AI Risk Management: 5 Critical Questions for Accountants
Without a clear AI risk management strategy, your accountancy practice could be exposed by PII gaps as clients begin to question your use of AI tools.
By Harmeen Birk, AI Governance Advisor · · 7 min read
You have adopted an AI platform. It prepares filings faster, flags anomalies your team might miss, and frees up senior time for advisory work. The efficiency case is clear.
But your largest client's CFO has just sent you a questionnaire. They want to know which AI tools you use in their engagement, how you have assessed the risks, and whether your Professional Indemnity Insurance explicitly covers AI-related errors.
This is happening. Not in two years. Now.
The accountancy firms that will retain and grow mandates over the next 24 months are not the ones that avoid AI. They are the ones that can prove they use it responsibly. That proof needs to be independent, documented, and ready to share.
The Liability Gap Your PII Policy Probably Has
Professional Indemnity Insurance was built around a simple assumption: a human professional makes a mistake, negligence is established, the insurer pays.
AI breaks that model. When an AI system contributes to an error; a miscalculated forecast, a missed liability, a flawed tax position, assigning blame becomes genuinely complex. Was the error caused by the professional who trusted the output? The model itself? The training data? The vendor who built it?
Insurers know this. Many PII policies now contain exclusions for technology-related failures, or were simply never written with AI in mind. If a claim arises from AI-assisted work, your insurer may argue the error falls outside your coverage.
The liability does not disappear. It lands on your client. And then it comes back to you.
| PII Policy Feature | Traditional Assumption | AI Complication |
|---|---|---|
| Standard of Care | Judged against a reasonably competent peer | What is reasonable care when trusting AI output? |
| Negligence | Human breach of duty of care | Black-box decisions make negligence hard to establish |
| Exclusions | Software failure or cyber events | AI errors may be classified as technology failure and excluded |
| Geographic Scope | Tied to where the service is rendered | AI hosted overseas, trained on global data — jurisdiction is unclear |
A common mistake: Assuming your PII automatically covers AI-assisted work. Many policies were not written with AI in mind. Check before a claim forces the issue.
What Your Clients Are Already Asking
Procurement teams at mid-market companies, listed businesses, and any firm with EU operations are updating their supplier due diligence processes right now. AI governance is moving from a nice-to-have to a contract requirement.
Here are the five questions your clients will ask, and what a confident answer looks like:
**1. Do you use AI systems in the work you deliver for us?** Weak answer: "We use some tools to help with efficiency." Strong answer: A named inventory of AI systems, their purpose, and the controls applied to each.
**2. How have you assessed and mitigated the risks of those systems?** Weak answer: "We follow the vendor's guidelines." Strong answer: Reference to a formal AI governance framework, ideally independently verified.
**3. Does your Professional Indemnity Insurance explicitly cover AI-related errors?** Weak answer: "We would have to check with our broker." Strong answer: Written confirmation from your insurer or broker, on file and ready to share.
**4. What human oversight is applied before AI output reaches us?** Weak answer: "Our team reviews everything." Strong answer: A documented review process with named sign-off authority, not a rubber-stamping exercise.
**5. How is our data used by your AI systems?** Weak answer: "It is covered in our data processing agreement." Strong answer: Explicit confirmation that client data is not used to train underlying models, with a contractual warranty.
If you read those questions and felt uncertainty about your own answers, you are not alone. Most accountancy practices using AI tools have adopted them faster than their governance has kept pace.
::cta[Find your tier]{href=/selector variant=primary}
Not sure where your practice stands? Find out which AI Assured tier applies to you. Takes two minutes.
The Client Impact You Cannot Ignore
When your AI makes an error and your insurance does not cover it, the immediate damage lands on your client. The subsequent dispute between you, your insurer, and the AI vendor is slow, expensive, and does nothing to help them in the short term.
Consider what that looks like in practice:
**Financial forecasting:** Your AI tool produces an optimistic projection based on flawed market data. Your client uses it to secure a business loan. The forecast proves wrong. Their business is in default. Your PII provider argues the fault lies with the AI vendor. Your client is in a legal battle they did not expect and cannot afford.
Tax filing: An AI-assisted filing misinterprets a complex piece of tax code. HMRC investigates. Penalties follow. Your client wants to know why the error was not caught. You want to know why your insurer is querying the claim.
Due diligence: AI document review misses a liability clause in an acquisition. The deal completes. Your client inherits a lawsuit. The question of who bears responsibility; your firm, your AI vendor, or your insurer will take months to resolve.
In every scenario, the client suffers first. Their trust in your firm is the casualty. The instruction to move their work may follow.
::cta[Start free assessment]{href=/assessment variant=primary}
See how your AI governance compares against the AI Essentials standard. Free, no commitment.
What Responsible AI Use Actually Looks Like
Responsible AI in an accountancy practice is not about avoiding the tools. It is about being able to demonstrate, to any client who asks, that you have:
- An inventory of every AI system used in client work
- A documented process for reviewing AI output before it reaches the client
- Contractual clarity with your AI vendors on data use and liability
- Insurance coverage that has been explicitly verified for AI-related work
- A governance framework your team understands and follows
This is not a compliance burden. It is a commercial advantage. The firms that can hand a client a certificate of independent AI governance assurance will win mandates that firms without one will lose.
The EU AI Act enforcement deadline is August 2026. Professional services firms advising businesses with EU operations will face direct pressure from clients who are themselves under compliance obligations. That pressure is already moving through supply chains.
The question is not whether your clients will ask. It is whether you will be ready when they do.
AI Assured Certification: Your Answer to Every Question
AI Assured is the independent certification standard for AI governance in SMEs and professional services firms. It is structured, pass-or-fail, and designed to be completed without a consultant or a six-month implementation project.
Certification gives you:
- An independently verified governance badge you can show clients, boards, and insurers
- A gap report identifying exactly what needs to improve before you certify
- A documented framework your team can follow and your clients can rely on
- A credible answer to every procurement questionnaire that arrives in your inbox
It is the Cyber Essentials equivalent for AI governance: proportionate, credible, and built for firms like yours.
::cta[Get AI Assured certified]{href=/selector variant=primary}
The companies asking for AI governance assurance are already your clients. Get certified before they ask.