WISP Checklist for CPA Firms Using Offshore Support

WISP Checklist for CPA Firms Using Offshore Support
Table of Contents
Share This Article

WISP Checklist for CPA Firms Outsourcing Tax and Accounting Work

Three months into an offshore accounting arrangement, a CPA firm received a call from a client.

The client had received a breach notification connected to the firm’s service provider.

The firm had a Written Information Security Plan, or WISP, but it had not been updated since it was approved. The Qualified Individual named in the document had left two years earlier. The vendor’s SOC 2 report had also been accepted without confirming whether the offshore tax preparation team was included in the audit scope.

The incident resulted in remediation work, internal disruption, and the loss of a client relationship.

The lesson was clear: a WISP that mentions third-party vendors but does not reflect how offshore work is actually performed provides limited protection.

CPA firms outsourcing bookkeeping, tax preparation, audit support, or back-office work need a WISP that covers vendor access, client information, contractual responsibilities, incident reporting, and ongoing review.

Key Takeaway

A WISP for a CPA firm should clearly document who owns the security program, which offshore providers can access client data, how that access is controlled and reviewed, whether vendor security reports cover the actual services being used, and how client consent, contracts, incident response, and annual updates are managed.

Start With Clear Ownership

A WISP needs a named person responsible for maintaining and overseeing the information security program.

The FTC Safeguards Rule refers to this person as the Qualified Individual. The individual may be an employee, an affiliate, or an external service provider, depending on the firm’s structure.

The WISP should identify the person by name and role. It should also describe their responsibilities, including vendor oversight, risk assessment, access reviews, incident response, and periodic reporting.

Before reviewing the rest of the document, confirm:

  • The named Qualified Individual is still with the firm
  • Their responsibilities are documented
  • They have access to vendor contracts and security reports
  • The latest WISP review has been recorded

A title such as “IT department” or “firm management” is not enough. Accountability should rest with a defined person.

Add Offshore Providers to the WISP Scope

Many WISPs include a general reference to third-party vendors. That does not provide enough detail for firms sharing taxpayer or financial information with remote teams.

Create a dedicated section for outsourced service providers. Record what each provider does, where the work is performed, and which information can be accessed.

WISP area

What the firm should document

Verification step

Provider details

Legal name, service location, contact, and assigned function

Compare the list with accounts payable records

Data access

SSNs, EINs, tax documents, bank records, payroll data, and financial statements

Review actual folders and systems available to the provider

Authorized roles

Named users or defined job roles with access

Match users against current access logs

Security controls

VDI or VPN access, MFA, encryption, permissions, and monitoring

Request current technical evidence

Contract terms

Confidentiality, incident reporting, audit rights, and termination duties

Compare the contract with the WISP

Client consent

Required consent or disclosure records

Test a sample of client files

This vendor inventory should include every provider supporting remote bookkeeping, tax, audit, or back-office workflows.

Cloud access does not remove the need to assess the provider’s physical and operational controls. Firms should also understand clean-desk rules, visitor access, device restrictions, employee screening, and facility monitoring where relevant.

Restrict Access to What Each Team Member Needs

Offshore access should follow the principle of least privilege.

A remote professional working on one group of bookkeeping clients should not automatically receive access to the firm’s entire client database. Permissions should be assigned at the client, folder, application, or workflow level.

Important controls may include secure virtual desktop access, multifactor authentication, encrypted connections, restricted downloads, and activity logging.

The WISP should also define how access is approved, reviewed, changed, and removed.

A practical quarterly review should confirm:

  • Users still require their assigned access
  • No one has broad permissions without a documented reason
  • Former team members have been removed
  • Access to new clients has been approved
  • Unusual downloads or login patterns have been investigated

SafeBooks Global explains these controls in its guide to offshore accounting data security and its overview of protecting client financial information.

WISP Checklist for CPA Firms Outsourcing Tax and Accounting Work

Review the Vendor’s Security Evidence Carefully

A SOC 2 Type II report can support vendor due diligence, but the report should not be accepted based on the title alone.

Review the scope, testing period, systems covered, service locations, subservice providers, exceptions, and management responses.

The report may cover the vendor’s general technology environment without covering the accounting team, offshore location, or applications used for your engagement.

The Qualified Individual should confirm that the controls described in the report apply to the services the firm is purchasing.

When the provider does not have a relevant SOC 2 Type II report, the firm may need additional due diligence and compensating controls. These could include stronger access restrictions, independent security testing, contractual audit rights, and more frequent monitoring.

Use a structured offshore accounting partner evaluation rather than relying only on certifications or sales presentations.

Address Client Consent and Contract Terms

CPA firms outsourcing tax-related work should review whether taxpayer consent requirements apply before information is disclosed to a third party, particularly when information is shared outside the United States.

Generic wording stating that the firm “may use service providers” may not satisfy every requirement.

Consent language should clearly explain the nature of the disclosure, the purpose of the outsourcing arrangement, and the parties receiving the information when required.

Because the application and wording of Internal Revenue Code Section 7216 and related guidance can depend on the engagement, firms should have their consent process reviewed by qualified legal or tax counsel.

The vendor contract should also address:

  • Permitted use of client information
  • Confidentiality and employee NDAs
  • Security and access requirements
  • Incident notification procedures
  • Cooperation during investigations
  • Data return or destruction at termination
  • Audit and evidence-request rights
  • Use of subcontractors

A one-hour vendor notification requirement may be adopted as a firm risk-control standard, but it should be presented as a contractual expectation, not as a universal statutory deadline.

Firms can also use the questions to ask before hiring a remote accounting team to strengthen vendor discussions.

Make the WISP Part of Daily Operations

A WISP should change when the firm’s systems, vendors, workflows, or risks change.

Review the document at least annually and after material changes, such as adding a provider, assigning a new service, changing file-sharing platforms, or expanding access to additional client information.

Keep a signed review memo recording the review date, participants, changes, unresolved risks, owners, and remediation deadlines.

The WISP should align with the firm’s actual remote accounting workflow. If the workflow changes but the WISP does not, the security plan will no longer describe the real operating environment.

Expert Insight

“CPA firm should be able to connect every outsourced tax workflow to a documented consent process, an approved access path, and a named reviewer. A policy is useful only when those controls can be verified in the actual client file.

Shivangi Agrawal
Managing Director, CA, CPA (USA), SafeBooks Global

Build Offshore Support Around Verifiable Controls

Build Offshore Support Around Verifiable Controls

SafeBooks Global supports U.S. CPA and accounting firms through controlled remote workflows, role-based access, secure connections, documented responsibilities, and review-ready delivery.

The goal is not to replace the firm’s WISP or legal review. It is to provide an accounting support model that gives the firm clearer evidence for its security, access, and vendor oversight processes.

Explore SafeBooks Global’s offshore accounting services for CPA firms or schedule a discovery call to review how your outsourced workflows, access controls, and documentation should work together.

FAQS

How long does it take to update a WISP for offshore outsourcing?
The timeline depends on the number of providers, systems, and workflows involved. Reviewing vendor evidence, contracts, access permissions, and consent records often requires more time than editing the policy itself.
A SOC 2 Type II report is not the only way to evaluate a provider, but it can provide useful evidence. Firms should review whether its scope covers the actual services, systems, and locations used.
Consent may be required when taxpayer information is disclosed to third parties, especially outside the United States. Firms should confirm the correct process and wording with qualified legal or tax counsel.
Quarterly access reviews are a practical minimum for many firms. Access should also be reviewed immediately after staff changes, service changes, or unusual security activity.
The provider should notify the firm promptly, remove access, recover or disable devices, confirm that information was not retained, and document the handoff to any replacement team member.
  • Director (CA, CPA (USA))

    Shivangi is a U.S.-certified CPA and Chartered Accountant with deep expertise in U.S. tax, financial reporting, and audit compliance. She has supported CPA and EA firms across sectors like real estate, SaaS, and healthcare. At SafeBooks, she leads global delivery, ensuring every remote accounting team meets U.S. standards with accuracy, discipline, and client-first execution.

Related Blogs

Ready to Build a Smarter Accounting Team?

Let’s simplify your operations with secure, scalable, and U.S.-aligned remote staffing.