AICPA, IRS Pub 4557, and the FTC Safeguards Rule: A CPA AI Governance Checklist
A firm AI policy you can hand your peer reviewer — mapped to AICPA SSTS, IRS Pub 4557, and GLBA.
- PUBLISHED
- May 13, 2026
- READ TIME
- 7 MIN
- AUTHOR
- ONE FREQUENCY
- Topic
- CPA AI compliance, AICPA AI policy, IRS Pub 4557 AI
- Industry
- accountants
- Published
- May 13, 2026
- Read time
- 7 min
- Word count
- 1,306
Every CPA firm running AI in 2026 has the same conversation with the same peer reviewer at the same time of year. "Show me your AI policy." Half the firms produce a slide deck from a vendor. The other half produce a Slack thread. Neither passes peer review, and neither survives the first FTC Safeguards-related audit.
This article is the firm AI policy you can hand your peer reviewer — mapped to AICPA Statements on Standards for Tax Services (SSTS), IRS Publication 4557, the FTC Safeguards Rule, and GLBA. It is for the owner of a 2-to-20-person firm running AI on client tax and financial data.
The 4 regulatory frames
A CPA firm running AI sits at the intersection of four regulatory frames. Get clear on all four.
1. AICPA Statements on Standards for Tax Services (SSTS)
SSTS No. 1 (Tax Return Positions) requires the preparer to have a reasonable basis for every position. SSTS No. 3 (Certain Procedural Aspects of Preparing Returns) requires the preparer to make a reasonable effort to obtain the information necessary to answer questions on the return. AI does not change either requirement. The AI extracts; the preparer validates and signs.
Operationally: every AI-extracted field on a return must be tied out by the preparer against the source document before signing.
2. IRS Publication 4557 — Written Information Security Plan
Pub 4557 requires every paid preparer to maintain a written information security plan. Since 2023 the FTC Safeguards Rule has been fully effective, layering on the requirement that the plan cover every vendor with access to taxpayer data. AI vendors are explicitly in scope.
The plan must cover:
- Vendor inventory and DPA review per vendor.
- Access controls per role.
- Encryption in transit and at rest.
- Incident-response plan.
- Annual review and update.
- Designated qualified individual (typically the managing partner).
3. GLBA and the FTC Safeguards Rule
The Gramm-Leach-Bliley Act, as implemented by the FTC Safeguards Rule, requires the firm to maintain reasonable safeguards for nonpublic personal information. The 2023 amendments require an information-security program that explicitly covers third-party service providers — including AI vendors.
The five-key requirements: written plan; qualified individual; risk assessment; safeguards including encryption and access controls; vendor oversight.
4. State board AI-use disclosure
Several state boards (CA, NY, TX, and a growing list) have issued AI-use guidance in 2025 and 2026, typically requiring engagement-letter language disclosing AI assistance in preparation. The AICPA does not yet require disclosure, but the trend is one-way.
Operationally: engagement-letter template includes AI-disclosure language. Aiwyn's default templates handle this; verify against your state board's current guidance.
The 8 controls every CPA firm needs
Build these controls into the firm AI policy. This is the document you hand your peer reviewer.
1. Vendor DPA inventory
Every AI vendor with access to client data signs a DPA covering:
- No use of client data for model training.
- Retention windows (typically 30 days).
- Subprocessor disclosure and notification.
- Data residency (US only for most CPA firms).
- Incident-notification SLA (72 hours or faster).
Maintain a one-page summary per vendor in the IRS Pub 4557 plan.
2. Enterprise-tier-only rule
Consumer ChatGPT, free Claude, and free Gemini are not appropriate for client data. Enterprise-tier subscriptions with signed DPAs are the floor.
3. PII redaction protocol
No client SSN, EIN, bank account number, or routing number enters an AI prompt — even on enterprise tier. Build a redaction step into every workflow. Karbon AI and Canopy redact natively for major sensitive fields; for free-text drafting in Claude or ChatGPT Enterprise, train staff on manual redaction.
4. Engagement-letter disclosure
Every engagement letter discloses AI assistance in preparation. Aiwyn's templates include the language. Verify against state board guidance annually.
5. Preparer tie-out requirement (SSTS)
Every AI-extracted field on a return is tied out by the preparer against the source document before signing. Document the tie-out in the work papers. This is non-negotiable under SSTS.
6. Role-based access controls
Staff accountants access source documents. Seniors access the trial balance and prior-year return. Managers access engagement-status data. Partners access everything. AI tools respect the same role-based access controls. Karbon, Canopy, and Microsoft Copilot all support role-based scoping; configure it on day one.
7. Audit logging
Every AI prompt and response touching client data is logged. Microsoft Copilot audit logs, Karbon AI activity logs, and ChatGPT Enterprise admin logs all satisfy this. Retain logs for the same period as the underlying engagement (typically 7 years).
8. Annual policy review and staff training
The IRS Pub 4557 plan is reviewed annually. Staff training on AI use and DPA posture is mandatory at hire and refreshed annually. Document attendance.
What good looks like
Four metrics every CPA owner should track on the compliance posture.
- Vendor DPA coverage. Floor unmeasurable. Target 100% — every AI vendor under signed DPA.
- Tie-out documentation rate. Floor 60–75%. Target 100% — every AI-extracted field tied out.
- PII-incident rate. Floor unmeasurable. Target 0 incidents per year.
- Annual training completion rate. Floor 0%. Target 100% of staff with documented annual AI training.
These feed the broader AI enablement engagement and the 2026 firm playbook.
Pitfalls to avoid
Do not skip the written plan. A vendor deck is not a written information security plan. The plan is a firm-owned document covering the eight controls above, updated annually, signed by the managing partner.
Do not let consumer-tier AI touch client data. Even for "just rewording a memo." Enterprise tier across the board.
Do not skip the engagement-letter disclosure. State boards are moving fast. The firm that disclosed AI use in 2026 will not face a remediation when their state board mandates it in 2027.
Do not treat Karbon AI's or Canopy's DPA as sufficient. Read every vendor's DPA. Verify no-training, retention, and subprocessor terms. Vendor defaults change; the partner review is annual.
Do not skip the intake-automation controls. Onboarding is where most PII-redaction failures originate. See the onboarding automation walkthrough.
Do build the audit-log review into the monthly close. A 15-minute monthly review of the AI audit logs catches issues before peer review does.
FAQ
Q: What does my peer reviewer actually look at? A: The IRS Pub 4557 written plan, the vendor DPA inventory, the tie-out documentation in a sample of returns, and the staff-training attendance log. If those four are clean, the peer review on AI usage is straightforward.
Q: Does AICPA require AI-use disclosure on engagement letters? A: Not yet. State boards are moving first. The cleanest posture is to disclose now under all engagement letters.
Q: What about audit engagements — is AI allowed? A: Yes, with caveats. AICPA SAS 145 and PCAOB guidance allow AI in risk assessment and analytics. The auditor remains responsible for sufficient appropriate evidence. Document AI use in work papers; the audit team's transcription-drafting workflow is in scope.
Q: How does this interact with billable-time-leakage controls? A: Compliance and productivity are not in tension here. The same Karbon AI or Canopy that drives realization also satisfies the audit-log and access-control requirements.
Q: What if a vendor cannot produce a DPA in 72 hours? A: That vendor is not ready for CPA work. Pause the engagement until the DPA lands.
Q: How does GDPR or CCPA factor in? A: For firms with EU or California clients, add a GDPR data-processing-agreement and a CCPA-compliant retention notice on top of the IRS Pub 4557 plan. Most enterprise AI vendors ship both as standard.
If you want a one-page firm AI policy mapped to your state board, your client mix, and your AI stack — reach out. We hand every CPA firm we work with a peer-review-ready policy and an annual review cadence. Or see the engagement on AI for accountants.
Cited and consulted.
- 01Journal of Accountancy — Practice Management & Standardsjournalofaccountancy.com · accessed May 8, 2026
- 02Accounting Today — Regulation Coverageaccountingtoday.com · accessed May 8, 2026
- 03CPA Practice Advisor — Firm Management & Compliancecpapracticeadvisor.com · accessed May 8, 2026
- 04Karbon — Practice Management Resourceskarbonhq.com · accessed May 8, 2026
Ready to ship the next outcome?
One Frequency Consulting brings 25+ years of technology leadership and military discipline to every engagement. First call is operator-grade scoping — sixty minutes, no charge.