Governance for AI in Regulated Practice
What is already required today, what is changing, and the specific steps that let a mid sized firm use AI with genuine confidence rather than quiet hope.
Most AI governance content is written for a general audience, and reads that way. Be transparent. Keep a human in the loop. Know your risks. None of it is wrong, and none of it tells a mid sized accounting firm what it actually needs to do this month, this quarter, and before the next regulatory update lands.
This guide takes a different approach. It separates what is already a legal requirement today from what is still emerging, names the specific bodies and documents shaping this space for your profession right now, and sets out the concrete steps a firm without a dedicated compliance department can actually put in place. The aim is not general awareness. It is the confidence to act, and to explain what you have done if you are ever asked to.
A note on scope. This guide reflects the regulatory position in the UK at the time of writing, August 2026. AI regulation in this space is moving quickly, particularly around the ICO’s forthcoming statutory code. Treat this as a solid, practical foundation, and confirm specific points against current guidance or your own legal advice before relying on them for a formal compliance submission.
What is already required today, not coming soon
Before considering anything AI specific, it is worth being clear that several relevant obligations already exist under UK GDPR and the Data Protection Act 2018, regardless of how new or experimental your use of AI feels. These are not proposals. They apply now, to any firm processing personal data through an AI system.
| Existing requirement | What it actually means for your firm |
|---|---|
| The accountability principle | You must be able to demonstrate how you comply, not just assert that you do. A verbal assurance is not accountability. A documented process is. |
| Data protection impact assessments | Processing that is likely to result in high risk to individuals, which includes a good deal of AI supported client work, requires a formal assessment before you begin, not after a concern is raised. |
| Rights around automated decisions | Individuals have rights where a decision with legal or similarly significant effect is made about them solely by automated means, including a right to meaningful human involvement. |
| Lawful basis and data minimisation | Feeding client data into an AI system still requires a proper lawful basis, and using only what is genuinely necessary, exactly as it would for any other system. |
None of this is unique to AI. What changes with AI is how easy it becomes to breach these principles without anyone intending to, simply because the system is new, unfamiliar, and often adopted faster than the paperwork around it.
What is specific to your profession right now
The FRC’s guidance on generative and agentic AI
In March 2026, the Financial Reporting Council published guidance specifically addressing generative and agentic AI in audit engagements, the first of its kind from any audit regulator globally. It sets out three categories of risk worth understanding even if your firm does not carry out audit work directly: AI producing an output that is simply wrong, an output that is correct but misunderstood or misapplied by the person using it, and a use of AI that does not comply with a firm’s own methodology or the relevant professional standards.
The guidance frames its expectations around four areas: how systems are designed and developed, how tools are certified for use before they go anywhere near client work, how staff are trained and governed around their use, and how human review and oversight is built into the process rather than assumed. Regulatory accountability for the quality of the work itself does not shift onto the tool. It remains with the firm and the individual responsible, exactly as before.
Professional body guidance reinforces the same point
Updated guidance under the Professional Conduct in Relation to Taxation framework, and ethical guidance issued by the Consultative Committee of Accountancy Bodies, both make the same central point in different words. AI can support professional work. It does not replace professional judgement, and it does not change who is accountable for the outcome.
Every piece of sector specific guidance published so far lands on the same conclusion. The tool changes. The responsibility for the outcome does not move.
What is changing, and why preparing now matters
The Information Commissioner’s Office is developing a statutory code of practice covering AI and automated decision making. A consultation on draft guidance closed in May 2026, with fuller guidance expected later in the year and the statutory code itself expected to follow in 2027.
This is genuinely still in development, and it would be inaccurate to describe it as settled law today. What is already clear, from the ICO’s own published direction of travel, is the shape it is taking: firms will be expected to demonstrate human oversight of AI assisted decisions, be able to explain those decisions to the people affected by them, and review their systems periodically for accuracy and bias, underpinned by data protection impact assessments that are genuinely prepared in advance rather than reconstructed after a complaint arrives.
Waiting for the statutory code to land before acting on any of this is a common instinct, and a poor one. Firms that build good habits now, while the requirements are still guidance rather than law, tend to find the eventual statutory version is simply a formal description of what they are already doing.
The framework that ties it together
With several sources of guidance in play at once, it helps to have a single structure to organise them around, rather than treating each new document as a separate task. ISO/IEC 42001, the international standard for AI management systems, provides exactly that structure, and it is worth understanding even if your firm never pursues formal certification.
In plain terms, it asks an organisation to do a small number of things properly: show leadership commitment to managing AI responsibly, identify and assess the risks and opportunities involved, provide the resources and training people actually need, define clear processes for how AI is used day to day, and commit to reviewing all of it on an ongoing basis rather than treating a policy document as finished once it is written.
Voluntary does not mean optional in practice. The standard does not carry legal force on its own. It is, however, rapidly becoming the reference structure regulators, clients and insurers expect to see echoed in a firm’s own governance, whether or not that firm ever seeks formal certification against it.
Six things every mid sized firm needs in place
- A named owner of AI governance. One person, not a vague shared responsibility, accountable for knowing what AI is in use across the firm and ensuring the rest of this list actually happens.
- A live register of every AI system in use. Including tools individual staff have adopted informally. Unrecorded, personal use of AI on client work is one of the most common and least discussed governance gaps in practice today.
- A proper data protection impact assessment for AI supported client work. Prepared before the work begins, specific to how the AI is actually used, not a generic template completed once and left unrevisited.
- Defined human review points before anything reaches a client. A clear, agreed moment where a person checks an AI assisted output, not an assumption that someone probably will.
- An audit trail for AI assisted decisions that affect a client. A record of what happened, when, and who reviewed it, so the firm can answer a question about any specific piece of work months later, not just at the time.
- A genuine review cycle, not a one off policy document. A fixed point, at least twice a year, to check the register, the risk assessments and the review process are still accurate, since AI use inside a firm tends to grow faster than anyone tracks it.
Where firms most often get this wrong
Treating a written policy as the same thing as a working system
A policy document that nobody actually follows day to day provides no real protection, and can arguably look worse under scrutiny than having no document at all, because it demonstrates awareness without action.
Missing the AI nobody officially approved
The AI tools causing the most exposure are rarely the ones the firm deliberately adopted. They are the ones a staff member started using quietly because it was useful, without anyone recording that client information was ever going anywhere near it.
Treating this as an IT problem rather than a firm wide one
Governance that sits entirely with IT, with no involvement from the partners actually accountable for client outcomes, tends to produce technically sound policies that nobody on the front line has actually internalised.
Assuming existing data protection policy already covers it
A general data protection policy written before AI was in regular use rarely anticipates the specific risks AI introduces, and reviewing it properly usually reveals gaps nobody had previously considered.
Waiting for the statutory code before doing anything at all
The direction of travel is already clear enough to act on. Firms who wait for a final statutory version before starting will simply be doing this same work later, under more scrutiny and with less time.
What good governance actually looks like day to day
Firms who get this right do not experience it as a heavy compliance burden sitting on top of their real work. It becomes a short, familiar set of habits. A new AI tool gets added to the register before it touches client data, not after. A junior member of staff knows exactly which piece of AI assisted work needs a senior sign off before it goes any further. When a client or a regulator asks how a particular output was reached, someone can actually answer, calmly, with a record to point to.
None of that requires a large compliance function or an expensive platform. It requires the six things set out in this guide, owned properly, and revisited regularly enough that they stay true. That is a realistic standard for a mid sized firm to hold itself to, starting well before anyone else asks you to.
