AI Policy for SA Businesses: POPIA Rules and What to Include.
This article will count 0.25 units (15 minutes) of unverifiable CPD. Remember to log these units under your membership profile.
Government's AI Policy died of Its own hallucination. Your practice’s should not. On 10 April 2026, the Department of Communications and Digital Technologies (DCDT) responsible for governing artificial intelligence in South Africa gazetted its Draft National AI Policy. Sixteen days later the Minister withdrew it. A portion of the references were fabricated, most plausibly by the very technology the document was written to govern. A revised draft is expected, and the 2024 National AI Policy Framework still points the direction: risk-based, human oversight, transparency.
Now ask the uncomfortable version of that question. On a Thursday night in your practice, when a junior is trying to finish management accounts before midnight, what is stopping them from pasting a client's trial balance into a free chatbot?
If the answer is "nothing written down", you have the same governance gap the Department of Communications and Digital Technologies had. You just have not been caught yet.
There is no AI law. There is plenty of AI liability.
Waiting for legislation was never the real risk. The duties an AI policy manages already bind you today. POPIA applies the moment client information enters a prompt. Your CIBA Code obligations on competence, due care and confidentiality do not pause because software drafted the first version. Professional negligence does not care which tool made the error.
There is also this: your staff are already using AI. Shadow AI, meaning tools your practice has not approved and does not know about, is the current operating position in most small firms. It runs on personal phones and personal accounts where you have no visibility and no audit trail. As AI Risks Every Accountant Should Understand Before Using It sets out, confident wrong answers are the default failure mode, not the exception.
The laws that already bind you
POPIA is the big one.
Every client file you hold is personal information. Names. ID numbers. Tax numbers. Bank details. Salary histories. POPIA regulates all of it. That means four things the moment you use AI.
You need a lawful reason before client information goes into any AI tool. You cannot paste first and justify later.
You need an operator agreement if the AI vendor processes that information for you.
You need to deal with cross-border rules under section 72, because almost every mainstream AI tool stores data outside South Africa.
You need to think about section 71, which restricts decisions made only by automated processing where they seriously affect a person. That matters the moment AI touches credit assessments, hiring or claims.
There is a fifth risk. If a staff member pastes a client database into a free chatbot, that may be a reportable breach under section 22, and you would have to notify the Regulator.
This is not theoretical. As covered in Two Enforcement Notices, One Message, the Information Regulator has stopped warning and started enforcing. Serious breaches carry penalties up to R10 million.
Then everything else stacks on top. The Copyright Act decides who owns AI-assisted work, and it does not automatically belong to you if a contractor produced it. The Tax Administration Act still expects records showing how you reached a position. The Labour Relations Act turns a properly communicated AI policy into a workplace rule you can enforce. The Employment Equity Act makes AI bias in hiring a discrimination problem, not a technology problem. Your RMCP has to cover AI in client onboarding and screening. And for financial services clients, FSCA and Prudential Authority supervision pulls AI into their existing risk and outsourcing frameworks.
None of this is new law. All of it applies to you today.
What actually goes into the policy
Most practices get this wrong in one of two ways. They write nothing. Or they write a one-line ban that everyone ignores within a fortnight. Banning AI does not work. Staff still use it, just on their own phones and their own accounts where you cannot see any of it. You end up with more risk, not less. A policy that works says yes, with rules attached.
Here are the ten things it needs to cover.
Who and what this applies to
Everyone who touches client work: employees, contractors, temps, outsourced bookkeepers. Define "AI tool" widely, not just ChatGPT and Claude. Include the AI features already switched on inside the software you pay for. Your email. Your practice management system. Your cloud accounting platform. Even your PDF reader.
What may never go into a prompt
This is the most important section. Be specific. Be blunt.
⛔Never: client names attached to financial data, ID numbers, tax numbers, bank details, payroll registers, unpublished financial statements, draft SARS correspondence, anything under a confidentiality undertaking, passwords and logins.
✅Safe: public information, general technical questions, properly anonymised figures, your own internal templates.
Then do the thing most policies skip. Show staff how to redact. "Draft a query letter about VAT input claims" is fine. Pasting the actual VAT201 with the registration number on it is not. People break rules they do not understand far more often than rules they disagree with.
Which tools are allowed
Keep three lists. Approved for client work. Approved for low-risk internal work. Not allowed.
What matters is the account type, not the brand. Free and personal accounts often allow the provider to train on whatever you type in. Business accounts usually let you switch that off. So a tool only belongs on the client work list if it runs on a business account, with training switched off, and with data terms you have read.
Add a route for requesting new tools. Note: if your approval takes three weeks, nobody will ask, they will just use it.
Who is in charge
Name one person, even in a three-person practice. That person keeps the tool list current, approves new tools, handles incidents and reviews the policy. Without a name, you have a document. With a name, you have a control.
Someone must check the work
Nothing AI-assisted goes to a client, SARS, CIPC or a bank until a competent person has reviewed it. The policy should say who may sign and what the review must cover. The reviewer owns the output, not the software.
AI must never finalise a client decision on its own. Not a tax position. Not an independent review conclusion. Not advice. The person who signs carries the work, and "the software said so" has never been a defence.
🛑Remember the AI bias: AI repeats the bias in the data it learned from. Where output touches hiring, staff performance, credit recommendations or client risk ratings, a person must review it critically. Your Employment Equity Act obligations apply to an AI-generated shortlist exactly as they apply to one you wrote yourself.
Check every figure and every reference
This is the DCDT lesson applied to your practice. AI invents section numbers, case names, tax rates and standards. Confidently, and often. Verify everything against the original source before you use it: the Income Tax Act, the VAT Act, SARS Interpretation Notes and Binding Rulings, IFRS for SMEs, the Companies Act. Don’t just check the summary, check the source itself.
Document it in the file
Where AI helped on an engagement, record four things in a clear working paper: the prompt used, the output relied on, how it was checked, and who reviewed it. We make the same point in our earlier article: The AI-Augmented Accountant. Prompts and outputs belong in your working papers, treated like reliance on any other expert. This is also your defence file. If a claim arrives in two years, documented checking is what separates a defensible judgement from an indefensible shortcut.
POPIA and ownership
Write down your lawful reason for each type of processing. List which vendors need operator agreements. Note where data is stored and how cross-border transfer is handled. Flag any use where AI output feeds a decision that seriously affects a person, and require a human in that decision.
Then deal with ownership. State who owns AI-assisted work and back it with contract wording. Employment contracts usually cover staff. Contractors and outsourced teams do not, so you need a written assignment.
What you tell the client
Decide this once, centrally. Do not leave staff to work it out at 4pm on a Friday.
A sensible default: tell the client when they ask, when a contract requires it, and when AI did substantial work on something the client assumed a person had written. Add standing wording to your engagement letter confirming that AI tools may be used, that human review still applies, and that your professional responsibility is unchanged. As The Claim Your PI Insurance Won't Cover explains, the engagement letter defines the duty you owed in the first place. That is the ground your PI cover stands on.
Incidents, training and review
Set up a reporting route and make it blame-free. Confidential data in the wrong tool. A fake citation spotted after the letter went out. A suspected leak. Staff must be able to report these fast without fearing punishment, because speed decides whether a section 22 notification is handled properly or badly.
Train people once, properly. Refresh when tools change. Get a signed acknowledgement from every staff member. Then review the policy every six to twelve months, and immediately if a new type of tool appears, an incident happens, a vendor changes its terms, or the revised National AI Policy lands.
A new service you can offer to clients - AI policy
Every SME client you have is in the same position your practice is. Staff pasting things into chatbots, no inventory, no rules, no idea what their vendor terms say. Almost none of them have a policy. Attorneys will draft the document, and they should for anything complex, at fees currently sitting around R8,500 to R15,000. You are not competing on legal drafting. You are competing on something you already have: you know where the client's data lives, who touches it, and where the compliance pressure points sit. No attorney walks in with that.
We can take construction industry as an example. Those clients run subcontractor databases full of ID numbers and banking details, payroll for teams that change monthly, and tender documents increasingly drafted with AI. A fabricated compliance claim in a bid is not an embarrassment, it is a disqualification. A subcontractor register pasted into a consumer AI tool is a POPIA compromise with a reporting obligation attached.
The service ladder writes itself. An AI use audit as a fixed-fee engagement. Policy drafting and the staff acknowledgement pack. POPIA integration covering the privacy notice, operator register, PAIA manual and breach plan. Then an annual review retainer, because the regulatory position will keep moving.
That is recurring advisory income built on compliance work you already understand. It is also the identity shift that matters: from the person who submits the returns to the person the board calls before they buy the software.
What to do this week
Write down every AI tool anyone in your practice touches, including the AI features already switched on inside your accounting software, your email and your PDF reader.
Draft one page listing what may never go into a prompt. Circulate it. Get it signed.
Check whether your AI accounts are consumer or business tier, and whether training opt-out is enabled. Fix it if not.
Add AI disclosure wording to your engagement letter template.
Pick three clients this month and open the AI policy conversation. Charge for it.
None of that takes a legal budget. All of it is evidence that you governed AI deliberately rather than by accident, and that evidence is what a regulator, an insurer or a client's attorney will ask for. The department that was supposed to write the rules could not verify its own footnotes. Your clients cannot afford the same mistake, and neither can you.
👉 Watch CIBA’s IT Principles and Policies for your business webinar and learn more about the IT policy.
By attending this webinar you will gain the following competencies
You’ll stop running your practice on assumptions: Get clarity on what a proper IT policy actually looks like—and why skipping it puts your entire business and client base at risk.
You’ll have a ready-made policy toolkit: Walk away with templates and real-life examples for acceptable use, password security, remote access, device management, backups, and more.
You’ll protect yourself from SARS audits and data complaints: Avoid the fines, investigations, and finger-pointing that follow poor digital controls—especially around POPIA and independent reviews.
You’ll turn IT governance into a value-add for clients: Most small businesses don’t know how exposed they are. You’ll know exactly how to help them fix it—and charge for the service.
You’ll know how to communicate IT expectations to staff and clients: No more vague rules or crossed wires—just clear, simple policies everyone understands and follows.
You’ll be audit- and review-ready—even for remote teams: With the right IT policies, your review files won’t fall apart when questions are asked about access, records, or security controls.
You’ll add a layer of professional credibility to your offering: Clients trust accountants who take security seriously. By having—and explaining—strong IT governance, you’ll set yourself apart as a trusted, forward-thinking advisor.