General · Security
Data Security Questions to Ask an Accounting Outsourcing Provider
Questions to clarify system access, document handling, incident contacts and exit arrangements before sharing accounting information offshore.
Before sharing financial information with an accounting outsourcing provider, ask how the proposed workflow will use that information. Broad phrases such as secure systems do not identify who will have access, what they can do or where documents will be retained. The answers should relate to the actual engagement and client environment.
Who will access the systems?
Ask which named users require access and who authorises additions or changes. Discuss the permissions needed for each task, how authentication will work and who will remove access when a role changes. Do not assume that a preparer needs the same authority as an administrator or payment approver.
Record the client-side contact responsible for access decisions. If the arrangement includes substitutes or supervisors, identify how their access would be approved rather than treating coverage as an automatic permission to share credentials.
Where will records move?
- Which document-sharing channels are approved?
- Are downloads or local copies permitted?
- Where will working files and backups be stored?
- Who can forward information to another party?
- What retention and deletion arrangements apply?
Ask for a workflow explanation, not simply a list of security products. Your responsible advisers should assess whether the proposed handling meets the requirements applicable to the information and jurisdiction involved.
What happens when something goes wrong?
Agree whom each side contacts if access is lost, a device is suspected to be compromised or information is shared incorrectly. Clarify who investigates, who decides whether external notification is required and how work is paused or continued. Incident and continuity arrangements should be documented before sensitive records are exchanged.
Do not infer a recovery time or uninterrupted service from a general reference to backup. Ask what has actually been arranged for the engagement and who owns the relevant systems.
How does access end?
Include return of records, handover of open work, account removal and treatment of retained copies in the exit discussion. A final accounting handover and access closure are separate tasks; both need an owner.
NIST’s Small Business Cybersecurity Corner provides general security resources, while the IRS’s Protect Your Clients material addresses taxpayer-data protection for tax professionals. These sources are further reading, not proof that any provider is certified or compliant. This editorial checklist is not a security audit. Assess specific controls and evidence with the people responsible for your systems, professional obligations and engagement.