Fractional CFOs, outsourced controllers and part-time finance leads

Fractional CFOs: is it safe to keep several clients' financials in one AI account?

Sources verified Sanitized Ai Team

The short answer

Not without deliberate separation. Features such as memory, chat history, projects and custom GPTs are built to carry context forward, so one client's figures can shape the answers you get for another. If you are a CPA in Ontario, Rule 208 of the CPA Code prohibits using one client's confidential information for the advantage of a third party and requires measures that limit access to it, and CPA Ontario's 2026 AI guidance says confidential data should go only into environments verified as secure.

The situation

A fractional CFO works with five companies: a SaaS startup, two distributors, a clinic group and a family-owned manufacturer. Everything runs through one ChatGPT account. There is a project for board decks, a custom GPT loaded with a cash flow template and last quarter's numbers, and memory is on because it saves time. On Monday, drafting a lender update for one distributor, the draft mentions a margin figure and a supplier name that belong to the other distributor.

Nobody outside the account saw anything. But the CFO has just learned that the tool treats five clients as one body of context, and that the separation they assumed was never there.

What the rules actually say

How the features carry context

OpenAI's help page on Memory in ChatGPT explains that, depending on plan and settings, memory can draw on past chats, saved memories, custom instructions, files in the Library and connected apps. It also notes that turning memory off does not delete past chats, and that deleting a chat does not necessarily remove a saved memory created from it. The page on Projects in ChatGPT describes projects as a place where chats, files and instructions are kept together as shared context, which can be shared with others, including by link.

These are useful features for one person's work. For a professional serving competing clients, they are exactly how information crosses from one engagement into another. Other AI assistants offer similar features, so check the settings of whichever tool you use.

The CPA Code

For CPAs in Ontario, Rule 208 of the CPA Code of Professional Conduct sets three obligations that map directly onto this problem:

  • 208.1 prohibits disclosing a client's confidential information except in specified cases, including client consent.
  • 208.2 prohibits using a client's confidential information for the advantage of a third party without consent. Another client is a third party.
  • 208.3 requires appropriate measures to protect confidential information and limit access to those with a legitimate purpose, and the written agreement of anyone given access to keep it confidential.

In June 2026, CPA Ontario published The Responsible Use of AI in Professional Practice, which ties AI use to Rules 202, 203, 205 and 208. On confidentiality, it says members must ensure confidential or personally identifiable information goes into AI tools only when the environment is verified as secure and compliant. That is guidance interpreting binding rules. Other provinces' CPA bodies have their own codes, so confirm your own. Our post on the CPA confidentiality duty and generative AI covers the duty in general; this guide is about the multi-client problem.

Privacy law

Client ledgers, payroll files and customer lists contain personal information. Under PIPEDA, an organization remains responsible for information it transfers to a third party for processing, and safeguards must match the sensitivity of the data. See our PIPEDA overview.

Why policies and bans fall short

Most fractional CFOs are a practice of one or a small team, with no IT department and no one reviewing settings. A policy that says "keep clients separate" does not change how memory works. A personal ban on AI gives up the productivity that makes the fractional model viable.

Account type also matters. OpenAI says it does not train on Business or Enterprise workspace content by default, but personal accounts follow the individual's own settings, as explained in does ChatGPT train on company data. Either way, content already submitted cannot be recalled.

What a practical control looks like

  1. Separate by client. Use a separate project or workspace for each client, never a shared one, and never a custom GPT that holds more than one client's files.
  2. Set memory deliberately. Review memory and chat history settings, and use a temporary chat for client work if you keep memory on for anything else. Check the memory summary periodically and delete saved memories along with the chats they came from.
  3. Use a business account. Choose a plan with contractual commitments on training and retention, and keep personal accounts out of client work.
  4. Strip identifiers before prompting. Client names, account numbers, SINs, employee names and customer names rarely need to be in a prompt to get a useful answer.
  5. Never share client projects by link. Invite named people only, and remove access at the end of an engagement.
  6. Put it in the engagement letter. Name the tool, explain how client data is separated, and obtain consent where your code or the client's agreement requires it.
  7. Offboard cleanly. When an engagement ends, delete that client's projects, files, chats and saved memories, and record that you did.

Sanitized Ai is a browser extension that supports steps 4 and 6. When you or a team member is about to submit client names and identifiers, financial data or personal information to an AI assistant, it redacts or blocks that content before submission and explains in plain language what was flagged and why. Details that are redacted or blocked before submission do not reach the account's history or memory, which supports the client separation described above.

For practices with staff, administrators see a dashboard of flagged-event metadata (which tool, what type of data, which policy, when), never prompt content. That gives you an audit-ready record to show clients how their data is handled, without reading anyone's prompts. See how it fits accounting practices.

Frequently asked questions

If I turn off memory, is the problem solved?

It helps, but it is not the whole answer. OpenAI's help pages explain that turning memory off does not delete past chats, and that deleting a chat does not necessarily delete a saved memory created from it. Projects, custom GPTs and uploaded files can also carry one client's material into work for another.

Does a ChatGPT Business account fix the confidentiality issue?

It improves it. OpenAI states that it does not use content from Business or Enterprise workspaces to train its models by default. The separation between clients inside your own account is still your responsibility, and so is what each client has agreed to.

I am not a CPA. Do these rules apply to me?

The CPA Code applies to CPA members and firms. If you are not a member, your obligations come mainly from your engagement agreements, any NDAs, and privacy law such as PIPEDA for personal information in client records. In practice, clients expect the same standard either way.

Should I tell clients I use AI tools?

Yes, in most cases. Rule 208 turns on consent for disclosure and on written confidentiality agreements with anyone given access, so a short clause in the engagement letter that names the tool and explains how each client's data is kept separate is a sound starting point. Confirm the wording with CPA Ontario's Professional Advisory Services or your own counsel.

Close the gap between the rule and the prompt box.

Sanitized Ai is a browser extension that coaches staff at the moment they type, redacts or blocks sensitive data before it reaches an AI tool, and gives administrators audit-ready records of flagged events without showing prompt content.

Talk to us

Primary sources

This guide summarizes the cited sources as of the verification date. It is practical guidance, not legal advice. Confirm your obligations with your regulator or counsel.

For your industry

Standards that apply

Related guides

Further reading