The AI audit — 12 questions to find your firm's actual exposure
The point isn't to catch anyone. The point is to know what's actually happening before the OAIC asks.
Published 26 July 2026
Every firm we speak with begins the conversation the same way: “we have a policy that says staff shouldn’t use AI with client information, but honestly we’re not sure what’s really going on.”
That gap between policy and reality is where AI risk actually lives. Closing it does not require sophisticated tools or an external audit; it requires a set of specific questions asked in the right order, without consequences attached to the answers.
This is that list. Work through it once and you will know more than 90% of firms know about their own AI exposure.
Setting the tone
Before running the questions, one framing point matters. If staff believe answering honestly will result in disciplinary action, they will not answer honestly. You will get plausible answers that make the numbers look better and change nothing.
The right frame is:
“We are trying to work out what to sanction. Nobody is in trouble for telling us what they’ve been doing. We need the real picture, not the neat picture.”
This is true, and it works. Most staff want to use AI safely and are quietly worried about doing it wrong. Give them a genuine amnesty and they will tell you.
The 12 questions
1. Which AI services do we know staff are using?
Not the ones you have licences for — the ones staff are actually using. Ask openly. The list is usually longer than expected. Common entries include ChatGPT (free and paid), Claude, Google Gemini, Microsoft Copilot (personal and enterprise), Otter, Fireflies, Perplexity, Grammarly, and any number of vertical tools.
2. Are they using them on firm devices or personal devices?
This is the single most important distinction and the one most audits skip. Personal-device use is invisible to your infrastructure, cannot be centrally logged, and is where the majority of your unmanaged risk sits.
3. Are they using firm accounts or personal accounts?
Even where the service is sanctioned, a staff member logging into their personal ChatGPT account rather than the firm’s enterprise tenancy means the safeguards you paid for do not apply. This is common; ask.
4. What kinds of documents have they used AI with?
Categories, not specifics. Client correspondence? Matter files? Patient notes? Financial statements? Contracts? Discovery bundles? HR files? Board papers? Get a rough distribution — you are trying to understand the shape of exposure, not build a case.
5. In the last month, has any staff member pasted a document identifying a client, patient or counterparty into an AI service?
This yes/no question, asked with genuine amnesty, tells you more than any policy audit. In most firms the answer is yes, and it has happened more than the person answering realises.
6. Do we have an AI note-taking tool joining our meetings?
Otter, Fireflies, Read, Fathom and their peers are widely used on personal accounts by individual staff. If a meeting bot has appeared in your Zoom or Teams rooms, someone signed it in — and the transcript went somewhere.
7. What happens to the AI-generated output?
Is it filed to the matter/patient file? Sent to a client? Circulated internally? Discarded? The output is where the accuracy responsibility becomes concrete — an AI-generated file note that nobody reviewed is a professional liability regardless of privacy compliance.
8. What does our AI policy actually say, and when was it last updated?
Read it. Actually read it, not the summary. If it says “staff must not use unapproved AI tools with confidential material” and there is no list of approved tools, the policy is unactionable.
9. When did we last audit AI usage?
If the answer is “never” or “when the policy was written”, you have not audited it. The point of the audit is not to establish policy exists; it is to establish what is happening.
10. Do we have contractual obligations that specifically restrict AI use?
Some client contracts explicitly restrict processing to nominated jurisdictions or prohibit third-party disclosure. Government contracts, defence contracts, some international commercial arrangements, and some large corporate client agreements now include AI clauses. Check the ones you know are large or sensitive.
11. If we had to notify a client tomorrow that their material had been in an AI service, could we tell them what was disclosed?
The question that decides your NDB exposure. If the honest answer is no, that is your gap. It stays a gap until either (a) the disclosure never happens, or (b) the disclosure happens through a system that logs it.
12. What would we do about it if we found out something had happened?
Have the plan before you need it. See our AI incident response article for a starting point. If your plan is “we’d have to work it out”, now is the time to work it out.
What to do with the answers
Once you have run the audit, the picture usually falls into one of three categories.
Low exposure
A small team, mostly using AI for non-client tasks, on approved accounts, with a clear policy and a sanctioned tool that people actually use. You are in good shape. Rerun the audit annually.
Medium exposure
Some client work is touching AI, mostly on the enterprise account but with some personal-account leakage, no serious incidents. The response is (a) make the sanctioned tool easier to reach so personal accounts stop being tempting, (b) tighten the policy on client-facing work specifically, and (c) commit to running the audit twice a year.
High exposure
Significant client-facing AI use, on mixed accounts and devices, without central visibility, and with no reliable way to answer question 11. The response is architectural — either substantially better governance of the enterprise cloud AI, or on-premise for the confidential-material use case, or (usually) both. Continuing to run the same setup that produced this audit will produce another audit like it.
The one thing not to do
Do not run this audit and then not do anything.
The audit produces institutional knowledge. Once the firm knows there is a problem, doing nothing about it is a materially worse position than not having asked — it establishes that the firm was on notice and elected not to act. If an incident later occurs, that is a much harder conversation with a client, an insurer or a regulator than “we did not realise this was happening”.
Run the audit when you are ready to act on what it tells you. Then act.
This article is general information about common obligations under Australian privacy and professional conduct rules. It is not legal, medical or financial advice and does not account for your circumstances. Obtain your own advice before acting on it.