Before we start

You already have an AI policy. Right now it's "whatever each person decides on the day." The only real question is whether you've written down a better one.

THIS WEEK RECONCILED

A written policy makes you faster, not slower

Most firms think an AI policy is the brake. It's the opposite. It's the thing that lets you put your foot down.

I resisted writing one for months. It felt like bureaucracy — we're a small practice, not a Big Four risk committee. Then I noticed what was actually happening without one. One person wouldn't touch AI at all, frightened of doing something wrong. Another was pasting who-knows-what into a free ChatGPT account. Both were guessing, because nobody had said what "allowed" looked like. That's not caution. It's just risk with no map.

The fix took an afternoon and fits on one page — the Reconciled AI Policy. Three things: which tools we've approved, what client data may go into them, and who checks AI-assisted work before it goes out. No jargon, no manual nobody reads.

The effect wasn't caution — it was speed. Once the team knew the rules, the nervous ones started using AI, because they finally knew they wouldn't get it wrong. The gung-ho ones dropped the risky habits, because "no client data in free tools" was now written down instead of folklore. A one-page policy is permission with edges. Everyone moves faster when they can see the edges.

The bit I'd genuinely lose sleep over if we hadn't sorted it: free consumer tools and client data. Paste a client's information into a free ChatGPT or Gemini account and that data can be used to train the model. You are the data controller. Under UK GDPR that can be a breach — and "I didn't realise the free version was different" is not a line anyone wants to give the ICO. Business-tier tools — Claude Team or Enterprise, Copilot in M365, ChatGPT Teams — contract that away. On client data, the tier isn't a nice-to-have. It's the whole game.

There's a second document most firms have forgotten, too: your engagement letter. If AI now touches client work, your letter should say so — disclosure, human review, data handling, where liability sits. Clients are starting to ask. Better your letter answers the question before they do.

None of this slows you down. It's the paperwork that lets you say yes.

RECONCILED IN PRACTICE
Write the one page this week

Don't overthink it. One page, three sections — here's the whole skeleton:

1. Approved tools

The specific tools we permit, and the tier — e.g. Claude Team/Enterprise, Copilot in M365. Anything not on the list isn't approved for client work.

2. Permitted data

What client data may go into which tools. Default: no client personal or identifying data into any free/consumer tool, ever.

3. Who reviews

The named human-review step before AI-assisted work is filed, sent or advised on — and who owns that sign-off.

Fill those three boxes honestly and you have a policy that's actually better than 95% of what's out there — because it's one page, and people will read it.

Rich's Take

The firm with a written policy adopts AI faster, not slower — because everyone already knows the rules. Uncertainty is what kills adoption. Clear boundaries are the cheapest growth lever you'll find this year.

Richard Allen

YOUR QUESTIONS RECONCILED
"Do we need to tell clients — and put it in our engagement letter — that we use AI?"

It's fast becoming the expectation, and it protects you either way. A short, plain-English clause covering four things — that you may use AI tools, that a qualified human reviews the output, how client data is handled, and where responsibility sits — heads off the awkward question and shows you've thought about it. Draft your own version, then have it checked against your professional body's template or by your solicitor before it goes live. Don't lift a clause off the internet and hope.

Careful with the liability line: where responsibility actually sits when AI-assisted work goes wrong is its own subject — and it's exactly where we finish this run next week.

PROMPTS RECONCILED
Draft both documents in one go

Give AI the first draft, then make it yours and get it reviewed:

Draft a one-page AI policy for a UK accountancy practice, covering: approved tools and their tier, what client data is permitted in each, the human-review step, and who owns sign-off. Plain English, no jargon. Then draft a short plain-English engagement-letter clause covering AI disclosure to clients, human review, data handling, and where liability sits.

It'll get you a strong skeleton in seconds. The judgement — which tools, which data, who signs — is yours to set, and the wording is yours to have checked.

This week

Draft your one-page AI policy — approved tools, permitted data, who reviews. Then hit reply and let us know how you got on, and tell us the one line you found hardest to pin down. That's usually the important one.

Next week in Reconciled

We close Safe Hands with the question your new policy raises: when AI gets a number wrong and it slips through, who actually carries the can — you, your PI insurer, or nobody?

— Aaron, Loz & Rich

Reconciled

Helping accountants build faster, smarter, more profitable firms.

Aaron Burton ACCA CTA · Laurence Maynard ACCA · Richard Allen, entrepreneur

If this was useful, forward it to one person who'd find it valuable.

Reconciled is for informational purposes only. Nothing here constitutes professional accounting, tax, or legal advice. Always apply your own professional judgement before acting on anything published here.