AI and your obligations as an accountant: APES 110, the TPB and client data.

Accountants sit under two codified confidentiality regimes at once, which makes the AI question sharper than for most professions: it is not one set of obligations you would need to satisfy, but two, with different regulators behind them.

General information only. This guide is not legal advice and is not a substitute for advice about your specific obligations. Verify positions against the primary sources linked throughout, and take professional advice where it matters.

APES 110: the confidentiality section

APES 110, the Code of Ethics for Professional Accountants issued by APESB, is mandatory for members of CPA Australia, CA ANZ and the IPA. Section 114 requires members to respect the confidentiality of information acquired through professional relationships, and not to disclose it outside the firm without proper authority or a legal duty (APESB, APES 110). Pasting client information into a cloud AI service is, on its face, providing it to a third party; the open question is whether the vendor's terms make that a defensible handling of confidential information. It is a question each firm must be able to answer, in writing, before the tool is in use rather than after.

The TPB Code of Professional Conduct

Registered tax agents and BAS agents carry parallel statutory obligations under the Tax Agent Services Act 2009. The TPB's Code of Professional Conduct includes an obligation not to disclose client information to a third party without the client's permission or a legal duty to do so (TPB, Code of Professional Conduct). The TPB has also published guidance on practice management and technology; the confidentiality item is the one an AI evaluation turns on, because "third party" is exactly what an offshore AI provider is.

What the ATO side adds

Firms handling tax file numbers and ATO-sourced data also operate inside the ATO's operational security expectations for digital service providers and practices. The theme is the same: know where client data flows, restrict it to systems you can account for, and be able to demonstrate both.

A practical evaluation checklist

Name the data

List what would actually enter the tool: TFNs, financials, identity documents, correspondence. If the answer in practice is "whatever staff paste", the policy is not real.

Trace the flow

Where is it processed, where is it stored, who can access it, under what law? Get vendor answers in writing and keep them with your engagement files.

Test against s.114 and the TPB code

Could you explain to a client, or the Board, why this handling respects confidentiality? If the explanation depends on trusting an offshore vendor's internal controls, decide whether that is a position you want to hold.

Prefer structure over policy

Rules staff must remember fail at deadline. Architectures where the compliant path is the productive one, such as processing that never leaves the practice, fail less.

The practical takeaway

Neither APES 110 nor the TPB code prohibits AI. Both make the firm accountable for where client information goes. On-premise AI answers the accountability question structurally, which is why Ermos builds on-premise AI for accounting practices; and if you are weighing Copilot because the firm already lives in Microsoft 365, our Copilot comparison works through both the arithmetic and the data-flow fine print.

Common questions

Can accountants use ChatGPT with client data?
Both APES 110 s.114 and the TPB code restrict disclosing client information to third parties without permission or legal duty. An offshore AI provider is a third party, so the defensibility of doing it rests entirely on the vendor terms and your documented analysis. Many practices conclude the cleaner answer is not to send client data out at all.
Do we need client consent to use AI tools?
If client information will be disclosed to a third-party service, authority to do so is the safest foundation, whether through engagement terms or specific consent. If processing stays inside the practice, there is no third-party disclosure to authorise.
What should we document?
The data types involved, the vendor's written answers on processing, storage, access and governing law, and your assessment against s.114 and the TPB code. If a tool cannot survive that one page of documentation, that is the answer.

See Dominion answering from your own documents.

A demonstration takes 30 minutes, uses no client data, and comes with no obligation.

Book a demo