What should a buyer mean by an AI workflow?
An AI workflow is a specific operating process, not a general claim that the firm uses modern technology. Identify the task, tool, users, input data, output, review, and final use. The operations hub focuses on whether actual work can transfer with supported costs and responsibilities, rather than whether a demonstration looks impressive.
An AI-assisted workflow is a defined process in which an AI system contributes to work while authorized people retain the responsibilities, verification, and judgment required for the actual service.Separate systems already used on completed assignments from experiments and proposals. A seller may have a useful pilot without having implemented it across the practice. Record that status accurately. A product feature available today is not evidence that the firm’s staff use it effectively or that historical costs have already fallen.
Which use cases should be inventoried?
List drafting, document extraction, classification suggestions, research assistance, internal summaries, client communications, and other actual uses. Distinguish generative outputs from conventional automation and rules-based software where relevant. Different tasks create different verification needs; a draft internal checklist is not the same as a client-facing tax conclusion.
For each use, identify who approves the tool, which data may enter it, what it produces, and how the output is checked. Note whether the workflow relies on the seller’s technical judgment or a staff member’s undocumented prompting method. A successor needs a repeatable process with competent oversight, not merely a saved account login.
What does the NIST profile contribute?
The NIST Generative Artificial Intelligence Profile, published in July 2024, is a cross-sector companion to its voluntary AI Risk Management Framework. It discusses risks including confidently incorrect content, data privacy, information security, and human-AI interaction. It offers a structure for evaluating risks rather than a guarantee that a particular accounting use is acceptable.
Use that structure to ask what could go wrong in the actual task, how the firm detects it, who responds, and what evidence supports the control. A source-verification step may matter more for a research conclusion than for a low-consequence formatting suggestion. Explain the chosen checks and their limits instead of treating every use as identical.
How should human review be defined?
Specify the required reviewer competence, source evidence, checks, and approval authority for each output. Identify which conclusions require professional judgment and which errors can be detected through defined comparisons. Preserve the review result where appropriate to the engagement. A general instruction to review everything can be difficult to execute and inspect.
The AICPA Code of Professional Conduct addresses member responsibilities including competence and confidentiality within its scope. An AI provider does not replace the firm’s professional responsibilities. Determine the standards and rules that actually apply to the service, with qualified review of the workflow and its intended use.
Which evidence should a buyer request?
Review controlled samples of completed work, approved inputs, outputs, corrections, source checks, and final decisions. Include exceptions and rejected outputs rather than only successful demonstrations. The workflow exception guide helps identify where human intervention or seller knowledge remains necessary.
| Topic | Evidence | Question |
|---|---|---|
| Actual use | Completed assignments and dates | Is this operating or proposed? |
| Authorized inputs | Approved data and provider arrangement | Is the use permitted? |
| Output verification | Source checks and corrections | How are errors detected? |
| Human responsibility | Qualified review and final approval | Who remains accountable? |
| Net cost | Tool, review, rework, and oversight time | What savings are actually supported? |
State the period and population examined. A few selected outputs cannot establish reliability across every service, client, and deadline. If the tool or process changed during the period, identify the version or relevant configuration where available. The buyer should know whether the evidence describes the intended post-closing workflow.
How should source verification be tested?
Check important factual outputs against the actual authoritative source and its date. A plausible citation or confident explanation is not sufficient. Verify calculations independently using the relevant records and method. For professional conclusions, the qualified person should assess the source, applicability, and reasoning rather than merely confirming that a link opens.
Preserve the distinction between extraction and judgment. Correctly extracting a number from a document does not establish that the number belongs in the intended calculation. The firm needs controls for interpretation and context as well as transcription. Identify which parts are automated and which remain subject to review.
What does an illustrative cost comparison show?
Suppose a fictional manual task takes 90 minutes. An AI-assisted version takes 20 minutes to prepare, 25 minutes to verify, and 15 minutes to correct. The assumed net time reduction is 30 minutes, not the 70 minutes suggested by comparing preparation alone. These invented figures are not a performance claim about any product or firm.
At an illustrative $80 hourly labor cost, the 30-minute reduction represents $40 before subscription, implementation, training, and oversight costs. Test repeated assignments and unsuccessful outputs. A faster individual task may free capacity without reducing payroll expense, so do not automatically translate every saved minute into a realized earnings increase.
Which data safeguards must be evaluated?
IRS Publication 4557 discusses safeguards for taxpayer data, including access limits, authentication, training, and service provider arrangements. Review the actual data, provider terms, retention, access, and permitted uses before information is entered into a tool. Do not assume that a product’s availability makes every client data use authorized.
Evaluate confidentiality and tax information restrictions with the relevant advisors as well. Identify whether the provider retains inputs, permits access by others, or uses information for purposes beyond the firm’s intended task under the applicable arrangement. Obtain the correct evidence rather than assuming all versions of a service have identical terms.
How do vendor terms affect transferability?
The vendor transfer review guide separates contract continuation, account authority, data arrangements, and migration. Apply that review to AI services too. A seller’s personal subscription or experimental account may not be the arrangement a buyer should use for ongoing professional work.
Record the configuration and approved process sufficiently for an authorized successor to operate it. Avoid putting sensitive prompts, credentials, or client data in an unrestricted transaction document. A reproducible workflow needs controlled documentation and access, not indiscriminate copying of every conversation or dataset used in the pilot.
What should happen when the tool fails?
Define a fallback for unavailable service, inconsistent output, failed verification, or a changed provider arrangement. Staff should know when to stop and escalate. The reviewer capacity guide helps test whether qualified people have time to perform the necessary checks and fallback work during peak deadlines.
Do not reduce the staffing model on the assumption that the tool always works. Evaluate the consequence of failure and the capacity needed to continue safely. A fallback documented but never tested remains an assumption. State which conditions were observed and which need a controlled exercise or additional support.
How should a buyer describe the opportunity?
Separate supported historical results, current operating capability, and proposed future improvement. Present the actual use cases, evidence limits, costs, review responsibilities, and remaining dependencies. Avoid unsupported claims that AI makes the practice independent of skilled staff or guarantees a particular profit increase.
AI-assisted work can be a useful part of an operating system when its role and controls are clear. For acquisition purposes, the relevant evidence is what the firm actually does, how people verify it, and what resources the process requires. That evidence supports a practical transition plan without confusing a promising tool with completed performance.
A few common questions
What else should you know?
Can a buyer count claimed AI time savings as an earnings add-back?
Not merely because a tool or demonstration appears faster. Examine actual completed work, review and correction time, software costs, and the accounting treatment of any implemented change. Proposed savings belong in a clearly labeled forecast. Historical earnings should remain supported by actual records rather than a projection of what automation might eventually achieve.
Does human approval make an AI output reliable?
Approval is useful only when the reviewer has appropriate competence, evidence, and time to perform the necessary checks. A quick click does not establish verification. Define what must be reviewed and preserve the result. The required professional judgment depends on the service, and responsibility is not automatically transferred to the tool or its provider.
May staff paste client tax information into any AI service?
Do not assume that a convenient tool permits that use. Review confidentiality, tax information restrictions, security requirements, client arrangements, and provider terms for the actual data and purpose. Use approved systems and permissions. A provider’s technical ability to receive information does not establish that the firm is authorized to disclose or process it there.
Does using the NIST AI profile certify a practice as compliant?
No. NIST describes its AI risk framework and generative AI profile as voluntary resources. They can help organize risk questions and controls, but they are not a certification of the firm or a substitute for applicable professional, contractual, tax, and legal requirements. Evaluate the actual workflow and obligations rather than treating a framework reference as approval.
Which sources support this guide?
Primary rules and guidance support the factual statements in this article. The worked examples and decision frameworks are original educational analysis.
- AI Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1 — National Institute of Standards and Technology
- AICPA Code of Professional Conduct — American Institute of CPAs
- Publication 4557: Safeguarding Taxpayer Data — Internal Revenue Service