Skip to main content
article

Governed or ungoverned: the real AI choice facing CA firms

PASDACS Team7 min read

In conversations about AI, firms often frame the decision as adopt or wait. That framing is already out of date. In most practices, staff are using consumer AI tools today - for drafting, for summarising, occasionally with client material in the prompt. The real choice is not whether AI is in the practice. It is whether it operates under the firm's governance or around it.

Why “wait” is the riskiest option

A firm that has not provided a governed alternative has not avoided AI risk; it has outsourced its AI policy to whichever tool each employee prefers. Client confidentiality then depends on individual judgement about what is safe to paste into a public tool - a standard no firm would accept for physical files. The uncomfortable conclusion: doing nothing is the permissive option.

What governed looks like

A governed deployment differs from consumer usage on five specifics:

  • Approved sources only. The assistant indexes the firm's SOPs, templates, precedents, circulars and internal guidance - nothing else. It answers from the firm's knowledge, not the open internet's confidence.
  • Role-based access. Engagement teams see only their own client material. The partner's boundary questions - who can see what - are answered by the access model, not by trust.
  • Source-linked answers. Every draft cites the document and section it came from, so review means checking a reference, not fact-checking a black box.
  • Audit logging. Every query and retrieval is recorded. When someone asks “has client data been put into AI?”, the firm has a log, not a hope.
  • A data boundary. The environment is approved, and client data never trains a public model.

The line that does not move

One rule sits above the architecture: the assistant produces assistance and first drafts - it never produces a professional opinion. Anything that becomes advice, a filing or a client communication is approved by a qualified person. This is not a limitation to apologise for; it is the design principle that makes the rest acceptable. Technology adoption should strengthen professional responsibility, never weaken it.

Where to start if the firm is uneasy

Governance can precede any assistant. An AI acceptable-use policy, an access model and a data-handling standard are a complete, standalone piece of work - no assistant, no client data, just the guardrails. Firms that start there make the eventual deployment decision from a position of control rather than anxiety. And if the answer is still “not yet”, the policy alone has closed the ungoverned gap that existed before.

The firms that navigate this well will not be the ones that adopted fastest or resisted longest. They will be the ones that made the choice deliberately, wrote the rules down, and could evidence both.

Share this insight

Keep reading

Related insights

article

Choosing practice software without the regret

The demo was impressive, the discount was real, and a year later the team is back in spreadsheets. Most software regret is decided before the purchase. Here is the sequence that prevents it.

29 July 2026 · 6 min read

article

Automating GST reconciliation without losing control

Reconciliation absorbs experienced hours every single month, but a CA firm cannot hand tax positions to a machine. The answer is a control boundary, drawn before the first rule is written.

8 July 2026 · 7 min read

Want to talk this through?

If this piece raises questions about your own operations, our team is happy to discuss what it could mean in practice.