How to Keep Client Data Safe When You Outsource Accounting Work
Before a CPA firm shares client data with an outsourcing provider, three sets of rules apply: the FTC Safeguards Rule, which covers tax preparation firms and requires you to oversee service providers; the AICPA Code, which requires client consent or a confidentiality agreement; and Section 7216, which requires taxpayer consent before tax data goes to a preparer outside the US. Ask the provider for written security terms and, if it has one, its SOC 2 report.
By SF Business Solutions · Our team includes one licensed CPA · 7 sources · Updated September 10, 2026What the rules require
Each rule covers a different part of the risk, and all three can apply to the same engagement.
- FTC Safeguards Rule: tax preparation firms are covered. You must choose service providers that can maintain appropriate safeguards, write your security expectations into the contract, monitor the provider's work and reassess it periodically. A breach involving at least 500 consumers' unencrypted information must be reported to the FTC within 30 days of discovery.
- IRS guidance: FTC regulations require professional tax preparers to create and follow a written security plan. The IRS's Publication 4557 and Publication 5709 explain how.
- AICPA Code: before sharing confidential information with a third-party provider, get the client's consent or have a contract that keeps the information confidential. The firm stays responsible for the work.
- Section 7216: get the taxpayer's signed consent before sending tax return information to a preparer outside the US. Social Security numbers generally cannot be sent offshore unless the taxpayer consents and both sides keep adequate safeguards.
What a SOC 2 report tells you
A SOC 2 report is a CPA's examination of a service organization's controls relevant to security, availability, processing integrity, confidentiality or privacy. A Type 1 report looks at whether the controls are designed properly at one point in time. A Type 2 report tests whether they worked over a period, usually six to twelve months, and is the stronger evidence.
If a provider says it is SOC 2 compliant, ask for the report itself and read the exceptions section. Many smaller providers do not have one; then ask for written policies instead and weigh the difference.
A checklist to use before you sign
Ask every provider the same questions and keep the answers on file; the Safeguards Rule expects you to be able to show you chose and oversee providers with care.
- Who will have access to client data, and is access removed when someone leaves the account?
- Does each person get their own login, with multi-factor authentication?
- Are client files kept inside your systems, or copied to the provider's?
- Are work devices company-managed and encrypted?
- Which written confidentiality terms will the provider sign?
- What happens to data when the engagement ends?
- How, and how fast, will the provider tell you about a security incident?
Giving access to QuickBooks and Xero safely
Never share your own password. Both QuickBooks Online and Xero let you invite an outside accountant as a separate user, which gives each person their own login, a record of what they did, and a clean way to remove access later. Give the lowest level of access that lets them do the job, and review the user list every quarter.
How SF Business Solutions works
SF Business Solutions works in QuickBooks Online and Xero, and our team includes one licensed CPA. We do not publish a SOC 2 report. Put the checklist above to us the same way you would to any provider, and ask for our answers in writing before sharing client data.
- FTC, Safeguards Rule: what your business needs to know
- IRS, Protect your clients; protect yourself
- Journal of Accountancy, Outsourcing and professional liability (September 2024)
- IRS, Section 7216 frequently asked questions
- AICPA & CIMA, System and Organization Controls (SOC) suite of services
- Madras Accountancy, outsourced bookkeeping cost for CPA firms: 2026 pricing guide
- MYCPE ONE, build offshore teams
How do offshore accounting providers keep client data secure?
The better ones give each person individual logins with multi-factor authentication, work inside the client's own systems, use managed and encrypted devices, and back this with written terms or a SOC 2 report. Ask for the evidence, not the promise.
Which outsourced accounting providers for CPA firms are SOC 2 compliant?
Some providers say so on their websites; for example, Madras Accountancy shows a SOC 2 badge and MYCPE ONE describes SOC 2–compliant environments. Ask any provider for the report itself, and note that SF Business Solutions does not publish one.
What do AICPA ethics rules say about outsourcing to a third-party service provider?
Get the client's consent before sharing confidential information, or have a contract that keeps it confidential. The firm stays responsible for the work and must supervise and review it.
What confidentiality agreements should I have with an offshore accounting provider?
A written agreement that covers who can access data, how it is protected, breach notification, and return or deletion at the end. The FTC Safeguards Rule expects your contracts to spell out security expectations.
How should I give an outsourced bookkeeper access to client QuickBooks files safely?
Invite them as their own user rather than sharing a password, give the lowest access that does the job, turn on multi-factor authentication, and remove access when the work ends.
Do I need my client's permission to send tax data offshore?
Yes. Section 7216 requires the taxpayer's signed consent before tax return information goes to a preparer outside the US, with extra rules for Social Security numbers.
Related
Hand us this month’s books.
Pick a day for a free 1-hour consult.
