Skip to content

A simple AI policy a small firm will actually use

On this page

The document most firms end up with says the practice uses AI responsibly, applies appropriate safeguards, and maintains professional judgment at all times. None of it is false. None of it can be followed either, because there is no moment in anybody’s week where it tells them what to do. At four people that matters more than it would at four hundred, since this is the only document you are going to write.

  • The rule that would otherwise have dictated the shape of it exempts a firm your size from exactly the parts you were about to copy, and keeps you on the substance.
  • A large firm’s policy is one component of an apparatus: supervision, monitoring, an annual sign-off, somebody whose job it is. Lift the document without the apparatus and you are holding the paperwork of a control rather than a control.
  • Write it as a register of decisions already taken, each with a date and a name against it, instead of a statement of what the firm believes.
  • The one rule that has to survive a bad afternoon turns on where something came from, never on how sensitive it is. Sensitivity asks for a judgment at the exact moment nobody has one going spare.

The rule that would have written it for you lets you off

If your practice prepares returns, the FTC’s Safeguards Rule reaches you, and what that does to your choice of supplier is an argument of its own. What is worth knowing before you draft anything is that the same rule has an exceptions section, and it is one sentence long.

“Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers” (16 CFR §314.6, checked 19 August 2026).

Those four paragraphs are the ones every template in this category is built out of: the requirement that your risk assessment be written out to a prescribed set of criteria, the requirement for continuous monitoring or annual penetration testing, the requirement for a written incident response plan, and the requirement for an annual written report to a governing body. The count is of consumers whose information you hold rather than of engagements, so it runs somewhat ahead of your client list, and a practice with a few hundred returns is still a long way under.

Now read what the exception does not touch. Access controls stay. The service provider paragraph stays. And so does the requirement to provide your personnel with “security awareness training that is updated as necessary to reflect risks identified by the risk assessment” (16 CFR §314.4, checked 19 August 2026).

Look at the split. What comes off is everything aimed at producing a file. What stays is everything aimed at your people. That is not a loophole and it is not a licence to skip the thinking, because the assessment underneath is still expected of you. It is a fairly clear statement about what a firm at this size is supposed to be doing with its afternoon, and it happens to be the same instruction the rest of this page arrives at from a different direction.

So a small practice that is excused the prescribed document and copies its shape anyway has taken on all of the cost and none of the benefit. The form is yours to choose. Choose it for the four of you.

What a policy can do when there are four of you

A policy in a firm of two hundred works through machinery. Someone reviews access quarterly because reviewing access is their job. Something flags a file leaving. New staff sign an attestation in their first week and again every year. There is a person to escalate to, and behind them a process nobody wants to meet. The written policy is the part of that you can photocopy, and it is the least of it.

Take an inventory of what you actually have. Nobody is watching what goes into a browser tab. There is no induction week: the seasonal preparer starts on a Monday in the middle of the worst month you have, and gets whatever you can hand them between two calls. The compliance function is a partner who is also the person with the most work on. What is left is three mechanisms, and they are all the ones you have.

Somebody remembers the rule while they are busy. The right route is easier than the wrong one. And somebody asks.

That decides the form before you write a word of it. It has to be short enough that it was actually read, because the second page of a one-page document does not exist. It has to be specific, because a general instruction loses every argument with a person’s own sense of being careful. And it has to be about moments rather than values. “Use good judgment with client data” is not a rule. It is a description of what everybody believes they are doing at the moment they are getting it wrong.

The other half of what makes it stick is not in the document at all. A policy two partners settled out loud in twenty minutes gets kept. One downloaded on a Sunday evening does not, and the difference has nothing to do with the wording.

The template is written for the wrong reader

There are two readers, and they want opposite things.

The first is the four of you, on the day, mid-task, needing an answer in seconds. The second is an examiner, an insurer, a client’s lawyer or a state board, reading months later with something already gone wrong.

Templates are drafted for the second reader, in the register of assurance, and firms copy that register because it is what a policy sounds like. The trouble is that it does not even work on the second reader. What that reader does is put your document beside what actually happened. A sweeping sentence that plainly was not kept is worse evidence than a modest one that was, because the first one establishes that your written rules and your practice are different things.

“All AI output is reviewed by a qualified professional before use”, in a firm where the scheduling ran itself all season, is a document arguing against you. Set beside it: client replies are prepared and wait for a person, filing and ranking run on their own, set this way on 3 March by the partner named at the top. That is not impressive. It is a decision, taken by somebody, on a date, matching what the software did.

Which produces the inversion worth carrying away. Writing for your own people gives the outside reader the better document too. Writing for the outside reader gives neither of them anything.

A record of decisions rather than a statement of principle

Almost none of the decisions get made in this document. Each one is made somewhere else, and in most firms most of them are already made: how far the software may go for each kind of work, who holds a seat, what clients are told and what they sign, what the profession’s own rule book requires when work goes outside the firm, what your supplier committed to and in which document, and what happens to the copies. Every one of those is its own piece of work, linked at the foot of this page.

What a small practice loses is not the decision. It is that the decision was reached between two people at a kitchen table, and a year later nobody can say whether the reply setting was raised deliberately or by somebody trying something out. Institutional memory at this size is two people’s memory, and it is not written down anywhere.

So the register, and five entries carry it.

Who may say yes, and to what. One person, named. Yes covers connecting anything to the mailbox or the ledger, accepting terms in the practice’s name, and moving a setting up. The value here is not the authority, which nobody was going to dispute. It is that a decision now has to be said out loud to another person, and at this size that is close to the whole of your detection.

What may be put into something that is not on the list. The next section, because it is the entry that does the most work and the one most often written in a way that cannot be followed.

Where the dial sits. A line for each kind of work, who may change it, and when it last changed. This entry ages fastest, and it is the first thing an outside reader will hold up against what the software actually did.

What a person does in the ten minutes after they think something went wrong. The section after next. Most policies at this size have no such entry, which is the reason they are found out at the worst possible moment.

When this gets read again, and by whom. Attach it to something that already happens rather than to a date in the diary. A new person is the obvious hook, because at four people a new person is a quarter of the firm and this page is the whole of their induction. The other hook is any entry above changing. What sets off a fresh round of questions to your supplier is a different trigger with its own answer.

Anything that will not sit under one of those five is not policy. It is either a decision belonging to one of the pieces linked below, or a sentence you were writing for the wrong reader.

The rule for the tool nobody bought

The list of what the firm uses is necessary and it is not the control. A list has no opinion about what is absent from it, and what is absent from it is where the exposure lives. Every other document your practice will produce attaches to software you chose and looked at. This is the only one that reaches the thing nobody chose.

The standard fix is a classification scheme: three or four tiers of sensitivity, each with rules hung off it. There is a legal problem with that, which is that in a practice nearly everything is inside the protected category anyway, and it is settled elsewhere. There is a second problem that belongs to policy design rather than to law, and it is the one that decides the matter.

Classification asks a person to make an assessment at the moment they are least equipped to make one. They are stuck, it is late, the tool is one tab away, and “is this really sensitive” has a convenient answer sitting right there. A scheme that requires judgment is a test that a tired person takes and passes.

Provenance asks for nothing. Did this come from a client, or out of work you are doing for a client? Then it does not go into anything that is not on the list. One question, one answer, no assessment, and it is answerable by somebody who is not thinking clearly, which is the entire property you are buying.

Three things that rule has to say out loud, because each of them is a place people quietly assume an exception.

It covers uses that have nothing to do with advice. A client’s letter dropped into a free grammar checker. A paragraph pasted somewhere to be made less blunt before it goes out. A photographed statement handed to a chatbot to work out what one line means. The person doing any of those is not seeking tax help and does not feel like they are handling client data.

It covers the fragment as much as the file. People hear this rule as being about documents, and almost nothing that actually crosses the line is a document.

And it has no anonymizing exception. That is deliberate rather than strict: “unless you take the names out” puts back precisely the judgment the rule exists to remove, and it is the amendment somebody will reach for at the moment you would least like them exercising judgment.

Then the part that decides whether any of it survives contact with March. A prohibition with no route through it is a prohibition that gets broken quietly, and quiet is the failure you cannot afford, because quiet and fine look identical from where you sit. So the rule arrives with a promise attached: ask, and you get an answer inside a day. And the person who may say yes has to actually answer inside a day. Miss that three or four times and the rule is dead, and it will die without anybody mentioning it to you.

Keep the refusals as well as the approvals. What was asked for, turned down, when, and one line of why. Otherwise the same question comes round every quarter and collects whichever answer that week happens to allow.

The half that always gets left out

Policies at this size stop at the prohibition, and the interesting hour is the one after somebody has already done it.

Go back to the inventory. There is no monitoring of what went into a browser tab, no alert, nobody reviewing anything. The only detection your practice owns is a colleague deciding to tell you, and that decision gets made in about four seconds, against whatever they expect to happen next.

Which makes the most load-bearing sentence in the document the one that makes telling you cheap. Say it the same day, it is what we expect rather than a confession, and it has never once been treated as a disciplinary matter. If you cannot write that sentence honestly, do not write the policy, because you will get exactly the silence you designed for and you will not know you are getting it.

Then four things, which are an afternoon rather than a project.

Write down what went in, into what, and when, while somebody still remembers it properly. A week later you are reconstructing rather than recording.

Read that tool’s terms for the two paragraphs that decide the answer: how long it keeps what it was given, and what it may do with it afterwards. Consumer terms in this category often say the opposite of what your own supplier’s say, and why the second paragraph is the one to read carefully is a subject of its own.

Delete what can be deleted, and ask about what cannot.

Decide whether this stops in your office, and take that one to your adviser rather than settling it yourself at six in the evening with a return open on the desk.

The last step is the one that separates a firm that learns from a firm with an incident file. Change the rule that permitted it, not the person. At four people the person is a quarter of your staff, and you are not going to lose them over a paragraph pasted into the wrong tab.

Where does Point fit?

A practice that connects Point is filling in most of the register above at once. The useful thing to set out here is which entries Point turns into a fact you can write down, and the place where the written record runs out.

  • How far Point goes is a setting, held separately for each kind of work, which is what lets “client replies wait for a person” be an entry you can check rather than an intention. Every kind starts on review, meaning Point prepares the work and stops there. Move one to the top and Point completes that kind without coming back to you, and the day you move it is the day the register entry changes.
  • A new kind of action begins on a short leash, waiting for your yes until you decide it has earned more. That is a default your policy can rest on instead of a rule it has to invent, which is why the entry is about what you raised rather than about what you permitted.
  • The log covers what Point did, in plain language, and most of it can be approved, turned down or reversed. What no log covers is the other half of this page, because nothing records a paragraph pasted into a browser tab. Knowing precisely where the written record stops is what tells you which line of your policy is carrying the weight on its own.
  • If the mailbox carries return information, the standard service does not extend to it unless a separate written supplement says so, and tax return information is named among the excluded categories. Put that document’s date in your register rather than a sentence describing it, and ask for it while you are still deciding.
  • Subprocessors carries a version and an effective date. That is what turns “keep a copy and name who compares it” into an instruction somebody can follow instead of a gesture, and the terms hold the rest of what was actually promised to you.

Written out at length rather than summarized, the capabilities are on the benefits page, and Point for accountants puts them in a firm’s own terms.

Common questions

Do four of us really need a written AI policy?

Nobody is requiring the file. The rule that prescribes written plans for larger institutions lets a firm holding information on fewer than five thousand consumers off those particular paragraphs, so the compliance answer is that your document is not the point. What you need is that the decisions you already took can be found by somebody who was not in the room when they were taken. Two partners agreeing something at a kitchen table is a real decision, and it evaporates in about a month.

Can we start from a template?

Take its headings and throw away its sentences. A template is drafted for a firm with the machinery to enforce it, and its language quietly assumes monitoring, an attestation and somebody whose job this is. You have none of those, so those sentences are decoration in your version and they read as decoration to anyone who checks. What survives at your size is the register: who may say yes, what may go where, where the settings sit, what happens afterwards, and when it gets read again.

How long should it be?

One page, and the test is a person rather than a word count. Somebody starts on a Monday in the middle of your busiest month and gets no induction beyond what you hand them between two calls. Whatever sits past the point where they stop reading does not exist, and everything you added for the benefit of a future examiner is sitting exactly there. Length is not a virtue in this document. It is the way it fails.

Should the policy name the tools we allow?

Yes, and this is precisely where the internal document parts company with the client-facing one. Naming a product in your engagement letter ties a signed contract to a decision you will revisit, so that document describes what the software does instead. Your own list has the opposite job. It has to be specific enough to check against in the second before somebody opens something, so it names products, dates them, and carries the ones you turned down beside the ones you allowed.

Somebody has broken the rule. What now?

Treat the report as the thing you wanted, because a colleague’s willingness to tell you is the whole of your detection at this size and it costs almost nothing to switch off. Write down what went where while it is still recent, read that tool’s terms on retention and on what it may do with what it received, delete what can be deleted, and take the question of whether this leaves your office to your adviser. Then change the rule that allowed it rather than the person, since one of four is not a headcount decision.

The short version

  • The Safeguards Rule excuses a firm holding information on fewer than five thousand consumers from the written risk assessment, the written incident response plan and the annual report. It excuses nobody from training their own people, which tells you who the document is for.
  • A large firm’s policy is the paperwork of an apparatus you do not have. Copied without it, you are holding the artefact and none of the control.
  • There are two readers and the template is drafted badly for the second one. A modest rule that was kept is better evidence than a sweeping one that plainly was not.
  • Write a register rather than an essay. Who may say yes, what may go where, where the dial sits, what happens afterwards, and when it is read again, each with a date and a name against it.
  • The rule that survives a bad afternoon asks where something came from, never how sensitive it is, and it comes with a route to yes inside a day. A prohibition with no route gets broken quietly, and quiet looks the same as fine.

Each entry in that register is decided elsewhere. How far to let the software go is is it safe to use AI with client financial data. What changes inside a firm once reading becomes cheap, including the seat list, is using an AI inbox without breaking confidentiality. What clients are told and what they sign is the engagement letter, what the profession already requires when work goes to an outside supplier is AI and the CPA Code, how to grade what a supplier tells you is questions to ask any AI tool, and what happens to the copies is keeping client data out of AI model training. Whether to connect a practice mailbox at all is the client data guide. And Point is what the whole of it looks like when it is working.

Join the private beta

We're onboarding a few teams at a time. Leave your email, confirm it once, and we'll send an invitation the moment a place opens.