How Should Los Angeles Accounting Firms Govern AI? (A Practical Guide to Secure AI Adoption)

Artificial Intelligence is rapidly becoming part of daily operations within accounting firms. Employees are using AI to draft emails, summarize documents, analyze information, generate reports, and improve productivity.
While these capabilities offer significant benefits, they also introduce new questions about client confidentiality, data protection, regulatory responsibilities, and acceptable use.
For accounting firms throughout Los Angeles County and Greater Los Angeles, successful AI adoption requires more than choosing the right technology. It requires governance.
An effective AI governance program establishes policies for approved AI tools, defines how employees may use them, protects confidential client information, aligns AI usage with Microsoft 365 security controls, and provides executive oversight as AI capabilities continue to evolve.
Why AI Governance Matters Now
Many firms have already adopted AI even if leadership has not formally approved it.
Employees frequently experiment with tools such as:
- Microsoft Copilot
- ChatGPT
- Claude
- Google Gemini
- AI meeting assistants
- AI writing tools
- AI research platforms
Often, these tools are introduced informally by individual employees seeking to improve productivity.
Without governance, however, firms may unknowingly expose confidential client information or create inconsistent practices across departments.
AI governance helps ensure innovation occurs responsibly.
Why This Matters
The question is no longer: “Should our accounting firm use AI?”
The better question is: “How do we ensure AI is used safely, responsibly, and consistently?”
The Seven Pillars of AI Governance
Rather than creating isolated AI policies for individual tools, firms should establish a governance framework that applies to current and future AI technologies.
Pillar #1 — Executive Ownership
AI governance should begin with leadership and not IT.
Managing partners and firm leadership should determine:
- Business objectives
- Risk tolerance
- Acceptable use
- Data protection priorities
- Regulatory expectations
- Governance responsibilities
Technology teams then implement those decisions through policies and security controls.
Executive Planning Tip
Treat AI governance the same way you would treat financial governance, cybersecurity governance, or business continuity planning.
It is an executive responsibility supported by technology and not the other way around.
Decision Table
| Governance Question | Recommended Approach | Common Mistake |
|---|---|---|
| Who owns AI governance? | Executive leadership with IT support | Delegating entirely to IT |
| Should AI policies be documented? | Yes | Relying on informal employee guidance |
| Should AI usage be reviewed? | Quarterly | Reviewing only after an incident |
Pillar #2 — Approved AI Platforms
One of the first governance decisions should be identifying which AI platforms employees are permitted to use.
Examples include:
- Microsoft Copilot
- ChatGPT Enterprise
- Claude for Teams
- Google Gemini for Workspace
- Other approved business AI platforms
Clearly defining approved platforms helps reduce shadow AI usage and provides employees with confidence about which tools align with firm policies.
Key Insight
Employees are more likely to follow AI policies when leadership provides approved alternatives rather than simply prohibiting AI use.
Pillar #3 — Protect Client Data and Confidential Information
The most important objective of AI governance is protecting confidential client information.
Accounting firms routinely manage:
- Tax returns
- Financial statements
- Payroll records
- Banking information
- Social Security numbers
- Employer Identification Numbers (EINs)
- Personally Identifiable Information (PII)
- Confidential business records
Before employees use any AI platform, leadership should establish clear guidance regarding what information may or may not be entered into AI systems.
A practical policy should address:
- Whether client names may be entered.
- Whether financial documents may be uploaded.
- Whether tax returns may be summarized.
- Whether AI may be used to draft client communications.
- Whether confidential information must be anonymized before use.
Why This Matters
AI tools can improve productivity, but they should never become an unintended path for exposing confidential client information.
Executive Planning Tip
When evaluating an AI use case, ask: “Would we be comfortable sharing this information outside the firm?”
If the answer is no, additional governance or technical controls are likely required.
Pillar #4 — Establish Clear AI Usage Policies
Technology alone cannot define responsible AI use.
Employees need written guidance that explains:
- Approved AI platforms
- Prohibited activities
- Acceptable business use
- Data handling requirements
- Human review expectations
- Documentation requirements
- Client confidentiality obligations
Policies should also clarify that AI-generated content remains subject to professional review before being shared with clients.
For accounting firms, AI should support professional judgment and not replace it.
Decision Table
| AI Activity | Recommended Approach | Governance Consideration |
|---|---|---|
| Draft internal emails | Permitted | Review before sending |
| Summarize meeting notes | Permitted | Remove confidential information if required |
| Draft marketing content | Permitted | Human review before publication |
| Analyze client tax data | Controlled | Follow documented data protection policies |
| Upload confidential client documents to public AI tools | Generally prohibited | Use approved enterprise AI solutions where appropriate |
Pillar #5 — Govern Microsoft Copilot and Enterprise AI
Enterprise AI platforms such as Microsoft Copilot offer stronger administrative controls than many public AI services, but they still require governance.
Leadership should review:
- Identity and access controls
- SharePoint permissions
- Microsoft Teams access
- OneDrive sharing
- Data classification
- Sensitivity labels
- Audit logging
- Retention policies
AI inherits existing permissions.
If employees have access to information they should not see, AI tools may surface that information more efficiently, not more securely.
Why This Matters
Preparing for AI often begins with improving Microsoft 365 governance rather than implementing new AI technology.
Pillar #6 — Train Employees to Use AI Responsibly
Policies are only effective when employees understand them.
Training should explain:
- Approved AI platforms
- Appropriate use cases
- Confidentiality expectations
- Data protection responsibilities
- AI limitations
- Hallucination risks
- Verification requirements
- Reporting procedures for suspected misuse
Training should emphasize that AI-generated responses may contain inaccuracies and should always be reviewed before being used in client work.
Key Insight
Responsible AI adoption depends as much on informed employees as it does on secure technology.
Pillar #7 — Continuously Monitor and Improve
AI governance should evolve alongside the business.
As new AI capabilities emerge, firms should periodically review:
- Approved AI platforms
- Employee adoption
- Security controls
- Regulatory developments
- Client expectations
- Internal policies
- Technology roadmap
Governance is an ongoing management process rather than a one-time implementation project.
AI Governance Maturity Model
Accounting firms can use the following framework to evaluate their current AI governance posture.
| Level | Characteristics |
|---|---|
| Exploring | Employees are experimenting with AI informally. No documented policies exist. |
| Developing | Leadership has identified approved AI platforms and drafted initial usage guidelines. |
| Managed | AI policies, employee training, Microsoft 365 governance, and executive oversight are established. |
| Optimized | AI governance is reviewed regularly, integrated into technology planning, and aligned with cybersecurity and compliance initiatives. |
The objective is to mature governance alongside AI adoption rather than trying to implement every control immediately.
Sample AI Governance Framework
A practical AI governance program may include:
| Governance Area | Example Activities |
|---|---|
| Executive Oversight | Annual AI strategy review, quarterly governance updates |
| Approved Platforms | Microsoft Copilot, approved enterprise AI solutions |
| Data Protection | Data classification, approved use guidelines, sensitivity labels |
| Employee Training | AI awareness, prompt best practices, confidentiality requirements |
| Security Controls | Identity protection, logging, Conditional Access, DLP |
| Continuous Review | Annual policy review, emerging AI technology assessment |
AI Risk Assessment Matrix
Leadership should evaluate AI initiatives according to business impact.
| Risk Level | Example | Recommended Action |
|---|---|---|
| Low | Drafting internal meeting notes | Standard review process |
| Moderate | Creating client-facing communications | Human approval required |
| High | Summarizing confidential financial information | Use only approved enterprise AI with documented safeguards |
| Critical | Uploading sensitive client records to unapproved public AI platforms | Prohibit under firm policy |
This type of framework helps leadership prioritize governance controls according to business risk rather than applying identical rules to every AI activity.
Executive AI Governance Checklist
Review this checklist with your leadership team.
Governance
☐ AI ownership assigned.
☐ Approved AI platforms documented.
☐ AI usage policy approved.
☐ Annual governance review scheduled.
Security
☐ Microsoft 365 permissions reviewed.
☐ Identity protection validated.
☐ Data Loss Prevention (DLP) configured where appropriate.
☐ Audit logging enabled.
Employee Readiness
☐ AI awareness training completed.
☐ Acceptable use policy communicated.
☐ Confidentiality guidance documented.
☐ Human review requirements established.
Continuous Improvement
☐ AI roadmap reviewed quarterly.
☐ New AI tools evaluated before adoption.
☐ Policies updated as technology evolves.
☐ Executive reporting includes AI governance.
Common AI Governance Mistakes
Many accounting firms are eager to embrace AI but overlook the governance needed to use it responsibly.
Common mistakes include:
- Assuming Employees Know What Is Appropriate
- Without written guidance, employees may unknowingly use AI tools in ways that conflict with firm policies or client expectations.
- Treating Public and Enterprise AI Platforms the Same
- Enterprise AI offerings often provide stronger administrative controls and contractual protections than public consumer services. Governance policies should recognize these differences.
- Skipping Human Review
- AI-generated content should support professional work and not replace professional judgment. Client deliverables should always be reviewed by qualified personnel.
- Ignoring Existing Data Permissions
- AI reflects existing access controls. Overly broad permissions within Microsoft 365 can become a larger issue as AI tools become more capable.
- Writing Policies Once and Never Updating Them
- AI technologies evolve rapidly. Governance policies should be reviewed regularly alongside cybersecurity, compliance, and technology strategy.
Cost Expectations
AI governance does not necessarily require significant new technology investments.
For accounting firms with 20–100 employees, the primary investments are typically:
- Leadership planning time
- Policy development
- Employee training
- Microsoft 365 governance improvements
- Security assessments
- Periodic AI governance reviews
Many firms incorporate these activities into their broader Managed IT Services and strategic planning engagements.
“Successful AI adoption isn’t measured by how quickly a firm implements new tools. It’s measured by how confidently leadership can govern their responsible use.”
Why AI Governance Matters in Los Angeles
Accounting firms throughout Los Angeles County and Greater Los Angeles are under increasing pressure to improve efficiency while protecting sensitive client information. AI can help firms streamline administrative work, enhance research, and improve collaboration, but only when supported by clear governance.
By establishing executive oversight, written policies, employee training, and strong Microsoft 365 security, firms can adopt AI in a way that encourages innovation while protecting client trust, operational integrity, and long-term business objectives.
Real-World Planning Scenario
How a Los Angeles Accounting Firm Introduced AI Responsibly
A growing accounting firm in Los Angeles County noticed that employees were already experimenting with AI tools to summarize meetings, draft emails, organize research, and improve productivity.
The firm’s leadership supported innovation but recognized a challenge: there were no documented guidelines for AI usage.
Different employees were using different platforms, there was uncertainty about whether client information could be entered into AI tools, and managers had no visibility into how AI was being incorporated into daily work.
Rather than banning AI, the firm developed a structured AI governance program.
Leadership first identified approved AI platforms, documented acceptable use policies, clarified how confidential information should be handled, and incorporated AI guidance into employee cybersecurity awareness training.
The firm also reviewed Microsoft 365 permissions, strengthened data governance, and established quarterly AI governance reviews as part of its existing technology planning process.
Within several months, employees had greater confidence about how AI could be used appropriately, leadership gained better oversight of emerging technologies, and the firm was positioned to adopt future AI capabilities without compromising client trust.
The most valuable outcome was not simply adopting AI. It was establishing a repeatable governance process that could evolve alongside future technology.
Executive Decision Framework
Use the following framework to determine the next step in your firm’s AI journey.
If Your Firm Has No AI Policy
Begin by establishing governance before expanding AI usage.
Priority initiatives include:
- Assign executive ownership.
- Identify approved AI platforms.
- Draft an acceptable use policy.
- Review Microsoft 365 permissions.
- Educate employees on responsible AI use.
If Employees Are Already Using AI
Focus on consistency and visibility.
Recommended priorities include:
- Standardize approved tools.
- Define data handling requirements.
- Establish human review procedures.
- Document AI usage guidelines.
- Incorporate AI into security awareness training.
If Your Firm Has Adopted Microsoft Copilot
Expand governance to include enterprise oversight.
Leadership should review:
- Identity protection
- SharePoint permissions
- Teams governance
- Data Loss Prevention (DLP)
- Audit logging
- AI-related executive reporting
If AI Governance Is Mature
Shift from policy development to continuous improvement.
Areas of focus include:
- Quarterly governance reviews
- AI risk assessments
- Employee feedback
- Emerging AI technologies
- Regulatory developments
- Strategic AI planning
Boardroom Questions Every Managing Partner Should Ask
Artificial Intelligence should be reviewed as part of executive governance and not just technology management.
During your next technology strategy meeting, consider asking:
- Which AI platforms has the firm approved?
- Are employees using any unapproved AI tools?
- How are we protecting confidential client information when AI is used?
- Have we documented acceptable AI use?
- How are we preparing Microsoft 365 for Microsoft Copilot?
- Have employees received AI awareness training?
- How will AI affect our cybersecurity and compliance responsibilities?
- What opportunities can AI create for our firm over the next three years?
These questions help ensure AI adoption remains aligned with business objectives while protecting client trust.
Conclusion
Artificial Intelligence is becoming an increasingly valuable productivity tool for accounting firms but successful adoption depends on more than selecting the right platform.
For firms throughout Los Angeles County and Greater Los Angeles, responsible AI adoption requires executive leadership, documented governance, secure Microsoft 365 environments, employee education, and ongoing oversight.
Rather than asking whether AI should be part of the business, leadership should focus on how AI can be implemented in a way that protects confidential information, supports professional standards, and aligns with long-term business goals.
The firms that realize the greatest value from AI will not necessarily be the first to adopt it. They will be the ones that govern it effectively.
Is your accounting firm prepared to adopt AI securely and responsibly?
Fothion helps accounting firms throughout Los Angeles County and Greater Los Angeles develop AI governance strategies that align Microsoft 365 security, cybersecurity best practices, executive oversight, and long-term technology planning.
An AI readiness assessment can help your leadership team establish practical policies, reduce risk, and confidently prepare for the next generation of AI-powered business tools.
Book a 30-minute call with Fothion: https://www.fothion.com/schedule-a-phone-call/
- Frequently Asked Questions
- Should accounting firms allow employees to use AI?
- Many accounting firms can benefit from AI, provided leadership establishes clear governance, approved platforms, security controls, and acceptable use policies before widespread adoption.
- Can confidential client information be entered into AI tools?
- Firms should establish policies governing what information may be entered into AI systems. Sensitive client information should only be handled in accordance with the firm’s data protection policies and the capabilities of approved enterprise AI platforms.
- Is Microsoft Copilot safer than public AI tools?
- Microsoft Copilot generally offers stronger administrative controls when deployed within a properly governed Microsoft 365 environment. However, governance, permissions, and data protection remain essential regardless of the AI platform.
- Who should own AI governance?
- Executive leadership should own AI governance because it affects business strategy, client relationships, risk management, and operational policies. IT supports implementation, but governance decisions should be made at the leadership level.
- How often should AI governance policies be reviewed?
- At least annually, with additional reviews whenever the firm adopts new AI capabilities, expands Microsoft 365 functionality, experiences significant business changes, or responds to evolving regulatory expectations.
- Can AI replace professional judgment?
- No. AI can improve efficiency and support research, drafting, and administrative tasks, but professional judgment, ethical responsibilities, and client service remain the responsibility of qualified accounting professionals.
- Does AI governance belong in our cybersecurity program?
- Yes. AI governance should be integrated with cybersecurity, Microsoft 365 security, identity protection, business continuity, employee awareness training, and technology governance.
- Can a Managed IT Services Provider help develop an AI governance strategy?
- Many strategic Managed IT Services Providers assist firms with AI readiness assessments, Microsoft 365 governance, acceptable use policies, cybersecurity controls, employee education, and long-term AI planning.
Leave a Comment