WISP Checklist for CPA Firms Outsourcing Tax and Accounting Work
Three months into an offshore accounting arrangement, a CPA firm received a call from a client.
The client had received a breach notification connected to the firm’s service provider.
The firm had a Written Information Security Plan, or WISP, but it had not been updated since it was approved. The Qualified Individual named in the document had left two years earlier. The vendor’s SOC 2 report had also been accepted without confirming whether the offshore tax preparation team was included in the audit scope.
The incident resulted in remediation work, internal disruption, and the loss of a client relationship.
The lesson was clear: a WISP that mentions third-party vendors but does not reflect how offshore work is actually performed provides limited protection.
CPA firms outsourcing bookkeeping, tax preparation, audit support, or back-office work need a WISP that covers vendor access, client information, contractual responsibilities, incident reporting, and ongoing review.
Key Takeaway
A WISP for a CPA firm should clearly document who owns the security program, which offshore providers can access client data, how that access is controlled and reviewed, whether vendor security reports cover the actual services being used, and how client consent, contracts, incident response, and annual updates are managed.
Start With Clear Ownership
A WISP needs a named person responsible for maintaining and overseeing the information security program.
The FTC Safeguards Rule refers to this person as the Qualified Individual. The individual may be an employee, an affiliate, or an external service provider, depending on the firm’s structure.
The WISP should identify the person by name and role. It should also describe their responsibilities, including vendor oversight, risk assessment, access reviews, incident response, and periodic reporting.
Before reviewing the rest of the document, confirm:
- The named Qualified Individual is still with the firm
- Their responsibilities are documented
- They have access to vendor contracts and security reports
- The latest WISP review has been recorded
A title such as “IT department” or “firm management” is not enough. Accountability should rest with a defined person.
Add Offshore Providers to the WISP Scope
Many WISPs include a general reference to third-party vendors. That does not provide enough detail for firms sharing taxpayer or financial information with remote teams.
Create a dedicated section for outsourced service providers. Record what each provider does, where the work is performed, and which information can be accessed.
WISP area | What the firm should document | Verification step |
Provider details | Legal name, service location, contact, and assigned function | Compare the list with accounts payable records |
Data access | SSNs, EINs, tax documents, bank records, payroll data, and financial statements | Review actual folders and systems available to the provider |
Authorized roles | Named users or defined job roles with access | Match users against current access logs |
Security controls | VDI or VPN access, MFA, encryption, permissions, and monitoring | Request current technical evidence |
Contract terms | Confidentiality, incident reporting, audit rights, and termination duties | Compare the contract with the WISP |
Client consent | Required consent or disclosure records | Test a sample of client files |
This vendor inventory should include every provider supporting remote bookkeeping, tax, audit, or back-office workflows.
Cloud access does not remove the need to assess the provider’s physical and operational controls. Firms should also understand clean-desk rules, visitor access, device restrictions, employee screening, and facility monitoring where relevant.
Restrict Access to What Each Team Member Needs
Offshore access should follow the principle of least privilege.
A remote professional working on one group of bookkeeping clients should not automatically receive access to the firm’s entire client database. Permissions should be assigned at the client, folder, application, or workflow level.
Important controls may include secure virtual desktop access, multifactor authentication, encrypted connections, restricted downloads, and activity logging.
The WISP should also define how access is approved, reviewed, changed, and removed.
A practical quarterly review should confirm:
- Users still require their assigned access
- No one has broad permissions without a documented reason
- Former team members have been removed
- Access to new clients has been approved
- Unusual downloads or login patterns have been investigated
SafeBooks Global explains these controls in its guide to offshore accounting data security and its overview of protecting client financial information.

Review the Vendor’s Security Evidence Carefully
A SOC 2 Type II report can support vendor due diligence, but the report should not be accepted based on the title alone.
Review the scope, testing period, systems covered, service locations, subservice providers, exceptions, and management responses.
The report may cover the vendor’s general technology environment without covering the accounting team, offshore location, or applications used for your engagement.
The Qualified Individual should confirm that the controls described in the report apply to the services the firm is purchasing.
When the provider does not have a relevant SOC 2 Type II report, the firm may need additional due diligence and compensating controls. These could include stronger access restrictions, independent security testing, contractual audit rights, and more frequent monitoring.
Use a structured offshore accounting partner evaluation rather than relying only on certifications or sales presentations.
Address Client Consent and Contract Terms
CPA firms outsourcing tax-related work should review whether taxpayer consent requirements apply before information is disclosed to a third party, particularly when information is shared outside the United States.
Generic wording stating that the firm “may use service providers” may not satisfy every requirement.
Consent language should clearly explain the nature of the disclosure, the purpose of the outsourcing arrangement, and the parties receiving the information when required.
Because the application and wording of Internal Revenue Code Section 7216 and related guidance can depend on the engagement, firms should have their consent process reviewed by qualified legal or tax counsel.
The vendor contract should also address:
- Permitted use of client information
- Confidentiality and employee NDAs
- Security and access requirements
- Incident notification procedures
- Cooperation during investigations
- Data return or destruction at termination
- Audit and evidence-request rights
- Use of subcontractors
A one-hour vendor notification requirement may be adopted as a firm risk-control standard, but it should be presented as a contractual expectation, not as a universal statutory deadline.
Firms can also use the questions to ask before hiring a remote accounting team to strengthen vendor discussions.
Make the WISP Part of Daily Operations
A WISP should change when the firm’s systems, vendors, workflows, or risks change.
Review the document at least annually and after material changes, such as adding a provider, assigning a new service, changing file-sharing platforms, or expanding access to additional client information.
Keep a signed review memo recording the review date, participants, changes, unresolved risks, owners, and remediation deadlines.
The WISP should align with the firm’s actual remote accounting workflow. If the workflow changes but the WISP does not, the security plan will no longer describe the real operating environment.
Expert Insight
“CPA firm should be able to connect every outsourced tax workflow to a documented consent process, an approved access path, and a named reviewer. A policy is useful only when those controls can be verified in the actual client file.“
Shivangi Agrawal
Managing Director, CA, CPA (USA), SafeBooks Global

Build Offshore Support Around Verifiable Controls
SafeBooks Global supports U.S. CPA and accounting firms through controlled remote workflows, role-based access, secure connections, documented responsibilities, and review-ready delivery.
The goal is not to replace the firm’s WISP or legal review. It is to provide an accounting support model that gives the firm clearer evidence for its security, access, and vendor oversight processes.
Explore SafeBooks Global’s offshore accounting services for CPA firms or schedule a discovery call to review how your outsourced workflows, access controls, and documentation should work together.
FAQS
How long does it take to update a WISP for offshore outsourcing?
Does every offshore accounting vendor need a SOC 2 Type II report?
Does a CPA firm need client consent before outsourcing tax work?
How often should offshore access be reviewed?
What should happen when an offshore team member leaves?

Director (CA, CPA (USA))
Shivangi is a U.S.-certified CPA and Chartered Accountant with deep expertise in U.S. tax, financial reporting, and audit compliance. She has supported CPA and EA firms across sectors like real estate, SaaS, and healthcare. At SafeBooks, she leads global delivery, ensuring every remote accounting team meets U.S. standards with accuracy, discipline, and client-first execution.




