FirmSteward blog
How to write an AI acceptable-use policy for an accounting firm
An AI acceptable-use policy is a short set of written rules that tells your staff which AI tools they may use, what information they may enter into them, and who approves exceptions. It is not a security assessment, a legal review, or a compliance certification. It is a guardrail: a boundary that keeps client data from ending up somewhere you did not intend, written plainly enough that people actually read it.
If your firm is like most small and mid-size accounting practices, staff have already opened ChatGPT, Copilot, or another tool with a client file open. That is the moment the policy earns its keep. Here is a practical way to write one.
Why a written boundary matters for an accounting firm
Accounting firms hold some of the most sensitive information a household or business owns: tax returns, payroll runs, bank details, social security and employer identification numbers, and the identity data behind every client file. When someone pastes any of that into a public AI tool, you generally cannot call it back. The prompt may be stored, reviewed, or used as training data depending on the provider and their settings — and you rarely know which.
A written policy does not make that risk vanish. What it does is replace "everyone assumes" with "everyone was told," in a form you can refer to later. It tells a new hire their first day what is off-limits, gives a manager something concrete to point to, and gives staff a safe answer when a client asks, "Do you use AI with my information?" For a firm facing a professional body, insurer, or client questionnaire, a short written policy is also the kind of thing a reviewer expects to see.
None of this is a substitute for review by an attorney, your professional liability insurer, or a qualified security adviser. Those are separate conversations. This guide is about the practical first draft.
What the policy should actually say
Keep the list short. A policy that tries to cover every new tool will be out of date in a month. Cover these five things and you are in good shape:
1. Name the approved tools
List the AI tools staff are allowed to use for work — for example, the ones baked into your Microsoft 365 tenant (like Copilot) and any specific third-party tools the firm has approved. The rule of thumb: if it is not on the list, ask before using it.
2. Name what is never entered
Be explicit about the no-go items, because that is the whole point of the document. A clear sentence like this works: "Never enter client identifying information, tax or payroll data, bank or card details, or any information that could identify a client into an unapproved or public AI tool." Keep it specific to your firm's risk.
3. Assign an owner
Name the person who answers AI questions and approves additions to the approved list — a partner, office manager, or IT lead. One named owner beats a policy with no one behind it.
4. Give real examples both ways
People remember examples better than rules. Put a few allowed and prohibited cases in the policy so there is no guesswork. For instance:
- Allowed: Entering a generic, de-identified question such as "Draft a polite follow-up email about a missing W-9," with no client name or identifiable detail.
- Allowed: Drafting an internal job description or a proposal boilerplate that contains no client data.
- Allowed: Using the firm-approved AI tools on firm-approved, appropriately protected work.
- Not allowed: Pasting a client's tax return, a payroll register, or a full bank statement into a tool.
- Not allowed: Entering a client's name, Social Security or EIN, address, or account numbers into a public AI tool.
- Not allowed: Using an unapproved tool for client work because it is convenient or free.
5. Give staff a way to raise a concern
Someone will make a mistake or hit a situation the policy does not cover. That is expected. The policy should say plainly who to tell and why it is safe to tell them. A no-blame path — "if you are unsure, or if something slips through, tell [owner] and we will work it out" — does more for your firm than a threat-heavy tone ever will.
Keep it short enough that staff read it
The biggest mistake firms make is turning this into a twenty-page manual. Nobody reads that, and an unread policy protects nothing. Aim for one or two pages. If you have drafted something longer, the test is simple: the most senior person whose staff it affects should be able to read it aloud in about five minutes, and a staff member should be able to find an answer to a specific question quickly.
Use plain language over legal tone. Short sentences. Headings staff can scan. Put the "never enter this" sentence near the top, not buried on page four. A short policy you distribute beats a comprehensive one you write and forget.
Rollout can be simple: announce, train, revisit
You do not need a campaign. Three steps are enough to make the policy real:
- Announce. Send the policy in a short email or a firm meeting. Say what changed, why it matters, and who the owner is.
- Train. Walk through the allowed and not-allowed examples with staff, ideally live, so questions are answered at the moment people are paying attention. New hires should see the policy in their first week.
- Revisit. Schedule a check-in — every six months is reasonable, and any time you add or remove an approved tool. The single most useful edit is keeping the approved-tool list current.
Treat the first version as a start, not a finish. Policies get better as staff actually use them and surface the gaps.
One note before you start writing
This article is educational, not legal, tax, compliance, or cybersecurity advice. It cannot tell you what your firm is required to do, and it makes no guarantee about any tool, provider, or practice. Before finalizing, have your attorney and professional liability insurer review your draft, and confirm the guidance fits how your firm actually works.
Free AI readiness scorecard
Not sure where your firm stands? Take the scorecard.
Answer ten questions about how your firm handles AI today — boundaries, client data, Microsoft 365 readiness — and see a clearer first move. It is a free educational starting point, not a security or compliance review.
Take the 5-minute scorecardEducational resources, not legal, tax, compliance, or cybersecurity advice.