Skip to main content
CAAIforCAs

AI Policy for CA Firms: A Practical Template and Guide

P

CA Prateek Agarwal ·

Every CA firm using AI needs a written policy, not verbal guidance repeated inconsistently to whoever asks — and it does not need to be long to be effective. This is a practical, copy-paste template with twelve sections a firm can adapt in an afternoon, plus sample clause language for the two sections that matter most: what staff may never do, and what gets verified before an AI-assisted deliverable reaches a client.

Why a written policy, specifically

Verbal instructions about AI use drift. One partner tells a junior "don't paste client data into ChatGPT," another says nothing at all, and a new hire who was never told either way makes their own judgement call under deadline pressure. A written policy fixes the rule once, makes it visible to everyone at the same time, and gives you something concrete to point to if a client asks how their data is handled or if a review reveals a mistake. It is the same reason a firm has an engagement letter instead of relying on what was said in a meeting — the value is in the record, not in the ceremony.

Before you write anything: two decisions to make first

Classify your data. Most firms find it useful to separate data into a few buckets: public (no restriction), internal firm information (low sensitivity), client-identifiable (names, PANs, GSTINs, financial figures — high sensitivity), and anything statutorily sensitive (minors' data, banking credentials — highest sensitivity). The policy's rules will differ by bucket, so decide the buckets before writing the rules.

Decide your approved tools list. Which AI tools does the firm actually endorse, at which tier, for which purpose? A firm with a paid TaxBotGPT or Taxmann.ai subscription for research and an enterprise ChatGPT seat for drafting has a very different policy from a firm relying entirely on free consumer tools. Decide this first — the policy documents a decision, it does not make one for you.

The policy template

Copy these twelve section headers and adapt the content under each to your firm.

1. Purpose and scope

State that the policy governs how the firm's partners, staff, and articled assistants use AI tools in client work, and that it applies regardless of whether the tool is firm-provided or personally adopted.

2. Definitions and data classification

Define your data buckets from above (public, internal, client-identifiable, high-sensitivity) so every later section can reference them without re-explaining.

3. Approved tools list

A living table: tool name, approved use (drafting / research / reconciliation / bookkeeping), account tier, and which data classification it may touch. Review and update this list at least quarterly.

4. Prohibited uses

The explicit "never do this" list — see sample language below.

5. Roles and responsibilities

Name who approves new tools, who owns the tool inventory, and who staff escalate a data-handling question or a suspected incident to (this should match the accountable owner named in your DPDP implementation work — see DPDP Act and AI: what CA firms need to know).

6. Client consent and engagement letter language

State that engagement letters disclose AI use, and reference the standard clause the firm uses (see can you upload client financial data to ChatGPT for the reasoning behind this clause).

7. Data handling rules by tool tier

Spell out concretely: free consumer accounts get anonymised, non-identifiable tasks only; paid business or enterprise accounts with a data processing agreement may handle client-identifiable data within the scope the DPA permits.

8. Verification and sign-off requirements

The section that actually protects deliverable quality — see sample language below.

9. Incident and breach reporting

A short, clear instruction: what to do the moment someone realises client data went somewhere it should not have, including who to notify immediately and what not to do (do not try to "fix" it quietly before reporting).

10. Training requirements

State the minimum onboarding training for new joiners and the cadence of refresher training for existing staff.

11. Policy review cycle

State the review frequency (annually, minimum) and the trigger events that force an earlier review — a new tool, a vendor terms change, an incident.

12. Acknowledgement and sign-off

A simple line for each staff member to sign confirming they have read and understood the policy, with a log the firm keeps on file.

Sample clause language: prohibited uses

Adapt this directly:

Staff must not paste or upload client-identifiable data — including names, PANs, GSTINs, bank account details, salary figures, or the contents of any notice or order — into a free consumer AI account. Client-identifiable data may only be processed through tools named on the Approved Tools List operating under a signed data processing agreement. Staff must not rely on any AI-generated legal citation, case reference, or statutory provision without independently verifying it against the primary source before it appears in any client-facing document. Staff must not use AI output to make a final interpretive judgement on a client's behalf without partner or manager review.

Sample clause language: verification and sign-off

Adapt this directly:

Every AI-assisted deliverable — including drafts, computations, research summaries, and correspondence — must be reviewed by a person other than its preparer before it is issued to a client or filed with an authority. The reviewer must confirm: (a) every legal citation has been checked against its primary source, (b) every computation has been independently verified or re-run, (c) any document summary has been spot-checked against the original file, and (d) no client-identifiable data was processed through a tool outside the Approved Tools List. The reviewer records their name and the date of verification in the working paper file.

Rolling this out: small firm vs larger firm

A two-to-five person firm can run the whole template as a single one-to-two page document, with the managing partner as the accountable owner for every role in Section 5. Rollout is a short team conversation plus a signature on Section 12 — this should not take more than a week.

A larger, multi-partner firm benefits from a fuller document: a dedicated owner or small committee for Section 5, a more detailed Approved Tools List broken out by department (tax, audit, bookkeeping), and a formal training session rather than an informal briefing. Practice-management platforms such as TechCA or workflow tools like Finexo can help operationalise the tool inventory and sign-off tracking called for in Sections 3 and 8, turning the policy from a document into an enforced workflow rather than something staff are simply asked to remember.

Either way, resist the urge to write a long, generic policy that reads well but tells no one what to actually do at their desk. The test of a good AI policy is whether a junior under deadline pressure can read Section 4 and know immediately whether they are allowed to paste this specific file into that specific tool.

Frequently asked questions

Does a two-partner firm really need a written AI policy?

Yes, and it can be one page. The value of writing it down is not bureaucracy — it is that verbal instructions get forgotten, differ between who gave them, and leave no record if a client or regulator asks what the firm's rule actually was. A one-page policy covering approved tools, the client-data rule, and who to escalate to takes an afternoon to write and removes most of the ambiguity that causes mistakes.

Should the policy name specific AI tools or stay generic?

Name specific tools. A generic policy that says "use AI responsibly" gives staff no actual decision rule. A policy that says "ChatGPT (personal accounts) is approved for anonymised drafting only; TaxBotGPT and the firm's enterprise account are approved for client-identifiable research" tells a junior exactly what to do at 6pm on a deadline. Update the named list whenever tools change — this is meant to be a living document, not a one-time exercise.

Who should sign off on the AI policy — does it need partner approval?

A CA firm's AI policy should be approved by the partner(s) with overall responsibility for risk and quality control, the same level that signs off on the firm's engagement quality control document. It is not a document a single senior associate should issue informally, because it sets rules that affect confidentiality obligations the whole firm carries.

How often should the policy be reviewed?

At minimum annually, and immediately whenever the firm adopts a new AI tool, a vendor changes its data-handling terms, or a near-miss incident reveals a gap. Treat the review date the same way you treat renewal of any other firm policy — put it on the compliance calendar so it does not get forgotten for three years.

The takeaway

An AI policy earns its place only if it tells staff exactly what to do with a specific file and a specific tool, not "use good judgement." The twelve-section template above — data classification, an actual approved tools list, explicit prohibited uses, and a verification sign-off step that names a reviewer — covers the ground a CA firm needs, and the two sample clauses give you language you can paste in today rather than draft from scratch. Write it, get partner sign-off, have every staff member acknowledge it, and put a review date on the calendar so it stays current as your tools change.

Related software