ailiteracynepal 🇳🇵
Text size

Chapter 01 · Section III · 16 min read

Cost, risk, and the audit-trail question

Three questions every Nepali accountant should ask before letting AI touch a workpaper — and the small firm policy that answers all three at once.

Suppose, after the last two sections, you are persuaded. You can see where AI helps in your firm, you have a sense of where it does not, and you are ready to actually use it on Tuesday morning. Before you do, there are three questions to settle — together, before you start, in writing if your firm has more than one partner. They are unglamorous questions about money, exposure, and paperwork, and they are the difference between a tool that quietly upgrades your practice and a habit that quietly creates a liability you cannot see until the season the IRD or ICAN asks.

Question one: cost

Cost is the easiest question and the one most often answered badly. There are two layers, and most firms see only the first.

The visible layer is the subscription. A consumer chatbot is free or about USD 20 per month per user; a firm-grade tool with a logged history, an admin console, and a data-handling agreement runs three to ten times that. For a Kathmandu practice of four people the arithmetic is not difficult — USD 80 to 800 a month, or roughly NPR 11,000 to 110,000, against several days of recovered partner and junior time. Almost any honest accounting of hours saved makes the paid tier the right choice. The free tier is a fine place to learn the tool; it is a poor place to do client work, because it usually trains on your inputs and offers no admin controls.

The hidden layer is time-to-learn, and it is where firms underspend. A new tool dropped onto a busy team without training produces two outcomes: a few enthusiastic adopters who use it well, and a silent majority who either ignore it or — worse — use it badly. Plan for two to four hours of structured practice per person in the first month, plus a weekly fifteen-minute “what worked, what failed” conversation for the first quarter. Without this, the subscription is wasted regardless of price.

Question two: risk

Risk is the question firms answer best when they answer it task-by-task, not tool-by-tool. The same chatbot is low-risk when used to draft a covering letter and high-risk when used to opine on a transfer-pricing question. The right risk frame is not “is AI safe?” but “is this use of AI safe enough for this task?”

A practical three-line filter, used before any client-facing task:

1. If the output is silently wrong, what is the cost to the client and the firm? A misdrafted reminder letter costs an apology. A misstated VAT input credit costs penalties, interest, and a notice from the IRD that consumes weeks of partner time. The two are not in the same category and should not get the same care.

2. How quickly can I catch the error against a trusted source? If the source is your own trial balance and the model is summarising it, you can catch errors in seconds. If the source is a chatbot’s claim about section 88 of the Income Tax Act, you cannot catch the error at all without going to the bare act yourself — at which point the model has saved you nothing.

3. If the error is caught later — by the client, by the IRD, by the next year’s audit — who is accountable? You are. The model is not on the engagement letter; you are. If the answer to that question makes you uncomfortable, the use is wrong, regardless of how plausible the output looks.

These three questions, asked in two minutes before each new use, prevent almost all the avoidable AI failures the international accounting press has been busy reporting since 2024.

Question three: the audit trail

This is the question most firms have not yet thought through, and it is the one the regulators will get to.

The audit trail is the principle that any professional decision — what was recorded, how it was classified, why a position was taken on tax — should be reconstructible by a competent later reader from the workpapers. The principle is older than computers; it is older than calculators. It does not care what tool was used. It cares only whether the path is documentable.

Apply that to AI honestly and a small handful of new requirements fall out. First, the workpaper should note when an AI tool was used materially. Not for spell-check, not for an internal draft you rewrote entirely — but for an extraction, a summary that informed a decision, or a draft that went out substantially as the model produced it. One line is enough: “Draft of management commentary generated using [tool], reviewed and edited by [initials], [date].”

Second, the firm should keep a short list of approved tools — not because the tools are dangerous, but because a workpaper that cites a tool no partner can identify is a workpaper a regulator cannot evaluate. The list does not need to be long. Three or four tools, agreed by the partners, with a one-line note about what each is approved for.

Third, the firm needs a written, internal AI policy — even if the firm is three people. It need not be longer than a page. It should say which client data may be put into which tools (almost certainly: not the free consumer tier), what must be documented in the workpaper, who is responsible for keeping the approved-tools list current, and what the firm’s position is when a client asks whether AI was used in their engagement. The act of writing the policy forces the conversations the firm needed to have anyway.

What you actually do this week

If you are a sole practitioner or a partner reading this, the operational version of the three questions is small enough to start this week. Decide your paid tool, budget the subscription, and book two hours next Saturday morning to draft the firm’s one-page AI policy. Print the approved-tools list and tape it to the wall above the bookkeeper’s desk. Add the one-line “AI used” stamp to your workpaper template. None of this is expensive; all of it would have been the work of a frantic week if it waited until ICAN issued a guideline you needed to comply with retroactively.

The accountants who will struggle with AI over the next three years are not the ones who use it too little or the ones who use it too much. They are the ones who use it without the three artefacts above — who let the tools quietly spread through the office without policy, without documentation, and without an answer when somebody senior asks “and how do we know that number is right?” The artefacts are cheap. Build them first.

Check your understanding

Quick check

A Nepali audit firm uses an AI tool to draft a long summary of a client's loan agreements, then a junior reviews and edits it before it goes into the audit file. What does the audit-trail principle require?

What comes next

That closes Chapter 1. You now have a working answer to three questions: what AI does well, where in your month it actually helps, and how to keep the audit trail intact while you use it. Chapter 2 leaves the meta-discussion behind and gets specific. It walks through bookkeeping and data entry — the highest-leverage stage from this chapter’s workflow map — with concrete tools, real prompts, and the exact checks a Nepali bookkeeper should run before accepting any AI output into the ledger.