Why this matters now
Staff may be using ChatGPT, Copilot or AI features in existing software before the firm has agreed how those tools should be used. For accountancy, legal and financial services firms, that raises questions about client confidentiality, the accuracy of work and professional responsibilities.
AI governance sets out which uses are permitted, which information staff may enter and who is responsible for checking the work.
The risks specific to professional firms
The first concern is confidentiality. Pasting client information into a public, consumer AI tool may place it outside the firm’s control and, depending on the tool, outside any agreement you would normally expect when handling client data. For a firm that holds confidential or regulated information, that is a serious exposure.
The second is accuracy. AI tools produce fluent answers that are sometimes wrong. Where output informs advice, accounts or legal work, an unchecked answer is a professional risk, not just a technical one.
The third is regulatory and reputational. Your regulator (for example the SRA, ICAEW or FCA) expects confidentiality, competence and proper supervision regardless of the tools involved. Work produced with AI tools still needs appropriate review and supervision.
A practical starting point
A starting point is to:
- decide which AI tools are approved, and which must not be used with client or firm data
- give staff a short, plain statement of what they can and cannot put into AI tools
- be clear that AI output must be checked by a competent person before it informs advice or client work
- prefer tools that keep data within your existing Microsoft 365 or other trusted environment over public consumer tools
- make sure someone owns the topic, reviews it as the tools change and answers questions as they come up
How this connects to the rest of your security
AI governance is part of information governance, not separate from it. The same controls that protect client data generally, such as access management, sensitivity labelling and Microsoft 365 configuration, also help reduce the risks of adopting tools such as Copilot. Firms working towards Cyber Essentials or IASME Cyber Assurance already have much of the foundation in place.
How Be Secure Cyber can help
We can help your firm agree an approved tools list, write a usage policy and define the checks staff need to carry out, as a one-off piece of work or as part of ongoing vCISO support . If you are considering Microsoft 365 Copilot, see Is Microsoft 365 Copilot safe for business use? .
Speak to us about AI governance.