Ethics, Professional Standards, and AI Governance in Accounting
Deliberate Academy Editorial Team
Reviewed for accuracy and professional relevance
You're 9 lessons in — don't lose your progress.
Sign up free to save where you are and earn a verified certificate when you pass.
- Identify the professional code obligations under ICAEW, ACCA, and AICPA that directly govern AI use in accounting practice
- Assess which AI tools are safe for use with client data given GDPR obligations and the data handling arrangements of common platforms
- Explain the duty to explain obligation as it applies to AI-assisted professional advice and describe what documentation in an engagement file must include
- Build a practice-level AI governance policy that satisfies the core regulatory requirements applicable to an accounting firm in 2026
Every practising accountant using AI tools in their work is already operating within a governance framework. The ICAEW Code of Ethics, the ACCA Code of Ethics and Conduct, and the AICPA Code of Professional Conduct all contain obligations that apply directly to AI-assisted practice, even though those codes were written before the current generation of AI tools existed. Understanding which obligations apply, and how to satisfy them in practice, is not optional for any professional who takes their qualification and liability seriously.
The Professional Code Obligations That Apply to AI Use
Competence is the most directly applicable obligation across all three codes. The ICAEW's fundamental principles require that members "maintain professional knowledge and skill at the level required to ensure that a client or employer receives competent professional service." Using a tool you do not understand to a sufficient level to supervise its output and catch its errors is not competent service. This obligation was discussed in Lesson 1 in the context of categorisation review, but it applies across every AI application: audit workpapers, tax research, client correspondence, and data analysis all require the practitioner to be able to evaluate the AI output professionally, not simply to forward it.
The ACCA's fundamental principles contain an equivalent competence obligation: members must "attain and maintain professional knowledge and skill at the level required to ensure that a client or employer receives competent professional service." The AICPA's standards contain the General Standards requirement that practitioners "undertake only those professional services that they have reasonable expectation of completing with professional competence."
Integrity is the second applicable obligation. ICAEW, ACCA, and AICPA all require that professional work is honest and straightforward. Where AI has materially contributed to professional advice, advice, or a working paper, representing that work as the product of the practitioner's own independent analysis and judgment without acknowledging the AI contribution is a question of professional integrity. This does not mean every use of AI requires explicit disclosure to clients, but it does mean practitioners must be honest with themselves about the basis of their work and must not overstate the depth of their own independent analysis when AI has done the substantive first pass. For AICPA members and CPAs, this integrity obligation is codified in the AICPA Code of Professional Conduct's Integrity and Objectivity Rule, which requires a member to be free of conflicts of interest and to not knowingly misrepresent facts — a standard that extends naturally to being honest about the actual basis of a piece of professional work, including how much of it an AI tool produced.
Professional behaviour requires that members "comply with relevant laws and regulations and avoid any action that discredits the profession." Using AI tools that handle client data in ways that breach GDPR is a violation of this principle. Using AI output in circumstances where professional standards require independent judgment is a violation of this principle. Deploying AI tools whose outputs cannot be adequately supervised given the practitioner's competence level is a violation of this principle.
Check your professional indemnity policy before using any AI tool with client data. Some PI providers have updated their terms since 2025 to include AI usage disclosure requirements or to limit coverage in circumstances where AI tools were used without adequate oversight documentation. Using a tool that puts your PI coverage at risk is a material governance failure, not just a technical compliance issue.
Client Data Confidentiality and AI Tool Safety
The GDPR and the Data Protection Act 2018 impose specific obligations on accountants who process client personal data. When that processing involves submitting data to a third-party AI platform, the accounting firm is acting as a data controller and the AI platform is acting as a data processor. The firm's GDPR obligations include ensuring that the processor arrangements satisfy Article 28 requirements: a data processing agreement must be in place, the processor must provide sufficient guarantees of appropriate technical and organisational measures, and the firm must maintain records of the processing activity.
In practice, this means that before submitting any client personal data to an AI tool, the practitioner must verify: does the platform have a Data Processing Agreement available? Does the platform's terms of service specify that user data is not used to train the model? Where are the servers located? Are they within the UK and EU, or in third countries that require an adequacy decision or appropriate safeguards under GDPR Article 46?
For commonly used AI tools in 2026: Claude (Anthropic) and ChatGPT (OpenAI) both offer enterprise plans that include DPAs and data residency commitments, but the free and consumer plans do not offer the same guarantees. Microsoft Copilot accessed through a licensed Microsoft 365 enterprise subscription is covered by Microsoft's DPA. Free tools used through consumer-facing interfaces without a DPA in place are not appropriate for processing client personal data.
The safe working rule is that personally identifiable client data should not be submitted to any AI tool unless a DPA is in place and the data handling terms have been reviewed and confirmed as GDPR-compliant. For the vast majority of accounting AI use cases, it is possible to anonymise or pseudonymise the data sufficiently to allow AI processing without submitting personally identifiable information: describing a client as "a UK VAT-registered sole trader in the retail sector" rather than naming them, or providing a trial balance with client references removed rather than client names present.
The Duty to Explain
Professional accounting advice is not an anonymous output. It carries the practitioner's name, their qualification, and their professional liability. If AI materially contributed to the basis of advice, the practitioner must be able to explain the reasoning behind that advice in their own words, in sufficient depth to demonstrate that they independently understood and assessed the position, not merely forwarded an AI output.
This is not a theoretical obligation. An HMRC challenge to a tax position, a PI claim arising from incorrect advice, or a professional disciplinary inquiry will all require the practitioner to demonstrate that the advice given was the product of professional competence and judgment. "The AI said so" is not a professional defence. If the practitioner cannot explain the basis of the advice without referring back to the AI output, the advice was not adequately reviewed before being given.
The practical implication is that AI-assisted work should leave the practitioner more informed, not less. Using AI for research should produce a practitioner who understands the relevant framework better, not one who knows the AI said something without understanding what it said. Using AI for drafting should produce a practitioner who has reviewed and understood the technical content of the document, not one who signed off on an AI draft they did not fully understand.
Documenting AI Usage in an Engagement File
An engagement file that includes AI-assisted work should document: which tools were used, what data was submitted to those tools, what the AI output contributed, and what independent verification and professional review was applied before the output was relied upon.
This documentation standard serves two purposes. First, it creates an audit trail that demonstrates professional oversight if the work is ever challenged. Second, it creates internal accountability: when practitioners know their AI usage will be documented, the review standard they apply to AI output tends to rise.
A minimal documentation entry for AI-assisted work might read: "Initial lead schedule drafts for fixed assets, debtors, and creditors areas were prepared using Claude (enterprise plan, DPA in place). Drafts were reviewed against the trial balance and prior year file by [name]. All figures verified. Two structural corrections made to the debtors schedule to reflect the client's aged debtor categories. Final schedules are the reviewer's work product." This note demonstrates oversight, identifies the tool, confirms the data handling arrangements, and records what independent verification was performed.
For firms auditing US public companies, this documentation obligation has a specific statutory dimension that goes beyond good practice. The Sarbanes-Oxley Act of 2002 (Section 802) makes it a federal offense to knowingly destroy, alter, or falsify audit workpapers. The SEC's implementing rule under Section 802 (17 CFR 210.2-06) sets a seven-year retention period for records relevant to the audit or review, running from the conclusion of the audit or review.
The PCAOB's own auditing standard on this point, AS 1215 (Audit Documentation), layers additional, more detailed requirements on top of that statutory duty: a complete and final set of audit documentation must be assembled within 45 days of the report release date, after which the same seven-year retention clock applies. An AI-assisted audit workpaper that is not retained on the same basis as any other working paper, or whose preparation and review trail cannot be reconstructed after the fact, creates exposure under this framework that goes beyond ordinary professional negligence risk.
Small practice builds an AI usage policy after partner raises professional indemnity concern
Context
A three-partner practice had been using AI tools informally for approximately 18 months, with individual partners and staff using a mix of consumer-plan ChatGPT, Microsoft Copilot, and Claude for various drafting and research tasks. No formal policy governed which tools could be used for which purposes or what data handling requirements applied. In a partner meeting, the senior partner raised a concern after reading an updated PI renewal questionnaire that included questions about AI tool usage in client work.
Action
The practice manager was tasked with building an AI usage policy. The policy addressed four areas: approved tools (a short approved list with DPA status confirmed for each), permitted data categories (anonymised and pseudonymised data permitted freely; personally identifiable data only through enterprise-plan tools with DPA in place), review and documentation requirements (minimum documentation standard for any AI contribution to client work), and prohibited uses (HMRC enquiry correspondence, dispute letters, and audit sign-off material must not be AI-drafted without qualified principal review).
Outcome
The policy was implemented within four weeks. Three tools that had been used informally without DPA arrangements were removed from practice use for client data purposes. Staff training on the policy took approximately two hours. The PI renewal questionnaire was completed with documentation of the policy in place. The practice manager noted that the process of building the policy had also surfaced some informal AI usage patterns that had not been visible to partners, including one instance where a junior had been using a consumer AI tool to draft tax research summaries for client matters without any verification protocol.
An accountant uses a free consumer plan of a large language model to research a client's eligibility for a specific tax relief. The research involves describing the client's business activities in detail, including their industry, transaction types, and approximate revenue figures. Which GDPR obligation has most likely been breached?
Select one answer.
This lesson offers a practical test for whether AI-assisted advice has actually been reviewed to a professional standard. What is that test?
Select one answer.
Exercise
Your Task
Review the AI tools you currently use or are considering using in your practice or role. For each tool, answer the following questions: Is there a DPA available for this tool? If so, have you or your practice accepted it? Does the tool's terms of service specify that submitted data is not used for model training? Where are the servers located? Is this tool on your practice's approved list (or, if no list exists, should it be)? Then draft a one-page AI tool usage policy for your practice or team that addresses: approved tools, permitted data categories, review and documentation requirements, and prohibited uses. Use the policy described in the CaseStudy in this lesson as a structural guide.
Your reflection
Did you complete this exercise? What did you find? (Saved locally in your browser)
- ICAEW, ACCA, and AICPA all impose competence, integrity, and professional behaviour obligations that directly govern AI use: using tools you cannot adequately supervise, overstating the depth of your independent analysis, or breaching GDPR with client data are all code violations.
- Client personal data must not be submitted to AI tools without a Data Processing Agreement in place. Consumer-plan AI tools without DPAs are not appropriate for client data. Enterprise plans from Anthropic, OpenAI, and Microsoft with DPAs in place are safe for use within their stated data residency terms.
- The duty to explain obligation means practitioners must be able to explain the basis of AI-assisted advice in their own words. If the practitioner cannot explain the reasoning without referring back to the AI output, the advice was not adequately reviewed.
- AI usage should be documented in the engagement file: which tool was used, what data was submitted, what the AI contributed, and what independent verification was performed. This creates an audit trail and raises the internal review standard.
- For firms auditing US public companies, audit workpaper documentation is not just good practice but a statutory obligation: Sarbanes-Oxley Section 802 makes it a federal offense to destroy or falsify audit workpapers and imposes a retention requirement, on top of which PCAOB standards add further documentation detail — both apply to AI-assisted workpapers exactly as they apply to any other working paper.
- A practice AI policy should address four areas: approved tools with DPA status confirmed, permitted data categories, review and documentation requirements, and prohibited uses including HMRC enquiry correspondence and audit sign-off material.