A PE-backed accounting platform should give each client of every firm it buys one ID in a single client master, carrying that client's related people and entities and the status of its consent to the file transfer, before the platform's AI tools read that client's files.
The AICPA Code of Professional Conduct, updated through July 2026, bears on the master's contents. On conflicts, before accepting a new client relationship, engagement, or business relationship, a member should take reasonable steps to identify circumstances that might create a conflict of interest. Its examples of where conflicts may arise include tax or personal financial planning work for several members of a family whom the member knows to have opposing interests. On files, a member who sells or transfers all or part of a practice and will no longer retain any ownership in it should ask each client in writing to consent to its files moving, telling the client that consent may be presumed if it does not respond within a period of not less than 90 days, unless law, including state board of accountancy rules, prohibits that. The buying member should be satisfied that all clients of the predecessor firm subject to the acquisition have consented to its continuing service and keeping their files.
Within thirty days each acquired firm's operations lead exports its client list: name, entity type, tax ID, services and engagement letter date. The platform's data lead runs an AI matcher that proposes which records describe one client and which are related, such as a couple and their companies; the acquired firm's partner accepts or rejects each proposal before an ID is issued. Each ID then records every firm serving that client, its related parties, and its consent status: obtained, presumed on a date, pending, refused, or outside the rule because the seller retains ownership in the practice.
By day sixty the platform's ethics partner runs the conflict check across the master, listing every client or related group served by more than one acquired firm. When a conflict exists, the Code says the member should disclose it to those affected and obtain their consent, even if threats are at an acceptable level; where they are not, the Code's example safeguards include separate engagement teams and policies that limit access to client files. Consents and limits go onto the IDs. By day ninety the AI tools start on the files of clients whose status is obtained, presumed or outside the rule, within each ID's access limits. The COO owns and funds the master from the integration budget, and each acquired firm's managing partner signs off its clients' consent status.
The master holds nothing else; billing stays with each firm.
Today the Code does not require a member to take specific steps to identify other network firms' conflicts, though one who knows or has reason to believe they may exist should evaluate the threat's significance. A December 29, 2025 exposure draft from the AICPA's Professional Ethics Executive Committee, for structures in which an attest firm is closely aligned with a nonattest entity at least partly owned by investors, proposes that the attest firm and nonattest entity, and entities it controls, should take specific steps to identify conflicts of interest that may arise from their relationships with or between clients. NASBA, the state boards' association, wrote in August 2026 that after 81 comment letters the draft is being rewritten, with "closely aligned entity" replacing "nonattest entity" among some of its key changes, and that the committee will convene a special meeting in October with an expected vote on releasing a second exposure draft.