On this page
- 01Purpose and status
- 02Responsibilities
- 03Client authority and notice
- 04Minimum information
- 05Prohibited and restricted information
- 06Transfer and access
- 07Permitted AI assistance
- 08AI controls
- 09AI uses that are not permitted
- 10Client choice and opt-out
- 11Retention and deletion
- 12Incidents and individual requests
- 13Providers and overseas processing
- 14Review and contact
Purpose and status
This Client Data and AI Schedule sets the minimum rules for client information used during a Seamless AML engagement. It applies when it is referred to in a proposal, engagement letter or other accepted engagement document.
If this Schedule conflicts with the engagement letter, the engagement letter takes priority for that engagement. A law, regulator direction or court order takes priority over both.
Responsibilities
- Client
- Decides what information is supplied, keeps the original statutory records, controls its nominated users and remains responsible for its legal duties.
- Seamless AML
- Uses information only for the accepted work, protects the copies it holds, keeps a suitable work record and returns or deletes material under this Schedule.
- Both parties
- Must act promptly on access changes, suspected breaches, legal restrictions and requests from an individual or regulator.
Each party is responsible for the personal information it holds. A party may also be treated as holding information processed by a service provider acting on its behalf.
Minimum information
Only information reasonably needed for the agreed scope should be supplied. Before transfer, the client should remove unrelated documents, blank pages, duplicate files, account passwords, authentication codes and information outside the sample or period requested.
- Registers and client lists should use internal identifiers where names are not needed.
- Identity documents should be limited to the selected test sample and should not be supplied if a result or verification record is enough.
- Transaction data should be limited to the fields and period needed for the test.
- Health, criminal, biometric and other highly sensitive information should be removed unless its review is necessary and agreed.
- The client should tell Seamless AML if a document contains legal privilege or a special secrecy restriction.
Prohibited and restricted information
SAR and SMR information must never be sent to an AI provider. It must not be placed in a public form, ordinary email or an unrestricted shared link.
Transfer and access
Client evidence should be transferred through the client's dedicated Dropbox folder or another method agreed in writing. Public enquiry forms are not approved transfer channels for client records.
- Casey Marsh has direct access to the main client-data Dropbox.
- A client folder is shared only with client users nominated for that engagement.
- The client must tell Seamless AML when a user should be added or removed.
- Multi-factor authentication should be used for accounts with access.
- Links must not be forwarded and files must not be copied to personal accounts.
- A specialist may receive only the minimum information needed, under confidentiality terms and with identifiers removed where practical.
Permitted AI assistance
Subject to this Schedule, an approved AI system may assist with:
- researching legislation, rules and regulator materials
- drafting and structuring working material and deliverables
- checking references, consistency and missing cross-references
- comparing working papers with source documents
- suggesting possible risk ratings, findings or wording for human review
- designing a sample-selection method without receiving an identifiable client list
These uses support the work. They do not transfer professional responsibility to the AI provider.
AI controls
Before client information is used with AI:
- the use must be needed for the accepted scope
- a suitable business or API service must have been approved after privacy, security and contract checks
- the provider's training, retention, location, access and subprocessors must be understood
- personal and confidential information must be removed or reduced where practical
- the input must exclude identity documents, authentication data, full raw CDD files, SARs and SMRs
- the output must be checked against the source evidence and law by a suitable person
- the material use of AI and the human check must be recorded in the work file
Personal or sensitive client information is not authorised for consumer ChatGPT, Claude or another consumer AI account. Client information must not be used to train a general model for other customers.
AI uses that are not permitted
- making or issuing a finding, rating or professional conclusion without human review
- selecting samples from a named or directly identifiable full client list
- uploading a full client folder or bulk CDD repository
- entering SAR, SMR, law-enforcement, password or authentication information
- using client data to develop or train a model for unrelated use
- trying to re-identify information that has been coded or de-identified
- allowing an AI provider or plugin to send information to an unapproved third party
Client choice and opt-out
The client may request that no AI be used by giving written notice before the engagement begins. The proposal may then be revised to reflect any change to method, timing or fee.
If a request is made after work begins, it will be handled as a scope change. Work already completed in line with the accepted Schedule will not be repeated unless that is agreed.
Retention and deletion
- Raw CDD and audit samples
- Deleted within 90 days after the final report or deliverable, unless a legal hold or written exception applies.
- Core engagement record
- Kept for seven years after the engagement ends. It may include key working papers, test results, methodology, findings, correspondence, final deliverables, review evidence and the AI-use record.
- Temporary AI input
- Kept only for the shortest period supported by the approved service and required for the task. Zero-retention or equivalent settings should be used where available.
A client may ask for early return or deletion of material that is no longer needed. Seamless AML may keep information required by law, professional accountability, an insurer, a dispute or a legal hold. The client remains responsible for keeping its original AML records for the period required by law.
Incidents and individual requests
Each party must tell the other without undue delay if client information may have been lost, wrongly disclosed, altered or accessed without authority. The parties will cooperate to contain the event, preserve evidence, assess harm and meet any notification duty.
If an individual asks to access or correct information held for the engagement, the parties will cooperate so the request can be answered by the responsible agency. Protected SAR, SMR, privileged and third-party information will not be released where the law permits or requires refusal.
Providers and overseas processing
Approved providers may include Dropbox, Google Workspace, Xero, website and security providers, video meeting providers and approved AI services. Their systems or subprocessors may operate in New Zealand, Australia, the United States or other countries.
Suitable due diligence and contractual safeguards will be used before sensitive client information is processed. The current provider list relevant to an engagement can be requested.
Review and contact
This Schedule will be reviewed when the type of client data, AI use, provider or law changes. A material change affecting an active engagement must be agreed before the changed practice is used.
Questions or opt-out requests should be sent to casey@seamlessaml.com.
Related documents