CPAs face an immediate challenge in adopting AI across tax research, audit preparation, client communication, financial analysis, engagement administration and internal knowledge work. While AI can reduce repetitive effort, plausible errors, confidentiality risks, weak documentation and uneven staff practices can quickly undermine professional judgment and client trust.
CPAs work in a field where accuracy, independence, evidence and accountability matter. Firms need a practical adoption protocol that lets people experiment with useful tools while preserving the standards that make their work credible.
Start With the Engagement Workflow
Leaders should identify where AI enters the work rather than approving a tool in the abstract. A tax team might use AI to organize public guidance, draft a client checklist or compare alternative explanations of a rule. An audit team might use it to prepare planning questions, summarize nonconfidential process notes or draft internal training material. Advisory teams might use it to structure meeting notes or generate scenarios that professionals evaluate.
Each workflow needs a named owner, an approved tool, a clear data rule, a human review step and a record of how the output affected the final work. The professional who signs or approves the work remains accountable.
Confidential client information should never move into an unapproved system. Staff need simple rules that distinguish public information, internal firm information, client confidential information and regulated personal data. Vague warnings create hidden use. Specific examples make compliance easier.
Use Risk Tiers
A practical protocol can divide uses into three tiers:
Low-risk uses rely on public or synthetic information and have limited consequences. Examples include brainstorming training topics, drafting an agenda or turning an approved internal procedure into a checklist.
Moderate-risk uses influence professional work but remain subject to complete human review. Examples include organizing research questions, drafting client communications, summarizing internal meetings or comparing language across approved documents. These uses require documentation, verification, and a responsible reviewer.
High-risk uses affect an audit conclusion, tax position, valuation, financial recommendation, legal right or regulatory filing. Firms should prohibit unsupported reliance on AI in these areas and require specialized approval before any AI-enabled process becomes part of the engagement methodology.
The NIST AI Risk Management Framework gives firms a useful structure through its govern, map, measure and manage functions. CPAs can turn those functions into practical questions: Who owns the use? What information enters the system? How will we test accuracy? What evidence supports continued use? What happens when the output conflicts with professional judgment?
Train By Role
A generic demonstration does not prepare a tax manager, audit senior, controller, forensic accountant and client-service administrator for their actual decisions. Training should use realistic workflows, approved sample data and examples of both helpful and misleading outputs.
Staff should practice checking citations, tracing calculations, identifying missing assumptions, comparing outputs with authoritative sources and explaining why a recommendation remains professionally supportable. They should also learn when AI adds unnecessary complexity.
Managers play a central role. They answer daily questions, approve shortcuts, review workpapers and signal whether reporting a problem is safe. A firm that punishes every failed experiment will drive experimentation underground. A firm that ignores weak outputs will normalize risk. Leaders need a middle position that rewards responsible testing and honest reporting.
Document The Human Review
“Human in the loop” means little unless the firm defines the review. The protocol should identify what the reviewer must check, what source controls the answer, how corrections are documented and when escalation is required.
For research, the reviewer should inspect the underlying authority rather than rely on an AI summary. For calculations, the reviewer should reproduce or independently validate the result. For client communication, the reviewer should confirm accuracy, tone, confidentiality and whether the message creates unintended advice or commitments.
Measure Value Beyond Usage
Tool logins and prompt counts do not establish value. Firms should measure time saved, correction rates, cycle time, rework, staff confidence, client experience and whether the process improves quality.
A useful pilot starts with a baseline. Leaders should know how long the current workflow takes and where errors or delays occur. After the pilot, they can decide whether AI improved the work, merely shifted effort into review or created risk that outweighs the savings.
Build A Repeatable Approval Process
A short AI use-case form can record the workflow, tool, information category, reviewer, risks, testing method and outcome measure. Low-risk uses can move quickly. Higher-risk uses should receive review from appropriate leaders in professional practice, information security, legal, compliance and operations.
The goal is reliable improvement rather than maximum AI use. CPAs can gain meaningful efficiency when clear boundaries, role-specific learning, evidence-based review and professional accountability move together. A practical protocol gives staff permission to learn while protecting the judgment and trust clients expect.
Adapted from The Psychology of AI Adoption at Work: From Resistance to Results.
Dr. Gleb Tsipursky, a behavioral scientist called the “Office Whisperer” by The New York Times, is CEO of AI consultancy Disaster Avoidance Experts and author of eight books, including The Psychology of AI Adoption at Work: From Resistance to Results.

