When AI goes wrong inside an accounting firm, the first hour should not be improvised.
If client data enters an unapproved tool, an AI-generated answer is materially wrong, or staff bypass a governance rule, the response should be controlled, documented and owned.
Stop further exposure or use
Pause the affected workflow or tool where appropriate so the issue does not continue while facts are still unclear.
Preserve the evidence
Record the tool, user, date, prompt or workflow, output, data involved and relevant screenshots or logs. Avoid destroying context that may be needed later.
Notify the governance owner
Route the event to the person responsible for AI governance, information security, firm operations or risk—based on the firm’s structure.
Classify the issue
Separate unreliable output, policy exception, confidential-data exposure, vendor issue and client-impact risk. Different incidents require different escalation.
Assess obligations
Evaluate professional, contractual, privacy, insurance, client-notification and legal obligations with qualified advisers when necessary.
Correct the immediate problem
Remove incorrect work from the workflow, change access or settings, retrain staff, update the approved-tool list or take other corrective action.
Close the loop
Document what happened, what changed, who approved closure and whether the policy, vendor review or training process needs revision.
Governance works better when the records already exist.
The AI Governance Control Pack is designed to help organizations maintain practical governance artifacts around tools, vendors, ownership, incidents and recurring review.
$49 one time.
Get the AI Governance Control Pack — $49