On 19 January 2026, the seven professional bodies behind Professional Conduct in Relation to Taxation published topical guidance on using artificial intelligence in tax work. ICAEW, ICAS, ACCA, AAT, ATT, CIOT and STEP looked at what these tools do to tax practice and reached a conclusion with very little drama in it: the fundamental principles apply in the same way whether or not AI formed part of the work.
That is a more demanding answer than a new rulebook would have been. A rulebook gives a firm boxes to tick and a defence when something goes wrong. Leaving the existing principles standing means competence still requires that somebody understood the answer, due care still requires that somebody read the source, and confidentiality still governs whatever is pasted into a text box at half past six on a Thursday.
A written AI use policy is the cheapest way for a practice to hold that answer ready. This article sets out the six sections a workable policy covers, what belongs in each, and the traps that make policies unusable.
Key takeaways
Why a written policy, and why now
The guidance shifted the burden to the firm
By declining to write AI-specific ethics, the PCRT bodies left each firm to demonstrate how it applies the ordinary principles when AI is in the workflow. A firm that can produce a policy, and evidence that it is followed, has a straightforward answer to a client or a professional body. A firm relying on custom and practice has a conversation to reconstruct.
The tools are already in the building
Most practices discover, when they ask honestly, that AI use began well before any policy existed. Staff use general-purpose assistants for drafting, summarising and first-pass research. A policy written as though adoption is a future decision will describe a firm that does not exist.
It is a short document
The best policies in small practices run to a page. They name tools, name limits, name the check, and name the owner. Everything else belongs in training.
The six sections
1. Approved tools
State which AI tools may be used for client work, which may be used for internal work only, and which are prohibited.
- Keep a named list rather than a category description. "Approved research tools" invites interpretation; a list does not.
- Include the route by which a new tool gets added, and who decides.
- Say plainly what happens if someone wants to use something not on the list. A path that exists is used; a path that does not exist is bypassed.
2. Client data
This is the section that carries the confidentiality risk.
- Define what may be entered into a prompt. Most firms land on: no client names, no identifying details, no documents containing personal data, unless the tool is on the approved list and covered by appropriate terms.
- Address whether the vendor trains on your inputs. This is a question of fact about each tool, and the answer belongs in the policy next to the tool's name.
- Cover anonymisation where the firm relies on it, including who checks that anonymisation actually worked.
⚠️ Watch: The confidentiality question is not answered by the tool being "secure". It is answered by knowing what happens to the input: where it is stored, for how long, who can see it, and whether it contributes to model training. If you cannot answer those four for a tool, it does not belong on the approved list. Our own answers are published in security and data handling.
3. Verification
The section that decides whether the policy is worth anything.
- Say who reviews AI-assisted output before it reaches a client, by grade or role.
- Define what "checked" means. A workable definition: the reviewer has opened the cited source and read the relevant passage, confirmed the tax year or period, and confirmed that the authority decides the point at issue rather than merely mentioning it.
- Distinguish between output used as a first draft and output used as the basis for advice. The second demands more.
"A tool earns its place by what a reviewer can verify at four in the afternoon, not by what a demo performs at ten in the morning."
4. Records
- State what the firm keeps about how an answer was produced, and where it is kept.
- Keep it proportionate. For most work, the sources relied on and the identity of the reviewer are enough. For genuinely arguable positions, the alternative reading and the reason for rejecting it are worth recording at the time.
- Name a retention period so the question is settled once.
5. Client transparency
- Decide the firm's position on telling clients that AI formed part of the work, and write it down, including whether it appears in the engagement letter.
- Cover client-facing tools separately. Anything that talks directly to a client raises questions the back-office use of a research tool does not.
- Keep the position consistent across the practice. Inconsistency here is what turns a reasonable approach into an awkward conversation.
6. Review and ownership
- Name an owner. A policy nobody owns ages badly.
- Set a review cadence, and make it shorter than you would for other policies. Six months is realistic; annual is already too slow for this category.
- Record the version and date on the document itself.
Traps that make policies useless
Banning what people already do
A policy that prohibits tools in daily use produces quiet non-compliance and destroys the firm's visibility into what is actually happening. Describe the practice you want and make the approved route the easy one.
Confusing accuracy with verifiability
A tool that is right most of the time and shows nothing leaves a reviewer with no way to confirm anything. A tool that shows its source turns verification into a click.
✅ In practice: This is the design principle behind GAIN Tax. Each answer to a UK tax question arrives grounded in legislation, HMRC guidance and case law with the source shown against the point. Our published benchmark records 93.2% correct across 250 questions in 21 UK tax domains, 4.8% partially correct and 2.0% incorrect, and we publish what the tool will not do and where professional judgement stays with you. You can create an account and test it against your own questions before it goes near a policy.
Writing twenty pages
Long policies are read once, at induction, and never again. If a member of staff cannot find the answer to "can I paste this in?" in under thirty seconds, the document has failed.
Treating it as a compliance artefact
The point is not to have a policy. The point is that the work is checked by someone who understood it. A policy that produces the second is worth having; one that only produces the first is paperwork.
A one-page outline you can adapt
- Purpose and scope. Who this applies to, and what counts as an AI tool for these purposes.
- Approved tools. The named list, plus the route for adding to it and who decides.
- Client data. What may go into a prompt, what may not, and the anonymisation rule.
- Verification. Who reviews, what "checked" means, and the higher bar for advice.
- Records. What is kept, where, and for how long.
- Client transparency. The firm's position and where it is stated.
- Ownership and review. Named owner, review cadence, version and date.
Conclusion
The PCRT bodies had the opportunity in January to write a separate ethical regime for artificial intelligence and chose not to. The principles a tax professional already works under were judged sufficient, which means the interesting work sits in application rather than in rules.
A written AI use policy is how a firm makes that application visible. Named tools, a clear line on client data, a definition of checking that means something, proportionate records, a settled position on client transparency, and an owner who revisits it.
One page, reviewed every six months, is worth more than twenty pages written once. And the tool choices underneath it matter more than the wording above them: for how to assess those, see our guide to choosing AI tax research software in the UK, or browse more on the blog.
Frequently asked questions
Does PCRT require accountancy firms to have an AI policy?
The PCRT topical guidance published on 19 January 2026 applies the existing fundamental principles to work involving AI, rather than creating a separate AI regime. A written policy is not the only way to demonstrate that those principles are being applied, but it is the most practical way for a firm to hold that answer ready for a client or a professional body.
Which bodies issued the PCRT AI guidance?
The seven bodies that promote Professional Conduct in Relation to Taxation: the Institute of Chartered Accountants in England and Wales, the Institute of Chartered Accountants of Scotland, the Association of Accounting Technicians, the Association of Chartered Certified Accountants, the Association of Taxation Technicians, the Chartered Institute of Taxation, and the Society of Trust and Estate Practitioners.
Can we put client information into an AI tool?
That depends on the tool and on your engagement terms, and it is exactly what the client data section of a policy exists to settle. The four questions to answer for any tool are where inputs are stored, for how long, who can access them, and whether they contribute to model training. If those cannot be answered, the tool should not be approved for client work.
What should "verified" mean in an AI policy?
Something specific enough to audit. A workable definition is that the reviewer has opened the cited source and read the relevant passage, confirmed the tax year or period the figure belongs to, and confirmed the authority actually decides the point rather than merely mentioning it. A definition that says only "output must be reviewed" is not enforceable.
How long should an AI use policy be?
One to two pages for most practices. The test is whether a member of staff can find the answer to a practical question in under thirty seconds. Longer documents get read at induction and never again, which produces a policy that exists on paper and not in the work.
How often should the policy be reviewed?
Every six months is realistic for this category. AI tools, their terms and their capabilities change considerably faster than the documents most firms review annually, and a policy naming tools that have since changed their data terms is worse than no policy at all.

