BeforeMay docs
Security, data & AI

AI processing and human review

What the Workpapers AI flow receives, how identifiers are handled and what a delivery gate can prove.

Source reviewed Security and privacy documentation

Workpapers uses AI to help read, classify, assemble and review working papers. The accountant remains responsible for the figures and treatment they rely on. The system's review and delivery steps do not lodge a return or replace the practice's professional judgement.

Inputs and provider choices

Processing can include recognised document text, processed source files, filenames and case context such as financial year and taxpayer name. Provider and model choices are configured per stage. The Privacy Policy names providers and processing countries; ask which apply to your practice rather than relying on a fixed model name in a guide.

The policy states that client documents and extracted financial information are not used to train our own or providers' general AI models. Provider retention is a separate issue; see retention.

Identifier controls

MaterialControl and limits
TFN, Medicare, passport and licence valuesIdentified values are removed or substituted in outbound material; the gate stops on unsafe or unreadable input rather than sending the original as fallback.
Recognised textAdditional bank, email, phone and recognised crypto identifiers are coded or substituted according to the text policy.
Source filesEmail and recognised crypto identifiers join the sensitive-identifier controls. Bank details and phone values are not removed by the same file policy.
Names, addresses and financial factsCan remain because the working paper needs the client's context and evidence.

This is redaction and pseudonymisation, not anonymisation. Detector coverage, file type, layout and context affect which values are identified. Do not assume that every personal identifier is removed. The original client record and source document can still contain the information the firm needs. TFN storage on a client record is different from TFN extraction or outbound AI processing. Request scoped coverage and failure evidence for a technical assessment.

Verify's direct identity capture is a separate flow, described in data flow.

Draft, review and delivery

A build produces a draft, which can be inspected read-only while review is running or after some failures. A visible draft is not a delivered working paper. When enabled, independent review and repair examine the draft before output. Independent review can be deselected in the offered preparation choices. The current delivery policy can release a rendered paper with remaining findings; not every validation failure blocks delivery. Some failures hold or refuse the run. Request current review configuration and delivery evidence if the review process or provider independence is part of your assessment.

Checks address supported formula integrity, totals, breakdowns and workbook presentation. Passing them does not prove that every source document was complete, every judgement correct or every accounting/tax issue covered. A formula can correctly sum the wrong inputs.

Your review

Check the client and year, source amounts, material treatment decisions, missing evidence and findings. Answer questions with the underlying evidence in mind. Review changed output after an update. Use the source-tracing tutorial and keep the version you reviewed.

Review outstanding findings on delivered output. If the system refuses a document or holds the run, resolve the cause or inspect the evidence manually. Do not treat a skipped review, failed draft or unresolved finding as a completed human check. With AI auto-answer enabled for the run, inspect the recorded answers after preparation; this option removes an immediate human checkpoint.

On this page