Ops Control HQ · CPA / Tax Firm Controls

Govern the AI your firm is already using.

Not another generic policy template. This resource focuses on the operating evidence a tax or accounting firm can actually maintain: which tools are approved, what client data may enter them, how vendors are reviewed, who verifies AI-assisted work, and how exceptions are documented.

See the $49 control system →
Why this matters now: The IRS reiterated in August 2026 that tax and accounting professionals must create and maintain a Written Information Security Plan to protect client information. That does not mean a separate “AI WISP addendum” is legally required by name. It does mean new AI tools, vendors and data flows should be evaluated against the firm’s existing security and professional-responsibility controls.

AI + WISP addendum checklist

Questions to connect AI tool use to existing security-plan ownership, service-provider oversight, data handling and incident procedures.

Open checklist →

AI vendor risk review for CPA firms

A practical review covering training use, retention, access, subprocessors, security, deletion, exportability and contract-change risk.

Review vendor questions →

Human verification for AI-assisted tax work

A lightweight control for citations, calculations, factual assertions and client-facing conclusions before release.

Open verification checklist →

What the paid pack adds

The AI Governance Control Pack combines an AI inventory, use-case approval gate, vendor review, risk register and executive review into one Excel-based operating system. It is designed for operational readiness and documentation—not legal advice, a compliance certification, or a substitute for counsel, professional standards, cybersecurity controls or a firm-specific WISP.

View the $49 CPA-focused offer →

Primary and professional sources

IRS — Aug. 18, 2026 WISP reminder
IRS — WISP essentials
Journal of Accountancy — responsible AI use in tax practice