AI Governance and Data Protection: New Rules for Accountants
Following the Data (Use and Access) Act 2025, the Information Commissioner has now formally replaced the Information Commissioner's Office (ICO) and taken on new responsibilities. Among these is the requirement to prepare a statutory code of practice on artificial intelligence and automated decision-making in personal data processing.
For accountancy practices and SME business owners, this signals a significant tightening of regulatory scrutiny around AI use in systems handling client data, employee records, and customer information. Any automated decision-making—such as AI-powered receipt categorisation, invoice matching, or payroll algorithms—now falls under heightened oversight.
The practical implication is clear: if your accounting software or internal systems use AI or automation to process personal data, you should conduct a data protection impact assessment (DPIA) before deploying those tools. This includes AI features for receipt scanning, bank feed categorisation, or data-matching workflows. Practices must document how the AI works, why it's necessary, and how it protects personal data.
For management consulting and advisory work, if you're advising clients on AI implementation, this new code of practice will influence their compliance obligations. Accountants and compliance professionals should stay informed as the Information Commissioner's code of practice develops through 2026 and 2027.
Read more about the Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 on legislation.gov.uk.