AI Fluency Is More Than Prompting: A Practical Guide for Accounting Firms

Key takeaways

  • AI fluency combines tool use with critical thinking, professional judgement, privacy awareness and ethical responsibility.
  • Firms should begin with time-consuming tasks whose outputs can be checked easily by a suitably qualified person.
  • Effective governance should support controlled experimentation rather than rely on blanket permission or prohibition.

Generative AI is becoming part of everyday accounting work, from drafting client communications to analysing data and preparing reports.

CA ANZ’s AI Fluency Playbook provides practical guidance for accountants and finance professionals seeking to use these tools without compromising accuracy, confidentiality or professional standards. Its central message is straightforward: organisations should build AI capability now, while keeping human expertise and accountability firmly in control.

What AI fluency means

CA ANZ defines AI fluency as the ability to use artificial intelligence ethically and effectively to enhance accounting practices, support data-driven decision-making and improve stakeholder outcomes. An AI-fluent accountant should be able to identify suitable tasks, choose an appropriate tool, provide clear instructions and context, assess the result, recognise possible bias, protect confidential information and remain accountable for the final work.

AI fluency is not a standalone technical skill. It also depends on critical thinking, problem-solving, ethical awareness, adaptability and accounting expertise. Generative AI can produce convincing responses without understanding financial information in the way an experienced accountant does. It may assist with the work, but it cannot accept professional responsibility for the outcome.

Accountants are already using AI

The playbook reports that 70 percent of surveyed chartered accountants were already using generative AI, while 85 percent were willing to use AI when given the opportunity. Seventy-nine percent believed accountants would become increasingly important as data guardians.

Common uses include drafting communications, transcribing meetings, explaining financial concepts, analysing data, preparing reports, detecting anomalies and managing client work.

The case studies show a common adoption path. Accountants often begin with lower-risk productivity tasks, build confidence and then move into more valuable applications.

One Auckland-based commercial business partner began by using ChatGPT to improve emails and business communications before extending its use to commercial analysis. Another Auckland finance professional uses ChatGPT and Microsoft Copilot for administrative work and data analysis, while emphasising that every result must still be checked and considered in its proper business context.

Prompting helps, but verification matters more

The playbook introduces a simple prompting framework built around four elements:

  1. Role
  2. Task
  3. Requirements
  4. Instructions

This encourages users to provide enough context about the audience, objective, required content and preferred format.

However, a better prompt does not guarantee a correct answer. Generative AI may invent sources, omit important qualifications, misinterpret information or produce inaccurate calculations.

Review requirements should therefore match the risk of the work. A draft internal email may need only a basic check. A tax interpretation, financial forecast or client-facing report should be reviewed by someone with the appropriate technical knowledge.

Professional scepticism remains essential. The user must decide whether an AI-generated response is accurate, relevant and suitable for its intended purpose.

Confidentiality still applies

Some AI services may collect prompts or use submitted information to improve future models. Entering client, personal or commercially sensitive information may therefore disclose more than the user intends.

The playbook recommends treating an external AI service with the same caution that would apply when sharing information with any outside party. Users should understand the platform’s data-retention, model-training and security arrangements before entering sensitive information.

Firms should clearly explain which tools are approved, what information may be entered, when fictional or properly de-identified information must be used, which uses require approval, how outputs must be checked and how incidents should be reported. Removing names alone should not be treated as sufficient de-identification.

Employees should not be left to guess whether a particular use is acceptable.

Start where effort is high and validation is easy

The playbook recommends beginning with tasks that require significant human effort but produce outputs that are easy to check.

Examples include preparing first drafts, summarising non-sensitive information, reformatting data, checking documents for inconsistencies, improving routine communications and preparing meeting notes.

These tasks allow firms to test whether AI saves time and produces acceptable work without beginning with a large transformation project.

One case study describes an invoice-related process that was reduced from approximately two hours to 15 minutes. Other examples include reconciliation, anomaly detection, PDF processing and internal reporting dashboards.

A good starting point is work where the effort is high, the risk is manageable and a qualified person can readily verify the result.

Governance should enable responsible use

AI implementation is not simply an IT project. It can affect privacy, professional obligations, client service, financial reporting and organisational strategy, so governance should involve people from across the business. CA ANZ identifies fairness, transparency, safety and privacy, reliability, and human accountability as the foundations of responsible AI use.

In practice, a governance framework should also establish clear leadership, acceptable-use and data-protection policies, a process for approving tools and use cases, risk assessment and escalation pathways, output-review requirements, ongoing monitoring and defined responsibilities.

Assigning roles to an executive sponsor, governance group, business leaders and individual users helps prevent accountability from becoming unclear between employees, technology teams and suppliers.

Avoid policies based only on “always” and “never”

A complete ban on generative AI may encourage employees to use unapproved tools without telling the organisation, while unrestricted access may expose confidential information and lead to inconsistent work.

A better approach is to apply controls according to the level of risk. Drafting a generic internal agenda may be low risk, while summarising confidential client information may require an approved enterprise system. Producing tax or financial advice may need specialist review, and delegating a material management decision to AI may be unacceptable.

Policies should therefore reflect the sensitivity of the information, the possible consequences of an error and the strength of the available human oversight.

What this means for your organisation

Organisations should begin by identifying which AI tools employees already use and where AI features are embedded in existing software. They can then select a small number of low-risk, time-consuming tasks where outputs can be checked easily and the value of the tool can be measured.

Practical guidance should explain which tools are approved, what information must not be entered, how outputs are to be reviewed and when concerns should be escalated.

Training should be tailored to different roles and cover not only prompting, but also confidentiality, verification, bias, professional scepticism and accountability.

Clear ownership is also essential, with an executive responsible for the overall approach and a defined process for approving tools, monitoring use and responding to incidents.

Conclusion

The CA ANZ playbook presents AI fluency as a professional capability, not simply a technical skill.

Accountants need to understand how to work with generative AI, but they must also know when to question it, when not to use it and how to remain accountable for the outcome.

Organisations do not need to transform every process immediately. They can begin with controlled experimentation, practical training and governance that gives employees clear boundaries.

The playbook’s core advice is simple: start small, but start now.

Sources and qualification

The playbook provides general professional guidance. Organisations should assess AI use against their own legal, privacy, contractual, security and professional obligations.

Related reading

About the author

Campbell McKenzie is a Director at Incident Response Solutions, a New Zealand firm experienced in cyber incident response, digital forensics, investigations and technology risk. Through KiwiGen.AI, Campbell helps professional services firms adopt generative AI safely, with practical governance and controls.