Where Is My Client's Data Actually Going? A CA Firm's Guide to Evaluating AI Audit Tools
Across dozens of demo calls we've sat through with Indian CA firms this year, one question comes up more than any other — not "how much does it cost" or "does it work with Tally," but some version of: where is my client's data actually going once I upload it? It's not a box-ticking question. A partner signing off on an engagement is putting their own name and UDIN behind whatever tool they let near client ledgers, and "I didn't know where the data went" isn't a defensible answer if something goes wrong.
The honest problem is that most vendor answers are reassurance, not information. "We take security seriously" tells you nothing. Here's the actual checklist worth working through before you commit — six specific questions, and what a real answer to each looks like.
1. Where is the data physically hosted?
Not "we're cloud-based" — which region, which provider. For Indian audit work, the DPDPA-conscious answer is India-only hosting, on a named provider, in a named region, with no replication outside Indian borders. Vague answers ("our infrastructure is secure and compliant") usually mean the vendor either doesn't know or doesn't want to say. Ask for the specific answer and write it down — you'll want it for your own client due-diligence file.
CORAA is hosted entirely on AWS, Mumbai region (ap-south-1) — no replication outside India, full stop. That's a check-in-two-seconds answer, and it's the standard every vendor should be able to meet.
2. Is the underlying AI model open or closed — and does that even matter?
This question comes up more often than you'd expect, and it's a fair one, but the framing usually misses the actual point. "Open vs. closed" isn't really about the base model — it's about two separate questions people are actually asking: is my data going to a foreign server, and does anyone outside this vendor ever see it.
CORAA's answer: open-source LLMs, hosted and run entirely on India-based infrastructure — never a shared public API, never a foreign-hosted endpoint. What's actually proprietary is CORAA's own patent-pending deterministic execution layer wrapping those models, which is what makes identical inputs produce identical, reproducible outputs every time — the part that matters for peer review isn't which foundation model sits underneath, it's whether the system is reproducible and auditable end to end.
3. Does the vendor train any model on your client's data?
This is the one question every firm should insist on getting in writing, not just verbally. The right answer is unambiguous: no, never, full stop — customer ledgers, vouchers, and findings are evidence, not training material. A vendor that hedges ("we may use aggregated, anonymized data to improve our models") is telling you they do train on your data in some form. For audit work specifically, that's disqualifying — your engagement letter almost certainly doesn't authorize your client's financial data being used to improve someone else's product.
4. What happens to the data if you cancel?
Ask this before you sign, not after. A defensible answer covers: how you export everything you need before leaving (working papers, findings, the full audit trail), a specific deletion timeframe after contract termination (30 days is a reasonable standard), and confirmation that deletion is real deletion, not just access revocation while the data sits on a server somewhere. If a vendor can't give you a specific number of days, that's itself the answer.
5. Is there an actual Data Processing Agreement, or just a privacy policy?
A privacy policy is marketing copy dressed as compliance. A Data Processing Agreement (DPA) is a contractual document — under DPDPA Section 8, your firm is typically the Data Processor for your client (the Data Fiduciary), which means you carry real obligations, and a vendor's DPA is part of how you discharge them. Ask specifically: "Is there a DPDPA-compliant DPA I can show my client as part of my own due diligence, and where's your sub-processor list?" A vendor with a real security posture will have both ready, usually on a dedicated trust page.
6. Who inside the vendor's team — and inside your own firm — can actually access what?
Two separate access questions, both worth asking. On the vendor side: does anyone at the company have standing access to your client data, or is it genuinely locked to the engagement? On your own firm's side: can you scope what your article assistants see versus your managers versus your partners, or is it all-or-nothing? Firms running confidential audits (listed companies, sensitive sectors) need role-based access as a baseline, not an add-on.
Putting it together
None of these six questions are exotic — they're the same due-diligence a firm would run on any vendor handling sensitive data, applied specifically to what AI tools now touch. The reason it feels newer with AI is that "the model" adds a layer most partners haven't had to evaluate before. Strip that away and it's the same discipline: where's the data, who can see it, what's the contract say, what happens if you leave.
If you want the fuller version of this checklist — scored across six pillars including India compliance, audit-grade features, and vendor quality, mapped to ICAI's AQMM v2.0 — we built one: the AI Audit Tool Evaluation Checklist. It's free, and it's not scoped to make any one vendor look good — use it against whoever you're evaluating, CORAA included.
Frequently Asked Questions
Where should I ask a vendor's data actually be hosted for Indian audit work?
India-only, in a named region with a named provider (e.g. AWS Mumbai, ap-south-1), with no replication outside Indian borders. If a vendor can't give you a specific region, treat that as a red flag rather than reassurance.
Does CORAA train its AI models on client data?
No. Client ledgers, vouchers and findings are never used to train any model — they're treated as evidence, not training material. This is a standing commitment, not a case-by-case decision.
What's the difference between a vendor's privacy policy and a Data Processing Agreement?
A privacy policy is a general public statement; a DPA is a contractual document that spells out your specific rights and the vendor's specific obligations as a data processor under DPDPA Section 8 — ask for the DPA, not just the policy page.
Should I be worried if a vendor uses an open-source AI model instead of a proprietary one?
Not on its own — what matters more is where the model runs and whether your data ever leaves a secure, India-hosted environment. An open-source model hosted entirely on Indian infrastructure with no public API exposure is a stronger security posture than a "proprietary" model that's actually a wrapper around a foreign public API.
How long should a vendor keep my data after I cancel my subscription?
Look for a specific, stated number — 30 days is a reasonable standard — followed by real deletion, not just account deactivation. If the vendor's answer is vague on either the timeframe or what "deletion" actually means, ask again in writing before you sign.
Related: AI Audit Tool Evaluation Checklist · CORAA Trust Centre · Start a free trial