# AI Policy for Australian Accounting Firms: 2026 Template

> An AI policy for an accounting firm, as a template: nine sections an Australian practice can adapt in an afternoon, grounded in TPB and Privacy Act rules.

**Source:** https://agentive.au/blog/ai-policy-template-for-australian-accounting-firms/ · **Published:** 2026-09-11 · **Author:** Dr. Ash Khalilian

---

Short Answer

**An AI policy for an Australian accounting firm needs nine sections: scope, approved tools, client data rules, client consent, human review checkpoints, verification, record keeping, incident response, and training.** Section 40 of the Code Determination requires you to document and enforce it. Below is the template, written so a principal can adapt it in an afternoon.

Last reviewed: September 2026

Key takeaways

-   No Australian law is titled "you must have an AI policy", but section 40 of the Code Determination requires you to document and enforce the policies of your quality management system, and TPB(GS) 55/2026 applies that section to AI.
-   The two sections most firm policies leave out are the approval route for a new tool and the incident response procedure, which are the only two anyone reaches for under pressure.
-   The Privacy Act small business threshold does not rescue a small practice: the TFN Rule applies regardless of turnover, and TPB obligations have no size threshold.
-   From 10 December 2026, new APP 1 obligations require an APP entity's privacy policy to describe automated decisions that could significantly affect a person's rights or interests.
-   Every policy section implies a vendor question. A policy you cannot get a supplier to answer in writing is a policy you cannot enforce.
-   Retain the AI audit trail for the same period as the file: TPB(GS) 52/2024 requires client records to be kept for at least 5 years after the service has been provided.

Australian bookkeepers and accountants keep asking the same forum question and keep getting a lecture back. The question is not whether a firm should have an AI policy. It is what one looks like. So this is the document, not the argument for it: nine sections of adaptable policy text, each with its regulatory hook and the vendor question it forces you to ask. If you run a [dedicated AI](/ai-employee/) in the practice, that last part decides whether the policy is real or decorative.

## Does an Australian accounting firm actually need a written AI policy?

Yes, if AI touches your tax agent services, and the hook is more specific than most commentary suggests. [TPB(GS) 55/2026](https://www.tpb.gov.au/tpbgs-552026-use-artificial-intelligence-and-code-professional-conduct), issued by the Tax Practitioners Board on 22 July 2026, applies the Code of Professional Conduct to AI. Its competency table points at section 40 of the Tax Agent Services (Code of Professional Conduct) Determination 2024, which requires a practitioner to maintain a system of quality management and to document and enforce its policies and procedures. The guidance adds that practitioners should verify AI generated content for accuracy at each step of the workflow, establish processes to contest AI outputs, and document each of those steps.

Professional bodies land in the same place. The Accounting Professional and Ethical Standards Board's Technical Alert of [31 October 2025 on the ethical use of AI](https://apesb.org.au/wp-content/uploads/2025/10/TA_Use_of_AI_Oct_31_Oct_25.pdf) notes that new technology provisions in APES 110 took effect on 1 January 2025, and says members "must have an inquiring mind to critically assess and verify any information used or produced for a professional activity, which includes AI-generated information". The National AI Centre's [Guidance for AI Adoption](https://www.industry.gov.au/publications/guidance-for-ai-adoption/guidance-ai-adoption-foundations), published 21 October 2025, makes creating an AI policy a getting-started action. Three sources, one instruction.

## What should be in an AI policy for an accounting firm?

Nine sections. Print this as page one and the rest of the document becomes a reference rather than a read.

| Section | What it settles | Source it answers to |
| --- | --- | --- |
| 1\. Scope and definitions | What counts as AI here, including embedded features and staff personal accounts | TPB(GS) 55/2026, para on embedded AI |
| 2\. Approved and prohibited tools | The register, and how a new tool gets on it | Section 40 of the Determination; NAIC AI register |
| 3\. Client data rules | What may be entered, what never, residency, training opt-out | Code item 6; Privacy Act and the APPs |
| 4\. Consent and disclosure | What the engagement letter says and when you tell the client | Code item 6; APP 1 from 10 Dec 2026 |
| 5\. Human review checkpoints | Who signs off on which output type, before it moves | Code items 7 and 9; section 35 supervision |
| 6\. Accuracy and verification | Every figure traced to a source record before it is relied on | Code item 10; APES 110 inquiring mind |
| 7\. Records and audit trail | What you must be able to reproduce, and for how long | Section 30 of the Determination; TPB(GS) 52/2024 |
| 8\. Incident response | What happens when a wrong output has already reached a client | Notifiable Data Breaches scheme; Code item 7 |
| 9\. Training and sign-off | Who has read it, who owns it, when it is next reviewed | Code item 8; section 40 enforcement limb |

## Section 1: What does the policy cover?

Scope fails when it only lists the tools the firm bought. TPB(GS) 55/2026 expressly includes AI features embedded within software or third-party platforms, and functionality that operates autonomously without continuous human intervention. Your ledger's coding suggestions are in scope whether or not anyone adopted them deliberately.

Policy text

This policy applies to any system that generates, summarises, classifies, drafts or recommends using machine learning, including generative assistants, AI features embedded in practice software or ledgers, and any tool that acts without a person reviewing each step. It covers firm-provided tools and personal accounts used on firm work, on any device, whether or not the firm pays for them, and applies to partners, employees, contractors and offshore staff.

Keep the personal-account clause, however much it gets argued about. A staff member pasting a client's trial balance into a consumer chatbot on their own phone has disclosed to a third party under Code item 6, whoever paid for the subscription.

## Section 2: Which tools are approved, and how does a new one get approved?

Keep a register, not a prohibition list. The National AI Centre's guidance recommends maintaining an AI register documenting all your AI systems and how you use them, including AI embedded in other systems. A list of banned tools ages badly; a register of approved ones does not.

Policy text

The firm maintains an AI register listing every approved tool, its purpose, the data classes it may receive, its named owner and its last review date. Only registered tools may be used on client work; anything else is prohibited, including free tiers and trials. To add a tool, submit the vendor due diligence checklist at Appendix A to the AI governance owner. Approval requires a written answer to all seven questions, a recorded data classification and sign-off by a principal, and is provisional for 90 days.

Do not skip the 90-day provisional period. It turns "we tried it and never revisited it" into a diary date, and gives the firm a clean exit from a poor-fit tool without anyone losing an argument.

## Section 3: What client data may be entered into an AI tool?

Classify the data, then bind each class to a tool tier. The [OAIC's guidance on commercially available AI products](https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-the-use-of-commercially-available-ai-products), published 21 October 2024 and updated 17 January 2025, recommends as best practice that organisations do not enter personal information, particularly sensitive information, into publicly available generative AI tools, and warns that some products include terms allowing the owner to collect input data for further training. CPA Australia put it more bluntly in an [InPractice article of 25 August 2025](https://www.cpaaustralia.com.au/public-practice/inpractice/digital-technology/how-far-can-you-go-ai-before-hit-ethical-dilemma): "Uploading client data into public AI tools such as ChatGPT is not OK, as confidentiality is not guaranteed."

Policy text

Class A (prohibited in all tools not on the register, and never in a consumer chatbot): tax file numbers, bank account and credit card numbers, identity documents, health information, and anything identifying an individual's financial position. Class B (approved tools only): client name, entity details, ledger data, correspondence. Class C (any approved tool): de-identified extracts, public information, internal drafts containing no client data. Approved tools must host and process data in Australia, must not use firm or client inputs to train or improve models, and must be single-tenant or provide equivalent logical separation evidenced in writing.

One Privacy Act point small practices routinely get wrong. The [OAIC's small business page](https://www.oaic.gov.au/privacy/privacy-for-organisations/small-business) confirms a small business is one with annual turnover of $3 million or less and that most are not covered by the Privacy Act, so a two-partner firm may sit outside the Australian Privacy Principles. That is less relief than it sounds: the [Privacy (Tax File Number) Rule 2015](https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/handling-personal-information/the-privacy-tax-file-number-rule-2015-and-the-protection-of-tax-file-number-information) applies to TFN recipients regardless of turnover, and TPB obligations have no turnover threshold at all. What belongs in a prompt at all is covered in [putting client data into an AI tool](/blog/is-it-safe-to-put-client-data-into-ai/).

## Section 4: What do you have to tell clients, and when?

Permission comes before the first run, not before the first client-facing output. TPB(GS) 55/2026 states that practitioners must obtain permission from each client prior to divulging client information to a third party, which can include entering client information into AI models and tools depending on how they are configured. It recommends telling the client to whom and where the disclosure is made, where data will be stored and whether AI tools may be used, and notes permission may come by way of a signed letter of engagement.

Policy text

The firm's letter of engagement discloses that AI tools may be used in providing services, names the categories of tool, states where data is stored and processed, and confirms that inputs are not used to train third-party models. No client work may be processed through an approved tool until that consent is on file. Where a client declines, the engagement is flagged as manual-only in practice management. Where AI materially shapes advice or a figure presented to the client, the working paper records that fact.

One dated obligation belongs in your diary rather than your policy debate. Per the [OAIC's APP 1 guidelines](https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-1-app-1-open-and-transparent-management-of-personal-information), from 10 December 2026 new obligations introduced by the Privacy and Other Legislation Amendment Act 2024 require an APP entity's privacy policy to describe arrangements where a computer program uses personal information to make a decision that could reasonably be expected to significantly affect an individual's rights or interests. If the Privacy Act covers your firm, that amendment is due in under three months. The rest of the disclosure picture sits in [what tax and BAS agents must disclose about AI](/blog/tpb-ai-guidance-what-tax-and-bas-agents-must-disclose/).

## Section 5: Where are the human review checkpoints?

Set review by output type, not by tool. "Always review AI output" is unenforceable, because it never says what review means for a bank coding suggestion versus a letter of advice. Section 35 of the Determination requires each entity providing tax agent services on your behalf to be appropriately supervised, having regard to the services provided and your system of quality management.

| Output type | Review required | Who |
| --- | --- | --- |
| Transaction coding, bank reconciliation | Sample plus every exception and every new payee | Bookkeeper |
| Internal summary, meeting note, draft email | Read before it leaves the firm | Author |
| BAS, IAS, working papers | Line-by-line, every figure traced to source | Registered BAS or tax agent |
| Tax position, technical research, citations | Independent verification against the primary source | Principal |
| Anything sent to the ATO or signed | Full review, recorded, before lodgement | Principal |

## Section 6: How does the firm verify accuracy?

One rule does most of the work: a figure that cannot be traced to a source record does not go in the file. TPB(GS) 55/2026 warns that AI models may hallucinate or provide inaccurate information and cannot replace tax knowledge, experience or expertise. The failure mode is not a number that looks wrong; it is one that looks exactly right with no document behind it. That is why the control must be structural rather than attentional.

Policy text

Every figure produced or amended by an AI tool must be traceable to a source record: an invoice, a bank line, a ledger account, a statutory rate or a client instruction. Where the tool cannot show the source, the figure is unverified and is not used. Legislative references, rates, thresholds and citations must be checked against the ATO, TPB or legislative source before use. Reviewers record what they verified, not that they reviewed.

Insist reviewers record what they checked rather than tick a box: that is the difference between a review that catches a fabricated figure and one that reads as plausible and moves on. See also [why AI invents figures in financial reports](/blog/ai-hallucinations-in-financial-reports/).

## Section 7: What must the firm be able to reproduce, and for how long?

Retain the AI audit trail on the same clock as the file it belongs to. Section 30 of the Determination requires records that correctly record the tax agent services provided, and [TPB(GS) 52/2024](https://www.tpb.gov.au/tpbgs-522024-obligation-keep-proper-client-records-tax-agent-services-provided), issued 23 December 2024 and updated 30 April 2026, states those records must be retained for at least 5 years after the service has been provided. It also lists client permissions, including consent to disclose client information, among the records practitioners must keep. That is where your AI consent evidence lives.

Policy text

For any AI-assisted step that affects a client deliverable, the firm must be able to reproduce: which tool was used, on what date, by which user, what data it received, what it returned, who reviewed the output and what they changed. These records are retained for at least 5 years after the relevant service is complete, alongside the client file. AI consent evidence is filed with the letter of engagement. Where an approved tool's own logging cannot supply this, the reviewing staff member records it in the working paper instead.

## Section 8: What happens when a wrong AI output reaches a client?

Assume it will, and write the procedure while nobody is panicking. This is the most commonly missing section and the only one anyone ever reads at speed. Two pathways matter: accuracy failure, and confidentiality failure.

1.  **Contain it the same day.** Correct the client in writing, in plain terms, stating what was wrong and what the right position is. Do not wait for the internal investigation to finish.
2.  **Reconstruct the step from the audit trail.** Identify the tool, the input, the output and the review that let it through. If you cannot reconstruct it, that is a finding about the tool, and it goes in the register review.
3.  **Check the blast radius.** The same prompt, template or workflow has almost certainly touched other files. Find them before you close the incident. A single-file fix on a systemic cause is how the error returns next quarter.
4.  **Run the privacy test separately.** If personal information was exposed rather than merely wrong, the [Notifiable Data Breaches scheme](https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/preventing-preparing-for-and-responding-to-data-breaches/data-breach-preparation-and-response/part-4-notifiable-data-breach-ndb-scheme) may apply. The OAIC states an entity must take all reasonable steps to complete its assessment of a suspected eligible breach within 30 calendar days of becoming aware of the grounds for suspicion, and expects 30 days to be treated as a maximum rather than a target.
5.  **Record the finding and change something.** Tighten the review checkpoint, restrict the data class, or remove the tool. An incident that changes no control is an incident you have agreed to repeat.

Worked example (illustrative, not a client matter)

An assistant drafts a quarterly client summary and includes a superannuation guarantee rate it generated rather than retrieved. The reviewer reads for tone and sends it. The client queries the figure a fortnight later. Under this policy: written correction that day; the audit log shows the rate had no source record, so it should have failed the section 6 trace rule; the same template produced summaries for eleven other clients that quarter, two of which carry the rate and are corrected; the control change is that statutory rates come from a maintained internal table rather than being generated at all. No privacy pathway, because nothing was disclosed.

## Section 9: Training, sign-off and annual review

Section 40 of the Determination has two limbs, and the second is enforcement. A policy nobody has read is not enforced, and an unenforced policy is worse evidence than no policy, because it establishes the standard you then failed to meet.

Policy text

A named principal is the AI governance owner and is accountable for this policy. All partners, employees and contractors complete AI policy training at induction and annually, and sign an acknowledgement that is retained. Breaches are handled under the firm's disciplinary procedure. This policy, the AI register and the vendor checklist responses are reviewed at least annually, and immediately after any incident, tool change, or relevant change in TPB, OAIC or professional body guidance.

## Appendix A: How do you vet an AI vendor?

Every section above implies a question a supplier must answer in writing. TPB(GS) 55/2026 is direct: tax practitioners are ultimately responsible for exercising due diligence when using AI tools, including appropriate review of commercial and internally developed tools to ensure information will be kept secure and that the Privacy Act 1988 requirements are met. Agentive's answers sit in the last column as a benchmark to hold other vendors against.

| Question | Why the policy needs it | Agentive's answer |
| --- | --- | --- |
| Where is data hosted and processed? | Section 3 residency rule; APP 8 if the Act applies to you | AWS Sydney, with all inference performed inside Australia |
| Is the tenancy shared or single? | Separation of one firm's client data from another's | Single-tenant per customer |
| Are our inputs used to train models? | Code item 6; the OAIC's warning about training terms | No. Client data is never used to train a model |
| What does the audit log capture, and for how long? | Section 7 reproducibility; section 30 of the Determination | A per-action log of every action taken, readable and exportable by the firm |
| How is access controlled and separated by role? | Section 5 checkpoints; TFN Rule access restrictions | Per-user access, with the firm controlling which data and actions each role reaches |
| What is the breach notification commitment, in writing? | Section 8; the 30-day NDB assessment clock | Agreed in writing at contracting, so the firm's own assessment clock can start |
| Which sub-processors touch the data? | Code item 6 disclosure chain; supply chain transparency | Disclosed on request; the Australian hosting and no-training position applies end to end |

Treat the last column as a benchmark, not a substitute for diligence: get every vendor's answers, Agentive's included, written into the agreement rather than left in a sales email.

A position worth stating plainly, from building this for Australian finance teams: the question that separates vendors is not residency, it is the audit log. Hosting is a data centre region on a slide, so almost everyone answers it straight. Far fewer will show you a log that reconstructs a single action months later, which is the artefact section 30 of the Determination actually needs. If a demo cannot produce that, the residency answer does not save the policy. The architecture behind those answers is set out in [AI security and data governance in Australia](/blog/ai-employee-security-data-governance-australia/), and its effect on lodgement work on the [tax compliance page](/ai-employee/tax-compliance/).

## How should a practice adapt this in an afternoon?

1.  **Name the owner first.** One principal, by name, on the cover page. Everything else is unallocated until that is done.
2.  **Build the register from reality, not intention.** Ask every staff member what they actually used on client work last month, with no consequences attached. That list is your real starting scope, and it will be longer than the licence list.
3.  **Fill in sections 3 and 5 in your own words.** Data classes and review checkpoints must match how your firm really works. Copying someone else's here produces a policy staff route around.
4.  **Send Appendix A to every vendor on the register.** Give them a fortnight. The responses, and the silences, will tell you more about your risk than the policy does.
5.  **Update the engagement letter and diarise 10 December 2026.** Consent belongs in the letter now, and the APP 1 automated decision obligations commence that day if the Privacy Act covers your firm.
6.  **Get signatures, then set the annual review date.** An unsigned policy fails the enforcement limb of section 40 however well it is drafted.

This post is general information for Australian practices and is not legal advice. Obligations depend on your registration, entity and client base. Confirm your firm's position with the TPB, your professional body or your own adviser.

## The document is the easy part

Writing the nine sections takes an afternoon. Finding out that your current tools cannot satisfy sections 3 and 7 takes longer, and that is the point of the exercise rather than a failure of it. For Australian bookkeepers, BAS agents and tax agents, a policy's real function is to convert a vague unease about AI into seven questions a supplier either answers in writing or does not.

Agentive was built around those answers rather than retrofitted to them, which is why the [AI Operation Engine](/ai-employee/) is single-tenant on AWS Sydney with all inference in Australia, never trains on client data, and logs every action at a level a reviewer can reconstruct. The same posture carries into daily work for [bookkeeping practices](/ai-employee/use-cases/bookkeepers/). Write the policy before you buy the next tool: it is far cheaper to learn that a vendor cannot meet section 7 during due diligence than during a TPB review.
