Register

Client confidentiality and AI suppliers

The duty of confidentiality in the codes of ethics covers client information put into an AI tool. Before a tool is used on client data, the practice needs answers from the supplier about training, retention, location, sub-processors, security and deletion.

Accountin · Last checked 2 October 2026

The duty in the codes

Section 140 of the AAT Code of Professional Ethics says members must not disclose confidential information outside the firm without proper and specific authority, unless there is a legal or professional right or duty to disclose. Members must take reasonable steps so that staff and people giving them advice or assistance respect confidentiality, and the duty continues after the client relationship ends (AAT Code of Professional Ethics). The ICAEW, ACCA and ICAS codes rest on the same IESBA principle (ICAEW: generative AI and ethics).

The ACCA and CISI report of October 2025 says the IESBA technology revisions added guidance on securing confidential information across the whole data cycle, from collection through transfer, storage and use to lawful destruction (ACCA and CISI, October 2025).

How it applies to AI tools

The PCRT AI guidance says putting client data into publicly available AI tools is likely to breach confidentiality unless the client has consented. Once information goes into such a tool, control over it is lost, its storage and retention are not governed by the practice, and it may be held by third parties or overseas (PCRT AI topical guidance, January 2026).

The guidance also covers information about third parties, such as the other side of a transaction under a non-disclosure agreement, and the case where a client asks that AI tools are not used on their affairs. There it suggests agreeing with the client what they regard as unacceptable use, and whether that can be applied to the engagement.

Public tools and business tools

ICAEW's guide says respecting confidentiality means not loading confidential information into public generative AI tools, even if it has become public, because there is little visibility of who sees it, how it is secured and how long it is kept (ICAEW: generative AI and ethics). A business version of a tool, under a contract that limits what the supplier can do with the data, is a different position. The practice still reads the contract terms for that plan before relying on them.

Questions to ask an AI supplier

  • Training. Is our data, or anything derived from it, used to train or improve your systems or anyone else's? Is that off by default, and is it written into the contract?
  • Retention. How long are prompts, uploaded files and outputs kept, including in logs and backups? Can we set a shorter period?
  • Location. In which countries is data processed and stored, including for support and monitoring? Which transfer mechanism covers any transfer outside the UK (ICO: international transfers)?
  • Sub-processors. Who are your sub-processors, what does each do, and how will you tell us about changes? Can we object?
  • Access. Which of your staff can see our data, in what circumstances, and is that access logged?
  • Security. Which independent certifications or reports do you hold, such as ISO/IEC 27001 or a SOC 2 report, or Cyber Essentials for UK suppliers? Can we see the certificate and its scope?
  • Deletion. Can we delete a single file or conversation, and all our data at the end of the contract? Will you confirm deletion in writing?
  • Contract terms. Is there a data processing agreement with the Article 28 terms (ICO: what needs to be in the contract)? Does it oblige you to tell us of a breach promptly?
  • Separation. Is our data kept apart from other customers' data, and can one customer's prompts surface another customer's information?
  • Security of the tool itself. How do you protect against prompt injection and tampering with training data, the risks the NCSC describes (NCSC: AI and cyber security, 13 February 2024)?
  • Explainability. Can the tool show the sources behind an answer, so a reviewer can check them?

Recording the answers

Keep the supplier's answers, the contract and any certificates with the practice's assessment of the tool. ICAEW's guide says accountants should ask the right questions of suppliers and get the evidence (ICAEW: generative AI and ethics). The ACCA and CISI report lists supplier due diligence, audit rights, deletion commitments, logging and data residency controls among its suggested safeguards (ACCA and CISI, October 2025). Review the answers when the supplier changes its terms or releases a new version of the tool.

Questions

Does client consent in the engagement letter cover everything?

Consent to the use of AI-enabled software does not remove the duty to choose a tool that keeps the data secure. The PCRT AI guidance also says that where AI use is fundamental to a deliverable it may be appropriate to tell the client before the work starts (PCRT AI topical guidance).

What about staff using their own accounts on free tools?

The PCRT AI guidance says staff should disclose to senior colleagues when they have used an AI tool, and gives an AI usage policy as a safeguard against unknown use. See the AI policy outline.

In Accountin

In Accountin, staff are invited by the owner with owner or staff roles, every login uses two-step sign-in, and exports and filings are written to the audit log.

Accountin is opening to its first practices

Register your practice and we will contact you to set up your account.

Register your practice