Client-approved access
Agree which systems and records the India delivery team may use. Identify named users, the roles required and approval for any access changes. Use the least access needed for the work; bookkeeping access should not silently include payment approval or release authority.
Confidentiality and document exchange
Confirm confidentiality terms, client permissions, approved exchange channels and storage locations before sharing files. Use a client-approved system where agreed. This website has no client document portal and the enquiry form must not be used for financial records, identity documents or employee data.
Passwords and staff permissions
Define how individual accounts, multi-factor authentication and password-management tools will be used within the client’s systems. Do not email shared passwords. Record onboarding, role changes and access removal so access can end promptly when the engagement changes.
Handling, retention and incident responsibilities
The engagement should identify the data needed, who can handle it, permitted downloads, retention and deletion arrangements, and the contact process if something goes wrong. Cross-border processing and local compliance requirements need assessment with the client’s responsible advisers.
Backup and business continuity
Confirm the system owner’s backup arrangements, restoration responsibility, absence cover and interruption communications. A recovery time, data-residency guarantee or continuous availability commitment is only meaningful when separately assessed and agreed. None is implied by this page.
Review before the pilot
Use a limited, approved data set to establish the workflow where appropriate. Record instructions, checks, questions and handover status. Ask for the specific controls relevant to your proposed engagement before deciding to share records.