[Firm name] client AI data checklist
Replace everything in [square brackets].
Before you use the tool
- The tool is on the firm's approved list: [approved tools].
- You are logged in to the firm's account, not a personal one.
- The plan does not train on our data (it is in the register; if you are not sure, ask before you paste).
- You know what you are asking it to do, and whether the task needs client data at all.
- The client has not asked us to keep their work out of AI tools (check the client file).
- For a recorded meeting: everyone in it agreed to the recording at the start.
Green: fine in any approved tool
- Information that is already public: legislation, published guidance, a public company report, a website.
- The firm's own templates, checklists, process notes and marketing copy.
- General questions about tax, accounting or software that do not name or describe a client.
- Figures and scenarios you have made up, or anonymised so no client can be recognised.
Amber: approved tool, identifiers out, reviewer signs off
- Client financial statements, trial balances and management accounts.
- Transaction lists and bank or card exports.
- Emails and letters to or from a client.
- Meeting recordings, transcripts and notes.
- Payroll summaries (with employee names and identifiers removed).
Strip before you paste, wherever the task still works without it:
- Replace client, staff and customer names with roles ("Client A", "Employee 2", "Customer").
- Delete account numbers, BSBs, sort codes, routing numbers and card numbers.
- Delete addresses, phone numbers, email addresses and dates of birth.
- Round or band figures when the exact amount does not matter to the question.
- Rename files so the file name does not carry the client name.
Red: never goes in
- Tax file numbers, National Insurance numbers, Social Security numbers, ITINs and any other government identifier for a person.
- Bank account, card and payment details in full.
- Passwords, login details, security codes and API keys, for any system.
- Passports, driving licences and other identity documents.
- Health and medical information about anyone.
- Anything received under a confidentiality agreement that does not allow third-party processing.
- Anything a client has asked us to keep out of AI tools or third-party systems.
- US tax return information where Section 7216 requires the client's written consent and we do not have it.
The only exception is a specific tool and process the policy owner has approved in writing for that kind of data.
After: before anything leaves the firm
- Figures checked against the source documents, not against the tool.
- Every reference to legislation, a ruling or a standard checked against the primary source.
- The output answers the client's actual question, in our words.
- No client details in a shared chat link, public workspace or prompt library.
- Final version and your checks saved to the client file.
- Uploaded files deleted from the tool if it keeps them and you no longer need them there.
The obligations behind the lists
No regulator has written an AI-specific rule for accountants yet. The lists above come from obligations that already apply to anything you put into any third-party system:
| Market | What applies |
|---|---|
| Australia | The TPB Code of Professional Conduct requires registered tax and BAS agents to keep client information confidential, and APES 110 applies confidentiality and competence and due care to members of CA ANZ, CPA Australia and the IPA. If the Privacy Act applies to your firm, sending personal information to an AI provider that processes it offshore is a cross-border disclosure under APP 8. |
| United Kingdom | The ICAEW, ACCA and AAT codes carry the same fundamental principles of confidentiality and professional competence. UK GDPR governs personal data you send to a processor, so treat an AI vendor as one: a contract, a lawful basis and a record of what goes in. |
| United States | The AICPA Code's confidential client information rule applies. Section 7216 of the Internal Revenue Code restricts how tax return preparers use and disclose return information, so check whether sending it to a third-party AI tool needs the client's written consent. Circular 230 still governs practice before the IRS. |
This template is a starting point, not legal advice. Your obligations depend on where you practise, your professional body and your clients; take advice on anything you are unsure of.