Skip to main content
Skip to content

AI compliance for accounting and bookkeeping firms

AI compliance for accounting firms starts with tax file numbers and client financial records

The small business exemption is the first thing most practices reach for, and for an accounting firm it settles less than it appears to. Tax file number information is regulated separately, by a binding rule that applies to anyone holding a record containing it.

Which matters, because the AI use spreading fastest through accounting practices is document extraction, and the documents are full of exactly that.

General information about Australian obligations, not legal or tax advice.

What a practice actually holds
1
Tax file numbersRegulated by a binding rule under the Privacy Act, with offence provisions in tax law behind it.
2
Complete financial picturesIncome, debts, assets, relationships and business performance, for hundreds of clients at once.
3
Other people's employeesPayroll work means holding personal information about people who are not your clients.
4
Professional confidentialityObligations to clients that sit alongside privacy law and are not switched off by an exemption.
TFN Rule 2015
Privacy Act 1988
APP 11 reasonable steps
NDB scheme
Applicability

Does the small business exemption cover an accounting practice?

For the Australian Privacy Principles, possibly. For tax file number information, no. The Privacy (Tax File Number) Rule 2015, issued under section 17 of the Privacy Act, is binding on any TFN recipient, meaning anyone in possession or control of a record containing TFN information. It regulates the collection, storage, use, disclosure, security and disposal of that information.

It requires a TFN recipient to take reasonable steps to safeguard TFN information from loss, unauthorised access, use, modification, disclosure or other misuse, and to securely destroy or permanently de-identify it when it is no longer required by law. Sections 8WA and 8WB of the Taxation Administration Act 1953 create offences for unauthorised recording, use or disclosure of tax file numbers.

There are three further reasons a practice should not lean on the exemption. Turnover is measured once: a single financial year above $3 million removes the exemption permanently. Many practices are already above it. And clients, insurers and larger customers ask the same questions the Act does, so the exemption changes what binds you without changing what you get asked.

The practical conclusion is straightforward. Work to the standard, and settle where you sit as a recorded position rather than an assumption, because the answer decides which obligations you are actually managing.

Source: The Privacy (Tax File Number) Rule 2015 (OAIC).

The dominant use case

Document extraction is where the exposure concentrates

Most AI risk conversations focus on what people type. In an accounting practice the volume is in what people upload, and an uploaded document carries everything in it rather than only the part the question was about.

Volume

A statement is not a question

A year of bank statements uploaded for categorisation contains transaction-level detail about a client's life. A notice of assessment contains a TFN. Nobody re-reads what they attach.

Third parties

Payroll is other people's data

Processing a client's payroll means holding personal information about their employees, who have no relationship with your firm and no idea it happens.

Accuracy

A confident number is still a number

Extraction and categorisation errors propagate into returns and financial statements. The review that catches them is the control, and it needs to be a rule rather than a habit.

Where the AI usually already is

Practices frequently discover that AI arrived without a decision, through features switched on inside ledger, workpaper, document management and practice management software. That is a change to your data handling even though nothing was purchased, and it belongs on the register alongside the tools people chose deliberately.

Across the practice

Where AI turns up, and what each raises

Use What it raises
Source document extractionBulk upload of financial records. The highest-volume exposure in most practices, and often the least examined.
Transaction categorisationAccuracy feeding directly into a lodgement. Needs a review rule, not a spot check.
Payroll processing supportPersonal information about people who are not your clients, plus TFN information in most cases.
Client correspondence draftingClient financial context leaving the practice, in something going out under your name.
Meeting transcriptionA client's financial and personal circumstances captured and processed by a third party, usually adopted with no assessment.
Research on tax treatmentConfident answers that may be wrong, out of date, or drawn from another country's rules entirely.
Workpaper and file reviewWhole client files put through a tool. Volume again, and often the material with the widest scope.
AI features inside ledger or practice softwareA change to data handling with no procurement decision behind it. Check what a vendor update enabled.
Anything scoring or ranking clientsIf an output contributes to a decision that significantly affects a person, it belongs in the highest-attention band and engages the December 2026 privacy policy disclosure.
Example

How it actually arrives

Illustrative example, not a real customer

A bookkeeping practice with nine staff

Two bookkeepers start uploading client bank statements and supplier invoices to a general AI tool to speed up coding. It works, and by the end of the quarter most of the team is doing it. Nobody decided anything. The practice manager finds out when a client asks, during a tender, which third parties see their financial records.

What is true

  • Turnaround improved measurably
  • The staff were solving a real bottleneck
  • No client has been harmed
  • The work quality is fine

What the practice cannot answer

  • Which client records went into the tool, and when
  • Whether any contained a tax file number
  • Whether the provider retains uploads or uses them for training
  • Where the processing happened
  • What to write in the tender response

The tender is the visible problem and the smallest one. The real position is that the practice has no idea what has left it, which is also the answer it would need if something went wrong. Choosing one assessed tool, on a practice account, with a rule about TFNs and a review step, takes about a day and preserves every bit of the speed gain.

The record

What a practice should be able to produce

Client tenders, professional indemnity renewals and larger clients' supplier questionnaires all ask versions of the same thing. These are the records that answer them.

  • The approved AI services, with who approved them and on what basis.
  • Provider assessments covering retention, training use, processing location and subprocessors.
  • An explicit rule on TFN information, since that obligation applies whatever your turnover.
  • A rule about uploads, because that is where the volume of exposure is.
  • The review requirement, saying what a person checks before it reaches a lodgement or a client.
  • Staff acknowledgements, with dates, covering everyone including seasonal staff.
  • Training completions by name, covering the failure modes specific to this work.
  • Your Privacy Act position, recorded rather than assumed.
  • MFA and offboarding on every AI account.
  • Incident records, including breach assessments where client or employee information was exposed.
  • A review date and an owner for the policy and the approved list.
Where a platform fits

Practices keep meticulous records, rarely of their own governance

An accounting practice keeps meticulous records of its clients' affairs and frequently none of its own governance. Cleverer holds the second kind: what was decided, who owns it, who was told, and when it was last reviewed.

Providers on one register

Each AI service recorded with data types received, whether tax file numbers are involved, storage country, offshore disclosure, subprocessor visibility, contract status, an owner and a review date.

Your Privacy Act position, once

Whether the Act applies to the practice, and why, recorded at organisation level and carried into every policy that depends on it rather than re-guessed each time.

An exportable answer

A dated Evidence Pack covering control posture, policies, training by role, registers, open gaps and the chronology, for the tender or the indemnity renewal.

Cleverer does not connect to your ledger or practice software, review client files or give tax advice. It is the compliance record around the practice's own decisions, and it does not guarantee legal compliance.

The tender will ask. Better to find out first.

Client tenders and indemnity renewals cover this ground whether or not the practice has prepared for it. The Readiness Check asks the same questions with nothing riding on the answers.

FAQ

Questions from Australian accounting practices

Can client tax information be put into an AI tool?

Not as an informal habit. Tax file number information is regulated by the Privacy (Tax File Number) Rule 2015, which binds any TFN recipient and requires reasonable steps to safeguard that information from unauthorised access, use or disclosure. Where the practice is also an APP entity, entering client information into a service the provider can access is generally a disclosure under APP 6. A practice can use AI on client material, but it needs an assessed service, a decision that has been recorded, and rules people know.

Does the small business exemption apply to an accounting firm?

For the Australian Privacy Principles it may, if annual turnover has never exceeded $3 million and no exception applies. It does not affect the TFN Rule, which binds anyone holding a record containing tax file number information. Note that turnover is measured once: a single year above the threshold removes the exemption permanently.

Is uploading bank statements to an AI tool riskier than typing a question?

Considerably, and it is the difference most practices do not account for. People calibrate their caution to what they type. An upload carries everything in the document, including transaction detail, identifiers and sometimes a tax file number that nobody looked at before attaching it.

What about payroll data for our clients' employees?

Those employees are individuals whose personal information you hold, and they have no relationship with your practice. That information usually includes tax file numbers, so the TFN Rule applies to it directly. Treat payroll material as the most restricted category in any AI rule you set.

Do we need to tell clients we use AI?

Where the Privacy Act applies, the OAIC's guidance is that businesses should update their privacy policies and notifications with clear and transparent information about their use of AI. Beyond the legal position, clients increasingly ask directly in tenders and engagement discussions, and a practice that has decided and recorded its position answers that well.

What if staff have already been using AI on client files?

Establish what went where, when, into which service and on which account. Check what the provider does with uploads and whether they can be deleted. Assess whether client or employee information was disclosed without authorisation and whether that meets the notifiable data breach threshold. Record what you found. Then decide what is approved and tell everyone, because in most cases the staff were solving a real problem with no rule to follow.

© 2026 Cleverer. Human-layer cyber compliance for Australian businesses.