CPA firm data security
Data Security Checklist for CPA Firms Outsourcing to India
Security should be designed into the offshore workflow before client data, tax software or firm systems are opened to an external preparation team.
Quick summary
Give the offshore team only the access required to perform the assigned work.
A secure workflow uses named accounts, multi-factor authentication, role-based permissions, firm-controlled portals, documented device rules and prompt access removal.
The CPA firm should maintain a written information security plan, review service-provider safeguards and preserve final control over client data and systems.
Start with limited access during the pilot. Expand permissions only after the process, supervision and security controls have been tested.
Professional ownership
Outsourcing preparation work does not outsource security responsibility
The CPA firm selects the systems, decides which client information is shared, approves access and supervises the service provider. A contract or confidentiality clause does not replace active oversight.
The firm should understand where information can be accessed, whether it can be downloaded, who administers user accounts and how activity is reviewed.
Include offshore workflows in the firm’s written security plan
| Plan area | Questions to document |
|---|---|
| Information handled | Which taxpayer records, credentials, workpapers and communications may be accessed? |
| People and roles | Who approves access, administers users, reviews activity and handles incidents? |
| Systems | Which tax, bookkeeping, portal, email and remote-access systems are permitted? |
| Risk controls | What safeguards reduce unauthorised access, disclosure, alteration or loss? |
| Service providers | How are vendors selected, contracted, reviewed and offboarded? |
| Incident response | Who is contacted and what steps follow suspected loss, theft or unauthorised access? |
IRS Publication 4557 and the IRS Written Information Security Plan materials provide useful starting points for tax practices reviewing their safeguards.
Least privilege
Use named accounts and role-based access
Each team member should have an individual user account. The permission set should reflect the assigned work rather than granting broad access to every client, return or firm folder.
- limit access by client, engagement or work queue;
- separate preparer and administrator permissions;
- avoid generic team logins;
- review inactive and excessive permissions regularly;
- maintain a record of who approved each access level.
Account protection
Enable multi-factor authentication and control credentials
Multi-factor authentication should be enabled for tax software, cloud storage, portals, remote access, email and administrative accounts wherever available.
Passwords should not be sent through ordinary email or messaging apps. Use an approved credential manager or firm-controlled access method.
Use firm-controlled systems for documents and communication
| Preferred control | Avoid |
|---|---|
| Approved client portal or document-management system | Personal cloud drives and public sharing links |
| Firm email and approved workflow tools | Personal email accounts |
| Controlled messaging within the firm’s platform | Consumer messaging apps for taxpayer documents |
| Permissioned folders with expiration and audit records | Large unrestricted shared folders |
| Defined file naming and version controls | Untracked local copies and repeated attachments |
Endpoint control
Define which devices may access taxpayer information
The engagement should specify whether access is permitted only from managed devices, virtual desktops or a controlled remote environment.
- supported and patched operating systems;
- anti-malware and endpoint monitoring;
- screen-lock and inactivity timeout;
- encrypted storage;
- restriction of removable media;
- prohibition of shared family or public devices;
- secure network and remote-access rules.
Data minimisation
Restrict downloads, printing and local storage
Where the workflow permits preparation inside firm-controlled software or a virtual environment, local copies may not be necessary.
If downloading is permitted, define which files may be downloaded, where they may be stored, whether printing is allowed and how the files are removed after the task is complete.
Set retention and deletion rules before work begins
| Stage | Required decision |
|---|---|
| During preparation | Where may working copies, exports and temporary files exist? |
| After handoff | Which workpapers remain in the firm system and which temporary files must be deleted? |
| End of engagement | How is return or deletion of firm and client information confirmed? |
| Backup systems | Does deletion apply to local backups, sync folders and cached copies? |
| Evidence | What record shows that access and retained data were reviewed? |
Service-provider review
Perform due diligence before sharing client data
The firm should assess the provider’s access model, personnel controls, confidentiality obligations, device standards, security training, incident process, subcontractor use and offboarding procedures.
- Will any subcontractor or additional location access the information?
- Who can create users or change permissions?
- How are personnel background, training and confidentiality handled?
- How quickly will the provider notify the firm of a suspected incident?
- How will data and access be removed at the end of the relationship?
Access removal
Offboarding should be immediate and documented
When a team member changes role or leaves, remove access promptly. Revoke active sessions and tokens, recover firm-owned credentials or devices, and change any shared secrets that the person knew.
The service provider should confirm whether temporary working files remain and how they were deleted.
Prepared response
Define the incident process before an incident occurs
The plan should identify the firm contact, provider contact, system administrator and escalation path. It should explain how access is contained, evidence is preserved and affected systems and clients are assessed.
The firm should also determine when to contact its insurer, legal adviser, software provider, regulators, law enforcement or affected clients.
Secure offshore pilot checklist
| Before access | During the pilot | Before scaling |
|---|---|---|
| Define permitted work and clients | Review login and access activity | Confirm access remains appropriate |
| Create named user accounts | Check whether downloads were necessary | Review exceptions and security issues |
| Enable MFA | Use firm-controlled portals and communication | Update the written security plan |
| Document device and storage rules | Escalate unusual requests or access promptly | Test offboarding and incident contacts |
| Explain retention and deletion | Limit access expansion during the pilot | Approve additional users and clients deliberately |
Avoid these problems
Common security mistakes in offshore CPA workflows
- shared software or portal credentials;
- no multi-factor authentication;
- granting access to every client during the pilot;
- using personal email or messaging apps for documents;
- unrestricted downloading and printing;
- no written deletion or retention process;
- access remaining active after role changes;
- security obligations mentioned in a contract but not tested operationally;
- no clear incident notification timeline;
- assuming the provider alone is responsible for protecting client information.
Watch related guide
Security controls for CPA firms outsourcing to India
This CBTD video explains the access, authentication, portal, device and offboarding controls to establish before an offshore pilot.
FAQs
CPA outsourcing data-security questions
Do CPA firms need a written information security plan?
Tax professionals are expected to maintain a written information security plan that addresses the taxpayer information handled by the firm, the safeguards in place, incident response and ongoing review.
Should offshore team members use shared logins?
No. Each user should have a named account so access, activity and offboarding can be managed individually.
Is multi-factor authentication necessary?
Multi-factor authentication should be enabled wherever the firm’s tax software, document portal, email, remote-access tools and cloud systems support it.
Should client documents be downloaded to offshore devices?
The safest starting model is to minimise local downloads and use firm-controlled systems with restricted access.
Can an offshore team use personal email or messaging apps?
Client tax documents and credentials should not be exchanged through personal email, consumer messaging apps or unapproved file-sharing services.
What should happen when an offshore team member leaves?
Access should be removed promptly, active sessions and tokens revoked, shared secrets changed where necessary, and client information returned or deleted according to policy.
Who is responsible if a service provider handles client data?
The CPA firm retains responsibility for selecting, supervising and periodically reviewing service providers that handle client information.
What should a security incident process include?
It should identify who must be informed, how access is contained, how evidence is preserved, how affected systems and clients are assessed, and which notifications may be required.
Planning a secure offshore pilot?
Define access, supervision and data handling before sharing client files.
Share the proposed work, software, access model and expected volume. CBTD can help organise an India-based preparation workflow with clear operational controls.
Disclaimer: This guide provides general operational information and is not legal, cybersecurity, regulatory or professional-standards advice. CPA firms should review the safeguards applicable to their own practice, systems, clients and service-provider relationships.