download it here.
Get 50 copy-paste prompts delivered to your inbox — free.
Get the Free PDF →