DEV Community

Pratik Bajoria
Pratik Bajoria

Posted on Originally published at pratikbajoria.com

AI Controls Checklist for CA Firms in India: Practical Review Gates

Originally published on pratikbajoria.com.

A practical checklist for using AI in accounting and advisory workflows without losing confidentiality, evidence, review discipline or professional judgement.

Quick answer: AI governance for a CA firm is not a policy document alone. It is a set of repeatable review gates around data, tools, people, evidence and exceptions. Start with one controlled workflow and make the decision trail visible before expanding.

In practice, what I see in CA firms is that AI is already in use before anyone has written the rules. Which tools are approved? Which client data may go in? Who checks the output, and what happens when it is wrong? AI can help a firm research a standard, extract fields from a document, draft a first version of a memo, flag reconciliation exceptions or organise a client query queue. It can also cause a confidentiality incident, repeat one error across fifty files, or make a polished draft look more reliable than it is. Which of those the firm gets depends on its controls, not on the model.

I write this as a Chartered Accountant and AI implementation practitioner. The checklist is designed for partners, proprietors, finance leaders and practice managers who want a usable operating baseline. It is not a substitute for professional judgement, engagement terms, applicable law or the firm's own quality-control framework.

1. Write the purpose and name the owner

Every AI workflow should start with a narrow sentence: what work is being assisted, who owns the result and what good looks like. “Use AI for audit” is not a control objective. “Extract invoice fields into a review queue; the senior reviews low-confidence items before posting” is closer.

  • Purpose: the process constraint being addressed.
  • Owner: one person accountable for the workflow and exceptions.
  • Users: the people permitted to run or review it.
  • Output: the exact document, queue, report or draft produced.
  • Stop rule: the condition that sends work back to a human.

2. Classify the data before choosing a tool

Do not begin with a model catalogue. Begin with the data. Client identity, unpublished financial statements, payroll, bank details, tax working papers, audit evidence and draft advice should be classified before anyone decides where an input may be processed.

Record whether each data class may be used in an approved cloud service, requires redaction, must remain in a controlled environment or should not enter the workflow at all. Data classification also needs an owner; a label nobody applies is not a control.

This is no longer only good practice. Under the Digital Personal Data Protection Act, 2023, failing to take reasonable security safeguards to prevent a personal data breach can attract a penalty of up to ₹250 crore. The DPDP Rules, 2025, notified in November 2025, give organisations an 18-month phased timeline to comply. Payroll, KYC and individual taxpayer files are personal data; classify them as such.

3. Approve tools and accounts

Maintain a short approved-tool register. For each service, document the account owner, permitted data classes, access method, retention setting, export route, vendor terms reviewed and the process for revoking access. A free trial account used by one employee can quietly become an unmanaged system of record.

Read the vendor terms rather than assuming them. OpenAI states that it does not train its models on data from its business products, such as ChatGPT Enterprise and the API, by default. Microsoft states that prompts and responses in Microsoft 365 Copilot are not used to train its foundation models. Both commitments attach to the business offerings. Neither covers a personal account an employee signed up for on their phone.

  • Use named business accounts rather than personal accounts for client work.
  • Enable multi-factor authentication and least-privilege access.
  • Record which tools may receive client data and which may not.
  • Keep an exit path for prompts, files, outputs and workflow configuration.

4. Define the human review gate

AI can prepare, classify, reconcile, route and draft. The firm remains responsible for professional judgement and client-facing conclusions. Write the human gate in plain language: what the system may suggest, what must be checked, which confidence or exception conditions trigger review, and who signs off.

For material items, unusual evidence, ambiguous documents, fraud indicators, tax positions, audit conclusions and investment or client advice, the review gate should be explicit rather than implied. “The partner will look at it” is weaker than a named review step with evidence.

5. Preserve evidence and an audit trail

A useful AI workflow should make reconstruction easier, not harder. Keep enough information to answer: which input was used, which workflow version ran, what output was produced, who reviewed it, what changed and why the final result was accepted.

Companies already live with a version of this rule. Since 1 April 2023, the proviso to Rule 3(1) of the Companies (Accounts) Rules, 2014 has required accounting software that records an audit trail of every transaction, with an edit log that cannot be disabled. An AI step that feeds those books should not be the weak link in that trail.

  • Input source and date.
  • Workflow or prompt version.
  • Output and confidence or exception status.
  • Reviewer identity and review date.
  • Corrections, overrides and escalation reason.

Retention should follow the firm's engagement, privacy and quality-control requirements. Do not retain sensitive data merely because the tool makes retention easy.

6. Test normal cases and awkward cases

A demonstration with clean data is not a control test. Build a small test set containing ordinary examples, missing fields, duplicate records, unusual vendors, low-quality scans, conflicting dates and items that should be escalated. Keep the test set separate from live client data where possible.

Before release, record the expected result, observed result, error type, reviewer decision and remediation. After release, sample outputs periodically. A workflow that was safe in one month-end can drift when templates, vendors or source systems change.

7. Protect client communication and engagement boundaries

Decide what the firm tells clients about AI-assisted work. The answer depends on the engagement, data, professional standards and the role the tool plays. At minimum, staff should know what may be shared externally, what must be reviewed internally and how to respond when a client asks whether AI was used.

Do not allow a generated answer to create a new client commitment, change a filing position or communicate professional advice without the review required by the engagement and the firm's quality process.

8. Create an incident and exception path

Controls are tested when something goes wrong. Define how a user reports an incorrect output, accidental disclosure, prompt injection, unusual document, suspected fraud signal or vendor outage. The workflow should make it easy to pause processing and preserve the relevant evidence.

  • Stop the workflow and quarantine the output where necessary.
  • Notify the named owner and relevant quality or security contact.
  • Assess affected data, clients, deliverables and deadlines.
  • Record the decision, remediation and return-to-service condition.

9. Run a 30-day implementation sequence

Small firms do not need a forty-page AI policy to start. A controlled first month is more useful:

  1. Days 1–5: choose one low-risk, repetitive workflow and name its owner.
  2. Days 6–10: classify data, approve the tool and define the human gate.
  3. Days 11–20: test normal and awkward cases; record corrections.
  4. Days 21–25: run a limited parallel workflow with review evidence.
  5. Days 26–30: review time saved, exception quality, adoption and control concerns before scaling.

For a broader finance sequence, see the AI finance automation roadmap for CFOs and controllers. For a CA-specific implementation hub, see AI for Chartered Accountants in India.

10. What should stay human?

Keep accountability human for material judgement, ambiguous evidence, unusual estimates, fraud indicators, client advice, professional conclusions and decisions that are difficult to reverse. Automation can reduce preparation and routing effort without becoming the decision-maker.

Frequently asked questions

What should an AI controls checklist for a CA firm include?

It should cover purpose and ownership, data classification, approved tools, human review, evidence and audit trails, access and retention, testing, client communication, monitoring and incident handling.

Can a CA firm use AI for client work without human review?

AI may assist with research, extraction, drafting, reconciliation and routing, but the firm should define a human review gate for professional judgement, material conclusions, unusual items and client-facing advice.

How should a small CA firm start AI governance?

Start with one low-risk workflow, name an owner, classify the data, approve the tool, keep a test set and log exceptions before expanding to more sensitive work.

Sources

This operational checklist is educational commentary, not personalised accounting, tax, legal, audit or investment advice. Verify current professional requirements, client terms, privacy obligations and vendor policies before deployment.


Pratik Bajoria is a Chartered Accountant (ex-Big 4) who helps CA firms and finance teams in India implement AI with proper controls. More practical guides: AI for Chartered Accountants in India.

Top comments (0)