Try Tidyflow
Get your firm organized.
Watch a 4-minute demo, or start a free trial. No credit card required.
Every accounting firm whose staff touch client data needs a written AI policy — because your team is almost certainly already using AI, with or without rules. This guide explains what the policy must cover, answers the “can I upload tax documents to ChatGPT?” question directly, and gives you a complete template to copy, adapt, and roll out this week.
Why accounting firms need an AI policy
Your staff are using AI whether you’ve sanctioned it or not. Drafting a client email in ChatGPT, summarizing a long document, tidying up meeting notes — these are exactly the tasks AI is good at, which is why people quietly adopt it. The question isn’t whether AI is used at your firm. It’s whether it’s used under rules you wrote or rules each person invents for themselves.
Three things make this more serious for an accounting firm than for most businesses:
- Client confidentiality is a professional obligation, not a preference. Professional conduct rules — such as the AICPA Code of Professional Conduct’s confidential client information rule — restrict disclosing client information to third parties without consent. Tax preparers face additional federal restrictions on how tax return information can be used and disclosed. Pasting client data into an unapproved third-party AI tool can put you on the wrong side of those obligations, regardless of whether anything bad happens with the data.
- Your engagement letters may already constrain you. Many engagement letters include confidentiality clauses and language about third-party service providers. An AI vendor processing client information is a third party. If your letters require disclosure or consent for third-party providers, ungoverned AI use can quietly put you in breach of your own terms.
- Inconsistency is its own risk. Without a policy, one team member carefully anonymizes everything while another pastes an unredacted general ledger into a free chatbot. Your effective data-handling standard is whatever your least careful person does on their busiest day. A written policy sets the floor.
An AI policy also complements the written information security plan (WISP) that US tax practices are already expected to maintain under the FTC Safeguards Rule. The WISP covers how you protect data generally; the AI policy covers the newest and fastest-changing way data leaves your systems.
If your firm is earlier in its AI adoption and wants the broader picture first, start with our practical guide to AI for accounting firms, then come back for the policy.
Is it safe to upload tax documents to ChatGPT?
No — not to a free or personal ChatGPT account, and the same answer applies to any consumer AI tool.
A tax return or its source documents contain nearly everything a policy should protect: names, Social Security numbers, addresses, income details, bank accounts, dependents. Consumer AI products may use your inputs to improve their models, depending on the plan and settings, and once identifiable client data leaves your systems you’ve disclosed it to a third party — which is a confidentiality problem on its own, before any question of what the vendor does with it.
Business and enterprise tiers change the analysis but don’t end it. These tiers generally offer admin controls and commitments not to train on your inputs — verify the current terms for the specific product, because they change. Even then, the practical rule that serves firms best is:
Never paste client-identifiable or confidential information into a public AI tool. Anonymize inputs, use firm-approved tools with appropriate privacy controls, and have a qualified professional verify every financial, tax, regulatory, and client-facing output.
Here’s how that shakes out by data type:
| What you want to use | Consumer AI tools (free/personal) | Firm-approved business-tier AI |
|---|---|---|
| Fully anonymized examples and generic questions | Acceptable | Acceptable |
| Internal firm content with no client data (SOPs, templates, marketing) | Acceptable | Acceptable |
| Client-identifiable information (names, TINs, bank details, payroll) | Never | Only if approved, necessary, and consistent with your confidentiality obligations |
| Tax documents and unredacted source records | Never | Generally no — anonymize first, or keep this work in purpose-built systems your firm controls |
One caution on anonymization: removing the name isn’t always enough. A client can be identifiable from context — “a dental practice in [small town] with four partners” narrows quickly. Anonymize the details that identify, not just the label.
What an AI policy for an accounting firm should cover
A useful policy is short enough that people actually read it and specific enough that they know what to do. Nine sections cover it:
- Scope — who and what the policy applies to, including AI features embedded in software you already use.
- Approved tools — a named list, with account types. Everything else is off-limits by default.
- Prohibited data — the categories that never go into an AI tool outside approved, controlled channels.
- Anonymization rules — how to prepare inputs when client context is needed.
- Verification requirements — who reviews AI output, and against what.
- Client disclosure — when clients are told or asked.
- Training — what staff complete before they’re covered by the policy.
- Incident reporting — what happens when someone makes a mistake.
- Review cadence — who owns the policy and how often it’s refreshed.
Note that scope should explicitly include AI agents — tools that take multi-step actions rather than just answering prompts. Agents raise the stakes on every rule above because they act, not just draft. We cover what they can genuinely do (and the controls they need) in our guide to AI agents for accounting firms.
AI policy template for accounting firms (copy and adapt)
Everything below the line is the template. Copy it into a document, replace the bracketed placeholders, delete what doesn’t apply, and make it yours — firms are welcome to adapt it freely, no attribution needed.
One explicit caveat: this is a starting point, not legal advice. Professional obligations vary by jurisdiction, license, and service line. Have your counsel or professional body review the adapted policy before you rely on it.
[Firm Name] — Artificial Intelligence Use Policy
Effective date: [date] Policy owner: [name, role] Last reviewed: [date]
1. Purpose
This policy governs the use of artificial intelligence tools at [Firm Name]. Its purpose is to let the firm benefit from AI while protecting client confidentiality, meeting our professional and legal obligations, and ensuring that all work products meet the firm’s quality standards. AI is permitted at [Firm Name] within the rules below; it is not banned, and it is not unrestricted.
2. Scope
This policy applies to all partners, employees, and contractors of [Firm Name], on firm devices and on any personal device used for firm work. It covers all AI tools, including: general-purpose AI assistants and chatbots; AI features embedded in software the firm already uses (accounting, tax, practice management, email, and document tools); AI meeting notetakers; and AI agents that take actions on the firm’s behalf. If a tool generates content, summarizes information, or takes actions using AI, it is in scope.
3. Approved tools
Only the tools listed below may be used for firm work, and only under the listed account type. Personal or free-tier accounts are not approved for any work involving firm or client information.
| Tool | Approved account type | Approved uses |
|---|---|---|
| [e.g., ChatGPT] | [Business/enterprise tier under the firm’s workspace] | [Drafting, research preparation, internal documents] |
| [e.g., Claude] | [Business tier under the firm’s workspace] | [Long-document review, drafting, analysis of anonymized data] |
| [AI features in firm software, e.g., practice management or bookkeeping platforms] | [Firm account] | [As designed by the vendor, per that product’s settings] |
To request a new tool, contact [policy owner]. New tools are evaluated for data handling, training practices, admin controls, and vendor terms before approval.
4. Prohibited data
The following must never be entered into any AI tool, except where a specific tool has been approved for it in Section 3 and the data handling rules in Section 5 are followed:
- Client names or other identifying details
- Social Security numbers, EINs, or other tax identification numbers
- Bank account, credit card, or payroll details
- Unredacted tax returns, financial statements, or source documents
- Login credentials of any kind
- Nonpublic firm information (pricing strategy, staff compensation, prospective client lists)
- Any information covered by a specific confidentiality or nondisclosure agreement
5. Anonymization rules
When client context is needed to make an AI tool useful, prepare the input first:
- Remove names, identification numbers, addresses, and account details.
- Replace identifiers with generic labels (“Client A”, “a construction company”, “the owner”).
- Round or generalize figures where exact amounts are not needed for the task.
- Consider whether the client is identifiable from context (industry, location, unusual circumstances) even without a name — if so, generalize further.
- Re-read the input before submitting. Do not assume a redaction worked.
6. Verification and review
AI output is a first draft, never a finished product. Before any AI-assisted output is used or sent:
- A qualified professional must verify every financial, tax, regulatory, and client-facing output.
- All figures and calculations must be independently recalculated or traced to source.
- All tax, regulatory, and legal claims must be checked against current primary sources. AI-generated citations can be wrong or fabricated; open the source.
- Client-facing communications must be reviewed by [role] before sending.
Responsibility for work product rests with the professional who signs it off, not with the tool.
7. Client disclosure and consent
[Firm Name] will honor all engagement letter terms regarding third-party service providers, and will obtain client consent for AI use wherever our professional or legal obligations require it. Staff must answer honestly if a client asks whether AI was used in their work. [Choose and state the firm’s default position, e.g., “We disclose our use of AI tools in our engagement letters” or “We disclose on request and obtain consent where required.”] Questions about disclosure go to [policy owner].
8. Training
Staff must complete [Firm Name]‘s AI training before using AI tools for firm work, covering this policy, the approved tools, anonymization, and verification. A refresher is required [annually / every six months], and AI policy training is part of onboarding for all new hires.
9. Incident reporting
If confidential or client-identifiable information is entered into an unapproved tool, or into an approved tool outside these rules, report it immediately to [name/role]. Prompt self-reporting will not be penalized; concealment will. On report, the firm will: delete the conversation or data where the tool allows it, assess what was exposed, meet any notification obligations that apply, and document the incident and the fix.
10. Policy review
This policy is reviewed every [three / six] months by [policy owner], and immediately when an approved vendor changes its data-handling terms or the firm adopts a new tool. AI products change quickly; an unreviewed AI policy goes stale faster than any other policy the firm has.
11. Acknowledgment
I have read and understood the [Firm Name] Artificial Intelligence Use Policy and agree to follow it.
Name: ______________________ Signature: ______________________ Date: ____________
That’s the complete template. Most firms can adapt it in under an hour; the slowest part is deciding the approved-tools list, which is a decision worth making deliberately.
How to roll out your AI policy
A policy nobody has read is a document, not a policy. Roll it out in six steps:
- Adapt the template. Fill in the placeholders and cut anything that doesn’t apply. Shorter policies get read.
- Have counsel or your professional body review it. Especially the disclosure and consent section, which depends on your jurisdiction and services.
- Decide the approved-tools list deliberately. Trial the major assistants on real (anonymized) firm work before you commit — our comparison of ChatGPT vs Claude for accountants covers how the differences show up per workflow, and our roundup of the best AI tools for accounting firms maps the wider field.
- Train the team on the why, not just the rules. Staff who understand that a pasted general ledger is a confidentiality breach — not just a policy violation — make better judgment calls on everything the policy doesn’t explicitly cover.
- Give people approved ways to do what they were already doing. Prohibition without alternatives drives AI use underground. Pair the policy with sanctioned workflows — our ChatGPT prompts for accountants library is built around anonymized inputs and verification steps, and works as a ready-made starting kit.
- Put the review date in your workflow system. Treat the policy review like any other recurring job with an owner and a deadline, so it actually happens.
The bottom line
An AI policy is not about slowing your firm down. It’s the thing that lets you say yes to AI quickly, because the guardrails are already decided. The firms that struggle with AI aren’t the ones with rules — they’re the ones where every use is an improvised judgment call made under deadline pressure.
The lowest-risk AI use tends to happen inside systems the firm already controls, rather than in a browser tab with client data pasted into it. That’s the approach we take with Tidyflow, our practice management product: its AI assistant and email summaries work inside the firm’s own workspace, gated behind explicit consent settings, instead of through a public chatbot.
Copy the template, adapt it, get it reviewed, and train your team. It’s an afternoon of work that removes a category of risk your firm is otherwise carrying every single day.
Frequently asked questions
Do accounting firms need an AI policy?
Yes. If your team handles client financial data, you need written rules for AI use before staff improvise their own. An AI policy protects client confidentiality, keeps you aligned with professional standards, and tells staff exactly which tools they can use and what data can never leave firm systems.
Is it safe to upload tax documents to ChatGPT?
No, not to a free or personal ChatGPT account. Tax documents contain names, Social Security numbers, income details, and bank information, and consumer AI tools may use your inputs to improve their models depending on plan and settings. Even on business tiers with stronger data controls, anonymize first and confirm the use is consistent with your confidentiality obligations.
What should an AI policy for an accounting firm include?
At minimum: scope, an approved-tools list, prohibited data categories, anonymization rules, verification requirements for AI output, client disclosure guidance, training requirements, an incident-reporting process, and a review cadence. Prohibited data and verification matter most — they address the two ways AI use actually goes wrong in firms.
Does an accounting firm have to tell clients it uses AI?
It depends on your engagement letters, your jurisdiction, and how AI is used. Tax preparers face specific restrictions on how return information is used and disclosed, and many engagement letters address third-party service providers. Be able to answer honestly if a client asks, and obtain consent wherever your obligations require it.
How often should an AI policy be reviewed?
Every three to six months. AI tools change their features, terms, and data-handling practices far faster than most firm policies get reviewed. Assign a single owner, schedule the review like any other recurring job, and update the approved-tools list whenever a vendor changes its terms or the firm adopts a new tool.