The seven that do the most damage are: client files pasted into personal AI accounts, technical answers sent without review, automated chasers hitting the wrong clients, management-account commentary that invents reasons, AI use clients discover by accident, note takers recording calls without asking, and AI bank categorisation that nobody samples. Each has a simple control.
None of the seven is really about the AI being bad. Each one is a moment where machine output reaches a client, or client data leaves the practice, without a person in between. Clients forgive a slow reply far more readily than a wrong figure, a tactless reminder or the discovery that their bank statements sat in someone's personal chat history. So the fix is the same shape each time: find the point where output crosses to the client and put a named person there.
If you only have an afternoon, fix them in the order below. It ranks each by how often it happens in small practices that have started using AI without a plan, and by how hard the damage is to undo. The ratings are a judgement, not survey data.
| Mistake | How often it happens | Damage if a client sees it | Time to put the control in |
|---|---|---|---|
| 2. Unreviewed technical answers | Often | High: the client acts on it | One rule, today |
| 1. Personal AI accounts | Often | High: hard to undo | An hour plus a subscription |
| 7. Unsampled categorisation | Often | Medium, rising over time | Ten minutes per client per month |
| 3. Chasers to the wrong people | Sometimes | High for that client | Half a day to set up tags |
| 6. Note takers without consent | Sometimes | High if a dispute is involved | Fifteen minutes of settings |
| 4. Invented commentary | Sometimes | Medium; worse if a lender reads it | One prompt change |
| 5. AI use found by accident | Sometimes | Low to medium | A clause and a review habit |
1. Client files pasted into personal AI accounts
This is the mistake clients fear most, and it usually starts innocently. A junior wants a long loan agreement summarised, the practice hasn't approved a tool, so they drop the PDF into a free "chat with your PDF" website they found in a search. Nobody knows that site's terms, who runs it, or how long it keeps the file.
How it shows up: rarely as a breach notice. More often a staff member mentions a handy site in a team meeting, or a client asks during onboarding "do you use ChatGPT on my data?" and the partner realises they can't answer with certainty.
That second moment is the one to prepare for, because prospective clients increasingly ask it. A good answer is short and specific: "Yes, we use ChatGPT Business, which is a paid business plan where our data isn't used to train OpenAI's models. We've signed their data processing terms, we only put in what a task needs, and a qualified person checks everything before it reaches you." A vague "we're very careful" invites the follow-up question you can't answer.
The control: one approved business tool, a written rule about what may go in, and a ten-minute conversation where everyone lists the tools they actually use, including browser extensions and phone apps. Browser extensions deserve a specific look: writing assistants and "summarise this page" add-ons can read whatever is open in the browser, including the accounting software. Open the extensions page in each work browser once a quarter and remove anything the practice hasn't approved.
The written rule works best when it names real documents rather than categories. A filled-in version for a small practice might read (illustrative):
- May go into the approved tool: draft letters with the client's name removed, trial balances and summary figures, anonymised questions about how a rule works, and our own templates.
- Only with a manager's say-so: whole contracts, loan agreements or leases, and anything about a dispute, divorce or sale of the business.
- Never: passports, bank login details, payroll files with personal details, or anything a client has marked confidential. Nothing at all into a tool that isn't on the register below.
The junior with the loan agreement now has an answer before they reach for a website: it goes into the practice workspace after a manager agrees, or it gets read by a person. The plan-by-plan detail is in whether it's safe for an accountant to use ChatGPT with client data.
After that ten-minute conversation, write the answers down. A filled-in register from a five-person practice might look like this (illustrative):
| Tool | Who uses it | Client data allowed? | Decision |
|---|---|---|---|
| ChatGPT Business (practice workspace) | Everyone | Yes, minimum needed | Approved |
| Free PDF-chat website | One junior | No | Stopped; files deleted from the site where possible |
| Grammar-checking browser extension | Two staff | No | Removed from work browsers |
| Personal ChatGPT Plus | Manager | No | Kept for non-client research only |
| Accounting software's built-in AI | Bookkeepers | Yes | Approved; covered by existing contract |
The register takes a few minutes to update and it gives the partner the certain answer the client was asking for.
2. Technical answers sent to clients without review
Clients ask the same questions every year: can I claim this, when is that due, what happens if I'm late. It's tempting to let AI draft the reply and send it straight on. The risk is that language models state rates, thresholds and deadlines with total confidence, and sometimes pull them from the wrong year or another country's rules.
A before-and-after from a query about a new vehicle, from a client who runs a small letting agency (illustrative, figures removed):
AI draft, sent unchecked:
"Great news! You can claim the full cost of the van against this
year's profits, and you can also reclaim all fuel costs, including
personal journeys, as the van is a business asset."
Reply after the manager reviewed it:
"Thanks for checking before you buy. Whether you can deduct the full
cost this year depends on how the van is financed and how much you
use it privately. Fuel for private journeys isn't a business cost.
Can you tell me the purchase price, how you're paying for it, and a
rough split of business and private miles? I'll confirm the figures
for you this week."
The first version is friendly, fast and partly wrong, and the client will act on it. The second takes a manager three minutes and protects the relationship.
The risky queries are predictable, which makes the rule easy to apply. Anything that asks "can I claim", "when do I have to", "what happens if", "how much will I owe" or "is it better to" needs a qualified reviewer. Queries about appointments, document uploads, portal logins and invoice copies don't. Tag a week of your own inbox to find the split. As a sum: if a practice receives 90 client emails a week and a third are technical, that's 30 reviews; at three minutes each on a ready-written draft, about an hour and a half of a manager's week. That's real, but far less than writing the 30 replies from scratch, and far less than one partner's afternoon repairing a client who acted on a wrong answer.
An edge case that catches practices out: the client who asks a technical question inside a routine one. "Can you resend last year's invoice? Also, am I fine to pay my daughter for the admin she does?" A filter that routes on the first line files it as an invoice request. Have the reviewer rule apply to the whole email, and train the AI draft step to flag any sentence with "can I", "should I" or "am I fine to" wherever it sits.
The control: AI may draft, but any reply containing a rate, deadline, allowance or yes/no on a tax question needs a qualified reviewer before sending. For writing technical points clearly once they're checked, see how accountants use AI to explain tax in plain English.
3. Automated chasers that nag the wrong clients
Chasing missing records is one of the best uses of AI in a practice, and accounting software is building it in: Xero announced in August 2026 that its JAX agent will email clients for missing documents, send reminders and ask follow-up questions, rolling out over time. Automation at that scale also means mistakes at scale.
How it shows up: a reminder lands in the inbox of a client whose partner died last month. A holiday-let owner who uploaded every receipt to the portal on Friday gets a "final reminder" on Monday because the sync ran overnight. A client on a payment plan gets a chaser that reads like a demand. Each takes one email to send and a phone call from a partner to repair.
The control: three rules before any chaser runs on its own.
- A "do not chase" tag on the client record that any team member can set, for bereavement, illness, disputes or anything sensitive. Automations check it first.
- A check against the portal or document store immediately before sending, not at the time the list was built.
- A tone limit: no automated message ever uses the words "final", "failure" or "penalty". Those go out from a person.
Run any new chasing automation in draft mode for the first month: it builds the messages, a person reads the queue each morning and approves or deletes. Count how many drafts you delete and why. A first week's tally might look like this (illustrative): 46 drafts built, five deleted. Two were to clients who had uploaded after the list was built, because the portal check ran at 6am and they uploaded at 8. One went to a bereaved client whose "do not chase" tag sat on her personal contact but not on her company record. Two were duplicates to a married couple in partnership, each asked for the same bank statements. Every one of those points to a fix: move the portal check to the moment of sending, apply the tag at client-group level, and send joint-client chasers once, to the named contact. If a week passes with nothing deleted, let the routine reminders send on their own and keep reviewing the escalations. The full chasing workflow is in how to chase missing client records with AI before deadlines.
4. Management-account commentary that invents the reasons
Asking AI to write the commentary for monthly or quarterly management accounts saves real time. The trap is that when a model sees a number move, it supplies a plausible cause whether or not it knows one.
A campsite client's July figures, given to a chat assistant with no notes (sample output, illustrative):
"Pitch revenue fell 14% compared with July last year, likely
reflecting softer seasonal demand and increased competition from
nearby sites. Costs remained well controlled."
The real reason was that one field was closed for three weeks for drainage works, which the owner had mentioned on the phone. "Softer demand" and "competition" were invented. If the owner reads that, they either lose faith in the report or, worse, start discounting prices to fight a competitor who isn't the problem.
The control: give the model the reasons, and forbid it from inventing others.
Write commentary for these management accounts.
Rules:
- Explain a movement ONLY using the reasons in NOTES below.
- If a movement over 5% has no reason in NOTES, write
"[Reason needed: ask client]" instead of guessing.
- No forecasts, no advice, no adjectives such as "strong" or "weak".
NOTES: Field B closed 8-29 July for drainage works (about 30 pitches).
FIGURES: [paste the summary table]
Run with the note about Field B, the same figures come back like this (illustrative):
"Pitch revenue was 14% lower than July last year. Field B was
closed from 8 to 29 July for drainage works, taking about 30
pitches out of use. Shop takings rose 9% [Reason needed: ask
client]. Staff costs were broadly level, a strong result given
the closure."
Two things to fix before it goes out. "A strong result" breaks the no-adjectives rule, and models often let one slip through in the last sentence, so the reviewer reads the ending hardest. And "broadly level" hides the number: ask for the actual movement. The "[Reason needed]" marker on shop takings is the prompt working as intended. Those markers turn into the questions for the client call, which is what good commentary was meant to prompt anyway.
This matters more than it looks, because management accounts travel. A guest-house owner may send the quarterly pack to the bank with a loan application, or to a prospective buyer. An invented explanation in a document a lender relies on is no longer a tone problem; it's a statement the practice put its name to. If a pack might leave the client's hands, the reviewer reads the commentary against the notes line by line.
5. AI use the client discovers by accident
Clients don't mind a practice using AI nearly as much as they mind finding out by accident. The discovery usually comes from leftovers in the text:
- A bracketed placeholder left in: "Dear [Client first name]".
- Phrases nobody in the practice has ever said out loud: "I hope this email finds you well", "Great question!"
- Spellings and date formats that don't match anything else the practice sends.
- Three identical paragraphs sent to three clients who know each other.
- Figures to four decimal places, or percentages that don't match the table next to them.
A realistic version: two brothers who run a boutique hotel together each forward their "personal" year-end letter to the other and notice the middle two paragraphs are word for word the same. Nothing in either letter is wrong. Both still ask, at the next meeting, how much of their fee pays for a person to think about their business.
The control: say that you use AI, in the engagement letter and on the website, before clients work it out. Then add a thirty-second "artefact check" to the review of anything client-facing. Should you tell customers you use AI? covers the wording and how far to go.
A line like this on the practice's website, next to the privacy notice, does most of the work: "We use business-grade AI tools to help prepare drafts and analyse records. They run under contracts that stop your data being used to train AI models, and every piece of work is checked and signed off by a member of our team." Clients who want more detail will ask, and at least they'll ask before they find out.
Some will ask for the opposite: no AI on their file at all. Treat it like any other client instruction. Put a flag on the client record that shows wherever work is allocated, switch off the automated chasers and AI drafting for that client, and tell the team in the next meeting. If the software's built-in AI can't be switched off for one client (some accounting packages won't let you turn features off individually), say so honestly and explain what a person checks. The client who asked is testing whether you listen, and a flag that works is the answer.
6. Note takers joining client calls uninvited
AI note takers are useful for fact-finding and planning meetings, but some default to behaviour that suits a sales team, not an accountant. Bot-based tools can join every meeting in a connected calendar automatically, and some can email the notes to all attendees. Otter, for example, has separate settings for which meetings its note taker joins and for auto-sharing conversations, and both are worth checking before the tool touches a client call.
How it shows up: a note-taker bot appears in a video call with two business partners who are discussing buying each other out. The summary lands in both inboxes, including the half of the conversation one partner had with the accountant after the other dropped off. That is a confidentiality problem the practice created without anyone pressing a button.
The control:
- Set auto-join to off, or to "meetings I choose", for every account in the practice.
- Turn off automatic sharing of notes with attendees; send summaries by hand after review.
- Ask at the start of each call, every time: "Are you happy for me to use an AI note taker? It's for my file only."
If a client says no, the answer is simply to take notes by hand, and to record the refusal on the client file so the question isn't asked again at every meeting. Decide too how long recordings and transcripts are kept. For most practices the reviewed file note is the record; the raw recording can be deleted within a month unless there's a reason to keep it.
That review matters because transcript summaries firm up what people only discussed. Asked for a file note from a planning call, a note taker might produce (illustrative): "Client agreed to incorporate from April and will transfer the van into the company." What was said was "we'd like to look at incorporating, maybe from April, and we're not sure about the van." If that note goes on file unchanged, next year's adviser reads a decision that was never made. A prompt that reduces the risk:
Turn this transcript into a file note for an accountancy file.
Sort every point under one of three headings: DECIDED,
DISCUSSED BUT NOT DECIDED, ACTIONS (with who and by when).
Only put something under DECIDED if the client clearly said
yes to it. Quote the client's words for each decision.
The reviewer then checks the DECIDED list against their own memory of the call before the note is saved.
More on judging these tools is in are AI meeting note-takers safe for client calls.
7. AI bank categorisation that nobody samples
Receipt capture and bank-feed suggestions save bookkeepers hours. They also learn from what you accept. Approve a wrong suggestion a few times and the software applies it with growing confidence, and errors compound quietly into management accounts, year-end accounts and tax returns that the client signs.
Take a holiday-let manager's books (illustrative). The software learns that card payments at a big supermarket are "Cleaning supplies" because the first twenty were. By December, the owner's weekly family shop is coded there too, overstating costs by several thousand. It surfaces only when the owner queries why the cleaning bill doubled.
The control: a small monthly sample per client, logged. A filled-in example of the log for that client:
| Month | Transactions sampled | Wrong category | Pattern found | Action |
|---|---|---|---|---|
| October | 20 | 1 | Fuel coded as travel | Fixed, no rule change |
| November | 20 | 4 | Supermarket spend over 150 coded as cleaning | Rule edited; owner asked to use business card only |
| December | 20 | 0 | None | Keep sampling |
Twenty transactions takes about ten minutes. More than two wrong in a month means a rule needs looking at. Sample from the transactions the software categorised on its own, not the ones a person already touched, and pick across the month rather than the last twenty. If the sample finds an error in a period that has already been reported or filed, don't quietly correct it in the current month: tell the reviewer, work out the value, and decide with the client whether the earlier figures need amending. The setup side is in AI receipt capture and bank categorisation for bookkeepers.
When trust has already taken a knock: the reply that repairs it
If one of these has already happened, the first reply decides whether the client stays. The instinct is to explain the technology. Clients want to know you've noticed, it's fixed, and it won't happen again.
Defensive (don't send):
"Unfortunately our automated system sent this reminder in error.
These systems occasionally make mistakes, and we apologise for any
inconvenience caused."
Better:
"I'm sorry. You'd already sent everything on Friday and you should
never have received that reminder, least of all worded like that.
I've stopped all automatic reminders on your file, and from now on
anything we need from you will come from me directly. Thank you for
telling us."
The better reply takes ownership, names what went wrong in the client's terms, and states the change. It doesn't mention AI at all, because the client's problem was the practice, not the software.
A monthly twenty-minute trust check
One person, once a month, working through this list catches all seven before a client does:
- Ask the team: any new AI tools, extensions or apps this month? Add or block them.
- Pull three client-facing emails that AI helped draft. Check figures, tone and leftovers.
- Review the "do not chase" list and last month's automated reminders for anything that went to a flagged client.
- Read one set of management-account commentary against the notes it was based on.
- Check note-taker settings on every account: auto-join and auto-share still off.
- Look at the categorisation sample logs. Any client with two or more errors gets a rule review.
- Note anything that went wrong in the practice's incident log, even if the client never noticed.
Twenty minutes a month is cheap insurance on relationships that often run for a decade or more. Most practices find that after three months the list is mostly ticks, which is exactly the point.
Further reads
- Shadow AI: How to Stop Staff Pasting Client Data Into Free Tools — Practical ways to stop staff using personal AI accounts for client work.
- How Accountants Use AI to Spot Errors in Client Books — Turn AI the other way round: use it to find errors, not make them.
- AI Incident Response Plan for Small Businesses (With Template) — A template for what to do when an AI mistake reaches a client.
- AI Acceptable Use Policy for a Small Professional Firm — Write the rules that prevent most of these mistakes in one page.
- How to Choose an Accountant Who Uses AI Well — See your practice the way a prospective client judges AI use.
- AI Mistakes That Damage Customer Trust, and How to Avoid Them — The same trust problem across other kinds of small business.
- AI Engagement Letters for Accountants: Faster Drafts, Clear Scope — Which parts of an engagement letter AI should draft, five prompts with sample outputs, and the partner checks that keep scope clear and terms untouched.
- How Small Tax Practices Use AI Through the Busy Season — A season-long plan for tax preparers: what to build eight weeks out, how AI handles intake, chasers and the inbox, and where preparer review stays in charge.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: Xero announcements on JAX automated document requests (August 2026); Otter help articles on auto-join and auto-share settings; OpenAI enterprise privacy page.