A practical framework for valuation analysts and forensic accountants who want AI’s efficiency without a confidentiality breach, a privilege waiver, or a professional standards violation.
Why This Matters Now
Every week, another valuation analyst pastes a client’s trial balance into a free AI chatbot to “save time.” Most of them have never read the terms of service for the tool they are using, and many are violating their confidentiality obligations without realizing it.
The problem is not AI. The problem is treating a consumer chatbot like a locked filing cabinet. This guide maps your existing professional obligations to concrete AI usage rules, so you can capture the efficiency gains while staying on the right side of your standards, your engagement letters, and—in litigation contexts—attorney-client privilege.
Part 1: Your Professional Obligations (Nothing New Here)
AI does not create new confidentiality duties. It creates new ways to violate the ones you already have.
|
Obligation Source |
What It Requires |
How AI Creates Risk |
|
NACVA Professional Standards (confidentiality) |
Member shall not disclose confidential client information without client consent |
Uploading client data to a consumer AI tool may constitute disclosure to a third party |
|
AICPA Code of Professional Conduct (confidential client information rule, ET §1.700) |
Applies to CPA/CVA dual credential holders; no disclosure without specific consent |
Same disclosure risk; consumer AI terms often permit the vendor to use inputs for model training |
|
Engagement letters |
Many contain data handling, subcontractor, and confidentiality clauses |
An AI vendor may qualify as an undisclosed third-party service provider under your own contract |
|
Attorney-client privilege/work product (litigation engagements) |
Privilege can be waived by voluntary disclosure to third parties outside the privilege circle |
Pasting privileged material into a tool that logs, stores, or trains on inputs is arguably a voluntary disclosure |
|
State privacy statutes (varies) |
Protection of personally identifiable information (PII) |
SSNs, account numbers, and health information in source documents flow straight into AI inputs unless stripped or redacted |
|
Court protective orders |
Documents produced under a protective order have explicit handling restrictions |
“Confidential/Attorneys’ Eyes Only” material in an AI tool is a potential order violation, not just an ethics issue |
The one-sentence takeaway: If you could not e-mail the document to an unvetted outside vendor without client consent, you cannot paste it into an unvetted AI tool either.
Part 2: Not All AI Tools Are Equal—The Tier System
The single most important question is not which brand of AI you use, but which tier and under what terms.
|
Tier 1: Consumer/ |
Tier 2: Paid Individual |
Tier 3: Enterprise/ |
Tier 4: Local/ |
|
|
Examples |
Free chatbot accounts |
Pro/Plus subscriptions |
Enterprise plans, business API agreements, zero-data-retention addenda |
Locally run open-source models (e.g., GPT4All, Llama on your own hardware) |
|
Inputs used |
Often yes, by default |
Varies; usually opt-out available; verify it |
Contractually no |
Never; data never leaves your machine |
|
Data |
Indefinite or long-term |
Limited, but logs typically exist |
Contractually limited or zero |
You control it entirely |
|
Admin controls/ |
None |
None |
Yes |
Your own infrastructure |
|
BAA/DPA availability |
No |
No |
Often yes |
N/A |
|
Appropriate for client-identifiable data? |
Never |
No (even with training opt-out, retention and access terms are usually insufficient) |
Yes, with review; read the actual agreement, don’t assume |
Yes |
|
Appropriate for anonymized data? |
Risky; anonymization failures happen |
Acceptable for well-anonymized data |
Yes |
Yes |
|
Appropriate for general research/drafting (no client data)? |
Yes |
Yes |
Yes |
Yes |
Practical rule of thumb: Consumer tools are for learning and generic drafting. Client work belongs on an enterprise agreement you have actually read, or on hardware you control.
Part 3: The Anonymization Table—What to Strip Before You Paste
“Anonymized” means a reader could not re-identify the client. Changing “Smith Plumbing LLC” to “the Company” while leaving in the city, revenue, and industry of a business with three competitors is not anonymization.
|
Data Element |
Risk Level |
Treatment Before Upload |
|
Client/company names |
High |
Replace with generic labels (“the Company,” “Target Co.”) |
|
Individual names (owners, spouses, employees) |
High |
Replace with roles (“Owner A,” “the non-titled spouse”) |
|
SSNs, EINs, account numbers |
Critical |
Remove entirely; never merely relabel |
|
Addresses and specific locations |
High |
Generalize (“a metro area in the Southwest”) |
|
Exact revenue/financials of identifiable small businesses |
Medium-High |
Round or scale by a consistent factor; note the scaling privately |
|
Industry + geography combined |
Medium |
Generalize one or the other for niche businesses |
|
Case captions, docket numbers |
Critical |
Remove; these are trivially searchable |
|
Dates of specific transactions |
Medium |
Shift consistently or generalize to quarter/year |
|
Unique deal terms or contract language |
Medium |
Paraphrase rather than paste verbatim |
|
Medical, criminal, or lifestyle details (dissolution work) |
Critical |
Remove or abstract heavily; these are both sensitive and identifying |
The scaling trick for financial data: Multiply every figure by a consistent random factor (e.g., 1.37) before uploading. Ratios, trends, and anomaly patterns survive; the actual figures do not. Keep the factor in your workpapers, never in the AI conversation.
Part 4: The “Can I Paste This?” Decision Tree
Work through these questions in order. The first “stop” you hit is your answer.
START: I want to put something into an AI tool.
Q1: Does it contain ANY client-identifiable information, PII, or material from a litigation matter?
NO—PASTE FREELY (any tier). Generic prompts, public data, your own templates, published guidance = fair game.
YES ▼
Q2: Is the matter subject to privilege, work product protection, or a protective order?
YES—STOP. Consult engaging counsel before using any external tool. Local/on-premise processing may be the only safe option.
NO ▼
Q3: Am I using an enterprise-tier tool with a reviewed agreement (no training on inputs, defined retention, confidentiality terms)?
NO—STOP. Either anonymize fully per the table above, or do not upload. A training opt-out checkbox is not an agreement.
YES ▼
Q4: Does my engagement letter permit third-party service providers, or has the client consented to AI-assisted work?
NO/UNSURE—PAUSE. Update your engagement letter template and/or obtain written consent. (Do this once; it covers you forever.)
YES ▼
Q5: Even so, have I stripped what does not need to be there? (SSNs, account numbers, third-party names)
YES—PROCEED. Document the tool and tier used in your workpapers.
NO—Strip first, then proceed.
Part 5: Five Habits of the Compliance-Aware AI User
- Read one agreement. Pick your primary AI tool and actually read its data usage terms once. Thirty minutes now beats a disclosure incident later.
- Update your engagement letter template. Add a clause disclosing that AI-assisted tools operating under confidentiality agreements may be used in the engagement. Most clients will not blink; the ones who object are telling you something useful.
- Build an anonymization step into your workflow. Make “strip and scale” a checklist item before any upload, the same way you would redact before producing documents.
- Keep an AI usage log in your workpapers. Tool, tier, date, and nature of data uploaded. If your work is ever challenged in deposition, “I don’t know what I uploaded” is the worst possible answer.
- Default to the more restrictive rule. When NACVA standards, the AICPA Code, your engagement letter, and a protective order all apply, the strictest one governs. When in doubt, treat it as privileged.
The Bottom Line
AI is a leverage tool, not a filing system. Your confidentiality obligations did not change when chatbots arrived; only the number of ways to accidentally breach them did. Match the sensitivity of the data to the tier of the tool, redact like a professional (not like someone doing a find-and-replace on the company name), and document what you did. That is the whole game.
This guide provides general professional guidance, not legal advice. For litigation matters, coordinate AI usage with engaging counsel.
Colin Brown, CTO of Syncnet, helps consultants integrate AI into their practices.
Mr. Brown may be contacted by e-mail to cto@syncnet.com.



