A practical Excel workbook for firms that need to know which AI tools are in use, why they're approved, what data they touch, how vendors were reviewed, and who is accountable for the output.
Get the AI Governance Control Pack — $49
One-time purchase. Secure access is tied to the checkout email.
A written AI policy can define rules. Operations still need evidence: an inventory of tools, an approval gate for new use cases, a repeatable vendor review, a place to record risks and an executive review cadence.
Track tool, owner, purpose, data access, status and review date.
Require a business case, expected benefit, cost, confidence and go/no-go decision.
Record privacy, security, training-data, retention, access and contractual considerations.
Capture accuracy, confidentiality, access, operational and vendor risks with owners and mitigations.
Give firm leadership a recurring view of approved AI use, open risks and decisions.
Keep the workbook grounded in current governance and security references.
The IRS continues to remind professional tax preparers that federal safeguards requirements require them to protect client data and maintain a Written Information Security Plan appropriate to their business. This workbook does not replace that WISP. It gives firms an operational place to document AI-tool and AI-use decisions that may otherwise live in email, memory, or nowhere.
IRS client-data security guidance · IRS Publication 4557
Use the free AI controls hub for tax & accounting firms or review the AI WISP-addendum checklist.
Ops Control HQ · Practical operating controls, not shelfware.