AI Governance

AI vendor due diligence checklist for Australian tax agents

The most important questions about an AI product are usually not the ones answered in the demonstration.

A vendor can show that its software drafts quickly, reads documents or produces a polished tax answer. An accounting firm still needs to understand what happens to client information, how the output is produced, what can go wrong and whether the firm can use the tool while meeting its professional obligations.

The Tax Practitioners Board's 2026 guidance on artificial intelligence makes the basic position clear. The practitioner remains responsible for the tax agent service. AI does not take over responsibility for competence, reasonable care, confidentiality, supervision or record keeping.

That makes vendor due diligence a professional practice issue, not just an IT purchasing exercise.

Published 23 August 2026. Last reviewed 23 August 2026. Technically reviewed by the Taxpartna tax team.

Start by defining what the product will actually do

Before reviewing the vendor, define the use case.

A tool used to rewrite an internal email creates a different risk from a tool that receives complete client tax files and produces technical recommendations.

Record:

  • the task the tool will perform
  • the type of client information it will receive
  • whether TFNs or identity documents may be included
  • whether outputs will be sent to clients
  • whether staff are expected to rely on the output for tax work
  • whether the tool can take actions without a person approving them

The level of due diligence should match the risk of the intended use.

1. Who receives the client data?

Ask the vendor to describe the complete data path, not just the name of the product.

Questions to ask:

  • Does client data leave the vendor's own environment?
  • Is a third-party model provider used?
  • Which model provider receives prompts, files or extracted text?
  • Are subprocessors used for storage, logging, analytics, support or model inference?
  • Can vendor staff access client content?
  • Can overseas support staff access the environment?

A statement such as "we use enterprise AI" is not enough. The firm needs to know who actually receives the information.

2. Where is information processed and stored?

Ask for the locations used for:

  • file storage
  • temporary processing
  • model inference
  • backups
  • logs
  • disaster recovery
  • support access

Data may be stored in Australia but processed elsewhere. Those are separate questions.

If information is disclosed overseas, the firm should consider its confidentiality and privacy obligations and any client permission required for the arrangement. Our page on when a tax agent needs client permission to use AI covers that analysis.

3. Is client information used for model training?

Ask for a direct answer in writing.

Questions include:

  • Is customer data used to train the vendor's own models?
  • Is it used to train a third-party model provider's models?
  • Is it used for product improvement, evaluation or human review?
  • Can the firm opt out?
  • Does the contract override broader terms that might otherwise permit training or improvement use?

"Not used to train the public model" is narrower than "not used for training or product improvement". Read the actual wording.

4. How long is the data retained?

Retention should be understood at each layer.

Ask:

  • How long are uploaded files kept?
  • How long are prompts and outputs kept?
  • How long are logs kept?
  • Are backups deleted on the same timetable?
  • Can the firm set its own retention period?
  • What happens when the account is closed?
  • Can the vendor confirm deletion?

Short retention may reduce risk, but the accounting firm also needs to consider what evidence it should retain in its own client file.

5. What security controls are in place?

Useful areas to review include:

  • multi-factor authentication
  • role-based access
  • encryption in transit and at rest
  • audit logging
  • security monitoring
  • vulnerability management
  • penetration testing
  • incident response
  • independent assurance such as SOC reports or recognised security certifications
  • backup and recovery arrangements

Do not treat a certification logo as the entire due diligence process. Ask what part of the service is actually within scope.

6. How does the vendor deal with TFNs and identity information?

Tax files contain information that is more sensitive than ordinary business documents.

Ask whether the product is designed to handle:

  • TFNs
  • dates of birth
  • addresses
  • identity documents
  • bank details
  • payroll information
  • trust and company ownership information

The firm should consider the Privacy Act, the Privacy (Tax File Number) Rule 2015 where applicable and its professional confidentiality obligations.

If the vendor's answer is simply "do not upload sensitive information", the product may not be suitable for the proposed tax workflow.

7. Does the tool show where its answer came from?

For professional work, an answer is far more useful when it can be checked quickly.

Ask:

  • Does each material finding link back to the source document?
  • Can the reviewer see the values that were compared?
  • Are technical sources identified?
  • Can the reviewer distinguish a source fact from an AI interpretation?
  • Does the system make missing information visible?

A confident conclusion with no traceable evidence can increase review time rather than reduce it.

8. Which parts are AI and which parts are deterministic?

Language models are useful for reading unstructured material. They are not the best tool for every calculation.

Ask the vendor to identify which parts of the workflow use:

  • language model interpretation
  • fixed business rules
  • arithmetic or deterministic calculations
  • external databases
  • human review

For exact reconciliations and defined thresholds, deterministic logic is often easier to test and reproduce.

A good vendor should be able to explain the architecture without hiding behind the word "AI".

9. What happens when the tool is unsure?

This is one of the most revealing questions in a vendor assessment.

Look for behaviour such as:

  • reporting that information was not found
  • identifying conflicting source documents
  • showing low-confidence results for review
  • refusing to invent a missing fact
  • distinguishing an exception from an error

A system that always produces an answer can be more dangerous than one that clearly says the file is incomplete.

10. How are outputs tested before release?

Ask how the vendor validates changes to:

  • models
  • prompts
  • tax rules
  • calculations
  • document extraction
  • screening logic

Questions worth asking include:

  • Is there a regression test set?
  • Are Australian tax scenarios included?
  • Who approves changes to tax logic?
  • Can a model update change results without notice?
  • Are material product changes communicated to customers?

For a tax product, "the model improved" is not a sufficient release control.

11. Can the firm apply proper human review?

The TPB expects practitioners to assess AI output and apply their own professional judgement.

The product should therefore make human review practical.

Check whether users can:

  • inspect source material
  • understand why an item was flagged
  • accept, reject or amend an output
  • record a review note
  • escalate a matter
  • export or retain evidence of the completed review

A workflow that encourages automatic acceptance is a poor fit for professional tax work.

12. What record can be retained on the client file?

Ask what the system produces at the end of the task.

A useful record might show:

  • documents reviewed
  • checks performed
  • findings raised
  • source references
  • practitioner responses
  • matters overridden
  • final status
  • reviewer identity and date

The firm should decide what it needs to retain under its own record-keeping and quality management procedures.

13. Does the vendor contract match the sales claims?

Key promises should appear in the contractual documents, not only on a website.

Check the terms, privacy material and data processing agreement for matters such as:

  • data ownership
  • permitted use of client data
  • confidentiality
  • subprocessors
  • overseas processing
  • retention and deletion
  • security obligations
  • incident notification
  • audit or assurance rights
  • termination

Where the product will receive sensitive client information, legal review of the agreement may be appropriate.

14. Who is accountable inside the accounting firm?

Vendor due diligence is only half the control.

The firm should also decide:

  • who approves AI products
  • which staff can use them
  • which use cases are approved
  • whether client permission is needed
  • how outputs are reviewed
  • what training users receive
  • how incidents are reported
  • how the product is reviewed over time

This should connect with the firm's quality management system and AI policy. See TPB quality management systems for tax agents.

A simple vendor scorecard

A firm can score each area as satisfactory, needs clarification or unacceptable.

AreaSatisfactoryNeeds clarificationUnacceptable
Data recipients understood
Processing locations understood
No unauthorised training use
Retention acceptable
Security controls acceptable
TFN and sensitive data handling acceptable
Source evidence visible
Human review supported
Testing and change control understood
Contract matches representations

Any item in the final column should be resolved before client information is uploaded.

How Taxpartna approaches these questions

Taxpartna is designed as a quality assurance assistance platform for Australian accounting firms.

Client information is processed using a self-hosted private model environment rather than being submitted to a public AI chatbot. Taxpartna's workflow is designed to show the practitioner the items identified for review and keep the final assessment and sign-off with the registered tax practitioner.

The same due diligence principles should still be applied to Taxpartna. Firms should assess the product against their own policies, professional obligations, privacy position and intended use. Learn more about AI tax software in Australia.

Authoritative sources

AI vendor assessment intersects with TPB and privacy obligations. The following primary sources should be checked when this page is technically reviewed or materially updated.

Frequently asked questions

The TPB's AI guidance expects practitioners to understand the capabilities and limitations of tools they use, protect client confidentiality, apply professional judgement and review AI output. Reviewing the vendor is a practical way to support those obligations. See TPB AI guidance for tax practitioners.

Usually not for a high-risk tax workflow. Firms should understand the contract, data flow, subprocessors, security, retention and actual product architecture.

That is a policy decision for the firm. A sensible policy usually distinguishes between low-risk use with no client information and higher-risk use involving confidential client data or professional tax conclusions.

Review should occur before approval and again when there is a material change to the product, contract, model provider, data location or intended use. A periodic review is also sensible.

Important information. This checklist is general information and is not legal, privacy or professional advice. Accounting firms should assess their own obligations and obtain specialist advice where appropriate. Taxpartna is a quality assurance assistance platform for registered tax practitioners.