FTC Safeguards Rule, WISP Requirements, and Vendor Evaluation Checklist
Security due diligence should not stop at asking whether an offshore accounting provider uses MFA, encryption, or secure offices.
Accounting firms need to understand how the provider will handle their specific engagement. That includes the legal entity delivering the work, the people and locations involved, the systems used, the access granted, the data that can be downloaded or retained, and the response process when an employee leaves or a security incident occurs.
The provider may have strong controls, but the accounting firm still needs to incorporate the relationship into its risk assessment, WISP, access-management process, vendor contract, and ongoing monitoring.
The better question is not simply, “Is this provider secure?”
It is:
“Can this provider give our firm enough evidence, control, and visibility to support our own security and vendor-oversight responsibilities?”
Key Takeaway
Accounting firms should evaluate offshore security at the engagement level, including the entity, personnel, locations, systems, access methods, and data flows involved.
The provider should be incorporated into the firm’s WISP, vendor-risk process, contract controls, access-management procedures, and incident-response plan.
A SOC 2 Type II report supports due diligence, but it does not replace engagement-specific review or ongoing vendor oversight.
Why Offshore Security Must Be Reviewed at the Engagement Level
A single offshore provider may support different clients through different teams, locations, systems, and delivery models.
One accounting firm may require all work to remain inside a controlled virtual environment. Another may permit access through cloud accounting software. A third may require files to move through a provider-managed platform.
These arrangements do not create the same risk.
Before approving an engagement, the firm should understand which client information will be available, whether data stays inside approved systems, whether downloads or printing are possible, which locations and devices will be used, whether remote work is permitted, and whether affiliates or subcontractors are involved.
This information should become part of the firm’s existing security documentation rather than remaining in a sales presentation or onboarding email.
How the FTC Safeguards Rule Applies to Offshore Accounting Providers
The FTC Safeguards Rule requires covered financial institutions to maintain safeguards for customer information and oversee relevant service providers.
For accounting firms using offshore support, this has several practical implications.
The firm should select a provider capable of maintaining appropriate safeguards, define those expectations in the contract, monitor the provider’s performance, and reassess the relationship when risks or delivery arrangements change.
Using an offshore provider does not transfer the firm’s Safeguards Rule responsibilities.
The Qualified Individual responsible for the firm’s security program should have visibility into the provider relationship, including access methods, data flows, incident contacts, control changes, and assurance evidence.
Material changes should trigger review. Examples include a new delivery location, broader remote work, a different subcontractor, a new file-sharing system, or a change in how client information is stored.
How an Offshore Provider Should Fit Into the Firm’s WISP
The offshore provider should be reflected throughout the firm’s WISP rather than listed only in a vendor appendix.
WISP Area | Offshore Provider Consideration |
Data inventory | Which records and data categories the provider can access |
System inventory | Which accounting platforms, portals, devices, and access tools are involved |
Authorized users | Which offshore personnel are approved and what each person can access |
Access control | MFA, role-based permissions, review, and offboarding |
Data handling | Downloading, storage, printing, transmission, retention, and deletion |
Vendor oversight | Due diligence, contract terms, assurance evidence, and monitoring |
Incident response | Notification timing, contacts, logs, containment, and investigation support |
Business continuity | Backup staff, alternate locations, and controls during disruption |
Review cycle | Reassessment after incidents, system changes, new locations, or control changes |
The firm’s vendor register, access records, incident contacts, data-flow documentation, and retention procedures should be updated whenever the engagement changes.
The IRS WISP framework in Publication 5708 can support this process, but the final plan should reflect the firm’s actual systems and operating model.

Offshore Accounting Vendor Security Checklist
The strongest provider evaluation combines documentation, direct questions, contract terms, and engagement-level controls.
1. Confirm the Delivery Entity and Scope
Identify the legal entity signing the agreement and the entity employing the assigned professionals.
Confirm where the work will be completed, whether remote work is permitted, and whether affiliates, temporary staff, subcontractors, or subservice providers may access firm systems or client information.
A security report issued to one group company may not automatically cover every office, affiliate, or delivery team.
2. Map the Data Flow
The provider should explain how information enters, moves through, and leaves the delivery environment.
The firm should know whether work remains inside its own systems, whether files move into provider-managed platforms, whether local downloads are possible, where backups are held, how long data is retained, and how deletion is confirmed after termination.
Reducing unnecessary data movement usually makes access easier to control.
3. Review Identity and Access Controls
Each offshore professional should have a unique account.
Access should be protected through MFA, limited according to role, restricted by client where possible, reviewed periodically, and removed promptly when no longer required.
The firm should also know who can create accounts, change permissions, reset credentials, and approve privileged access.
4. Evaluate Devices and Work Environments
Confirm whether assigned personnel use provider-managed devices and how those devices are secured.
Relevant controls may include full-disk encryption, endpoint security, patch management, screen locks, software restrictions, USB controls, printing restrictions, and monitoring.
Some engagements may use a controlled virtual environment that limits downloading, printing, clipboard use, or local storage. This can reduce risk, but it should be evaluated as one control within the wider security environment.
5. Assess Logging, Monitoring, and Testing
The provider should be able to explain which activities are logged, how long logs are retained, who reviews alerts, and how suspicious access is investigated.
The firm should also understand how vulnerabilities, system changes, patches, backups, and recovery tests are managed.
The provider may not disclose sensitive technical details, but it should provide reasonable evidence that controls are tested and weaknesses are remediated.
6. Review Personnel Security
Technology controls are only part of the risk.
The provider should have documented background screening, confidentiality agreements, security training, phishing awareness, and joiner, mover, and leaver procedures.
Training should also address AI-enabled impersonation. Voice, video, and email requests may appear to come from a firm owner, manager, or client. Sensitive requests involving payments, data exports, credential resets, or access changes should require verification through a separate approved channel.
7. Prevent Shadow IT
The provider should prohibit personal email, consumer file-sharing services, unapproved messaging apps, and unauthorized AI tools for client work.
Approved communication and document-transfer channels should be defined during onboarding and reinforced through policy and training.
A single client file sent through an informal tool can move sensitive information outside the controls reviewed during due diligence.
8. Examine Incident-Response Obligations
The provider should notify the accounting firm promptly about suspected or confirmed unauthorized access, credential compromise, malware, lost devices, improper disclosure, or data loss.
The provider should not wait until it completes a full investigation or decides that the incident is legally reportable.
The contract should identify notification timing, named contacts, evidence preservation, containment responsibilities, investigation cooperation, and remediation reporting.
9. Verify Business-Continuity Controls
The provider’s continuity plan should preserve security during outages, office closures, or staffing disruptions.
The accounting firm should understand whether alternate locations or remote arrangements may be used, how access remains controlled, and whether data could move to unapproved environments during a disruption.
10. Confirm Data Retention and Deletion
The agreement should define how long client information may be retained, where copies and backups may exist, and how data is returned or deleted when the relationship ends.
The firm should ask whether the provider can confirm deletion and whether any legal or operational retention requirements create exceptions.
11. Review Contractual Safeguards
The agreement should address permitted data use, confidentiality, access restrictions, subcontractors, incident notification, investigation support, data return and deletion, business continuity, material control changes, and termination.
It should also require appropriate assurance evidence and notification of material changes that could affect the engagement.
12. Establish Ongoing Monitoring
Vendor due diligence should continue after onboarding.
The accounting firm should reassess access, updated assurance reports, material control changes, new locations, subcontractor changes, incidents, and continuity arrangements based on the risk of the engagement.
How to Read a Provider’s SOC 2 Type II Report
A SOC 2 Type II report should be reviewed as evidence, not treated as a badge.
Start by confirming that the report names the correct legal entity and covers the systems, services, and delivery locations involved in the proposed engagement.
The review should also consider:
- The examination period
- Trust Services Criteria included
- Subservice organizations
- Control exceptions
- Management responses
- Subsequent events
- Complementary user-entity controls
Complementary user-entity controls are especially important because they identify safeguards the accounting firm may need to maintain.
For example, the provider may be responsible for securing its environment, while the accounting firm remains responsible for approving users, configuring permissions, reviewing access, and removing accounts.
A SOC 2 Type II report does not guarantee that an incident will never occur, and it does not cover systems or services outside its stated scope.
The AICPA SOC resource center provides further guidance on SOC reporting and the Trust Services Criteria.

Common Vendor-Evaluation Mistakes
A common mistake is approving a provider because it mentions encryption, VPNs, or SOC 2 on its website.
Those claims may be meaningful, but they do not explain which entity, people, systems, locations, and services are actually covered.
Other common gaps include giving wider access than necessary, overlooking subcontractors, failing to review complementary user-entity controls, allowing unapproved communication tools, and not documenting deletion and offboarding.
A provider may have a mature security program and still be unsuitable for a specific engagement if the actual delivery model does not meet the firm’s requirements.
Expert Insight
“Accounting firms should evaluate security at the level of the actual engagement. The review should confirm which entity, people, systems, locations, and controls will handle client information, rather than relying only on the provider’s marketing claims.“
Shivangi Agrawal
Managing Director, CA, CPA (USA), SafeBooks Global
How SafeBooks Supports Accounting Firms
SafeBooks provides offshore bookkeeping and accounting support for accounting firms, CPA firms, bookkeeping practices, EAs, and tax professionals.
Our professionals work within agreed systems, workflows, and access structures. Engagements can be designed around role-based permissions, approved software, controlled access, documented onboarding, and clear offboarding procedures.
SafeBooks Global Pvt. Ltd. has undergone a SOC 2 Type II examination across all five Trust Services Criteria:
- Security
- Availability
- Processing Integrity
- Confidentiality
- Privacy
The report is available to qualified prospects and customers under NDA as part of the vendor due-diligence process.
SafeBooks can also provide engagement-level information concerning delivery locations, access methods, workflows, and security responsibilities.
The accounting firm continues to control its WISP, risk assessment, access approvals, legal obligations, and vendor-monitoring process. SafeBooks supports those responsibilities through a structured delivery environment and relevant due-diligence evidence.
Accounting firms can learn more about how SafeBooks protects client financial data and review the questions to ask before hiring a remote accounting team.
Final Takeaway
Offshore accounting data security should be evaluated through evidence, scope, access, and ongoing oversight.
Accounting firms should understand exactly which entity, people, systems, locations, and controls will handle client information. They should also confirm how access is limited, how activity is monitored, how incidents are reported, and how the provider supports the firm’s WISP and vendor-management process.
A credible offshore provider should be able to answer these questions clearly and provide documentation that supports its claims.
Reviewing an offshore accounting provider?
Contact SafeBooks Global to discuss your access model, vendor-security questions, and due-diligence requirements. Qualified prospects can also request SafeBooks’ SOC 2 Type II report under NDA.
FAQS
Which country is best for accounting outsourcing?
Is India good for accounting outsourcing?
Is the Philippines good for accounting outsourcing?
Is Colombia good for accounting outsourcing?
Is SafeBooks SOC 2 compliant?
How should U.S. accounting firms compare outsourcing destinations?

Director (CA, CPA (USA))
Shivangi is a U.S.-certified CPA and Chartered Accountant with deep expertise in U.S. tax, financial reporting, and audit compliance. She has supported CPA and EA firms across sectors like real estate, SaaS, and healthcare. At SafeBooks, she leads global delivery, ensuring every remote accounting team meets U.S. standards with accuracy, discipline, and client-first execution.




