# AI policy template for UK accounting firms

> A clause-by-clause AI policy template for UK accounting firms, mapped to UK GDPR, ICO guidance, ICAEW ethics and the 2026 PCRT AI guidance.

Guide · Accounting practices · By Syed Husnain Khalid · Published 8 October 2026 · Last checked 8 October 2026
Drafted with AI. Each claim was checked against the primary sources listed below by AI on 8 October 2026; a person has not reviewed it yet.
Canonical: https://vexralabs.com/insights/ai-policy-template-accounting-firms

Short answer

An AI policy for a UK accounting firm is **a rule set: approved tools, the client data staff may enter, and the person who signs off every output**. UK GDPR does not name it, but Article 24(2) requires data protection policies where proportionate, and ICAEW (the Institute of Chartered Accountants in England and Wales) tells finance professionals to have one.

This guide is for partners, compliance leads and practice managers at UK accounting firms that need one rule set before the next tool is adopted. Two dates matter in 2026: the Data (Use and Access) Act 2025 completed the replacement of Article 22 by Articles 22A to 22D on 5 February 2026, and the seven bodies behind Professional Conduct in Relation to Taxation (PCRT) published topical guidance on AI on 19 January 2026. Building Filyst, our case management product for immigration firms, taught us that a sign-off rule holds only when the server rejects self-approval. The sections cover who must follow the policy, the duties behind it, a template to adapt, and the records that prove it works.

**Diagram: Where the AI policy sits in one piece of client work.** A partner signs the policy. A member of staff picks an approved tool and enters only the data the policy allows. The draft is prepared, then a person checks it against the source and approves it. The record of who checked and what was entered stays on the file.

*The sign-off step is what keeps the work the firm's, not the tool's.*

## What is an AI policy for an accounting firm?

An AI policy is the firm’s rule set for AI use: which tools staff may use, what data they may enter, who checks the output and what gets recorded. The Information Commission is the UK data protection regulator: it replaced the Information Commissioner on 30 September 2026 under [section 118 of the Data (Use and Access) Act 2025](https://www.legislation.gov.uk/ukpga/2025/18/section/118) and still publishes at ico.org.uk, so this guide calls it the ICO. Its [guidance on explaining AI-assisted decisions](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/explaining-decisions-made-with-artificial-intelligence/part-3-what-explaining-ai-means-for-your-organisation/policies-and-procedures/) separates policy, which sets out what the rules are, why they exist and who they apply to, from procedure, which says how to follow them. The same split works for an AI-use policy.

Two bodies that oversee your work point at the same document. The [ICAEW dos and don’ts of using AI](https://www.icaew.com/technical/technology/artificial-intelligence/generative-ai-guide/dos-and-donts) tell finance professionals to “ensure you have appropriate policies and guidelines in place on how AI should be used”. The seven bodies behind PCRT go further in their [topical guidance of 19 January 2026](https://assets-eu-01.kc-usercontent.com/220a4c02-94bf-019b-9bac-51cdc7bf0d99/7b1b2fa2-794f-42d7-949d-5d74bbf42217/PCRT%20_%20ethical%20use%20of%20artificial%20intelligence%20tools%20%E2%80%93%20Jan%202026.pdf): an AI usage policy “may outline the acceptable use of AI tools and staff disclosure”, which they list as a safeguard against unknown or inappropriate use of AI inside a firm.

## Who must follow the policy, and what changed in 2026?

Everyone at the firm who uses an AI tool follows it, partners and juniors alike, on every engagement. Two sources shape what it should contain: the professional body you belong to, and UK GDPR, which binds the firm as controller ([Article 4(7)](https://www.legislation.gov.uk/eur/2016/679/article/4)) wherever it decides why and how client personal data is processed.

PCRT is Professional Conduct in Relation to Taxation, the ethical code prepared by seven bodies: the Association of Accounting Technicians (AAT), the Association of Chartered Certified Accountants (ACCA), the Association of Taxation Technicians (ATT), the Chartered Institute of Taxation (CIOT), the Institute of Chartered Accountants in England and Wales (ICAEW), the Institute of Chartered Accountants of Scotland (ICAS) and the Society of Trust and Estate Practitioners (STEP). The [seven bodies announced the AI guidance on 19 January 2026](https://www.tax.org.uk/professional-bodies-issue-ai-advice-to-members), and it applies to any PCRT body member or regulated firm using AI tools in work on UK tax matters.

The ICO publishes the guidance on AI and data protection. It says the guidance “is not a statutory code” and carries the notice that it is under review because of the Data (Use and Access) Act, so treat it as the regulator’s reading of the law rather than as law itself.

Two regulators sit at the edges of practice work. The Financial Reporting Council (FRC), the UK audit regulator, [published guidance on generative and agentic AI in audit on 30 March 2026](https://www.frc.org.uk/news-and-events/news/2026/03/innovative-new-guidance-supports-audit-firm-adoption-of-emerging-ai-technologies) and says regulatory accountability is unchanged: the human auditor is always accountable, and the guidance encourages firms to consider how their use of AI tools fits within quality management under ISQM (UK) 1. The Financial Conduct Authority (FCA) [relies on its existing frameworks for AI](https://www.fca.org.uk/firms/innovation/ai-approach) and does not plan extra AI regulation, so a firm the FCA authorises follows its existing FCA rules alongside this policy.

## What does UK GDPR require of the policy?

UK GDPR does not require a document called an AI policy. It requires the firm to follow the principles, to show that it follows them and to keep records of what it processes, and [Article 24(2)](https://www.legislation.gov.uk/eur/2016/679/article/24) says that, where proportionate in relation to the processing activities, those measures include appropriate data protection policies.

| Duty | Where it comes from | What the policy shows |
| --- | --- | --- |
| Follow the data protection principles and demonstrate compliance | Article 5(1) and 5(2): the controller is responsible for, and must be able to demonstrate, compliance | Who owns each rule, and where the evidence sits |
| Implement technical and organisational measures; where proportionate, data protection policies | Article 24(1) and 24(2), with measures reviewed and updated where necessary | The policy itself, with a named owner and a review date |
| Keep a record of processing activities | Article 30(1); Article 30(5) withdraws the under-250-person exemption where processing is likely to result in a risk, is not occasional, or includes special category data or criminal offence data | One register entry per AI use: purpose, data, tool, vendor |
| Assess the risk before high-risk processing starts | Article 35(1), including 35(3)(a) for systematic and extensive evaluation producing legal or similarly significant effects | The assessment date and the decision it supports |
| Give a processor written terms before it handles personal data | Article 28(3) and 28(9) | A vendor check before a tool reaches the approved list |

Article 30(5) is why a small practice still keeps the register: the exemption for organisations with fewer than 250 people does not apply when the processing is not occasional, is likely to result in a risk, or includes special category data, such as health information, or data about criminal convictions and offences. Accounting firms hold the last kind through anti-money laundering checks.

The assessment duty is easy to miss. The ICO puts it plainly: “In the vast majority of cases, the use of AI” is processing likely to result in a high risk and triggers the legal requirement for a data protection impact assessment, and a firm that judges a use not to be high risk still has to document how it reached that judgement. Our guide to [DPIA for AI tools: when a UK firm needs one](https://vexralabs.com/insights/dpia-for-ai-tools) runs that test use case by use case.

## When does Article 22 restrict a decision made with AI?

Only a significant decision about a person taken with no meaningful human involvement. [Article 22A](https://www.legislation.gov.uk/eur/2016/679/article/22A) defines a decision as based solely on automated processing when there is no meaningful human involvement, and as significant when it has a legal effect for the person or a similarly significant effect.

Section 4A, which holds Articles 22A to 22D, substituted for Article 22 by the Data (Use and Access) Act 2025 (c. 18), sections 80(1) and 142: in force on 19 June 2025 for specified purposes and otherwise on 5 February 2026 under S.I. 2026/82, regulation 2(j). Article 22A(2) adds that whoever decides whether human involvement was meaningful must consider, among other things, how far the decision came by means of profiling.

Most accounting work never reaches that test. Drafting an email, summarising a bank statement or extracting figures is not a decision about an individual. Where a tool does shape a decision about a person, the sign-off clause in the template is what keeps the human involvement meaningful. If a significant decision were ever taken with no meaningful human involvement, [Article 22C](https://www.legislation.gov.uk/eur/2016/679/article/22C) would require safeguards: information about the decision, a way to make representations about it, human intervention on the part of the controller, and the ability to contest it.

The other duties do not fall away when a person is involved. The ICO [says](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/explaining-decisions-made-with-artificial-intelligence/part-1-the-basics-of-explaining-ai/legal-framework/)that even where an AI-assisted decision is not a solely automated process because there is meaningful human involvement, personal data used in it is still subject to all the GDPR’s principles, with fairness, transparency and accountability of particular relevance.

[Article 22B](https://www.legislation.gov.uk/eur/2016/679/article/22B) adds two limits on that same kind of decision. For special category data under Article 9(1) it needs either a decision based entirely on data the person has explicitly consented to, or a decision necessary for a contract or required or authorised by law, together with the condition in Article 9(2)(g). And a significant decision may not be taken solely by automated processing where the processing relied on for it is a recognised legitimate interest under [Article 6(1)(ea)](https://www.legislation.gov.uk/eur/2016/679/article/6).

## AI policy template for UK accounting firms

This template is a starting point to adapt, not a finished policy. Replace every bracket, delete what does not apply, and have a partner approve the result. The ICO, ICAEW and the seven PCRT bodies have not reviewed or approved this text.

### Purpose and status

[Firm name] uses artificial intelligence (AI) tools to prepare work. This policy says which tools are approved, what data may be entered, who checks the output and what we record. It applies from [date], is owned by [name and role], was approved by [partner] on [date] and is next due for review on [date]. It sits alongside our data protection policy and does not replace professional judgement or the responsibility of the person who signs off.

### Who this policy covers

This policy applies to everyone at [firm name] who uses an AI tool: partners, employees, contractors and temporary staff, on client work and on the firm’s own administration. Where a client engagement gives its own instruction about AI, that instruction applies in addition to this policy.

### Approved tools

Staff may use only tools on the approved list: [tool, vendor, purpose, date approved]. A tool joins the list after [owner] checks the vendor’s business terms, where the data is stored, whether inputs are used for training and whether a data processing agreement is available. Personal accounts are not approved for client work. Staff request new tools at [address or form].

### Client and firm data

Client data stays out of publicly available AI tools unless the client has consented in writing. Where a public tool is used, the input is anonymised and generic so the client cannot be identified. Client records go only into tools listed as handling them. Never enter passwords, bank details, health information or anything covered by a non-disclosure agreement.

### Review and sign-off

Every AI-assisted output is checked by a person before it leaves the firm. The person signing off did not produce the draft, checks it against the source and against their knowledge of the client, and records [name, date, tool used]. Work that shapes a decision about a person needs [partner] approval whatever the tool produces.

### Telling clients

Our engagement letter states that AI-enabled software may be used in providing our services, and we tell a client when AI was used in a deliverable they receive. This policy is available to clients at [web address or on request]. Where a client objects to AI use, we do not use AI tools on their engagement.

### Records

For each piece of AI-assisted work we record the tool and vendor, the date, the prompt or instruction used, the person who checked it and the date of sign-off. Where a tool draws on a website we keep a copy of that page. Separately, the firm keeps its record of processing activities under Article 30, listing each AI use, its purpose and the categories of data involved.

### Training and questions

Before using an AI tool, staff complete [training] and read this policy. Questions about a tool, a client or an output go to [name and role] before the work is issued. No one is expected to sign off output they do not understand.

### If something goes wrong

Report client data entered into the wrong tool, an incorrect figure reaching a client, or a tool behaving outside its terms to [name] on [channel] within [time]. We record the incident, tell the client where they are affected, and check whether a personal data breach must be reported to the Information Commission (the ICO).

### Owner, checks and review

[Owner] checks this policy [monthly or quarterly]: which tools are on the list, how many sign-offs were recorded, whether any work left the firm without one, and whether any tool’s terms have changed. The policy is reviewed [at least annually] and whenever a new tool, a new service line or a change in the law requires it. Article 24(1) expects the measures behind it to be reviewed and updated where necessary.

## Which clause answers which duty?

Each clause above answers something a source already asks for, so a reviewer can trace the document in one pass. The table maps the template’s sections to the provision or guidance line behind them.

| Template clause | What it answers | The source behind it |
| --- | --- | --- |
| Approved tools | Who checked a vendor before staff may use it | ICAEW generative AI and ethics: ask the right questions of suppliers and get the evidence; Article 28(3): processor terms |
| Client and firm data | What may be typed into a publicly available tool | PCRT topical guidance 4.2, 4.4 and 4.5: likely breach of client confidentiality without consent; input anonymised and generic; control over the data is relinquished |
| Review and sign-off | Who is answerable for the output | PCRT topical guidance 3.5: members remain ultimately accountable regardless of AI; ICAEW: include humans in the loop as necessary, review with professional scepticism |
| Telling clients | How a client learns AI was used | PCRT topical guidance 1.3 and 4.3: engagement letter statement, and clients directed to an AI usage policy |
| Records | How the firm proves what happened | Article 30(1) register; Article 5(2) accountability; PCRT integrity safeguards: audit trail of tools used, prompts and copies of webpages |
| Owner, checks and review | Who monitors the policy and how often | The ICO's explainability policy table (ownership row): the checks to make, how often, and how to record and sign off that work, a model the firm can borrow |

The use cases this policy governs are the ones set out in [AI for accounting practices: safe uses and review steps](https://vexralabs.com/insights/ai-for-accounting-practices). The software built around that review step is [Software for accounting practices](https://vexralabs.com/accountants), where AI prepares drafts and your staff approve them before anything posts.

## Who signs off AI-assisted work?

Our template has a named person who understands the work sign off, and that person did not produce the draft. That separation is the firm’s choice, not a rule. What the sources require is accountability: PCRT makes members ultimately accountable for work produced with or without AI, and ICAEW asks firms to include humans in the loop as necessary and to review output with professional scepticism.

The ICO’s policy table, written for explaining AI-assisted decisions, asks a firm to set out the checks the policy owner makes, how often to make them, and how to record and sign off that work. A sign-off rule therefore needs an owner and a frequency, not only a principle. ICAEW’s [generative AI and ethics guidance](https://www.icaew.com/technical/technology/artificial-intelligence/generative-ai-guide/ethics) maps the five fundamental principles of the International Ethics Standards Board for Accountants (IESBA) Handbook onto AI use, and tells members to ask suppliers the right questions and get the evidence.

We hit this while building Filyst, our case management product for immigration firms: a sign-off rule that lives only in a document is easy to bypass, so Filyst rejects self-approval on the server and a case cannot move to the next stage when the same person prepares and approves it. The rule still belongs to the firm; the system only makes it harder to skip.

A workable split in a small firm: output that never leaves the practice is checked by a senior member of staff, output sent to a client is checked by the manager on the engagement, and output that shapes a decision about a person is approved by a partner. Record which of the three applied.

## How do you show the policy is followed?

Keep a record that ties the work to the policy: which tool was used, what data went in, who checked the output and when. Under Article 5(2) the firm must be able to demonstrate compliance, and the ICO [asks controllers to document their AI risk trade-off decisions](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/what-are-the-accountability-and-governance-implications-of-ai/)“to an auditable standard” as part of their Article 24 responsibility.

PCRT suggests the same trail from the other end: staff disclose AI use to senior colleagues, and members should consider keeping details of the tools used, screenshots of prompts and copies of relevant webpages as evidence that reasonable care was taken. What to capture per decision is set out in [AI audit trail](https://vexralabs.com/insights/ai-audit-trail).

Two softer checks close the loop. Staff are trained before they use a tool: PCRT says members must “ensure that staff receive appropriate training for any AI tool used”, and ICAEW’s dos and don’ts ask that those using AI are adequately trained. And the measures behind the policy are reviewed and updated where necessary, the wording of Article 24(1), so a set review date is a practical way to meet that duty, not just housekeeping.

## What should you do after the policy is signed?

Circulate it, put the engagement letter wording in front of every client, and test the policy against one real workflow. Two checks follow: whether the vendor’s terms allow the data you want to enter, and whether the use needs a data protection impact assessment (DPIA) before it starts.

[Is ChatGPT GDPR compliant?](https://vexralabs.com/insights/chatgpt-client-data-policy)checks a vendor’s terms clause by clause, the shape the approved-tools check above follows. Our [DPIA for AI tools: when a UK firm needs one](https://vexralabs.com/insights/dpia-for-ai-tools) runs the assessment test, and the accounting hub’s [AI for accounting practices: safe uses and review steps](https://vexralabs.com/insights/ai-for-accounting-practices) is where the use cases themselves are listed.

Not legal advice

This guide and template are built from the UK GDPR, the ICO’s AI guidance, which the ICO says is not a statutory code and has marked under review since the Data (Use and Access) Act, the ICAEW generative AI guide, and the PCRT topical guidance dated 19 January 2026, all read on the date checked. Adapt the template to your firm and take advice before relying on it.

## Frequently asked questions

### Does UK GDPR require an AI policy?

Not by that name. Article 24(2) says the controller's technical and organisational measures include appropriate data protection policies where proportionate, Article 30(1) requires a record of processing activities, and Article 5(2) requires you to demonstrate compliance. A written AI policy, kept alongside the Article 30 record, is how a small firm shows all three for its AI use.

### Can staff put client data into ChatGPT?

PCRT says the input of client data into publicly available AI tools is likely to constitute a breach of client confidentiality unless the client has consented, and that data entered should be anonymised and generic. ICAEW says to keep client and confidential internal data off public AI tools.

### Does Article 22 stop us using AI in client work?

No. Articles 22A to 22D restrict only significant decisions taken with no meaningful human involvement, where a legal effect or a similarly significant effect follows for the person. Drafting, summarising and extraction with a person checking the output sit outside that restriction, and the other UK GDPR duties still apply.

### Should clients see the AI policy?

PCRT suggests clients can be directed to a data handling or AI usage policy on the firm's website, and that the engagement letter states that AI-enabled software may be used in providing services. Whether the full policy goes on the website or on request is the firm's decision.

### How often must the policy be reviewed?

The law gives no fixed period. Article 24(1) says the measures behind compliance are reviewed and updated where necessary, so the template sets the firm's own review date and requires a check whenever a tool, a service line or the law changes.

## Sources

1. [UK GDPR Article 5: principles, including accountability](https://www.legislation.gov.uk/eur/2016/679/article/5)
2. [UK GDPR Article 22A: automated processing and significant decisions](https://www.legislation.gov.uk/eur/2016/679/article/22A)
3. [UK GDPR Article 22B: restrictions on automated decision-making](https://www.legislation.gov.uk/eur/2016/679/article/22B)
4. [UK GDPR Article 22C: safeguards for automated decision-making](https://www.legislation.gov.uk/eur/2016/679/article/22C)
5. [UK GDPR Article 4: definitions, including controller](https://www.legislation.gov.uk/eur/2016/679/article/4)
6. [UK GDPR Article 6: lawfulness of processing](https://www.legislation.gov.uk/eur/2016/679/article/6)
7. [UK GDPR Article 28: processor](https://www.legislation.gov.uk/eur/2016/679/article/28)
8. [Data (Use and Access) Act 2025, section 118: abolition of the office of Information Commissioner](https://www.legislation.gov.uk/ukpga/2025/18/section/118)
9. [ICO, Explaining decisions made with AI: legal framework](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/explaining-decisions-made-with-artificial-intelligence/part-1-the-basics-of-explaining-ai/legal-framework/)
10. [UK GDPR Article 24: responsibility of the controller](https://www.legislation.gov.uk/eur/2016/679/article/24)
11. [UK GDPR Article 30: records of processing activities](https://www.legislation.gov.uk/eur/2016/679/article/30)
12. [UK GDPR Article 35: data protection impact assessment](https://www.legislation.gov.uk/eur/2016/679/article/35)
13. [ICO, Guidance on AI and data protection: about this guidance](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/about-this-guidance/)
14. [ICO, Explaining decisions made with AI: policies and procedures](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/explaining-decisions-made-with-artificial-intelligence/part-3-what-explaining-ai-means-for-your-organisation/policies-and-procedures/)
15. [ICO, Guidance on AI and data protection: accountability and governance implications of AI](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/what-are-the-accountability-and-governance-implications-of-ai/)
16. [ICAEW, Dos and don'ts of using AI](https://www.icaew.com/technical/technology/artificial-intelligence/generative-ai-guide/dos-and-donts)
17. [ICAEW, Generative AI and ethics](https://www.icaew.com/technical/technology/artificial-intelligence/generative-ai-guide/ethics)
18. [PCRT bodies, Topical guidance: ethical use of artificial intelligence tools (19 January 2026)](https://assets-eu-01.kc-usercontent.com/220a4c02-94bf-019b-9bac-51cdc7bf0d99/7b1b2fa2-794f-42d7-949d-5d74bbf42217/PCRT%20_%20ethical%20use%20of%20artificial%20intelligence%20tools%20%E2%80%93%20Jan%202026.pdf)
19. [The seven PCRT bodies, Professional bodies issue AI advice to members (19 January 2026)](https://www.tax.org.uk/professional-bodies-issue-ai-advice-to-members)
20. [FRC, Innovative new guidance supports audit firm adoption of emerging AI technologies (30 March 2026)](https://www.frc.org.uk/news-and-events/news/2026/03/innovative-new-guidance-supports-audit-firm-adoption-of-emerging-ai-technologies)
21. [FCA, AI and the FCA: our approach](https://www.fca.org.uk/firms/innovation/ai-approach)
