Before You Connect AI to Your Ledger
Accounting systems hold client financial data, banking details and payment capability in one place. Connecting a third party to them warrants more scrutiny than a typical software integration, and rather more than it usually receives.
General guidance for structuring your own assessment, not legal, security or professional advice. Progress saves in this browser.
Pre-Connection Security Checklist
Settle these before granting access to any accounting system.
Your ticks are saved in this browser, so you can work through the list over several sessions.
01Access scope
0/6Almost always requested broader than the task requires.
02Data handling
0/6Client financial data carries confidentiality expectations.
03Client confidentiality
0/5Check what you have already committed to.
04Payment and lodgement controls
0/6Automation prepares. People approve.
05Logging and audit trail
0/6A reviewer must be able to tell what a system decided.
06Professional obligations
0/5These stay with the agent, not the software.
General guidance only, not legal, security, accounting or professional advice, and not exhaustive. Confirm current requirements with the Tax Practitioners Board and your professional body, and obtain advice for your specific circumstances.
Why This Warrants Extra Care
Three factors make accounting integrations higher risk than most, and all three are frequently overlooked because the software feels familiar.
Client data you hold on trust
A practice holds financial information for many clients, each of whom has confidentiality expectations and often contractual rights. A single supplier connection touches all of them at once, which concentrates the consequence of getting it wrong.
Payment capability is often bundled in
Accounting system permissions frequently bundle read access with the ability to create or approve payments. Granting broad access can hand a third party far more capability than the task requires, without anyone intending it.
Professional obligations do not transfer
Registered tax and BAS agents carry obligations under the Tax Agent Services Act and their professional body’s code. Engaging a supplier does not shift those, and the accountability for what is lodged stays firmly with the agent.
The Six Areas
Grouped so each section can be assigned to whoever is best placed to assess it.
Access scope
Which systems, which clients, which permissions, and via what kind of account.
Data handling
Where financial data goes, whether it is retained, and whether it trains anything.
Client confidentiality
What your clients have been told, and what your engagement terms actually permit.
Payment and lodgement controls
What the system can initiate, and what stops it doing so unattended.
Logging and oversight
Whether you would detect misuse, and whether automated entries are traceable.
Professional obligations
How the arrangement sits against your agent and professional body requirements.
The Four Risks Worth Understanding
Each has produced real problems in practice. Understanding the mechanism makes the controls obvious rather than bureaucratic.
Permission scopes broader than the task
Accounting platform integrations often request access across the whole practice file or every connected client, and frequently include write and payment permissions when only read access is needed. Approved once, the grant persists silently until somebody reviews it.
- Read the requested scopes in full before approving, not after
- Grant read-only where the task does not require writing
- Restrict to the specific clients in scope where the platform allows
- Schedule a periodic review of connected applications
Automated payments triggered by manipulated input
Where a system processes supplier invoices and can create payments, a fraudulent or manipulated invoice becomes a path to an unauthorised payment. This is a modern version of invoice fraud, and automation removes the human who would have noticed something odd.
- Never allow unattended payment creation from automated invoice processing
- Require human approval for every payment, with supplier bank detail checks
- Flag changes to supplier bank details for separate verification
- Set value thresholds that always require senior approval
Client financial data leaving the country
Financial records processed by an AI system may be transmitted to infrastructure outside Australia, including through sub-processors. Clients frequently have expectations, and sometimes contractual terms, about where their data goes.
- Confirm in writing which countries data is processed and stored in
- Obtain the sub-processor list, including the model provider
- Check your engagement terms for data-handling commitments
- Consider whether clients should be notified of the arrangement
Automated entries with no audit trail
Entries created by an automated process must be identifiable as such and traceable to their source. Without that, a reviewer cannot tell what was decided by a person and what by a system, which undermines both review and any later investigation.
- Ensure automated entries are tagged and identifiable in the ledger
- Require the source document to be attached or linked to every entry
- Confirm the audit trail records what triggered each automated action
- Ensure a reviewer can distinguish automated from manual entries at a glance
Next Steps
Accounting Firm Automation Scorecard
Work out which processes are worth automating before assessing suppliers.
Score your firm →How to Choose AI Accounting Software
The longer written guide to evaluating options for a practice.
Read the guide →Frequently Asked Questions
For invoice capture and coding, read access to the chart of accounts and supplier records plus the ability to create draft bills is generally sufficient, note that creating a draft is materially lower risk than creating an approved payable. For reconciliation assistance, read access to bank transactions and the ledger with the ability to suggest rather than post matches. Payment creation and approval permissions should be granted only where you have deliberately decided to enable that, with human approval retained. Broad write access across the whole practice file is rarely necessary.
Check your engagement terms first, since many include commitments about confidentiality, subcontracting or data handling that may require notification or consent. Beyond the contractual position, professional bodies expect members to act with integrity and transparency, and there is a reasonable argument that clients should know if their financial data is processed by a third party, particularly offshore. Many practices address this with a clause in updated engagement terms. Confirm the current expectations of your own professional body. This is general information, not professional advice.
It can assist with preparation, but the professional judgement and the lodgement decision must remain with the registered agent. Registered tax and BAS agents carry obligations under the Tax Agent Services Act and the Code of Professional Conduct that are not transferable to software, including taking reasonable care to ensure taxation laws are applied correctly. The workable model is automation handling data collection, entry and preparation, with a registered agent reviewing and taking responsibility for what is lodged. Confirm the current position with the Tax Practitioners Board.
Human approval on every payment is the baseline, and it should not be negotiated away for efficiency. Beyond that: verify supplier bank details independently when they change, since that is the most common invoice fraud vector; set value thresholds requiring senior approval; maintain separation between whoever sets up a supplier and whoever approves payment to them; and review the payment run before release rather than after. Automation should prepare payments and never release them unattended.
The practice or business remains responsible for the accuracy of its records regardless of how an entry was created, which is why the audit trail matters so much. Automated entries should be identifiable as automated, traceable to their source document, and reviewable before anything is reported or lodged. Where an error is discovered, the correction process is the same as for any error, but the ability to identify how many similar entries were affected depends entirely on having tagged them properly in the first place.
No. It is a practical prompt list covering the issues specific to connecting AI to accounting systems, and it is not exhaustive. It is not legal, security, accounting or professional advice, and it cannot account for your specific obligations, engagement terms or the product you are considering. For decisions with real consequence, obtain advice from a qualified professional and confirm the current requirements with the Tax Practitioners Board and your professional body.
Want to Ask Us These?
We will answer every question on this list in writing before any connection is made. That is the standard any practice should hold a supplier to.