Resources

AI-use policy template for UK practices

A working structure for a practice's own AI-use policy, built section by section from published UK professional and regulatory guidance. Change the wording; keep the duties it's built on.

An accountant signs a policy on Cast & Rule letterhead with a fountain pen, ring binders and a laptop on the desk.

About this template

A partner still needs to decide which tools are approved, who signs off what, and how the practice will check the policy is followed. Change the wording to fit your practice; the duties each section rests on are listed under Sources.

The template

1. Purpose and scope

This policy sets out how [practice name] staff may use AI tools in client work, and what must never be typed into one. It applies to every member of staff, every engagement, and every AI tool, whether formally approved, on trial, or found and used informally.

2. Confidentiality: what must never go into a public AI tool

Confidential client information must not be typed into a public AI tool. This includes client names, financial figures, tax positions, letters and emails, and any document that could identify a client, even when the request itself seems harmless. This follows directly from the ICAEW Code of Ethics 2026 (confidentiality, s.114) and ICAEW's own generative-AI guidance. That guidance says plainly that confidential firm or client information should not be loaded into public generative-AI tools, because once it's typed in you have little control over how it's shared, secured and kept.

3. Approved tools and registration

Staff may use only the AI tools on the practice's approved-tool list. A new tool goes on the list only after someone has checked what it does with the data it's given, whether it trains a model on that data, and where it processes and stores it. This mirrors ACCA's guidance that AI carries risk in what is typed in, in model training and in how outputs are passed on, and should be brought under the practice's rules rather than taken up informally.

4. Human review and partner sign-off before anything leaves the practice

No AI-assisted output (a draft, a calculation, a letter, a tax position) reaches a client or HMRC without a named person reviewing it first. That review must be real: enough information, skill and authority to challenge or change the result, not a quick click-through. This reflects PCRT's AI guidance, which says members and regulated firms stay responsible for AI-assisted work whatever tool was used, and the Data (Use and Access) Act 2025's test for meaningful human involvement in a significant decision.

5. Records, evidence and the audit trail

Where AI is used in work covered by the Money Laundering Regulations 2017 or audit and assurance standards, the practice keeps the original source documents, the reviewer's decision and enough context to show how that decision was reached. An AI-written summary doesn't replace the original evidence. This reflects the record-keeping rule in MLR 2017 regulation 40, and ISA (UK) 230's rule that audit files must support the work done, the evidence obtained and the judgements reached.

6. Data protection and where data is processed

Where an AI tool processes personal data on the practice's behalf, a written contract covering its instructions, security, any suppliers it uses and deletion is needed before client data goes through it. A consumer click-through licence isn't enough. Any transfer of personal data outside the UK is checked against the current transfer rules. This reflects UK GDPR Article 28 and the ICO's guidance on processor contracts and international transfers.

7. Training and competence

Staff are trained, in proportion to the tool and their role, before they're expected to use an approved AI tool on their own. That means understanding what it can get wrong as much as what it can do. This reflects PCRT's competence rule, ACCA's point that professional scepticism and judgement can't be handed to technology, and the general direction of the EU AI Act's AI-literacy rules for staff where they apply to the practice's work.

8. Incident reporting and escalation

Anyone who realises confidential information has gone into a tool it shouldn't have, or that an AI-assisted output reached a client without review, reports it straight away to [named person], not after the event is tidied up. Early reporting is what makes a sensible response possible. For a firm covered by the ECCTA failure-to-prevent-fraud offence, it's also what makes a documented monitoring and review step possible.

9. Review of this policy

This policy is reviewed at least once a year, and sooner if a new AI tool is approved, a regulator issues new guidance, or an incident under section 8 shows the policy needs to change.

Download the template

Free to download and adapt, with no sign-up.

  • AI-use policy template (editable)

    The nine-section policy with its sources, as plain text you can open in any word processor and edit.

    Markdown text · ai-use-policy-template.md

Update notices

Update notices for this template

We use your details only to answer you. The downloads above need no sign-up.

Questions partners ask

Frequently asked questions

Do I need a lawyer to use this?

Not always, but a practice with unusual client work, clients abroad or audit engagements should have its final policy checked by someone qualified to advise on it.

Will this template be kept up to date?

Yes. When the guidance it's built on changes in a way that matters, we update the template.

One practice first

Start with one workflow, over six weeks, with us alongside

For a UK practice of 5 to 20 staff, with a partner who'll own the review. We run one workflow, measure it before and after, and agree in writing how it ends. Send an enquiry or email us today.

Contact us