← Blog

Shadow AI in Accounting Firms: Confidentiality for Tax Data and Workpapers

Parminder Singh
Parminder Singh··7 min read
Summarize with AI

Shadow AI in accounting firms moves taxpayer data, payroll files, audit workpapers, and transaction details into AI services outside the firm''s approved workflow. This article maps that exposure to professional confidentiality and Internal Revenue Code Section 7216, plus the FTC Safeguards Rule, then sets out an enforceable control pattern for routed HTTP AI traffic.

Industry Verticalsshadow-aiai-securityai-governancecompliancedata-loss-preventionaudit
Shadow AI in Accounting Firms: Confidentiality for Tax Data and Workpapers

A senior tax associate copies a partnership allocation schedule into an AI assistant to draft a client explanation. The worksheet still contains partner names and taxpayer identification numbers, along with capital-account balances. On the second monitor, the approved tax application remains open behind a browser tab signed into a personal account. That single HTTP request can create a confidentiality, disclosure, vendor-management and evidence problem before the first sentence comes back.

Shadow AI in accounting firms deserves a narrower treatment than generic finance. The sensitive objects are tax returns, workpapers, payroll registers, bank confirmations, audit adjustments and client representations. Their professional and legal handling rules attach to the information itself, including when staff move a few rows into a prompt rather than uploading the whole file.

TL;DR

  • Accounting firms need AI controls that recognize taxpayer data and workpaper content, plus client identifiers, inside each routed prompt.
  • IRC Section 7216 and professional confidentiality duties can attach to the same AI request. The FTC Safeguards Rule can attach too.
  • Approved vendor lists provide procurement evidence; inline policy supplies the per-request enforcement record.
  • Browser-only consumer use that bypasses managed proxy routing sits outside DeepInspect's enforcement boundary and needs endpoint and browser controls, or network controls.

The accounting data inside a prompt

Accounting work produces unusually dense prompts. A request to "explain this variance" may contain a trial balance, account names, a client code and management's unreleased forecast. A request to rewrite a tax notice response may carry a taxpayer's address, filing status, income and controversy strategy. Audit staff can expose confirmations, proposed adjustments, control deficiencies or extracts from the permanent file while trying to speed up routine drafting.

The DeepInspect shadow AI pillar explains the category-wide mechanism. Accounting adds a chain-of-custody problem. A worksheet cell pasted into an AI prompt still came from a controlled engagement file. Removing the filename or the "Confidential" footer changes the visual wrapper; it leaves the underlying client information intact.

I think a policy that approves one enterprise chatbot while ignoring prompts sent by engagement applications is governance by logo. The firm needs to evaluate the actual request, its user, the engagement, the destination and the data present at that moment.

Confidentiality attaches before model selection

The AICPA Code of Professional Conduct's client confidentiality rule, section 1.700.001, limits disclosure of confidential client information without specific consent, subject to defined exceptions. The AICPA Code of Professional Conduct supplies the professional baseline for members. State accountancy rules and engagement terms can add further duties.

Tax work has an additional statutory layer. The IRS Section 7216 Information Center explains the restrictions on tax return preparers' use and disclosure of tax return information. A staff member's intention to improve prose provides no general exception. The firm must determine the permitted use and disclosure basis, plus applicable consent requirements, before return information enters an outside service.

These obligations make context important. The same model may be acceptable for public accounting research and prohibited for a prompt containing a named client's return position. A binary provider block loses that distinction. An unrestricted provider route loses control of it.

The FTC Safeguards Rule reaches tax practices

The IRS tells tax professionals that protecting taxpayer data is law. Publication 4557, Safeguarding Taxpayer Data, states that the FTC Safeguards Rule covers professional tax return preparers and requires a security plan for client data. It also calls for audit trails recording who performed an activity and when it occurred, plus what changed.

The FTC's official Safeguards Rule page links the current rule and amendments governing customer-information safeguards. For an accounting firm covered as a financial institution, an AI provider that receives tax data belongs in the firm's risk assessment and safeguards, along with service-provider oversight.

Shadow use defeats the service-provider process at inception. Procurement lacks a contract to review. Security lacks a configured route to monitor. The engagement partner lacks evidence tying a disclosure to a business purpose. An annual training slide cannot reconstruct a Tuesday afternoon request containing Schedule K-1 data.

Four workflows create different exposures

Each service line exposes a different combination of client information and professional duties.

Tax preparation and controversy

Preparers handle return information under Section 7216 and related regulations. Prompts can include W-2 values, entity ownership, estimated payments, notices and proposed response language. The policy decision needs the preparer's identity, client or engagement context, destination model and detected tax fields. An approval for generic tax research should never become blanket permission to transmit a completed return.

Audit and assurance

Audit prompts can expose workpaper conclusions, sampling results, fraud inquiries or proposed control findings. Confidentiality remains central, while audit quality also depends on preserving the human review trail. The per-request record should show the source workflow, reviewer role, model route, classification, policy version and outcome. Model output belongs in the engagement process only after the firm's review rules run.

Client accounting and payroll

Bookkeeping and payroll teams work with bank details, employee identifiers, compensation and payment files. Prompt-level classification has to detect combinations. A nine-digit number beside "routing" means something different from the same digits in a public technical manual.

Advisory work

Transaction and valuation teams hold forecasts, bidder lists, purchase-price assumptions and board materials. The shadow AI for finance article covers broader financial controls; accounting firms must add engagement acceptance and independence context, plus client confidentiality context, to the request.

Policy needs engagement context

A useful accounting-firm policy can make a decision with six inputs:

  • Identity: employee, contractor, service account and office.
  • Role: tax preparer, audit senior, payroll specialist, partner or approved agent.
  • Engagement: client code and service line, plus matter classification supplied by the application.
  • Content: taxpayer identifiers, bank data, payroll fields, workpaper language and transaction codenames.
  • Destination: the approved model endpoint and contractual data-handling tier.
  • Purpose: research, summarization, drafting, extraction or another registered use.

The application owns accurate identity and engagement context. The enforcement point evaluates what it receives. Shared credentials reduce the decision to the shared account's authority and produce weak evidence, so firm-built AI workflows should pass the natural-person or agent identity on every request.

A denied prompt should create a record with the same precision as a permitted one. That record lets the firm show that a named user attempted a specific route and a tax-data rule fired. It also shows that the request stopped before reaching the model. A monthly count of "AI events" lacks the resolution an engagement partner or investigator needs.

Discovery and enforcement have separate boundaries

Direct browser use creates the hardest boundary. A personal AI account accessed through an unmanaged browser can send HTTPS traffic outside the firm's configured AI proxy. DeepInspect only inspects HTTP AI traffic routed through it by authenticated applications, agents, or managed access paths. It cannot catch consumer use that bypasses that routing.

Accounting firms should cover that gap with endpoint telemetry, browser controls, DNS and egress monitoring, CASB discovery and policy enforcement appropriate to managed devices. Those controls identify or restrict the un-routed path. Once the firm channels approved AI activity through an authenticated HTTP route, request-level policy can evaluate content and engagement context before disclosure.

Embedded AI also requires inventory work. A tax, audit, document-management or payroll vendor may add an AI feature behind its own interface. Vendor due diligence should establish where prompts go, which subprocessors receive them, what retention applies and which logs the firm can obtain. The shadow AI governance framework provides the broader inventory and ownership model.

Audit evidence for an accounting firm

The evidence package should answer a practical sequence. Who initiated the AI request? Which client engagement was active? What categories of information were detected? Which model endpoint was selected? Which policy version applied? Did the control permit or deny the request, or redact it? Who reviewed any resulting work product?

For routed AI traffic, a per-decision audit record can preserve the enforcement facts independently of the tax or audit application. The application may retain its own workpaper and review evidence. Joining the two records through request and engagement identifiers gives an investigator a usable chain without pretending the gateway performed the accountant's professional judgment.

This separation also limits self-attestation. The application creating the prompt should not have sole custody of the enforcement log. A decoupled write path preserves the decision even when the application crashes after making the call or records only the successful branch.

DeepInspect

DeepInspect sits between authenticated accounting applications or agents and HTTP-based LLM endpoints. The application supplies identity and engagement context. DeepInspect classifies the routed prompt and evaluates per-role and per-route policy. It can permit or deny the request. It can also redact it before it reaches the model.

Each decision produces an identity-bound audit record containing the policy version, detected data category, destination, timestamp and outcome. That gives security and engagement leaders evidence for the AI traffic inside the managed route. Browser-only consumer activity that bypasses the proxy remains outside this boundary and requires the discovery and endpoint controls described above.

Book a demo today.

Frequently asked questions

Can an accounting firm solve shadow AI with an approved-tool list?

An approved-tool list supplies a procurement boundary. Enforcement still needs to distinguish a public research prompt from one containing return information or audit workpapers. The useful control binds provider approval to identity, engagement, content and purpose on each routed HTTP request. Endpoint and browser controls remain necessary for personal accounts that avoid the managed route.

Does redaction make every accounting prompt acceptable?

Redaction can remove recognized identifiers when firm policy permits the remaining content to leave. Context can remain identifying through entity names and transaction facts, plus unusual balances. The policy should treat redaction as one outcome after classification, with denial available when the residual prompt still carries confidential client information.

What should the firm record about model output?

The gateway record should connect the response to the original request, identity, policy, route and decision. The engagement system should separately preserve review, edits, approval and final use according to tax and audit procedures, or advisory procedures. Together, those records show control execution and professional review.