Template · Free · Updated September 2026

AI acceptable-use policy template for professional-services firms

A complete, editable policy written for firms that use AI: CPA and accounting firms, law firms, insurance agencies, RIAs, healthcare practices and consultancies. Copy it, replace the bracketed fields, delete what does not apply, and have leadership sign it. It is the first control every regulator, carrier and client questionnaire asks about, and a gating control in the AboveBoard Standard.

Before you start: three decisions

A policy is only as good as the three decisions behind it. Make them first; the template fills in around them.

  1. Which tools are approved. Ask every department head which AI tools their team has used in the last 90 days, including personal accounts. Fifty-seven percent of employees say they hide their AI use from their employer (KPMG / Univ. of Melbourne, Apr 2025, n=48,000), so ask without blame. Then pick the tools you will license on firm-managed accounts with enterprise terms that prohibit training on your data.
  2. What may never go in. Write one plain sentence for your firm. For a CPA firm: no returns, Social Security numbers or client financials in any tool not on the approved list. For a law firm: nothing privileged or confidential. For a practice: no protected health information. Roughly half of privacy and security professionals admit entering non-public data into generative AI tools (Cisco, Apr 2025, n=2,600); the sentence exists so nobody has to guess.
  3. Who owns it. Name one senior person with authority to switch off a tool. Not a committee.

The policy

Everything in brackets is yours to replace. Clauses marked "optional" can be deleted. This template is provided for information; have counsel review the final version for your jurisdiction and industry.

[Firm Name] Artificial Intelligence Acceptable Use Policy

Version [1.0] · Approved by [Managing Partner / Board / Executive Committee] on [date] · Owner: [Name, Title] · Next review: [date]

1. Purpose

This policy sets out how [Firm Name] ("the Firm") and its people may use artificial intelligence tools, including generative AI, in the Firm's work. Its purpose is to let the Firm benefit from AI while protecting client confidentiality, the accuracy of our work, our professional and legal obligations, and the trust of our clients, regulators and insurers.

2. Scope

This policy applies to all partners, owners, employees, temporary staff, interns and contractors of the Firm ("Personnel"), on any device and any account, whenever they perform work for the Firm or handle Firm or client information. It covers AI features embedded in software the Firm already uses (for example, document, email, meeting, research, practice-management and [industry-specific system] tools) as well as standalone AI applications.

3. Definitions

  • AI tool: any software that generates, summarizes, transcribes, classifies, predicts or recommends content or decisions using machine learning or large language models, whether standalone or embedded in another product.
  • Approved AI tool: an AI tool listed in the Firm's Approved AI Tools Register (Schedule A), accessed through a Firm-managed account under terms the Firm has reviewed.
  • Client information: any information received from or about a client or prospective client, including information protected by professional confidentiality rules, privilege, [IRC section 7216 / HIPAA / Regulation S-P / state insurance privacy law] or contract.
  • Personal information: information that identifies or could identify an individual, including employees and applicants.
  • AI-assisted work product: any document, analysis, communication, filing, code or decision in which an AI tool contributed content or a recommendation.
  • AI incident: any event in which an AI tool exposes information it should not, produces an output that causes or nearly causes harm, error or embarrassment, is used in breach of this policy, or is affected by a vendor security event.

4. Roles and accountability

  • The AI Owner ([Name, Title]) is accountable for this policy, maintains the Approved AI Tools Register and the AI inventory, approves or refuses new tools and use cases, may suspend any tool or use at any time, and reports to [the partners / the board] at least quarterly.
  • [The partners / the board / the executive committee] approve this policy, review AI risk and performance at least quarterly, and record that review in minutes.
  • Managers and engagement leaders ensure their teams follow this policy, that AI-assisted work product is reviewed as required in section 8, and that concerns are escalated.
  • All Personnel complete required training, acknowledge this policy, use only Approved AI tools for Firm work, and report AI incidents promptly.
  • [IT / the managed service provider] provisions Approved AI tools on Firm-managed accounts with single sign-on and multi-factor authentication, configures retention settings, and [blocks or monitors] unapproved tools where technically feasible.

5. Approved AI tools

Personnel may use only Approved AI tools for Firm work. The Approved AI Tools Register (Schedule A) lists each tool, the account type, the permitted uses, the data classifications permitted, the owner and the date the vendor's terms were last reviewed. A tool is added only after the AI Owner has confirmed, in writing, that the vendor's terms prohibit training on the Firm's inputs, state retention and deletion periods, identify sub-processors, and provide confidentiality and security commitments appropriate to the data involved [and, for healthcare, that a business associate agreement is in place]. Personal, free or consumer accounts may not be used for Firm work. Requests for new tools go to the AI Owner using the [request form / email address].

6. Prohibited uses

Personnel must not:

  • enter client information or personal information into any AI tool that is not an Approved AI tool, or into an Approved AI tool beyond the data classifications it is approved for;
  • rely on AI output as a final answer, citation, calculation or fact without verification as required in section 8;
  • present AI-generated content as the Firm's professional judgment where a client, court, regulator or professional body would reasonably expect that judgment to be a person's;
  • use AI tools to record, transcribe or analyze conversations with clients, patients or colleagues without the notice or consent required by law and by section 9;
  • use AI tools to make or materially influence decisions about individuals' employment, credit, insurance, housing, healthcare, education or legal rights unless the use has been approved by the AI Owner with the notices, explanations and human review that applicable law requires;
  • use AI tools to create content that is deceptive, discriminatory, defamatory, infringing or otherwise unlawful, or to circumvent Firm security controls;
  • make claims about the Firm's AI capabilities in marketing, proposals or client communications that have not been reviewed under section 9.

7. Client and personal data rules

Information is classified as follows for AI purposes: Public (may be used in any Approved AI tool); Internal (may be used in Approved AI tools on Firm accounts); Confidential and client information (may be used only in Approved AI tools expressly approved for that classification in Schedule A, and only as necessary for the engagement); Restricted ([Social Security numbers, tax return information, protected health information, account numbers, privileged material, material non-public information]: may not be entered into any AI tool unless Schedule A expressly permits it for that tool). Where a client's engagement terms, a privacy notice or applicable law require notice or consent before AI processing, the engagement leader obtains it before use and records it in the matter file. Prompts, outputs and AI-generated drafts are subject to the Firm's retention schedule; Personnel must not disable retention controls the Firm has configured.

8. Human review and quality

A qualified person, named in the record, reviews and takes responsibility for all AI-assisted work product before it is delivered to a client, filed with a court or regulator, published, or placed in a permanent file. Review includes verifying every factual statement, citation, calculation and quotation against original sources; checking for confidentiality breaches, bias and completeness; and confirming the output reflects the Firm's professional judgment. [For legal work: no citation is filed unverified. For accounting work: AI output is not audit evidence and is not relied upon as such. For clinical work: an AI-drafted note is not part of the record until a clinician has reviewed and signed it.] The AI Owner or delegate samples AI-assisted work product at least [quarterly], records results, and tracks corrective actions. AI-assisted work product is identified as such in the Firm's [document management / matter / engagement] system.

9. Disclosure and communications

The Firm discloses its use of AI to clients through [engagement letters / terms of business / statements of work] and a published AI statement, and honors client instructions that restrict AI use, which the engagement leader records in the matter file. Personnel disclose AI use to courts, regulators and professional bodies where their rules require it; the AI Owner maintains the list of such requirements. Where the Firm uses AI to communicate with clients or patients directly, or to record or transcribe conversations, the notice required by law and by this policy is given [and, where required, consent obtained] before use. Only [designated persons] may make statements about the Firm's AI capabilities in marketing, proposals, RFP responses or to the media, and every such statement is reviewed for accuracy and substantiation before publication.

10. Incidents

Personnel report any actual or suspected AI incident immediately to [the AI Owner / the incident email / the hotline], without fear of retaliation for good-faith reports. The Firm's incident response plan applies, including its AI section, which covers containment, assessment, notification of affected clients and any regulator or insurer where required, correction of the record, and documentation. The AI Owner maintains a log of AI incidents and near-misses and reports it to [the partners / the board] at least quarterly.

11. Training and acknowledgment

All Personnel complete AI awareness training within [30 days] of joining and at least annually thereafter. Personnel who review AI-assisted work product complete reviewer training. [Partners / board members] complete AI governance training annually. All Personnel sign the acknowledgment in Schedule B on joining, on each material revision of this policy, and at least annually. Training completion and acknowledgments are recorded by [HR / the AI Owner].

12. Monitoring

The Firm may monitor use of Firm systems and accounts, including AI tools, to the extent permitted by law, and may use technical controls to restrict unapproved tools. The AI Owner reviews the Approved AI Tools Register and vendor terms at least [twice a year] and monitors vendors for changes in terms, models, security notices and outages. Changes to prompts, templates and automated workflows that affect client work are approved, tested and logged.

13. Enforcement

Breaches of this policy are handled under the Firm's disciplinary procedures and may result in withdrawal of AI tool access, disciplinary action up to and including termination, and, for contractors, termination of engagement. Personnel who report their own good-faith mistakes promptly will have that fact taken into account.

14. Review

The AI Owner reviews this policy at least annually and whenever a new tool, law, professional guidance, client requirement or incident warrants it, and maintains a version history recording each change, its date and its approver. [The partners / the board] approve each revision.

Schedule A: Approved AI Tools Register

Tool · Vendor · Account type (enterprise / business) · Permitted uses · Permitted data classifications · Owner · Terms reviewed on · Training-on-data prohibited (Y/N) · Retention period · BAA or DPA on file (Y/N) · Notes.

Schedule B: Acknowledgment

See below.

Acknowledgment form

Acknowledgment of the [Firm Name] AI Acceptable Use Policy

I confirm that I have received and read the [Firm Name] Artificial Intelligence Acceptable Use Policy, version [1.0], dated [date], and that I have completed the AI training required for my role.

I understand that: I may use only Approved AI tools, on Firm-managed accounts, for Firm work; I may not enter Restricted information into any AI tool, or client or confidential information into any tool not approved for it; I am responsible for verifying any AI-assisted work product I deliver, file or place in a record; I must give any notice or obtain any consent the policy requires before using AI to record, transcribe or communicate with clients or patients; I must report AI incidents immediately; and breaches may result in loss of access and disciplinary action.

I agree to comply with the policy and with any revisions communicated to me.

Name: ____________________   Role: ____________________   Signature: ____________________   Date: ____________

Customizing by industry

Which AboveBoard controls it satisfies

Adopted, approved with a date and acknowledged by staff, this policy takes you to level 3 on G1 (written AI policy) and, with the records, on W3 (staff acknowledgment). Sections 7, 8 and 9 create the written requirements that D1 (data classification), O1 (human review before client-facing output) and T1 (engagement terms address AI) are scored on; sections 4, 5, 10 and 9 support G2 (named owner), D2 (approved tools), O3 (AI in the incident plan) and T6 (staff communications guidance). Two of those, G1 and O1, are gating controls: no firm is listed in the registry at any level with a zero on them.

A policy proves that rules exist. Evidence proves they operate. The reviewer will ask for the approval date, the acknowledgment records, Schedule A with the vendor-terms review dates, a sample review sign-off and the training completion report. The 40-point checklist lists the evidence for every control; the Standard shows all four levels.

Questions

How to write an AI policy?

Start from what is actually in use: inventory the tools, decide which are approved, and write the one rule about client data that matters most. Then fill in a template that covers purpose, scope, definitions, roles, approved and prohibited uses, data rules, human review, disclosure, incidents, training, monitoring, enforcement and review cadence. Have leadership approve it with a date, collect signed acknowledgments, and put a review date in the calendar. A first version takes an afternoon.

What should be included in an AI policy?

Purpose and scope; definitions; who is accountable; the approved-tool list and how tools get added; prohibited uses; what client, personal and confidential data may and may not be entered; the human-review requirement before AI output reaches a client, court, regulator or file; disclosure to clients and others; how to report an AI incident; training and acknowledgment requirements; monitoring; consequences of breach; and how often the policy is reviewed.

Is there a template for creating an AI corporate policy?

Yes. The template on this page is a complete AI acceptable-use policy written for professional-services firms, with an acknowledgment form and notes for customizing it by industry. Copy it, replace the bracketed fields, and delete what does not apply.

Why is it important to establish generative AI usage policies?

Because staff are already using generative AI and will not tell you unless you ask: 57% of employees say they hide their AI use from their employer, and 66% rely on AI output without checking it (KPMG / Univ. of Melbourne, Apr 2025). A written policy is also the first thing every regulator, insurer and client questionnaire asks for, and it is a gating control in the AboveBoard Standard: no firm is listed at any level without one.

Which AboveBoard controls does this template satisfy?

Adopted, approved and acknowledged, it satisfies G1 (written AI policy) and W3 (staff acknowledgment), and it establishes the written requirements behind D1 (data classification), O1 (human review before client-facing output) and T1 (engagement terms address AI). It also supports G2, D2, O3 and T6. The policy alone does not prove those controls operate; the evidence does.