Safe AI adoption for a tax practice

An example engagement for accounting firms in Houston.

This is an example engagement, not a client story. It shows how we would run an audit and build for a typical firm of this kind. The research figures come from the public sources cited, and nothing here reports a specific client's results.

A Houston tax and advisory practice with a few CPAs and enrolled agents that writes many client letters and IRS notice responses each year.

Staff have started pasting text into free AI chat tools to draft letters and summarize notices. Nobody is sure whether that counts as a disclosure of tax return information, or what the firm's security plan says about it.

The firm's written information security plan was drafted years ago and does not mention AI tools or the vendors behind them.

What the research says02

Section 7216 of the Internal Revenue Code requires tax return preparers to get the taxpayer's written consent before using or disclosing tax return information for purposes other than preparing returns, and the consent must meet specific content and signature rules.

The Tax Adviser (AICPA), "The many implications of Sec. 7216," January 2024↗

Federal law requires tax and accounting professionals to create and maintain a Written Information Security Plan. Under the FTC Safeguards Rule, security events affecting 500 or more people must generally be reported to the FTC within 30 days of discovery.

IRS, "IRS, Security Summit remind tax pros they need a Written Information Security Plan"↗
Audit, build, measure03

What the audit checks

  • Inventory every AI and cloud tool staff use and what client data goes into each.
  • Review vendor terms for data storage, retention, and model training.
  • Compare current engagement letters and consent forms with what the firm actually does.
  • Review the written information security plan against current IRS guidance.
  • Rank changes by risk reduced and staff time saved.

What we build

  • A written AI use policy that says which tools are approved and what data they may see.Advisory Retainer
  • Consent language for clients where a use requires it, reviewed with the firm's counsel.Advisory Retainer
  • Drafting and notice-summary tools set up on accounts that do not train on firm data.Internal AI Tooling
  • An updated written information security plan that covers AI vendors.Advisory Retainer

What we measure

  • Staff using only approved tools
  • Time to draft a routine client letter or notice response
  • Clients with signed consent where it is required
  • Security plan reviewed and dated within the last year

Every measure starts from the firm's own baseline, taken during the audit, so results are compared with how the firm ran before anything changed.

Keep reading03
Industry

Accounting firms

CPA and bookkeeping practices with seasonal spikes in demand.

Example engagement

Tax season document collection for a CPA firm

A small CPA firm spends tax season chasing clients for missing documents. The fix is automatic reminders that follow up until files arrive, plus intake and file search.

Example engagement

Month-end close for a bookkeeping firm

A bookkeeping firm closes the month late because client answers and receipts trickle in. The fix is automatic requests for missing items, clearer work assignment, and reports that build themselves.

Start with an audit.