7 Data Security Questions CPA Firms Should Ask Offshore Accounting Vendors
Three months into an offshore engagement, a managing partner discovered that someone at the vendor’s office had downloaded client tax returns to a personal laptop for offline work.
The firm had reviewed security documents during onboarding. However, its WISP did not clearly cover outsourced workflows, and the report shown by the vendor did not cover the accounting team handling client information.
No confirmed breach occurred, but the firm spent weeks reviewing access points, moving work, and rebuilding confidence in its vendor controls.
Security badges and policy statements are not enough. CPA firms need evidence that the provider’s controls apply to the people, systems, locations, and workflows involved in the engagement.
Key Takeaway
CPA firms should evaluate offshore accounting security by asking how client data is accessed, restricted, encrypted, monitored, retained, and deleted. A dependable provider should be able to demonstrate relevant security evidence, individual user access, incident procedures, insurance coverage, controlled offboarding, and compliance support for tax information shared outside the United States.
Confirm the Data and Consent Requirements First
Before reviewing a provider, identify exactly what the offshore team will access. Tax returns, Social Security numbers, payroll records, bank statements, audit workpapers, and financial reports create different levels of exposure.
The firm’s WISP should list the systems, data types, authorized roles, and outsourced workflows involved. SafeBooks Global’s guide to protecting client financial information explains why remote security must cover both technology and daily operating practices.
For Form 1040 series information disclosed to a tax return preparer outside the United States, IRS guidance requires taxpayer consent before disclosure. The consent must be a separate written document, require affirmative consent, and contain mandatory offshore disclosure language. When an unmasked SSN is disclosed, both the U.S. preparer and the foreign preparer must maintain an adequate data protection safeguard. Firms should have qualified counsel confirm the exact wording and process for their engagements.
The Seven Questions to Ask
Question | Evidence to request | Warning sign |
Does your security report cover our service? | Current report, scope, period, exceptions, and management responses | Only a badge or certificate is provided |
How can staff access or download data? | Live demonstration of the working environment | Files can be stored on personal devices |
Who can access each client? | User permissions and activity logs | Shared accounts or broad team access |
How is data encrypted? | Protocol and system documentation | Vague claims without evidence |
What happens when access ends? | Offboarding and deletion records | Removal depends on informal requests |
What insurance applies? | Current policy evidence and territorial scope | Coverage does not apply to the engagement |
How are weaknesses tested? | Recent testing summary and remediation evidence | Old tests or unresolved findings |
1. Does the Security Report Cover Your Actual Engagement?
A security report is useful only when its scope matches the service being purchased.
Ask whether it covers the offshore location, accounting delivery team, remote-access environment, applications, and subcontractors involved in your work. Review the reporting period, exceptions, management responses, and any controls that your firm must operate.
Do not approve a vendor based only on a website badge. Use a structured offshore partner evaluation process to record what was reviewed and which gaps still require action.
2. How Can the Team Access or Download Client Data?
Ask for a live demonstration of the actual working environment.
Client information should remain inside a firm-controlled or provider-controlled secure workspace. Depending on the engagement, this may involve virtual desktop infrastructure, secure remote access, or another controlled environment that restricts local storage.
The provider should explain how it controls downloads, external email, personal cloud storage, printing, clipboard transfers, and removable devices. Policies are not enough. Test the controls using sample data.
A provider offering secure offshore accounting support should be able to demonstrate what users can and cannot do from login to logout.

3. Who Can Access Each Client and Who Has Admin Rights?
Access should be limited to the clients, folders, and applications required for assigned work.
Ask for sample logs showing unique user IDs, timestamps, actions, and records accessed. Shared accounts make it difficult to determine who viewed or changed information.
The firm should also know who can create users, modify permissions, approve administrator rights, and export logs. Review access across every shift, including teams working U.S. hours.
Schedule periodic reviews because permissions often expand as new clients and assignments are added.
4. How Is Data Protected in Transit and at Rest?
The provider should explain how data is protected while moving between systems and while stored in applications, databases, backups, and archives.
Ask which encryption methods apply to each environment, how keys are managed, and who can access them. Avoid accepting phrases such as “bank-level security” without technical evidence.
Your IT adviser should validate whether the controls fit the systems used in the firm’s remote accounting workflow.
5. What Happens When a Team Member or Engagement Ends?
Offboarding should be defined before access begins.
The process should cover prompt permission removal, closure of provider accounts, return or approved deletion of firm information, and confirmation that each action was completed.
Open tasks and handoff notes should remain inside the firm-controlled practice management or document system. This allows work to move to another authorized person without exporting files or copying client information outside the secure environment.
The provider should be able to produce an access-removal record and explain how retained data and backups are handled under its policies.
6. What Insurance Applies to a Cross-Border Incident?
Request evidence of cyber liability and professional liability coverage, but do not stop at the policy limit.
Ask legal counsel and the firm’s insurance adviser to review the insured entity, covered services, territorial scope, jurisdiction, exclusions, deductibles, and claims requirements.
Do not assume a foreign vendor’s policy will respond to every U.S.-based claim simply because cyber coverage exists. Any required global or U.S. jurisdiction coverage should be confirmed in the actual policy and contract rather than relying on the name of a particular clause.
The contract should also define incident notification, investigation support, evidence preservation, data recovery, and responsibility for client communication.
Insurance provides financial protection. It does not replace strong controls or contractual accountability.
7. How Does the Provider Test and Correct Security Weaknesses?
Ask when the provider last completed an independent penetration test, vulnerability assessment, or security review.
The provider may restrict access to detailed findings because the report can contain sensitive technical information. It should still be able to share an executive summary, testing date, scope, risk ratings, and remediation status under suitable confidentiality terms.
Security testing should cover the systems used for your engagement, not only the provider’s public website.
Verify the Controls Through a Limited Pilot
Security due diligence should continue after the contract is signed.
Start with one workflow and a limited client group. Review permissions, access logs, handoff records, exception handling, and offboarding steps before expanding the engagement.
The pilot should confirm that the provider follows the same controls demonstrated during the sales process.
Expert Insight
“For outsourced tax work, security and consent must connect to the actual workflow. A firm should know which person can access the file, where that access occurs, what the client authorized, and how the activity can be verified.“
Anshul Agrawal,
Accounts Director, CA, SafeBooks Global
Choose a Provider That Can Demonstrate Its Controls
For firms that do not want to assemble security, workflow, and continuity controls across individual freelancers or disconnected vendors, a process-led offshore accounting partner is usually the stronger option.
SafeBooks Global supports U.S. CPA and accounting firms through controlled access, role-based permissions, secure remote workflows, documented responsibilities, and review-ready delivery.
Security is built into task assignment, preparation, review, communication, and offboarding, not treated as a separate document used only during vendor onboarding.
Explore SafeBooks Global’s offshore accounting services for CPA firms or schedule a discovery call to discuss the controls required for your bookkeeping, tax, audit, or back-office workflows.
FAQS
Is a security report enough to approve an offshore vendor?
Does a CPA firm need consent before sending Form 1040 data offshore?
Should offshore accountants use personal devices?
Can a provider refuse to share penetration test details?
What is the biggest offshore accounting security warning sign?

Director (CA)
Anshul is a detail-driven Chartered Accountant who works closely with CPA firms and small businesses to deliver high-impact accounting solutions. With a decade of hands-on experience in U.S. taxation, audits, and workflow optimization, he ensures every client receives consistent, quality-driven support from SafeBooks’ global team.





