This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.
If your team has started using AI but reviews its output differently from person to person, that is a normal early-stage problem. The useful next step is not a more elaborate prompt or another AI product. It is a shared control that helps staff decide what can proceed, what needs correction and what should be escalated.
In short: Treat AI output as unverified working material, not finished accounting work. Before anyone relies on it or sends it to a client, check the source material, recalculate every material number, confirm the client context, inspect citations, obtain an appropriate human approval and keep a proportionate record of the review.
This checklist is a general governance tool. It does not determine whether work complies with legislation, professional standards, engagement terms or local record-keeping rules. Accounting firms should adapt it with their professional advisers, insurers, regulators and professional bodies.
The practical change this checklist creates
Without a shared review step, two staff members can use the same AI output in very different ways. One may compare every figure with the ledger and document the source. Another may correct obvious wording but assume the calculations and references are sound.
For a senior accountant, the before-and-after use case is concrete. Before, a staff member asks an AI system to draft a client explanation of a variance, then sends the polished answer to a manager with no record of what was checked. After, the staff member attaches the original source, ties every number back to it, marks unsupported statements, records any AI use and obtains reviewer sign-off before the explanation is finalised.
The checklist does not make an unreliable output reliable by itself. It makes the review visible, consistent and easier to supervise.
Where the checklist should apply
Use the control whenever AI contributes content that could affect a client, financial decision, filing, report, advice, representation or internal approval. That can include:
- Draft client emails containing accounting or tax explanations
- Management commentary based on financial results
- Variance explanations and board-report narratives
- Summaries of contracts, standards or regulatory material
- Draft calculations, reconciliations or spreadsheet formulas
- Research notes, citations and technical memoranda
- Meeting summaries containing client instructions or decisions
- Internal risk assessments that influence engagement work
A spell-check suggestion presents a different level of risk from an AI-generated technical conclusion. The depth of review should therefore reflect the possible consequence of an error, not merely the length of the output.
Set the review level before checking the output
A simple three-level classification keeps the process proportionate.
Lower-risk output
This includes material that does not change a number, conclusion or client decision, such as restructuring an internally approved paragraph or simplifying non-technical wording. A competent preparer may be able to complete the review, provided the firm permits that arrangement.
Moderate-risk output
This includes client-facing explanations, summaries of source documents, management commentary and analysis that informs a decision. It normally benefits from a second person checking the material against the underlying evidence.
Higher-risk output
This includes material calculations, filings, technical accounting positions, tax conclusions, audit evidence, assurance judgements, fraud indicators and advice that may materially affect a client. These outputs should follow the firm’s existing specialist consultation and engagement-review processes. An AI checklist should not reduce the level of human review that the work would otherwise receive.
If the classification is uncertain, move the output to the higher review level or ask the engagement lead. Ambiguity is a reason to escalate, not a reason to assume the output is harmless.
The AI output review checklist
The following sections can be printed as one review sheet or added to an existing workpaper template. A reviewer should be able to answer each applicable item with Yes, No, Not applicable or Escalated.
1. Identify the output and its intended use
- [ ] The client, entity, engagement and reporting period are identified correctly.
- [ ] The intended audience and purpose are stated.
- [ ] The output is classified as internal, client-facing or externally submitted.
- [ ] The review level has been selected before approval.
- [ ] The preparer has disclosed where AI contributed to the work.
- [ ] The final use is permitted by the firm’s policies and engagement procedures.
This first step prevents a common control failure: reviewing an output as harmless drafting when it will actually support a decision or leave the firm.
2. Check the input and client context
- [ ] The source documents belong to the correct client and period.
- [ ] The prompt or instruction reflects the actual question being answered.
- [ ] Relevant facts, assumptions, exclusions and materiality considerations are recorded.
- [ ] The output has not mixed information from another client, entity or period.
- [ ] Client terminology, accounting policies and engagement scope are represented accurately.
- [ ] Missing information is identified rather than silently filled with plausible detail.
AI systems can produce a confident answer from an incomplete instruction. Review the information supplied to the system as carefully as the prose it returned.
3. Tie out every number
- [ ] Every material amount is traced to an approved source or independently recalculated.
- [ ] Totals, subtotals, percentages, ratios and variances are recalculated.
- [ ] Signs, decimal places, currencies, units and reporting periods are correct.
- [ ] Comparative figures match the relevant approved period.
- [ ] Rounding does not change the meaning or create an unexplained difference.
- [ ] Spreadsheet formulas or code produced by AI have been inspected and tested.
- [ ] No figure is accepted merely because it appears reasonable.
A polished explanation does not compensate for a failed numerical tie-out. If one material figure cannot be supported, stop the output and resolve the gap before continuing.
4. Verify factual statements and technical reasoning
- [ ] Material factual statements are supported by the engagement file or an authoritative source.
- [ ] Definitions and technical terms are used consistently.
- [ ] The reasoning follows from the stated facts and assumptions.
- [ ] Alternative explanations have been considered where the evidence is ambiguous.
- [ ] The output distinguishes facts, assumptions, estimates and professional judgement.
- [ ] Any limitation or uncertainty that affects the conclusion is visible to the reader.
- [ ] The conclusion has been formed by an appropriately qualified person, not delegated to the AI system.
Pay particular attention to sentences that sound definitive. Fluency is a presentation quality, not evidence that the reasoning is correct.
5. Inspect citations and references
- [ ] Every cited source exists.
- [ ] The title, author or issuing body, publication and section reference are accurate.
- [ ] The cited material supports the specific statement attached to it.
- [ ] The source is current for the period and jurisdiction under review.
- [ ] A primary source has been used where the conclusion depends on a law, standard or regulator’s guidance.
- [ ] Links, quotations and paragraph references have been opened and checked by a person.
- [ ] Unsupported citations generated by AI have been removed, not replaced with another unverified reference.
Never treat a detailed-looking citation as self-validating. AI can produce references that are incomplete, irrelevant or nonexistent.
6. Review confidentiality, privacy and data handling
- [ ] The information entered into the AI system was permitted under firm policy.
- [ ] Client confidentiality and engagement restrictions were considered before data was submitted.
- [ ] Unnecessary personal, financial or commercially sensitive information was excluded or minimised.
- [ ] The preparer knows which system, account and approved configuration were used.
- [ ] Any suspected disclosure, cross-client contamination or inappropriate access has been escalated.
- [ ] The output and its supporting records are stored only in approved locations.
This is a control checkpoint, not a conclusion about legal compliance. Applicable expectations can differ by jurisdiction, client contract, professional rules, system configuration and the type of information involved.
7. Check wording, audience and client impact
- [ ] The answer addresses the client’s actual question.
- [ ] The language matches the reader’s level of financial knowledge.
- [ ] The output does not overstate certainty or omit a material qualification.
- [ ] Advice, observation and general information are clearly distinguished.
- [ ] Defined terms, dates, names and entity details are consistent throughout.
- [ ] The wording does not imply that the AI system made or approved a professional judgement.
- [ ] The tone is professional and appropriate to the engagement.
A technically accurate answer can still be unsafe if it gives the client more certainty than the evidence supports.
8. Obtain the right human approval
- [ ] The preparer is identified.
- [ ] The reviewer has suitable authority and subject knowledge for the risk level.
- [ ] The reviewer has examined the source evidence, not only the AI-generated draft.
- [ ] Corrections and unresolved questions are recorded.
- [ ] Material disagreements or uncertainty have been escalated.
- [ ] The final approver is identified with the review date.
- [ ] The approved version is clearly distinguishable from earlier drafts.
Human sign-off should represent an actual review. A name added to the file without checking the evidence is not an effective control.
9. Keep a proportionate record
- [ ] The firm has retained enough information to understand how AI contributed.
- [ ] Relevant source documents and calculations are linked or referenced.
- [ ] Material prompts, outputs and corrections are retained where firm policy calls for them.
- [ ] The risk classification and review outcome are recorded.
- [ ] The preparer, reviewer and approval date are captured.
- [ ] Exceptions, consultations and escalation decisions are documented.
- [ ] Records follow the firm’s approved retention and access arrangements.
The record does not need to preserve every low-risk interaction forever. It should be proportionate to the output’s significance and sufficient for the firm to reconstruct important decisions under its applicable procedures.
A five-minute release check
For routine work, the full control can be condensed into six release questions:
- Source: Can I point to the evidence supporting every material statement?
- Numbers: Have I independently tied out every material figure?
- Context: Does this answer the right question for the right client and period?
- References: Have I opened and checked every important citation?
- Approval: Has the right person reviewed the evidence and conclusion?
- Record: Could the firm later show what was checked, corrected and approved?
If any answer is no, the output is not ready for release. If the item is not applicable, record why rather than leaving the field blank.
What this looks like in practice
Draft variance explanation
An AI draft says payroll expense increased by 18 per cent because of new hiring. The reviewer recalculates the percentage, ties the balances to the approved reports and checks personnel records. The calculation is correct, but the stated cause is unsupported because the increase also includes a one-off bonus.
The reviewer replaces the invented explanation with the supported components and records the correction. The value of the checklist is not that it found a bad sentence. It exposed the gap between a correct number and an unsupported reason.
Summary of technical material
A staff member uses AI to summarise a technical publication for an internal memo. The draft includes a precise paragraph reference and an unqualified conclusion. The reviewer opens the source, finds that the paragraph number is wrong and notes that the publication contains conditions omitted from the summary.
The memo is revised to include the conditions and the engagement lead reviews their application. The AI output remains a drafting aid, while the professional conclusion remains human work.
Client email containing a calculation
An AI-assisted email explains the effect of changing an assumption. The prose is clear, but a percentage was applied to the wrong base amount. The preparer independently recalculates the example, corrects the amount and asks a manager to review the final email because the result may influence a client decision.
This scenario shows why proofreading alone is insufficient. Language review and numerical review are separate controls.
How to introduce the checklist without creating paperwork theatre
Start with one workflow that already receives manager review, such as client-facing variance explanations. Add the checklist to the existing workpaper or approval route instead of creating a separate system.
For the first few weeks, collect the exceptions found during review. Group them into categories such as unsupported facts, numerical errors, missing qualifications, false citations and inappropriate data handling. Use those patterns to improve training, prompts and risk classifications, but do not remove the independent review simply because prompts improve.
Assign ownership clearly. A practice leader can own the policy, engagement leaders can set the review level, preparers can complete the evidence checks and reviewers can approve or escalate. Periodic file reviews can then test whether the control is operating in practice, rather than merely existing as a template.
Regulatory and professional context
Accounting firms often operate across overlapping professional, contractual, privacy, record-keeping and sector-specific expectations. Relevant sources may include local accounting and audit standard setters, tax authorities, privacy regulators and professional bodies. For cross-border governance, firms may also encounter frameworks or guidance associated with the GDPR, the EU AI Act, the US Federal Trade Commission, ISO/IEC 42001 or other national authorities.
Which sources apply depends on the firm’s jurisdiction, services, clients and use of AI. The checklist should therefore point reviewers towards the firm’s verified source library rather than attempting to encode one global legal answer. An editor should add current primary-source links before publication.
Methodology (Real-World, Verified)
This guide is researched against primary regulatory sources and official regulator guidance, verified as of the date shown, and written for a business with no dedicated compliance function.
Read our full methodology and independence and disclosure policy.
Related reading: our free AI acceptable use policy template and our AI governance by region.
Related reading: Best Accounting Practice Management Software and Best AI Bookkeeping Automation Tools.
Can an accountant rely on AI-generated calculations after reviewing them?
Only after the calculations have been independently checked through the firm’s normal procedures and the responsible professional is satisfied with the evidence. The AI output itself is not evidence that a figure is correct.
Does every AI-generated email need manager approval?
Not necessarily. Approval should reflect the content and consequence of the email, according to the firm’s policy. An administrative rewrite may be lower risk, while technical explanations, material figures or client advice justify a higher review level.
Should the firm keep every prompt and AI response?
A proportionate approach is more practical than treating every interaction identically. The firm should define what is retained based on risk, engagement procedures and applicable professional, contractual and legal guidance. Material outputs generally need a clearer review trail than minor wording assistance.
What happens if an AI citation cannot be verified?
Remove it from the output and find an authoritative source independently. Do not substitute another AI-generated citation without checking it. Escalate the issue if the unsupported reference affects a material conclusion.
Is proofreading enough for AI-assisted accounting work?
No. Proofreading finds wording and presentation problems, but it does not establish that numbers, sources, assumptions or conclusions are correct. Numerical tie-out, factual verification and appropriate professional review are separate steps.
Can this checklist prove that an accounting firm is compliant?
No. It is a general operational control, not a compliance assessment or substitute for professional advice. The firm should adapt it to its jurisdiction, engagements, professional obligations and approved systems.
Methodology
This checklist uses a risk-based control structure centred on evidence, numerical tie-out, context, citations, data handling, human approval and record keeping. It is designed for small and medium accounting practices without a dedicated AI governance team. Before publication, the regulatory references and suggested internal links require verification against current primary sources and the live Need to Know AI site.
Next step: Pair this printable checklist with a firm-level human review design that defines review levels, escalation routes and accountability for AI-assisted work.
The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.
Building a business case for AI in your practice before you put a review checklist in place? See how to measure the real return.
Accounting Automation ROI Calculator