Nanak Accountants & Associates
This policy sets the conditions for using artificial intelligence in our professional services and practice administration. It explains the permitted uses, required human review, client confidentiality safeguards and how clients can raise questions or concerns.
Document control | Details |
|---|---|
Policy holder | Nanak Associates Pty Ltd trading as Nanak Accountants & Associates |
Version and effective date | 2.1 | 15/09/2026 |
Policy owner | Puneet Singh, Principal, supported by the Privacy Officer and engagement reviewers |
Review | At least annually and following material legal, system or service changes; automated decision disclosures to be reviewed before 10 December 2026. |
1.1 This policy applies to Nanak Associates Pty Ltd, trading as Nanak Accountants & Associates (the Firm, we, us or our). It applies to all personnel acting for the Firm, including Australian and offshore employees, contractors and service providers, and to AI accessed through any account, application, integration or device for Firm work.
1.2 It supports our documented system of quality management under section 40 of the Tax Agent Services (Code of Professional Conduct) Determination 2024 (Code Determination). It operates with the Privacy Policy, engagement terms, confidentiality arrangements and internal procedures. The policy does not itself authorise disclosure of client information.
1.3 The Principal must appoint responsible people to administer tool approval, supervision, privacy, security, staff training and incident response. A tool or workflow must not be used with client information until the required controls and permissions are in place.
2.1 AI includes systems that infer from inputs to produce content, predictions, recommendations or other outputs. It includes generative assistants, transcription and translation, document extraction, classification, risk screening and AI features embedded in accounting or practice software, including custom tools and connected agents.
2.2 Ordinary arithmetic, bank feeds and ATO pre fill are not automatically AI. The same duties of accuracy, confidentiality and care still apply, and automated decision privacy rules can apply to computer programs that are not AI.
2.3 Client information includes any information about a client’s affairs, whether supplied by the client, obtained elsewhere or inferred. Removing a name does not necessarily de-identify a transaction, entity structure or fact pattern. Public availability does not by itself remove professional confidentiality restrictions.
3.1 The Firm and the responsible registered practitioner remain accountable for services provided using AI. Staff must understand the tool’s material limitations and exercise independent professional judgement. AI output is not evidence that a fact is true or that a tax treatment is correct.
3.2 AI may omit facts, invent sources, apply outdated or foreign law, miscalculate or produce biased or misleading results. The level of scrutiny must reflect the consequences of error and the complexity of the matter. Client permission does not lower the required professional standard.
3.3 We do not transfer responsibility to the client or the technology provider merely because AI was used. Nothing in this policy excludes a right or remedy that cannot lawfully be excluded.
4.1 Relevant obligations include Code items 6 to 10 under section 30-10 of the Tax Agent Services Act 2009 (Cth) (TASA), covering confidentiality, competence, maintained knowledge and reasonable care; and sections 30, 35 and 40 of the Code Determination, covering client records, supervised services and quality management.
4.2 We have regard to the TPB’s final Guidance Statement TPB(GS) 55/2026 on AI, issued 22 July 2026, together with its guidance on confidentiality, outsourcing, record keeping, client verification and supervision. The guidance explains existing duties; it is not a TPB certification of an AI product or of this policy.
4.3 Applicable privacy, TFN, consumer, confidentiality, intellectual property and anti discrimination requirements continue to apply. Where relevant, AML/CTF, recording and professional standards also apply. APES requirements apply according to the professional memberships and services concerned. A voluntary AI framework is not treated as legislation.
5.1 Only an approved tool, in its approved account configuration, may be used for an approved task. Approval is specific to the data, purpose, settings and connections involved; it does not automatically cover every feature in the same product.
Task | Permitted assistance and control |
|---|---|
Document processing | Extract data and suggest classifications. Compare material outputs with the original document and resolve omissions, duplicate entries and ambiguous readings. |
Bookkeeping and BAS | Suggest codes and flag unusual transactions. A competent person verifies the treatment and approves client work and lodgements. |
Research and calculations | Locate and summarise sources, organise an issue or assist a calculation. Check the actual authority, applicable jurisdiction, period and assumptions; independently verify material calculations. |
Drafting and translation | Prepare draft correspondence, workpapers and translations. Check factual, technical and language accuracy before reliance or issue. |
Client administration | Use an approved, identified assistant for general information, intake, routing or scheduling. Restrict it to approved content and provide human escalation. |
Marketing and education | Assist with general content using public or synthetic material. Check claims, sources, permissions and accuracy before publication. Client examples require separate approval and any necessary consent. |
5.2 A new use, material software change, integration, autonomous action or additional data category requires reassessment before use. Existing software access and a vendor’s “AI enabled” label are not sufficient authorisation.
6.1 Staff must not enter client confidential or personal information into unapproved AI, personal or consumer chatbot accounts, public prompt libraries or public sharing links. Buying a subscription or disabling one training setting does not establish that a tool is suitable.
6.2 AI must not independently determine or communicate a client’s tax position, create binding advice, sign an engagement, set or vary fees, lodge a return, execute a transaction or make a regulatory report. Approved administrative automations may send fixed confirmations within documented limits; they must not expand into these decisions.
6.3 Staff must not use an AI answer they cannot verify; invent documents, facts, deductions, citations or evidence; misrepresent authorship or review; or bypass the Firm’s approval and supervision process.
6.4 TFNs, passwords, authentication codes, banking credentials and full identity document images must not be entered into general purpose generative AI. A specialised identity or tax processing feature requires a separately documented lawful purpose, minimum data, Principal approval and the applicable permissions and safeguards. Approval or client consent cannot override a statutory prohibition.
6.5 Client information must not be made available to train or improve a provider’s general models or be included in public demonstrations. Training or fine tuning an internal model on client information requires a separate legal, privacy and technical assessment and specific approval; ordinary engagement consent is insufficient.
6.6 We prohibit AI based sensitive profiling unrelated to a lawful service, discriminatory decision making, covert recording, impersonation and use of unlicensed material contrary to applicable rights. Staff must not connect a tool to entire mailboxes, document stores or client databases without approval of the particular access and data flows.
7.1 Before use, the staff member must understand the task, verify the relevant input and identify missing information. AI must not be asked to fill evidentiary gaps with assumptions presented as client facts.
7.2 Material outputs must be checked against source records and appropriate current primary authorities. A plausible quotation, hyperlink or case name must be opened and verified. Important tax calculations must be independently reproduced or checked using a validated method.
7.3 Review must consider whether the output addresses the actual facts, uses the correct law and period, and omits a material exception or alternative. Discrepancies and unsupported conclusions must be resolved before reliance. A second AI response is not independent verification.
7.4 A competent reviewer must approve professional client work before issue or lodgement in accordance with the Firm’s supervision arrangements. The responsible registered tax practitioner retains oversight and approves matters requiring their judgement. The client’s required review, declaration and lodgement authority must also be obtained.
7.5 The file must show who performed the material checks, what was verified, how issues were resolved and who approved the result. A general tick stating “AI reviewed” is insufficient for a material judgement or complex calculation.
8.1 Before disclosing information about a client’s affairs to an AI provider or other third party, the responsible person must verify that the client has given informed permission covering the proposed disclosure, unless a legal duty requires it. Configuration may affect whether a tool involves disclosure; that assessment must be documented rather than assumed.
8.2 The client must receive a meaningful description of the information, purpose, provider or recipient, relevant countries and storage or support arrangements, and the intended use of AI. Material restrictions, onward access and provider retention must be considered when seeking permission.
8.3 The permission may be recorded in the signed engagement agreement, a separate consent or another clear communication. A reference to “technology” alone, the publication of a privacy policy or a supplier confidentiality agreement is not a substitute for checking that the particular disclosure is authorised. New uses outside an existing authority need further permission.
8.4 The client’s permission under TASA does not automatically satisfy every privacy requirement for personal information about employees, family members or other individuals. Sensitive information, government identifiers and TFNs need the applicable additional legal basis. Inferred personal information and outputs are assessed as well as inputs.
8.5 Clients may request restrictions or withdraw permission prospectively through the contact in clause 15. We record and implement the restriction, explain any limitations and discuss an available alternative before continuing affected work. If a service cannot practicably be provided without a necessary approved system, we explain this and agree a lawful course, including a transfer or ending that part of the engagement if necessary.
8.6 Withdrawal does not undo lawful past processing or remove mandatory retention duties. It does prevent further disclosure that requires and no longer has permission. No standard AI authority waives APP 8.1 safeguards for overseas disclosure.
9.1 Before approval, the Principal or authorised delegate must assess the business need and whether the task can be done with less information or without AI. A privacy and security risk assessment is required for client information, and a fuller impact assessment is required for material new risks.
9.2 The assessment must cover the provider’s legal identity; account terms; data and task; hosting, backups, support and subprocessor locations; access and logging; retention and deletion; training and feedback settings; contractual protection; incident response; accuracy and bias; connected actions; and the ability to export, correct and remove records.
9.3 Approval must record the permitted data and tasks, responsible owner, required permissions, review method, conditions and review date in an Approved Tool Register. Approval must be withheld where material information about handling is unavailable or the risks cannot be adequately controlled.
9.4 An approved service handling client information must have terms and settings that prevent provider use of that information for general model training. Staff must not opt in through feedback, shared conversations or a new feature. This training restriction does not mean the provider keeps no logs or that all processing occurs in Australia; those matters need separate assessment.
9.5 Use the minimum relevant material. Remove identifiers, metadata, unrelated pages and distinctive details where they are unnecessary; test the risk of re-identification. Synthetic examples are preferred for learning and trials. A whole client file must not be uploaded for convenience.
9.6 Apply approved access controls, multifactor authentication where required, secure transfer, account separation and appropriate retention. Connected tools must have the least access needed. Prompts, attachments, model output and external content must be treated as potentially untrusted; embedded instructions must not cause unauthorised disclosure or action.
9.7 A vendor, model, feature or terms change that may affect privacy, reliability or control requires review. Suspend affected use where approval conditions cannot be met. Do not assume a feature is safe merely because it is built into software already used by the Firm.
10.1 Our overseas personnel, including support in India, must meet the same approval, confidentiality and review requirements. The Firm must check the status of any separate provider, the scope of client permission and the actual locations of access and processing.
10.2 Supervisors assign work according to skills and complexity, provide escalation and ensure meaningful review. Offshore AI assisted professional work must receive the Australian review required by the Firm’s supervision arrangements before reliance or issue.
10.3 No contractor may introduce a further subcontractor, AI provider or unapproved integration for Firm work without authorisation. The Firm remains responsible for appropriate supervision and control of tax agent services provided on its behalf.
11.1 People make the professional, engagement and reporting decisions identified in this policy. Nevertheless, a computer program may perform a task substantially and directly related to a decision significantly affecting an individual. Staff must not treat a human sign off as automatically removing that process from the automated decision transparency rules.
11.2 The Firm must maintain an inventory of relevant AI and non AI processes and assess APPs 1.7 to 1.9 before 10 December 2026. Where applicable, the Privacy Policy must describe the information used and the relevant sole or assisted decisions. New processes and material changes require that assessment before deployment.
11.3 Client facing AI must be identified clearly at the point of interaction, use approved content and provide a practical human contact route. Optional recording or AI transcription must not begin until the relevant notice and consent requirements have been met. Requests to speak to a person or avoid recording must be escalated promptly.
11.4 If a client challenges an AI assisted result, an appropriately skilled person must examine the original evidence, explain the result where lawful and correct any error. Complaints are managed through the Privacy Policy and ordinary complaints process.
12.1 Staff must complete role appropriate training before using AI for Firm work and receive updates for material changes. Training covers confidentiality, minimisation, reliable source checking, tool limitations, bias, connected tool risks, record keeping and escalation.
12.2 The Firm must maintain evidence of approvals, vendor assessments, client permissions and restrictions, staff training, material review and incidents. For client work, retain sufficient inputs or a reference to them, material outputs, sources, assumptions, corrections and reviewer details to explain the service and its outcome. Do not duplicate entire confidential datasets merely to retain every prompt.
12.3 Records of tax agent services must meet section 30 of the Code Determination, including the minimum 5 year period after completion of the relevant service. Other record types, including identity checks and AML/CTF records, follow the separate periods in the Privacy Policy. Records must be accessible and in English or readily convertible into English.
12.4 The Principal must ensure periodic checks of actual use, approvals, review quality, privacy settings and recorded restrictions. Failures require remedial action, retraining, restricted access or withdrawal of approval. Staff breaches may lead to disciplinary or contractual action according to law.
13.1 Personnel must immediately report an unintended disclosure, unapproved upload, unsafe output, lost access control or material reliance on an incorrect output to the Principal and Privacy Officer. Stop the affected activity and preserve relevant evidence securely; do not attempt to hide the event or erase evidence.
13.2 The response must address containment, provider contact, exposed information, downstream use, corrections, client impact and any notification or reporting duty. A security or privacy incident is assessed under the Privacy Policy, including applicable Notifiable Data Breaches (NDB) assessment and notification requirements.
13.3 Where an error affects work supplied to a client, we investigate promptly, explain material implications and take appropriate corrective action. We assess any duty concerning false or misleading statements, breach reporting or regulator notification on its own legal terms. AI use is not a reason to leave an error uncorrected.
14.1 The Principal reviews this policy at least annually and following material incidents or changes to law, guidance, tools, services or insurance requirements. Approved versions and evidence of implementation must be retained.
14.2 This policy is supported by the Privacy Policy, engagement authorities, Approved Tool Register, automated processing inventory, supervision arrangements and incident procedures. Those operational records must be implemented and kept current; publication of this policy alone is not evidence of compliance.
15.1 Clients may ask how AI was used on their matter, ask about recipients and locations, request a restriction, seek correction or raise a concern. Access to personal information is handled under the Privacy Policy. We protect other clients’ information and any lawfully restricted material when responding.
Principal and Privacy Officer
Nanak Associates Pty Ltd trading as Nanak Accountants & Associates
Email: [email protected] | Phone: 1300 626 258
Postal address: [Insert address for privacy correspondence]
Privacy complaints: www.oaic.gov.au/privacy/privacy-complaints
Tax agent service complaints: www.tpb.gov.au/complaints