AI policy for Australian accounting firms: practical template and guidance
Most accounting firms are already using AI somewhere, even if the practice has never formally approved it.
It may be built into Microsoft products, document software, accounting platforms, meeting tools or tax research systems. Staff may also be using standalone AI tools to draft emails, summarise documents or answer technical questions.
That makes an AI policy useful for two reasons. First, it tells staff what they may and may not do with client information. Second, it gives the firm a documented way to connect AI use with its professional obligations, quality management system, privacy controls and review procedures.
The policy does not need to prohibit useful technology. It should make the safe path obvious.
Published 23 August 2026. Last reviewed 23 August 2026. Technically reviewed by the Taxpartna tax team.
What an accounting firm's AI policy should cover
A practical policy should address at least these areas:
- 1purpose and scope
- 2approved and prohibited tools
- 3permitted use cases
- 4confidential client information
- 5client permission and third-party disclosure
- 6human review and professional judgement
- 7technical tax research
- 8record keeping
- 9staff supervision and training
- 10automated actions and decision making
- 11vendor due diligence
- 12incident reporting
- 13monitoring and policy review
The level of detail should match the size and complexity of the practice.
1. Purpose and scope
The policy should apply to everyone who can access firm or client information, including partners, employees, contractors and offshore team members where relevant.
It should cover standalone AI products and AI features embedded inside other software.
A narrow policy that only names ChatGPT will become outdated quickly.
2. Approved tools
Create a clear approval process.
Staff should know that a tool is not approved merely because:
- it is free
- it is widely used
- it is supplied by a large technology company
- it is built into software the firm already licenses
- another accounting firm uses it
The firm should maintain a simple approved tools register showing:
- product name
- approved use cases
- whether client information may be used
- any restrictions
- date approved
- person responsible for review
3. Permitted and prohibited use cases
A good policy distinguishes low-risk and high-risk use.
Low-risk uses might include:
- rewriting non-confidential internal text
- generating generic meeting agendas
- brainstorming training topics
- summarising public material
Higher-risk uses include:
- uploading client tax files
- providing TFNs or identity documents
- generating tax advice
- making client acceptance decisions
- creating calculations relied on in returns
- sending AI-generated material directly to clients
The policy can permit higher-risk use through approved systems with appropriate review rather than banning it outright.
4. Confidential client information
This should be one of the clearest parts of the policy.
Staff should not enter confidential client information into an unapproved AI service.
The policy should address:
- names and contact details
- TFNs
- dates of birth
- bank details
- identity documents
- tax returns
- financial statements
- payroll data
- trust and company documents
- client correspondence
It should also warn that removing a client's name may not be enough to make detailed facts genuinely anonymous.
5. Client permission and third-party disclosure
The Tax Practitioners Board's 2026 AI guidance states that tax practitioners must obtain client permission before divulging client information to a third party, which can include use of AI chatbots or copilots depending on configuration and use.
The firm's policy should therefore require staff to use only approved tools for which the disclosure position has been assessed.
Where client permission is required, the firm should identify the approved engagement letter or consent wording rather than leaving each staff member to ask the client informally. Our guide on client permission to use AI explains this in more detail.
6. Human review and professional judgement
AI output should not be treated as final professional work.
For tax agent services, the registered practitioner remains responsible for competence, reasonable care and correct application of the tax law.
The policy should require an appropriately competent person to review AI-generated material before it is:
- relied upon in a tax return
- used to make a professional recommendation
- sent to a client
- used to resolve a review issue
- incorporated into a formal file note or advice document
The reviewer should be able to understand the source information and challenge the output where necessary.
7. Technical tax research
AI can be useful for finding issues and explaining concepts, but it can also produce authorities that do not exist or rely on outdated law.
A sensible policy should require technical conclusions to be checked against reliable sources.
For material tax matters:
- verify legislation, rulings and cases independently
- check that citations exist and say what the AI claims
- confirm the source is current
- do not rely on an AI-generated quotation without checking it
- record the research basis where the matter is complex or material
The policy can distinguish between using AI to find a starting point and using a verified authority to support the final conclusion.
8. Record keeping
The TPB requires registered tax practitioners to keep proper records of tax agent services provided.
The AI policy should tell staff what to retain when AI materially contributes to a tax engagement.
Depending on the use case, the file may need to show:
- the task performed
- source documents considered
- material output or finding
- how the output was checked
- changes made by the practitioner
- the final conclusion
It is not always necessary to retain every prompt ever entered. The firm should decide what is needed to evidence the service and the review performed.
9. Supervision and training
Staff need enough training to understand both the capability and limitations of the tools they are allowed to use.
Training should cover:
- approved tools
- prohibited data
- confidentiality
- hallucinations and unsupported answers
- source checking
- human review expectations
- incident reporting
Supervision should reflect the user's experience and the risk of the task.
A graduate using AI for a complex restructuring issue should not be treated the same as a partner using an approved tool to summarise a public ATO page.
10. Automated actions
Some AI systems can now send emails, change records, lodge forms or trigger workflows.
The policy should state which actions require human approval.
For a tax practice, high-consequence actions should generally remain under human control, particularly where they affect:
- lodgements
- client instructions
- financial transactions
- regulatory reporting
- acceptance or rejection of a client
- final tax positions
11. Vendor due diligence
Before approving a tool that will receive client information, the firm should assess:
- data recipients
- processing and storage locations
- model providers and subprocessors
- retention
- training use
- security controls
- TFN handling
- source traceability
- human review features
- testing and change control
- contractual terms
The assessment should be retained and revisited when the product changes materially. Our AI vendor due diligence checklist for tax agents sets out the questions in full.
12. Incident reporting
The policy should tell staff what to do if client information is entered into the wrong tool or an AI product behaves unexpectedly.
The first response should be internal escalation, not concealment.
The procedure should cover:
- who must be notified
- how access or sharing can be stopped
- whether deletion can be requested
- whether the privacy incident process is triggered
- whether the client or regulator must be notified
- how the root cause will be addressed
13. Monitoring and policy review
AI products change quickly.
Review the policy when:
- a new high-risk tool is approved
- a model provider changes
- data locations change
- the vendor changes its terms
- professional guidance changes
- an incident reveals a weakness
A scheduled annual review is sensible even if none of those events occurs.
Sample AI policy for an Australian accounting firm
The following template is deliberately practical. It should be adapted to the firm's actual systems, engagement terms and legal obligations before adoption.
Artificial Intelligence Use Policy
1. Purpose
This policy sets the firm's requirements for the responsible use of artificial intelligence systems in firm operations and client work. The objective is to obtain the productivity benefits of AI while protecting confidential information, maintaining professional standards and keeping human judgement and accountability with the firm.
2. Scope
This policy applies to all partners, employees, contractors and other persons who access firm systems or client information.
It applies to standalone AI services and AI functionality embedded within other software.
3. Approved tools
Only AI tools approved by the firm may be used with confidential firm or client information.
The firm will maintain an approved tools register that records the permitted use cases and any restrictions applying to each product.
Staff must not assume that a tool is approved because it is publicly available, supplied by a major technology provider or included within existing software.
4. Confidential information
Confidential client information must not be entered into an unapproved AI tool.
This includes tax file numbers, identity documents, tax returns, financial statements, bank details, payroll records, trust and company documents, client correspondence and other information obtained in the course of an engagement.
Staff must not attempt to avoid this rule by removing a client's name where the remaining information could still identify the client.
5. Client permission and disclosures
Where use of an approved AI tool involves disclosure of client information to a third party, the firm must confirm that appropriate client permission or other lawful authority has been obtained before the disclosure occurs.
Staff must use the firm's approved engagement or consent process and must not create their own consent wording without approval.
6. Professional responsibility
AI does not replace professional judgement.
A person responsible for tax or accounting work must remain satisfied that the final work is accurate, appropriate and supported by the relevant facts and authorities.
AI-generated content must be reviewed by a person with sufficient competence to identify errors before it is relied upon or provided to a client.
7. Technical research
AI may be used to assist technical research where the use is otherwise approved.
Material legal, tax or regulatory conclusions must be verified against reliable primary or authoritative sources before reliance.
AI-generated cases, rulings, legislative references and quotations must not be accepted without checking the original source.
8. Tax calculations and return preparation
AI-generated calculations must be checked before being used in a tax return or advice.
Where an approved system uses deterministic calculations or defined tax logic, the user must still review exceptions and confirm that the input facts are complete and appropriate.
9. Client communications
AI may assist with drafting client communications where the tool and data use are approved.
The person sending the communication remains responsible for its accuracy, tone and professional appropriateness.
Material advice must not be sent directly from an AI system to a client without appropriate human review.
10. Record keeping
Where AI materially contributes to a client tax service, the client file must contain enough information to show the nature and outcome of the work and how material AI output was reviewed.
The firm is not required by this policy to retain every prompt unless the prompt itself is necessary to understand or evidence the service provided.
11. Supervision
Managers and partners are responsible for supervising AI use within their teams in the same way they supervise other work.
The level of supervision must reflect the experience of the user, the complexity of the task and the consequence of an incorrect output.
12. Automated actions
AI systems must not lodge tax forms, send material advice, move client money, make regulatory reports or make final client acceptance decisions without the level of human approval required by the firm's procedures.
13. Vendor approval
AI products that will receive confidential client information must undergo the firm's vendor due diligence process before approval.
The review must consider data handling, third parties, security, retention, model use, human review capability and relevant contractual terms.
14. Incidents
Any actual or suspected disclosure of client information to an unapproved AI tool, material AI error, security incident or unexpected automated action must be reported promptly to the firm's nominated responsible person.
Staff should preserve relevant information and follow the firm's privacy, security and professional incident procedures.
15. Training
Users of approved AI tools must complete any training required by the firm and remain familiar with the restrictions applying to the relevant tool.
16. Breaches
Use of AI outside this policy may result in removal of system access and may be dealt with under the firm's normal employment, contractor or professional conduct procedures.
17. Review of this policy
The firm will review this policy at least annually and earlier where there is a material change to technology, regulation, professional guidance or the firm's approved AI systems.
Implementation checklist for practice owners
A policy is only useful if it matches what people actually do.
Before publishing the policy internally:
- identify the AI tools already being used across the firm
- disable or restrict unapproved products where practical
- complete vendor due diligence for tools that receive client information
- update engagement letters if required
- create the approved tools register
- train staff on the new policy
- nominate a person responsible for AI governance
- connect AI incidents with the firm's privacy and cyber incident process
- decide what evidence should be retained on tax files
- review the policy within the firm's quality management system
The firm's quality management system obligations for tax agents are a natural home for the AI policy.
Where Taxpartna fits
Taxpartna is designed to sit inside a controlled professional review process.
It can be listed in a firm's approved tools register with the use case, data handling conditions, reviewer responsibilities and retention settings that the firm has approved. It is one example of AI tax software for accountants that is built for a supervised review workflow.
Taxpartna does not replace the firm's AI policy or quality management system. The firm remains responsible for deciding how the platform may be used and how staff review the results.
Authoritative sources
An AI policy connects to TPB obligations and the Australian Privacy Principles. The following primary sources should be checked when this page is technically reviewed or materially updated.
- TPB - The use of Artificial Intelligence and the Code of Professional Conduct
- TPB - Keeping proper client records
- OAIC - Australian Privacy Principles
- TPB - Factsheets
Frequently asked questions
There is no single rule requiring every accounting firm to have a document titled "AI policy". A documented policy is a practical way to manage confidentiality, competence, supervision, record keeping and quality management obligations when AI is used.
Important information. This page and sample policy provide general information only. The template should be adapted to the firm's actual systems, professional obligations, privacy position and engagement arrangements before use. It is not legal advice. Taxpartna is a quality assurance assistance platform and does not provide tax advice, legal advice or final sign-off.
