Pumpkin
    Voice AI Security for Law, Accounting, and Advisory Firms
    VoIP

    Voice AI Security for Law, Accounting, and Advisory Firms

    By Aaron WatersJuly 30, 2024Updated August 15, 20267 min read

    Voice AI security for professional firms is mostly a vendor question, not a technology question. The tools themselves are fine. What varies enormously, and what decides whether your firm has a problem, is where the audio goes after the call, how long it stays there, who at the vendor can listen to it, and whether any of it gets used to train a model. Those four questions settle nearly everything, and the answers are rarely on the pricing page.

    If you handle client financial records or privileged communications, ask them before you sign, not after somebody notices.

    What counts as voice AI in a firm

    Broader than most people assume, which is part of the problem.

    The obvious one is an AI receptionist answering the main line. But there's also transcription running on client calls and meetings, call analytics scanning recordings for topics or keywords, voice-to-text built into your phone system and your meeting platform, and natural-language routing on the front end of a phone tree. Several of these arrive switched on inside products you already bought.

    Each one touches audio that, in a professional practice, routinely contains Social Security numbers, account details, matter specifics, and things a client said in confidence because they assumed the conversation was between two people.

    Where the audio goes in transit

    When a call gets processed, the audio has to travel from your phone system to wherever the analysis happens. That trip needs encryption, and the standard answers are TLS for signaling and SRTP for the media stream.

    This is the easy one. Any credible provider says yes immediately and can point at documentation. A vendor who has to check and get back to you has told you something.

    Retention, which is where it gets revealing

    Harder, and more revealing.

    Some tools process audio and discard it. Some keep the recording indefinitely because storage is cheap and nobody wrote a policy. Some keep transcripts forever while deleting audio, which people often don't realize is a distinction. Get specific answers on retention for audio, transcripts, and derived data like summaries and analytics, because those are three different objects with three different lifetimes.

    Then ask the follow-up. Can you set the retention period yourself, or is it whatever the vendor decided? A firm with a written information security plan needs the first answer. Storage should be encrypted at rest, retention should be configurable, and access should be limited by role, which is the design behind compliance call recording rather than a feature you have to negotiate for.

    Who at the vendor can listen

    Almost nobody asks this and it's the one with teeth.

    Vendors typically have some level of employee access for support and quality purposes. That may be entirely reasonable. What you want to know is who, under what circumstances, whether it's logged, and whether you'd ever be told. "Our engineers can access customer data for troubleshooting" is an honest answer you can work with. Silence isn't.

    The training question, asked plainly

    Ask it in exactly those words, and get the answer in writing.

    If client conversations are used to improve a model that serves other customers, that's a confidentiality question your professional obligations have opinions about, and a partner should be making that call rather than whoever signed up for the trial. Many vendors offer an opt-out or a business tier that excludes training by default. Some don't advertise either until asked.

    The sub-processor problem

    Here's the uncomfortable part. Your AI receptionist vendor may not be doing the processing. Speech recognition might come from one company, the language model from a second, the synthesized voice from a third. Each of those handles your audio.

    So ask for the sub-processor list. A vendor with a mature security posture has one ready, usually published. A vendor who's never been asked will improvise, and the improvisation is informative. This is ordinary diligence, the same thing you'd do with any vendor holding client data, and it takes one email.

    Compliance, stated concretely

    Accounting firms preparing returns operate under the FTC Safeguards Rule and IRS Publication 4557, which expect a written plan covering how client data is protected wherever it lives. Voice recordings and transcripts are client data. Nothing in either framework exempts audio.

    Law firms carry confidentiality obligations under professional conduct rules, and state bars have been publishing increasingly direct guidance about technology decisions made on a lawyer's behalf. Handing privileged conversations to a vendor whose data practices you can't describe is a decision, whether or not anyone framed it as one.

    Whatever framework applies to your practice, the test is the same: can you explain, in a sentence, where the audio goes and who can reach it? If not, that's the gap.

    What a good vendor answer sounds like

    Since the questions above only help if you can tell a real answer from a rehearsed one, here's the shape of a good one.

    It's specific and fast. The person on the call knows the retention default without checking, can name the sub-processors, and offers to send documentation rather than describing it. Somewhere in the conversation they volunteer a limitation, because vendors who understand security know their product has edges and aren't embarrassed by them.

    A weak answer sounds reassuring and contains no nouns. Bank-level encryption. Enterprise-grade security. Fully compliant, without naming a framework. Those phrases are the verbal equivalent of a stock photo, and the follow-up question that breaks them is always the same: compliant with what, and who audited it?

    Ask for the SOC 2 report rather than the badge. The badge is a picture. The report has scope and exceptions in it, and the exceptions are the interesting part.

    Controls worth putting in place

    Limit access internally before worrying about the vendor. Not everyone in the firm needs to read transcripts of every call. Partners might have full access, staff might see only their own, administrative users might have none. This takes ten minutes to configure and prevents the most likely incident, which is internal and mundane rather than dramatic.

    Decide what shouldn't be processed at all. Some conversations, particularly around active disputes or highly sensitive matters, are worth keeping off any AI pipeline. Say so in a written policy so the decision doesn't get made call by call by whoever is on the phone.

    Tell your team the tools are listening. People behave differently when they know a transcript exists, and they should know.

    Audit twice a year. Who has been accessing recordings, is retention behaving as configured, has a new tool appeared in the stack that nobody evaluated. Tools appear. Somebody enables a transcription toggle in a meeting platform and now there's a new data flow nobody approved.

    Keeping perspective

    None of this means avoid the technology. An AI answering layer that catches evening calls is worth real money to a small firm, and the security work required to deploy it responsibly is a few hours of vendor questions and an afternoon of configuration. The capabilities and the honest limitations are covered in how AI receptionists capture leads and the human comparison in live receptionist versus AI receptionist.

    What it means is that voice deserves the same scrutiny you'd give a document platform. Firms already know how to ask hard questions about where tax returns are stored. The habit just hasn't extended to audio yet, largely because voice tools got adopted quietly, one toggle at a time, without a purchase order.

    If you're building out the recording and reporting side too, call recording and analytics covers the operational half of the same subject. For the complete picture on choosing and running a firm's phone setup, start with our guide to business phone systems.