AI tools are already inside the finance function. ChatGPT, Copilot for Excel, Claude and a growing number of finance-specific AI applications are used daily by qualified finance professionals across the UK — for drafting management commentary, researching accounting standards, building financial models and summarising board papers. The productivity gains are real and the adoption is happening regardless of whether formal policies are in place.
The data security question is the one most frequently deferred. Finance teams adopt AI tools because they are visibly useful, and then discover six months later that no one has answered the fundamental questions: which data can go into which tools, what are the legal obligations when AI processes personal or commercially sensitive financial data, and what governance framework is required to make AI use auditable when the external auditors or the regulator asks about it. This guide provides the answers.
The Core Problem: Consumer AI Tools and Confidential Financial Data
The most widely used AI tools — ChatGPT, Claude and Google Gemini in their standard consumer versions — are external services. When a finance professional pastes management accounts, board pack commentary, salary data or M&A projections into a consumer AI chatbot, that data is transmitted to a third-party server and processed there. Depending on the service’s terms, it may also be used to train future versions of the model.
This creates three distinct problems for finance teams.
Data confidentiality. Management accounts, board papers, M&A projections and salary data are commercially sensitive. Transmitting them to an external AI service means they leave the organisation’s control environment. If the AI service suffers a data breach, or if data is used in model training and surfaces in responses to other users, the organisation has no remedy and no visibility.
UK GDPR obligations. Where financial data contains personal information — salary records, expenses, personnel costs, customer data — processing it through an external AI service constitutes a transfer to a data processor under the UK GDPR. This requires a lawful basis, a data processing agreement with the provider, and an adequacy assessment. Processing personal data through a consumer AI tool without these elements in place is a potential UK GDPR violation.
Professional and regulatory duties. Qualified finance professionals are subject to confidentiality obligations through their professional body — ACA, ACCA or CIMA. Using a consumer AI tool with confidential employer or client information may breach those duties. FCA-regulated businesses have additional obligations around confidential information handling and technology use in regulated activities.
Consumer vs Enterprise AI: The Distinction That Matters
The most important data security decision a finance team makes about AI is the choice between consumer-tier and enterprise-tier access. The underlying AI models are typically identical. What differs is what happens to the data provided.
Consumer-tier tools (ChatGPT Free, ChatGPT Plus, standard Claude.ai, Gemini free) typically use conversation data to train future models by default, operate under consumer terms that do not include a data processing agreement, and offer no contractual commitments on data residency, retention or staff access. These are appropriate for tasks involving non-sensitive, non-personal information — drafting a generic explanation, researching a publicly available accounting standard, generating ideas for a presentation structure.
Enterprise-tier tools (ChatGPT Enterprise, Claude for Work/Enterprise, Google Workspace with Gemini Enterprise, Microsoft Copilot for Microsoft 365 via enterprise licence) typically offer opt-out from model training on customer data, a data processing agreement meeting UK GDPR requirements, defined data residency, restricted staff access, and contractual security commitments. These are appropriate for commercially sensitive or personal financial data, subject to the organisation’s own data classification policies and the specific enterprise agreement terms.
The ICO guidance on AI and data protection confirms that organisations using AI tools to process personal data remain responsible for ensuring the processing meets UK GDPR requirements, regardless of whether the AI is provided by a third party.
Microsoft Copilot for Finance Teams
Microsoft Copilot for Microsoft 365 is the AI tool most widely deployed at enterprise scale in UK finance functions, primarily because most large businesses already operate within the Microsoft 365 environment.
When deployed through a Microsoft 365 enterprise licence with appropriate configuration, Copilot operates within the Microsoft 365 compliance boundary: data is not used to train the underlying models, data residency is within the customer’s configured Microsoft 365 region (EU/UK for most UK organisations), and access by Microsoft staff is subject to the same controls as the rest of the Microsoft 365 tenancy. This makes properly configured Copilot for Microsoft 365 generally appropriate for commercially sensitive financial data, subject to the organisation’s own data classification policies.
Two important caveats: ‘properly configured’ requires IT involvement to ensure the Copilot deployment meets the organisation’s data governance requirements; and the Microsoft terms of service, not this guide, are the definitive source of the data handling commitments. Finance teams should not treat this guide as a substitute for reviewing the specific terms of their Microsoft agreement.
Classifying Financial Data for AI Use
The practical approach to AI data security in finance is data classification: defining in advance which categories of financial data can be used with which categories of AI tool.
Green — appropriate for consumer AI: Publicly available information, generic accounting concepts and standards, non-sensitive draft text without financial figures or organisational identifiers, anonymised illustrative examples.
Amber — enterprise AI tools only: Management accounts with commercially sensitive data, board papers and investor presentations, budget and forecast models, operational financial data from the organisation’s systems. These require enterprise-tier AI with a data processing agreement, and ideally AI tools integrated directly into the organisation’s systems (Copilot for Excel, Copilot in Word) rather than copy-and-paste into external chatbots.
Red — AI use not appropriate without legal review: Personal data including salary records, individual expenses and customer financial data; M&A information subject to confidentiality obligations; regulatory submissions and FCA-reportable information; data subject to legal privilege or contractual confidentiality restrictions.
UK GDPR Obligations When AI Processes Personal Data
Where AI tools process personal data as part of financial operations — analysing payroll, processing expense reports, reviewing customer financial data — the organisation must comply with the UK GDPR as data controller. The AI service provider acts as a data processor, and the UK GDPR requires a data processing agreement before processing begins.
A data processing agreement must specify: the subject matter, duration and nature of the processing; the type of personal data and categories of data subjects; the obligations and rights of the controller. Consumer-tier AI tools do not provide data processing agreements. The major enterprise providers — Microsoft, OpenAI for Enterprise, Anthropic for Claude for Work — do provide them as part of enterprise terms, though the specific terms vary and should be reviewed by the organisation’s legal team before sensitive personal data is processed.
Where AI use involves automated decision-making with legal or similarly significant effects on individuals — using AI to inform decisions about individual pay, credit or eligibility — Article 22 of the UK GDPR may apply, requiring human review of automated decisions and specific disclosures in the organisation’s privacy notice.
Building an AI Data Security Framework
A practical AI data security framework for a finance function does not need to be lengthy or complex. It needs to answer four questions clearly.
Which tools are approved? A list of AI tools approved for finance team use, with the tier of approval for each. This list should be maintained by the CFO or FC in conjunction with IT and legal, and updated as new tools are adopted.
Which data can go where? The Green/Amber/Red classification above. Finance team members should be able to determine from the classification which AI tool is appropriate for any given task without consulting a policy document each time.
What review is required? The human oversight requirement: which AI outputs require human review before use, who is responsible, and what verification is needed. For financial reporting and regulatory submissions, human review of all AI-assisted output should be mandatory.
How is AI use documented? An audit trail allowing the finance function to demonstrate to auditors and regulators which elements of financial reporting involved AI assistance, what data was provided, which tool was used and who reviewed the output. A simple log in the finance function’s document management system is sufficient for most purposes.
See Human-in-the-Loop AI Controls and AI Usage Policy for Finance Teams for the detailed governance framework that sits alongside this data security foundation.
What Auditors and Regulators Are Now Asking
External auditors are increasingly asking about AI use in financial reporting as part of their risk assessment. Common questions include: which AI tools are used in the finance function; whether AI has been used in preparing financial information; what review process was applied to AI-assisted work; and whether the organisation has assessed the data security implications.
Finance teams with a documented AI data security framework — even a simple one — are significantly better positioned in these conversations than those answering ad hoc. The documentation demonstrates that AI use is governed, not uncontrolled, and that the finance team has considered the data security implications proactively.
FCA-regulated businesses should note that the FCA’s operational resilience requirements apply to AI use where it supports regulated activities. The FCA’s published AI strategy confirms that firms remain fully responsible for outcomes produced with AI assistance — a principle that reinforces the need for human oversight and data security governance. See What Auditors Ask About AI in Finance for the specific audit questions and how to prepare for them.
Practical Rules for Finance Teams Right Now
Without waiting for a full policy framework, three rules resolve most AI data security decisions for a finance function today.
Enterprise tools for anything with numbers or names in it. If the task involves actual financial data, salary information, or any identifiable individual, use an enterprise-tier tool with a data processing agreement. If the business does not have an enterprise AI agreement in place, the task should not use AI until it does.
Consumer tools for generic and public tasks only. Drafting generic explanations, summarising publicly available information, generating structural ideas for documents, writing from scratch using only information you type in (not paste from a financial system). No actual financial data, no organisational identifiers, no names.
Always review before filing or presenting. AI output must be reviewed by a qualified finance professional before it appears in a board pack, a statutory filing, an investor report or any communication to a regulator. The finance professional who reviewed and approved the output is accountable for its accuracy, regardless of whether AI was used to produce the first draft.
These three rules are sufficient for most finance functions at the current stage of AI adoption. The fuller framework above is the right destination — but these rules allow the finance team to use AI productively while that framework is being developed. See AI Tool Landscape for Finance Teams for the full comparison of tools and their appropriate use cases.
A Note from Our Founder — Adrian Lawrence FCA
The data security question is the one I hear most frequently deferred in finance teams that are otherwise moving quickly on AI adoption. The typical pattern is the FC or a senior team member starts using ChatGPT for drafting, finds it useful, others follow, and within a few months the team is routinely pasting management accounts commentary and board pack sections into a consumer AI tool without anyone having decided whether that is appropriate.
The rule I recommend to finance teams is simple: enterprise tools for anything with numbers or names, consumer tools for anything generic. That resolves ninety per cent of decisions without consulting a policy. The ten per cent that requires judgement — confidential M&A data, personal data, regulatory submissions — should be escalated to the CFO or FC before AI is used. One page of guidance on which tool to use for which task, reviewed by IT and legal, is sufficient for most finance functions at this stage of AI adoption.
Accountancy Capital places finance professionals who understand AI data security as part of their professional competence. See AI in Finance Hub, Hiring AI-Capable Finance Professionals and Knowledge Centre. ICAEW Fellow Founder Adrian Lawrence FCA — verify via ICAEW.
Adrian Lawrence FCA
Founder, Accountancy Capital — Qualified finance recruitment specialists, £50,000 and above. Adrian is a Fellow of the Institute of Chartered Accountants in England and Wales — verify via ICAEW.
Related Pages and Resources
| AI Governance KC guides on AI controls and governance. → Human-in-the-Loop AI Controls | AI Tools for Finance KC guides on specific tools. → AI Tool Landscape for Finance → LLMs for Finance Professionals | FCA and Regulated Firms FCA-specific compliance context. | AI Hiring Hiring finance professionals with AI skills. |
Finance Professionals Who Understand AI — 0204 553 8893
Accountancy Capital places qualified finance professionals at £50,000 and above who combine technical finance depth with practical AI competence. Same-day response.
Tell us about your hire → Register as a Candidate → 0204 553 8893