Vendor review · For small accounting firms

How to vet an AI tool before your staff start using it.

A vendor review is the short, practical check you do before a new AI tool touches any client data. For a small firm it is not a procurement department or a 40-page security questionnaire. It is a handful of plain questions answered in writing, by the person who owns AI in your firm, in about an hour. The goal is simple: make sure the tool does not quietly become a place where client information lands without anyone having agreed to that.

Here is the honest version of what staff AI use actually looks like in most small firms. Someone — often the most curious person on the team — finds a tool that saves them real time on a scramble, a draft, or a schedule. They try it, it works, they tell a colleague, and a month later a payroll or tax figure has been pasted into a tool no one reviewed. Nobody did anything reckless. The tool just arrived through the back door of enthusiasm.

That is the problem a lightweight review solves. It does not block experimentation. It just makes the first real use of a tool a decision someone made instead of an accident.

Why the vendor's data-handling terms matter

An AI tool is not like a spreadsheet. When your staff type a client name, an employer identification number, or a balance into a tool, that information leaves your firm's direct control and enters the vendor's systems. The terms and privacy policy are the only thing that tells you what happens to it there.

This matters for three practical reasons:

None of this is about trusting or distrusting any particular company. It is about reading the terms before the data goes in, so that the firm — not the vendor's marketing page — decides what happens with client information.

Five questions to ask before anyone starts using a tool

You do not need a checklist the length of a bank loan application. For a small firm, these five questions cover most of what actually matters. Ask them out loud, write down the answers you find in the vendor's policy, and keep that note next to the approval record.

1. Where is my data stored?

Find the country or region the vendor stores data in. If the tool is aimed at your market, look for whether your data stays in your country or region by default, and whether you can choose. A tool that says nothing about where data lives, or stores it in several regions with no control, needs a much harder look.

2. Who can see my data?

Behind the "secure" language, check who the policy says can actually access the data: the vendor's staff, sub-processors (companies they pass data to), or third parties. Pay attention to how the vendor describes access for its own support or engineering teams, and any list of sub-processors. "Only those who need it to run the service" is a reasonable answer. Silence is not.

3. Is my data used for training the model?

Look for an explicit statement of whether data you enter is used to train the tool's model. The words matter here, because "we do not train on your data" is different from "we may use prompts to improve our services." If the tool trains on your input by default, you need to know that clearly so you can decide whether client data is ever appropriate to enter.

4. What happens if we cancel?

Read what the terms promise when you stop paying or delete your account. Is your data deleted on request, and does the vendor say how long deletion takes? Is there a period of retention that matters for you? At minimum, you want a documented path to get your data out and have it deleted — not just an account that goes quiet.

5. Is there a data-processing agreement (DPA)?

A data-processing agreement is a written contract that specifies how the vendor may process data you hand it. For a small firm, the practical question is simpler: does the vendor offer one at all, and do the terms I rely on survive in writing? Many reputable tools make a standard DPA available without a negotiation. If a tool refuses to commit anything to writing about how it handles data, that is a strong signal to treat it as inappropriate for client information.

If you find a job, client names, and contact details are reasonably safe to try in most tools. The questions above matter most once you are about to enter financial figures, tax details, or anything that identifies a client. Draw that line, and let staff know where it is.

A simple approval step that fits a small firm

Your firm probably does not need a formal committee. It needs one named person whose job it is to say yes or no to AI tools — and a lightweight way for everyone else to check before they start.

A practical version looks like this:

  1. Name an owner. One person — the managing partner, the ops lead, or whoever owns technology — reviews new tools. Naming them out loud matters more than the title.
  2. Require a two-line check. Before staff adopt a tool for client work, they send the owner the tool name, what data they plan to put in it, and the answers to the five questions above. That is it.
  3. Keep a one-page log. When the owner approves a tool, record it in a simple list: the tool, the date, what data is allowed, and who the vendor contact is. A spreadsheet is fine. This log is what lets you answer "what have we actually approved?" in ten seconds.
  4. Decide what the default answer is. For many small firms, the simplest rule is: a tool that answers the five questions acceptably can be used for general work; a tool that will not answer them is a hard no for client data until someone says otherwise.

The point is not to slow people down. It is to make approval a real, recorded decision. In a small firm that is usually one conversation and one line in a list — not a process.

One honest caveat about scope

A vendor review like this is the right first step, but it is not the whole job. It tells you what the vendor promises in its terms. It does not prove those promises are kept, and it does not confirm the vendor meets any security standard that matters in your jurisdiction or to your clients. A tool can answer all five questions well and still not match the level of diligence your firm's clients or regulators expect.

If you are ever in real doubt about a critical tool, or about a specific professional or regulatory requirement, that is the moment to raise it with a qualified professional — not to guess from a blog post.

This is education, not legal advice

This article explains a practical way to think about vendor review. It is educational guidance only — not legal, tax, compliance, or cybersecurity advice. It does not create any professional relationship, and it does not guarantee that any particular tool, policy, or review process keeps your firm compliant or your data secure. Before you rely on any of it for a specific obligation, work with a qualified professional who understands your firm and your jurisdiction.

Where your firm stands today

Not sure where your firm's AI readiness is? Take the scorecard.

FirmSteward's free 10-question AI readiness scorecard takes about five minutes. It helps you see where your firm may need a written AI-use boundary, staff guidance, or a named owner — and it sets you up with a short, practical way to run reviews like this one.

Take the free scorecard