Back to Home

Solutions · Accounting firms

Busy-season speed, without the disclosure

The weeks your team most needs AI are the weeks client data is most likely to leave. The fix isn't banning the shortcut. It's making the shortcut safe.

The duty you carry

The CPA codes of professional conduct make client confidentiality non-negotiable: no consent, no disclosure. A SIN, a T1, a valuation pasted into a public AI tool is a disclosure to a third party, made at the exact moment your team is too busy to think twice. Privacy law adds breach-notification duties on top, but the professional duty alone is enough to lose the client.

The moment it breaks

Synthetic example. The real version happens on your busiest day.

TypedDraft a short letter telling the client we found the issue: Priya Sharma, SIN 046 454 286, overpaid instalments on her 2025 T1 and should expect a refund.
SentDraft a short letter telling the client we found the issue: [NAME], SIN [SIN], overpaid instalments on her [RETURN] and should expect a refund.

The letter still gets drafted. The SIN, the name, and the return never reach the AI provider, and the near-miss becomes a policy event you can point to.

Caught, in your vocabulary

SINs and government IDs

The identifiers that turn a working note into a breach-notification question.

Client returns and financials

T1s, statements, valuations, payroll: the files clients trust you to keep closed.

Payment and account numbers

Cards on file, banking details, and billing records sitting in engagement notes.

The rules you answer to

01

CPA confidentiality duty

The professional codes bar disclosure of client information without consent, and pasting it into a third-party AI tool is exactly that, whatever the intent.

02

PIPEDA & Quebec Law 25

Financial records are personal information. Law 25 adds incident record-keeping and penalties reaching C$25M or 4% of worldwide turnover.

03

Client expectations

Engagement letters promise confidentiality. Evidence that sensitive data is caught before submission is how that promise survives a client's AI-security questionnaire.

Also relevant: CCPA/CPRA · SOC 2

Answers for your situation

All guides
Fractional CFOs: is it safe to keep several clients' financials in one AI account?

Not without deliberate separation. Features such as memory, chat history, projects and custom GPTs are built to carry context forward, so one client's figures can shape the answers you get for another. If you are a CPA in Ontario, Rule 208 of the CPA Code prohibits using one client's confidential information for the advantage of a third party and requires measures that limit access to it, and CPA Ontario's 2026 AI guidance says confidential data should go only into environments verified as secure.

Read the guide
Can payroll and HR providers put SINs and payroll data into AI tools?

Not into a public AI tool. Service Canada treats employee SINs as confidential and limited to income-related purposes, and privacy law requires safeguards matched to the sensitivity of the data, so pasting a SIN, pay stub or benefits file into a personal AI account is very hard to justify. Payroll and HR teams can still use AI for formulas, policy drafts and reconciliation logic, as long as identifying employee data is removed before anything is submitted.

Read the guide
SR&ED consultants: can you draft client project descriptions with AI?

Yes, if the client's technical data stays out of tools your engagement does not cover. CRA has not published guidance on AI use by claim preparers that we could find, so the limits come from your client contracts and NDAs, privacy law for the personal information in a claim, and any professional code you belong to. Draft with abstracted facts in a vetted tool, and keep source code, experimental results and unreleased product details out of public AI accounts.

Read the guide

From our research