ICAEW.com works better with JavaScript enabled.

Protecting client confidentiality: internal controls and the ICAEW Code of Ethics

Author: Sophie Wales, Regulatory Policy Director, ICAEW

Published: 28 Jul 2026

Members are reminded that the duty to protect client confidentiality under the ICAEW Code of Ethics applies both externally and within the firm. Sophie Wales, Regulatory Policy Director, ICAEW, explains why firms need strict controls over how confidential information is shared, managed and used across their organisation.

Confidentiality is one of the five fundamental principles in the ICAEW Code of Ethics. The Code requires professional accountants to respect the confidentiality of information acquired in the course of professional and business relationships. This obligation applies to information about prospective, current and former clients, and continues even where that information later becomes publicly available.

The Code also prohibits a professional accountant from using confidential information for the advantage of the accountant, the firm, or a third party.

Recent cases involving confidentiality breaches outside the UK, where client information was used for the benefit of the firm, have highlighted the importance of firms having effective safeguards, training and oversight for how they use client information. While external disclosure is often the most obvious risk, firms should also consider how client information is handled internally and whether it is shared or used only where there is a proper basis for doing so.

What does the Code of Ethics say about confidentiality?

Subsection 114 of the ICAEW Code of Ethics covers confidentiality. Paragraph R114.1 states that a professional accountant must comply with the principle of confidentiality, which requires them to respect the confidentiality of information acquired through professional and business relationships.

The principle is not limited to preventing information from being disclosed outside the firm. Firms also need to consider whether information is being shared internally only with those who need to know it for a legitimate professional or business purpose, and whether appropriate safeguards are in place to prevent misuse.

“Client confidentiality is not just about avoiding external leaks or unauthorised disclosures,” says Sophie Wales, ICAEW Regulatory Policy Director. “Firms also need to think carefully about what happens inside the organisation. Information obtained through a client relationship should not be shared more widely than necessary, or used in a way that could give the firm, an individual or another client an unfair advantage.”

Why internal confidentiality matters

Internal confidentiality can be overlooked because firms may assume that information is safe if it remains within the practice. However, the ethical obligation is broader than simply considering how information is used externally. Client information should not be accessed, discussed or circulated simply because it may be interesting, commercially useful or relevant to another part of the firm.

For example, firms should be alert to situations where teams work with competing clients, information is discussed in open-plan or shared digital environments, or staff use client information to identify new opportunities. Even where no external disclosure occurs, the misuse of confidential information can still create ethical, legal and reputational risks.

“A useful test for firms is to ask whether the client would reasonably expect that information to be used or shared in that way,” says Sophie. “If the answer is no, or if the firm cannot clearly explain the professional reason for sharing it, it should pause and consider whether it has the right consent, authority or safeguards in place.”

Reviewing confidentiality controls

Firms should review their confidentiality arrangements regularly, particularly where they operate across multiple offices, jurisdictions, service lines or digital platforms. The review should consider whether policies, systems and staff behaviours support the requirements of the Code in practice.

  • Check that confidentiality policies clearly cover internal as well as external sharing of client information.
  • Limit access to client files, records and systems to those who need it for their role.
  • Make sure staff understand when client information can be shared internally, and when consent or further review is needed.
  • Consider confidentiality risks when working with clients who may be competitors or sharing updates across the firm.
  • Review how confidential information is protected in emails, messaging platforms, document management systems and AI tools.

Protecting confidential information when using digital tools and AI

As firms make greater use of digital tools, including artificial intelligence, they should ensure that confidential client information is not entered into systems without appropriate due diligence, contractual protections and internal approval. Not all employees within a firm may be entitled to access every category of client information, so firms should have controls in place to digitally restrict access to those who need it for a legitimate professional or business purpose. Firms should understand where data is stored, who can access it, whether it may be used to train models, and how outputs are monitored.

“AI and other digital tools can bring real benefits, but they do not reduce a firm’s ethical responsibilities,” says Sophie. “Before confidential information is uploaded, summarised, analysed or reused, firms need to be confident that they remain compliant with the Code and that client information is properly protected.”

Key takeaways

  • Client confidentiality applies to information acquired through professional and business relationships.
  • The duty applies to prospective, current and former clients, and can continue even where information becomes publicly available.
  • Firms should consider processes to restrict internal sharing and use of confidential information, not just external disclosure.
  • Client information should not be used to gain an unfair advantage for the firm, an individual or another client.
  • Policies, access controls, training and technology governance should be reviewed regularly.

Further support

Firms should familiarise themselves with the ICAEW Code of Ethics 2026, particularly Subsection 114 on confidentiality, and ensure their internal procedures reflect the Code’s requirements. ICAEW also provides ethics guidance and support to help members and firms apply the confidentiality principle in practice.

Open AddCPD icon