My AML program is no longer just a document. It is becoming part of how my practice operates.
Like many tax practitioners, I have spent a significant amount of time developing an AML program for my practice.
It sets out our risk assessment, client due diligence procedures, internal policies and the forms we need to complete when providing designated services.
Once I had finished it, I asked myself a fairly obvious question:
How often am I actually going to open this document?
Probably not very often.
That is the problem with many compliance manuals. We put considerable effort into developing them, but once they are finished, they can easily become documents we only revisit when something goes wrong, an obligation changes or we need to demonstrate that a process exists.
I wanted to see whether I could make mine more useful in the day-to-day operation of the practice.
Turning the program into a working system
Over the past few weeks, I have been building a private AI Chief of Staff for my practice.
It runs on my own VPS, connects with my Microsoft 365 environment and includes several specialist agents responsible for different areas of the practice.
One of them is a Compliance Manager.
I have given the agent access to my firm’s AML program and instructed it to help me follow the procedures contained in that program.
It does not make compliance decisions for me, and it does not replace my professional judgement. Its role is much more practical: help me work out which procedures apply, locate the correct templates and prepare the documentation for my review.
A recent example
I recently met with a new client who wanted assistance with two matters:
- preparing and lodging an income tax return; and
- changing from a sole trader structure to a company structure.
The tax return itself did not trigger the AML process. However, assistance with establishing the company was a designated service covered by my firm’s AML program.
Normally, I would need to open the program, confirm which procedures applied, locate the relevant templates and start preparing the documents.
Instead, I sent a WhatsApp message to my Compliance Manager:
“I’ve onboarded a new client. They require a tax return and assistance setting up a company structure. Please prepare the required AML compliance documents for my review.”
The agent reviewed my AML program, identified the procedures that applied and prepared the relevant documents using the firm’s approved templates.
It then saved the draft documents into the client’s folder in OneDrive, ready for me to review.
I then reviewed the documents, made the necessary changes, completed the information that required my input and arranged for the client to sign them.
The agent did not communicate with the client or send anything automatically. Every document remained subject to my review and approval, and professional responsibility remained with me.
Privacy and confidentiality
Whenever AI is discussed in a professional practice, one of the first questions should be:
What information is being given to the AI?
In this case, I deliberately did not provide the client’s Tax File Number, date of birth, identity documents or other sensitive personal information.
The agent did not need that information to identify the relevant AML procedure. It only needed to know that a new client required assistance establishing a company structure.
Its role was to interpret my firm’s process and prepare the required documentation using approved templates. Sensitive client information, identity verification and professional judgement remained outside that task.
Of course, hosting an AI system privately does not remove the need for proper security, access controls, data protection and human oversight. Those issues still need to be considered as part of the design of the system.
For me, responsible use of AI means applying the same care to technology that I apply to every other part of the practice.
What I found most useful
The main benefit was not the time saved preparing a few forms.
It was seeing the AML program used as part of an actual workflow.
Rather than opening a lengthy document and working through it from the beginning, I could describe the client engagement and ask:
“Based on our AML program, what do I need to do next?”
The system could then guide me through the process that I had already designed.
That is what made the experiment useful. The AI was not inventing the compliance process. It was helping me apply my own process more consistently.
The broader opportunity
Most accounting and professional practices already have a large amount of valuable internal knowledge contained in:
- compliance manuals;
- client onboarding procedures;
- engagement processes;
- quality management systems;
- checklists; and
- internal policies.
The challenge is that these documents are usually passive.
We prepare them, save them and then depend heavily on people remembering when and how to use them.
I think one of the more practical uses of AI in a professional practice is helping turn that existing knowledge into working processes.
Not by replacing professional judgement, but by helping practitioners apply their own procedures more consistently.
Where I am heading
This is still an experiment, and I am building it one workflow at a time.
I started with AML because it is a structured process with clear procedures, decision points and documentation requirements.
Over time, the same approach could potentially assist with client onboarding, engagement management, tax return workflows and other administrative processes within the practice.
The aim is not to automate professional judgement.
It is to make the practice more organised, more consistent and easier to manage, while maintaining the privacy, oversight and professional standards that clients should expect.
I am not trying to build an “AI practice”.
I am trying to build a better professional practice and use AI only where it adds genuine value.