What IRS AI Guidance Now Requires Your CPA Firm to Have in Writing

September 15, 202611 min readBy The Crossing Report

Most CPA firms heard about Alert 2026-19 as a billing issue. The IRS Office of Professional Responsibility said you cannot keep billing eight hours when AI got it done in two. That story traveled.

The second half of the same guidance got less attention. Alert 2026-19 also established four operational requirements that any firm using AI with client data must now be able to demonstrate. Not describe — demonstrate, with documents, if asked.

Most small CPA firms do not have those documents. That is the compliance gap the OPR left open when they issued the guidance in June 2026.

This post covers what the four IRS AI guidance accounting firm requirements 2026 actually require, what counts as adequate documentation for each, and a minimal-viable policy structure any small firm can implement in a day.

The 4 IRS AI Guidance Accounting Firm Requirements 2026

Alert 2026-19 established explicit obligations in four areas:

  1. Written AI use policy — a documented framework for how AI is used in the firm
  2. Staff training documentation — records showing staff have been trained on the policy
  3. Secure data handling protocols — a defined process for which tools handle client data and under what conditions
  4. Third-party tool vetting — a documented pre-approval process before any AI tool touches client data

The common thread: each obligation requires something you can hand to an OPR investigator. A culture of "we're careful about this" is not evidence. A dated document is.

1. Your Written AI Use Policy (What It Must Say)

The OPR does not specify a required format or minimum length. What Alert 2026-19 requires is that the policy exist in writing and cover the material risk areas — and that staff can be trained on it.

For a small CPA firm, a written AI use policy needs to answer five questions in plain language:

Which AI tools are approved for use in client work? Name them. Not categories — the actual tools. "Cloud-based AI tools with data agreements" is not a policy. "Thomson Reuters CoCounsel, Intuit Lacerte AI, and Microsoft 365 Copilot (Enterprise)" is a policy.

What client data can be processed by which tools? This is the critical permission boundary. The policy needs to specify which categories of client information — tax returns, financial statements, SSNs, EINs, account numbers — can be processed by each approved tool, and under what conditions.

What is prohibited? Name the prohibited uses explicitly. "Uploading client financial data to ChatGPT free, Claude.ai free, or any general-purpose AI tool without a signed data processing agreement" is the language the OPR's guidance implies. Writing it out removes ambiguity for staff.

What review is required before AI-generated work product is delivered? The professional judgment standard under Circular 230 has not changed. AI output used in a client deliverable must be reviewed by a licensed practitioner. The policy needs to say this explicitly, because staff will assume efficiency means less review.

What must be disclosed to clients about AI use? Reference your engagement letter AI disclosure here. Staff should know that every engagement letter includes this disclosure and why.

A small firm's written AI policy does not need to be long. Two pages covers everything above. The goal is specificity, not length.

2. Staff Training Documentation (What Counts as Adequate)

The OPR's Alert 2026-19 training obligation is about the paper trail, not the content of the training. What you train on matters, but what matters for compliance is whether you can prove the training happened.

Adequate staff training documentation has three components:

A training record for each staff member. Name, date, topics covered, and a signature or digital acknowledgment confirming they read and understood the policy. A training record that says "AI Policy Training — Q3 2026 — all staff" is not adequate. Individual records are.

A defined training curriculum. The curriculum does not need to be elaborate. It needs to cover: (1) which AI tools are approved and why, (2) what client data can and cannot be processed by which tools, (3) how to handle AI-generated output before using it in client work, and (4) what to do when uncertain — escalation path, not judgment call.

A cadence and trigger for updates. Annual training is the floor. You also need training triggered by: adding a new AI tool, a change in a vendor's data handling terms, or a staff incident involving AI. Document the trigger and the training event separately.

The format can be simple. A shared document with a table — staff name, date, version of policy reviewed, acknowledgment checkbox — is enough. The point is that it exists and is current.

3. Secure Data Handling Protocols (Which Tools Are Covered)

The data handling obligation in Alert 2026-19 flows from Circular 230's confidentiality provisions. The OPR made explicit what was previously implied: using a consumer AI tool that processes client financial data without a signed data processing agreement is a confidentiality compliance issue.

The practical standard: a signed data processing agreement between your firm and the AI vendor is required for any tool that processes client financial data.

What counts as client financial data? Tax returns, financial statements, bookkeeping records, SSNs, EINs, bank account numbers, payroll data, compensation records, and personally identifiable financial information of any kind. If you would not post it publicly, it is client financial data.

Which tools have signed DPAs available?

Tools that typically have signed DPAs at their enterprise or paid professional tiers:

  • Thomson Reuters CoCounsel (enterprise)
  • Wolters Kluwer CCH Axcess AI (enterprise)
  • Intuit Tax products with enterprise data agreements
  • Microsoft 365 Copilot (enterprise M365 subscription with signed DPA)
  • Karbon AI (enterprise tier)

Tools that do not have signed DPAs at free or consumer tiers, and are explicitly outside the safe zone for client data:

  • ChatGPT free plan (no DPA available)
  • Claude.ai free plan (no DPA available)
  • Google Gemini without enterprise Workspace contract
  • Any general-purpose consumer AI app without a vendor-signed data agreement

The protocol your firm needs in writing:

A one-paragraph written protocol that states: where client financial data can be processed, what tools are approved for that purpose, what tools are prohibited for that purpose, and what happens when a staff member uses an unapproved tool (the incident reporting path).

This protocol becomes Section 3 of your written AI policy. It also becomes the reference point for tool vetting decisions.

4. Third-Party Tool Vetting Before Use (The Approval Standard)

Before any new AI tool touches client data at your firm, Alert 2026-19 implies a pre-approval process. The OPR did not define this process in detail — but it identified the questions a practitioner must be able to answer about any tool they use with client data.

A tool vetting process has two parts: the evaluation criteria and the documentation.

Evaluation criteria — three questions your firm must answer before approving any AI tool for client data:

Question 1: Is a signed data processing agreement available? This is the gate question. If the vendor cannot provide a DPA, the tool is not approved for client financial data. Full stop. Move on.

Question 2: Does the vendor's terms of service permit training on submitted data? Some AI vendors train their models on content you submit unless you opt out — and the opt-out exists only at paid tiers. For client data, you need a hard contractual prohibition on training use, not a preference setting.

Question 3: Can the vendor provide a SOC 2 Type II report? This is evidence that the vendor's security claims have been independently audited. Free tools typically cannot provide this. Enterprise tools from major vendors typically can.

Documentation — what to record for each tool:

A single vetting record for each tool your firm approves. It should contain:

  • Tool name and vendor
  • Date of review
  • Who conducted the review
  • DPA status: available and signed / not available
  • Training data prohibition: confirmed in writing / not confirmed
  • SOC 2 availability: provided / not provided / not required (tool does not process client data)
  • Approval decision: approved for client data / approved for internal use only / not approved
  • Next review date

Store these records in the same location as your written AI policy. Update them annually and when a vendor changes their terms.

What Happens If You Cannot Demonstrate Compliance

The OPR does not audit AI governance proactively. What triggers an inquiry is a complaint — from a client, a state board referral, or a flag raised in the context of another proceeding.

When an OPR inquiry begins, the investigator will ask you to demonstrate your AI compliance practices. "We're careful" is not an answer they can work with. They need documents.

The specific risk for small CPA firms is not that you made a mistake. It is that you cannot demonstrate you had a system. An OPR investigator finding no written policy, no training records, and no tool vetting documentation will treat that as evidence the obligations were not met — regardless of how carefully your staff actually handles client data.

The consequences under Circular 230 disciplinary proceedings: censure, suspension, or disbarment from practice before the IRS. For a small CPA firm where one or two practitioners hold the firm's IRS practice authorization, any of those outcomes is a business-ending event.

The 2026 OPR compliance posture is not about catching firms in technical violations. It is about establishing that practitioners who use AI have thought through the risks. Practitioners who have not are the ones at exposure.

A Minimal-Viable AI Policy Template for Small CPA Firms

This structure is adapted from the full accounting firm AI policy template, which covers GLBA Safeguards compliance in more detail. What follows is the minimum structure that addresses the four Alert 2026-19 obligations for a typical 5-20 person CPA firm.


[FIRM NAME] AI Use Policy Adopted: [Date] | Policy Owner: [Managing Partner/Compliance Lead] | Next Review: [Date + 12 months]

Section 1 — Purpose This policy governs the use of artificial intelligence tools in client service delivery at [Firm Name]. It establishes which tools are approved, how client data is handled, what training is required, and how new tools are evaluated.

Section 2 — Approved AI Tools The following tools are approved for use with client financial data:

  • [Tool 1] — [Approved use: tax research / return preparation / document review]
  • [Tool 2] — [Approved use]
  • [Tool 3] — [Approved use]

All approved tools have signed data processing agreements on file with [Policy Owner]. The DPA records are stored at [location].

Section 3 — Prohibited Uses The following are prohibited at all times:

  • Processing client financial data through any AI tool not on the approved list above
  • Uploading client tax returns, financial statements, SSNs, EINs, or account information to any free-tier or consumer AI application
  • Using AI-generated content in client deliverables without practitioner review and approval

Section 4 — Client Data Handling Client financial data — including tax returns, financial statements, SSNs, EINs, account numbers, and payroll data — may only be processed by approved tools with signed data processing agreements. Staff with questions about whether a specific data type or tool is covered should contact [Policy Owner] before proceeding.

Section 5 — Staff Training All staff must complete AI policy training within 30 days of hire and annually thereafter. Training must cover: approved tools, prohibited uses, data handling rules, professional review requirements, and the escalation path for uncertain situations. Training records are maintained at [location]. Staff must sign an acknowledgment after each training.

Section 6 — New Tool Vetting Before any new AI tool is used with client data, it must be approved by [Policy Owner] using the firm's three-question vetting checklist: (1) Is a signed DPA available and executed? (2) Do vendor terms prohibit training on submitted data? (3) Is SOC 2 Type II documentation available? Unapproved tools may be used for internal purposes only, with no client data.

Section 7 — Incident Reporting Any staff member who suspects that client data has been processed by an unapproved tool must report it to [Policy Owner] within 24 hours. [Policy Owner] will assess the incident, determine client notification obligations, and document the response.

Section 8 — Review This policy is reviewed annually and updated whenever a new AI tool is added to the approved list, a vendor changes their data handling terms, or a significant AI compliance event occurs.


That structure addresses all four Alert 2026-19 operational obligations. It is not a substitute for legal review if your firm handles particularly sensitive client matters — but it is a working policy that lets you demonstrate compliance if asked.

The Practical Step for This Week

If your firm does not have a written AI policy, the single most useful thing you can do this week is pull your two or three most-used AI tools and answer the three vetting questions for each. Look up whether a DPA is available. Check the training data terms. That exercise usually produces a quick realization about which tools are actually approved for client data and which ones staff may be using without realizing they should not be.

That list becomes Section 2 of the policy template above.

For the billing ethics dimension of Alert 2026-19 — the unconscionable fee and engagement letter provisions — see The IRS Just Made AI Billing an Ethics Issue. For the specific data agreement requirements for AI meeting tools, see AI Meeting Assistants for Accounting Firms.

More on accounting firm AI compliance: AI Compliance for Accounting Firms Hub | IRS AI Audit-Proofing for CPA Firms.

Frequently Asked Questions

Does Circular 230 require CPA firms to have a written AI policy?

IRS OPR Alert 2026-19 does not use the phrase 'written AI policy' by name, but it establishes four operational obligations that practically require one: a documented AI use framework, staff training records, secure data handling protocols, and a tool vetting process. The only way to demonstrate compliance with these obligations in an OPR inquiry is to produce documents. A verbal policy cannot be demonstrated. The practical answer is yes — Circular 230 enforcement now requires written AI governance for any firm using AI tools with client data.

What must a CPA firm staff training program cover for AI use?

IRS OPR Alert 2026-19 does not specify a curriculum, but sets a standard: staff must understand which tools are approved for client data, which uses are prohibited, how to apply professional judgment to AI-generated output, and when to escalate uncertainty. A compliant training record documents who was trained, when, what was covered, and includes an acknowledgment that the employee understands the firm's AI policy. Annual training is the minimum; training updates are required when a new AI tool is added to the approved list.

Which AI tools meet IRS OPR Alert 2026-19 tool vetting requirements?

The OPR's standard is a signed data processing agreement (DPA) between your firm and the tool vendor — not the tool brand itself. Tools from Thomson Reuters, Wolters Kluwer, and Intuit Tax at the enterprise tier typically include signed DPAs and meet this standard for client financial data. Microsoft 365 Copilot at the enterprise tier also meets this standard. Free-tier and consumer versions of general-purpose AI tools — including ChatGPT free, Claude.ai free, and Google Gemini without an enterprise contract — do not have signed DPAs available and are explicitly outside the safe zone for client financial data under Alert 2026-19.

What is the penalty for a CPA firm that lacks an AI use policy under Circular 230?

OPR disciplinary proceedings under Circular 230 can result in censure, suspension, or disbarment from practice before the IRS. A complaint — from a client, a competing practitioner, or flagged through an audit — triggers an OPR inquiry. In that inquiry, you will be asked to produce evidence of your AI governance practices. If you cannot produce documents showing a written policy, staff training, and tool vetting, the OPR's standard is that the obligation was not met. For small CPA firms, a suspension or censure is a practice-ending event. The stakes are not theoretical.

How do I document AI tool vetting for IRS compliance purposes?

Create a one-page tool vetting record for each AI tool your firm uses with client data. The record should include: the tool name and vendor, the date of vetting, who conducted the review, and answers to three specific questions: (1) Is a signed data processing agreement available and executed? (2) Do the vendor's terms of service prohibit training on submitted client data? (3) Can the vendor provide a SOC 2 Type II audit report on request? Record your answers to each question, the source of that information (the DPA itself, the vendor's privacy terms page, the vendor's trust center), and the approval decision. Update this record annually and whenever the vendor changes their data handling terms.

Get the weekly briefing

AI adoption intelligence for accounting, law, and consulting firms. Free to start.

Related Reading

This is the kind of intelligence premium subscribers get every week.

Deep analysis, cross-sector patterns, and the frameworks that help professional services firms make the crossing.