By Vincent Howard, CPA | Managing Partner, Howard, Howard and Hodges | SkillAbility for Accounting Firms
Last updated: August 21, 2026 | 26-minute read
- What AI governance means in an accounting firm
- Why governance is a 2026 firm-management issue
- The professional-responsibility baseline
- The AI GOVERN framework
- Four AI risk tiers for accounting-firm work
- Allowed, controlled, restricted, and prohibited use cases
- Client confidentiality and data rules
- Tool and vendor approval
- Source evidence and authority verification
- How to review AI-generated work
- Who should approve the final output
- What AI use should be documented
- AI-assisted accounting and tax research
- Audit and attest work
- Tax preparation and tax advice
- CAS, bookkeeping, forecasting, and advisory
- Security, prompt injection, and shadow AI
- How to train staff on AI governance
- 100-point AI governance readiness scorecard
- 90-day implementation plan
- 15 realistic accounting-firm AI scenarios
- What firms should measure
- Frequently asked questions
What Is AI Governance for Accounting Firms?
AI governance is the system of policies, decision rights, controls, training, review standards, documentation, monitoring, and accountability an accounting firm uses to determine how artificial intelligence may be used in professional work.
It is broader than an “AI acceptable use policy.”
An acceptable-use policy tells people what they may or may not do.
Governance also answers:
- Who approves an AI tool?
- Who approves a new AI use case?
- What data may enter the tool?
- Which use cases require client consent or contract review?
- What output can enter a workpaper?
- What evidence must be independently verified?
- What level of reviewer is required?
- When does AI assistance need to be documented?
- Who monitors model/tool changes?
- Who can override or suspend a use case?
- Who owns the final professional conclusion?
Why AI Governance Is a 2026 CPA-Firm Management Issue
The profession has moved past the “Should accountants use AI?” stage.
The issue now is whether adoption is outrunning governance.
Current research shows a readiness gap
A February 2026 AICPA/CIMA and NC State ERM Initiative study included 1,735 executives across eight regions and eight industries.
AI is a Top 10 or major risk
Across the full AICPA/CIMA–NC State sample.
Report adequate readiness
Approximate range for AI-skilled talent, IT readiness, or regulatory preparedness.
Top-risk concern among transformed firms
Risk rises alongside deeper AI adoption.
Among organizations where AI was already materially affecting the business model, 73% said it was providing strategic advantage—but 69% also classified AI as a Top 10 or major risk.
The lesson is not that AI is unsafe.
It is that AI value and AI risk scale together.
Finance professionals expect transformation but do not feel ready
A CIMA survey of 1,446 senior finance and accounting leaders and managers found:
- 88% expected AI to be the most transformative technology trend over the next 12–24 months.
- Only 8% said their organization was very well prepared and 21% said well prepared.
- 56% identified GenAI as the most prominent skills gap.
- 50% cited lack of human capital, skills, and talent as the biggest technology-adoption barrier.
- 47% cited safety and security concerns.
- 61% identified on-the-job training as the most effective technology-upskilling method.
This supports a SkillAbility principle:
The AICPA’s 2026 CPA Firm Top Issues Survey also ranked technology/AI change management as the leading long-term issue across firm sizes.
The Professional Baseline: AI Does Not Change Who Is Responsible
AICPA/CIMA’s March 2026 TQA 400.02, Using the Output of Technology, emphasizes professional judgment in determining whether a technology output is appropriate for the intended purpose.
AICPA/CIMA’s current AI ethics guidance similarly stresses:
- Verify AI findings
- Understand tool limitations
- Understand how and where data is stored
- Maintain professional competence
- Maintain appropriate oversight and transparency
- Do not allow AI to supplant professional responsibility
In August 2026, the AICPA Center for Plain English Accounting specifically highlighted the growing use of AI in audit and accounting research and warned about overreliance, including known tendencies such as sycophancy.
The “human in the loop” phrase is not enough
A human who clicks “approve” without competence, evidence, or time is not an effective control.
The human reviewer must be:
- Qualified for the subject matter
- Independent enough from the AI output to challenge it
- Given source evidence
- Given enough time to review
- Clear about the intended purpose
- Accountable for approval
Effective Governance = Qualified Human + Evidence + Review Standard + Named Approval
The AI GOVERN Framework
To make governance teachable, I would require every material AI-assisted workflow to pass eight gates.
| Gate | Governance Question | Evidence |
|---|---|---|
| A — Authorize the use case | Is AI allowed for this task and service line? | Approved-use-case matrix |
| I — Identify the data risk | What client, confidential, personal, financial, tax, employee, or regulated information may enter the system? | Data classification / privacy rule |
| G — Govern the tool & access | Is the vendor/tool approved, configured, and limited to authorized users? | Vendor approval, settings, access list, contract |
| O — Obtain source evidence | What authoritative or client evidence supports the AI output? | Source documents, authoritative literature, client data |
| V — Validate the output | Have facts, calculations, citations, classifications, and assumptions been independently checked? | Validation checklist / recalculation / citation verification |
| E — Exercise professional judgment | What judgment did the professional make rather than inherit from the model? | Reasoning, alternatives, risk/escalation note |
| R — Review at the required risk level | Who must review this work based on its consequence and uncertainty? | Risk tier / reviewer sign-off |
| N — Name the final approver | Which human professional owns release of the final work? | Named approval / engagement sign-off |
AI GOVERN is intentionally output-focused.
It does not ask whether AI is “good.”
It asks whether the firm can defend the specific use, data, evidence, review, and approval.
Four AI Risk Tiers for Accounting-Firm Work
Not every AI use deserves the same control.
A partner asking AI to rewrite an internal meeting agenda does not create the same professional risk as AI proposing an uncertain tax position.
Tier 1 — Low-risk productivity
Examples: internal agendas, generic brainstorming, formatting, non-confidential drafting, summarizing firm-created non-client materials.
Default review: user review for accuracy, tone, and appropriateness.
Tier 2 — Controlled professional assistance
Examples: first draft of client email, workpaper narrative from verified facts, variance commentary, checklist drafting, meeting-summary draft, initial research query.
Default review: preparer validates facts and sources; normal engagement reviewer applies existing review standard.
Tier 3 — High-impact professional output
Examples: technical accounting research, tax position analysis, audit-risk analysis, substantive analytical procedures, forecast assumptions, valuation inputs, client recommendations, impairment or going-concern analysis.
Default review: authoritative source verification, independent calculation/logic checks, documented assumptions, qualified reviewer, explicit human approval.
Tier 4 — Prohibited or separately authorized
Examples can include: unsupervised AI making final professional conclusions; uploading confidential client data into unapproved tools; fabricated source citations; AI directly filing or releasing a return/report without required human review; autonomous approval of journal entries, client payments, or high-impact decisions outside approved controls.
Default: prohibited unless leadership has formally redesigned and approved the control environment for that use.
Create an AI Use-Case Matrix Before You Write a 20-Page Policy
| Use Case | Typical Tier | Data | Required Verification | Final Approval |
|---|---|---|---|---|
| Rewrite internal non-client email | 1 | No confidential data | Tone/accuracy | User |
| Draft client email from verified workpaper | 2 | Only in approved tool | Facts, tone, confidentiality | Engagement team per policy |
| Summarize accounting guidance | 2–3 | Authority/public data | Open and read original authority | Qualified professional |
| Generate tax research memo | 3 | Approved confidential-data rules | Every authority/citation; facts; contrary authority; conclusion | Tax reviewer/manager/partner per risk |
| Identify potential audit exceptions | 3 | Approved audit environment | Evidence, completeness, false positives/negatives, audit objective | Qualified auditor |
| Draft forecast narrative | 2 | Approved client environment | Actuals, assumptions, arithmetic, uncertainty | Controller/CFO/advisor |
| AI decides final tax position without reviewer | 4 | N/A | Not acceptable under default policy | Human professional required |
Client Confidentiality: What Data May Enter AI?
AI governance starts before the prompt.
The first question is:
Create data classes
A practical firm policy can classify information such as:
- Public: statutes, public filings, public websites, published guidance.
- Internal: firm processes, templates, internal training without client identifiers.
- Confidential client: client books, returns, workpapers, contracts, financial statements, source documents, correspondence.
- Restricted/highly sensitive: SSNs, bank data, credentials, health information where applicable, payroll/personnel data, access tokens, tax IDs, privileged communications, acquisition data, or other information the firm designates.
Do not equate “enterprise AI” with “all client data is approved”
Tool approval and data approval are separate.
A firm may approve an AI platform for:
- Public research
- Internal drafting
- Specified client-data use under configured controls
while prohibiting:
- Passwords
- authentication secrets
- unnecessary SSNs
- unredacted data when not needed
- privileged material
- client data outside the engagement scope
AICPA/CIMA’s 2026 ethics guidance specifically tells accounting and finance professionals to understand the nature of data being fed to AI, including where and how it is stored.
For tax-firm security practices, see WISP Training for Tax Professionals once published.
Approve the Tool Before You Approve the Prompt
A firm should maintain an AI tool inventory.
Tool approval should consider
- Vendor identity and contractual terms
- Whether prompts/inputs are used for model training
- Retention settings
- Data residency where relevant
- Access control and SSO/MFA
- Administrative logging
- Subprocessors
- Security certifications / assurance reports where relevant
- Export/deletion capability
- Integration permissions
- Model/version change behavior
- Ability to disable risky features
- Incident/breach notification terms
- Client contractual restrictions
NIST’s AI Risk Management Framework and Generative AI Profile provide a useful voluntary structure for identifying and managing AI risks throughout the AI lifecycle.
COSO’s 2026 Achieving Effective Internal Control Over Generative AI likewise emphasizes that generative AI introduces control risks including cyber exposure, prompt-based manipulation, opaque reasoning, model drift, and frequent configuration changes.
Shadow AI is a governance problem
Staff may quietly use:
- browser extensions
- free chatbots
- AI inside meeting tools
- PDF assistants
- email assistants
- spreadsheet add-ins
- coding copilots
A policy that bans all AI while the work makes AI useful tends to create hidden adoption.
A stronger policy gives employees approved paths and clear boundaries.
O — Obtain Source Evidence Before You Trust the Answer
AI output is not evidence merely because it is correct-sounding.
For technical work, the professional should be able to move from:
Never review a citation by reading only the AI quotation
Open the authority.
Confirm:
- It exists
- It is the correct source
- It is current
- The cited passage says what the AI claims
- The context does not reverse or narrow the conclusion
- The authority applies to the client’s facts
- Contrary authority has not been ignored
The AICPA Center for Plain English Accounting’s August 2026 update is particularly timely: accounting and audit research is one of the broadest current AI use cases, but overreliance can create judgment problems.
V + R — How to Review AI-Generated Accounting Work
The review should match the risk.
1. Factual review
Check:
- Client name/entity facts
- Dates
- Amounts
- rates
- jurisdictions
- ownership
- contracts
- account balances
- source documents
2. Calculation review
Recalculate material numbers independently.
Do not assume AI arithmetic is reliable because the explanation sounds sophisticated.
3. Authority review
Open and verify technical sources.
4. Logic review
Ask:
- What assumption drives this conclusion?
- What fact would change it?
- Is there an alternative explanation?
- Did the model simply agree with the prompt?
- Did it omit an unfavorable fact?
- Is the answer more certain than the evidence?
5. Professional-skepticism review
AI can encourage confirmation bias because the user may prompt it toward the answer they already want.
For staff development, use Professional Skepticism Training for Junior Accountants.
6. Confidentiality review
Confirm the content is appropriate to leave the approved system and reach the intended client or recipient.
7. Workpaper review
If the output supports professional work, the workpaper should show enough evidence for another professional to understand what was done and why.
Use Workpaper Review Checklist and Tax Workpaper Training for Staff Accountants.
N — Name the Human Who Has Authority to Approve the Work
“Reviewed by a human” is incomplete.
The firm needs approval rights.
| Output | Possible Preparer | Required Approver |
|---|---|---|
| Internal non-client draft | Any trained user | User / normal business owner |
| Client-facing routine email | Staff | Per engagement communication policy |
| Technical workpaper conclusion | Qualified preparer | Reviewer with required subject-matter competence |
| Material tax position | Tax professional | Manager/partner under firm risk policy |
| Audit conclusion / significant judgment | Engagement team | Appropriate engagement/review authority under applicable standards |
| Strategic recommendation | Controller/advisor | Professional assigned decision responsibility |
AI cannot approve the professional judgment simply because it produced the analysis.
What AI Use Should Be Documented?
Not every grammar rewrite needs an “AI workpaper.”
Material AI assistance should be documented when the AI use is important to:
- the conclusion
- the evidence trail
- the firm’s quality-management/control system
- reperformance
- client/contractual disclosure
- regulatory or professional requirements
- incident/security review
A practical AI-use record can capture
- Approved tool
- Approved use case
- Risk tier
- Data classification
- Model/version if material
- Purpose of use
- Key inputs/assumptions
- Source evidence verified
- Material AI-generated content used
- Reviewer
- Final approver
- Exceptions/corrections
Do not preserve sensitive prompts blindly
Documentation itself creates data risk.
Firm policy should define what is retained, where, for how long, and whether prompts contain information that should not be duplicated unnecessarily.
AI-Assisted Accounting and Tax Research
Research is one of AI’s most useful accounting applications.
It is also one of the easiest places to mistake fluent output for authority.
Use AI to:
- Generate research questions
- Identify possible authorities
- Summarize a body of literature
- Compare possible treatments
- Find missing fact questions
- Draft a research outline
Do not let AI:
- Invent citations
- Replace reading primary authority
- Hide contrary authority
- Decide materiality or client facts
- Convert an uncertain issue into a confident conclusion without reviewer judgment
Research verification workflow
AI Governance in Audit and Attest Work
Audit uses require special caution because the engagement team must comply with applicable auditing, evidence, documentation, supervision, review, and quality-management standards.
PCAOB stakeholders have specifically called attention to the risk that audit firms could deploy AI without adequate governance, over-rely on outputs, or lack transparency regarding AI use.
For PCAOB-registered firms, QC 1000 becomes effective December 15, 2026 and establishes a risk-based quality-control framework covering governance, ethics, engagement performance, resources, information and communication, monitoring, and remediation.
AI use should be integrated into that quality architecture where relevant—not managed as a disconnected innovation project.
AI may assist with
- Population analysis
- Exception identification
- Document extraction
- Research
- drafting
- pattern detection
But governance should address
- Completeness of data inputs
- False positives and false negatives
- Reliability of source data
- Model/tool limitations
- Audit objective
- Evidence sufficiency and appropriateness
- Documentation
- supervision/review
- independence/ethics implications
AI Governance in Tax Preparation and Tax Advice
Tax AI governance should separate:
- Data extraction
- return preparation assistance
- issue spotting
- research
- planning ideas
- position conclusions
- client advice
Example: safe escalation path
AI flags a possible state nexus issue.
The staff accountant should not write:
“The client has nexus in State X because AI identified $650,000 of sales.”
A better process is:
- Verify the sales data
- Identify the tax type
- Identify the jurisdiction’s current threshold/rule
- Confirm dates and transaction sourcing
- Research applicable authority
- Identify registration/filing implications
- Escalate novel or material judgment
See Multistate Tax Training for Staff Accountants when available, plus Professional Skepticism Training.
AI Governance in CAS, Bookkeeping, Forecasting, and Advisory
AI can be especially valuable in recurring accounting workflows.
Potential controlled uses
- Transaction classification suggestions
- reconciliation matching
- variance detection
- management-reporting commentary
- AR collection prioritization
- forecast-assumption challenge
- client meeting preparation
Governance should prevent a common mistake:
For management reporting or forecasting, the human controller still needs to confirm:
- accepted historical data
- consistent definitions
- source systems
- assumptions
- cash logic
- material business drivers
- client action
See Outsourced Controller Training for Accountants and Budgeting and Forecasting Training for Accountants.
Prompt Injection, Data Leakage, and Shadow AI Belong in the Governance Model
NIST’s Generative AI Profile and COSO’s 2026 GenAI control guidance reinforce an important point: AI risks are not limited to hallucinations.
Governance should consider
- Prompt injection
- malicious content in uploaded documents
- data leakage
- over-permissioned integrations
- model changes
- opaque reasoning
- drift
- cyber exposure
- unapproved plugins/extensions
- retrieval sources that can be manipulated
Accounting example
A staff member uploads a client PDF into an AI document assistant.
The PDF contains hidden instructions or malicious embedded content designed to alter model behavior.
The control cannot be merely:
“Review the answer.”
The firm also needs:
- approved tools
- secure configuration
- data restrictions
- vendor controls
- review procedures
- incident escalation
Train AI Governance as a Workflow Skill
A policy acknowledgement does not prove an accountant can govern AI use.
Training should give staff scenarios.
Every employee should be able to answer
- Can I use AI for this task?
- Can this data enter this tool?
- What source must I verify?
- What output may I rely on?
- What review level is required?
- When do I escalate?
- Who approves the final work?
Use Scenario-Based Training for Accountants to move from policy awareness to applied judgment.
Role-based AI governance training
| Role | Training Emphasis |
|---|---|
| New staff | Approved tools, prohibited data, citation verification, basic output review, escalation |
| Senior | First review, detecting hallucinations, source validation, coaching AI-assisted work |
| Manager | Risk classification, technical review, exception approval, client/engagement implications |
| Partner | Risk appetite, client disclosure, quality system, strategic approval, accountability |
| IT/security | Tool architecture, access, logging, retention, integration, security, vendor monitoring |
| AI governance lead / committee | Use-case inventory, policy, testing, monitoring, incidents, model/tool changes, cross-functional oversight |
AICPA/CIMA’s March 2026 governance guidance recommends cross-department perspectives rather than leaving emerging-technology governance to a single leader or IT person.
Create an AI Exception Queue
| Exception | Risk | Immediate Action | Owner |
|---|---|---|---|
| Client document uploaded to unapproved AI tool | Confidentiality/security | Stop use; preserve/report per security procedure | Security/privacy + engagement leader |
| AI citation cannot be located | Unsupported conclusion | Remove reliance; research from authority | Preparer/reviewer |
| Approved tool changed model/version | Output behavior/model drift | Assess impact on approved use cases | AI governance lead |
| Staff uses AI to draft a material client conclusion outside policy | Professional judgment | Reperform and escalate; coach policy | Manager/partner |
100-Point AI Governance Readiness Scorecard
| Capability | Points | Observable Evidence |
|---|---|---|
| Approved use-case framework | 10 | Staff can tell allowed, controlled, restricted, and prohibited uses |
| Data / confidentiality controls | 12 | Data classes and approved-tool rules prevent unauthorized disclosure |
| Tool / vendor governance | 10 | AI inventory, contracts, settings, access, and monitoring exist |
| Source / evidence verification | 14 | Material claims trace to original authority/client evidence |
| Output validation | 14 | Facts, calculations, logic, assumptions, and citations are independently checked |
| Risk-based review standard | 12 | Higher-consequence outputs receive deeper qualified review |
| Named human approval | 8 | Professional accountability is explicit before release |
| Documentation / traceability | 7 | Material AI assistance can be understood and reperformed where needed |
| Training / scenario readiness | 8 | Staff correctly classify and review realistic AI use cases |
| Monitoring / incident / change management | 5 | Model/tool changes, exceptions, incidents, and policy updates are tracked |
Suggested interpretation
- 90–100: Mature enough for controlled expansion of approved AI use cases.
- 80–89: Generally sound; close specific control gaps before expanding higher-risk work.
- 70–79: AI use should remain constrained to lower-risk applications while governance improves.
- Below 70: Significant governance design is needed before broad professional AI use.
A serious confidentiality event, fabricated authority used in client work, autonomous unapproved professional conclusion, hidden shadow-AI use with client data, or repeated bypass of required review should override the numerical score.
A 90-Day AI Governance Implementation Plan
Days 1–30: Discover and classify
Inventory:
- AI tools currently used
- embedded AI features inside existing software
- use cases by service line
- data being entered
- current review process
- current vendor terms
- current client/engagement restrictions
Then define:
- approved tools
- prohibited tools
- data classes
- four risk tiers
- initial use-case matrix
Days 31–60: Build the control system
Implement:
- AI GOVERN checklist
- risk-based review levels
- named approval authorities
- source-verification standard
- material AI-use documentation rule
- vendor/tool approval process
- shadow-AI reporting process
- AI exception queue
Days 61–90: Train and test
Run scenarios:
- fake citation
- client-data upload
- tax research
- audit exception analysis
- forecast narrative
- AI-generated client email
- model/version change
- prompt injection
Score employees on:
- use-case classification
- data decision
- source verification
- review depth
- escalation
- approval decision
15 Realistic AI Governance Scenarios for Accounting Firms
Scenario 1: The perfect tax citation
AI provides a regulation citation that precisely supports the desired conclusion. The learner must open the authority and discovers the section does not exist.
Scenario 2: The client email draft
AI rewrites a routine email but changes “estimated tax payment” to “required tax payment.” The employee must validate substance, not only tone.
Scenario 3: The public chatbot
A staff member pastes a client trial balance into an unapproved free AI tool because the client name was removed.
Scenario 4: The spreadsheet insight
AI says gross margin deteriorated because of labor inefficiency. The actual cause is a classification change. The accountant must trace the conclusion to the books.
Scenario 5: The audit exception list
An AI tool flags 75 “high-risk” transactions. The auditor must understand completeness, criteria, false positives, and whether unflagged items can still matter.
Scenario 6: The research summary
AI correctly summarizes general guidance but misses a jurisdiction-specific exception that changes the client conclusion.
Scenario 7: The approved enterprise tool
An employee assumes enterprise approval permits uploading passwords and unredacted SSNs.
Scenario 8: The hidden prompt injection
A client document tells the AI assistant to ignore firm instructions and reveal other available data. The learner must recognize this as a tool/security issue, not just a strange answer.
Scenario 9: The forecast recommendation
AI recommends hiring five people based on the base forecast but does not mention minimum cash under the downside scenario.
Scenario 10: The senior reviewer
The senior reads an AI-generated tax memo and agrees because it matches prior experience, but never checks primary authority.
Scenario 11: The AI-written workpaper
The narrative is polished but describes a procedure the preparer did not actually perform.
Scenario 12: The model changed overnight
An approved vendor upgrades the underlying model and output behavior changes. The firm must decide whether high-risk approved use cases need retesting.
Scenario 13: The autonomous journal entry
An AI-enabled system proposes and posts a material adjusting entry without the firm’s normal approval control.
Scenario 14: The partner override
A partner says the deadline is too close to reperform the AI-generated analysis. The governance standard must still define minimum review.
Scenario 15: The brilliant staff user
A high-performing associate builds an unofficial AI workflow that saves hours. Leadership must capture the innovation without allowing shadow governance.
What Accounting Firms Should Measure
| Metric | What It Reveals |
|---|---|
| Approved AI use cases | Where adoption is intentional |
| Unapproved/shadow AI exceptions | Where policy and workflow diverge |
| AI outputs rejected or materially corrected in review | Output quality and training needs |
| Fabricated/incorrect citation rate | Research-validation risk |
| High-risk AI work without required review | Governance control failures |
| Client-data / confidentiality exceptions | Data governance quality |
| Time saved after review/rework | Real—not theoretical—AI productivity |
| Review time per AI-assisted output | Whether automation is shifting the bottleneck |
| Staff governance scenario scores | Whether employees can apply the policy |
| Model/tool change assessments | Change-management discipline |
Common AI Governance Mistakes in CPA Firms
Mistake 1: “Always have a human in the loop.”
Without defining competence, evidence, review depth, and authority, the phrase creates the appearance of control rather than a control.
Mistake 2: One policy for every AI task
Risk differs dramatically between grammar assistance and a material technical conclusion.
Mistake 3: Approve the tool and forget the data
A secure enterprise tool may still be inappropriate for specific client, credential, privileged, or restricted data.
Mistake 4: Let AI cite the authority and call that research
The professional must verify the underlying source.
Mistake 5: Review for grammar instead of substance
Fluent AI output can conceal incorrect facts, calculations, procedures, or logic.
Mistake 6: Ban AI without providing an approved path
Useful technology tends to reappear as shadow AI.
Mistake 7: Let IT own professional-risk decisions alone
IT can assess security and architecture. Service-line professionals must assess technical, client, ethics, and engagement consequences.
Mistake 8: Let partners bypass the standard
Leadership exceptions train staff that deadlines outrank governance.
Mistake 9: Measure prompt volume instead of business value
AI is useful when reviewed output reduces total effort or improves quality—not when usage counts rise.
Mistake 10: Never retest approved workflows
Models, vendors, prompts, integrations, and firm processes change.
How SkillAbility Fits AI Governance
AI governance is ultimately a capability problem.
The firm can write:
“Verify AI output.”
But can a first-year staff accountant actually do that?
Verification requires:
- technical knowledge
- source literacy
- professional skepticism
- workpaper discipline
- judgment
- escalation
BASE — Verify AI-assisted execution
Train:
- approved tool use
- data rules
- recalculation
- citation checks
- source tracing
- workpaper evidence
MAPS — Govern judgment
Train:
- challenging AI assumptions
- identifying missing facts
- contrary authority
- client communication
- professional skepticism
- risk-based escalation
SUMMIT — Govern review and approval
Develop managers/partners who can:
- classify use cases
- define review depth
- approve exceptions
- monitor AI-assisted quality
- develop reviewers
- balance innovation with professional responsibility
See AI Accounting Training and Accountants Are Shifting From Preparers to Reviewers.
Frequently Asked Questions About AI Governance for Accounting Firms
What is AI governance for an accounting firm?
AI governance is the system of policies, approved tools, use-case rules, data controls, review standards, documentation, monitoring, training, and human accountability governing how AI is used in professional work.
Should CPA firms allow employees to use generative AI?
Many firms can use AI productively, but usage should be risk-based and controlled. Firms should define approved tools, permitted data, permitted use cases, source-verification requirements, review levels, and final approval authority before broad adoption.
Does AI-generated accounting work require human review?
Material professional work should remain subject to appropriate qualified human review and approval. AICPA’s 2026 TQA 400.02 emphasizes professional judgment when determining whether technology output is appropriate for its intended purpose.
What does “human in the loop” mean for accountants?
It should mean more than a person clicking approve. The reviewer needs appropriate competence, source evidence, enough time, a defined review standard, and authority/accountability for the final output.
Can staff put client data into ChatGPT or another AI tool?
Only if the firm has approved the specific tool and the specific data use under its confidentiality, security, privacy, contractual, and professional requirements. Staff should never assume a consumer or enterprise AI tool is approved for all client information.
What AI uses are low risk for accounting firms?
Examples can include non-confidential internal brainstorming, formatting, generic drafting, agenda preparation, or summarizing firm-created non-client content. Even low-risk output should be reviewed for accuracy and appropriateness.
What AI uses are high risk for CPA firms?
Examples include technical accounting conclusions, tax positions, audit-risk analysis, valuation inputs, material forecasts, financial-reporting judgments, client recommendations, and outputs that can materially affect a filing, report, transaction, or decision.
How should accountants verify AI research?
Open the original authority, confirm it exists and is current, read the relevant context, match the authority to the client’s facts, consider contrary authority, and document the professional conclusion. Do not rely on an AI citation or quotation without checking the source.
Should firms document when AI was used?
Material AI assistance should be documented when necessary to understand the work, evidence trail, quality/control system, reperformance, client requirements, or professional obligations. Routine low-risk grammar assistance generally does not need the same documentation as technical AI analysis.
Who should approve AI-generated client work?
The same professional authority that would be responsible for the substantive conclusion without AI should generally remain responsible with AI, subject to the firm’s risk policy. Higher-risk outputs should be approved by a professional with the required technical competence and engagement authority.
Can AI make a final tax or accounting conclusion?
AI can assist analysis, but professional responsibility should remain with the qualified human. Firms should generally prohibit unsupervised AI from making or releasing final material professional conclusions.
What is shadow AI?
Shadow AI is employee use of unapproved AI tools, extensions, assistants, or workflows outside the firm’s governance process. It can create confidentiality, cybersecurity, professional-quality, and documentation risks.
What framework can CPA firms use for AI governance?
Firms can draw from multiple resources. NIST’s voluntary AI Risk Management Framework and Generative AI Profile provide broad AI-risk structure. COSO released GenAI internal-control guidance in 2026. AICPA/CIMA provides profession-specific ethics, technology-output, governance, and AI resources. Firms should tailor governance to their services and obligations.
How often should an AI policy be reviewed?
At least on a defined periodic cadence and whenever material tools, models, integrations, laws, professional guidance, client requirements, or observed risks change. High-change AI workflows may need more frequent review than traditional annual policies.
What is AI GOVERN?
AI GOVERN is SkillAbility’s eight-gate governance framework: Authorize the use case; Identify data risk; Govern the tool and access; Obtain source evidence; Validate the output; Exercise professional judgment; Review at the required risk level; Name the final approver.
Current Research and Authority Resources
- AICPA — TQA 400.02: Using the Output of Technology (March 2026)
- AICPA & CIMA — Ethics, Accountancy, and AI-Powered Tools (April 2026)
- AICPA & CIMA — AI Governance and Internal Controls (March 2026)
- AICPA CPEA — Accounting Research & AI (August 2026)
- AICPA & CIMA / NC State — 2026 Global AI Opportunities & Risks Study
- CIMA — Future-Ready Finance: Technology, Productivity, and Skills
- NIST — AI Risk Management Framework
- NIST — Generative AI Profile (NIST AI 600-1)
- COSO — Achieving Effective Internal Control Over Generative AI (2026)
- PCAOB — QC 1000 (effective December 15, 2026)
- Google Search Central — Optimizing for Generative AI Features
AI and professional rules are evolving quickly. Firms should coordinate AI governance with qualified ethics, legal, privacy, cybersecurity, quality-management, insurance, and service-line specialists where appropriate.
The Bottom Line
Accounting firms do not need a policy that says AI is perfect.
They do not need a policy that says AI is forbidden.
They need a system that makes the professional standard clear when AI enters the workflow.
Authorize the use case.
Identify the data risk.
Govern the tool and access.
Obtain the source evidence.
Validate the output.
Exercise professional judgment.
Review at the required risk level.
Name the human who owns final approval.
That is AI GOVERN.
The question is not whether AI wrote the first draft.
The question is whether the final work is supportable.
Can the accountant trace it to evidence?
Can the reviewer reproduce the calculation?
Can the tax professional open the authority?
Can the auditor explain why the output is relevant to the audit objective?
Can the controller identify which assumption changed the forecast?
Can the manager explain why this use case was allowed?
Can the partner identify who approved it?
If the answer is yes, AI can become a force multiplier.
If the answer is no, speed has merely moved the risk downstream.
Approve the use.
Protect the data.
Verify the evidence.
Review the judgment.
Own the conclusion.
Protect Knowledge. Develop People. Scale the Firm.
Can Your Staff Verify AI-Generated Work—or Are Managers Becoming the AI Quality-Control Department?
SkillAbility helps accounting firms build the technical competence, professional skepticism, workpaper discipline, review judgment, and escalation behavior employees need to use AI without outsourcing professional responsibility to the model.
Book Your Free 10-Minute Structural Alignment Review →
Includes our 45-Day Out-of-Pocket Performance Guarantee.
To firms that make AI faster without making professional judgment weaker,
Vincent Howard, CPA
Managing Partner, Howard, Howard and Hodges
SkillAbility for Accounting Firms
About the Author
Vincent Howard, CPA has practiced public accounting since 1990. He earned a Bachelor of Science in Accounting and a Master’s in Taxation from the University of Central Florida, founded his accounting firm in 1993, and serves as Managing Partner of Howard, Howard and Hodges. He helped grow the organization from three people to approximately 50 staff across multiple Florida locations and states. He has participated in PASBA since 1997, and the firm was named PASBA Firm of the Year in 2015. Since 2020, he has built and run the SkillAbility accounting workforce development platform, used by more than 1,000 accounting professionals across dozens of PASBA firms.
How This Guide Was Developed
This guide combines Vincent Howard’s public-accounting and workforce-development experience with AICPA’s March 2026 guidance on using technology output, AICPA/CIMA’s 2026 AI ethics and governance resources, AICPA/CIMA and NC State’s global AI risk/readiness study, the August 2026 CPEA warning about AI-assisted accounting research, NIST’s AI Risk Management Framework and Generative AI Profile, COSO’s 2026 guidance on internal control over GenAI, PCAOB quality-control developments, and current SkillAbility frameworks for professional skepticism, workpaper review, AI training, tax research, controllership, and reviewer development. AI GOVERN and the 100-point readiness scorecard are SkillAbility operating frameworks designed to translate AI policy into observable professional behavior.
© 2026 SkillAbility for Accounting Firms. This article provides general educational information and does not replace legal, ethics, accounting, auditing, tax, privacy, cybersecurity, quality-management, insurance, state-board, client-contract, or other qualified professional advice.
