Accountancy, ICAEW supervised
You audit other people's controls. Yours get asked about too.
Accountancy has an awkward advantage here. Your firm understands control frameworks better than most clients we meet, which means the conversation is quicker and the questions are harder.
In short
For ICAEW supervised accountancy practices, EPX Intelligence builds the AI governance framework and the technical controls behind it: an AI policy that holds up under practice assurance, permissions and labelling work across the client files, and the evidence pack a client questionnaire or an audit monitoring visit will ask for. Where you want Copilot, the client confidentiality work comes before the licences.
What is driving it
Three pressures, and one of them is your own clients.
The third is the one firms mention last and worry about most.
Practice assurance and audit monitoring
If AI touches audit work, working papers or judgements, it becomes a quality control question. Your monitoring visit will reasonably ask how it is governed and who reviewed the output.
Client confidentiality across the file estate
You hold the financial records of every client you serve. An ungoverned rollout across that estate is a confidentiality exposure long before it is an efficiency gain.
Your clients are asking you
They assume you know, because you advise them on everything else. Being able to answer well is a commercial opportunity rather than only a compliance chore.
In your language
You already know what good control documentation looks like. That makes this faster, and it raises the bar on us.
Most practices we speak to can write the policy themselves. What they cannot easily do is the estate work underneath it, and that is where we are useful.
The specific problem is your client file structure. An AI tool that retrieves across your document estate will happily surface one client's numbers into another client's engagement if the permissions allow it. In a practice holding financial records for hundreds of clients, that is the risk that matters, and fixing it is technical work rather than a policy paragraph.
The second is the judgement question. Where AI touches working papers or anything approaching an opinion, the control is a named human reviewing and owning the output, evidenced. Not a disclaimer.
General information rather than regulatory advice. Your compliance principal owns the position; we build what sits underneath it.
What you get asked, and what answers it
The question, and the document behind the answer.
Every row is something a client, an insurer or an assessor has put in writing to a firm like yours. The right hand column is what we produce so the answer is a document you can attach.
| What you are asked | What answers it |
|---|---|
| How does your firm govern the use of artificial intelligence? | A written AI policy and acceptable use standard, with an approved tool list, mapped to the control set behind it. |
| What prevents one client's information reaching another client's work? | The client file permissions remediation record, sensitivity labelling and the retrieval test evidence. |
| Is AI used in audit work, and if so how is it controlled? | The AI system inventory scoped to engagement types, with the review checkpoints and sign off evidence. |
| Who reviews and owns AI assisted output? | Named human accountability recorded per workflow, so a named person answers for the judgement. |
| Who is accountable for AI in the firm, and how is it reviewed? | Named ownership in the management system, plus the internal audit and management review cycle covering it. |
| Are you certified to any AI standard? | Your current position stated accurately, plus the ISO/IEC 42001 readiness plan and its target date if you are pursuing one. |
Straight answers
Questions from firms like yours
Can we use AI in audit work?
Accountancy firms do use AI in audit work, and the controls around it are what matter. Where AI touches working papers or anything approaching a judgement, you need a named human reviewing and owning the output, evidenced, plus the tool on an approved list with an assessment behind it. General information rather than regulatory advice, and your compliance principal should form the view on scope.
Can we use Copilot without exposing client information?
Yes, an accountancy practice can use Microsoft 365 Copilot without exposing client information, provided the work is done in the right order. Copilot shows a user whatever they already have permission to see, so any loose permissions across your client file estate become visible on day one. For a practice holding financial records for hundreds of clients, that is the risk worth taking seriously. The permissions and labelling work comes before the licences.
We are a 50 person practice. Are we too small?
A 50 person practice is very unlikely to be too small for EPX Intelligence. Most of our clients are larger, but that describes who has found us rather than a rule. If a client has asked you how AI is governed, or a monitoring visit is coming, the size of the practice is not what decides it. If the right answer is something lighter, EPX IT sells a pared down AI Foundations engagement directly.
Our clients keep asking us about AI. Can you help us answer them?
EPX Intelligence can help an accountancy practice answer its own clients' AI questions up to a clear line. We can get your own house in order and explain what we did, which is a genuinely useful thing to be able to describe to a client. We are not going to help you resell AI advice to your client base, because that is your judgement to make rather than ours.
Will you work alongside our IT provider?
Yes, EPX Intelligence works alongside your existing IT provider and expects there to be one. This is bought standalone and it is not a route into a managed IT contract.
The next step is a conversation
Bring us the question a client asked you.
Thirty minutes, no proposal attached. Bring the AI question a client or a monitoring visit has actually put to you, and we will tell you honestly what it would take to answer it properly.