← AI controls for tax & accounting firms

AI vendor risk assessment for CPA firms

Use these questions before approving an AI product that may touch firm or client information. The point is not to produce a perfect score; it is to document what you know, what you do not know, and who accepted the residual risk.

Data and model use

  1. What data types will users realistically submit?
  2. Is customer content used to train or improve models?
  3. Can training use be disabled contractually or administratively?
  4. How long are prompts, files and outputs retained?
  5. Can the firm delete stored content and accounts on demand?

Access and security

  1. Does the product support SSO, MFA and role-based access?
  2. Are audit logs available?
  3. What encryption and security attestations are disclosed?
  4. Which subprocessors or model providers handle data?
  5. How are security incidents communicated?

Operational governance

  1. Can administrators restrict risky features or integrations?
  2. Can the firm define approved workspaces rather than personal accounts?
  3. Are model/version changes announced?
  4. Are citations or source links available when the use case requires verification?
  5. Can usage evidence be exported for review?

Commercial and exit risk

  1. Who owns inputs and outputs?
  2. Can terms materially change without notice?
  3. Can data be exported in a usable form?
  4. What happens to retained data after termination?
  5. Is there a practical alternative if the vendor becomes unsuitable?

Use the structured vendor-review workbook →

Operational checklist only; not legal, cybersecurity, privacy or compliance advice.