Practical AI and SaaS for Business

Professional Ethics and AI for Accountants

A plain-English guide to professional ethics and AI for accountants: how established ethical principles apply to AI-assisted work, and how to turn them into practical review and approval controls.

Last verified: 28 July 2026. References checked against current legislation.

Part of the AI for Accounting Firms and Bookkeeping Practices: A Practical Guide Return to the industry centre →
Editorial Perspective

You are a practice principal watching AI spread through the firm one task at a time. The pressure is not simply choosing tools, it is knowing who remains responsible when an AI-assisted answer is wrong or client information is mishandled. This guide gives you a plain-English framework for building internal guidance around professional ethics. You do not need technical expertise to start.

This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.

If AI use in your accounting practice has grown faster than the rules around it, that is a common management problem, not evidence that you have already failed. This guide explains professional ethics and AI for accountants, how established ethical principles apply, and how to turn them into practical review and approval controls.

In short: AI can assist with accounting work, but it does not take professional responsibility away from the accountant or firm. A sound internal approach connects each AI use to competence, integrity, objectivity, confidentiality, professional behaviour and appropriate human review. The exact professional and legal requirements depend on your jurisdiction, role and engagement.

This is general information, not legal, accounting or professional-conduct advice. Consult the current code adopted by your professional body and obtain qualified advice where the application to a particular engagement is unclear.

The Real Issue Is Responsibility, Not the Tool

Professional ethics do not become a separate subject simply because software helped produce an answer. The important question is whether the people responsible for the work can still explain, assess and stand behind the process and its result.

Consider a practice principal whose staff have individually started using general-purpose AI tools. One employee drafts client emails with AI, another summarises technical material, and another experiments with extracting information from uploaded documents. There is no shared understanding of which information may be entered, how outputs should be checked, or who approves client-facing work. After adopting a common ethics framework, the practice can classify those uses, set review expectations and identify work that should not enter an unapproved tool. Staff still use judgement, but they no longer have to invent the boundaries separately for every task.

The objective is not to eliminate every risk or prohibit every experiment. It is to make responsibility visible before an AI-assisted output reaches a client, a file, a regulator or another decision-maker.

IESBA Provides a Global Professional Reference Point

The International Ethics Standards Board for Accountants, or IESBA, publishes the International Code of Ethics for Professional Accountants, including International Independence Standards. Its Code is an important global reference, but it is not automatically the binding rule in every country or for every accountant.

Local professional bodies, regulators and lawmakers may adopt, adapt or supplement international standards. Accountants therefore need to check the current rules connected to their jurisdiction, membership, licence, service and engagement. The IESBA official website is the appropriate starting point for the current international material.

IESBA's framework is useful for AI because it is based on principles rather than a list of approved technologies. The familiar questions about honesty, bias, competence, care and confidentiality remain relevant even when the software changes.

Five Ethical Principles to Apply to AI-Assisted Work

The IESBA Code identifies five fundamental principles for professional accountants. These principles provide a practical set of lenses for reviewing AI use, although the precise interpretation and enforceability should be confirmed against the current applicable Code.

PrinciplePlain-English meaningQuestions for AI use
IntegrityBe straightforward and honest in professional and business relationships.Is the firm giving a misleading impression about how an answer was produced, reviewed or supported?
ObjectivityDo not allow bias, conflicts or undue influence to override professional judgement.Could automation bias, poor training data or pressure to save time be affecting the conclusion?
Professional competence and due careMaintain relevant knowledge and act diligently under applicable standards.Does the user understand the tool well enough to recognise unsupported, incomplete or outdated output?
ConfidentialityProtect information acquired through professional and business relationships.What information is being entered, where does it go, who can access it and under what terms?
Professional behaviourFollow applicable laws and regulations and avoid conduct that discredits the profession.Would the firm be comfortable explaining this use to the client, professional body or relevant authority?

These are not five independent tick boxes. One AI workflow may raise several issues at once. For example, uploading a client document could create a confidentiality concern, while accepting the resulting summary without checking it could also raise competence, due-care and integrity concerns.

Human Responsibility Remains Central

An AI system can generate text, rank information or suggest a conclusion. It cannot assume the accountant's professional accountability, understand every engagement condition, or decide whether reliance is appropriate in a particular jurisdiction.

Human review needs to mean more than clicking approve. The reviewer should have enough knowledge, context and authority to challenge the output. If nobody in the process can explain the source, assumptions or limitations behind a material conclusion, the workflow may not support meaningful professional judgement. The level of review can vary with risk: a low-risk internal rewrite may justify a lighter check than an AI-assisted analysis influencing tax advice, an audit conclusion, a valuation or a credit decision. The firm can define those levels in advance instead of relying on staff to judge every situation from scratch.

It is also helpful to separate assistance from delegation. Software may assist a competent person by producing a draft or organising information. Treating its output as the decision itself can obscure who assessed the evidence and who is prepared to defend the result.

How Ethical Threats Can Appear in Practice

The IESBA conceptual framework asks professional accountants to identify, evaluate and address threats to compliance with the fundamental principles. AI may create new versions of familiar threats rather than an entirely new ethics category.

Over-Reliance and Self-Review

A staff member may use AI to prepare a calculation, narrative or analysis and then perform only a superficial check of the same output. The apparent polish of the response can make the review feel more reliable than it is. A stronger control separates generation from verification: the reviewer can return to authoritative records, recalculate material figures, or use an independent source rather than asking the same system to confirm its original answer.

Automation Bias and Objectivity

Automation bias is the tendency to favour a computer-generated suggestion because it appears neutral or sophisticated. AI outputs can still reflect incomplete inputs, embedded assumptions or patterns that are unsuitable for the decision at hand. This matters when software ranks transactions, flags anomalies, evaluates applicants or suggests which evidence deserves attention. A practice can ask what information shaped the recommendation, which cases could be disadvantaged, and whether a qualified person can override it.

Commercial Pressure and Intimidation

A deadline, utilisation target or instruction from a senior colleague may encourage staff to accept an AI output without adequate review. The ethical concern is not resolved simply because the tool produced the mistake. Clear escalation paths help staff pause work without having to argue about the technology itself, so they can report that the evidence is inadequate, the data is too sensitive, or the reviewer lacks the competence needed for approval.

Conflicts, Advocacy and Familiarity

AI can make it easier to produce persuasive material quickly. That can amplify existing risks where an accountant is expected to remain objective but is also under pressure to support a preferred client or management position. The relevant question is whether the workflow helps examine evidence or merely produces a more convincing version of a predetermined conclusion. Existing conflict and independence procedures should therefore cover AI-assisted work rather than treating it as an unrelated technology matter.

Confidentiality Starts Before Anyone Enters Data

The safest time to decide whether client information belongs in an AI system is before it is pasted, uploaded or connected. Once data has left an approved environment, deleting the visible prompt may not answer questions about retention, access, reuse or subprocessors.

For each approved tool, the firm can document the permitted data categories, account type, access controls, retention settings and contractual terms. Public or personal accounts should not be assumed to have the same protections as an organisation-managed service. De-identification can reduce risk, but removing a client name is not always enough: a combination of transaction details, industry, location and unusual circumstances may still reveal the person or entity involved. Confidentiality also includes generated output. An AI response may reproduce sensitive information from the prompt, place it in a new document, or make it easier to forward outside the original engagement team.

A Practical Ethics Framework for a Small Accounting Practice

A proportionate framework does not need to begin as a lengthy policy. It needs to give staff clear answers about approved uses, review, information handling and escalation.

1. Record current AI uses. Ask teams which AI functions they already use, including features embedded in existing accounting, office and communications software. Record the task, data involved, output destination and person responsible. This is a discovery exercise, not an amnesty trap.

2. Classify work by consequence. Group uses by the possible effect of an error or disclosure, distinguishing low-risk internal assistance, controlled professional work and restricted uses requiring specialist approval. Avoid classifying risk solely by the name of the tool.

3. Assign a human owner. Every material workflow needs a named role responsible for the result. Ownership should remain clear when several people use the system or when the AI function is built into ordinary software. The owner needs appropriate authority, competence and access to evidence for the review expected of them.

4. Define what review means. Set review methods that match the risk, such as checking source records, recalculating figures, comparing against current authoritative guidance, testing exceptions and recording material assumptions. Staff need to know which evidence to inspect and when a second qualified reviewer is appropriate.

5. Set information boundaries. Create a short list of information that may be used in approved systems and information that requires further approval or must remain outside them, including personal data, client-confidential material, credentials, commercially sensitive records and engagement-specific restrictions. Also document approved accounts and access methods.

6. Check competence, not just access. Being able to open a tool does not establish competence to use it for professional work. Training should cover what the system can and cannot establish, common failure patterns, verification methods and the firm's escalation process. Competence also includes knowing when not to use AI.

7. Preserve an appropriate record. For higher-consequence work, record how AI contributed, which sources supported the conclusion, who reviewed it and what changes were made. Record design should reflect applicable professional, contractual, privacy and records-management requirements in the relevant jurisdiction.

8. Review incidents and near misses. Treat incorrect outputs, unintended disclosures and unexplained recommendations as learning signals. Examine the workflow, approval process and conditions that made the problem possible, not simply who entered the prompt.

Global Rules Sit Alongside Professional Ethics

Professional ethics is only one part of the risk picture. Depending on the location and use, privacy, consumer protection, employment, discrimination, records and sector-specific rules may also be relevant.

For example, organisations handling personal data may need to consider the EU General Data Protection Regulation where it applies. Certain AI activities connected to the European Union may also fall within the EU AI Act. In the United States, the Federal Trade Commission publishes business guidance relevant to deceptive or unfair practices.

ISO/IEC 42001 is an international management-system standard for organisational AI governance. It may offer useful governance structure, but using it does not by itself establish compliance with professional rules or local law. Review the current information through ISO and obtain advice on its relevance before treating it as a requirement.

A global article cannot determine which combination applies to a particular firm. The practice should map each AI use to the locations of the firm, client, data and affected people, then consult its professional body or advisers about material uncertainty.

Questions to Put in an Internal AI Review

Use these questions to organise discussion, not to certify that a workflow is compliant: what professional task is the system assisting; who remains accountable for the output; what could happen if the answer is wrong, incomplete or disclosed; which fundamental principles could be affected; does the user have the competence to challenge the result; which records or authoritative sources will be used for verification; what information enters the system, and under which contractual terms; could bias, a conflict or commercial pressure affect the conclusion; is the use consistent with client instructions and engagement terms; when should the work stop and be escalated; what evidence of review should be retained; and which local professional body, regulator or adviser can resolve uncertainty.

The output of this review might be approval, approval with safeguards, a limited pilot, or a decision that ordinary software and human review are the better answer. Ethical AI governance includes the option not to automate.

When to Pause and Seek Qualified Advice

Pause when the firm cannot establish who is responsible, what information the tool receives, or how a material output can be independently checked. These are governance gaps, not minor technical details.

Advice may also be appropriate when AI affects an audit or assurance conclusion, independence, regulated advice, employment decisions, vulnerable people, cross-border personal data or a contractual confidentiality restriction. The correct source may be the firm's professional body, legal adviser, privacy specialist, insurer, auditor or another relevant authority.

Methodology (Real-World, Verified)

This guide is researched against primary regulatory sources and official regulator guidance, verified as of the date shown, and written for a business with no dedicated compliance function.

Related reading: our AI governance by region.

Can an accountant rely on an AI-generated answer?

Not solely because the answer looks complete or confident. The appropriate level of reliance depends on the task, evidence, consequences and applicable professional standards. A competent person should be able to verify material content and take responsibility for the conclusion.

Does using AI breach client confidentiality?

Not automatically, but entering client information can create confidentiality and privacy risks. The answer depends on the information, system, contractual terms, access, retention and rules applying to the engagement. Check those conditions before information is submitted.

Does an accountant need to tell clients that AI was used?

There is no single global answer for every service or jurisdiction. Disclosure may depend on professional rules, engagement terms, client expectations, materiality and how the system affected the work. Seek guidance from the relevant professional body where the position is unclear.

Who is responsible when AI-assisted accounting work is wrong?

AI does not provide a simple transfer of professional accountability. Responsibility will depend on the roles, engagement and applicable law or professional standards, but the firm should identify a human owner and review process before relying on material output.

Is banning public AI tools enough?

Usually not as a complete governance approach. AI functions may already exist inside approved office and accounting software, while staff may seek unofficial alternatives if the permitted route does not meet their needs. A clearer response combines discovery, approved uses, information boundaries, training and escalation.

Find official guidance for your region

Requirements vary by jurisdiction. This article provides general information only. Consult your regional authority or a qualified professional for advice specific to your situation.

The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.

Want to see how accounting firms are actually applying AI in practice before you build internal guidance around it?

See How Accountants Are Using AI

Continue your Accounting & Bookkeeping journey

Next Using AI in Management Reporting Workflows
Centre Return to the AI for Accounting Firms and Bookkeeping Practices: A Practical Guide