← All guides

CPA firm data security

Data Security Checklist for CPA Firms Outsourcing to India

Security should be designed into the offshore workflow before client data, tax software or firm systems are opened to an external preparation team.

Published: July 2026Reading time: 8 minutesWISP · Access Control · Incident Response

Quick summary

Give the offshore team only the access required to perform the assigned work.

A secure workflow uses named accounts, multi-factor authentication, role-based permissions, firm-controlled portals, documented device rules and prompt access removal.

The CPA firm should maintain a written information security plan, review service-provider safeguards and preserve final control over client data and systems.

Start with limited access during the pilot. Expand permissions only after the process, supervision and security controls have been tested.

Professional ownership

Outsourcing preparation work does not outsource security responsibility

The CPA firm selects the systems, decides which client information is shared, approves access and supervises the service provider. A contract or confidentiality clause does not replace active oversight.

The firm should understand where information can be accessed, whether it can be downloaded, who administers user accounts and how activity is reviewed.

Core principle:the provider may operate the workflow, but the CPA firm must remain able to explain and control how client information is protected.

Include offshore workflows in the firm’s written security plan

Plan areaQuestions to document
Information handledWhich taxpayer records, credentials, workpapers and communications may be accessed?
People and rolesWho approves access, administers users, reviews activity and handles incidents?
SystemsWhich tax, bookkeeping, portal, email and remote-access systems are permitted?
Risk controlsWhat safeguards reduce unauthorised access, disclosure, alteration or loss?
Service providersHow are vendors selected, contracted, reviewed and offboarded?
Incident responseWho is contacted and what steps follow suspected loss, theft or unauthorised access?

IRS Publication 4557 and the IRS Written Information Security Plan materials provide useful starting points for tax practices reviewing their safeguards.

Least privilege

Use named accounts and role-based access

Each team member should have an individual user account. The permission set should reflect the assigned work rather than granting broad access to every client, return or firm folder.

  • limit access by client, engagement or work queue;
  • separate preparer and administrator permissions;
  • avoid generic team logins;
  • review inactive and excessive permissions regularly;
  • maintain a record of who approved each access level.

Account protection

Enable multi-factor authentication and control credentials

Multi-factor authentication should be enabled for tax software, cloud storage, portals, remote access, email and administrative accounts wherever available.

Passwords should not be sent through ordinary email or messaging apps. Use an approved credential manager or firm-controlled access method.

Use firm-controlled systems for documents and communication

Preferred controlAvoid
Approved client portal or document-management systemPersonal cloud drives and public sharing links
Firm email and approved workflow toolsPersonal email accounts
Controlled messaging within the firm’s platformConsumer messaging apps for taxpayer documents
Permissioned folders with expiration and audit recordsLarge unrestricted shared folders
Defined file naming and version controlsUntracked local copies and repeated attachments

Endpoint control

Define which devices may access taxpayer information

The engagement should specify whether access is permitted only from managed devices, virtual desktops or a controlled remote environment.

  • supported and patched operating systems;
  • anti-malware and endpoint monitoring;
  • screen-lock and inactivity timeout;
  • encrypted storage;
  • restriction of removable media;
  • prohibition of shared family or public devices;
  • secure network and remote-access rules.

Data minimisation

Restrict downloads, printing and local storage

Where the workflow permits preparation inside firm-controlled software or a virtual environment, local copies may not be necessary.

If downloading is permitted, define which files may be downloaded, where they may be stored, whether printing is allowed and how the files are removed after the task is complete.

Start with the minimum:permit local storage only where the workflow genuinely requires it and the retention process is controlled.

Set retention and deletion rules before work begins

StageRequired decision
During preparationWhere may working copies, exports and temporary files exist?
After handoffWhich workpapers remain in the firm system and which temporary files must be deleted?
End of engagementHow is return or deletion of firm and client information confirmed?
Backup systemsDoes deletion apply to local backups, sync folders and cached copies?
EvidenceWhat record shows that access and retained data were reviewed?

Service-provider review

Perform due diligence before sharing client data

The firm should assess the provider’s access model, personnel controls, confidentiality obligations, device standards, security training, incident process, subcontractor use and offboarding procedures.

  • Will any subcontractor or additional location access the information?
  • Who can create users or change permissions?
  • How are personnel background, training and confidentiality handled?
  • How quickly will the provider notify the firm of a suspected incident?
  • How will data and access be removed at the end of the relationship?

Access removal

Offboarding should be immediate and documented

When a team member changes role or leaves, remove access promptly. Revoke active sessions and tokens, recover firm-owned credentials or devices, and change any shared secrets that the person knew.

The service provider should confirm whether temporary working files remain and how they were deleted.

Prepared response

Define the incident process before an incident occurs

The plan should identify the firm contact, provider contact, system administrator and escalation path. It should explain how access is contained, evidence is preserved and affected systems and clients are assessed.

The firm should also determine when to contact its insurer, legal adviser, software provider, regulators, law enforcement or affected clients.

Secure offshore pilot checklist

Before accessDuring the pilotBefore scaling
Define permitted work and clientsReview login and access activityConfirm access remains appropriate
Create named user accountsCheck whether downloads were necessaryReview exceptions and security issues
Enable MFAUse firm-controlled portals and communicationUpdate the written security plan
Document device and storage rulesEscalate unusual requests or access promptlyTest offboarding and incident contacts
Explain retention and deletionLimit access expansion during the pilotApprove additional users and clients deliberately

Avoid these problems

Common security mistakes in offshore CPA workflows

  • shared software or portal credentials;
  • no multi-factor authentication;
  • granting access to every client during the pilot;
  • using personal email or messaging apps for documents;
  • unrestricted downloading and printing;
  • no written deletion or retention process;
  • access remaining active after role changes;
  • security obligations mentioned in a contract but not tested operationally;
  • no clear incident notification timeline;
  • assuming the provider alone is responsible for protecting client information.

Watch related guide

Security controls for CPA firms outsourcing to India

This CBTD video explains the access, authentication, portal, device and offboarding controls to establish before an offshore pilot.

Continue the CPA support journey

Read next

Pillar guideOffshore Tax and Accounting Support for CPA FirmsRead guide → Operating modelDedicated Staff vs Per-Return OutsourcingRead guide → Review workflowHow CPA Firms Should Review Offshore-Prepared Tax ReturnsRead guide → Bookkeeping workflowOffshore Bookkeeping Workflow for CPA FirmsRead guide →

FAQs

CPA outsourcing data-security questions

Do CPA firms need a written information security plan?

Tax professionals are expected to maintain a written information security plan that addresses the taxpayer information handled by the firm, the safeguards in place, incident response and ongoing review.

Should offshore team members use shared logins?

No. Each user should have a named account so access, activity and offboarding can be managed individually.

Is multi-factor authentication necessary?

Multi-factor authentication should be enabled wherever the firm’s tax software, document portal, email, remote-access tools and cloud systems support it.

Should client documents be downloaded to offshore devices?

The safest starting model is to minimise local downloads and use firm-controlled systems with restricted access.

Can an offshore team use personal email or messaging apps?

Client tax documents and credentials should not be exchanged through personal email, consumer messaging apps or unapproved file-sharing services.

What should happen when an offshore team member leaves?

Access should be removed promptly, active sessions and tokens revoked, shared secrets changed where necessary, and client information returned or deleted according to policy.

Who is responsible if a service provider handles client data?

The CPA firm retains responsibility for selecting, supervising and periodically reviewing service providers that handle client information.

What should a security incident process include?

It should identify who must be informed, how access is contained, how evidence is preserved, how affected systems and clients are assessed, and which notifications may be required.

Planning a secure offshore pilot?

Define access, supervision and data handling before sharing client files.

Share the proposed work, software, access model and expected volume. CBTD can help organise an India-based preparation workflow with clear operational controls.

Request a CPA Support Pilot

Disclaimer: This guide provides general operational information and is not legal, cybersecurity, regulatory or professional-standards advice. CPA firms should review the safeguards applicable to their own practice, systems, clients and service-provider relationships.