CPA Ontario’s position is direct: the CPA Code of Professional Conduct applies to AI exactly as it applies to any other tool. The CPA holds sole responsibility for the quality of the work performed, regardless of the technology used to produce it.
That’s not an opinion. That’s a direct quote from CPA Ontario’s regulatory guidance, published August 2024 and reinforced in December 2025. There is no carve-out for AI. There is no “the software made the error” defence. If it goes out under your name, it’s yours.
This post explains what that accountability means in practice: what CPA Ontario expects your firm to have in place, what Canadian courts have said when professionals didn’t verify AI output, what errors are already showing up in client files, and where client data actually goes when your staff uses an AI tool.
Why CPA Firms Are Asking About AI Right Now
AI adoption in the professional services sector has moved quickly. According to the Thomson Reuters Institute’s 2025 Generative AI in Professional Services Report, 22% of professional services organizations are actively using generative AI, nearly double the 12% adoption rate recorded in 2024. About half of all professionals across legal, tax, accounting, and audit sectors say they use GenAI in some form. A further 50% say their organizations are either creating plans to use it or actively deciding whether to do so.
The governance hasn’t kept pace. The same report found that 52% of organizations have no GenAI policy, whether standalone or as part of a broader technology policy. Only about one-third of professionals reported receiving any GenAI training at their organization.
The more immediate concern is what tools people are using day-to-day. Forty-one per cent of professionals surveyed personally use publicly available tools such as ChatGPT for work. Not enterprise-licensed, privacy-configured environments. Consumer tools, with client data.
CPA Ontario noticed. Its 2025 Annual Report confirms the organization added AI-specific questions to the Practice Profile Questionnaire sent to firms. Not having a policy is now a documented gap in your regulatory profile.
What CPA Ontario’s Guidance Actually Says
CPA Ontario has published two substantive regulatory documents on AI: Accountabilities for CPAs in the Age of Artificial Intelligence (August 2024) and No Algorithm for Ethics: AI and Regulatory Guidance (December 2025). Both are available on the CPA Ontario website and worth reading in full.
The core position is simple: the professional standards that govern how you use any software also govern how you use AI. No exceptions.
Beyond that, CPA Ontario identifies five questions every firm needs to be able to answer:
- Governance and policy: Do you have a written policy on the ethical use of generative AI, with clear accountability for who oversees it?
- Risk identification: Has your firm identified the specific risks of the AI tools you use, including hallucinations, data bias, and cybersecurity exposure?
- Privacy and legal compliance: Do you understand how existing Canadian privacy law applies to your firm’s AI use? (Note: CPA Ontario’s August 2024 guidance also referenced Bill C-27, the proposed federal AI and data legislation. That bill did not pass before Parliament prorogued in early 2025. PIPEDA and provincial privacy legislation remain the governing framework.)
- Internal capacity: Do you have the technical expertise in-house to support governance, or have you engaged someone who does?
- Third-party products: Have you verified that AI tools you purchase or subscribe to meet legal, regulatory, and governance requirements?
The guidance closes with a sentence worth keeping: “There is no algorithm for ethics, professional standards or good governance.”
CPA Ontario’s December 2025 guidance adds specific documentation requirements for assurance engagements. Where AI has been used, engagement files should include a clear description of the tool’s capabilities and limitations, an evaluation of data sources and potential biases, confirmation that algorithms are based on accurate and current information, and validation of outputs against results obtained through traditional methods.
That last point matters. Documenting that you used AI is not the same as documenting that you verified what it produced.
What Happens When Professionals Don’t Verify AI Output
Two Ontario cases from the past year illustrate exactly what is at stake for professionals who file AI-generated work without checking it.
Ko v. Li, 2025 ONSC 2965 (Ontario Superior Court, May 2025)
A Toronto lawyer’s factum contained three case citations that did not exist. They were ChatGPT hallucinations. Justice Fred Myers noticed the links were broken and the cases could not be found on CanLII, Westlaw, or Google. The lawyer was ordered to show cause why she should not be held in contempt of court.
She admitted the error, apologized, and proposed corrective steps before the hearing. The contempt proceeding was dismissed on conditions: a minimum of six hours of CPD in legal ethics and technology, and she could not bill the client for any of the defective work.
Justice Myers noted: “There had to be someone who was going to be the first lawyer to file AI hallucinations here.”
Mazaheri v. Law Society of Ontario, 2026 ONLSTH 112 (Law Society Tribunal, June 12, 2026)
A lawyer whose licence was under suspension used Grok to prepare motion materials before the Law Society Tribunal. Those materials contained citations to cases that do not exist and real cases cited for propositions they do not support. He admitted he used AI and did not check the output before filing.
The Tribunal described the conduct as “irresponsible” and treated it as a significantly aggravating factor. Costs were awarded in full: $31,150 to the Law Society of Ontario.
Both decisions involved lawyers, not accountants. But the professional accountability principle is identical. The tool doesn’t carry the liability. The professional does. The CRA does not accept “the AI calculated it” as an explanation for an incorrect filing.
The Errors Already in Your Clients’ Files
In January 2026, Dext and Censuswide published results from a survey of 500 Canadian accountants and bookkeepers conducted in December 2025. The findings are specific and worth reading carefully.
Only 7% of respondents said they had never encountered a public AI-driven error in client work. Eleven per cent encounter them daily. Twenty-nine per cent encounter them weekly.

Half of respondents are aware of businesses that have suffered direct financial losses from acting on incorrect AI-generated advice, including overpayments, missed tax allowances, penalties, and compliance failures.
The survey also found that 70% of accountants have seen clients use AI-generated outputs to challenge professional advice, and 68% have seen clients suggest AI could replace the need for professional accounting services. That is not just an error problem. It is a scope and authority problem. The firms that have clear, documented positions on what AI can and cannot do will handle those conversations more effectively than those that don’t.
Where Client Data Goes When Your Staff Uses an AI Tool
This is the question most CPA firms are actually asking, and the answer depends entirely on which tool is being used and how it is configured.
Consumer ChatGPT (free or personal tier): Data entered may be used for model improvement under OpenAI’s default terms unless the user has opted out. Under PIPEDA’s safeguards and limiting-collection principles, and under CPA Ontario’s confidentiality obligations, entering client data into a public consumer tool under these conditions is a compliance problem. A breach of client confidentiality can simultaneously trigger a CPA professional conduct matter and a PIPEDA obligation. Under PIPEDA, organizations must report breaches to the Office of the Privacy Commissioner and notify affected individuals when the breach creates a real risk of significant harm. Records must be kept for all breaches regardless of harm level. Both obligations are addressed independently of any professional conduct process.
ChatGPT Enterprise or API: For Enterprise plans and API access, OpenAI’s default terms do not use business data for model training. That is a meaningfully different arrangement than the consumer tier, but it still requires verification of your specific contract terms and a review of where data is processed. “Enterprise” is not a privacy guarantee on its own.
Microsoft 365 Copilot, properly licensed and configured: Microsoft’s Copilot privacy documentation confirms that prompts, responses, and Microsoft Graph data are not used to train foundation models. However, “tenant” refers to your organization’s Microsoft environment, not necessarily a Canadian data centre. Physical data residency in Canada depends on your tenant’s geographic configuration and your subscription type. It still requires correct configuration, appropriate licensing, and a review of the vendor data processing agreement.
The governing principle is straightforward: every cloud platform, AI tool, or third-party service that touches client data needs a written contract with explicit privacy and security obligations. PIPEDA’s safeguard and limiting-collection principles both apply. Quebec firms have additional obligations under Law 25. And if you use an IT advisory partner to evaluate your tool stack, confirm they understand Canadian privacy law, not just vendor marketing materials.

What a Governed AI Approach Looks Like for a CPA Firm
This does not need to be complicated. For a firm in the 15 to 250 employee range, a governed AI approach comes down to six actions:
- Name someone accountable. Designate a person in the firm responsible for AI governance. It doesn’t have to be a dedicated role. It does have to be a named person with authority to set and enforce policy.
- Audit what tools are in use. Find out what your staff are actually using, including tools built into existing software, browser extensions, and personal subscriptions used for work. If consumer-grade tools are touching client data, that stops now.
- Write a use policy. Cover: which tools are permitted, which are not, what client data may never be entered into any AI tool, what verification is required before any AI-generated output goes to a client or regulator, and what the consequences are for non-compliance.
- Require verification of every AI output. This is CPA Ontario’s explicit expectation. Document that the verification happened.
- Document AI use in engagement files. Where AI materially contributed to work product, note which tool was used, what it produced, and how you validated it.
- Review vendor contracts. AI features have been added to many practice management, tax preparation, and document tools without firms noticing. Review the data processing terms for every subscription that may now include AI. If there is no contract, get one before those tools touch client data. Our cybersecurity team regularly identifies ungoverned AI features inside tools firms already use.
CPA Ontario’s 2025 Annual Report is explicit: firms are being asked about AI governance in the Practice Profile Questionnaire. “We don’t have a policy yet” is an answer, but it’s not a comfortable one to give a regulator.
What CPA Ontario Actually Requires: The Short Version
AI is not off-limits for CPA firms. CPA Ontario is not telling its members to avoid the technology. It is telling them that professional accountability doesn’t pause when you use a new tool, and the CPA Code applies regardless of what produced the output.
The firms that handle this well are not the ones waiting to see what happens. They’re the ones with a written policy, that know what tools their staff are using, have reviewed their vendor contracts, and can demonstrate to a regulator or a client that they approached this deliberately.
That is not a high bar. But right now, it is a bar that most firms haven’t cleared.
Not sure where your firm stands? ITS Canada works with CPA firms and professional services organizations to assess how AI is being used across their operations, identify data handling risks, and build the governance framework your team actually needs. We’re an independent advisor, so the recommendation is based on what’s right for your firm, not what we sell.

