Short answer

The file needs to show three things: which step was AI-assisted, who reviewed the output, and what it was verified against. TPB(GS) 55/2026 states that the steps taken when using AI should be documented, and that doing so assists with obligations under sections 30 and 40 of the Determination 2024. A one-line file note per engagement usually satisfies it.

Most firms hear "documentation obligation" and picture a compliance burden. In practice this one is small, provided you design it into the workflow rather than bolting it on afterwards.

Here is what the obligation actually is and what a defensible file looks like.

Which obligations are engaged?

Two sections of the Tax Agent Services (Code of Professional Conduct) Determination 2024.

Section 30, keeping of proper client records. You must keep records that correctly record the tax agent services provided. If part of a service was produced by a tool, the record of that service is incomplete if it does not reflect how it was produced.

Section 40, quality management systems. You must establish and maintain a system of quality management in relation to the provision of tax agent services. Your controls over AI-assisted work live here, and a QMS that exists only in the partners' heads is not maintained in any meaningful sense.

These commenced 1 August 2024, applying from 1 January 2025 for larger firms and 1 July 2025 for smaller ones. Section 35, covering services provided on your behalf, sits alongside them and is worth reading in the same pass.

TPB(GS) 55/2026, published 22 July 2026, connects AI use to both. The guidance's position is that the steps taken should be documented, and that documenting them assists in meeting sections 30 and 40.

What does a defensible file actually contain?

Six artefacts. Most firms already produce four of them.

ArtefactWhere it usually livesAlready have it?
Source documents as receivedDocument management systemYes
The work product (workpaper, return, letter)Practice management or DMSYes
Evidence the output was reviewed by a qualified personSign-off in workflowUsually
What the output was verified againstWorkpaper referencesUsually
Which step was AI-assisted, and by which toolOften missingNo
The firm's approved-tool and review policy in force at the timeOften missingNo

The last two are the gap. Neither is difficult.

What is the minimum viable record?

A single line on the engagement file. Something in the shape of:

Workpapers prepared with [tool] from client-supplied source documents. All extracted figures agreed to source by [initials] on [date]. Technical treatment of [item] verified against [reference].

That is it. It names the tool, names the reviewer, and names what the verification was against. Under a minute to complete if it is a template field rather than free text.

What we would avoid is the opposite failure mode: a firm that logs every prompt and response into the file. It creates volume without adding assurance, and nobody reviews it. The obligation is to record the service accurately, not to produce a transcript.

A worked example: an individual return workpaper

Take a workflow where a tool reads client source documents and populates a workpaper template.

What the file shows without any AI-specific documentation: source documents in, completed workpaper out, preparer and reviewer sign-off. A reviewer looking at this cannot tell how the figures got from one to the other.

What it needs to add:

  1. The tool used and the step it performed. "Workpaper populated by [tool] from uploaded source documents."
  2. The verification. Not "reviewed", but what against. "All figures agreed to source documents. Interest income agreed to ATO pre-fill."
  3. Any exception. If the tool got something wrong and it was corrected, say so. This is the entry that most protects you, because it evidences that the review is real.
  4. The reviewer and date.

Why the exceptions matter

A file where the AI-assisted output was accepted without a single amendment, every time, across every engagement, invites the question of whether the review is happening. Recording corrections is evidence of control, not evidence of failure.

For the workflow side of this, see how to automate compliance workflows in an Australian accounting firm.

How does this interact with supervision?

Section 35 requires that tax agent services provided on your behalf are provided competently, and section 40 requires quality management. TPB(GS) 53/2024 covers both in detail.

The supervision question that AI raises is not new, but it is sharper. When a graduate prepares a workpaper, the reviewer knows roughly where errors cluster and reviews accordingly. When a tool prepares it, the error profile is different. Tools tend to be highly consistent on structured data and to fail in unfamiliar ways on edge cases, which means a review calibrated to human error patterns will miss things.

Practically, this means your review procedure for AI-assisted work should be written down separately rather than assumed to be the same as your existing one. What gets checked, by whom, against what. That document is part of your QMS and part of what a reviewer would expect to see.

How long do you need to keep this?

Your existing record retention periods apply. AI involvement does not change how long a client record must be kept, and it does not create a separate retention class.

One thing worth noting: if you use a tool where the vendor retains inputs and outputs on their systems, that is their retention, not yours. It does not discharge your obligation to keep proper client records, and you should not rely on being able to retrieve anything from a vendor after termination. Keep your own copy of the work product in your own systems.

The vendor questions that matter here are covered in our AI use policy template.

What would a TPB reviewer look for?

We are not the regulator and this is not a prediction of TPB behaviour. But the obligations point in an obvious direction.

Given a sample of engagements, a reviewer would reasonably want to see that the service was recorded correctly under section 30, that a quality management system exists and operates under section 40, that someone competent reviewed the output, and that client information was handled consistently with Code item 6 and any permission on file.

The firms that would struggle are not the ones using AI heavily. They are the ones where AI use is real but undocumented, so the file shows a work product with no visible route from source to output and no policy explaining how it should have happened.

The practical takeaway

Add two fields to your existing engagement checklist: tool used, and verified against. Write down your AI review procedure as a page in your quality management documentation. That is the substance of it.

The obligation is proportionate. What creates exposure is not AI use, it is AI use that nobody decided on and nobody recorded.

If you want a view of where AI would actually reduce time in your practice and what the file needs to look like around it, our automation audit covers both.

Frequently asked questions

No. The obligation is to keep records that correctly record the service provided. A file note naming the tool, the reviewer and the verification basis meets that. Prompt-level logging adds volume without assurance.
No. It is a firm record, not a client-facing disclosure. Separately, you do need the client's permission before disclosing their information to a third party such as an AI vendor.
The obligations still apply, but the practical documentation is lighter. Recording your platform stack and its AI features once in your QMS is usually sufficient, rather than a note on every engagement.
Your existing client record retention periods apply. AI does not create a separate class.
Yes. Sections 30, 35 and 40 of the Determination apply to registered tax agents and BAS agents.
Record it. An exception log is evidence that your review control operates. A file with zero corrections across every engagement raises more questions than one with a few.

Related reading: what TPB(GS) 55/2026 means for your firm and our AI use policy template.

Sources: Tax Agent Services (Code of Professional Conduct) Determination 2024, sections 30, 35 and 40; TPB(GS) 55/2026; TPB(GS) 53/2024 Supervision, competency and quality management; TPB(GS) 52/2024.

General information only, not legal advice.