← AI controls for tax & accounting firms
AI vendor risk assessment for CPA firms
Use these questions before approving an AI product that may touch firm or client information. The point is not to produce a perfect score; it is to document what you know, what you do not know, and who accepted the residual risk.
Data and model use
- What data types will users realistically submit?
- Is customer content used to train or improve models?
- Can training use be disabled contractually or administratively?
- How long are prompts, files and outputs retained?
- Can the firm delete stored content and accounts on demand?
Access and security
- Does the product support SSO, MFA and role-based access?
- Are audit logs available?
- What encryption and security attestations are disclosed?
- Which subprocessors or model providers handle data?
- How are security incidents communicated?
Operational governance
- Can administrators restrict risky features or integrations?
- Can the firm define approved workspaces rather than personal accounts?
- Are model/version changes announced?
- Are citations or source links available when the use case requires verification?
- Can usage evidence be exported for review?
Commercial and exit risk
- Who owns inputs and outputs?
- Can terms materially change without notice?
- Can data be exported in a usable form?
- What happens to retained data after termination?
- Is there a practical alternative if the vendor becomes unsuitable?
Use the structured vendor-review workbook →
Operational checklist only; not legal, cybersecurity, privacy or compliance advice.