You're offline, showing the last version we saved.

Part of our AI in accounting coverage. See the full AI for accountants guide →

An AI notetaker hears more about your clients in a week than most of your software sees in a year: the divorce behind the restructure, the cash a director took out, the tax position nobody has filed yet. Before one joins a client call, the vendor should answer a short list of plain questions in writing. This is that list, grouped so you can paste it into an email to any vendor, with what a good answer looks like and the answer that should stop the sign-up.

The obligations section further down ties each question to the rule in your market, as at October 2026.

Why the vendor’s answers are your obligation

In every one of these markets the firm that collects client information stays answerable when a supplier processes it. Australia’s Privacy Act makes an entity accountable for an overseas recipient’s breach (section 16C). UK GDPR requires a written processor contract. The FTC Safeguards Rule names tax preparation firms as covered financial institutions and requires them to oversee service providers. “The vendor said it was secure” is not a defence. A written answer you checked, filed against the tool in your approved tools register, is the closest thing to one.

If you have not yet decided what client data may go into any AI tool, start with the client AI data checklist, then come back to vet the tool.

The questions, grouped

1. Training: is our client audio or text used to train models?

Ask whether the vendor trains its own models on customer content, and whether the AI providers it calls do. Good: “never, by contract”, covering the vendor and every model provider, with the clause named. Red flag: an opt-out toggle, or training on “de-identified” content. Opt-out means the default is yes.

2. Sub-processors and models: who else touches the data?

Ask for the current sub-processor list (hosting, transcription, the language model, analytics, support tools) and how you will hear about changes. Good: a published, dated list with each provider’s role and location, advance notice and a right to object. Red flag: “industry-leading AI partners” with no names.

3. Data residency and cross-border transfer

Ask where recordings, transcripts and summaries are stored, and where they are processed. They can differ: data stored in Sydney can still be sent to a model hosted in the US for every summary. Good: named regions for both, ideally your choice. Red flag: a storage region with silence on processing.

4. Retention and deletion, including the raw audio

Ask whether retention is configurable, whether raw audio can be deleted while notes are kept, how long deleted data lingers in backups, and whether deletion reaches sub-processors. Good: configurable periods, a separate audio setting and a stated backup purge window. Red flag: “kept while your account is active”. For how long to keep recordings at all, see how long to keep client meeting recordings.

5. Access controls: SSO, MFA and audit logs

Ask about single sign-on with your Microsoft or Google identity, enforced multi-factor authentication for every user, role-based access, and an audit log of who viewed, shared or exported a recording. Good: yes to all four, with exportable logs. Red flag: public share links switched on by default.

6. Encryption

Ask about encryption in transit and at rest, and which vendor staff can decrypt content and under what process. Good: TLS in transit, strong encryption at rest, a named access process. Red flag: “bank-grade security” and nothing more.

7. Certifications: what they prove and what they don’t

Ask for the SOC 2 Type II report or the ISO/IEC 27001 certificate, and read the scope. A SOC 2 Type II report is a CPA firm’s opinion on whether controls were designed well and operated effectively over a period, usually several months, against AICPA criteria that always include security. ISO/IEC 27001 certifies that an information security management system is run for the scope named on the certificate. Neither says the vendor won’t train on your data, neither covers its sub-processors, and either can be scoped to exclude the product you are buying. Red flag: “SOC 2 compliant” with no report, a Type I passed off as a Type II, or a scope that does not name the product.

8. Breach notification timing

Ask how fast they will tell you after becoming aware of a breach affecting your data, and what the notice will contain. Your own clocks are short, so good is a contractual commitment in hours or a few days. Red flag: notice only “where required by law”.

9. What happens to the data when you leave

Ask for a full export in a usable format, the deletion window after cancellation and written confirmation of deletion. Red flag: data held indefinitely “for service improvement”.

Ask how the notetaker joins (a visible bot, a desktop app capturing audio, a phone in the room), whether it announces itself, whether clients get a consent prompt, and whether it joins calls the user was merely invited to. Good: a visible, named participant, an automatic notice, auto-join limited to meetings you choose. Red flag: a bot that joins every calendar event by default. Recording consent rules vary by country, state and province, so take advice on your own.

11. Integrations writing into the practice system

Ask which permissions the integration needs in your practice management software (FYI, Xero Practice Manager, AccountKit, Karbon or another), whether it respects each user’s access, and whether a person approves notes before they are posted. Good: least privilege and a review step before anything lands on a client file. Red flag: an admin-level token that writes anywhere. Notetakers built for accounting firms, such as Vinyl, push notes and actions into the practice system by design, so this is a natural first question for any of them.

The short version

QuestionGood answerRed flag
TrainingNever, by contract, incl. model providersOpt-out toggle
Sub-processorsNamed, dated list, notice of changesNo names
ResidencyStorage and processing regions namedStorage region only
RetentionConfigurable, audio separatelyKept while account is active
AccessSSO, enforced MFA, audit logPublic links on by default
CertificationsType II report, product in scope“Compliant”, no report
Breach noticeContractual, hours or days“Where required by law”
ExitFull export, written deletionIndefinite retention
Meeting botVisible, announced, opt-inJoins every event
IntegrationsLeast privilege, human reviewAdmin token

The obligations behind the questions, by market

  • Australia. If the Privacy Act applies to your firm, APP 8 requires reasonable steps, usually an enforceable contract, before disclosing personal information overseas, and section 16C makes you accountable for the recipient’s breach. The OAIC says a cloud arrangement can be a use rather than a disclosure where you keep effective control, which is why questions 2, 3 and 9 matter. APP 11 requires reasonable steps to secure information and destroy it when no longer needed. Registered tax and BAS agents also answer to Code item 6: the TPB’s TPB(GS) 55/2026 (22 July 2026) says client permission is needed before disclosing information to a third party, which can include an AI tool depending on its configuration, and recommends telling clients where data will be stored. TPB(GS) 31/2018 applies the same thinking to outsourcing and offshoring.
  • United Kingdom. UK GDPR Article 28 requires a written processor contract: instructions only, authorised sub-processors, help with breaches, deletion or return at the end, and audits. Transfers outside the UK need adequacy regulations or a safeguard such as the IDTA, with a transfer risk assessment (ICO guidance). Article 33 gives you 72 hours to report a notifiable breach.
  • United States. The FTC Safeguards Rule requires MFA, encryption and service provider oversight, and since May 2024 a report to the FTC within 30 days of a breach involving 500 or more consumers. Under IRC section 7216 regulations, a contractor maintaining your software must get written notice of the penalties, and disclosure to a preparer outside the US needs the taxpayer’s consent, with the SSN generally masked.
  • New Zealand. Privacy Act 2020 IPP 12 restricts disclosure overseas unless the recipient has comparable safeguards or the client authorises it after being told. A provider holding data only on your behalf is generally not a disclosure, but you stay responsible.
  • Canada. The OPC’s PIPEDA cross-border guidelines treat transfer for processing as a use, require comparable protection by contract, and expect clients to be told their information may be processed abroad.
  • South Africa. POPIA section 72 allows transfers abroad with adequate protection by law or binding agreement, client consent, or another listed ground. Section 21 requires a written operator contract.

This is general information, not legal advice. Check your own position with your adviser or professional body.

How to use the answers

Send the questions before the trial, not after a month of client calls. Ask for written answers with links to the contract terms behind them. Score each one good, fixable with a setting, or red flag. One red flag on training, residency or breach notice should end the evaluation for client meetings. File the answers in your AI policy and recheck them at renewal. Our guide to whether AI is safe for client data covers the policy side, the AI and automation directory lists tools, and the AI meeting assistants guide explains what each type does.

Frequently asked questions

Often, for two separate reasons: recording laws in many places require the other party to know or agree, and rules such as the TPB’s Code item 6 and section 7216 in the US can require permission before client information reaches a third party. An engagement letter clause plus a spoken notice at the start of the call covers most firms.

Is a SOC 2 Type II report enough on its own?

No. It shows the in-scope controls worked over the audit period. Read the exceptions the auditor noted, then ask the other ten questions anyway.

What if the vendor refuses to share its sub-processor list?

Treat that as the answer. UK GDPR requires your authorisation for sub-processors, and APP 8 and POPIA section 72 both turn on knowing who receives the data and where. If a vendor will not say, the tool should not hear client calls.

Should the questions differ for internal meetings?

The bar can be lower for stand-ups with no client detail, but the two are hard to keep apart once a bot is on every invite. Vetting to the client standard and limiting auto-join is simpler than running two policies.

How often should we re-ask these questions?

At each renewal, and whenever the vendor announces a new model, region or terms. Keep the original answers, because your clients’ permission was given against them.

Sponsored

Abby — compliance automation and workpapers for busy accountants. Start your free 30-day trial.

AIMeeting NotesData SecurityPrivacyVendor Due Diligence

Was this useful?
Thanks — noted.

Sponsored

Easy Business App
Read next
Related
Listen next