Privacy Policy
Artificial Intelligence (AI) Use Policy
1. Purpose
This policy outlines how our firm uses Artificial Intelligence (AI) tools safely, responsibly, and in line with Australian law, client expectations, and professional ethics.
Aspen Corp recognises that AI can enhance productivity, technical research, workflow efficiency, and service quality. However, AI must be used in a manner that protects:
- Client confidentiality
- Data security
- Professional judgement
- Regulatory compliance
- The firm’s reputation
AI is a support tool and must not be treated as a substitute for professional expertise or judgement.
2. Scope of Use
AI tools may be used for the following purposes, subject to the restrictions in sections 4 and 5:
- Drafting client communications, reports, proposals, and internal documents
- Summarising legislation, rulings, or technical materials
- Research support (tax, accounting, superannuation, advisory)
- Workflow automation and administrative efficiency
- Learning, development, and productivity assistance
- Data pattern analysis (using de-identified data only)
AI must not be used for:
- Providing final professional advice without human review
- Entering or uploading any client, confidential, personal or sensitive information into unapproved or public AI tools
- Making decisions that materially affect clients without verification
- Preparing or lodging documents with regulators without review
- Generating tax, legal, or financial advice that is not independently validated
Example:
AI may assist with preparing a draft tax planning memo. Where Microsoft Copilot is used within the approved Microsoft 365 environment, staff may work within that secure environment subject to this policy. Where any other AI tool is used, prompts must be fully de-identified and must not contain any client, confidential, personal or sensitive information. The responsible manager or partner must review, amend, and approve the document before it is issued to a client.
3. Guiding Principles
- Transparency
Where appropriate, clients may be informed that AI-assisted tools are used to support efficiency and service delivery. - Accountability
A qualified staff member remains fully responsible for all advice and outputs. - Accuracy
All AI-generated material must be verified against reliable sources. - Confidentiality
Client, firm, personal, and other sensitive information must not be disclosed to unauthorised or unapproved systems. - Professional Ethics
All AI use must align with APES 110 Code of Ethics and the firm’s professional standards and values. - Risk Awareness
AI outputs may contain errors, inaccuracies, outdated information, or biased content. Independent verification is mandatory.
4. Approved AI Tools
Microsoft Copilot is the firm’s preferred AI tool for work-related use within the approved Microsoft 365 environment. Wherever possible, staff should use Copilot in preference to other AI tools. Other AI tools may be used for work-related purposes only in limited circumstances and subject to the restrictions set out in this policy.
| Tool / Platform | Permitted Use | Conditions |
|---|---|---|
| Microsoft Copilot (paid firm-approved version) | Approved for work-related items | Preferred option for work-related use. Must be accessed using the staff member’s work account within the firm’s approved Microsoft 365 environment. |
| Other AI tools (for example ChatGPT, Gemini or similar platforms) | Permitted only in limited circumstances and with strict restrictions | Other AI tools (for example ChatGPT, Gemini or similar platforms) Permitted only in limited circumstances and with strict restrictions May only be used where Copilot is not being used or is not suitable for the task. Must never be used with any client, confidential, personal or sensitive information. Use is limited to generic drafting, brainstorming, research support, or productivity tasks where all prompts are fully de-identified and non-sensitive. |
How to confirm you are using the paid Copilot version: Sign in using your work Microsoft 365 account and open Copilot in Microsoft 365 or within a Microsoft 365 application such as Word or Outlook. Check the Copilot label displayed with your account or in the Copilot pane. Staff approved to use the paid version should see a label such as M365 Copilot (Premium). If the label is not present the approved version will have This is the firm’s preferred option for work-related use because it operates within the firm’s approved Microsoft 365 environment.

If the label is not present the approved version will also have the following two icons at the top of the screen. The briefcase should be coloured blue as per the below illustration.

OR
- Compliance with the Privacy Act 1988 (Cth)
- No use of firm data for external model training
- Clear data storage location (preferably Australian-hosted)
- Contractual confidentiality protections
- Vendor cybersecurity standards
Where other AI tools are used for work-related purposes, staff must ensure that no client, confidential, personal, or sensitive information is entered into the tool. Use of other AI tools is limited to prompts that are fully de-identified and non-sensitive. Although other AI tools may be used in limited circumstances, the firm’s preference is that staff use Microsoft Copilot wherever possible. If there is any uncertainty as to whether a tool or use case is appropriate, staff must seek confirmation from the General Manager or Managing Director before use.
5. Data Handling & Security
5.1 Strict Prohibitions
Staff must never:
- Enter or upload any client, confidential, personal or sensitive information into unapproved or public AI tools
- Upload tax file numbers, financial statements, payroll data, identification documents, or other sensitive records into any AI tool unless expressly permitted within an approved secure environment
- Paste confidential emails, internal strategy documents, or other sensitive material into unapproved systems
5.2 Permitted Use Conditions
Where AI is used:
- Use Microsoft Copilot within the firm’s approved Microsoft 365 environment wherever possible
- Where another AI tool is used, ensure all prompts are fully de-identified and non-sensitive
- Remove client names, ABNs, TFNs, addresses, contact details, and any other identifying information before use
- Confirm the tool’s data handling settings and do not use a tool if entered data may be retained or used for external model training contrary to firm requirements
- Use only firm-approved secure environments for any activity involving firm information
If there is any uncertainty about whether a tool or use case is appropriate, staff must seek confirmation from the General Manager or Managing Director before proceeding.
6. Regulatory & Professional Compliance
AI use must comply with:
- Privacy Act 1988 (Cth)
- Australian Privacy Principles
- Tax Agent Services Act 2009
- APES 110 Code of Ethics
- ASIC regulatory expectations
- ATO confidentiality obligations
The use of AI does not diminish or modify the firm’s professional duty of care.
7. Human Review Requirements
The following always require partner or manager review:
- Client advice letters
- Tax planning strategies
- Complex structuring advice
- Financial modelling outputs
- Regulatory submissions
- Board reports
AI-generated content must never be sent directly to a client without review.
8. Roles & Responsibilities
| Role | Responsibility |
|---|---|
| Board / Directors | Set strategic direction and risk appetite |
| General Manager | Oversee compliance, data protection, and the approved tool register; coordinate training; and monitor usage. |
| Managers | Ensure appropriate supervision and review |
| All Staff | Comply with this policy and report concerns, incidents, or suspected misuse immediately. |
9. Training & Competency
All staff must:
- Complete annual AI awareness training
- Understand risks of hallucinations and bias
- Know when AI use is inappropriate
- Escalate uncertainties promptly
New staff must complete AI induction training before being granted access to approved tools.
10. Incident Reporting
Any suspected misuse, data breach, or inappropriate AI output must be reported immediately to:
- General Manager
- Managing Director
Incidents will be assessed and managed in accordance with the firm’s data breach response plan and any other applicable internal procedures.
11. Monitoring & Review
- This policy will be reviewed at least quarterly.
- The approved AI tool list will be updated as required.
- Compliance monitoring, including spot checks, may be conducted to assess adherence to this policy.
- Breaches of this policy may result in disciplinary action.
12. Breach Consequences and Escalation Pathway
Any breach of this policy, whether actual or suspected, must be treated seriously and escalated promptly. The firm may take action to contain risk, protect client and firm information, and address non-compliance.
- Immediate suspension or restriction of access to AI tools or affected systems
- Internal review or investigation of the incident and affected work
- Additional training, supervision, or corrective action
- Disciplinary action in accordance with firm policies and employment obligations
- Notification to insurers, legal advisers, regulators, or affected clients where required
Escalation pathway: Staff must immediately report any actual, suspected, or accidental breach involving AI use to the General Manager or Managing Director. The firm will then assess the nature and severity of the issue, determine whether access should be suspended, and decide what further action is required under the firm’s incident response, employment, privacy, and regulatory obligations.
Staff must cooperate fully with any review, investigation, containment action, or remediation process arising from a suspected or confirmed breach.
Why this policy matters
Responsible AI use protects:
- Client trust
- Our professional reputation
- Compliance with Australian law
- Our licence and registration standing
- Long-term firm sustainability
AI should enhance, and not replace, professional judgement.


