Industry Solutions

AI in Australian Accounting Firms

AI in Australian Accounting Firms

AI governance and professional conduct for accounting firms

The professional conduct surface area of AI in an accounting firm

AI is already inside Australian accounting firms. It is extracting line items from supplier invoices, drafting tax notes, summarising audit working papers, classifying GL transactions, and generating client correspondence. Each of those touches a discrete obligation under APES 110, the TPB Code of Professional Conduct, ATO record-keeping rules, or the Privacy Act 1988. None of those obligations went away because the work was done by a model rather than a graduate.

For partners and practice managers at Australian accounting firms covering business services, tax, audit, and advisory, the regulatory exposure profile of AI is different from almost any other deployment we see in Australia. Healthcare practices and aged care providers face concentrated regulators. Financial services firms face APRA and ASIC. Accounting firms face all of the above plus a profession-specific code (APES 110), a profession-specific registration regime (TPB), and the standards of CA ANZ, CPA Australia, and the IPA. That stack does not have a single front door.

If you have read AI Agents for Australian Businesses: Why DIY Without Understanding Fails, Operating AI Agents: The Production Reality for Australian Business, and our parallel piece on Financial Services AI Compliance: APRA and ASIC, the framing here will feel familiar. Accounting firms carry one of the highest professional-conduct exposure profiles of any AI deployment in Australia, and the work to make AI safe in a practice is mostly governance, supervision, and disclosure, not model selection.

This article is the regulator map.


Part 1: The bodies looking at your AI

Five regulators and three professional bodies have a claim on what happens when AI touches client work in your firm. Treat them as a stack, not a list, because the same AI workflow can trigger multiple obligations simultaneously.

Regulators and professional bodies with a claim on AI in accounting practice

Metric
Body
What it covers for AI
TPB (Tax Practitioners Board)Tax Agent Services Act 2009, Code of Professional Conduct (s30 TASA), 2024 Code reformsCompetent provision of tax agent services, supervisory arrangements, disclosure, breach reporting
APESB / APES 110Code of Ethics for Professional Accountants (incl. Independence Standards)Confidentiality (s140), professional competence and due care (s130), integrity (s120), professional behaviour (s150)
ATORecord-keeping rules, lodgement integrity, FBT, GST, PAYG, STPSubstantiation of AI-assisted positions, retention of AI working papers, the lodger remains responsible
ASICCorporations Act, AFSL obligations, RG 271, RG 78Where the firm holds an AFSL or provides financial advice, AI in advice processes must meet licensee obligations
OAICPrivacy Act 1988, Australian Privacy Principles, Notifiable Data Breach schemeAPP 1 governance, APP 6 use/disclosure, APP 8 cross-border, APP 11 security, NDB notification
AUSTRACAML/CTF Act for designated services (incl. some tax/accounting services)AI-assisted KYC, suspicious matter reporting, sanctions screening must remain auditable
CA ANZ / CPA / IPAMember professional standards adopting APES 110 plus body-specific guidanceMember discipline channels, body-issued AI guidance, CPD obligations for AI competence

Two things stand out. First, the TPB Code was tightened in 2024 with new obligations relating to honest and ethical conduct, supervisory arrangements, and breach notification that apply directly to AI use. Second, OAIC reporting consistently places professional services in the top sectors for notifiable data breaches, which means the privacy layer is not theoretical for accounting firms.


Part 2: Six accounting AI use cases mapped to obligations

The mistake we see in firm-level AI deployments is treating "AI in the practice" as one thing. Each use case sits inside a different obligation envelope.

Common accounting AI use cases and the obligations they trigger

Metric
Use case
Primary obligations triggered + minimum control
Invoice and receipt data extractionSource documents to GL, often via Xero/MYOB or document AIAPES 110 s140 (confidentiality), APP 11 (security), APP 8 if vendor offshore. Control: vendor data residency clause, no training on client data, vendor DPIA on file
Bank reconciliation and categorisation AIML suggesting account codes, matching feeds to invoicesAPES 110 s130 (competence), TPB Code (competent provision). Control: documented review threshold, accuracy sampling, exception handling
Tax return draft generationAI drafting schedules, deductions, narrative for lodgementTPB Code s30, ATO record-keeping, APES 110 s130. Control: practitioner review of every position, retained working paper showing AI output and human override
Audit working paper summarisationLLM summarising controls testing, walkthroughs, evidenceASA 230 documentation, APES 110 s130. Control: source-linked summary, reviewer signs off original evidence, AI summary not the audit record
Client-facing communication (advice drafts, chatbots)Drafting emails, answering FAQs, generating advice templatesAPES 110 s120, TPB Code, ACL misleading conduct, agent-representation liability (Moffatt v Air Canada). Control: human approval before send, disclosed AI assistance where material, scope guardrails on chatbots
Practice management (workflow, time, billing)Workflow prediction, time capture, narrative generation, billingPrivacy Act (staff data), Fair Work where it touches performance, APES 320 and APES 325. Control: APES 320 quality system documents AI tools used, APES 325 risk register includes AI risks

Notice that the same vendor can sit in three of these rows at once. A general-purpose LLM with access to your document management system is simultaneously a confidentiality risk, a competence risk (because junior staff can produce work above their skill level without realising), and a record-keeping risk (because the prompt and output may not be preserved).

If you are at the model selection stage, our AI Model Selection Guide for Australian Business and AWS, Azure, GCP AI Services in Australia cover the residency and processing-location questions you need answered before any of the above use cases go live.


Part 3: APES 110 and the AI confidentiality and competence problem

APES 110 is the Code of Ethics issued by the Accounting Professional and Ethical Standards Board (APESB). The four sections that bite hardest on AI are:

s140 Confidentiality. A member shall not disclose, outside the firm, confidential information acquired as a result of professional and business relationships, without proper and specific authority. Sending client data to a third-party LLM that retains, logs, or trains on that data is a disclosure outside the firm. This is the single most common APES 110 issue we see. The mitigations are well known (enterprise tier with no-training contractual clauses, in-region processing, data minimisation in prompts) but they require a documented policy that staff actually follow.

s130 Professional Competence and Due Care. A member shall maintain professional knowledge and skill at the level required to ensure that a client receives competent professional services. The AI is a tool. The practitioner is responsible for the output. Two failure modes: a senior practitioner relies on AI output they cannot themselves verify (over-reliance), or a junior produces output that looks senior-level and gets signed off without proper review (false competence). Both are s130 breaches.

s120 Integrity. Be straightforward and honest in all professional and business relationships. The integrity question with AI is disclosure to clients. APES 110 does not yet contain a specific AI disclosure rule. The TPB's 2024 reforms and CA ANZ and CPA guidance push firms toward proactive disclosure where AI is materially involved in client work. The practical test: would the client be surprised, and would that surprise cause them to question the work?

s150 Professional Behaviour. Comply with relevant laws and regulations and avoid any conduct that may discredit the profession. AI failures that become public events (a leaked client file via an unauthorised LLM, a hallucinated tax position causing a penalty) are professional behaviour exposures, not just operational ones.

APES 320 (Quality Management for Firms) and APES 325 (Risk Management for Firms) sit alongside. Both require the firm-level system of quality and risk management to address how the firm controls its use of technology, including AI. If your APES 320 documentation does not mention AI tools, it is out of date.


Part 4: The TPB Code and AI

The Tax Practitioners Board is the registrant body for tax agents and BAS agents under the Tax Agent Services Act 2009. Section 30 sets the Code of Professional Conduct. In 2024 the Code was strengthened with new obligations covering honest and ethical conduct, undertaking only work the practitioner is competent to perform, supervisory arrangements, keeping clients informed of matters that could affect their decisions, and notifying the TPB of breaches.

The TPB has signalled in its guidance that AI does not change registrant obligations: a registered tax agent is responsible for the work, regardless of whether AI was used to produce it. In practice, this maps to the following exposure flow.

TPB Code exposure flow when AI sits in tax work

AI produces output
Draft return, schedule, classification, position narrative
Practitioner review
Registered agent must verify the work meets s30(1)(d) competent provision
Supervisory arrangement
Junior using AI must be supervised under the firm's documented supervisory model
Client disclosure
Material AI involvement disclosed in engagement letter or work papers
Working paper retained
AI prompt, output, and human override retained per ATO record-keeping rules
Breach notification
If AI error causes a Code breach, notify TPB under the post-2024 reform obligation

The supervisory arrangement step is where firms most commonly fall short. A graduate with access to a capable LLM can produce work that looks senior. Without a documented supervisory model that explicitly addresses AI-assisted work, the firm cannot demonstrate to the TPB that the work was performed under appropriate supervision.

The breach notification step is the new one. Firms should have a process for identifying when an AI-related error rises to a Code breach and ensure the responsible registrant knows their notification obligation.


Part 5: ATO record-keeping and AI-generated outputs

The ATO's position on AI in tax practice is consistent with its position on every other tool: the lodger is responsible for the lodgement. AI does not transfer responsibility. What changes with AI is the record-keeping question.

Three exposures are worth naming explicitly:

Missed exceptions in AI-drafted positions. AI systems trained on general tax content will return the typical answer. Australian tax law is full of exceptions, integrity measures, and timing rules where the typical answer is wrong (Division 7A, small business CGT concessions, FBT exemptions, GST going concerns, residency edge cases). The mitigation is a documented review checklist the practitioner runs against the AI output before lodgement. A better model does not remove the need for it.

Working paper retention. ATO general record-keeping rules require records to be retained for five years (longer in some scenarios). When AI sits between the source documents and the final return, the AI prompt, the AI output, and the human review and override are all part of the working paper trail. Practices that do not retain this trail cannot demonstrate substantiation if a position is queried.

Substantiation of AI-assisted positions. If the position taken on a return relies on AI-generated reasoning, and the client is later queried, the practice must be able to explain how the position was arrived at and on what basis. "The AI said so" is not a defensible answer. The defensible answer is "the AI produced a draft, the practitioner reviewed it against the following sources and reasoning, and the position was retained for these documented reasons".

For practices that have not yet documented how AI sits in their working paper trail, Operating AI Agents: The Production Reality and The AI Agent Staffing Gap cover the operational layer this requires.


Part 6: Privacy Act, NDB, and the AUSTRAC layer

The Privacy Act 1988 applies to APP entities, and accounting firms above the small business threshold are squarely in scope. Four APPs do most of the AI work:

APP 1 Open and transparent management. The firm's privacy policy must accurately describe how personal information is handled, including by AI systems. Generic policies that do not mention AI processing are out of date.

APP 6 Use and disclosure. Personal information collected for one purpose (e.g. tax preparation) cannot be used for a secondary purpose (e.g. training a vendor's model) without consent or another lawful basis.

APP 8 Cross-border disclosure. If AI processing happens outside Australia (most major LLM APIs), the firm must take reasonable steps to ensure the overseas recipient does not breach the APPs, or rely on a specific exception. Contractual data residency clauses and in-region processing are the most common path. Our piece on GDPR vs Privacy Act for Australian Business covers the practical mechanics.

APP 11 Security. Reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. Putting client tax data into a personal ChatGPT account does not meet APP 11. Putting it through a procured enterprise service with appropriate contractual and technical controls can.

The Notifiable Data Breach scheme is the consequence layer. If an AI exposure leaks personal information likely to result in serious harm, the firm must notify the OAIC and affected individuals. OAIC half-year reports consistently show professional services as a top reporting sector. Accounting firms hold TFNs, bank details, salary data, and dependant information. The harm threshold is low.

The AUSTRAC layer applies to designated services. Some tax agent services trigger AML/CTF obligations. AI-assisted KYC, sanctions screening, or suspicious matter reporting must remain auditable and explainable. The AUSTRAC position on AI is that the reporting entity remains accountable for compliance, including when AI produces the screening output.

For the broader security frame, our AI Security Checklist: 50 Points for Australian Businesses is the operational companion to this regulatory map.


Part 7: The control stack

Across all of the above, the controls an accounting firm actually needs cluster into a pre-deployment, live, and review cycle. The same cycle applies whether you are deploying a Xero AI feature, a document automation tool, an LLM for drafting, or a workflow agent.

The accounting firm AI control stack

1
Pre-deployment
Vendor and use case assessment
Document the use case against APES 110 sections, TPB Code, ATO record-keeping. Vendor data residency, training clauses, sub-processor list. APES 320 and APES 325 updates.
2
Pre-deployment
Privacy and security review
APP 1 policy update, APP 8 cross-border assessment, APP 11 security controls, DPIA where personal info is in scope. NDB response plan updated.
3
Pre-deployment
Supervisory and disclosure model
Documented supervisory model for AI-assisted work. Engagement letter and client disclosure language. Breach reporting flow to TPB.
4
Live
Practitioner review and working paper retention
Documented review threshold for AI output by use case. Retention of prompt, output, and override in the working paper trail. Sampling regime for quality.
5
Live
Exception handling and incident response
Defined exception categories, escalation paths, and incident triggers for NDB and TPB notification. Staff trained on what to escalate and when.
6
Review
Quarterly AI register review
APES 320 quality management review of AI tools in use. APES 325 risk register refresh. Vendor reassessment for material changes (model updates, sub-processor changes).
7
Review
Annual independent review
Independent review of the firm's AI governance against APES 110, TPB Code, and Privacy Act obligations. Outcomes feed the next year's quality plan.

This is the minimum that lets a firm demonstrate it has met its obligations across the stack. The work is mostly documentation and consistent practice, not technology spend. The Automation Business Case Template and AI Vendor Selection Questions are the supporting pieces for funding and procurement.


Part 8: Which obligation is the binding constraint for your AI deployment?

For most accounting firm AI deployments, more than one obligation applies, but one usually dominates as the binding constraint that determines whether the deployment can go live and on what terms.

Identifying the binding constraint for an accounting firm AI deployment

What does the AI actually do with client information?
Processes client confidential information offshore without contractual data residency control
→ BLOCKED. APP 8 + APES 110 s140. Fix residency or change vendor before proceeding.
Produces a tax position, advice, or audit conclusion
→ TPB Code s30 + APES 110 s130 are binding. Practitioner review and supervisory model are non-negotiable controls.
Sends output to a client without practitioner review
→ APES 110 s120 + ACL misleading conduct + agent-representation liability (Moffatt v Air Canada). Require human-in-loop before send.
Processes personal information of a kind that would trigger NDB if leaked (TFNs, banking, dependants)
→ APP 11 + NDB scheme are binding. Security controls and incident plan are non-negotiable.
Touches a designated service under AML/CTF
→ AUSTRAC is the binding regulator. AI output must remain explainable and auditable for SMR and KYC.
Only processes the firm's own internal data with no client PI
→ Privacy Act partially relevant; APES 320 quality management and APES 325 risk management still apply.

The agent-representation question in the client communication branch deserves a closer look. In Moffatt v Air Canada (2024 BCCRT 149), Air Canada was held liable for information provided by its chatbot to a customer. Australian Consumer Law has its own misleading conduct framework, and the principle reads across: a firm is responsible for representations its AI makes to clients, whether those go out by email, chatbot, or any other channel. Our ACCC Consumer Guarantees and AI Implementation covers the ACL angle.

For verticals with parallel regulatory exposure, the framing in Financial Services AI Compliance: APRA and ASIC, Healthcare Practice AI Patient Automation, and AI Government Contracts and Compliance shows how the same stack-thinking applies in each profession-specific regulatory environment. Aged Care AI and Compliance Care and Construction AI Automation and Project Documentation round out the regulated vertical set.


Part 9: 12-question partner and practice manager readiness checklist

If you are a partner, principal, or practice manager considering or already running AI in your firm, work these twelve questions in order. If you cannot answer any of them with documented evidence, that is your next piece of work.

  1. Which AI tools are in use across the firm today, including informal use by individual staff?
  2. For each tool, what client information passes through it, and where is that information processed?
  3. Does the vendor contractually commit to no training on your data and to specified data residency?
  4. Has the privacy policy been updated to reflect AI processing of personal information?
  5. Is there a documented supervisory model for AI-assisted work that satisfies the TPB Code?
  6. Is there a documented review threshold for AI output by use case (e.g. tax positions reviewed line by line, internal drafts sampled)?
  7. Are AI prompts, outputs, and human overrides retained in the working paper trail in line with ATO record-keeping?
  8. Has APES 320 quality management documentation been updated to include AI tools?
  9. Does the APES 325 risk register include AI-specific risks (hallucination, data leakage, vendor change, model drift)?
  10. Is there a documented disclosure approach for material AI involvement in client work, in engagement letters or work papers?
  11. Does the NDB response plan cover AI-related incidents, including who calls OAIC, the TPB, and affected clients?
  12. Is there a quarterly review process that revisits the AI register, vendor assessments, and incident log?

The firms that get this right are the ones with a documented system that can survive a TPB sanction review, an OAIC investigation, or a CA ANZ disciplinary referral. The number of tools has nothing to do with it.


Where to next

If you are at the point where the obligations are clear and the question is how to operationalise without absorbing the work into already-stretched partners, this is the conversation we have most often with accounting firms. Our AI Strategy and Managed AI Services practices, and our Professional Services solutions, are built around the control stack above rather than tool selection.

For grounded examples of how this works in practice, our Carbonly and RootCauseAI case studies show the same stack-first approach applied in carbon reporting and engineering investigation respectively. The disciplines transfer.

If you want a partner-level conversation about where your firm sits against the obligations in this article, book a 30-minute consultation. We will work through your current AI footprint against the TPB, APES 110, ATO, and Privacy Act obligations and identify what needs to be in place before any further expansion.


Related Reading:


Research synthesised from APESB APES 110 Code of Ethics, APES 320 Quality Management for Firms, APES 325 Risk Management for Firms, Tax Practitioners Board guidance and 2024 Code reforms, ATO record-keeping guidance, OAIC Notifiable Data Breach reports, AUSTRAC AML/CTF guidance, and the Moffatt v Air Canada 2024 BCCRT 149 decision.