AI Governance for Accounting Firms Starts at the Client-Data Boundary
AI governance for accounting firms needs separate rules for research, audit work, attest work, and tax engagements. A defensible program identifies approved LLM routes, limits the client data each route can receive, keeps engagement professionals responsible for outputs, and retains evidence of each policy decision. Request-layer controls can support that program only when authenticated HTTP model traffic passes through the enforcement point.

An associate pastes a yellow-highlighted column from a client bank-reconciliation workbook into an LLM and asks for an exception summary. The request may contain account numbers and preparer notes plus an unresolved variance. AI governance for accounting firms starts at that request, before the model produces a polished paragraph. The firm needs to know who sent it, which engagement authorized it, what client information entered the prompt, and which model received it. I would block public consumer chat interfaces for client work until the firm can answer those questions with executed evidence.
TL;DR
- Accounting firms should approve AI by use case and data class, rather than granting one firm-wide permission for a named tool.
- Engagement professionals remain responsible for AI-assisted audit work and source evaluation, including supervision and documentation.
- Tax practices need to include LLM prompts and responses in their FTC Safeguards Rule information-security program.
- Request-layer enforcement can govern authenticated HTTP calls routed through it. It cannot stand in for engagement review, audit evidence, model testing, or a regulatory examination.
AI governance for accounting firms starts with use-case boundaries
The PCAOB's July 2024 staff Spotlight found that participating audit firms primarily used generative AI for administrative and research activities at the time of its outreach. Examples included initial drafts of memos and presentations plus research into internal accounting and auditing guidance. Firms also identified possible future uses in risk assessment and audit scoping, along with disclosure checks and comparisons between financial-statement amounts and audited amounts.
A policy should separate internal research using public material and administrative drafting from audit or attest procedures and tax work involving taxpayer information. Each approved use case then names its owner and permitted data classes, plus available model routes, the required reviewer, and retained evidence.
The AICPA's small-firm generative AI policy template frames policy as a way to align public-LLM use with integrity and accuracy. Use that as a starting artifact. The production control still has to recognize the engagement and data inside each request.
Client confidentiality follows the prompt into the model route
A prompt can contain the same sensitive material as a workpaper. Trial-balance exports and payroll files, plus tax organizers, bank confirmations, and acquisition schedules, keep their client context when copied into a chat box. An approved browser icon changes the destination; it leaves the data sensitivity intact.
The governance register should identify the legal entity operating the model and the contractual account, along with retention settings, training terms, region, subprocessor path, and approved information classes. It should also record how the calling application supplies the individual user's identity and engagement context. A shared API key labeled audit-tools-prod obscures the person who submitted the client material and weakens subsequent review.
Set policy at the narrowest useful layer. A staff member may receive permission to summarize a public accounting standard while client names and taxpayer identifiers, along with unreleased financial results and authentication secrets, trigger a block or redaction. AI policy enforcement at the HTTP layer explains the difference between checking the actual request and relying on the label attached to its source document.
Engagement teams retain responsibility for AI-assisted work
PCAOB staff reported that firms expected generative AI to augment human work. The firms said engagement personnel remained responsible for the results and documentation, while supervisors applied the same diligence to AI-assisted work. They also emphasized auditability of the underlying source data and the generated content.
PCAOB AS 1105 requires sufficient appropriate audit evidence and evaluates appropriateness through relevance and reliability. Fluent model output supplies neither property by appearance alone. The reviewer needs the source and the procedure performed, plus the transformation applied and any contradictory information.
PCAOB AS 1201 places primary responsibility for the engagement and its performance with the engagement partner. A firm can use an LLM to draft a memo or help inspect a population. The engagement workflow must still show who reviewed the output and how exceptions were resolved. It must also show which evidence supported the conclusion. A generated citation that points to the wrong paragraph should stop the workpaper at review.
Tax practices need a separate information-security mapping
Tax return preparers face a specific data-protection regime. IRS Publication 4557 states that professional tax return preparers must create and enact security plans under the FTC Safeguards Rule. The guide calls for limiting taxpayer-data access to people with a need to know and implementing audit trails that identify who performed an activity and when it happened, plus what changed.
An AI policy should bring model-bound prompts and returned content into that information-system inventory. Record which applications send taxpayer data and the approved recipients, along with access control, retention, and incident handling. A workflow that uploads a Form W-2 or Schedule K-1 to an unregistered model creates another customer-information path that the written security program must address.
The FTC's Safeguards Rule guidance requires covered financial institutions to maintain a written information-security program with administrative and technical safeguards, together with physical safeguards. Its coverage turns on the business activity. Firms should map the rule to each covered tax service with counsel instead of treating every accounting engagement as identical.
The governance file needs executed records
A policy PDF establishes intent. The stronger governance file shows operation through records tied to real tests. I would ask for five artifacts before approving client-data use:
- Use-case record: the engagement activity and accountable owner, plus the model route, approved data classes, and prohibited inputs.
- Access result: a named user's allowed and denied test requests under the assigned role, preserved with the effective policy version.
- Source trail: the material supplied to the model and the generated passage selected for engagement review.
- Review record: the engagement professional's disposition and corrections, plus supporting evidence and sign-off.
- Change record: approval and regression testing for a new model or prompt template, connector, retention setting, or provider route.
The output resembles a reviewer packet rather than a dashboard. One page should connect the employee and client code with the policy decision and model destination, plus the source set and review outcome. AI model inventory management covers the route register. The AI governance audit framework covers the distinction between a written control and proof that it operated.
Request-layer controls cover a defined part of the program
A customer-controlled application can send an authenticated HTTP request to an LLM through an external policy point. On that route, the application supplies the user or agent identity plus engagement context. The enforcement layer can classify the prompt and check the destination and role. It can then apply a versioned rule and retain the decision before forwarding an allowed request.
That control has a precise boundary. Native AI inside tax and audit SaaS, along with document-management and productivity SaaS, may use vendor-managed inference routes that the accounting firm cannot redirect. Local model execution and offline spreadsheet automation also sit outside an HTTP LLM proxy. Those systems need their own vendor settings and application logs, plus access tests and engagement review.
Keep the architecture diagram honest. The HTTP policy point supports the client-data and authorization record for traffic deliberately routed through it. Firm leadership owns use-case approval. Engagement partners own supervision and conclusions. Tax security and professional independence, along with audit evidence and model-performance testing, remain separate obligations.
DeepInspect
This is the part DeepInspect can support for accounting firms with customer-controlled LLM routes. DeepInspect sits inline as a stateless proxy between authenticated users or agents and HTTP-based LLM endpoints. The calling application supplies identity and context. DeepInspect evaluates the model destination and prompt classification, plus the role and versioned policy, before an allowed request reaches the model.
Each routed decision produces a signed, tamper-evident record. That record can show the engagement's reviewers which policy operated on a specific model call. Vendor-managed embedded AI and local execution, plus engagement supervision and the sufficiency of audit evidence, remain outside the proxy's scope. DeepInspect supports the request-control record; it does not perform or certify the firm's audit. Book a technical deep dive at deepinspect.ai.
Frequently asked questions
- Can accounting staff use a public LLM for research?
A firm can approve public-source research as a distinct use case with clear input restrictions and review requirements. The AICPA policy template specifically addresses publicly available LLMs, while the PCAOB Spotlight observed firms using generative AI for research into internal accounting and auditing guidance. The approved workflow should keep confidential client information out of the request and identify acceptable sources. The professional should verify the cited standard before relying on the output.
- Can generative AI prepare an audit workpaper?
Generative AI can assist with an initial draft when firm policy permits that use. The engagement team remains responsible for the work and its documentation. Under AS 1105, the conclusion still needs sufficient appropriate evidence. Under AS 1201, the engagement partner retains primary responsibility for supervision. Preserve the source material and model-assisted transformation, plus reviewer corrections and final support, so another experienced reviewer can reconstruct what happened.
- Does an enterprise LLM account solve client confidentiality risk?
An enterprise account provides contractual and administrative settings that may support approval. The firm still needs to verify the exact product and model route, plus the retention option, training terms, access configuration, and subprocessors. Request content also needs an engagement-specific rule. A licensed account can still receive information outside the user's authority when policy grants broad access without data-class and client context.
- What belongs in an accounting firm's AI inventory?
Include the business owner and use case, plus the calling application, model and provider, account type, and data classes. Add the client or engagement scope and identity source, along with the retention configuration, reviewers, and evidence location. Capture vendor-managed embedded AI separately because its requests may bypass the firm's HTTP enforcement route. Update the entry after a model change or connector activation, plus a new data source or material policy revision.
- Can request logs prove that an accounting firm complied with auditing standards?
Request logs can prove a bounded event: a named identity sent specified content to a model route under a particular policy, and the system allowed, blocked, or redacted it. They can support supervision and reconstruction. Compliance with auditing standards also depends on audit planning and professional judgment, plus evidence sufficiency and reliability, documentation, review, independence, and the facts of the engagement. An HTTP log provides one evidence source and never constitutes an audit opinion.