You're offline — showing the last version we saved.
Free template

Client AI data checklist: what can go into an AI tool

The question every team member asks before they paste something into an assistant: is this allowed? This checklist answers it in green, amber and red, with the checks to run before and after. It sits under the AI policy template and works on its own.

Updated · Editable Word document (.docx) · Free

How to use it

How to use this template

  1. Put your approved tools at the top

    List the tools your firm has approved (from your AI policy register), so the first check is a glance, not a question.

  2. Adjust the three lists to your clients

    Add anything specific to your client base: trust deeds, medical practices, government contracts, clients under a confidentiality agreement.

  3. Pin it where the work happens

    Print it, add it to your intranet, or save it next to the prompt library. It only works if it is in front of people at the moment they paste.

  4. Use it in reviews

    Reviewers check the "after" list when they sign off AI-assisted work. It takes a minute and catches most problems.

The template

The template in full

[Firm name] client AI data checklist

Replace everything in [square brackets].

Before you use the tool

  • The tool is on the firm's approved list: [approved tools].
  • You are logged in to the firm's account, not a personal one.
  • The plan does not train on our data (it is in the register; if you are not sure, ask before you paste).
  • You know what you are asking it to do, and whether the task needs client data at all.
  • The client has not asked us to keep their work out of AI tools (check the client file).
  • For a recorded meeting: everyone in it agreed to the recording at the start.

Green: fine in any approved tool

  • Information that is already public: legislation, published guidance, a public company report, a website.
  • The firm's own templates, checklists, process notes and marketing copy.
  • General questions about tax, accounting or software that do not name or describe a client.
  • Figures and scenarios you have made up, or anonymised so no client can be recognised.

Amber: approved tool, identifiers out, reviewer signs off

  • Client financial statements, trial balances and management accounts.
  • Transaction lists and bank or card exports.
  • Emails and letters to or from a client.
  • Meeting recordings, transcripts and notes.
  • Payroll summaries (with employee names and identifiers removed).

Strip before you paste, wherever the task still works without it:

  • Replace client, staff and customer names with roles ("Client A", "Employee 2", "Customer").
  • Delete account numbers, BSBs, sort codes, routing numbers and card numbers.
  • Delete addresses, phone numbers, email addresses and dates of birth.
  • Round or band figures when the exact amount does not matter to the question.
  • Rename files so the file name does not carry the client name.

Red: never goes in

  • Tax file numbers, National Insurance numbers, Social Security numbers, ITINs and any other government identifier for a person.
  • Bank account, card and payment details in full.
  • Passwords, login details, security codes and API keys, for any system.
  • Passports, driving licences and other identity documents.
  • Health and medical information about anyone.
  • Anything received under a confidentiality agreement that does not allow third-party processing.
  • Anything a client has asked us to keep out of AI tools or third-party systems.
  • US tax return information where Section 7216 requires the client's written consent and we do not have it.

The only exception is a specific tool and process the policy owner has approved in writing for that kind of data.

After: before anything leaves the firm

  • Figures checked against the source documents, not against the tool.
  • Every reference to legislation, a ruling or a standard checked against the primary source.
  • The output answers the client's actual question, in our words.
  • No client details in a shared chat link, public workspace or prompt library.
  • Final version and your checks saved to the client file.
  • Uploaded files deleted from the tool if it keeps them and you no longer need them there.

The obligations behind the lists

No regulator has written an AI-specific rule for accountants yet. The lists above come from obligations that already apply to anything you put into any third-party system:

MarketWhat applies
AustraliaThe TPB Code of Professional Conduct requires registered tax and BAS agents to keep client information confidential, and APES 110 applies confidentiality and competence and due care to members of CA ANZ, CPA Australia and the IPA. If the Privacy Act applies to your firm, sending personal information to an AI provider that processes it offshore is a cross-border disclosure under APP 8.
United KingdomThe ICAEW, ACCA and AAT codes carry the same fundamental principles of confidentiality and professional competence. UK GDPR governs personal data you send to a processor, so treat an AI vendor as one: a contract, a lawful basis and a record of what goes in.
United StatesThe AICPA Code's confidential client information rule applies. Section 7216 of the Internal Revenue Code restricts how tax return preparers use and disclose return information, so check whether sending it to a third-party AI tool needs the client's written consent. Circular 230 still governs practice before the IRS.

This template is a starting point, not legal advice. Your obligations depend on where you practise, your professional body and your clients; take advice on anything you are unsure of.

Common questions

Frequently asked questions

What client data should never go into an AI tool?
Government identifiers such as tax file numbers and Social Security numbers, bank and card details, passwords and login details, identity documents, health information, anything under a confidentiality agreement that rules out third-party processing, and anything a client has asked you to keep out. Treat these as never, unless your firm has approved a specific tool and process for them in writing.
Is de-identified client data safe to use with AI?
Safer, not automatically safe. Removing names and account numbers lowers the risk, but a client can still be recognisable from a distinctive business, location or set of figures. Use de-identified data in an approved, business-tier tool, and have a reviewer check the output before it is used.
Do I need client consent to use AI on their work?
It depends on the work and the market. For US tax work, Section 7216 can require the client's written consent before return information goes to a third party. Elsewhere, telling clients in your engagement letter how you use AI, and honouring a request not to, is the standard to meet. Recording a meeting needs everyone's agreement.
Does this apply to AI features inside Xero or my practice software?
Yes. AI features inside your ledger or practice management system process client data within that vendor's systems, under your existing agreement with them, which usually makes them the lower-risk option. Check the feature's settings and the vendor's data terms, and list the feature in your approved tools register like any other tool.
More templates

More templates

The thinking behind these: AI for accountants and bookkeepers: what actually works.

Get your free seat →

AI in Practice Summit returns. What worked, what's next: two days on what AI actually did for firms this year, and where it goes in 2027. 11–12 November 2026, virtual and free.