Skip to main content
Billswarm

Field notes

What to Ask Any Vendor Before You Let AI Touch Your WIP and Billing Data

A vendor-neutral checklist for CPA firm partners evaluating AI tools that read work-in-process and billing data: the data-residency, deployment, §7216, audit-trail, and approval-gate questions to get answered in writing before you sign.

A Billswarm publicationBy AJ, Founder6-minute read

An AI tool that scrubs your work-in-process and drafts your bills sees most of what matters about the firm: which clients are under-realized, who gets written down year after year, what a partner charges, and, through engagement names and matter descriptions, who your clients are. That is a different risk profile from a tool that formats a document. Before that software reads a WIP file, I want a short, boring list of questions answered in writing. This is the list I use, in the order I ask it.

1. Where does our data go, and who can see it?

Ask the vendor to draw the data path. When a WIP file or a matter description leaves your system, which server receives it, in what country, and does a copy persist after the job finishes? "It's in the cloud" is not an answer. Get the regions by name, get the encryption posture at rest and in transit, and get a straight answer on whether the vendor or any subprocessor keeps your inputs.

One question trips up a lot of AI vendors: is our data used to train or improve any model? Get a yes or a no, then get the same answer in the contract. Many general-purpose AI services reserve the right to use submitted content to improve their systems unless you sit on an enterprise tier with a zero-retention or no-training term. Billing narratives in someone's training set is a disclosure you did not plan to make.

2. Can it run on our infrastructure, and what breaks if it can't?

Make the vendor place themselves on a spectrum. At one end the tool runs inside your environment, your AWS or Azure tenant or your on-prem box, and the data stays there. At the other end the vendor's multi-tenant SaaS receives all of it. Hybrid setups sit in the middle: the software runs in your tenant and calls out to a third-party model API for the AI step.

Probe that middle case. A tool that "runs on your infrastructure" and ships every WIP line to an outside model endpoint for scrubbing still sends your data out, one hop later than you thought. Ask this: when the AI does its work, does the client data travel to a model hosted outside our environment, and if so, whose, where, and under what retention terms? An in-tenant model endpoint, meaning a model served inside your own cloud account, keeps the data home. A call to a public model API does not, unless that API carries an enterprise no-retention agreement.

3. What are the §7216 implications, and have you raised them with counsel?

Firms skip this question, and it lands on the firm rather than the vendor. IRC §7216 makes it a criminal misdemeanor for a tax return preparer to knowingly or recklessly disclose or use a client's tax return information without consent, and the Treasury regulations under it spell out the permitted uses and the consent mechanics. (See 26 U.S.C. §7216 and Treas. Reg. §301.7216-3.)

Billing and WIP data can contain tax return information. Sending it to a third-party service can be a "disclosure." Your own counsel decides whether a given AI arrangement is a permissible use, requires client consent, or falls under an exception. The vendor's job is narrower: they should be able to describe how their architecture affects that analysis. Does data leave the firm at all? Which subprocessors touch it? Can they support a deployment that keeps tax return information inside your control? Take those answers to your attorney. A vendor who has never heard of §7216 has not thought about the rules you work under.

4. Show me the audit trail.

For any bill the AI touches, you want an answer to "what did it change, from what to what, and why." Ask to see an audit record from a real run, on screen, during the demo. A credible tool logs the original WIP, the proposed edit, the human decision, and a timestamped identity for each, and it lets you export that log. You need it twice: once when a partner reviews the engagement, and again if a client questions a bill or a regulator asks how the firm produced the number.

Then ask the follow-up: can the AI's output be reconstructed and explained? If no one can trace a write-down or a re-narrated time entry back to a specific input and a specific human approval, the log is decoration.

5. Where does a human have to say yes?

Wrong suggestions are survivable. The failure mode that should worry a practice leader is a wrong suggestion that reaches the client because no gate stopped it. Ask the vendor to walk you through the approval gates. Does the AI draft a bill for a human to approve, or can it finalize and send? Who signs off, and can an admin switch that gate off during a deadline crunch?

Build the human-in-the-loop point into the structure so nobody can switch it off under pressure. The CCH Axcess workflow you already run does this: a person reviews and releases WIP through a billing review step before anyone finalizes an invoice, with someone accountable at each stage. An AI layer should slot into that discipline, proposing and drafting inside the same gates. If the tool can push a final bill to a client without a named human approving the dollar amount, you are accepting a process change, and you should accept it on purpose.

A four-minute version

If you have room for five questions in the demo, ask these and write the answers down:

  1. Does our WIP and billing data ever leave our environment, and is it ever used to train a model?
  2. Can this run entirely in our own cloud tenant, and if not, where does the data go?
  3. What have you seen firms' counsel conclude about §7216 for this architecture, and can you support a deployment that keeps tax return information in-house?
  4. Can you show me an audit log from a real run right now?
  5. Where is a named human required to approve, and can that gate be disabled?

Good vendors answer these fast and do not flinch when you say "put that in the contract." Whatever they will not put in writing is the part to worry about.

This article is buyer education, not legal advice — the §7216 questions above are for your own counsel to answer for your specific facts.