The situation
A fractional CFO works with five companies: a SaaS startup, two distributors, a clinic group and a family-owned manufacturer. Everything runs through one ChatGPT account. There is a project for board decks, a custom GPT loaded with a cash flow template and last quarter's numbers, and memory is on because it saves time. On Monday, drafting a lender update for one distributor, the draft mentions a margin figure and a supplier name that belong to the other distributor.
Nobody outside the account saw anything. But the CFO has just learned that the tool treats five clients as one body of context, and that the separation they assumed was never there.
What the rules actually say
How the features carry context
OpenAI's help page on Memory in ChatGPT explains that, depending on plan and settings, memory can draw on past chats, saved memories, custom instructions, files in the Library and connected apps. It also notes that turning memory off does not delete past chats, and that deleting a chat does not necessarily remove a saved memory created from it. The page on Projects in ChatGPT describes projects as a place where chats, files and instructions are kept together as shared context, which can be shared with others, including by link.
These are useful features for one person's work. For a professional serving competing clients, they are exactly how information crosses from one engagement into another. Other AI assistants offer similar features, so check the settings of whichever tool you use.
The CPA Code
For CPAs in Ontario, Rule 208 of the CPA Code of Professional Conduct sets three obligations that map directly onto this problem:
- 208.1 prohibits disclosing a client's confidential information except in specified cases, including client consent.
- 208.2 prohibits using a client's confidential information for the advantage of a third party without consent. Another client is a third party.
- 208.3 requires appropriate measures to protect confidential information and limit access to those with a legitimate purpose, and the written agreement of anyone given access to keep it confidential.
In June 2026, CPA Ontario published The Responsible Use of AI in Professional Practice, which ties AI use to Rules 202, 203, 205 and 208. On confidentiality, it says members must ensure confidential or personally identifiable information goes into AI tools only when the environment is verified as secure and compliant. That is guidance interpreting binding rules. Other provinces' CPA bodies have their own codes, so confirm your own. Our post on the CPA confidentiality duty and generative AI covers the duty in general; this guide is about the multi-client problem.
Privacy law
Client ledgers, payroll files and customer lists contain personal information. Under PIPEDA, an organization remains responsible for information it transfers to a third party for processing, and safeguards must match the sensitivity of the data. See our PIPEDA overview.
Why policies and bans fall short
Most fractional CFOs are a practice of one or a small team, with no IT department and no one reviewing settings. A policy that says "keep clients separate" does not change how memory works. A personal ban on AI gives up the productivity that makes the fractional model viable.
Account type also matters. OpenAI says it does not train on Business or Enterprise workspace content by default, but personal accounts follow the individual's own settings, as explained in does ChatGPT train on company data. Either way, content already submitted cannot be recalled.
What a practical control looks like
- Separate by client. Use a separate project or workspace for each client, never a shared one, and never a custom GPT that holds more than one client's files.
- Set memory deliberately. Review memory and chat history settings, and use a temporary chat for client work if you keep memory on for anything else. Check the memory summary periodically and delete saved memories along with the chats they came from.
- Use a business account. Choose a plan with contractual commitments on training and retention, and keep personal accounts out of client work.
- Strip identifiers before prompting. Client names, account numbers, SINs, employee names and customer names rarely need to be in a prompt to get a useful answer.
- Never share client projects by link. Invite named people only, and remove access at the end of an engagement.
- Put it in the engagement letter. Name the tool, explain how client data is separated, and obtain consent where your code or the client's agreement requires it.
- Offboard cleanly. When an engagement ends, delete that client's projects, files, chats and saved memories, and record that you did.
Sanitized Ai is a browser extension that supports steps 4 and 6. When you or a team member is about to submit client names and identifiers, financial data or personal information to an AI assistant, it redacts or blocks that content before submission and explains in plain language what was flagged and why. Details that are redacted or blocked before submission do not reach the account's history or memory, which supports the client separation described above.
For practices with staff, administrators see a dashboard of flagged-event metadata (which tool, what type of data, which policy, when), never prompt content. That gives you an audit-ready record to show clients how their data is handled, without reading anyone's prompts. See how it fits accounting practices.