- feature
- TECHNOLOGY
New checklist helps CPAs manage AI cyber risks
Finance departments and firms can use an accountant developed self-evaluation tool to identify gaps and strengthen cybersecurity fundamentals.
Related
Using Excel to automatically flag unusual transactions
The No. 1 cybersecurity tip for sole practitioners
Using an Excel agent to clean, validate, and reconcile data
The practice of cybersecurity is often described as an arms race, with organizations constantly forced to adopt new technologies and policies to counter increasingly powerful attacks. Today, that conflict is growing even more intense and complicated with the widespread adoption of artificial intelligence (AI), particularly generative and agentic AI.
Attackers are now armed with AI tools that allow them to carry out far more elaborate and convincing deceptions; to search for exploitable technical weaknesses; and even to subvert AI-enhanced cyber defenses used by their victims. (See “AI Risks CPAs Should Know,” JofA, Feb. 1, 2026.)
“The threat environment is becoming significantly more serious,” said Sanjay Chadha, CPA/CITP, founding partner at SAV Associates, a Toronto-based firm with offices in Canada and the United States. “It has become much more dangerous, and the speed at which the threat landscape is changing has accelerated significantly.”
The threat is particularly alarming for finance departments and accounting firms, which process and store copious amounts of personally identifiable information and financial data.
So, what is a CFO or firm partner to do? There are many cybersecurity frameworks to choose from, which can make designing and implementing security measures overwhelming — especially if you felt your organization’s cybersecurity was lagging even before the AI explosion.
That’s why Chadha has developed a “Baseline Security Checklist.” Described as a practical self-evaluation for practitioners, the checklist combines core elements of several sets of standards, guidance, and initiatives into a single rubric for assessing a firm’s high-level cybersecurity maturity.
The “problem isn’t choosing the ‘right’ framework. It’s knowing whether you’ve covered the fundamentals,” Chadha writes in the introduction to the checklist. He selected a dozen baseline security areas, including resilience and recovery as well as AI governance and responsible use. Each is evaluated based on five to 10 checkpoints for a maximum score of 75 points. You can access the checklist at “Baseline Security Checklist: A Practical Self-Evaluation for Practitioners,” starting on page XX10
Chadha and other experts offer suggestions on how to turn the checklist’s recommendations into reality, with a focus on emerging risk areas like AI.
AI AND VIBE CODING
AI use is putting intense new pressure on security and data privacy policies. Chadha’s checklist urges practitioners to establish acceptable AI uses, ensure that sensitive data doesn’t leak into unauthorized tools, and review all outputs before business use.
At the most basic level, that requires a set of authorized AI tools and instructions on how to use them. Organizations should consider enterprise versions of AI tools such as OpenAI’s ChatGPT or Anthropic’s Claude, which may provide stronger organizational data protections, contractual assurances, and administrative controls than consumer versions.
But that’s only the tip of the iceberg. Individual employees can now use AI platforms to generate computer code and design and implement their own automations, dashboards, and apps. This AI-assisted software development approach, called “vibe coding,” is a powerful new capability that brings substantial risk.
“When you start to have users vibe coding, it’s almost like you’re extending your developer pool into folks that … may not have the direct understanding of all that’s happening behind the scenes,” said Steven Ursillo, CPA/CITP, CGMA, a risk accounting and advisory services partner with Cherry Bekaert in greater Providence, R.I. “As [user-driven development] gets more complex, and as it starts to render more risk to the process, especially at a scale where it’s affecting multiple clients, you would expect a more rigorous process with reviews.”
Organizations should consider establishing a review and validation process that checks AI-generated software, agents, and automation to confirm they comply with standard security practices and that the firm’s defenses are properly configured, Ursillo and others said. The goal is not just reviewing code but governing uses of AI to keep applications and authorizations from entering the workflow without being assigned ownership or submitted to review and change management processes.
“When you have created an [AI] agent or other AI-enabled tools that are going to be widely used in the organization, it should go through an established governance and formal change management process,” Chadha said. “If you don’t retain clear information about how it was created and what it does, it becomes difficult to achieve scalable, reliable, and secure deployments.”
More broadly, finance departments and firms should be aware that large language models powering generative and agentic AI introduce new attack vectors, particularly when agents have access to enterprise data, credentials, applications, application programming interfaces (APIs), or the ability to take actions autonomously, Ursillo said. Organizations that adopt AI agents that can plan and carry out complex tasks must:
- Ensure that deployments of AI are tracked and reviewed through a governance model.
- Limit AI systems’ access to sensitive data unless the use has been approved through governance and is executed with safeguards to ensure that data is kept confidential and utilized appropriately.
- Establish technical guardrails for AI agents, including secure “sandboxes,” least–privilege access, restricted tool and API permissions, credential and data–access controls, activity monitoring, and human approval requirements for higher–risk actions. These controls help prevent unauthorized system access, data exposure, and unintended agent behavior.
- Monitor and secure inputs so that an attacker can’t “inject” malicious instructions for an AI model.
DATA CLASSIFICATION AND GOVERNANCE
The ever-expanding use of AI points to a higher need: governance. As the checklist explains, finance departments and firms must ensure that “AI tools are used responsibly, securely, and with appropriate human oversight.”
Finance departments and firms must understand how, where, and why AI is being used. But teams should have room to experiment with these emerging capabilities.
“If you have too much governance and too much control, people are going to find workarounds,” said Paul Perry, CPA/CITP, practice leader for Warren Averett’s risk advisory and assurance services group in Birmingham, Ala. “You have to have good governance, which the checklist points to.”
Governance, Perry said, isn’t just about defining the rules. It’s about creating an environment where employees have safe guardrails for using the organization’s resources and data.
“Instead of trying to control what people can and cannot do, you need to govern what they’re allowed to use,” he said.
Chadha’s checklist urges finance organizations to implement data classification policies that categorize data by characteristics like sensitivity and exposure risk. For example, a dataset might be flagged as including personally identifiable information that should be handled with care. Those classifications can be used to limit access and usage, ensuring that data isn’t vacuumed up by overzealous employees or their AI agents without properly considering questions about privacy and security.
“Innovation moves faster than we can sometimes govern,” Perry said. “If we can, on the front end, set up the guardrails, set up the guidelines, that makes me feel more comfortable.”
Governance also means preparing for the worst: ensuring that the organization has policies in place in case of a leak or breach. The checklist recommends organizations establish a tested process for backing up data and documented plans for business continuity and disaster recovery.
“You need to look at your incident response programs,” Ursillo said. “If you do have an incident, are you going to be able to stay within the confines of regulatory and contractual obligations?”
Besides documenting plans, finance departments and firms should also test their capacity for and speed of incident response and recovery and the organization’s ability to meet regulatory and contractual response and reporting obligations, using tabletop exercises and testing technical capabilities such as data recovery.
Finance departments and firms also have to consider their third-party risk, Perry added, as startups and established vendors offer countless new ways to integrate and use their data. Chadha’s checklist includes suggestions like assessing vendor risks and reviewing assurance reports, as well as vetting vendor data access.
Above all, Chadha, Ursillo, and Perry said, governance requires leadership from the top and agreement throughout the organization. It represents a shared commitment to security, even when innovation beckons.
“Governance is all about buy-in, and it’s all about making sure that we are aware of what is happening. We want it to be innovative, but you can’t go rogue,” Perry said.
FUNDAMENTAL DEFENSES FOR POTENT ATTACKS
Even organizations that don’t use AI face rising threats. Attackers are using AI to generate convincing fake images and audio for social engineering attacks. (See “How CPAs Can Combat the Rising Threat of Deepfake Fraud,” JofA, May 1, 2025.) At the same time, AI agents are increasingly capable of hacking cyber defenses directly.
“The speed at which breaches can occur is expected to increase significantly as AI adoption expands,” Chadha said.
Last year, Anthropic revealed that one of its users had launched cyberattacks with malicious software created with and deployed by Claude Code. AI models can be used to find weaknesses in targets’ defenses — whether it’s an undiscovered vulnerability in commercial software or a gap in the configuration of the target’s defenses.
More recently, Anthropic claimed its top-end Mythos model had “found thousands of high-severity vulnerabilities, including some in every major operating system and web browser.”
Anthropic and other large AI companies are trying to restrict malicious uses, especially as the U.S. government pressures them to control access to the most potent AI models. Meanwhile, software providers will have to address vulnerabilities faster than ever, which means finance departments and accounting firms must ensure they apply software updates, also known as patching, quickly. Finance departments and firms should also proactively identify vulnerabilities in their software deployments, prioritizing fixes based on risk, and testing to make sure remediations are effective.
“The time to exploitation, that window, is just going to get crazy short and the scalability of those attacks is growing,” Ursillo said.
Finance departments and firms should ensure that they’re embracing other fundamental cybersecurity and antifraud techniques, too, including:
- Role–based access control, which defines the data and functions allowed to specific users.
- Logging the actions taken by users, which can reveal if an account is compromised.
- Multifactor authentication, which requires users to verify their identity with another device or method besides a password.
- Techniques to combat AI–powered fraud, such as requiring dual authorization for major transactions.
“IT’S NOT A PANIC GAME”
Chadha acknowledged that many organizations have not yet implemented now-basic defenses. But finance departments and firm leaders shouldn’t panic, he said, even if they’ve fallen behind on security practices.
Instead, he said, accountants should adopt a “defense in depth” mindset. Each new cybersecurity technique adds one more layer of defense. Even if a firm can’t achieve a perfect score on Chadha’s checklist, it can improve its chances of withstanding an attack.
“It’s not a panic game where everything has to be implemented in one go,” Chadha said. “Everything has cost. Try to adopt a step-by-step process.”
It begins with a baseline, he reiterated — a map of an organization’s systems and data. From there, finance departments and firms can use the checklist and other resources to decide which assets are their top priorities for protection and which defenses they must implement first. Most importantly, their self-assessment must be honest, he added.
The best defenses are built brick by brick, Perry said, including improvements to an organization’s culture, governance, training, and software.
“What the checklist helps show is that I don’t have to do all of it at once to feel secure,” Perry said. “You’ve got to do it over time. If people are feeling behind, find your next vulnerable area, fix that, and move on.”
Baseline security checklist: A practical self-evaluation for practitioners
Developed by Sanjay Chadha, CPA/CITP
Most practitioners know they need better cybersecurity. The question is: where do you actually start?
Let’s start with the basics. Most frameworks aren’t that different at their core. They all expect you to do the baseline well. That means control who has access to systems, back up your data, train your staff, and respond when something goes wrong. If you’re like many practitioners, you’ve heard about NIST, CIS Controls, ISO 27001, and a dozen other frameworks. Each one promises to help you protect client data and meet regulatory requirements.
So, the problem isn’t choosing the “right” framework. It’s knowing whether you’ve covered the fundamentals.
That’s why we built this baseline security checklist. It pulls together the core requirements from major standards and guidance, including NIST CSF 2.0, CIS Controls v8, ISO 27001:2022, ASD Essential Eight, UK Cyber Essentials, and AI risk management guidance, into 12 straightforward areas. It can serve as a practical checklist intended to help you self-assess cybersecurity readiness against imminent threats to corporate safety.
Common Baseline Security Self-Evaluation Matrix. For framework references, check appendix 1
How to use it:
Go through each of the 12 areas and check off what you’ve actually implemented, not what you plan to do or what you think you should have. Be honest. Each checkpoint is worth one point. Add up your total, then compare it to the grading matrix. You’re not trying to get a perfect score on day one. You’re trying to see clearly where the gaps are so you can prioritize what matters most.
What your score actually means
Once you’ve tallied your points, the grading matrix will place you in one of four categories.
- If you scored between 66 and 75, this means you’re “Baseline Ready”. It shows you’ve got the baseline essentials right.
- If you landed between 54 and 65, this means you have a strong foundation with some gaps still there to close.
- If you ranged between 39 and 53, this means you’re building maturity but have some more heavy lifting to do.
- If you came in at 38 or below, this means you have got foundational gaps that need attention now.
Grading Matrix

What to do about the gaps
Start with the areas where you scored lowest. But don’t just work down the list mechanically. Think about three things: how sensitive is the data you handle, what regulations apply to your firm, and what resources do you realistically have to fix the problem?
Don’t try to fix everything at once. Just pick two or three critical gaps and then assign someone to own them. Then come back to this checklist in three to six months and reassess.
Conclusion
While cybersecurity threats aren’t going away, phishing emails are getting harder to spot, and ransomware gangs are targeting firms like yours because they know you hold valuable data. But here’s the good news — you don’t need a perfect security program. You need a solid one. So start with this. This checklist aims to give you a straightforward way to measure where you are and what needs work. Send this to your in-house expert or consultant.
About the author
Andrew Kenney is a freelance writer based in Colorado. To comment on this article or to suggest an idea for another article, contact Jeff Drew at Jeff.Drew@aicpa-cima.com.
LEARNING RESOURCES
Josi — Gen AI tool built for auditing and accounting professionals
Josi is a Frontier model LLM with access to the AICPA professional and PCAOB standards, FASB/GASB codifications, and industry guides (including disclosure checklists). Josi keeps your/your client data secure, answers the hard questions, and does the heavy lifting on document review, research, and accelerating your team. Use the tool; apply your professional judgment.
GEN AI TOOL
AI Accelerator Program — Operational Tier
Designed for accounting and finance professionals seeking hands-on knowledge of AI tools and operational workflows.
CPE SELF-STUDY
AI Accelerator Program — Strategic Tier
Designed for accounting and finance leaders seeking to understand the organizational impact of artificial intelligence and develop strategies for responsible AI adoption.
CPE SELF-STUDY
The accounting and finance industry’s premier event offers a technology track.
June 7—10, Aria Resort & Casino, Las Vegas
CONFERENCE
For more information or to make a purchase, go to aicpa-cima.com/cpe-learning or call 888-777-7077.
MEMBER RESOURCES
Engage365 communities bring together AICPA members to support one another in their careers, participate in discussions, and share resources. Use your aicpa-cima.com login to get started.
Articles
“7 Steps to Boost Your Small Firm’s Cybersecurity,” Professional Insights, July 13, 2026
“Building Cyber Resilience in the Age of AI,” Professional Insights, March 24, 2026
“Lurking in the Shadows: The Costs of Unapproved AI Tools,” JofA, Nov. 12, 2025
“Reputation, Security, Compliance: Why AI Risk Disclosures Are Surging,” JofA, Oct. 29, 2025
“Are You Prepared for the Cost of a Data Security Incident?” JofA, Oct. 1, 2025
“AI-Powered Hacking in Accounting: ‘No One Is Safe,’” JofA, Oct. 1, 2025
