Guide for firmsAI governance
AI policy for accounting firms: what to decide, test and record
A policy earns its keep when a colleague can tell, before opening a tool, what they may do, what they must check and when they must stop.

Short answerWhat should an accounting firm's AI policy include?
An accounting firm's AI policy should name the approved tools and accounts, the tasks each may do, the client data allowed in, what a human reviewer checks, who handles doubts and who can stop a tool. In the EU, a firm that uses AI at work must also take measures to support its staff's AI literacy. Test the policy on one workflow before you widen it.
Key takeaways
- Write the policy per task: tool, data, permitted action, stopping point and reviewer.
- The EU AI Act's literacy rule has applied since 2 February 2025. Since 27 July 2026 it requires firms that use AI at work to take measures to support their staff's AI literacy; the Commission says no certificate is needed.
- Human review means checking the output against its source and recording the decision, not rereading a fluent draft.
- A tool that can send, post or change records needs a named person who can stop it.
- Pilot one workflow, including awkward cases, before you widen the policy.
01What should an accounting firm's AI policy cover?
A useful AI policy is a set of decisions, not a statement of values. For each use, it records which tool and account are approved, what the tool may do, which client data may go in, who reviews the output and who answers when something looks wrong. If a colleague cannot apply it to a real file on an ordinary afternoon, it is not finished.
Firms are already writing these rules. ICAEW research published on 22 May 2026 surveyed leaders of 35 UK mid-tier firms in February and March 2026. Of those firms, 86% had a technology strategy that includes AI adoption, but only 17% felt confident assessing AI's effect on their workforce. That is one UK sample, not a picture of every firm. It does show the gap a policy has to close: adoption is planned, while the effect on people's work is still uncertain.
The templates we reviewed stop at a list of banned data and a promise of review. The table below works as a one-page template and adds the parts that make a policy usable: the permitted action, the stopping point, the escalation route and the person who can switch a tool off. Copy the first two columns, then write the third for each task you approve.
| Decision | What to write down | Example: drafting a document request |
|---|---|---|
| Approved tool and account | The configured service the firm pays for and controls, not a personal account with a similar name. | The firm's licensed workspace, used only with firm sign-ins. |
| Task | One defined job with an input and an expected output. | Draft the list of records needed for a year-end engagement from the approved template. |
| Permitted action | What the tool may do on its own, and what it must never do. | Draft only. It may not send, post or change any record. |
| Permitted data | Which categories of client data may go in, and which never may. | Company name, period and engagement plan. No identity documents or bank log-ins. |
| Human review | What the reviewer compares, resolves and records. | The engagement manager checks company, period, records and deadline against the plan, then approves. |
| Escalation | Who answers when the output or the rules are unclear. | The engagement partner for scope; the policy owner for tool questions. |
| Stop authority | Who can pause the workflow or withdraw access, and how quickly. | The policy owner can disable the workspace connection the same day. |
| Owner and review trigger | Who keeps the policy current, and which events force a re-check. | Re-check when the supplier changes a feature or the task widens. |
From scattered AI use to a policy your people can apply
Most of the work is in the first and fourth steps: knowing what is already in use, and saying exactly what a reviewer checks.
-
01
Inventory
List every AI tool in use, including personal accounts, and what people use each one for.
Read this step: Inventory -
02
Boundaries
Give each task a permitted action, a stopping point and a reviewer.
Read this step: Boundaries -
03
Data
Decide which client data may go into which approved account, with the supplier's answers in writing.
Read this step: Data -
04
Review
Write what the reviewer compares, resolves and records, who answers doubts and who can stop the tool.
Read this step: Review -
05
Pilot and brief
Run one workflow with awkward cases, record the failures, then brief staff and set a review date.
Read this step: Pilot and brief
The gates further down turn these steps into criteria you can tick, with an owner for each gate.
02Does the EU AI Act require an AI policy or AI training?
It does not prescribe a policy document, but it does require action on AI literacy. Article 4 of the EU AI Act, Regulation (EU) 2024/1689, has applied since 2 February 2025. It covers providers and deployers of AI systems. A deployer is any person or organisation using an AI system under its authority, other than for personal, non-professional activity. A firm whose staff use AI tools on client work is therefore a deployer. As an EU regulation, the Act applies directly in Malta, as in the rest of the EU. In Malta, the Malta Digital Innovation Authority is designated as a market surveillance authority and as the single point of contact for the AI Act (L.N. 226 of 2025, regulation 3).
Article 4 has since been replaced. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. The current text requires providers and deployers to 'take measures to support the development of AI literacy' of their staff and of others using AI on their behalf. Those measures should reflect people's knowledge, experience and training and the context in which the tools are used. The new text adds that a firm need not guarantee any specific level of AI literacy for any individual.
Several pages that rank for this topic still quote the original wording, which asked for 'a sufficient level of AI literacy'. That wording no longer applies; the duty to take measures remains. The Commission's AI literacy Q&A, last updated on 27 July 2026, says no certificate is needed, that organisations can keep an internal record of training and other guidance, and that no particular governance structure, such as an AI officer, is mandated. That is Commission guidance, not the legal text.
Two more EU rules shape the policy. The Act's stricter high-risk rules cover only the uses it lists, such as AI used to hire or evaluate staff, or to assess an individual's creditworthiness. They do not apply yet: Regulation (EU) 2026/1744 moved their start for those listed uses to 2 December 2027. Routine drafting and summarising is not itself a listed use, but check each use against the list now, so the policy is ready before those rules start. And where an AI supplier processes client personal data on the firm's behalf, the GDPR requires a binding contract that sets out the processing and the supplier's duties (Article 28).
| Source | What it is | What it means for your policy |
|---|---|---|
| EU AI Act, Article 4, as amended by Regulation (EU) 2026/1744 | EU law, directly applicable in Malta. Article 4 has applied since 2 February 2025; the amended text has been in force since 27 July 2026. | Take measures to support staff AI literacy, suited to their roles and tools. Keep a record of what you did. |
| GDPR, Article 28 | EU law, directly applicable in Malta. | Where a supplier processes client personal data for the firm, have a processor contract in place before use. |
| Artificial Intelligence Regulations, 2025 (L.N. 226 of 2025, Cap. 591) | Maltese regulations implementing the AI Act, published on 10 October 2025. | The Malta Digital Innovation Authority is designated as a market surveillance authority and as the single point of contact for the AI Act in Malta. Watch it for Malta guidance. |
| IESBA Code, technology revisions (2023) | International ethics standard; the technology revisions took effect internationally on 15 December 2024. In Malta, the Accountancy Board's 2016 Code of Ethics for Warrant Holders (Directive 2), in force since 17 June 2016, is mandatory for warrant holders. The Board based it on the IESBA Code with EU audit amendments; it predates the technology revisions and does not mention automation bias. | Good practice that informs the policy: treat automation bias and whole-lifecycle confidentiality as policy points. Responsibility stays with the accountant. |
| FRC Generative and Agentic AI Guidance, March 2026 | Non-binding guidance from the UK audit regulator, aimed at audit firms' central technical teams. | Three useful questions: is the output sound, is it used as intended, and does the methodology still meet auditing standards? |
| NCSC blog posts on shadow AI and agentic AI, and joint agentic AI guidance, 2026 | UK cyber security agency blog posts, and guidance the NCSC co-wrote with Australian, US, Canadian and New Zealand agencies. Context, not binding in Malta. | Offer approved alternatives to personal tools, limit access to what each task needs, and name who can stop an agent. |
| IAASB technology quality management guides | Proposed and working drafts discussed at the September 2026 board meeting. Not final. | Watch for the final guides. Do not treat drafts as requirements. |
03Which tasks should AI do first, and where must it stop?
Start with a task that is frequent, bounded and easy to check against a source. Drafting a document request from an approved template is a good first case. Summarising a long contract for an audit file is harder, because a missing clause is less visible than a wrong one. 'Use AI to improve productivity' is not a task. 'Draft the request, then ask the engagement manager to check the period and scope before anything is sent' is.
Give every task a permitted action and a stopping point. A drafting tool does not need permission to send emails, post journals or approve work, so do not give it any. List the uses that need a separate decision before anyone tries them, such as anything that files with an authority or messages a client directly. If staff cannot tell whether a proposed use falls inside the policy, name one person to ask and answer quickly.
| Task | The tool may | The tool must not | The reviewer checks |
|---|---|---|---|
| Draft a document request | Draft from the approved template and the engagement plan | Send it to the client | Company, period, records, deadline and scope |
| Propose categories for bank lines | Suggest an account for each line | Post entries without approval | Unusual payees, mixed business and personal spending, totals agreed to the statement |
| Summarise board minutes for the audit file | Summarise and give page references | Decide what matters to the audit | Each point against the minutes, and anything the summary left out |
| Draft a VAT return from the books | Prepare figures and a draft for approval | Submit the return | Figures agreed to the ledger and the treatment of unusual items |
04What client data may go into which AI tool?
The approved-tool list needs enough detail to tell the firm's configured service from a personal account with a similar name. Record the account, the permitted data categories and who approved the supplier arrangement. Then ask the supplier for written answers and keep them. Fill gaps with evidence, not assumptions.
Where the supplier processes personal data on the firm's behalf, the GDPR requires a binding contract. Among other things, it must require the supplier to act only on the firm's documented instructions, to keep the data confidential and to secure it. Ethics guidance points the same way. IESBA's June 2026 snapshot explains that, under the international Code as revised for technology, confidentiality covers the whole data lifecycle, from collection and use through transfer and storage to lawful destruction.
Plan for the tool people use anyway. An NCSC blog post of 7 September 2026 describes shadow AI as AI use outside an organisation's approved systems and processes. It warns that sending sensitive information to consumer AI services is likely to reduce an organisation's visibility and control over that information. Its advice is to understand why staff turn to unapproved tools, to offer secure approved alternatives and to keep a positive security culture with open communication. Make reporting a mistake easy, so a pasted client record is found the same day rather than at year end.
- Where are inputs and outputs stored, and for how long?
- Are inputs or outputs used to train or improve models, and can that be switched off for the firm's account?
- Which other companies process the data, and how will you tell us about changes?
- Who at the supplier can see our data, and is that access logged?
- Can we export or delete everything if we leave?
05What does human review of AI output actually involve?
A review instruction should say what the reviewer compares, what they resolve and what they record. Rereading a fluent draft is not the same as checking its facts against the source. For the document request, the reviewer confirms the company, period, records and deadline against the engagement plan, removes anything outside scope, approves the final text and keeps a note of the changes.
The FRC's March 2026 guidance on generative and agentic AI offers a useful structure, though it is non-binding UK guidance aimed at audit firms' central technical teams. It groups the risks to audit quality into three: the output is deficient; a sound output is misused; or the firm's methodology permits a use that does not meet auditing standards. It defines a human in the loop as someone who directs, authorises or reviews the system's actions or outputs while it runs. The FRC's announcement is plain on accountability: 'the human auditor is always accountable'.
International ethics standards point the same way. The IESBA Code's technology revisions took effect internationally on 15 December 2024. IESBA's 11 June 2026 snapshot explains that the Code now names automation bias, the tendency to favour a system's output even when contradictory information questions it, as a bias that can impair objectivity. It also states: 'Professional responsibility cannot be delegated to a machine.' In Malta, the Accountancy Board's 2016 Code of Ethics for Warrant Holders (Directive 2) is mandatory for warrant holders. It predates these revisions and does not mention automation bias. Treat automation bias as good practice for your policy, and train for it directly: ask reviewers to explain why they accepted an output, including any conflicting information they set aside.
A correct draft does not prove that it should be sent automatically.
06How do you control AI agents that can act, not just draft?
Some tools now take steps on their own: reading a mailbox, posting entries, sending requests. Test that authority separately from the quality of the writing. A correct draft does not prove that it should be sent automatically.
Joint guidance published on 1 May 2026 by the NCSC and cyber security agencies in Australia, the US, Canada and New Zealand, 'Careful adoption of agentic AI services', recommends a phased roll-out that starts with clearly defined, low-risk tasks. It advises limiting an agent's access to the resources, operations and time each task needs, and monitoring for unusual behaviour. It also advises using agentic AI only for low-risk, non-sensitive tasks, and never giving it broad or unrestricted access to sensitive data.
An NCSC blog post of 15 May 2026, which summarises that guidance, asks firms to settle ownership before deployment: who owns the system, who approves its access, who monitors it, who reviews incidents and who can stop it. In the NCSC's view, an agent whose actions you cannot understand, monitor or contain is not ready to deploy.
Write those answers into the policy. Name who can pause the workflow, withdraw access and restore an earlier version of a record. Check that each action leaves a log a reviewer can follow, and that the agent cannot widen its own permissions. Client files hold sensitive data, so start an agent on approved sample material or low-risk work, and keep client files in the firm's approved systems.
07How should a firm test and roll out the policy?
Roll out in stages and finish each stage before starting the next. The gates tool below uses six: know what is in use, write the rules, get supplier evidence, define review and escalation, pilot one workflow, then brief staff and set the review date. A gate passes only when every criterion in it is ticked.
In the pilot, rehearse awkward cases on purpose: a missing input, an outdated template and a request containing contradictory facts. Watch whether the preparer notices the problem and sends it to the right person. Record each failure as a change to the workflow or the training, then repeat the case. Keep the pilot small enough that the reviewer can explain every decision.
Give the policy one owner and each approved workflow its own owner. Keep a short decision record: tool and account, task, data boundary, reviewer, open questions and the date checked. The same record can hold your note of the AI literacy measures you have taken. Re-check it when the supplier changes a feature, the task widens or an incident shows a gap.
If you are assessing Vacei, its published pages describe VEE, the AI inside the platform, preparing the routine work while the firm's people review, decide and sign. They describe preparer, reviewer and partner sign-off on every file and a record of every step VEE takes. They also describe connecting Claude or ChatGPT, on subscriptions separate from Vacei, and AI training for the firm's team. Vacei's firm demo is shown on sample data, so you can watch those paths against one workflow from your policy. A demonstration is an input to your policy, not a substitute for it.
Plan your AI policy roll-out in six gates
Tick each criterion you can evidence today. A gate passes only when every criterion in it is ticked. Name an owner for each gate. The result shows your current gate and what is still missing.
How the result is worked out
A gate passes only when every one of its criteria is ticked; there is no partial pass. The current gate is the first gate, in the order listed, that has not passed.
Ticks are your own record of where things stand. Nothing is checked, verified or approved by this page.
Common questions
Does a small firm need a written AI policy?
The EU AI Act does not require a written policy document, but if anyone uses AI on client work, write one, even a single page. The Act's literacy duty applies to any organisation that uses AI at work, whatever its size, and a written policy is an easy place to record the measures you took. The confidentiality and review questions are the same for two people as for two hundred. Start from the one-page template in section 01: approved tools, permitted data, review, who to ask and who can stop a tool.
Does the EU AI Act require AI literacy certificates for staff?
The Commission's Q&A says no certificate is needed and that organisations can keep an internal record of training and other guidance. Since 27 July 2026, Article 4 also states that a firm need not guarantee any specific level of literacy for any individual. The duty to take measures that support literacy remains, so record what you did, for whom and when.
What is the '30% rule' or '70/30 rule' for AI?
It appears in search snippets, but none of the regulators and standard-setters cited on this page sets a share of work that AI may do. What they ask for is defined tasks, review suited to the risk and a person who stays responsible. Set the review for each task rather than by percentage.
Are accountants allowed to use AI on client work?
Yes. None of the laws, standards or guidance on this page bans it; they set conditions instead. Under the EU AI Act the firm takes measures to support staff AI literacy, the GDPR requires a processor contract where a supplier processes client personal data for the firm, and your ethics code still applies. Approval of the final output by a person is necessary but not enough: the tool, the account, the permitted data, the supplier terms and the reviewer's competence matter too. The FRC also separates a deficient output from a sound output that is misused.
Should the policy cover personal AI accounts?
Yes. Say which accounts and settings are approved for firm work, which data must never go into a personal account, and how staff report a mistake or request an approved alternative. The NCSC recommends finding out why people use unapproved tools and offering secure alternatives that meet the need.
Do we need to tell clients we use AI?
The sources on this page do not set one standard disclosure. Your engagement letters, privacy notice and supplier contracts must match what you actually do, so decide a position, write it into the policy and have the wording checked by your adviser.
Can AI sign off audit work?
AI can prepare work for review, but it cannot carry responsibility for it. The FRC states that the human auditor is always accountable, and IESBA states that professional responsibility cannot be delegated to a machine. The conclusion and the signature stay with a qualified person.
How often should we review the policy?
Set a date, for example every six months, and add triggers: a supplier changes a feature or its terms, the firm widens a task, someone asks for a new tool, or an incident or near miss shows a gap. Record the date checked each time.
How this guide was prepared
Method and limits
This guide sets out the decisions a firm makes when it writes an AI policy. Each legal or standards statement comes from a source listed below, with the date we checked it. EU law is described as amended and in force on 6 October 2026. UK guidance and international standards are labelled as such and kept apart from the EU and Maltese law that applies to a firm in Malta.
The gates tool records what you say you can evidence. It does not inspect documents, test tools or decide whether you comply with the EU AI Act, the GDPR or any ethics code. Passing every gate means you ticked every criterion, nothing more.
Statements about Vacei describe its published pages. They are not test results, and a demonstration does not settle any of the policy decisions above.
Related Vacei pages: The operating system for firms · Audit on Vacei · Pricing for firms.
Who prepared it
- Author
- A4 Team
- Published
- 6 October 2026
- Last substantive update
- 6 October 2026
- Sources checked
- 6 October 2026
Sources
- EUR-Lex: Regulation (EU) 2024/1689 (AI Act), consolidated text of 27 July 2026, Articles 3(4), 4, 26, 113 and Annex IIIeur-lex.europa.eu · published 27 July 2026 · checked 6 October 2026
- EUR-Lex: Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal of 24 July 2026eur-lex.europa.eu · published 24 July 2026 · checked 6 October 2026
- European Commission: AI Literacy, questions and answers (last update 27 July 2026)digital-strategy.ec.europa.eu · published 27 July 2026 · checked 6 October 2026
- EUR-Lex: Regulation (EU) 2016/679 (GDPR), Article 28eur-lex.europa.eu · published 4 May 2016 · checked 6 October 2026
- legislation.mt: Artificial Intelligence Regulations, 2025 (L.N. 226 of 2025, Cap. 591), regulations 1 and 3legislation.mt · published 10 October 2025 · checked 6 October 2026
- IESBA: Ethics and Independence Approach to the Use of Technology (snapshot)ethicsboard.org · published 11 June 2026 · checked 6 October 2026
- IESBA: technology-related revisions to the Code and their effective datesethicsboard.org · published 11 April 2023 · checked 6 October 2026
- Accountancy Board Malta: directives library, Directive 2, 2016 Code of Ethics for Warrant Holders (in force since 17 June 2016)accountancyboard.gov.mt · checked 6 October 2026
- FRC: Generative and Agentic AI Guidance (PDF)media.frc.org.uk · published 30 March 2026 · checked 6 October 2026
- FRC: announcement of the Generative and Agentic AI Guidancefrc.org.uk · published 30 March 2026 · checked 6 October 2026
- NCSC blog: The hidden risks of shadow AIncsc.gov.uk · published 7 September 2026 · checked 6 October 2026
- NCSC blog: Thinking carefully before adopting agentic AIncsc.gov.uk · published 15 May 2026 · checked 6 October 2026
- Cyber.gov.au: Careful adoption of agentic AI services (joint guidance co-authored by the NCSC)cyber.gov.au · published 1 May 2026 · checked 6 October 2026
- ICAEW: Mid-tier firms focused on AI and consolidationicaew.com · published 22 May 2026 · checked 6 October 2026
- IAASB: September 2026 board meeting, Technology Quality Management Guides (drafts)iaasb.org · published 14 September 2026 · checked 6 October 2026
- Vacei: published firm overviewvacei.com · checked 6 October 2026
- Vacei: book a firm demovacei.com · checked 6 October 2026
See how review and sign-off work in Vacei
Bring one workflow from your policy. See the preparation path, the review and sign-off path and the record of each step VEE takes, shown on sample data.