,

Your Firm Is Already Using AI. The Question Is Whether You Can Govern It.

By

Blog post about AI Governance

For most CPA firms, AI adoption isn’t a future initiative. It’s already happening, mostly out of view.

Your people are using ChatGPT, Claude and other tools to draft, summarize and research. The software you already license is adding AI features on the vendor’s timeline, not yours. And a few employees are starting to build their own AI agents that connect directly to firm systems. Most of it is productive and well-intentioned. Almost none of it leaves a record of which tools were used, what client data was involved or whether your policy was followed.

That gap between adoption and oversight has a name: shadow AI. And the numbers say most firms are already exposed. Nearly a quarter of employees using generative AI have pasted proprietary company data into public tools. Sixty-nine percent of organizations suspect or have evidence their people are using prohibited AI. And 78% of business leaders aren’t confident they could pass an independent AI governance audit within 90 days.

Why This Hits CPA Firms Harder

Your staff work with tax returns, financial statements, Social Security numbers, payroll and banking data every day. To an employee, pasting a client file into a consumer AI tool feels like using any other app. But that data can leave your controlled environment for good with no way to know where it landed.

The exposure doesn’t stop at data leakage. AI-generated work product can introduce errors if no one reviews it. New AI features appear inside trusted applications without passing your technology review. Employee-built agents interact with business systems in ways your security tools were never designed to see. And the regulatory stakes are real: under IRC Section 7216, disclosing client tax return information without consent is a federal misdemeanor punishable by up to a year in prison per violation.

Telling people not to use AI won’t hold. Writing an acceptable-use policy is a start, but a policy only says what should happen. Governance shows you what is happening and lets you enforce the rule.

Five Questions Every Firm Should Be Able to Answer

  1. Which AI tools are people actually using in the browser, embedded in your apps and through personal accounts?
  2. Which of those are safe for client data? Not every provider handles or trains on data the same way.
  3. Is sensitive client information going somewhere it shouldn’t? Knowing a tool exists is different from controlling how it’s used.
  4. What about agents and automation? AI is moving beyond chat windows to tools that take action inside your systems.
  5. Can you prove your program works? Partners, regulators, peer reviewers and cyber insurers increasingly expect evidence, not a policy document.

For most firms, the honest answer to several of these is no.

Introducing Netgain AI Governance for CPA Firms

Netgain now offers a fully managed AI Governance Service built specifically for CPA firms. It’s not another tool for your team to run or a one-time assessment. Our security team runs the program with you, turning your acceptable-use policy into controls you can actually enforce.

See the AI you don’t know about. We discover AI used through browsers on managed devices, embedded in your applications and accessed through personal accounts. This is a real inventory, not a spreadsheet of what people remembered to report.

Decide what’s allowed. Tools are evaluated on how they handle your data, whether they train on it and their track record, then classified under your policy as approved, conditionally approved or prohibited. Clear guardrails, not a blanket ban.

Protect client data in motion. If sensitive information heads to an unapproved tool, the service can block the upload. For approved tools, it can automatically redact sensitive data. The goal isn’t to stop people from using AI; it’s to help them use it safely.

Go beyond ChatGPT. Discovery and controls extend to web-based agents and automation, so governance keeps pace as AI gets woven into your workflows.

Governance That Reflects CPA Firm Requirements

Generic frameworks are a starting point, but your firm operates in a specific professional and regulatory environment. We configure policy, monitoring and reporting around what actually applies to you, including the FTC Safeguards Rule, professional confidentiality obligations and, where relevant, SEC/FINRA recordkeeping or state rules like NY DFS 23 NYCRR 500. Effective governance isn’t checking an “AI compliance” box; it’s applying the right controls to your real risks and obligations.

Start With Visibility, Not Restrictions

We begin with a short discovery assessment to review or build your acceptable-use policy and connect to your environment. Then a monitor-only baseline period shows how your people actually use AI today without disrupting anyone. That picture lets you and Netgain decide what to approve, where to add controls and where the biggest risks sit. Controls follow your policy and risk profile from there.

If your firm doesn’t have clear answers to the five questions above, a Netgain AI Governance Discovery Assessment can help establish a baseline. We’ll help you understand where AI is already in use, where sensitive data may be at risk and which gaps deserve attention first.

Sumeet Sabharwal is CEO of Netgain, where he leads the company’s strategy for helping CPA, legal and healthcare organizations manage technology, security and operational change. He brings decades of experience building and scaling IT services with a focus on practical outcomes, strong client relationships and the realities of operating in regulated industries. Read more about Sumeet.