Home For Firms FAQs
For Firms · Frequently Asked Questions

AI governance questions, answered plainly.

Practical answers about AIGAS, AI Tool Registers, ChatGPT and client data, Bronze and Silver certification, ISO/IEC 42001 and getting started — written for accounting firms, bookkeepers, payroll bureaux and tax advisers.

63Questions answered
12Topic categories
2Free tools to start
No questions match your search.
Try a different word, or clear the search to see all 63 questions.

AI governance basics

8 questions

AI governance is the way an organisation decides how artificial intelligence can be selected, approved, used, monitored and reviewed.

  • In practice, that means being able to answer questions such as:
  • What AI tools are we using?
  • What information are staff allowed to enter into them?
  • Who is responsible for overseeing AI use?
  • What risks have we considered?
  • When must a human review an AI-generated output?
  • How do we assess new AI tools and suppliers?
  • What happens if something goes wrong?

Good AI governance is not about stopping people from using AI. It is about making sure AI is being adopted deliberately, responsibly and with appropriate oversight.

AIGAS turns those principles into a practical framework specifically for accounting firms.

Accounting firms routinely handle confidential client information, personal data, financial records and work requiring professional judgement.

AI can make many tasks faster, but it can also introduce new risks. These include inaccurate outputs, inappropriate disclosure of client information, reliance on unverified results, uncontrolled use of AI by staff and limited visibility over what happens to information entered into third-party systems.

AI governance helps the firm understand those risks and put proportionate controls around them.

The objective is not to eliminate risk. It is to ensure the firm understands how AI is being used and can demonstrate that appropriate oversight exists.

There is not one single requirement that says every UK accounting firm must obtain an AI governance certification.

However, using AI does not remove the legal, regulatory, contractual and professional obligations that already apply to a firm.

Depending on how AI is being used, these may include obligations relating to data protection, confidentiality, information security, professional judgement, record keeping and accountability.

AIGAS itself is a voluntary independent assurance standard. It provides a structured way for firms to demonstrate how they are governing AI, but it does not replace any legal or professional obligations that apply to the firm.

Yes — but the governance should be proportionate.

A sole practitioner using a small number of AI-enabled tools does not need the same governance infrastructure as a large multi-office practice with AI embedded across dozens of workflows.

The principle behind AIGAS is therefore not “more paperwork”.

It is enough governance to understand what AI is being used, what the main risks are, what staff can and cannot do, who is responsible and how professional work is checked.

For many smaller firms, AIGAS Bronze may provide an appropriate governance baseline.

No.

An AI policy is useful, but a policy alone does not demonstrate that AI is being governed.

Effective AI governance also requires visibility over the tools being used, clear responsibility, appropriate risk management, staff awareness, human oversight, consideration of suppliers and an ongoing process for reviewing how AI is being used.

A firm can have an excellent AI policy sitting in a folder while staff continue using unapproved tools in ways that management does not know about.

AIGAS therefore treats policy as one part of governance rather than governance itself.

In most firms using AI, clear guidance for staff is sensible.

An AI policy or acceptable-use policy can establish boundaries around issues such as approved tools, confidential information, client data, verification of outputs, human review and responsibility for professional work.

The policy should reflect how the firm actually works. A generic AI policy downloaded from the internet is unlikely to be sufficient if nobody understands it or follows it.

AIGAS looks at whether appropriate controls exist in practice, not simply whether a document exists.

Shadow AI is the use of AI tools or features without the organisation necessarily knowing about or formally approving them.

For example, an employee might begin using a free AI writing tool, meeting transcription service, browser extension or chatbot without telling anyone.

Shadow AI is particularly difficult to govern because the firm cannot assess risks associated with systems it does not know are being used.

This is why the AIGAS pathway begins with visibility and the AI Tool Register.

You cannot govern what you cannot see.

No.

AI risk depends on what the tool does, what information it accesses, how important its outputs are and how those outputs are subsequently used.

An AI tool helping draft an internal marketing idea creates a very different level of risk from an AI system processing confidential client information or generating work relied upon in a professional engagement.

AIGAS is designed around proportionate governance rather than treating every use of AI as equally risky.

AI tools, ChatGPT and client information

6 questions

Potentially, yes.

The question is not simply whether ChatGPT — or any other AI service — can be used. The more important question is how it is being used.

A firm should consider what information employees are entering, what version or account type is being used, what contractual and privacy arrangements apply, whether the use has been approved, how outputs are checked and whether appropriate human oversight remains in place.

The same principles apply to other generative AI tools.

AIGAS does not exist to ban tools such as ChatGPT. It exists to help firms put sensible governance around their use.

Client information should not simply be entered into an AI service because the service is convenient or publicly available.

The firm needs to understand the particular service, its contractual and data-processing arrangements, how information is handled, what controls are available and whether that use is appropriate for the information concerned.

Confidentiality, data protection and professional obligations continue to apply when AI is used.

Firms should therefore establish clear rules about which AI systems are approved and what types of information may be entered into them.

It is usually more useful to ask whether your organisation’s use of a particular AI system complies with its data-protection obligations.

Software cannot make an organisation compliant simply by being purchased or enabled.

The firm still needs to understand issues such as the information being processed, its purpose, the applicable lawful basis, supplier arrangements, security, retention, access and appropriate safeguards.

The same applies to ChatGPT, Microsoft Copilot, Gemini and other AI platforms.

No.

AI can assist with research, analysis, drafting, summarising, automation and many other activities.

It does not transfer professional responsibility for the work away from the firm.

Where an AI-generated output contributes to professional work, appropriate human review remains important. The person reviewing the work should have sufficient competence to identify errors rather than simply accepting the AI output because it appears convincing.

Human oversight is therefore an important part of the AIGAS Standard.

That possibility is one reason AI governance is necessary.

Generative AI systems can produce inaccurate, incomplete or misleading outputs while presenting them confidently.

Firms should establish appropriate verification and human-review controls based on the significance of the work being performed.

The greater the potential impact of an error, the stronger the verification process should normally be.

Not necessarily simply because AI is involved.

The appropriate approach depends on what the AI system is doing, what information is being processed, the legal basis for processing, contractual arrangements, confidentiality obligations and the nature of the service being provided.

Firms should therefore consider AI use within their existing data-protection, engagement, confidentiality and professional-responsibility arrangements rather than assuming that either consent is always required or that it is never required.

Where there is uncertainty about a particular use case, appropriate legal or data-protection advice should be obtained.

The AI Tool Register

6 questions

An AI Tool Register is a central record of the AI-enabled systems being used within an organisation.

It helps a firm understand what AI is present, where it is being used and what it is being used for.

The AIGAS AI Tool Register is the starting point of the AIGAS governance pathway because effective governance begins with visibility.

The AIGAS AI Tool Register is free to use.

AI is increasingly appearing inside software that firms already use.

Management may know that employees are using ChatGPT but be less aware that AI functionality has also appeared inside accounting platforms, Microsoft 365, Google Workspace, CRM systems, transcription tools, document-management platforms and other software.

A register creates a central picture of that environment.

It also provides a foundation for risk assessment, supplier review, staff guidance and ongoing governance.

  • The register should include relevant AI-enabled systems being used by the firm.
  • That may include:
  • Standalone generative AI tools.
  • Accounting and tax software containing AI functionality.
  • Microsoft 365 or Google Workspace AI features.
  • Meeting transcription and note-taking services.
  • Document analysis tools.
  • Research assistants.
  • CRM and marketing platforms.
  • Automation systems.
  • Internally developed AI tools.
  • Other software containing relevant AI-enabled functionality.

The objective is not to create an enormous software inventory for its own sake. It is to create sufficient visibility over the AI that could affect the firm’s work, information or clients.

Potentially, yes.

AI governance is not limited to standalone chatbots.

If an existing system introduces AI functionality that is relevant to the firm’s activities, information or professional workflows, the firm should understand that functionality and consider whether it belongs within its AI inventory.

This is becoming increasingly important because organisations may adopt AI functionality without purchasing an entirely new product.

It should be treated as a living record.

New tools appear, existing products gain AI functionality and employees find new ways of using technology.

The register should therefore be updated when relevant tools or uses change and periodically reviewed to make sure it still reflects what is actually happening within the firm.

Yes.

The AI Tool Register is the free starting point within the AIGAS pathway. A firm does not need to commit to Bronze or Silver certification in order to begin recording its AI tools.

The aim is to make basic visibility over AI accessible to every accounting firm.

The AIGAS Self-Assessment

5 questions

The AIGAS Self-Assessment is a free readiness check that helps a firm understand its current AI governance position.

It looks at areas including AI awareness, governance and responsibility, risk and compliance, controls and oversight, and future readiness.

The questions draw from the six governance areas within the AIGAS Standard.

At the end, the firm receives an immediate result showing its overall position, stronger and weaker areas, and recommended next steps.

  • Around seven minutes for most firms.
  • It is deliberately designed as a quick readiness check rather than a certification audit.
  • There are no evidence uploads required simply to complete the Self-Assessment.

Yes.

Both the AIGAS AI Tool Register and the AIGAS Self-Assessment can be used free of charge.

A firm can therefore understand more about its existing AI use and governance position before deciding whether it wants to progress towards certification.

No.

The Self-Assessment is an informal readiness check.

It helps identify where your firm currently stands and what you may need to address, but it does not award Bronze or Silver certification.

AIGAS assurance is evidence-based. Certification requires the firm to demonstrate that the relevant requirements have actually been implemented.

  • No.
  • The free Self-Assessment is question-based and does not require evidence uploads.
  • Evidence becomes relevant when a firm progresses into the formal AIGAS assurance pathway.

About AIGAS

9 questions

AIGAS™ stands for the AI Governance Assurance Standard.

It is a practical, sector-specific AI governance framework created for UK accounting firms.

AIGAS is designed to help firms understand how AI is being used, put proportionate controls around it, evidence those controls and increase the level of assurance as their use of AI becomes more mature.

The pathway begins with the free AI Tool Register and progresses through AIGAS Bronze and AIGAS Silver, with a longer-term route towards ISO/IEC 42001 for organisations that require an international AI management-system standard.

AIGAS is designed for organisations providing accounting and related professional services, including:

  • Accounting practices.
  • Sole practitioners.
  • Bookkeepers.
  • Payroll bureaux.
  • Tax advisers.
  • Outsourced finance teams.
  • Multi-partner and multi-office accounting firms.

The framework is deliberately proportionate so that the level of governance can reflect the size, complexity and AI use of the organisation.

  • The AIGAS framework covers six broad areas of AI governance:
  • Strategy and Purpose — understanding why and where AI is being used.
  • Risk and Compliance — identifying and managing relevant AI risks.

Data Protection and Confidentiality — protecting information and considering supplier relationships.

Governance and Accountability — establishing responsibility and appropriate oversight.

Operational Controls — putting practical controls around real-world AI use.

Ongoing Review — ensuring governance continues to evolve as technology and working practices change.

Bronze and Silver both work across these areas, but at different levels of depth and maturity.

No.

AIGAS is intended to enable responsible AI adoption rather than prevent it.

Without governance, firms may respond to AI risk by either ignoring it or attempting to prohibit AI entirely.

Neither approach is particularly sustainable.

Good governance gives a firm greater confidence to decide which tools and uses are appropriate, what controls are required and where the boundaries should be.

No.

AIGAS is an independent, sector-specific AI governance assurance standard designed for accounting firms.

ISO/IEC 42001 is the international standard for Artificial Intelligence Management Systems.

They serve different purposes.

AIGAS provides a practical entry point for accounting firms that may not need, or may not yet be ready for, a full international management-system certification.

AIGAS has also been structured so that organisations can develop governance disciplines that can support a future move towards ISO/IEC 42001.

No.

AIGAS is an independent governance and assurance standard and does not claim to be UKAS accreditation or ISO certification.

Achieving AIGAS Bronze or Silver does not constitute approval by UKAS, ISO, the ICO, ICAEW, ACCA or another professional or regulatory body unless such approval is expressly stated.

AIGAS is an independent standard.

Certification should not be interpreted as endorsement by ICAEW, ACCA or another professional body unless AIGAS explicitly states that such a relationship or endorsement exists.

No.

AIGAS does not replace the UK GDPR, Data Protection Act or other legal obligations.

Instead, it helps a firm create governance around AI use, including areas where AI interacts with personal data, confidential information and third-party suppliers.

Legal compliance remains the responsibility of the organisation.

No.

Cybersecurity, information security and AI governance overlap, but they are not the same thing.

  • Cyber Essentials focuses primarily on fundamental cybersecurity protections.
  • ISO/IEC 27001 is an information-security management-system standard.
  • AIGAS focuses specifically on governance of AI within accounting firms.
  • An organisation may therefore use these frameworks alongside one another.

AIGAS Bronze

5 questions

AIGAS Bronze is the foundational assurance level within the AIGAS Standard.

It is designed for firms that want to demonstrate that they understand how AI is being used and have established sensible, proportionate governance around it.

Bronze focuses on fundamentals such as visibility, responsibility, acceptable use, staff awareness, protection of confidential information, human oversight and ongoing review.

It is particularly suitable for smaller firms and organisations at an earlier stage of AI adoption.

AIGAS Bronze currently consists of 15 core controls across the six AIGAS governance areas.

The controls are intended to establish the fundamental building blocks of responsible AI governance without requiring smaller accounting firms to implement a complex enterprise management system.

The evidence should demonstrate that the required governance controls genuinely exist.

Depending on the requirement, this might include information from the AI Tool Register, governance documentation, evidence of staff awareness, assigned responsibilities and other relevant records.

AIGAS is evidence-based.

Simply ticking a box to say that something has been done is not the same as demonstrating that an appropriate control is actually in place.

AIGAS assurance is valid for 12 months.

During that period, the firm should continue maintaining its AI Tool Register and governance arrangements as tools, risks and working practices change.

Assurance is then revalidated.

No.

For some firms, Bronze may be an appropriate level of governance for their current size, AI use and risk profile.

Others may decide to progress to Silver as their use of AI becomes more extensive or they require stronger external assurance.

The AIGAS pathway is designed to allow governance to mature with the organisation rather than forcing every firm towards the same destination.

AIGAS Silver

6 questions

AIGAS Silver is the higher assurance level within the AIGAS framework.

Where Bronze establishes the foundations, Silver looks more deeply at whether AI governance is structured, documented, embedded into working practices and actively maintained.

Silver introduces areas such as more formal AI risk management, defined governance responsibilities, supplier consideration, operational controls, monitoring and continuous improvement.

Evidence is independently reviewed before Silver assurance is awarded.

  • The main difference is the level of maturity and assurance.
  • Bronze asks:
  • Have we established the foundations of AI governance?
  • Silver asks:
  • Can we demonstrate that AI governance is structured, implemented and actively managed?
  • Bronze is designed as a practical baseline.

Silver provides stronger assurance for firms where AI is becoming more important to operations, client work or organisational risk.

No.

Bronze is not a mandatory prerequisite for Silver.

A firm that already has mature governance arrangements, uses AI extensively or needs stronger assurance may decide to begin directly with Silver.

Where a firm has already achieved Bronze, the relevant governance work and evidence can provide a foundation for progressing towards Silver rather than starting again.

Yes.

Silver requires supporting evidence to be independently reviewed by an appropriately authorised assessor.

This provides a higher level of assurance than simply asking the organisation to declare that its controls exist.

  • Silver may be particularly appropriate where:
  • AI is becoming important to the firm’s operations.
  • Multiple teams or systems use AI.
  • AI is embedded into client or operational workflows.
  • The firm wants structured AI risk management.
  • Clients or stakeholders are asking questions about responsible AI use.
  • The firm wants stronger evidence of its governance arrangements.
  • The organisation expects its AI adoption to grow.
  • The firm may ultimately consider ISO/IEC 42001.

Silver assurance is valid for 12 months.

During that period the firm is expected to maintain its governance arrangements, respond to relevant changes and continue reviewing how AI is being used.

Assurance is then revalidated.

Implementation and certification

6 questions

There is no single timescale because firms start from very different positions.

A small firm that already has clear policies, appropriate controls and a good understanding of its technology may require relatively little remediation.

Another firm may discover significant gaps around staff use, suppliers, risk management or documentation.

The free AI Tool Register and Self-Assessment are designed to help firms understand their starting position before committing to a certification project.

  • Yes.
  • AIGAS is designed so that firms can complete parts of the pathway directly.
  • Some organisations will be comfortable implementing the necessary controls themselves.

Others may prefer support, particularly where governance arrangements need to be developed or the firm is progressing towards Silver.

Not necessarily.

AIGAS Certified Service Providers are available for firms that want implementation support, but using one is not automatically required.

A Service Provider can assist with areas such as assessing the current position, implementation planning, policies, risk assessments, staff training, the AI Tool Register, evidence preparation and ongoing governance.

The firm nevertheless remains responsible for how AI is ultimately governed.

Evidence depends on the assurance level, the control being demonstrated and the circumstances of the firm.

  • It may include:
  • Policies and governance documentation.
  • The AI Tool Register.
  • Records of assigned responsibilities.
  • Staff training or awareness records.
  • Risk assessments.
  • Supplier reviews.
  • Documented approval processes.
  • Evidence of human-review controls.
  • Incident or corrective-action records.
  • Governance meeting or review records.
  • The purpose is not to build the largest possible evidence folder.
  • The purpose is to demonstrate that appropriate governance actually exists.

AIGAS is assessing your AI governance arrangements, not auditing the contents of your clients’ accounting records.

Evidence should demonstrate that a control exists without unnecessarily exposing confidential client information.

Firms remain responsible for ensuring that any evidence supplied is appropriate and does not disclose information unnecessarily.

The AI Tool Register and AI Governance Self-Assessment are free.

As currently published, AIGAS Bronze is £495 per year and AIGAS Silver is £1,995.

Additional implementation support, consultancy or training provided by a Certified Service Provider may be charged separately.

Please refer to the relevant Bronze or Silver page for current certification pricing.

AIGAS, ISO 42001 and other standards

3 questions

ISO/IEC 42001 is the international management-system standard for artificial intelligence.

It establishes requirements for organisations to create, implement, maintain and continually improve an Artificial Intelligence Management System.

It can apply across industries and organisation sizes.

For some accounting firms, particularly larger organisations or those with extensive AI use, ISO/IEC 42001 may eventually be an appropriate destination.

For many smaller firms, however, implementing a full international management system may be more than they currently require.

AIGAS provides a sector-specific pathway that allows firms to begin with proportionate governance and mature over time.

  • No.
  • AIGAS and ISO/IEC 42001 are separate standards.
  • AIGAS is sector-specific and designed around the realities of accounting firms.
  • ISO/IEC 42001 is an international management-system standard applicable across industries.

AIGAS has been structured around governance disciplines that can help an organisation develop towards a more mature management-system approach, but AIGAS certification is not ISO/IEC 42001 certification and does not claim equivalence with it.

It can provide useful foundations.

AIGAS introduces disciplines such as defined responsibility, AI inventories, risk management, operational controls, monitoring and continual improvement.

Those habits and records can make the transition towards a more formal AI management system more structured.

An organisation pursuing ISO/IEC 42001 would still need to meet the requirements of ISO/IEC 42001 and undertake the appropriate certification process independently.

Vendors and AI software

3 questions

AIGAS does not simply label every product as either safe or unsafe.

Whether a particular tool is appropriate depends partly on how the firm intends to use it.

AIGAS therefore encourages firms to understand their suppliers, the AI capabilities involved, relevant data-processing arrangements and the risks associated with the intended use.

The AIGAS Vendor Transparency Programme provides additional structured information to help firms make informed decisions.

A Verified Vendor has completed the AIGAS Vendor Transparency process and provided structured information about relevant aspects of its product and governance arrangements.

Verification is intended to improve transparency for accounting firms considering AI-enabled technology.

It does not remove the firm’s responsibility to decide whether a particular product or use is appropriate for its own circumstances.

No.

Vendor transparency is one part of good governance.

The accounting firm still needs appropriate policies, responsibility, staff awareness, risk management, human oversight and other relevant controls around how the technology is actually used.

Good technology can still be used badly.

AIGAS therefore considers both the technology supply chain and the governance within the accounting firm.

Clients, insurers and external assurance

3 questions

Yes.

One advantage of structured AI governance is that the firm is better able to answer questions from clients about how AI is being managed.

Instead of simply saying, “We have an AI policy”, the firm can demonstrate that it understands what tools are being used, has assigned responsibility, has appropriate controls and reviews its governance arrangements.

Certification does not guarantee that every client will accept a particular response, but it gives the firm a much stronger evidence base.

Potentially.

Organisations are increasingly asking suppliers about AI use, information security, data handling and governance.

AIGAS provides a structured way of evidencing the firm’s approach to AI governance, which can help when responding to procurement or due-diligence questions.

The exact requirements will still depend on the organisation asking the questions.

No.

No governance standard can guarantee that an AI system will never produce an incorrect result or that an incident will never occur.

The purpose of governance is to reduce unmanaged risk, create appropriate controls, establish accountability and make sure the organisation has a process for responding when problems arise.

AIGAS certification demonstrates that relevant governance arrangements have been established. It is not a guarantee of the performance of every AI system used by the firm.

Getting started

3 questions

Start with visibility.

Create your free AIGAS AI Tool Register and identify the AI systems already being used across your organisation.

Then complete the free AIGAS Self-Assessment to understand the governance you already have in place and where gaps may exist.

From there, you can decide whether Bronze, Silver or simply improving particular controls is the appropriate next step.

You do not need to solve AI governance in one day.

Discover → Assess → Improve → Demonstrate → Maintain

You do not need to decide before you begin.

The free Self-Assessment can give you an initial indication of your current governance position.

Broadly, Bronze is designed to establish the foundations of responsible AI governance, while Silver is intended for firms that need a more structured, embedded and independently reviewed level of assurance.

The appropriate level should reflect the size of the firm, complexity of its operations, extent of AI use, associated risks and the assurance expected by clients and other stakeholders.

Yes.

In fact, that can be an ideal time to put basic governance in place.

It is considerably easier to establish appropriate rules, responsibilities and visibility while AI use is limited than to reconstruct what happened after dozens of tools and workflows have already developed.

And you may discover that your firm is already using more AI than you think.

Still have a question?

You don’t need to solve AI governance in one day.

Start by understanding what AI your firm already uses. The AI Tool Register is free, and the Self-Assessment takes about seven minutes.

Scroll to Top