Skip to content

Resource

What Accounting and Financial Firms Need to Know About AI Tools and Client Data

Staff at CPA and financial firms are already using AI to draft communications, summarize documents, and speed up research, often with client financial data included without a second thought. Under the FTC Safeguards Rule, that habit can turn a convenience into a real regulatory exposure.

The real pattern: convenience first, data handling second.

The most common exposure isn't a firm adopting an AI platform after review. It's an individual preparer or staff member pasting client financial details into a general-purpose AI tool to draft an email, summarize a return, or answer a client question faster. It feels like using a better search engine. Functionally, it's often sending regulated client financial data to a third party with no vendor agreement and no idea what happens to it afterward.

Industry guidance on AI use and client data in accounting firms

Where that data actually goes.

Many free and general-purpose AI tools' terms of service permit using submitted data to train or improve future models. Client financial data entered this way isn't just seen once, it may be retained indefinitely and incorporated into a system with no practical way to verify deletion. This is the same underlying problem covered elsewhere on client confidentiality and AI, applied specifically to financial data instead of legal or medical records. See AI Readiness & Governance.

What the FTC Safeguards Rule actually says about this.

The Safeguards Rule requires a written information security program covering vendor and service provider oversight, meaning any tool that touches client financial data, including an AI tool, is supposed to be reviewed and covered by an appropriate agreement before it's used, not adopted informally by whoever finds it convenient. An unreviewed AI tool touching client data is a vendor management failure under the Rule, not a gray area.

The penalties are real. FTC enforcement authority allows fines that commonly reach up to $100,000 per violation for the firm and up to $10,000 per violation for individual officers and directors personally, figures that adjust and vary by case, on top of consent decrees, mandatory breach notification, and potential civil suits from affected clients. A pattern of staff using ungoverned AI tools with client financial data is exactly the kind of documented gap that turns a routine audit into an enforcement action. See Governance, Risk & Compliance and our guide on what the FTC Safeguards Rule means for your business.

This isn't hypothetical, it's the same gap insurers and auditors already ask about.

Cyber insurance applications and client security questionnaires increasingly ask directly whether AI tool use is governed and reviewed. A firm that hasn't answered that question honestly, because nobody has actually looked, is carrying exposure it doesn't know about yet. See Cyber Insurance Readiness.

Common questions

Questions leadership usually asks first.

Next step

Get a clearer view of your IT environment.

Find out what is working, where the risks are, and what needs attention next.