AI, client data, and the plan you're required to keep

Your security plan doesn't mention AI.
Your staff already use it.

Every tax and accounting firm is required to keep a written information security plan — and almost none of them say a word about AI. Meanwhile the work is already being pasted into tools nobody approved. Chorusse closes that gap and leaves you the documentation: an assessment of what's actually in use, an AI addendum to your plan, a policy your staff will read, and the training to make it stick.

Fixed fee, agreed up front Built for firms of 3–50 Documentation you keep
The gap

The plan is solid on laptops and email, and silent on AI.

Most firms wrote their security plan before any of this existed. It covers devices, passwords, vendors and disposal — then stops. Nothing in it tells a preparer under deadline whether a client's return can go into a chatbot, which tools are approved, or what to do the morning someone realises it already happened.

The tools are already in use

Not as policy — as workflow. Drafting, summarising, transcribing, research. Usually on personal accounts, because the firm never provided an approved one.

Nobody wrote down what's allowed

So the answer is whatever each person decided privately. That is the exposure: not the technology, but the absence of a recorded decision about it.

The paperwork is the deliverable

If the question is ever asked, "we handled it" is worth very little. Dated documentation showing you assessed it, decided, and told your staff is worth a great deal.

What we do

One engagement. Five things you keep.

A fixed-fee review, typically one to two weeks, sized for firms of three to fifty people. You end with documents that live in your plan and your staff handbook — not a slide deck.

Plainly

What this is, and what it isn't.

Chorusse is not a law firm or an accounting firm, and nothing we produce is legal, tax or accounting advice. What we deliver is documented, defensible work product: an honest account of what your firm is doing with these tools, the policy language to govern it, and the record that you addressed it. We recommend your counsel review the addendum before you adopt it — and we put that recommendation in the engagement file rather than leaving it implied.