Every tax and accounting firm is required to keep a written information security plan — and almost none of them say a word about AI. Meanwhile the work is already being pasted into tools nobody approved. Chorusse closes that gap and leaves you the documentation: an assessment of what's actually in use, an AI addendum to your plan, a policy your staff will read, and the training to make it stick.
Most firms wrote their security plan before any of this existed. It covers devices, passwords, vendors and disposal — then stops. Nothing in it tells a preparer under deadline whether a client's return can go into a chatbot, which tools are approved, or what to do the morning someone realises it already happened.
Not as policy — as workflow. Drafting, summarising, transcribing, research. Usually on personal accounts, because the firm never provided an approved one.
So the answer is whatever each person decided privately. That is the exposure: not the technology, but the absence of a recorded decision about it.
If the question is ever asked, "we handled it" is worth very little. Dated documentation showing you assessed it, decided, and told your staff is worth a great deal.
A fixed-fee review, typically one to two weeks, sized for firms of three to fifty people. You end with documents that live in your plan and your staff handbook — not a slide deck.
What's actually in use, what your plan should say about it, and the record that you did the work.
It is hard to judge whether someone really understands these tools. It is easier to look at what they have built, and whether they are honest about it.