AI Governance

AI policy for Australian accounting firms: practical template and guidance

Most accounting firms are already using AI somewhere, even if the practice has never formally approved it.

It may be built into Microsoft products, document software, accounting platforms, meeting tools or tax research systems. Staff may also be using standalone AI tools to draft emails, summarise documents or answer technical questions.

That makes an AI policy useful for two reasons. First, it tells staff what they may and may not do with client information. Second, it gives the firm a documented way to connect AI use with its professional obligations, quality management system, privacy controls and review procedures.

The policy does not need to prohibit useful technology. It should make the safe path obvious.

Published 23 August 2026. Last reviewed 23 August 2026. Technically reviewed by the Taxpartna tax team.

What an accounting firm's AI policy should cover

A practical policy should address at least these areas:

  1. 1purpose and scope
  2. 2approved and prohibited tools
  3. 3permitted use cases
  4. 4confidential client information
  5. 5client permission and third-party disclosure
  6. 6human review and professional judgement
  7. 7technical tax research
  8. 8record keeping
  9. 9staff supervision and training
  10. 10automated actions and decision making
  11. 11vendor due diligence
  12. 12incident reporting
  13. 13monitoring and policy review

The level of detail should match the size and complexity of the practice.

1. Purpose and scope

The policy should apply to everyone who can access firm or client information, including partners, employees, contractors and offshore team members where relevant.

It should cover standalone AI products and AI features embedded inside other software.

A narrow policy that only names ChatGPT will become outdated quickly.

2. Approved tools

Create a clear approval process.

Staff should know that a tool is not approved merely because:

  • it is free
  • it is widely used
  • it is supplied by a large technology company
  • it is built into software the firm already licenses
  • another accounting firm uses it

The firm should maintain a simple approved tools register showing:

  • product name
  • approved use cases
  • whether client information may be used
  • any restrictions
  • date approved
  • person responsible for review

3. Permitted and prohibited use cases

A good policy distinguishes low-risk and high-risk use.

Low-risk uses might include:

  • rewriting non-confidential internal text
  • generating generic meeting agendas
  • brainstorming training topics
  • summarising public material

Higher-risk uses include:

  • uploading client tax files
  • providing TFNs or identity documents
  • generating tax advice
  • making client acceptance decisions
  • creating calculations relied on in returns
  • sending AI-generated material directly to clients

The policy can permit higher-risk use through approved systems with appropriate review rather than banning it outright.

4. Confidential client information

This should be one of the clearest parts of the policy.

Staff should not enter confidential client information into an unapproved AI service.

The policy should address:

  • names and contact details
  • TFNs
  • dates of birth
  • bank details
  • identity documents
  • tax returns
  • financial statements
  • payroll data
  • trust and company documents
  • client correspondence

It should also warn that removing a client's name may not be enough to make detailed facts genuinely anonymous.

5. Client permission and third-party disclosure

The Tax Practitioners Board's 2026 AI guidance states that tax practitioners must obtain client permission before divulging client information to a third party, which can include use of AI chatbots or copilots depending on configuration and use.

The firm's policy should therefore require staff to use only approved tools for which the disclosure position has been assessed.

Where client permission is required, the firm should identify the approved engagement letter or consent wording rather than leaving each staff member to ask the client informally. Our guide on client permission to use AI explains this in more detail.

6. Human review and professional judgement

AI output should not be treated as final professional work.

For tax agent services, the registered practitioner remains responsible for competence, reasonable care and correct application of the tax law.

The policy should require an appropriately competent person to review AI-generated material before it is:

  • relied upon in a tax return
  • used to make a professional recommendation
  • sent to a client
  • used to resolve a review issue
  • incorporated into a formal file note or advice document

The reviewer should be able to understand the source information and challenge the output where necessary.

7. Technical tax research

AI can be useful for finding issues and explaining concepts, but it can also produce authorities that do not exist or rely on outdated law.

A sensible policy should require technical conclusions to be checked against reliable sources.

For material tax matters:

  • verify legislation, rulings and cases independently
  • check that citations exist and say what the AI claims
  • confirm the source is current
  • do not rely on an AI-generated quotation without checking it
  • record the research basis where the matter is complex or material

The policy can distinguish between using AI to find a starting point and using a verified authority to support the final conclusion.

8. Record keeping

The TPB requires registered tax practitioners to keep proper records of tax agent services provided.

The AI policy should tell staff what to retain when AI materially contributes to a tax engagement.

Depending on the use case, the file may need to show:

  • the task performed
  • source documents considered
  • material output or finding
  • how the output was checked
  • changes made by the practitioner
  • the final conclusion

It is not always necessary to retain every prompt ever entered. The firm should decide what is needed to evidence the service and the review performed.

9. Supervision and training

Staff need enough training to understand both the capability and limitations of the tools they are allowed to use.

Training should cover:

  • approved tools
  • prohibited data
  • confidentiality
  • hallucinations and unsupported answers
  • source checking
  • human review expectations
  • incident reporting

Supervision should reflect the user's experience and the risk of the task.

A graduate using AI for a complex restructuring issue should not be treated the same as a partner using an approved tool to summarise a public ATO page.

10. Automated actions

Some AI systems can now send emails, change records, lodge forms or trigger workflows.

The policy should state which actions require human approval.

For a tax practice, high-consequence actions should generally remain under human control, particularly where they affect:

  • lodgements
  • client instructions
  • financial transactions
  • regulatory reporting
  • acceptance or rejection of a client
  • final tax positions

11. Vendor due diligence

Before approving a tool that will receive client information, the firm should assess:

  • data recipients
  • processing and storage locations
  • model providers and subprocessors
  • retention
  • training use
  • security controls
  • TFN handling
  • source traceability
  • human review features
  • testing and change control
  • contractual terms

The assessment should be retained and revisited when the product changes materially. Our AI vendor due diligence checklist for tax agents sets out the questions in full.

12. Incident reporting

The policy should tell staff what to do if client information is entered into the wrong tool or an AI product behaves unexpectedly.

The first response should be internal escalation, not concealment.

The procedure should cover:

  • who must be notified
  • how access or sharing can be stopped
  • whether deletion can be requested
  • whether the privacy incident process is triggered
  • whether the client or regulator must be notified
  • how the root cause will be addressed

13. Monitoring and policy review

AI products change quickly.

Review the policy when:

  • a new high-risk tool is approved
  • a model provider changes
  • data locations change
  • the vendor changes its terms
  • professional guidance changes
  • an incident reveals a weakness

A scheduled annual review is sensible even if none of those events occurs.

Sample AI policy for an Australian accounting firm

The following template is deliberately practical. It should be adapted to the firm's actual systems, engagement terms and legal obligations before adoption.

Artificial Intelligence Use Policy

1. Purpose

This policy sets the firm's requirements for the responsible use of artificial intelligence systems in firm operations and client work. The objective is to obtain the productivity benefits of AI while protecting confidential information, maintaining professional standards and keeping human judgement and accountability with the firm.

2. Scope

This policy applies to all partners, employees, contractors and other persons who access firm systems or client information.

It applies to standalone AI services and AI functionality embedded within other software.

3. Approved tools

Only AI tools approved by the firm may be used with confidential firm or client information.

The firm will maintain an approved tools register that records the permitted use cases and any restrictions applying to each product.

Staff must not assume that a tool is approved because it is publicly available, supplied by a major technology provider or included within existing software.

4. Confidential information

Confidential client information must not be entered into an unapproved AI tool.

This includes tax file numbers, identity documents, tax returns, financial statements, bank details, payroll records, trust and company documents, client correspondence and other information obtained in the course of an engagement.

Staff must not attempt to avoid this rule by removing a client's name where the remaining information could still identify the client.

5. Client permission and disclosures

Where use of an approved AI tool involves disclosure of client information to a third party, the firm must confirm that appropriate client permission or other lawful authority has been obtained before the disclosure occurs.

Staff must use the firm's approved engagement or consent process and must not create their own consent wording without approval.

6. Professional responsibility

AI does not replace professional judgement.

A person responsible for tax or accounting work must remain satisfied that the final work is accurate, appropriate and supported by the relevant facts and authorities.

AI-generated content must be reviewed by a person with sufficient competence to identify errors before it is relied upon or provided to a client.

7. Technical research

AI may be used to assist technical research where the use is otherwise approved.

Material legal, tax or regulatory conclusions must be verified against reliable primary or authoritative sources before reliance.

AI-generated cases, rulings, legislative references and quotations must not be accepted without checking the original source.

8. Tax calculations and return preparation

AI-generated calculations must be checked before being used in a tax return or advice.

Where an approved system uses deterministic calculations or defined tax logic, the user must still review exceptions and confirm that the input facts are complete and appropriate.

9. Client communications

AI may assist with drafting client communications where the tool and data use are approved.

The person sending the communication remains responsible for its accuracy, tone and professional appropriateness.

Material advice must not be sent directly from an AI system to a client without appropriate human review.

10. Record keeping

Where AI materially contributes to a client tax service, the client file must contain enough information to show the nature and outcome of the work and how material AI output was reviewed.

The firm is not required by this policy to retain every prompt unless the prompt itself is necessary to understand or evidence the service provided.

11. Supervision

Managers and partners are responsible for supervising AI use within their teams in the same way they supervise other work.

The level of supervision must reflect the experience of the user, the complexity of the task and the consequence of an incorrect output.

12. Automated actions

AI systems must not lodge tax forms, send material advice, move client money, make regulatory reports or make final client acceptance decisions without the level of human approval required by the firm's procedures.

13. Vendor approval

AI products that will receive confidential client information must undergo the firm's vendor due diligence process before approval.

The review must consider data handling, third parties, security, retention, model use, human review capability and relevant contractual terms.

14. Incidents

Any actual or suspected disclosure of client information to an unapproved AI tool, material AI error, security incident or unexpected automated action must be reported promptly to the firm's nominated responsible person.

Staff should preserve relevant information and follow the firm's privacy, security and professional incident procedures.

15. Training

Users of approved AI tools must complete any training required by the firm and remain familiar with the restrictions applying to the relevant tool.

16. Breaches

Use of AI outside this policy may result in removal of system access and may be dealt with under the firm's normal employment, contractor or professional conduct procedures.

17. Review of this policy

The firm will review this policy at least annually and earlier where there is a material change to technology, regulation, professional guidance or the firm's approved AI systems.

Implementation checklist for practice owners

A policy is only useful if it matches what people actually do.

Before publishing the policy internally:

  • identify the AI tools already being used across the firm
  • disable or restrict unapproved products where practical
  • complete vendor due diligence for tools that receive client information
  • update engagement letters if required
  • create the approved tools register
  • train staff on the new policy
  • nominate a person responsible for AI governance
  • connect AI incidents with the firm's privacy and cyber incident process
  • decide what evidence should be retained on tax files
  • review the policy within the firm's quality management system

The firm's quality management system obligations for tax agents are a natural home for the AI policy.

Where Taxpartna fits

Taxpartna is designed to sit inside a controlled professional review process.

It can be listed in a firm's approved tools register with the use case, data handling conditions, reviewer responsibilities and retention settings that the firm has approved. It is one example of AI tax software for accountants that is built for a supervised review workflow.

Taxpartna does not replace the firm's AI policy or quality management system. The firm remains responsible for deciding how the platform may be used and how staff review the results.

Authoritative sources

An AI policy connects to TPB obligations and the Australian Privacy Principles. The following primary sources should be checked when this page is technically reviewed or materially updated.

Frequently asked questions

There is no single rule requiring every accounting firm to have a document titled "AI policy". A documented policy is a practical way to manage confidentiality, competence, supervision, record keeping and quality management obligations when AI is used.

That depends on the firm's risk settings. Many firms will allow low-risk use that does not involve client information while prohibiting confidential client data from being entered into unapproved systems.

Where client information may be disclosed to third parties through approved AI tools, the firm should consider how client permission is obtained and whether the engagement terms adequately explain the disclosure. See our guide on when a tax agent needs client permission to use AI.

Responsibility should sit with a person senior enough to coordinate professional, privacy, security and operational issues. In a smaller firm this may be a partner. Larger firms may split responsibility across several functions but should still nominate a clear owner.

At least annually is a sensible baseline, with earlier review when tools, vendors, data arrangements or professional guidance change materially.

Important information. This page and sample policy provide general information only. The template should be adapted to the firm's actual systems, professional obligations, privacy position and engagement arrangements before use. It is not legal advice. Taxpartna is a quality assurance assistance platform and does not provide tax advice, legal advice or final sign-off.