AI in Australian Accounting Firms

The professional conduct surface area of AI in an accounting firm
AI is already inside Australian accounting firms. It is extracting line items from supplier invoices, drafting tax notes, summarising audit working papers, classifying GL transactions, and generating client correspondence. Each of those touches a discrete obligation under APES 110, the TPB Code of Professional Conduct, ATO record-keeping rules, or the Privacy Act 1988. None of those obligations went away because the work was done by a model rather than a graduate.
For partners and practice managers at Australian accounting firms covering business services, tax, audit, and advisory, the regulatory exposure profile of AI is different from almost any other deployment we see in Australia. Healthcare practices and aged care providers face concentrated regulators. Financial services firms face APRA and ASIC. Accounting firms face all of the above plus a profession-specific code (APES 110), a profession-specific registration regime (TPB), and the standards of CA ANZ, CPA Australia, and the IPA. That stack does not have a single front door.
If you have read AI Agents for Australian Businesses: Why DIY Without Understanding Fails, Operating AI Agents: The Production Reality for Australian Business, and our parallel piece on Financial Services AI Compliance: APRA and ASIC, the framing here will feel familiar. Accounting firms carry one of the highest professional-conduct exposure profiles of any AI deployment in Australia, and the work to make AI safe in a practice is mostly governance, supervision, and disclosure, not model selection.
This article is the regulator map.
Part 1: The bodies looking at your AI
Five regulators and three professional bodies have a claim on what happens when AI touches client work in your firm. Treat them as a stack, not a list, because the same AI workflow can trigger multiple obligations simultaneously.
Regulators and professional bodies with a claim on AI in accounting practice
| Metric | Body | What it covers for AI |
|---|---|---|
| TPB (Tax Practitioners Board) | Tax Agent Services Act 2009, Code of Professional Conduct (s30 TASA), 2024 Code reforms | Competent provision of tax agent services, supervisory arrangements, disclosure, breach reporting |
| APESB / APES 110 | Code of Ethics for Professional Accountants (incl. Independence Standards) | Confidentiality (s140), professional competence and due care (s130), integrity (s120), professional behaviour (s150) |
| ATO | Record-keeping rules, lodgement integrity, FBT, GST, PAYG, STP | Substantiation of AI-assisted positions, retention of AI working papers, the lodger remains responsible |
| ASIC | Corporations Act, AFSL obligations, RG 271, RG 78 | Where the firm holds an AFSL or provides financial advice, AI in advice processes must meet licensee obligations |
| OAIC | Privacy Act 1988, Australian Privacy Principles, Notifiable Data Breach scheme | APP 1 governance, APP 6 use/disclosure, APP 8 cross-border, APP 11 security, NDB notification |
| AUSTRAC | AML/CTF Act for designated services (incl. some tax/accounting services) | AI-assisted KYC, suspicious matter reporting, sanctions screening must remain auditable |
| CA ANZ / CPA / IPA | Member professional standards adopting APES 110 plus body-specific guidance | Member discipline channels, body-issued AI guidance, CPD obligations for AI competence |
Two things stand out. First, the TPB Code was tightened in 2024 with new obligations relating to honest and ethical conduct, supervisory arrangements, and breach notification that apply directly to AI use. Second, OAIC reporting consistently places professional services in the top sectors for notifiable data breaches, which means the privacy layer is not theoretical for accounting firms.
Part 2: Six accounting AI use cases mapped to obligations
The mistake we see in firm-level AI deployments is treating "AI in the practice" as one thing. Each use case sits inside a different obligation envelope.
Common accounting AI use cases and the obligations they trigger
| Metric | Use case | Primary obligations triggered + minimum control |
|---|---|---|
| Invoice and receipt data extraction | Source documents to GL, often via Xero/MYOB or document AI | APES 110 s140 (confidentiality), APP 11 (security), APP 8 if vendor offshore. Control: vendor data residency clause, no training on client data, vendor DPIA on file |
| Bank reconciliation and categorisation AI | ML suggesting account codes, matching feeds to invoices | APES 110 s130 (competence), TPB Code (competent provision). Control: documented review threshold, accuracy sampling, exception handling |
| Tax return draft generation | AI drafting schedules, deductions, narrative for lodgement | TPB Code s30, ATO record-keeping, APES 110 s130. Control: practitioner review of every position, retained working paper showing AI output and human override |
| Audit working paper summarisation | LLM summarising controls testing, walkthroughs, evidence | ASA 230 documentation, APES 110 s130. Control: source-linked summary, reviewer signs off original evidence, AI summary not the audit record |
| Client-facing communication (advice drafts, chatbots) | Drafting emails, answering FAQs, generating advice templates | APES 110 s120, TPB Code, ACL misleading conduct, agent-representation liability (Moffatt v Air Canada). Control: human approval before send, disclosed AI assistance where material, scope guardrails on chatbots |
| Practice management (workflow, time, billing) | Workflow prediction, time capture, narrative generation, billing | Privacy Act (staff data), Fair Work where it touches performance, APES 320 and APES 325. Control: APES 320 quality system documents AI tools used, APES 325 risk register includes AI risks |
Notice that the same vendor can sit in three of these rows at once. A general-purpose LLM with access to your document management system is simultaneously a confidentiality risk, a competence risk (because junior staff can produce work above their skill level without realising), and a record-keeping risk (because the prompt and output may not be preserved).
If you are at the model selection stage, our AI Model Selection Guide for Australian Business and AWS, Azure, GCP AI Services in Australia cover the residency and processing-location questions you need answered before any of the above use cases go live.
Part 3: APES 110 and the AI confidentiality and competence problem
APES 110 is the Code of Ethics issued by the Accounting Professional and Ethical Standards Board (APESB). The four sections that bite hardest on AI are:
s140 Confidentiality. A member shall not disclose, outside the firm, confidential information acquired as a result of professional and business relationships, without proper and specific authority. Sending client data to a third-party LLM that retains, logs, or trains on that data is a disclosure outside the firm. This is the single most common APES 110 issue we see. The mitigations are well known (enterprise tier with no-training contractual clauses, in-region processing, data minimisation in prompts) but they require a documented policy that staff actually follow.
s130 Professional Competence and Due Care. A member shall maintain professional knowledge and skill at the level required to ensure that a client receives competent professional services. The AI is a tool. The practitioner is responsible for the output. Two failure modes: a senior practitioner relies on AI output they cannot themselves verify (over-reliance), or a junior produces output that looks senior-level and gets signed off without proper review (false competence). Both are s130 breaches.
s120 Integrity. Be straightforward and honest in all professional and business relationships. The integrity question with AI is disclosure to clients. APES 110 does not yet contain a specific AI disclosure rule. The TPB's 2024 reforms and CA ANZ and CPA guidance push firms toward proactive disclosure where AI is materially involved in client work. The practical test: would the client be surprised, and would that surprise cause them to question the work?
s150 Professional Behaviour. Comply with relevant laws and regulations and avoid any conduct that may discredit the profession. AI failures that become public events (a leaked client file via an unauthorised LLM, a hallucinated tax position causing a penalty) are professional behaviour exposures, not just operational ones.
APES 320 (Quality Management for Firms) and APES 325 (Risk Management for Firms) sit alongside. Both require the firm-level system of quality and risk management to address how the firm controls its use of technology, including AI. If your APES 320 documentation does not mention AI tools, it is out of date.
Part 4: The TPB Code and AI
The Tax Practitioners Board is the registrant body for tax agents and BAS agents under the Tax Agent Services Act 2009. Section 30 sets the Code of Professional Conduct. In 2024 the Code was strengthened with new obligations covering honest and ethical conduct, undertaking only work the practitioner is competent to perform, supervisory arrangements, keeping clients informed of matters that could affect their decisions, and notifying the TPB of breaches.
The TPB has signalled in its guidance that AI does not change registrant obligations: a registered tax agent is responsible for the work, regardless of whether AI was used to produce it. In practice, this maps to the following exposure flow.
TPB Code exposure flow when AI sits in tax work
The supervisory arrangement step is where firms most commonly fall short. A graduate with access to a capable LLM can produce work that looks senior. Without a documented supervisory model that explicitly addresses AI-assisted work, the firm cannot demonstrate to the TPB that the work was performed under appropriate supervision.
The breach notification step is the new one. Firms should have a process for identifying when an AI-related error rises to a Code breach and ensure the responsible registrant knows their notification obligation.
Part 5: ATO record-keeping and AI-generated outputs
The ATO's position on AI in tax practice is consistent with its position on every other tool: the lodger is responsible for the lodgement. AI does not transfer responsibility. What changes with AI is the record-keeping question.
Three exposures are worth naming explicitly:
Missed exceptions in AI-drafted positions. AI systems trained on general tax content will return the typical answer. Australian tax law is full of exceptions, integrity measures, and timing rules where the typical answer is wrong (Division 7A, small business CGT concessions, FBT exemptions, GST going concerns, residency edge cases). The mitigation is a documented review checklist the practitioner runs against the AI output before lodgement. A better model does not remove the need for it.
Working paper retention. ATO general record-keeping rules require records to be retained for five years (longer in some scenarios). When AI sits between the source documents and the final return, the AI prompt, the AI output, and the human review and override are all part of the working paper trail. Practices that do not retain this trail cannot demonstrate substantiation if a position is queried.
Substantiation of AI-assisted positions. If the position taken on a return relies on AI-generated reasoning, and the client is later queried, the practice must be able to explain how the position was arrived at and on what basis. "The AI said so" is not a defensible answer. The defensible answer is "the AI produced a draft, the practitioner reviewed it against the following sources and reasoning, and the position was retained for these documented reasons".
For practices that have not yet documented how AI sits in their working paper trail, Operating AI Agents: The Production Reality and The AI Agent Staffing Gap cover the operational layer this requires.
Part 6: Privacy Act, NDB, and the AUSTRAC layer
The Privacy Act 1988 applies to APP entities, and accounting firms above the small business threshold are squarely in scope. Four APPs do most of the AI work:
APP 1 Open and transparent management. The firm's privacy policy must accurately describe how personal information is handled, including by AI systems. Generic policies that do not mention AI processing are out of date.
APP 6 Use and disclosure. Personal information collected for one purpose (e.g. tax preparation) cannot be used for a secondary purpose (e.g. training a vendor's model) without consent or another lawful basis.
APP 8 Cross-border disclosure. If AI processing happens outside Australia (most major LLM APIs), the firm must take reasonable steps to ensure the overseas recipient does not breach the APPs, or rely on a specific exception. Contractual data residency clauses and in-region processing are the most common path. Our piece on GDPR vs Privacy Act for Australian Business covers the practical mechanics.
APP 11 Security. Reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. Putting client tax data into a personal ChatGPT account does not meet APP 11. Putting it through a procured enterprise service with appropriate contractual and technical controls can.
The Notifiable Data Breach scheme is the consequence layer. If an AI exposure leaks personal information likely to result in serious harm, the firm must notify the OAIC and affected individuals. OAIC half-year reports consistently show professional services as a top reporting sector. Accounting firms hold TFNs, bank details, salary data, and dependant information. The harm threshold is low.
The AUSTRAC layer applies to designated services. Some tax agent services trigger AML/CTF obligations. AI-assisted KYC, sanctions screening, or suspicious matter reporting must remain auditable and explainable. The AUSTRAC position on AI is that the reporting entity remains accountable for compliance, including when AI produces the screening output.
For the broader security frame, our AI Security Checklist: 50 Points for Australian Businesses is the operational companion to this regulatory map.
Part 7: The control stack
Across all of the above, the controls an accounting firm actually needs cluster into a pre-deployment, live, and review cycle. The same cycle applies whether you are deploying a Xero AI feature, a document automation tool, an LLM for drafting, or a workflow agent.
The accounting firm AI control stack
This is the minimum that lets a firm demonstrate it has met its obligations across the stack. The work is mostly documentation and consistent practice, not technology spend. The Automation Business Case Template and AI Vendor Selection Questions are the supporting pieces for funding and procurement.
Part 8: Which obligation is the binding constraint for your AI deployment?
For most accounting firm AI deployments, more than one obligation applies, but one usually dominates as the binding constraint that determines whether the deployment can go live and on what terms.
Identifying the binding constraint for an accounting firm AI deployment
The agent-representation question in the client communication branch deserves a closer look. In Moffatt v Air Canada (2024 BCCRT 149), Air Canada was held liable for information provided by its chatbot to a customer. Australian Consumer Law has its own misleading conduct framework, and the principle reads across: a firm is responsible for representations its AI makes to clients, whether those go out by email, chatbot, or any other channel. Our ACCC Consumer Guarantees and AI Implementation covers the ACL angle.
For verticals with parallel regulatory exposure, the framing in Financial Services AI Compliance: APRA and ASIC, Healthcare Practice AI Patient Automation, and AI Government Contracts and Compliance shows how the same stack-thinking applies in each profession-specific regulatory environment. Aged Care AI and Compliance Care and Construction AI Automation and Project Documentation round out the regulated vertical set.
Part 9: 12-question partner and practice manager readiness checklist
If you are a partner, principal, or practice manager considering or already running AI in your firm, work these twelve questions in order. If you cannot answer any of them with documented evidence, that is your next piece of work.
- Which AI tools are in use across the firm today, including informal use by individual staff?
- For each tool, what client information passes through it, and where is that information processed?
- Does the vendor contractually commit to no training on your data and to specified data residency?
- Has the privacy policy been updated to reflect AI processing of personal information?
- Is there a documented supervisory model for AI-assisted work that satisfies the TPB Code?
- Is there a documented review threshold for AI output by use case (e.g. tax positions reviewed line by line, internal drafts sampled)?
- Are AI prompts, outputs, and human overrides retained in the working paper trail in line with ATO record-keeping?
- Has APES 320 quality management documentation been updated to include AI tools?
- Does the APES 325 risk register include AI-specific risks (hallucination, data leakage, vendor change, model drift)?
- Is there a documented disclosure approach for material AI involvement in client work, in engagement letters or work papers?
- Does the NDB response plan cover AI-related incidents, including who calls OAIC, the TPB, and affected clients?
- Is there a quarterly review process that revisits the AI register, vendor assessments, and incident log?
The firms that get this right are the ones with a documented system that can survive a TPB sanction review, an OAIC investigation, or a CA ANZ disciplinary referral. The number of tools has nothing to do with it.
Where to next
If you are at the point where the obligations are clear and the question is how to operationalise without absorbing the work into already-stretched partners, this is the conversation we have most often with accounting firms. Our AI Strategy and Managed AI Services practices, and our Professional Services solutions, are built around the control stack above rather than tool selection.
For grounded examples of how this works in practice, our Carbonly and RootCauseAI case studies show the same stack-first approach applied in carbon reporting and engineering investigation respectively. The disciplines transfer.
If you want a partner-level conversation about where your firm sits against the obligations in this article, book a 30-minute consultation. We will work through your current AI footprint against the TPB, APES 110, ATO, and Privacy Act obligations and identify what needs to be in place before any further expansion.
Related Reading:
- Financial Services AI Compliance: APRA and ASIC - The parallel regulator-led vertical, with structural lessons for accounting firms holding AFSLs.
- AI Agents for Australian Businesses: Why DIY Without Understanding Fails - The series opener on why governance, not technology, is the binding constraint.
- Operating AI Agents: The Production Reality - What it actually takes to run AI in production once obligations are mapped.
- The AI Agent Staffing Gap in Australian Business - The people layer that makes supervisory models work.
- AI Vendor Selection Questions for Australian Business - The procurement diligence questions that map directly to APES 110 and APP 8.
Research synthesised from APESB APES 110 Code of Ethics, APES 320 Quality Management for Firms, APES 325 Risk Management for Firms, Tax Practitioners Board guidance and 2024 Code reforms, ATO record-keeping guidance, OAIC Notifiable Data Breach reports, AUSTRAC AML/CTF guidance, and the Moffatt v Air Canada 2024 BCCRT 149 decision.