The duty you carry
The CPA codes of professional conduct make client confidentiality non-negotiable: no consent, no disclosure. A SIN, a T1, a valuation pasted into a public AI tool is a disclosure to a third party, made at the exact moment your team is too busy to think twice. Privacy law adds breach-notification duties on top, but the professional duty alone is enough to lose the client.
The moment it breaks
Synthetic example. The real version happens on your busiest day.
The letter still gets drafted. The SIN, the name, and the return never reach the AI provider, and the near-miss becomes a policy event you can point to.
Caught, in your vocabulary
SINs and government IDs
The identifiers that turn a working note into a breach-notification question.
Client returns and financials
T1s, statements, valuations, payroll: the files clients trust you to keep closed.
Payment and account numbers
Cards on file, banking details, and billing records sitting in engagement notes.
The rules you answer to
CPA confidentiality duty
The professional codes bar disclosure of client information without consent, and pasting it into a third-party AI tool is exactly that, whatever the intent.
PIPEDA & Quebec Law 25
Financial records are personal information. Law 25 adds incident record-keeping and penalties reaching C$25M or 4% of worldwide turnover.
Client expectations
Engagement letters promise confidentiality. Evidence that sensitive data is caught before submission is how that promise survives a client's AI-security questionnaire.
From our research
What the CPA Confidentiality Duty Means When Client Data Meets Generative AI
Your professional code binds you to keep client financial information confidential. But the moment a staff accountant pastes a return into a public AI tool, that duty is already in jeopardy.
Keeping Client Tax Returns Out of ChatGPT During Busy Season
During busy season, an overloaded associate pastes a client's return into ChatGPT to summarize it faster. The client's SIN and income just left your firm's control, and it can't be recalled.
Answering the Client AI-Security Questionnaire: What Outside Counsel Needs to Show
Clients now send law firms AI-security questionnaires before handing over sensitive matters. The ones asking how you protect their data in AI tools want evidence, not assurances. Here's what a credible answer looks like.
Also built for
See it on your own scenarios
Twenty minutes, your examples, no slideware. Or start with the five-question readiness check. No email required.