Policy section
1. Purpose and scope
State why the policy exists, who it covers, and which AI systems count. Include stand-alone chatbots, meeting tools, browser extensions, embedded software features, APIs, models running locally, and AI used by contractors when they handle firm work.
Starter language: This policy governs the use of AI systems for firm business by personnel and contractors. AI may support work only when the service, account, data, and workflow are approved under this policy.
Policy section
2. Approved systems
Maintain a controlled list with the exact product, account or workspace, permitted data classes, approved workflows, owner, settings, and approval date. A familiar vendor name is not enough.
Starter language: Users may use only the systems and account types listed in the firm’s AI register. Personal accounts and unlisted AI features may not be used for firm work.
Policy section
3. Data rules
Translate the firm’s information classification into simple AI instructions. State what may enter each approved environment and what always requires specific review.
Starter language: Client, taxpayer, employee, credential, and other restricted information may enter an AI system only when the written register expressly permits that data class and workflow.
Policy section
4. Human responsibility
Make clear that AI output is a draft. Assign review for facts, calculations, sources, tax positions, confidential information, bias, tone, and records treatment before reliance or delivery.
Starter language: The responsible professional must verify AI-assisted work to the same standard as other work. AI does not approve a conclusion, sign a deliverable, or replace professional judgment.
Policy section
5. Prohibited uses
Name uses the firm will not allow, such as entering restricted data into an unapproved system, exposing credentials, hiding AI use from a required reviewer, auto-sending unreviewed output, or delegating a decision that must remain with a professional.
Starter language: Users may not bypass access controls, connect an unapproved plug-in, disable required logging, or represent unverified AI output as established fact.
Policy section
6. Records and reporting
Explain which prompts, inputs, outputs, approvals, corrections, and incidents become firm records. Give staff a nonpunitive path to report a mistake or unapproved use quickly.
Starter language: Report accidental disclosure, suspicious output, unexpected system behavior, or unapproved use immediately through the firm’s security process. Prompt reporting supports containment and review.
Policy section
7. New uses and exceptions
Provide a short intake form and name the decision owner. Require the purpose, data, service, flow, professional reviewer, expected value, and proposed test. Time-box exceptions and document conditions.
Starter language: A new AI use requires approval before production data is used. Material changes to the provider, model, integration, purpose, or data path trigger review again.
Policy section
8. Training and enforcement
Train with real firm scenarios and verify understanding. Apply existing employment and professional policies consistently. Review the AI policy on a defined schedule and after significant changes or incidents.
Starter language: Users receive role-based instruction before access and periodic refreshers. The firm reviews this policy and AI register at least annually and when material changes occur.