Plainstart Back to the kit

Article

The Review Step That Makes AI Safe in an Accounting Practice

AI adoption, done properly.

Your staff are already using AI. They are drafting client emails, writing file notes, and producing commentary for management reports. Most of that output is probably fine. Some of it will be confidently wrong in ways that are hard to spot on a quick read. One piece of that output will go out under your firm's name before anyone catches it, unless you build a specific review step for AI-drafted work.

This article is about that step. Not the tools. Not the policy. The actual moment of review, what to check, who checks it, and how to keep it fast enough that people do not route around it.


Why AI-Drafted Work Needs a Different Kind of Review

When a junior staff member drafts a client email, a reviewer looks for unclear phrasing, missing context, and the occasional factual slip. The errors tend to be obvious. Numbers get transposed. A sentence trails off. The tone is occasionally too casual.

AI-drafted work fails differently. The prose is clean. The sentences are complete. The tone is appropriate. The structure is exactly what you asked for. And somewhere in the middle, a number is wrong by a factor of ten, or a reference period is twelve months off, or a deduction category that applies to a different industry has been included as if it applies to your client.

The problem is plausibility. Human errors often look like errors. AI errors often look like correct output. That is the gap your review process has to close.

There are two failure modes worth naming clearly.

The first is the confident wrong number. AI models do not distinguish between a figure they have reliably reproduced from your prompt and a figure they have inferred, rounded, or generated from a false assumption. Both come out looking the same. A management report commentary might state that revenue grew by 18% when the underlying data shows 8%. The sentence is grammatically correct, appropriately hedged, and completely wrong.

The second is the plausible wrong wording. This is subtler. The numbers check out, but a phrase like "your provisional tax position" or "the GST treatment of these receipts" has been included in a way that implies an assurance your firm has not given, or advice you have not provided. The client reads it as a firm view. It was a drafting shortcut that no one caught.

Both failure modes are recoverable before the email goes out. Neither is recoverable after.


What the Review Step Is Actually Checking

Reviewing AI-drafted work is not proofreading. It is verification. The reviewer's job is to confirm that every material fact in the document traces back to a source they can see, not to confirm that the prose sounds right.

Here is what that means in practice.

Numbers first, always. Every figure in the draft should be cross-referenced to the source data, whether that is the client's accounts, a prior-year return, or a calculation the reviewer can run themselves. If a figure cannot be traced in thirty seconds, it should be treated as unverified until it is.

Dates and periods. AI models work from whatever context was in the prompt. If the prompt included figures from a prior period, the draft may quietly refer to the wrong year. Check that every reference to a reporting period matches the period the client is actually asking about.

Client-specific claims. Phrases like "as we discussed", "as previously advised", or "consistent with your current structure" are dangerous when AI generates them, because the model is producing plausible language, not recalling an actual conversation. The reviewer needs to confirm that any claim about prior advice or agreed positions is accurate.

Scope of what the firm is saying. This is the second failure mode. Read the draft as the client will read it. Does any sentence imply a view, a recommendation, or an assurance that the firm has not formally given? If so, it needs to be reworded before it goes.

Jurisdiction and entity-specific context. AI tools have broad training. They do not know that your client operates in a particular state, uses a specific entity structure, or has an unusual arrangement that affects how standard guidance applies. The reviewer should flag any general statement that could be read as specific advice when it is not.


Who Signs Off, and at What Level of Client Exposure

Not every AI-drafted document carries the same risk. A routine acknowledgement email that a document has been received is different from a letter commenting on a client's tax position. The sign-off level should reflect that difference.

A simple tiered approach works in most practices.

Low exposure (acknowledgement emails, file notes, internal summaries): a senior staff member reviews before sending. The reviewer is checking for the confident wrong number and the plausible wrong wording, but a quick read against source material is usually enough.

Medium exposure (management report commentary, draft letters with financial content, client-facing summaries of work done): a manager or senior accountant reviews. They are checking numbers against the underlying figures and reading for implied scope.

High exposure (anything that contains an opinion, a recommendation, a comparison to prior advice, or a comment on a client's position): a principal or partner reviews before it goes. This is not a formality. The reviewer should be able to explain, if asked, why every material statement in the document is accurate.

For guidance on what your firm's existing engagement terms and professional obligations say about sign-off responsibility, your professional body's standards are the right reference. This article is general guidance, not professional advice.


A Worked Example

A staff member uses AI to draft a brief commentary paragraph for a quarterly management report. The prompt included the current quarter's figures and last quarter's figures for comparison.

The draft reads: "Revenue for the quarter came in at $412,000, representing an increase of 14% on the prior corresponding period."

The reviewer checks. The prior corresponding period is the same quarter last year, not last quarter. The prompt only included last quarter's figures. The AI has calculated the percentage change against the wrong comparison period, and "prior corresponding period" is a phrase it generated because it sounds right in this context.

The actual change against the prior corresponding period is 6%, not 14%.

That error would have gone out. It would have been read by the client, probably by their bank, possibly by their board. It would have been attributed to the firm. The review step caught it because the reviewer did not trust the number and checked the source. That is the whole job.


Keeping the Step From Becoming a Bottleneck

The review step fails when it is too slow. People route around slow steps. They send the email before the review is done because the client is waiting. The review becomes a formality. The value disappears.

Three things keep the step fast.

Standardise the prompt so the output is predictable. If staff are using a consistent prompt structure, the reviewer knows what to expect and where to look. Random prompts produce random structures, which take longer to check.

Keep source materials adjacent to the draft. The reviewer should not have to open three systems to verify a number. If the AI output and the source data are side by side, the check takes seconds.

Make the checklist short enough to hold in your head. Here it is.


The AI Review Checklist for Accounting Firms

  1. Every number traces to a source I can see.
  2. Every date and period matches what the client is actually asking about.
  3. No claim about a prior conversation or prior advice that I cannot verify.
  4. No sentence implies a scope of service we have not provided.
  5. No general statement that could be read as specific advice for this client.
  6. The sign-off level matches the exposure level of this document.

Six checks. Most of them take under a minute if the source material is in front of you.


The Broader Picture

The review step is the most important control in any AI adoption for an accounting firm. It is worth spending time on before the first draft goes out to a client.

If your firm does not yet have a written AI usage policy that covers who can use AI, for which tasks, and what the review requirements are, that is the right place to start. A policy built specifically for accounting firms is available at getplainstart.com/ai-policy-for-accounting-firms, free to download.

The tool does not make AI safe in your practice. The review step does.

Free, no email required

Build your own AI usage policy in about two minutes

Answer eight questions and the full policy writes itself around your business. Copy it, download it, put it in front of staff today.

Open the policy generator