FTC Safeguards Rule for CPA Firms Using Offshore Accounting Teams
A CPA firm believed its offshore accounting portal was encrypted and secure.
Eighteen months into the engagement, someone reviewed the technical configuration. The portal still supported an outdated encryption protocol, access permissions had expanded beyond the original team, and the firm’s WISP had not been updated since the provider was onboarded.
The contract promised security. The operating environment told a different story.
That gap creates the greatest risk for CPA firms. The FTC Safeguards Rule does not stop at having a policy or collecting a security certificate. Covered firms must maintain safeguards that reflect how customer information is actually accessed, transmitted, stored, monitored, and protected.
Key Takeaway
CPA firms should treat offshore accounting providers as part of their information security environment. The firm must assign security ownership, document offshore data flows, restrict and monitor access, include enforceable safeguards in vendor contracts, test whether controls work, and prepare for security incidents. Unauthorized access to unencrypted customer information is presumed to be unauthorized acquisition unless reliable evidence proves otherwise, and encrypted data is treated as unencrypted when an unauthorized person accesses the encryption key.
Does the Safeguards Rule Apply to CPA Firms?
The Safeguards Rule applies to financial institutions under the FTC’s jurisdiction. Tax preparation firms are specifically listed as an example of a covered financial institution. Customer information handled by an offshore provider on the firm’s behalf can remain within the rule’s scope.
Covered firms must maintain a written information security program with administrative, technical, and physical safeguards appropriate to their size, operations, and the sensitivity of the information involved.
Firms maintaining customer information concerning fewer than 5,000 consumers may qualify for exemptions from certain requirements, including specified risk assessment, testing, incident response, and reporting provisions. They are not exempt from the entire Safeguards Rule.
CPA firms should confirm their specific obligations with qualified legal and security advisers.
Name the Person Responsible for Security
The firm must designate a Qualified Individual to implement and supervise the information security program.
The Qualified Individual may be an employee, affiliate, or outside service provider. When the role is outsourced, the firm must retain responsibility and appoint a senior employee to oversee the external individual.
The WISP should identify the person by name and define their authority to approve access, review vendor evidence, require remediation, manage incidents, and report significant security matters to firm leadership.
Assigning responsibility vaguely to “IT” or “operations” weakens accountability.
Make the Offshore Provider Visible in the WISP
A generic reference to third-party vendors is not enough.
The WISP should identify the provider’s legal entity, locations, services, systems, subcontractors, data types, assigned roles, access methods, and incident responsibilities.
The firm should also document:
- Where client information originates
- Which systems provide offshore access
- Whether information can be downloaded
- Who can access each client
- Where logs and backups are retained
- How access is changed or removed
This information should match the firm’s actual remote accounting workflow, not only the arrangement described when the contract was signed.

Assess the Actual Data Flow
The firm should understand what customer information it holds, where it moves, which systems process it, and what could compromise its confidentiality or integrity.
The Safeguards Rule requires periodic risk reassessment as operations, business arrangements, and threats change.
Do not accept a SOC report or security summary without checking whether its scope covers the offshore location, assigned accounting team, remote-access system, applications, and subcontractors involved in your engagement.
The rule requires customer information to be protected through encryption at rest and in transit, unless an effective alternative control is approved by the Qualified Individual. It does not prescribe one universal protocol for every system.
A qualified security professional should review the provider’s configuration evidence and testing results. SafeBooks Global’s guide to offshore accounting data security provides additional operational questions for this assessment.
Validate Identity and Conditional Access
Every offshore professional should have a unique account connected to a defined role and approved client list.
Shared accounts weaken activity records and make it difficult to identify who viewed, changed, or exported information.
The firm should validate the conditional access policies applied through the actual login path. Depending on the firm’s architecture, these controls may require MFA, compliant managed devices, approved networks, single sign-on, or risk-based access restrictions.
Location controls can provide another layer of protection, but they should not be treated as the only safeguard. IP addresses can change, and authorized remote systems may route traffic through centralized gateways.
During a controlled pilot, confirm that:
- Unmanaged devices are blocked where required
- MFA applies through the full login path
- Users cannot bypass the approved SSO gateway
- Unassigned client files remain inaccessible
- Permission changes are logged
- Former staff lose access promptly
The rule requires access controls, MFA, authorized-user monitoring, and detection of unauthorized access.
Test Safeguards Through the Real Workflow
A vendor dashboard showing enabled controls is useful, but it is not enough.
Test the systems used by the offshore team, including remote desktops, file-sharing tools, tax applications, accounting software, document portals, and identity platforms.
When effective continuous monitoring is not in place, covered firms subject to the testing provision must conduct annual penetration testing and vulnerability assessments that include system-wide scans at least every six months. Additional testing is required after material changes or when circumstances may materially affect the security program.
The testing scope should cover the actual offshore workflow, not only the provider’s public website.
Close the Vendor Notification Gap in the Contract
The Safeguards Rule requires firms to select capable service providers, include security requirements in contracts, monitor their performance, and periodically reassess their suitability.
The contract should address permitted data use, access restrictions, encryption, MFA, subcontractors, activity logs, incident cooperation, evidence preservation, deletion, and offboarding.
It should also require rapid incident notification from the provider’s first detection or reasonable suspicion of an event. A 24-hour vendor-to-firm notification standard can provide a useful contractual safeguard, although the FTC does not universally mandate that specific vendor notification period.
The rule treats a notification event as discovered when it is first known to the financial institution. It also deems the firm to have knowledge when the event is known to an employee, officer, or other agent, excluding the person committing the breach. Whether a particular provider qualifies as the firm’s agent can depend on the legal and operational relationship. The contract should therefore avoid leaving the firm dependent on that interpretation.
Prepare for Presumed Acquisition
A qualifying notification event involving at least 500 consumers must be reported to the FTC as soon as possible and no later than 30 days after discovery.
Two rules are especially important during an offshore vendor incident:
First, unauthorized access to unencrypted customer information is treated as unauthorized acquisition unless reliable evidence shows that acquisition did not occur or could not reasonably have occurred.
Second, encrypted customer information is treated as unencrypted when an unauthorized person also accesses the encryption key.
The incident response process should therefore address not only whether files were downloaded, but also:
- Whether attackers reached administrative systems
- Whether encryption keys or key-management systems were exposed
- Whether access logs are complete and trustworthy
- Whether forensic evidence can disprove acquisition
- When the firm, vendor, employee, or potential agent first knew of the event
The provider should preserve evidence immediately and provide the firm with the records needed to evaluate its notification obligations.
Expert Insight
“An offshore provider’s notification process must connect directly to the CPA firm’s regulatory clock. The firm needs prompt facts about affected systems, users, records, encryption keys, and access logs so leadership can make a defensible reporting decision.“
Shivangi Agrawal
Managing Director, CA, CPA (USA), SafeBooks Global
Keep FTC Security Separate From Taxpayer Consent
The Safeguards Rule focuses on protecting customer information. It does not replace the separate consent requirements that may apply when Form 1040 series information is disclosed to a tax return preparer outside the United States.
Firms should connect taxpayer consent status to offshore access approval so a remote user cannot enter the client file before the required authorization is recorded.
Build Vendor Oversight Into the Delivery Model
SafeBooks Global helps U.S. CPA and accounting firms establish process-led offshore support through controlled access, documented workflows, defined responsibilities, clear handoffs, and review-ready delivery.
This does not remove the CPA firm’s responsibility under the Safeguards Rule. It provides a stronger operating structure for connecting security requirements with daily accounting work.
Review how SafeBooks Global approaches protecting client financial data or explore its offshore accounting support for U.S. firms.
To discuss how your offshore workflow can align with the firm’s information security program, schedule a discovery call.
FAQS
How long does an offshore accounting team take to become productive?
What work should CPA firms move offshore first?
Should offshore teams make final tax or audit decisions?
How should firms calculate offshore staffing savings?
Why work with SafeBooks Global instead of hiring directly?

Director (CA, CPA (USA))
Shivangi is a U.S.-certified CPA and Chartered Accountant with deep expertise in U.S. tax, financial reporting, and audit compliance. She has supported CPA and EA firms across sectors like real estate, SaaS, and healthcare. At SafeBooks, she leads global delivery, ensuring every remote accounting team meets U.S. standards with accuracy, discipline, and client-first execution.





