Accounting AI: is it safe inside a SARS practice?
Accounting AI is safe in a South African practice when it stays read-only, keeps off eFiling, and a person signs off every output. The five guardrails.
Ty Panaino is the founder of C-Suite Holdings (Pty) Ltd. Since 2017 he has built paid-acquisition, lifecycle, and AI-engineering systems for South African and offshore clients, and now runs C-Suite, two managed tax engines for South African accounting practices.
Accounting AI is safe in a South African tax practice when three limits hold: the system works read-only on the tools the firm already runs, it never touches SARS eFiling, and a person at the practice approves every output before it reaches a client or a return. A partner weighing up AI for an accounting firm in South Africa is weighing up whether those limits are real and checkable, so this page starts from what unsafe actually looks like, sets out the five guardrails that block it, covers where POPIA and the SAICA Code sit, and ends with a way to test everything on five clients before the wider book is involved.
What makes accounting AI safe to run in a tax practice?
Start from the failures, because every guardrail below exists to block a specific one. Write access lets a system post a wrong entry, or submit a wrong return, at volume, and volume is what turns a software error into a book-wide incident. When a tool messages clients under its own name, your clients learn to trust a third party instead of the firm. Without an attributed log, the practice cannot answer SARS or the professional-indemnity insurer when they ask who did what and when. And a provider that trains models on client data has repurposed information that was shared for one engagement. Each failure has a matching, checkable guardrail:
- No write access to eFiling. The permission scopes granted to the system show the limit. It reads what it needs, and it cannot file, pay, or change anything on the SARS side. Your team files.
- Sign-off that cannot be switched off. Nothing reaches a client and nothing is filed until someone at the practice approves it, and that approval is on by default rather than an optional setting a busy season quietly disables.
- A full, exportable audit log. Every action is recorded and attributed, so when SARS or the professional-indemnity insurer asks who did what and when, the answer is an export rather than a reconstruction from memory.
- Work done in the practice's name. The system runs on the firm's existing tools and every message goes out under the firm's identity, so a client sees their own accountant being fast.
- The practitioner of record unchanged. Professional judgement and the SARS relationship stay with the registered practitioner, and the system carries the operational load underneath.
The five lines work as a vendor checklist for any provider, C-Suite included: ask where each limit is enforced, and be wary of an answer that rests on a policy document rather than a permission scope, because a scope holds under pressure and a policy depends on people remembering it in the busiest week of the year.
Where do POPIA and the SAICA Code come in?
POPIA treats a provider working on client records as an operator, so a written operator agreement under section 20 and section 21 comes before any data moves, and the section 19 safeguards have to be documented, current, and real. Purpose limitation does the quiet work here: client information is used for the engagement it was shared for, it stays hosted in South Africa, and it is never used to train a model.
The SAICA Code of Professional Conduct adds the professional layer on top. Confidentiality, professional competence and due care stay with the member whatever tooling the practice runs, which is one more reason the approval step stays human. The operational mechanics, including what the operator agreement covers when documents are chased at month end, are walked through in the POPIA document-chase piece.
Can accounting AI touch SARS eFiling?
No, and a practice should treat that as a hard boundary rather than a product preference. Filing rights on eFiling belong to the registered practitioner, and a system that could submit a return could also submit a wrong one at volume, which is a category of risk no audit log repairs after the fact. Read access is a different matter: statuses, correspondence and assessment notices are exactly the inputs preparation work needs. The full boundary, including what AI can carry right up to the point of filing, is mapped in AI and SARS eFiling: what it can and can't do.
What should AI do in a practice, and what stays with the practice?
AI earns its place on volume work with a clear right answer: chasing outstanding documents, reading and naming what comes back, sorting each file against the right client and return, and flagging what is missing or inconsistent. That work has an unambiguous done-state, it takes up senior hours in season, and every step of it can be checked afterwards.
Judgement stays with the practice. The accept-or-override call on an auto assessment, the conversation that carries advice, the SARS relationship, and the filing itself belong to a person whose name is on the return. When a vendor demos a feature, the dividing question is which of those two lists the feature sits on, and who approves anything that moves from the first list toward the second.
Each of the workflows on that boundary carries a number that prices its risk, and the numbers measure different things: an error rate, a penalty rate, a fine ceiling, and a statutory deadline.
| Workflow | The number in play | What it measures | Where the line sits |
|---|---|---|---|
| End-to-end preparation of an ITR12 or VAT201 | About 5-10% | How often AI gets an end-to-end return calculation wrong | AI drafts and flags, and a person owns the calculation and the return |
| The IRP6 provisional estimate | 20% of the shortfall | The paragraph 20 penalty on a serious underestimation | The estimate decision stays with the registered practitioner |
| Document chase and intake | R10 million | The ceiling on POPIA administrative fines | The chase runs read-only under a written operator agreement |
| A SARS verification letter | 21 business days | The window to submit supporting documents | AI collates and sorts the pack, and a person reviews and submits it |
How the same split runs across the rest of a practice's workflows is mapped on AI for accounting.
How do you pilot accounting AI without exposing the whole book?
Run it on five clients for one week, and pick the five deliberately: two single-employer PAYE files where the right answer is obvious, one client with rental or trade income where documents scatter, one company with a live VAT cycle, and one file the firm knows is messy. During the week, watch three things: the approval queue (does anything try to move without sign-off), the audit log (can you reconstruct the week from it), and the hours the senior on those five clients got back.
At the end there is a real before-and-after on the firm's own data, and the decision about the wider book is grounded in something observed rather than promised. C-Suite runs this as a free one-week pilot during filing season itself.
Frequently asked questions
Is AI allowed under the SAICA Code of Professional Conduct? The Code prohibits no class of tool. It holds the member to confidentiality, professional competence and due care regardless of what runs underneath, so the practical question is whether the practice can show who approved each output and where client information went. An exportable audit log and a signed operator agreement answer both.
Does POPIA allow an AI system to process client personal information? Yes, as an operator under a written agreement per sections 20 and 21 of POPIA, with section 19 safeguards in place and processing limited to the purpose the information was collected for. A provider that cannot produce the agreement, name where data is hosted, or state its retention rule has answered the question already.
Can accounting AI file a return on SARS eFiling? No. A safe system holds no filing rights, and the corrected or original return is submitted by the practitioner through the firm's own eFiling profile. AI's contribution ends at a prepared, checked, human-approved file.
What access does an accounting AI system actually need? Read access to the ledger or practice-management system, plus the mailbox or document store where client paperwork arrives, granted through permission scopes the firm controls and can revoke. Nothing on that list requires write access to accounting records or to eFiling.
Where to go next
The eFiling boundary in full detail is in AI and SARS eFiling: what it can and can't do, and the POPIA mechanics are in chasing month-end documents without breaking POPIA.