HomeInsights › AI for accounting firms

Guide · Accounting & CPA firms

AI for accounting firms, without leaking a single client’s data.

Short answer: somebody in your firm has already pasted a client document into a free AI tool to save twenty minutes. That is a missing-policy problem rather than a staff problem, and it has a clean fix. AI can take real hours off an accounting practice: summarizing what a client sent in, drafting the routine letters, finding the one engagement letter from 2019. The question is never whether to use it. It is where the client’s data goes when you do, and for a firm holding Social Security numbers and financials, that question has a right answer.

What is happening in your office right now

We look after accounting firms, one of them for nine years, and the pattern is the same in every office we walk into. A preparer has a long, messy set of documents from a client. It is the week before a deadline. They open a free chatbot in a browser tab, paste in the pile, and ask for a summary. It takes ninety seconds, it works, and nobody mentions it because nobody thinks of it as sending data anywhere.

It is sending data somewhere. A consumer chatbot is another company’s server, outside your firm, outside your backups, outside any agreement you have with the client about who sees their information. Depending on the tool and the settings, what was pasted may be kept, may be reviewed, and may be used to train the next version.

None of this makes your staff careless. It makes them busy people using the fastest tool in reach. The fix is to give them a faster tool that is also the right one, and a one-page rule about what goes where.

Why this is a sharper question for accountants than for almost anyone

A builder’s job files are sensitive. A CPA firm’s files are a different category. You hold, for every client, exactly what an identity thief wants in one place: names, dates of birth, Social Security numbers, addresses, income, bank details. That is why accounting firms are a target out of proportion to their size, and it is why the rules around your data are stricter than the rules around most small businesses.

Two of those rules matter here. The IRS expects tax professionals to maintain a written data security plan and publishes guidance on safeguarding taxpayer data. Massachusetts, separately, requires a written information security program from any business holding personal information about a resident, and part of that program is overseeing the outside parties you hand data to. A free chatbot that a preparer pasted a return into is an outside party that nobody assessed, nobody has an agreement with, and nobody wrote down. We are IT and security people, not attorneys, and this is not legal advice. But we have written enough of these plans to know that “where does our AI send client data” is now a question that belongs in one.

What AI is genuinely good for in a practice

Start here, because it is easy to talk yourself into banning the whole thing, and that just sends it underground. The uses that hold up in a real firm are unglamorous and worth having:

  • Summarizing what a client sent. Forty pages of bank statements, brokerage reports and a shoebox of receipts become a two-paragraph briefing before anyone opens the return. Not a replacement for reading it. A head start.
  • Finding things across years of files. “The engagement letter where we agreed the Q3 estimated payment schedule” turns up even though none of those words are in the file name. For a firm with fifteen years of client folders, this one alone earns its keep.
  • Routine drafting. Extension reminders, missing-document requests, the standard reply to “why is my refund smaller this year”. Letters that follow a pattern you have written a thousand times.
  • Answering staff questions from your own records. A new hire asking what the firm’s standard retention period is, without interrupting the partner who knows.

Notice what is not on that list: signing off on anything. AI removes the tedious half of the job. The judgement stays with the person whose name is on the return.

The three ways to get there, honestly compared

A free consumer chatbot. Fast, capable, free, and the wrong tool for client data. Fine for drafting a blog post or rewording a paragraph that contains nothing identifying. Not for anything with a client’s name on it. If you do nothing else from this page, write that line down and pin it up.

A licensed business AI with proper data terms. The paid business versions of the mainstream tools come with contractual promises the free versions do not: your data is kept out of training and handled under a business agreement, and there is someone accountable. For many firms this is the sensible middle. It is still another company’s server, so it still belongs on your list of outside parties, but now it is one you can name, assess and write down. We covered the Microsoft version of this in our Copilot guide.

Private AI, running on hardware the firm controls. The same kind of AI, on a server in your office or your own private cloud. Nothing leaves the building. No per-seat subscription. No outside party to oversee, because there is not one. It wins outright on the sensitive pile, which for an accounting firm is most of the pile. It costs more up front and needs someone to own it, which is usually us. We wrote up what private AI is and what it runs on separately; the short version is a server with a good graphics card, sitting next to your file server, in the same backup routine.

Most firms that take this seriously land on two of the three: a licensed business tool for general work, private AI for anything touching client records, and a policy that says which is which.

The one-page policy your firm needs

This is the part that gets skipped, and it is the part that protects you. Not a forty-page document. One page, four sections:

  • What may never go into a public AI tool. Client names, SSNs, financials, anything from a return, anything a client sent you. Spell it out.
  • What the firm provides instead. Name the tool. If it is a licensed business product, say which. If it is private AI, say where it lives and how to reach it.
  • Who owns it. One person responsible for the tool, the settings, and the annual review. If that person does not exist and you are not hiring us to be them, the policy will quietly rot.
  • What happens if the rule is broken. Not a punishment clause. A “tell us straight away so we can assess it” clause. The damaging version of a mistake is the one nobody reports.

That page slots into the written security plan you are already expected to keep. If you do not have one of those yet, the AI question is a good reason to finally write it, and we explain what goes in one in plain English.

What a sensible first step looks like

Not a project. An hour on the phone about what your team does with AI today, what client data is involved, and what you would most like to stop doing by hand. Out of that comes the one-page policy above and a straight recommendation on which of the three routes fits your firm and your budget. If the honest answer is “a licensed tool and a policy, you do not need private AI”, that is what we will say.

If the sensitive pile is big enough, the next step is a pilot: one server, one job, usually document summarizing or file search, run for a month and measured. Timing matters for accountants more than most. Do not start this in February. Start it in the quiet stretch, so by the time the season hits the tool is boring and the staff already trust it.

Related: IT support for accounting firms covers the security baseline this sits on top of, and our cybersecurity guide covers the seven protections that stop most of what actually happens.

Common questions

There is no single rule that names ChatGPT. What there is: an expectation from the IRS that tax professionals keep a written data security plan, and a Massachusetts requirement to oversee the outside parties you give personal information to. Pasting a client’s documents into a free consumer tool is handing data to an outside party with no agreement and no record, which sits badly against both. A licensed business tool with data terms, or private AI, does not have that problem. We are not attorneys; this is how it looks from the security side.

Yes, if you let it near one. That is why the uses we recommend are summarizing, finding and drafting, and never signing off. The AI shortens the tedious half of the work. The person whose name is on the return still reads it, still checks it, and still owns it.

Usually yes, and a policy that says so is better than one that bans everything. Rewording a newsletter paragraph or drafting a job posting contains nothing identifying. The line is client data, and the policy should draw it clearly enough that nobody has to guess.

For raw capability, no. The frontier cloud models are stronger than anything a small firm can run on its own hardware. For the focused jobs a practice needs, summarizing documents and searching your own files, the gap matters far less than you would expect, and the data control often matters more. Plenty of firms sensibly run both.

The quiet months. Late spring through early autumn for most firms. A pilot takes a few weeks, most of it preparing your files rather than the AI itself, and you want the tool to be boring and trusted before the season starts, not arriving in the middle of it.

Want the one-page policy for your firm?

An hour’s conversation about what your team does with AI today and what your client data allows. You leave with a written policy and a straight recommendation, whichever way it goes.