A Tuesday morning in November. A promising new client sends over its supplier questionnaire. Question 14: "Describe your governance of artificial intelligence. Do you hold ISO/IEC 42001?" Question 15: "Are you Cyber Essentials certified?"
You read both twice and put the kettle on.
The honest answer to Question 14 is rarely a badge. It's a clear description of what you actually do.
What clients and insurers may ask about
Voluntary standards and frameworks
- ISO/IEC 42001:2023 is the AI management-system standard for organisations that build or use AI. It sits alongside ISO/IEC 23894 (AI risk guidance) and ISO/IEC 42005:2025 (AI impact assessment). It's voluntary, unless a contract requires it.
- ISO/IEC 27001:2022 is the information-security standard. The deadline to move accredited certificates off the 2013 version was 31 October 2025. That was a certification deadline, not a legal duty to certify.
- Cyber Essentials is voluntary unless a contract or client makes it mandatory. The NCSC's December 2025 supply-chain playbook recommends it as a supplier baseline. Expect your clients to expect the same of you. Expect to ask the same of your AI providers.
- The NIST AI RMF helps you show you manage AI sensibly, but it isn't a safe harbour. The Government's AI Management Essentials tool was withdrawn before publication in February 2026. DSIT said it aims to focus future guidance for SMEs on basic AI governance. None had been published by 27 September 2026.
EU law that may reach you through clients
NIS2 (an EU directive) and DORA (an EU regulation) are law. But they apply to in-scope EU entities, not an ordinary UK practice. If you work for an in-scope client, they may pass on their security and due-diligence requirements to you by contract.
Insurance
We couldn't find a published, market-wide insurer rule on AI exclusions, disclosure or cover. So read your own policy wording and proposal answers with your broker. Don't just assume.
Four things, asked four different ways
Across all of these, the regulators are asking for broadly the same four things.
- Keep client data under your control.
- Match human oversight to the task and its risk. A competent person, with authority to change the result, reviews what matters before it leaves.
- Keep a record that lets someone reconstruct what happened. Keep it for as long as the rules require, and no longer.
- Have a policy people actually follow.
No rule says a partner has to approve every output. For audit work, the FRC's guidance supports documentation and human review in proportion to the risk. The Data (Use and Access) Act allows some solely automated decisions, with safeguards. But for client work that carries your firm's name, a named reviewer is the prudent default. It's the default Cast & Rule is built around.
AI does the casting: it adds up the figures. A named partner does the ruling: they sign it off.
Read as a table
| Part, in order | What it does |
|---|---|
| Sources | Reads the client's records |
| Strongroom | Keeps each client's records apart |
| Workpapers | Drafts the work |
| Ruling | A named partner decides |
| The Ledger: what the ai did, recorded from every part | Records every step |
How the obligations map to Cast & Rule
Cast & Rule processes client content on hardware your practice controls. Nothing goes to a client or HMRC without a partner's ruling. The Ledger records what the AI did, with each entry linked to the previous one (hash-chained), so it reveals changes to records already checked by our service. The security overview gives the status of each control.
| Obligation | What you need to be able to show | Cast & Rule |
|---|---|---|
| ICAEW s.114, ACCA, PCRT confidentiality; ICAEW GenAI guidance | Client data isn't going into public tools | Local processing on local hardware the practice controls; the Strongroom: encrypted per-client compartments. A no-cloud report shows what left the machine, and anything allowed to leave is encrypted first |
| UK GDPR Article 28, transfers, NCSC supply chain | Who processes the data, where it goes | Sub-processor list and data-flow diagram |
| DUAA meaningful human involvement; PCRT responsibility; FRC audit guidance on proportionate review | A competent person, with authority to change the result, reviews what matters | Ruling: the partner sign-off queue, with client, period, preparer, exceptions and evidence alongside |
| MLR regulation 40; ISA (UK) 230; ICO accountability | You can reconstruct what happened, and when | The Ledger: a record of every AI action. Each entry is locked to the one before it (hash-chained), so a change to an already-checked entry shows up |
| PCRT review of output; ICO accuracy; FRC audit source testing | Output traces back to the client's own records | Sources (Xero, Microsoft 365, Companies House, HMRC) feeding Workpapers, read-only, one client per connection |
| AI-use policy; ECCTA and Criminal Finances Act reasonable procedures; EU AI literacy | A policy people actually follow | Rules: the firm's AI-use policy as task permissions; tasks run only from signed definitions, and documents cannot grant permissions |
| MTD records; HMRC agent standard | A reviewed route from record to submission | Schedules (per-client MTD tracker) and Workpapers, then Ruling |
Five things to do this quarter
None of them needs a purchase. If you only have time for one, start with the first.
- Write (or rewrite) your AI-use policy. Base it on ICAEW Code section 114, ICAEW's generative AI guidance and the PCRT AI guidance. Say which tools are approved. Say what may never go into them, including anything touching a suspicious activity report. Say who reviews output. Say how exceptions are escalated. Keep it short enough that people actually read it.
- Find out what's already in use. Ask your team which tools they use, and why. Do this without blame. Then build a register of approved tools.
29%
had a formal AI policy at all
ICAEW Practice Assurance Monitoring Report 2025
20%
monitored staff access to AI tools
ICAEW Practice Assurance Monitoring Report 2025
Among the larger firms ICAEW held AI discussions with during its 2024 monitoring. ICAEW does not publish the size of this subgroup. These figures do not represent the whole sector.
- Read the terms of every AI tool that touches client data. Check five things. Is the provider your processor? Where does the data go? Does it train a model on it? How long is the data kept? Who are the sub-processors? Put an Article 28 contract in place where you need one. Run a DPIA where the risk is high.
- Define what "reviewed" means in your firm. Decide which work needs a named reviewer, based on its risk. Give that person the source material, and the authority to change the result. Keep the sources, the output and the decision. That one habit serves DUAA, PCRT, MLR and, for audit firms, ISA 230.
- Put the dates in the diary. Check your tax adviser registration position. List the clients whose 2025–26 qualifying income is over £30,000. They'll normally enter MTD in April 2027, subject to exemptions. Add AI-assisted tax work to your Criminal Finances Act risk assessment. Ask your broker how your PI policy treats AI-assisted work. The full timeline is in Part 2.
Do these five things and you can answer Question 14 in plain English, with evidence to back it up.
Start with the policy
For a head start on step one, get our AI-use policy template. It's written against ICAEW Code section 114 and ICAEW's generative AI guidance. It's free to read and download. Have it reviewed professionally before you use it.
If you'd like to go further, pilot enquiries open at launch. The pilot covers one workflow: either an MTD quarterly review for a group of clients, or a management pack. It runs for six weeks, at one UK practice of 5 to 20 staff. It's supervised and measured before and after, including the reviewer's time. It comes with a written exit.
