Day 05 Firm Policy

Build Your Firm's AI Policy

Every accounting firm — from a sole proprietor to a Top 100 — needs a written AI policy. Today you draft yours: approved tools, prohibited inputs, client consent, documentation, supervision. Aligned to AICPA Rule 1.700 confidentiality and the AICPA Code of Professional Conduct.

~45 min Day 5 of 5 By Bo Peng Hands-on

Today's Goal

By the end of this lesson you will have a one-page AI policy for your firm covering approved tools, prohibited inputs, client consent under IRC section 7216 and AICPA Rule 1.700, mandatory documentation, supervision and review, and incident response. The template is designed to satisfy AICPA Quality Management Standards and to give your professional liability insurer something to point to.

What you'll learn

Why a written policy matters

Three audiences are watching. First, the AICPA, through peer review and Quality Management Standards, expects firms to address technology resources in their system of quality management. Second, your professional liability insurer increasingly asks about AI policies on renewal applications, and an unfavorable answer can move your premium. Third, your clients — especially the sophisticated ones — will ask about your AI practices, and you want a coherent answer in writing rather than improvised on a call.

The policy does not need to be long. A one-page document that covers the essentials beats a thirty-page treatise that nobody reads. The eight sections below are a starting structure; adjust for your firm's size, practice mix, and risk tolerance.

Section 1: Scope and definitions

State what the policy covers. "AI tools" means generative AI services including but not limited to ChatGPT (OpenAI), Claude (Anthropic), Gemini (Google), Microsoft 365 Copilot, GitHub Copilot, and any tool that processes client information through a large language model. State that the policy applies to all partners, professional staff, contractors, and interns.

Section 2: Approved tools

List the AI tools the firm has approved for use, the data classifications each can handle, and any restrictions. This is the most important section because it is the one staff actually look up.

# Example approved-tools matrix
| Tool                             | Public Data | Internal | Confidential | Client Data |
|----------------------------------|-------------|----------|--------------|-------------|
| Microsoft 365 Copilot (Business) | Yes         | Yes      | Yes          | Yes (with consent) |
| Claude for Work (Team plan)      | Yes         | Yes      | Yes          | Yes (with consent) |
| ChatGPT Enterprise               | Yes         | Yes      | Yes          | Yes (with consent) |
| ChatGPT (free or Plus, personal) | Yes         | No       | No           | No          |
| Claude (free or Pro, personal)   | Yes         | No       | No           | No          |
| Gemini (consumer)                | Yes         | No       | No           | No          |

"Public data" = freely available material (Code, regs, public filings).
"Internal" = firm methodology, templates, marketing draft.
"Confidential" = firm financials, salary, strategy.
"Client data" = anything received from a client engagement.

The matrix solves the most common compliance question — "can I paste this into ChatGPT?" — without requiring a partner-level decision each time.

Section 3: Prohibited inputs

List the categories of information that may never be input to any AI tool, including approved enterprise tiers, without specific written authorization. Examples: taxpayer SSN or EIN in unredacted form, client banking credentials, personal health information subject to HIPAA, federal tax return information without IRC section 7216 consent, attorney-client privileged material, anything subject to a non-disclosure agreement that the firm has not first reviewed for AI-vendor terms.

The phrase "without specific written authorization" matters because there are legitimate exceptions — a tax-research project that requires PII, a fraud investigation, an enterprise-tier deployment with documented vendor terms. The policy carves out a path for those exceptions rather than pretending they do not exist.

Section 4: Client consent

For tax practices, reference IRC section 7216 and Treas. Reg. section 301.7216-3 and require written consent in the format prescribed by Rev. Proc. 2013-14 before client return information is processed by an AI vendor that is not acting as a section 301.7216-2(d) agent. For attest engagements, require client awareness disclosure consistent with AICPA AT-C standards. For all engagements, the engagement letter should include a clause noting that the firm may use AI tools in the course of the engagement and committing to confidentiality safeguards.

Compliance pitfall. A clause in the engagement letter is not a substitute for IRC section 7216 consent for tax-return preparation engagements. Section 7216 requires consent in a specific format with specific disclosures. Your tax engagement letter and your section 7216 consent are two different documents. Always check with your firm's compliance officer and tax counsel on consent forms.

Section 5: Documentation

Require that any AI use that informs a deliverable, an audit conclusion, or a tax position be documented in the workpaper file. The minimum elements: the prompt, the response (verbatim), the model and version used, who ran it, when, and the reviewer's verification step. Reference PCAOB AS 1215 for issuer audits and AICPA AU-C 230 for non-issuer audits — both standards apply with full force to AI-assisted procedures.

Section 6: Supervision and review

State that AI output is treated like the work of a junior staff member: it must be supervised and reviewed before it is relied upon. AICPA Rule 1.300 (General Standards) and Statements on Standards for Tax Services (SSTS) No. 1 require professional competence and due professional care; both apply when the input came from an AI rather than a human. The reviewer is responsible for the conclusion, not the AI.

Section 7: Incident response

Define what an incident looks like (unauthorized disclosure of client information to an AI vendor, suspected data leak, AI-generated error in a delivered work product). Require staff to report incidents to the managing partner or compliance officer within 24 hours. Specify the firm's response protocol: contain, assess, notify the client if required, document, and update the policy if a gap is exposed.

For section 7216 violations, the IRS Office of Professional Responsibility (OPR) and Treasury Department Circular No. 230 are relevant. For confidentiality breaches, AICPA Rule 1.700 and state board rules govern. Many states also have data-breach notification laws that may apply. None of this is hypothetical; firms have already had incidents and the firms that did best had a written response plan in place.

Section 8: Training and acknowledgment

Require annual AI training for all professional staff and an annual signed acknowledgment that staff have read and understand the policy. Tie this to the firm's broader QMS training requirements. New hires and contractors should sign the acknowledgment before they touch a client file.

Rolling out the policy

The risk in rolling out a policy like this is overshooting and grinding work to a halt. The fix is staged adoption. Week one: distribute the policy and the approved-tools matrix; require acknowledgment. Week two: run a one-hour training. Weeks three through six: pilot the documentation requirements on three engagements, gather feedback, refine. Week seven: full deployment.

Practical tip. A policy that nobody reads protects nothing. The single most effective adoption tactic is to put the approved-tools matrix on a one-page laminated card on every desk. The policy itself can be ten pages; the card is what people actually use.

Homework

  1. Draft the eight sections of your firm's AI policy using the structure above. Aim for two pages, not ten.
  2. Build the approved-tools matrix for your firm. Be specific about which products and tiers are approved.
  3. Review your engagement letters and add an AI-use clause if one is not present.
  4. Draft a one-page incident response checklist that the partner-on-call can follow.
  5. Read AICPA ET section 1.700.001 (Rule 1.700) and the AICPA Quality Management Standards summary at the AICPA website. Both are short and both control your work.
  6. Schedule a 30-minute conversation with your professional liability carrier about AI coverage and policy expectations.

Day 5 Checkpoint & Course Wrap

Before you complete the course, you should be able to answer:

  • What are the eight sections of a complete firm AI policy?
  • What is the difference between an engagement letter AI clause and an IRC section 7216 consent?
  • How does AICPA Rule 1.700 apply when client information is processed by an AI vendor?
  • What is the firm's response when a partner pastes a client SSN into a public ChatGPT?
  • How does the policy match up with the AICPA QMS effective December 15, 2025?

Course complete. You now have prompt patterns for tax-return prep, reconciliation, JE review, audit-trail documentation, Excel automation, and a written firm policy. The work that remains is your firm's — apply, iterate, document.

Disclaimer. This lesson is educational and not legal, audit, or accounting advice. Always check with your firm's compliance officer, your professional liability insurer, your tax counsel, and your peer reviewer before deploying any AI workflow against client data or finalizing a firm policy.