Good AI direction means stronger margins and more capacity long-term. Whether you want to play golf or spend time with your kids or scale your practice, you have the ability to do so with that extra capacity.
Now what’s the alternative? Well, bad AI direction (or none at all) means eroding margins, market share and eventually your entire business. You’ll be fighting for every customer dollar, let alone scaling your practice.
I speak to tons of business owners, majority of them being Partners at Accounting firms, and there’s a range of firms with:
- Strong AI committees: fully fluent in the latest happenings and best practices and share it with the wider org, who adopt it well.
- Low-tier AI committees: who feel they need to do it out of FOMO (fear of missing out), but the team has no real understanding on where to start and the wider org is either risk-averse or don’t want to invest the time to learn.
- No-tier AI committees: they don’t exist because they don’t know where to start.
Research shows that:
- 74% of employees use generative AI weekly
- 44% of companies have no clear company AI policy
- 82% of companies have no AI committee at all
What does this tell us? Your employees want it but your firm doesn’t know how to approach it or what are the best tools to use.
After building and teaching in the accounting-tech and AI space for quite a while, I’ve researched what it takes to develop an AI committee and best practices in order maintain a competitive advantage for your business long-term.
Here are the four traits of the best AI committees I’ve seen, from the lens of an accounting firm:
1) Small and cross-functional
They consist of 3-5 people at max (up to 100 person firm) and split into these roles:
- 1-2 firm partners - they typically have ownership of the outcome of the committee. They cannot simply rely on the other members, typically younger, to own it. The partners are the ones who influence change the most and must ensure the firm adopts AI successfully.
- 1 practice lead for whichever service line generates the most AI use - this is where the cross-functional piece comes in. Your entire firm doesn’t need to be changed overnight, however find the one service line you want to automate the most and then have the lead from that department be the domain expert when developing your AI strategy. Example: if you’re trying to automate T1s, your personal tax lead should be the one who helps the most there because they have the first-hand experience of being on the front lines and knowing operationally the best way to approach it.
- Your IT or the vendor relationships lead - this is mainly to vet out any vendors for security and integration help if you choose to bring on a company. We live in a world where there are a lot of AI startups coming up, so ensuring the vendor is safe, trustworthy, no going concern, and credible, is very important.
- Lastly, 1 junior - typically these are the heaviest users of AI outside of work. They may have learned how to use it in school or on YouTube, so it’s important to consult with them on usage and policies. The last thing you want is to have a junior hack their way to using AI at your firm to get their job done and your client data going right out the window into the AI model of their choice. Get ahead of it by collaborating with your junior workers.
2) Classify types of work
All work is not made equal.
I’m going to repeat that, in this new technological era, all work is not made equal.
There’s two types of work your committee should be classifying:
- AI-safe work - public research, drafting things like emails from non-confidential input data, brainstorming
- Traditional work - which means everything else that contains confidential information (i.e. PII, SINs, financial statements)
The main reason for this is that in May 2025, there was a U.S. court order requiring OpenAI to preserve every ChatGPT conversation, deleted ones included, during the New York Times litigation.
Key takeaway? Assume every prompt is discoverable.
Now the questions remain: if you want to automate your work, how can traditional work become AI-safe work? If you find an amazing AI tool to automate your work that has confidential client information, can you (and should you) still use it at your firm?
This is how:
- Move off consumer tools - The NYT preservation order hit consumer and standard API ChatGPT logs. If a tool retains prompts, it is not AI-safe for client data.
- Get a ZDR (zero data retention) agreement in place - OpenAI enterprise ZDR, Anthropic API with ZDR, Azure OpenAI, AWS Bedrock. Your data processing agreement should say: no training, no retention, no human review.
- Strip confidential identifiers before you prompt - Tokenize names, SINs, business numbers, addresses (Client_A, SIN_001), send the shell to the model, re-map the output locally. Now this is not something you particularly would do because it’s not scalable, but double check if this is something your vendor/AI tool does.
- Run models locally for anything that can’t be de-identified - Open-weight models on your vendor’s own hardware or a private cloud tenant, this is something your vendor should be doing to maintain a high level of security.
- Log and access-control everything - If a regulator or court does come asking, you want to show exactly what went where, your vendor should be default have this integrated in their platform.
3) Have multiple HITL (humans in the loop)
There should be three tiers of human approvals to ensure absolutely nothing gets through that shouldn’t:
- Human approval required - first and foremost before a platform gets approved the committee should review it with humans.
- Human review of an AI output - once the platform is being used in practice, humans should review what the AI puts out (i.e. AI drafts a tax return, a human should review the return)
- AI autonomous with human monitoring - if the AI agent is completing tasks by itself (i.e. organizing away your client files in your cloud drive after a file is done), a human should periodically pick a sample of clients and check if the agent did it correctly. This doesn’t need to be overkill, but definitely just checking in time-to-time to ensure it’s being done the way your firm set out to do it.
Who approves it, what gets approved, when and how it gets approved, all those policies must be set out by the committee themselves.
4) Frequent meetings with metrics and accountability
Just like with anything, if you don’t measure it, you can’t manage it.
Having monthly meetings is helpful, to discuss the following:
- AI best practices
- AI tools on the company’s radar
- Internal risks or incidents related to AI
- New features that are being released on AI that the company is already using
- Share of staff on approved tools vs. personal tools usage
These are topics I’ve heard work well for committees, however the more you meet the more you’ll figure out what else is important to discuss specific to your firm.
Metrics that you can track include:
- Time saved per employee or money saved per month - Pick 3 to 5 workflows the committee has automated with AI and measure time/money before vs. after. This is the only metric partners actually care about as it justifies the committee’s existence and impact long-term. Also, this is the whole reason why AI exists, to save you time and money.
- Sanctioned tool adoption rate - Percentage of staff actively using approved tools versus personal accounts (ChatGPT free, Gemini on their phone). If personal usage isn’t falling, your approved tools aren’t good enough or training isn’t working.
- Incidents logged - Count of confidential data entered into a non-approved tool, hallucinated figures caught in review or client complaints tied to AI output. A rising count early means people are reporting, which is good. The goal is get the count flat or falling, while AI adoption climbs, showing that even with people using AI the risk is falling.
What you don’t want as a committee
- The most common one I’ve seen: the same meetings every month just pushing the ball around the room with no real movement on anything. You just have a AI committee because it feels like progress, but really isn’t moving the needle at all.
- The committee becomes a permission desk. All of a sudden if someone wants to do something, they must go through the committee, which only meets every month, so your company could lose up to a month or more worth of time/money savings because of the bureaucracy. You don’t want staff avoiding AI entirely for fear of an internal rule, that just stifles internal innovation. You want to guide strategy and remove barriers for your firm to move fast, not be an IT ticket desk.
- Firing juniors. Another common trend that comes to mind, why do we even need them? Well you need successors eventually, but more importantly if you automate the grunt work, get them to review the AI work. Remember point number 3 (humans in the loop), these are examples of humans.
Where do I even start?
If you have no committee, here’s what you can do within the next 90 days to get one up and running:
- Meeting 1: inventory every AI tool already in use, personal accounts included and without consequences, classify your data, name the owner. Remember: collaborate with your employees, not punish them.
- Meeting 2: do numbers 1 and 2 from above. Review any new tools and best practices to share with the team.
- Meeting 3: do numbers 3 and 4 from above, set the review cadence, train everyone and log the first quarter.
Need help with your commmittee? Email us at training (at) yourlastbusyseason.com