AI for accounting firms: 7 controlled use cases

An accountant reviewing a controlled voice AI workflow
An accountant reviewing a controlled voice AI workflow

AI can help an accounting firm handle narrow, repeatable work. It can also produce a confident error, expose client information, or change a record without adequate authority. A useful program starts with a task boundary, a controlled data path, and a named reviewer. That keeps the technology in a support role while qualified professionals retain responsibility for the work clients and regulators rely on.

Operating rule: Treat every AI output as a draft or proposed action. Keep calculations in deterministic systems. Require a qualified person to approve tax advice, filings, audit conclusions, financial statements, valuations, and any other work that depends on professional judgment.

For client phone operations, we recommend Dasha when a technical team is building the workflow. Our role is narrow: client-inquiry triage, developer-configured scheduling, outbound reminder calls through connected systems, read-only status retrieval, and transfer to a person. Dasha is voice AI infrastructure for technical teams. It is not a turnkey no-code accounting receptionist, and it does not perform accounting work.

Define the AI role before choosing a tool

The effect of an output determines the control, regardless of which model or product generated it.

Work typeAppropriate AI roleRequired release control
Administrative and reversibleRoute a call, propose meeting times, format an internal draft, or extract action items within an approved policyAutomated action may be acceptable when permissions are narrow, failures are logged, and a human fallback exists
Record-affectingExtract a field, suggest a category, propose a match, or flag an exceptionAn authorized reviewer approves the change before it reaches the ledger or client record
Research and communicationRetrieve source material, summarize it, or prepare a draft memo or messageThe reviewer opens the underlying sources, confirms the facts, and approves the final communication
Professional judgmentOrganize evidence and prepare a working draftA qualified professional independently reaches and signs the conclusion

The same system can cross several rows. A meeting summary is administrative. A sentence in that summary that gives individualized tax advice is professional work. Permissions and review follow the consequence of the task, not the label attached to the application.

Seven controlled AI use cases for accounting firms

1. Client-inquiry triage, scheduling, reminders, and status calls

A voice workflow can collect the reason for a call, route it to the right team, offer appointment times from an authorized calendar service, place approved reminder calls, or relay a limited status returned by the firm's system. The agent needs a direct transfer path for tax questions, disputes, account changes, identity uncertainty, or anything outside its approved content.

Dasha supports this pattern through four documented building blocks:

  • Inbound calls route a linked phone number to a configured agent.
  • Tools and functions let developers define JSON Schema parameters and webhook endpoints for a connected scheduling or status service. The service remains responsible for authentication, authorization, validation, and the system-of-record change.
  • Outbound calls can be scheduled through the API for reminder lists already approved by the firm's application.
  • Call transfers can be warm, cold, or HTTP-routed. Warm transfer briefs the operator, cold transfer routes directly, and HTTP transfer lets the firm's routing service choose a destination.

The safest status tool is read-only. It returns an allowlisted field after the firm's authentication service approves the request. The voice agent does not create the status, alter the engagement record, or infer whether work is complete. Scheduling is also developer-configured through the firm's connected service rather than a claimed native accounting integration.

Callers should never be asked to speak portal passwords, full payment credentials, or Social Security numbers into a general intake flow. A transfer or callback process is the correct outcome when the approved identity path cannot establish access.

2. Document intake and field extraction

Document AI can propose fields from invoices, receipts, statements, and tax documents. The source image and extracted fields belong together in the review screen so a person can resolve omissions and ambiguous values.

Accuracy varies by document type, layout, image quality, handwriting, and field. A controlled workflow records confidence and sends uncertain or consequential fields to review. The proposed data stays outside the ledger until an authorized person approves it.

3. Transaction coding and matching suggestions

Pattern models can suggest an account category, identify a possible duplicate, or propose a match between a transaction and supporting document. Each suggestion needs evidence: the source transaction, related document, prior treatment when relevant, and the rule or model version that produced it.

Posting rights remain in the accounting system and follow the firm's segregation of duties. The model produces a proposal. It does not approve journal entries, complete reconciliations, or perform bookkeeping independently.

4. Tax and accounting research drafts

A language model can help locate potentially relevant material, summarize an authority, and organize a first-pass memo. Its output is an index into the research process. It is never the authority itself.

Every cited source must open to the relevant primary material. A qualified reviewer confirms jurisdiction, effective dates, client facts, contrary authority, and the relationship between the authority and the proposed conclusion. Calculations are recreated in a deterministic tax, spreadsheet, or accounting system. The final advice and filing remain human-owned.

5. Close and anomaly-review support

Models can compare periods, surface unusual movements, group exceptions, and draft possible variance explanations. The useful output is a review queue with links to source balances and transactions.

Materiality, approval rights, reconciliation signoff, and final financial reporting stay outside an unconstrained prompt. An explanation generated from a pattern is a hypothesis. The reviewer investigates it and reaches the conclusion.

6. Client communication and meeting administration

AI can draft an email from an approved template, summarize a meeting, or propose action items with owners and dates. A reviewer confirms recipients, attachments, commitments, deadlines, and any language that could be read as advice.

The system must not invent completed work or send an unsupported status update. Recordings and transcripts also need defined access, retention, and deletion rules because they may contain taxpayer or client information.

7. Scenario narratives and advisory drafts

AI can turn approved scenario outputs into a plain-language draft and suggest questions for a client discussion. The numbers come from a spreadsheet, planning platform, valuation model, or other deterministic calculation system.

The workpaper retains input versions, assumptions, formulas, results, and reviewer approval. A qualified person owns the forecast assumptions, valuation, recommendation, and final client deliverable.

Apply professional and regulatory controls to the firm's actual services

Accounting firms do not all have identical duties. Applicable requirements depend on the services performed, professional licenses, client type, engagement, jurisdiction, and regulator. The sources below support a conservative control model without treating one rule as universal.

Federal tax practice and tax return information

For practitioners covered by Circular 230, the IRS rules address due diligence, competence, firm procedures, and written federal tax advice. Sections 10.22, 10.35, 10.36, and 10.37 of Circular 230 keep responsibility with the practitioner. AI does not change the need to establish relevant facts, apply authority, use reasonable assumptions, and exercise due diligence.

Tax return preparers also have separate restrictions on use and disclosure of tax return information under Internal Revenue Code sections 6713 and 7216. The IRS Section 7216 center explains the rules and consent framework. A firm's approved AI data path must account for those restrictions when the information falls within their scope.

Audit and financial reporting work

The PCAOB oversees audits of public companies and SEC-registered brokers and dealers, so its material does not govern every accounting engagement. Its staff's GenAI outreach is also an observation report rather than a new auditing standard. Still, it records a useful pattern from the firms interviewed: early uses centered on administrative work and research, while human review, source-data auditability, supervision, privacy, and security remained central.

The AICPA makes the broader professional point that generative AI depends on the human judgment governing when, where, and how it is used. Its guidance for CPAs supports keeping people responsible for the final work. Its small-firm policy template can help structure an internal policy, which still needs to reflect the firm's engagements and obligations.

Information security and AI risk management

The FTC Safeguards Rule applies to financial institutions within the FTC's jurisdiction, with coverage based on the activities a business performs. The FTC's compliance guide lists tax preparation firms as an example of a covered financial institution. It does not state that every accounting firm is covered in the same way. Covered firms need an information security program that addresses risk assessment, access, encryption, multifactor authentication, monitoring, staff training, service providers, change, and incident response.

For an operational framework that is voluntary rather than a regulation, the NIST AI Risk Management Framework organizes AI risk work around Govern, Map, Measure, and Manage. In an accounting firm, that translates into an AI inventory, named owners, documented use boundaries, pre-release evaluation, monitoring, incident handling, and retirement criteria.

Turn those boundaries into operating controls

A short control specification for each use case should contain:

  1. Purpose: the single task the system may support.
  2. Inputs: permitted sources, prohibited data, and the authoritative system.
  3. Outputs: a draft, proposed action, read-only answer, or bounded administrative action.
  4. Permissions: allowed records and fields, with writes disabled unless the use case requires them.
  5. Review: the role that approves the output and the evidence available to that reviewer.
  6. Escalation: uncertainty, sensitive topics, failed authentication, tool errors, and explicit requests for a person.
  7. Records: prompt and workflow version, source references, tool calls, approvals, transfers, errors, retention, and deletion.
  8. Failure: timeout behavior, duplicate-action prevention, reconciliation, human fallback, and incident ownership.

The evaluation set should represent the actual queue. For a call workflow, it includes corrections, silence, background noise, identity failure, unavailable appointment slots, stale status data, tool timeouts, direct requests for a person, and failed transfers. For research, it includes superseded authority, conflicting sources, missing facts, false citations, and calculations that require a deterministic tool.

Release decisions should rely on control signals rather than a broad productivity claim. Useful signals include unsupported citations, unapproved record changes, field corrections by document type, duplicate bookings, status responses released without authorization, tool failures, missed escalations, transfer failures, and prohibited-data events. Any material change to a model, prompt, tool, data source, or permission set triggers the same scenario evaluation again. Our voice agent testing guide shows how to turn those scenarios into a repeatable release process.

Questions for an AI vendor or implementation team

The answers need to describe the complete data path, including model providers and subprocessors.

  • Is customer data used to train a shared model?
  • Where are prompts, files, audio, transcripts, outputs, and logs stored, and when are they deleted?
  • How are clients, engagements, and tenants isolated?
  • Which roles and service accounts can read data or invoke an action?
  • Can an output retain its source, tool result, model or prompt version, and reviewer approval?
  • Which system is authoritative after a write, and how are partial or duplicate writes reconciled?
  • What happens when a model, telephony route, webhook, or system of record is unavailable?
  • How are behavior changes announced, evaluated, rolled back, and recorded?
  • Can the firm export its configurations, evidence, and operational history in a usable format?

Frequently asked questions

Will AI replace accountants?

AI can support extraction, matching, research, drafting, and routine communication. It cannot assume professional responsibility. Firms still need qualified people to establish facts, apply standards and law, exercise skepticism, communicate advice, and sign work that depends on professional judgment.

Can accountants use a general-purpose AI assistant?

An approved enterprise service can support a defined use case when the firm's confidentiality, access, retention, source, and review controls cover it. Consumer accounts and unapproved plug-ins are not an appropriate path for client or taxpayer information. The output remains a draft, and a qualified person remains responsible for the final work.

What is a sensible first use case?

A narrow queue with visible inputs, reversible actions, and a clear escalation path is a better starting point than a judgment-heavy engagement. For a technical team, client-inquiry triage with read-only retrieval and human transfer provides a bounded voice workflow. Document-field extraction behind review and internal meeting summaries are also contained starting points.

Build one bounded voice workflow with Dasha

If your technical team is building client-inquiry triage, connected scheduling, approved reminder calls, read-only status retrieval, or human transfer, start evaluating Dasha with one end-to-end workflow and an explicit human boundary.

Related Posts

We use cookies for functional and analytical purposes. Please refer to our Privacy Policy for details.