Skip to main content

AI Policy for Accounting Firms: The Template You Can Fill In Today

Your clients already assume you use AI. A one-page AI policy answers where, who reviews it, and what never goes into a chatbot. Free template for firms.

Rain Allikvee Rain Allikvee · Jul 28, 2026 · 9 min read · Reviewed by Jaanus Lang
Cover for AI Policy for Accounting Firms: The Template You Can Fill In Today
Contents
  1. The two rules most firms have not connected to AI
  2. What applies where
  3. The ten sections
  4. The paragraph to send your clients
  5. What to do with the time AI gives back
  6. The template, ready to copy

An accounting firm’s AI policy is a short internal document that says where the firm uses AI, what data may never go into an AI tool, and who reviews AI output before it reaches a client. It needs ten sections and it fits on three pages. The point is not compliance theatre. Your clients have already assumed you use AI, and the firms that can answer “here is exactly where, and here is who checks it” keep the trust. The firms that improvise when asked do not.

Most firms have not written one. That is the gap, and it closes in an hour.

The two rules most firms have not connected to AI

If you operate in the United States, two rules that predate the current AI wave apply to it directly.

IRC §7216 makes it a criminal offence to disclose tax return information without the taxpayer’s knowing, voluntary, written consent. Running a client’s return data through a general-purpose AI tool is very likely a disclosure, and the auxiliary-service exception probably does not cover it. If your firm does this, consent has to be obtained in the required form, before the disclosure, and consent with no stated duration expires after a year.

The FTC Safeguards Rule treats tax and accounting professionals as financial institutions, regardless of firm size. Solo practitioners included. You need a written information security program, a designated qualified individual, multi-factor authentication, and encryption. Your AI tools belong inside that program, not alongside it.

Neither rule mentions AI. Both govern it.

What applies where

United StatesEuropean Union
Client data to a third partyIRC §7216 written consent before disclosureGDPR, AI vendor is a subprocessor
Security baselineFTC Safeguards Rule: written program, MFA, encryptionGDPR Art. 32 technical and organisational measures
Staff trainingProfessional body guidanceAI Act Art. 4, legally required since 2 Feb 2025, covers contractors
Telling people AI is involvedProfessional judgmentAI Act Art. 50, from 2 Aug 2026
AI in hiringState law variesHigh risk under the AI Act

The EU column has a deadline arriving this week. The US column has been live for years and is enforced more aggressively than most small firms assume.

EU AI Act deadlines that reach an accounting firm: AI literacy and prohibited practices since 2 February 2025, transparency from 2 August 2026, high-risk obligations deferred to December 2027 and August 2028

The ten sections

The ten sections of an accounting firm's AI policy, laid out as a numbered list from who it applies to through who owns the policy

An accounting firm’s AI policy needs these, in this order:

  1. Who it applies to. Employees, partners, interns, and contractors. The most common gap is not the employee using an approved tool. It is the contract bookkeeper using a personal AI account on your client’s payroll file.
  2. Where you use AI, and where you do not. Real tasks, not categories. “Reading data off invoices” and “drafting internal summaries”, not “improving efficiency”.
  3. A person signs off. Nothing reaches a client without documented human review. This is the whole policy in one line. Everything else is detail.
  4. What may never be entered. ID numbers, bank statements, payroll, client lists, signed agreements. And the part firms miss: removing the client’s name does not anonymise the file. A location, an unusual transaction, and an industry identify a business as reliably as its name does.
  5. Approved tools, and how you vet new ones. Firm accounts only. Five questions before adding anything: is our input used for training, where is data stored, is there a processing agreement, who at the vendor can access it, how fast is it deleted.
  6. Subprocessors and consent. An AI vendor handling client data is a subprocessor. It goes on the list, under an agreement, and clients are told.
  7. Your legal baseline. Keep it in an appendix so the policy does not go stale every time a deadline moves.
  8. What you tell clients. One paragraph for the engagement letter. This is the only part a client reads.
  9. When AI gets it wrong. Who is responsible (a named person, never “the system”), how errors are reported, what you keep to reconstruct what happened.
  10. Who owns the policy, and when it is reviewed. Undated policies are wrong within a year.

Then print a one-page version for the team. The full document is for the file. The one-pager is what people actually follow.

The paragraph to send your clients

Put your whole firm in one place Start free for 14 days. No credit card, full access. Try Uku free

Most of the value is here, and it takes ten minutes:

We use AI tools to assist with parts of our work, including [short list]. These tools help us prepare drafts and organise information. They do not make decisions about your accounts or your business. Every deliverable is reviewed and approved by a member of our team, who remains responsible for it. We do not enter your confidential information into public AI tools, and any AI provider that processes your data is bound by a written agreement. You can ask us at any time how AI is used in your work, and you can ask us not to use it.

Send it to your three largest clients before they think to ask. Being early on this is worth more than being thorough about it.

What to do with the time AI gives back

There is a quieter question underneath the policy one. If AI handles more of the routine work, what happens to those hours?

The answer that holds a client relationship is not a discount. It is attention: the call before the deadline rather than after it, the review nobody asked for, the plan that accounts for what the owner is doing next year. Clients notice speed for about a week. They notice being understood for a decade.

That is also why the human sign-off in section 3 is not a brake on AI. It is the thing you are selling.

Uku is practice management built for that model: the routine work tracked and automated, the client relationship left where it belongs. See what a firm running on Uku looks like, or read how our API was designed for AI agents from the start.

The template, ready to copy

Nothing to download and no form to fill in. Copy the document below, paste it into Word or Google Docs, replace everything in brackets, and delete what does not apply to your firm. Budget an hour, and expect section 2 to take most of it, because that is the one where you have to ask your team what they are actually using.

AI-Use-Policy-[FIRM-NAME].docx Editable

[FIRM NAME] AI Use Policy · Version [1.0] · Effective [DATE] · Owner [NAME, ROLE] · Next review [DATE + 12 MONTHS]

1. Who this applies to. This policy applies to everyone who uses AI tools on behalf of [FIRM NAME]: employees, partners, interns, and contractors. If you work on our client files, this policy is part of how you work.

2. Where we use AI. We use AI to help with [reading data off source documents], [drafting emails and internal summaries], [organising and cross-checking data we already hold], [flagging items that need a human look]. We do not use AI for [final advice to a client], [filing a return], [personnel decisions], [communication during a dispute or a crisis].

3. A person signs off. AI can produce a draft. A named person at [FIRM NAME] reviews it and takes responsibility before it leaves the firm. Nothing in this list reaches a client without documented human review: financial statements and management reports, tax returns and statutory filings, any advice a client may act on, any figure with a monetary consequence, any sensitive conversation.

4. What may never be entered. Never enter into a public or personal AI account: national ID or Social Security numbers, bank statements and account numbers, payroll records, client lists, signed agreements, anything covered by a confidentiality clause. Removing the client’s name is not enough: a location, an unusual transaction, and an industry together identify a business. If you are unsure, ask [NAME] before you paste.

5. Approved tools. Currently approved: [TOOL] for [PURPOSE], [TOOL] for [PURPOSE]. Firm accounts only. Client work does not go through anyone’s personal subscription or free tier. Before we add a tool, [NAME] answers five questions in writing: is our input used to train the vendor’s models, where is the data stored, is there a data processing agreement, who at the vendor can access it, how and how fast is it deleted.

6. Subprocessors and consent. An AI vendor that processes client data is a subprocessor: it goes on our subprocessor list, we hold an agreement with it, and clients are told. We do not extend the purpose of data we already hold. Where consent is required before client information goes to a third party, we obtain it in writing before the disclosure, not after.

7. Our legal baseline. [US firms: IRC §7216 written consent before any disclosure of tax return information; FTC Safeguards Rule written information security program, designated qualified individual, MFA, encryption.] [EU firms: AI Act Art. 4 AI literacy, in force since 2 February 2025 and covering contractors; prohibited practices; Art. 50 transparency from 2 August 2026; GDPR in full. AI used in hiring is high risk.] [NAME] reviews this section at least annually.

8. What we tell clients. We raise AI use when we take on a new client and again at the annual review, using the paragraph above.

9. When AI gets it wrong. Responsibility sits with [FIRM NAME] and the named person who approved the work, never with “the system”. Report any AI error to [NAME] immediately: there is no penalty for reporting one you caught, and a serious one for hiding it. We correct it with the client directly, explain what happened, and keep enough of a trail to reconstruct what went in, what came out, and who approved it, for [X MONTHS].

10. Ownership and review. Owner: [NAME, ROLE]. Everyone who uses AI on client work is briefed on what the tool does, where it fails, and what this policy requires, before they touch a client file, with a refresher [annually] and a record of who was trained when. Reviewed every 12 months, and immediately when we adopt a new tool or the rules change. Questions: [NAME, CONTACT].

The one page your team will actually read

Print this and put it where people sit. The full policy is for the file.

Yes: use [approved tools] from your firm account · use AI for drafts, summaries, data cleanup and finding things · read everything it produces before anyone else sees it · ask [NAME] if unsure.

No: no personal or free AI accounts for client work · no ID numbers, bank statements, payroll or client lists in a public tool · no AI output to a client without a named person approving it · no AI filing, no AI final advice, no AI hiring decisions.

If something goes wrong: tell [NAME] the same day. Catching it is not the problem. Hiding it is.

Paste into Word or Google Docs, then fill in the brackets

This is a starting point, not legal advice. Your obligations depend on where you operate and what work you do. Have a qualified advisor review the finished document before you rely on it.

Frequently asked questions

Does an accounting firm need a written AI policy?

Practically, yes. Clients assume you use AI and ask where. A written policy is also the only way to answer a due diligence questionnaire, and in the EU staff AI literacy has been a legal requirement since 2 February 2025.

Can I put client tax data into ChatGPT?

In the US, running tax return information through a general-purpose AI tool is very likely a disclosure under IRC §7216, a criminal provision. You need the client's knowing, written consent in the required form before the disclosure, not after.

Does the EU AI Act apply to a small accounting firm?

Three parts do. AI literacy for anyone using AI on your behalf and the ban on prohibited practices have applied since 2 February 2025. Transparency obligations apply from 2 August 2026. High-risk obligations are deferred to 2027 and 2028.

Is using AI to screen job candidates high risk?

Yes. Under the EU AI Act, AI used in recruitment and staff evaluation falls in the high-risk category. Many firms miss this because they treat it as an HR question rather than an AI one.

What should we tell clients about our AI use?

One short paragraph in your engagement letter: which tasks AI assists with, that it makes no decisions, that a named person reviews every deliverable, that confidential data never goes into public tools, and who to ask.

How long does it take to write an AI policy?

About an hour with a template. The section that takes real thought is the list of where you actually use AI today, because you have to ask your team and accept the honest answer.

Rain Allikvee

Co-founder & Visionary at Uku. Building the future of accounting practice management — where AI handles the routine so accountants can focus on what matters.

Get Growing Get Uku

Built for accounting firms.

Uku gives accounting, bookkeeping and audit firms one source of truth for who's doing what across the team — so work gets done on time, billed, and paid.

4.8 Capterra
4.7 G2
1000+ firms
25+ countries
Uku dashboard — every client's tasks, deadlines and billable time on one screen