AI governance: The foundation for successful AI adoption in CPA firms
July 30, 2026

Artificial intelligence is no longer a future consideration for CPA firms—it's already reshaping the profession. During a recent presentation to the Iowa Society of CPAs Taxation Committee, Marc Staut, Chief Innovation & Technology Officer at Boomer Consulting, Inc., emphasized that the conversation has shifted from whether firms should use AI to how they should govern it. His central message was clear: successful AI adoption depends on strong governance.
Staut noted that AI is rapidly becoming embedded in tax practice. He pointed to AI agents capable of preparing simple tax returns, major tax software vendors releasing autonomous tax preparation capabilities, and large accounting firms integrating agentic AI into their workflows. While adoption is accelerating, he cautioned that technology alone is not enough. Firms must establish policies, oversight, and accountability before expanding AI use.
Setting guardrails
At the heart of his presentation was the concept of AI governance. Rather than treating AI, cybersecurity, business continuity, and Written Information Security Plans (WISPs) as separate initiatives, Staut encouraged firms to view them as components of one governance framework. Governance establishes the guardrails that allow firms to innovate while protecting client information and maintaining professional responsibility.
Staut distinguished between today's generative AI tools and the emerging world of agentic AI. While generative AI responds to prompts, agentic AI works toward a goal by completing multiple tasks using connected systems such as email, calendars, document management, and tax software. However, these systems should never operate without clearly defined boundaries. Firms must determine what AI can access, what actions require human approval, and who is accountable for final decisions.
Led by people
One of Staut's strongest messages was that AI should augment—not replace—CPAs. He described the profession's future as "human in the lead," with AI handling repetitive tasks such as research, document analysis, drafting, and data synthesis while professionals continue providing judgment, ethics, client relationships, and strategic advice. Human review remains essential, especially for client-facing work. AI-generated drafts can significantly improve efficiency, but they still require experienced professionals to verify accuracy before anything is delivered.
Governance also extends to data security. Staut warned firms against entering taxpayer information into consumer versions of AI tools. Instead, firms should use enterprise-grade platforms with appropriate security protections, such as Microsoft 365 Copilot. He recommended that every firm adopt a simple AI use policy identifying approved tools, defining acceptable uses, and requiring human review before work reaches clients.
Include cybersecurity
Beyond AI itself, Staut stressed that governance includes cybersecurity fundamentals. Multi-factor authentication, password managers, tested offline backups, least-privilege access, phishing awareness training, and regularly updated WISPs all support responsible AI adoption. As AI systems gain greater access to firm data, controlling user permissions and documenting security practices become even more critical.
His advice for firms was practical: start with small AI pilots, focus on measurable return on investment, update governance documents regularly, and ensure policies reflect actual practice rather than aspirational goals. A concise, accurate WISP with a clearly identified owner is far more valuable than an extensive document that no one follows.
Staut concluded that firms embracing AI thoughtfully—supported by governance, security, and human oversight—will be well positioned to improve efficiency while continuing to deliver the trusted expertise clients expect. AI is transforming the profession, but governance will determine which firms realize its full potential.
Note: Article created using an AI-assisted recorded transcript of the ISCPA Taxation Committee meeting.