# AI-use policy template for UK practices

> Check it against your practice's own facts and the cited sources before you use it, with a qualified adviser where the work needs one.

From Cast & Rule: https://www.castandrule.co.uk/resources/ai-use-policy-template

A partner still needs to decide which tools are approved, who signs off what, and how the practice will check the policy is followed. Change the wording to fit your practice; the duties each section rests on are listed under Sources.

## 1. Purpose and scope

This policy sets out how [practice name] staff may use AI tools in client work, and what must never be typed into one. It applies to every member of staff, every engagement, and every AI tool, whether formally approved, on trial, or found and used informally.

## 2. Confidentiality: what must never go into a public AI tool

Confidential client information must not be typed into a public AI tool. This includes client names, financial figures, tax positions, letters and emails, and any document that could identify a client, even when the request itself seems harmless. This follows directly from the ICAEW Code of Ethics 2026 (confidentiality, s.114) and ICAEW's own generative-AI guidance. That guidance says plainly that confidential firm or client information should not be loaded into public generative-AI tools, because once it's typed in you have little control over how it's shared, secured and kept.

Sources: ICAEW, Code of Ethics 2026 (https://www.icaew.com/-/media/corporate/files/technical/ethics/code-of-ethics/icaew-code-of-ethics-2026.ashx, accessed 27 September 2026); ICAEW, Generative AI and ethics (https://www.icaew.com/technical/technology/artificial-intelligence/generative-ai-guide/ethics, accessed 27 September 2026)

## 3. Approved tools and registration

Staff may use only the AI tools on the practice's approved-tool list. A new tool goes on the list only after someone has checked what it does with the data it's given, whether it trains a model on that data, and where it processes and stores it. This mirrors ACCA's guidance that AI carries risk in what is typed in, in model training and in how outputs are passed on, and should be brought under the practice's rules rather than taken up informally.

Sources: ACCA, Key areas of risk when adopting AI (https://www.accaglobal.com/gb/en/technical-activities/technical-resources-search/2026/March/Key-areas-of-risk-when-adopting-AI.html, accessed 27 September 2026)

## 4. Human review and partner sign-off before anything leaves the practice

No AI-assisted output (a draft, a calculation, a letter, a tax position) reaches a client or HMRC without a named person reviewing it first. That review must be real: enough information, skill and authority to challenge or change the result, not a quick click-through. This reflects PCRT's AI guidance, which says members and regulated firms stay responsible for AI-assisted work whatever tool was used, and the Data (Use and Access) Act 2025's test for meaningful human involvement in a significant decision.

Sources: ICAEW / PCRT bodies, Topical guidance: application of PCRT to ethical use of AI tools (https://www.icaew.com/technical/tax/working-in-tax/pcrt/topical-guidance-application-of-pcrt-to-ethical-use-of-artificial-intelligence-tools, accessed 27 September 2026); ICO, The Data (Use and Access) Act 2025: what does it mean for organisations? (https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/the-data-use-and-access-act-2025-what-does-it-mean-for-organisations/, accessed 27 September 2026)

## 5. Records, evidence and the audit trail

Where AI is used in work covered by the Money Laundering Regulations 2017 or audit and assurance standards, the practice keeps the original source documents, the reviewer's decision and enough context to show how that decision was reached. An AI-written summary doesn't replace the original evidence. This reflects the record-keeping rule in MLR 2017 regulation 40, and ISA (UK) 230's rule that audit files must support the work done, the evidence obtained and the judgements reached.

Sources: Money Laundering Regulations 2017, regulation 40 (https://www.legislation.gov.uk/uksi/2017/692/2017-11-28?view=plain+extent, accessed 27 September 2026); FRC, ISQM (UK) 1 and related UK auditing standards (https://media.frc.org.uk/documents/ISQM_UK_1_Issued_July_2021_Updated_September_2025.pdf, accessed 27 September 2026)

## 6. Data protection and where data is processed

Where an AI tool processes personal data on the practice's behalf, a written contract covering its instructions, security, any suppliers it uses and deletion is needed before client data goes through it. A consumer click-through licence isn't enough. Any transfer of personal data outside the UK is checked against the current transfer rules. This reflects UK GDPR Article 28 and the ICO's guidance on processor contracts and international transfers.

Sources: ICO, Contracts and liabilities between controllers and processors (https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/contracts-and-liabilities-between-controllers-and-processors-multi/what-needs-to-be-included-in-the-contract/, accessed 27 September 2026); ICO, A guide to international transfers (https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/a-guide-to-international-transfers/, accessed 27 September 2026)

## 7. Training and competence

Staff are trained, in proportion to the tool and their role, before they're expected to use an approved AI tool on their own. That means understanding what it can get wrong as much as what it can do. This reflects PCRT's competence rule, ACCA's point that professional scepticism and judgement can't be handed to technology, and the general direction of the EU AI Act's AI-literacy rules for staff where they apply to the practice's work.

Sources: ICAEW / PCRT bodies, Topical guidance: application of PCRT to ethical use of AI tools (https://www.icaew.com/technical/tax/working-in-tax/pcrt/topical-guidance-application-of-pcrt-to-ethical-use-of-artificial-intelligence-tools, accessed 27 September 2026); ACCA, Key areas of risk when adopting AI (https://www.accaglobal.com/gb/en/technical-activities/technical-resources-search/2026/March/Key-areas-of-risk-when-adopting-AI.html, accessed 27 September 2026)

## 8. Incident reporting and escalation

Anyone who realises confidential information has gone into a tool it shouldn't have, or that an AI-assisted output reached a client without review, reports it straight away to [named person], not after the event is tidied up. Early reporting is what makes a sensible response possible. For a firm covered by the ECCTA failure-to-prevent-fraud offence, it's also what makes a documented monitoring and review step possible.

## 9. Review of this policy

This policy is reviewed at least once a year, and sooner if a new AI tool is approved, a regulator issues new guidance, or an incident under section 8 shows the policy needs to change.

## Sources

- ICAEW, Code of Ethics 2026: https://www.icaew.com/-/media/corporate/files/technical/ethics/code-of-ethics/icaew-code-of-ethics-2026.ashx (accessed 27 September 2026)
- ICAEW, Generative AI and ethics: https://www.icaew.com/technical/technology/artificial-intelligence/generative-ai-guide/ethics (accessed 27 September 2026)
- ACCA, Key areas of risk when adopting AI: https://www.accaglobal.com/gb/en/technical-activities/technical-resources-search/2026/March/Key-areas-of-risk-when-adopting-AI.html (accessed 27 September 2026)
- ICAEW / PCRT bodies, Topical guidance: application of PCRT to ethical use of AI tools: https://www.icaew.com/technical/tax/working-in-tax/pcrt/topical-guidance-application-of-pcrt-to-ethical-use-of-artificial-intelligence-tools (accessed 27 September 2026)
- ICO, The Data (Use and Access) Act 2025: what does it mean for organisations?: https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/the-data-use-and-access-act-2025-what-does-it-mean-for-organisations/ (accessed 27 September 2026)
- Money Laundering Regulations 2017, regulation 40: https://www.legislation.gov.uk/uksi/2017/692/2017-11-28?view=plain+extent (accessed 27 September 2026)
- FRC, ISQM (UK) 1 and related UK auditing standards: https://media.frc.org.uk/documents/ISQM_UK_1_Issued_July_2021_Updated_September_2025.pdf (accessed 27 September 2026)
- ICO, Contracts and liabilities between controllers and processors: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/contracts-and-liabilities-between-controllers-and-processors-multi/what-needs-to-be-included-in-the-contract/ (accessed 27 September 2026)
- ICO, A guide to international transfers: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/a-guide-to-international-transfers/ (accessed 27 September 2026)

Check each section against your practice's own facts, and against the sources below, before adopting it. Audit, EU-facing or unusual client work needs a specialist review of its own.
