← Insights
Practical2026-08-137 min read

Is AI safe for your books? GDPR, your auditor and where your data stays

What to arrange before AI writes to your books: a GDPR basis, a data processing agreement, where your data sits, and how to explain an AI posting to your auditor.

Book a demo →
JR
Jeroen Ruigrok
Co-founder · Claridy

The question every finance lead asks and rarely gets a concrete answer to. What is genuinely at stake around privacy, auditability and data residency, and the eight questions to put to a vendor.

Where the concern comes from, and where it is right

The concern is not irrational. There is a real difference between software that proposes something and software that does something, and that difference touches three things at once: privacy, reliability and accountability.

What often gets conflated is whether AI "learns" your data and whether AI makes a mistake. Those are two different risks with two different answers, and they are rarely discussed separately.

1. GDPR: your invoices contain personal data

That is underestimated. A purchase invoice carries contact names, email addresses, sometimes phone numbers, and for sole traders a home address. The mailbox around it holds correspondence. That is personal data processing, even if it is "only" invoices.

What you have to arrange is not complicated, but it does have to exist:

A data processing agreement with the vendor, setting out what happens to the data, how long it is kept and what happens when you stop.

A sub-processor list. Almost every AI vendor uses a third-party model. Ask who they are, where they run, and whether you are notified when one is added.

Clarity on training. The question is not whether AI is used but whether your data is used to train other people's models. With the business tiers of the major providers that is contractually excluded, but you need it on paper.

2. Where your data sits

For most finance teams this is the sharpest question, and there is a difference between "we are GDPR compliant" and "your data stays in the EU". The first can be true while your data is processed outside the EU on the basis of standard contractual clauses.

Ask three things separately: where is the data stored, where is it processed, and where does the AI model run. Those three can each be somewhere else, and it is the third that most often stays out of view.

At Claridy, storage and processing stay within the EU. What we do not publish is the full sub-processor list; you get that in a security review.

3. Can you explain an AI posting to your auditor

This is what it really comes down to, and it is the question asked least.

On a sample, your auditor asks: why was this invoice posted this way? With a manual posting the answer is a person. With a rule-based system the answer is a rule. With a system that predicts the posting, the answer is that the model considered this most likely, and that is not an answer.

So the shape that works is a separation: the AI reads and understands, the rule decides. The AI does what it is good at, understanding language and context, and what happens next is deterministic logic that you defined and that runs identically every time. The same invoice produces the same posting, today and in a year.

That makes three things possible that otherwise are not: you can repeat the posting, you can explain it, and you can trace it to a rule someone deliberately set.

4. Why 95 percent accurate is not good enough

A system that is right 95 percent of the time sounds excellent. Five percent of two thousand invoices a month is a hundred wrong postings. Finding them all again takes longer than posting them yourself would have.

The real risk sits behind that: a system that is usually right teaches your team to stop checking. Then those hundred errors stay invisible until the auditor trips over them.

That is not an argument against AI. It is an argument against AI in the execution path.

5. The rollout that keeps the risk small

Do not switch a system to autonomous on day one, and be suspicious of a vendor who suggests it.

First the system proposes every action and your team approves. You see where it is right and where it is not, on your own invoices. Then you set a threshold: above a certain confidence the system executes, below it the item goes to your team with the preparation done. You move that threshold, based on what you have watched happen.

And one practical point that lowers the risk structurally: choose a layer that keeps no books of its own. If it reads from your ERP and writes back to it, then after you switch it off your administration is exactly as it was. There is no second truth that can drift, and stopping is not a project.

The eight questions to ask a vendor

  1. Is there a data processing agreement, and what does it say about retention?
  2. Who are the sub-processors, and am I notified when one is added?
  3. Where is the data stored, where is it processed, and where does the model run?
  4. Is my data used to train models? Where is that stated contractually?
  5. Does the AI decide the posting, or does the AI read and a rule decide?
  6. For any single posting, can I see which rule and which source it was based on?
  7. What has been independently assessed, and may I see the report?
  8. If I stop in a year, what do I have to do?

That last one is the most useful and the least asked. The answer separates a layer from a lock-in.

What we can show ourselves

Independent assessment: a CASA Tier 2 review, carried out by TAC Security in February 2026. The report and the Security Overview are available on request in a security review; we do not publish them openly. A SOC 2 programme is under way, and until it is complete we describe it as a programme and not as a certification. We make no ISO claim, because we do not hold one.

Every action sits in an audit trail with the rule and the source it was based on. Storage and processing within the EU. And the architecture itself: we keep no books of our own, so your ERP stays the only place where the truth lives.

Frequently asked questions

Is AI safe for my books?

Yes, provided three things are in place: a data processing agreement because your invoices contain personal data, clarity on where your data is stored and processed, and a deterministic decision so every posting is traceable to a rule. A system that predicts the posting rather than deriving it cannot be audited.

Does GDPR allow AI to process my invoices?

Yes, with a data processing agreement and a valid basis. Invoices carry personal data, so GDPR simply applies. Ask separately who the sub-processors are and whether your data is used to train models.

Does my data stay in the EU?

That differs per vendor, and "GDPR compliant" does not automatically mean "inside the EU". Ask about storage, processing and the location of the AI model, because those three can differ. At Claridy, storage and processing stay within the EU.

How do I explain an AI posting to my auditor?

By making the decision deterministic. A posting that follows from a defined rule can be repeated and explained; one that follows from a prediction cannot. Ask whether you can see the rule and the source behind any single posting.

Is my data used to train AI?

With the business tiers of the major model providers that is contractually excluded, but you need it on paper from your vendor, including who the sub-processors are.

What if the system makes a mistake?

That is why you run supervised first, with every action as a proposal, and only then set a threshold above which it executes by itself. And it is why the decision should follow from a rule: a mistake is then a wrong rule you adjust, not an untraceable outcome.

More on the architecture where the AI reads and the rule decides: what is a system of action for finance. What we have in place on security: security and audit.

Last checked: 2026-08.

See it on your own invoices.
A demo on an example from your own process.
Book a demo ↗
Read next