|
EXPLAINER |
AI FOR ACCOUNTANTS · PART 7 OF 16
How to evaluate an AI feature before it touches client data
Data residency, training opt-outs, audit logs, and error accountability are the four things to settle before you click enable.
Every AI feature in an accounting tool eventually asks to read something sensitive - a reconciliation in progress, a client's invoice history, a workpaper with unreleased figures. The vendor's marketing says the feature saves hours. What it rarely says clearly is where that data goes after you click the button, who can read it, and what the firm's liability is when the output is wrong. Those are the questions worth settling first.
Start with data routing. When an AI feature summarizes a client file or categorizes transactions, the text usually leaves your environment and travels to an inference endpoint - often a large model hosted by a third-party provider. The question is whether that routing is disclosed, whether it crosses a jurisdiction your engagement letter or a client's data agreement prohibits, and whether the vendor's subprocessor list is current and auditable. A reconciliation for a public-company client may carry restrictions that make a cloud inference call a breach of the data-handling protocol, regardless of how useful the feature is.
The training question is separate and often muddled. Many vendors distinguish between 'your data trains the model' and 'your data improves the model' - language that can mean the same thing or not, depending on the contract. What matters practically is whether a prompt you submit today could surface in someone else's output tomorrow. Ask for the data processing addendum, not the FAQ. If the vendor cannot produce a written answer to 'is my input used to update model weights,' treat the answer as yes until told otherwise.
Audit logs and error accountability are the parts that accounting teams tend to skip until something goes wrong. If an AI feature auto-categorizes fifty expense lines on a client's month-end close and three are wrong, you need to know which lines changed, when, and based on what input. Some tools log this at the field level; others log only that the feature ran. Before relying on any AI-assisted workpaper step in a review or audit engagement, confirm that the log is exportable, timestamped, and readable by someone other than the vendor's support team.
The practical approach is to treat AI feature evaluation like a new software vendor evaluation, just compressed. Pull the data processing addendum, check the subprocessor list, ask specifically about training opt-outs, and open one client file that is low-sensitivity to see what the log actually captures before you enable the feature for a full engagement. Emburse's unified AI-powered AP and payments solution - a platform that consolidates expense, invoice, and payment management for lean finance teams - is a reminder that these features are arriving faster than most firms have built a policy to receive them. The policy does not have to be long - four questions, written down, reviewed before each new feature goes live, is enough to stay ahead of the exposure.
WORKED EXAMPLE
In practice
A senior accountant is preparing a month-end close workpaper for a mid-market client. The accounting platform has just added an AI feature that proposes journal entry descriptions and account codes for uncategorized transactions. Before enabling it on the client file, the accountant wants to understand what the feature actually does with the data.
What came back. The assistant returned four well-formed questions that named the specific data elements at issue - transaction descriptions, amounts, and account codes - and asked for written responses referencing the data processing addendum. One question asked the vendor to 'identify the third-party inference provider and confirm whether it appears on your current subprocessor list,' which was more precise than the accountant's original framing. The question about error responsibility came back phrased as a liability question rather than a process question, which needed rewording to be useful in a vendor
How it was checked. The accountant compared each question against the vendor's published data processing addendum to confirm the questions targeted gaps - items the addendum addressed vaguely or not at all - before sending them.
A constructed example. The prompt is usable as written; the figures show the shape of a result, not a measured one.
WHEN TO USE IT
| WHEN NOT TO
|
WHAT TO TAKE FROM THIS
| Get the data processing addendum in writing before enabling any AI feature on client files. | |
| Test the audit log on a low-sensitivity file first - confirm it is exportable and field-level. | |
| Ask explicitly whether your input updates model weights; accept only a written answer. |
SPONSORED
QUESTIONS THIS ANSWERS
What is a data processing addendum and why does it matter for AI features?
A data processing addendum is the contractual document that specifies how a vendor handles your data, including where it is stored, who can access it, and whether it is used to train or improve the vendor's models. It matters because the marketing page for an AI feature rarely answers these questions precisely, and the addendum is what is enforceable.
How do I know if an AI feature uses my client data to train the model?
Ask the vendor in writing: 'Is any input I submit used to update model weights or fine-tune the model?' If they cannot answer that question in the data processing addendum or a written response, treat the answer as yes and evaluate the risk accordingly.
What should an audit log for an AI-assisted accounting step contain?
At minimum: which fields or lines were changed, the timestamp, the input that triggered the change, and the output that was applied. If the log only records that a feature ran - without field-level detail - it is not sufficient for a review or audit engagement workpaper.
SOURCES
Where this comes from
What the accounting job market is actually asking for.
GO DEEPER
Go deeper
IN THIS SERIES
Previously: Prompt patterns for reconciliations
Next: Why a model invents a number and how to stop it (coming)
An explainer, not a study: it carries no statistics on purpose. Examples are illustrative.
How accountants are using AI, automation and smarter workflows to close faster, audit cleaner, and free up time for real work.
Accounting Stack · Audit Friendly Data · Accounting & Finance Jobs
Audit Friendly · modernaccounting.ai