Technology & Innovation

Client data and AI: A security guide for accountancy practices

Data security is the profession’s biggest AI barrier, cited by 62% of accountants in research. This guide turns that concern into a checklist you can work through in an afternoon.

Accountants working in an office observing security within AI
Published 10 min read

Key takeaways

  • Data security is the most cited AI implementation challenge in the profession, named by 62% of accountants in AccountingWEB’s research, produced in association with Sage.
  • Asked for their single biggest concern, accountants put accuracy and hallucinations first at 29%, with data security second at around 22%.
  • Around half of accountants using external AI tools use them to research tax rules, which carries a confidentiality risk and an accuracy risk at the same time.
  • A one-page data-handling policy that people actually follow protects you far better than a comprehensive one nobody reads.

Every practice holds information that people would rather not lose control of.

Payroll data, bank details, unfiled figures, disputes with HMRC, and plans that have not been announced yet… Accountancy and bookkeeping are more burdened with personally identifiable data than nearly any other profession.

So it is no surprise that data security tops the list of AI implementation challenges. In the AccountingWEB report State of the nation: AI in accountancy and bookkeeping, produced in association with Sage, 62% of respondents named it, putting it ahead of a lack of skilled personnel at 48%.

The encouraging part is that this is a procedural problem with a procedural answer.

Work through the checklist below and data security stops being the thing blocking your AI decision. It becomes the thing that makes your decision defensible.

Here’s what we discuss:

Why data security tops the list of AI barriers

At 62%, data security is the most frequently cited implementation challenge in the profession. It sits ahead of the skills shortage and ahead of cost.

There is a nuance worth noticing, though.

When the same research asked respondents for their single biggest concern about the rise of AI, a lack of accuracy and hallucinations came first at 29%, with data security second at around 22%.

Both findings are true and they measure different things. Security is the barrier accountants name when they think about implementation. Accuracy is the fear that keeps them up at night.

That distinction is useful, because the two risks have different remedies.

Accuracy is managed through review processes and human sign-off. Security is managed through tool selection, contracts, and daily habits.

This guide covers the second.

The underlying obligation has not changed. Your duty of confidentiality contains no technology exemption, and UK GDPR applies to personal data whether it sits in a filing cabinet or a chat window.

What accounting data should never enter a general LLM

Start with a clear prohibited list, written down and shared with everyone.

As a baseline, none of the following should be pasted into a general consumer AI tool:

  • Client names alongside any financial detail
  • National Insurance numbers, UTRs, bank details, and payroll records
  • Anything covered by legal professional privilege or a specific confidentiality undertaking
  • Unpublished results, valuations, or price-sensitive information
  • HMRC correspondence containing client identifiers
  • Anything you would hesitate to email to a third party you had never met

The habit that makes this workable is redaction before pasting.

Ask about the scenario rather than the client. A question on the VAT treatment of a mixed supply does not need your client’s name, turnover, or reference numbers to be answered well.

This matters more than it might seem, because of where external tools are actually being used.

In the research, around half of those using AI outside their core accounting software use it to research tax rules or other technical knowledge, and just under half use it to draft client emails and content.

Both of those uses invite people to paste in real client facts without thinking about it.

Premium and non-training settings, explained

Free consumer tiers commonly use your inputs to improve their models by default.

Paid business and enterprise tiers usually do not, and they typically add retention controls, data residency options, and administrator visibility.

Establish all of the following before anyone in your practice types anything sensitive:

  • Is the training exclusion contractual, or a toggle in settings that a user could switch back?
  • How long are inputs retained, and can you set that to zero or near zero?
  • Where is data processed and stored, and can you demand a specific region, e.g. EU vs US?
  • Is there a data processing agreement, and does it name every sub-processor?
  • Which underlying model providers sit beneath the tool, and what are their terms?
  • Are conversations subject to human review for safety or quality purposes?

Get those answers from the contract rather than the FAQ page.

A marketing page can be rewritten overnight without anyone telling you. A data processing agreement cannot.

Embedded versus external tools

Two routes into AI carry different risk profiles, and most practices end up using both.

Embedded AI lives inside software you already use and have already assessed. Client data stays within a system you have contracted for, and the supplier is one you have a relationship with.

The trade-off is narrower capability, since the features are built for defined accounting tasks. Around two-thirds of accountants believe their core software already includes AI of this kind.

External tools are general models and standalone products. The capability is broader and often better at open-ended work, but you are adding a new processor, a new data flow, and a new contract to your risk register.

A workable rule of thumb: use embedded tools for anything that touches client records, and reserve external tools for generic drafting, structuring, and thinking, with identifiers stripped before anything is pasted.

When a task genuinely needs an external tool and real client data, that is the moment for a proper procurement conversation rather than a personal subscription paid for on someone’s card.

Vetting a tool before sensitive information touches it

Here are a good set of questions to ask before trying-out the software, rather than after it.

  • Who is the legal entity behind the product, where is it based, and how long has it operated?
  • Is there a data processing agreement, and does it list sub-processors by name?
  • Are your inputs used for training, and will they confirm that in writing?
  • Where is data stored and processed, and is there a UK or EU option?
  • What are the retention and deletion policies, and can you export and delete everything on demand?
  • Do they hold SOC 2 Type II, ISO 27001, or Cyber Essentials Plus?
  • Does the product support single sign-on and role-based access?
  • What happens to your data if the company is acquired or ceases trading?
  • Has there been a security incident, and how was it disclosed?

Two further steps that practices routinely skip: Tell your professional indemnity insurer what you are planning, because some policies now ask about AI use at renewal. And check whether your engagement letters need a clause added before you begin rather than after.

Documenting your approach for clients and regulators

A written policy protects you twice.

It gives your team a clear line to work to, and it gives you something to show when a client, an insurer, or a professional body asks.

One page covers it. Here are some suggestions as to what you might include:

  • The list of approved tools, and the tier or settings each must be used on
  • The prohibited data list from earlier in this guide
  • Who can approve a new tool, and what evidence they need first
  • How often the list is reviewed, and by whom
  • What you tell clients, and where that appears
  • What happens if data goes somewhere it should not, and who is told within what timeframe

Keep it short enough that people read it. A one-page policy that is followed protects you considerably better than a fifteen-page policy sitting unread in a shared drive.

For clients, a short paragraph in your engagement letter and a page on your website will usually be enough.

Say what you use AI for, say what you do not use it for, say what happens to their data, and say that a qualified person reviews the work. Clients rarely want more detail than that. They want to know somebody is in charge.

Final thoughts

Data security is the most cited barrier to AI in the profession, and it has earned that position. It is also the barrier most amenable to being solved by an afternoon of deliberate work.

The practices that get this right do not have better technology than everyone else. They have a written list of what may go where, a habit of stripping identifiers before pasting, and one person whose job it is to approve new tools. None of that requires budget or specialist expertise.

Here is the takeaway: Decide your prohibited data list this week and circulate it. Move anything touching client records onto embedded tools inside software you have already assessed. Get training exclusions in the contract rather than the settings menu. Write one page describing your approach, and put a short version in front of clients before they think to ask.

Do that, and the 62% barrier turns into a competitive position.

Very few practices can currently answer a client who asks what happens to their data. You can be one of them.

Read below—State of the nation: AI in accountancy and bookkeeping, produced by AccountingWEB in association with Sage

Frequently asked questions

Can accountants use AI chatbots to discuss client data and issues?

Not with identifiable client data on a standard consumer tier, where inputs may be used for model training by default. Client names alongside financial detail, National Insurance numbers, UTRs, bank details, and payroll records should not be entered. Accountants can use general AI tools safely for generic technical questions and drafting, provided identifying details are stripped out first. For work involving real client records, use AI embedded in accounting software you have already assessed, or a paid business tier with contractual training exclusions and a data processing agreement in place.

What is the biggest data security risk when accountants use AI?

The most common risk is not a breach at the AI provider. It is staff pasting identifiable client information into free consumer tools during ordinary work, particularly when researching tax rules or drafting client emails, which research shows are the two most common uses of external AI tools in practice. The remedy is a written prohibited data list, a habit of redacting before pasting, and a short approved tools list everyone knows about.

Does paying for an AI subscription stop my data being used for training?

Usually, but verify it rather than assume it. Paid business and enterprise tiers commonly exclude customer inputs from model training and add retention controls and data residency options. Confirm whether the exclusion is contractual or a settings toggle a user could reverse, check the retention period, and obtain a data processing agreement that names sub-processors. Rely on the contract rather than the marketing page, since published terms can change without notice.

Is AI built into accounting software safer than an external tool?

Generally yes, for work involving client records. Embedded AI operates inside a system you have already contracted for and assessed, so no new processor or data flow is introduced. External tools offer broader capability but add a supplier, a contract, and a route for data to leave your assessed environment. A practical approach is to use embedded tools for anything touching client data, and external tools for generic drafting and research with identifiers removed.

Do accountants need a written AI policy?

A written policy is not universally mandated, but it is strongly advisable and increasingly expected by insurers, clients, and professional bodies. One page is enough. Cover your approved tools and required settings, the data types that must never be entered, who approves new tools, how often the list is reviewed, what clients are told, and what happens if data is exposed. A short policy people follow offers far more protection than a long one nobody reads.