The 8 Point AI Security Checklist
Eight things to sort before AI touches client data.
Someone in your firm is already using AI. You probably do not know which tool, whose account it is on, or what went into it.
That is not a telling off. It is just what happens when a tool is useful and nobody has written down the rules yet.
This is one page. Eight items. Work down it in order and by the end of the month you have a framework that stands up to a client asking questions.
- Approved tools list, so everyone knows what is sanctioned
- Data classification, so the team knows what must never be pasted in
- Whose account, and how to audit it in your M365 or Google admin centre
- Vendor due diligence, DPA and retention terms in writing
- Human review, documented, so you have evidence twelve months later
- Engagement letter, privacy notice and your leaver process
Written for practices without an IT department as a guide.

Your instructor
Billie McLoughlin FCCA
Teaching AI for UK practice, without the hype.
Accountants also bought
