Cleanup

Is Your Outsourcing Partner Safe With Client Data?

 ·  June 25, 2026  ·  7 min read

Key takeaways

  • When your firm outsources bookkeeping or tax prep, the duty to protect client confidentiality stays with you. A vendor breach becomes your firm’s liability, not theirs.
  • Ask for a SOC 2 Type II report, not Type I. Type I rates control design on one day; Type II tests whether those controls actually held over a 3-to-12-month window.
  • If the partner touches tax data, IRS Section 7216 requires the taxpayer’s prior written consent before that data is disclosed or used. A violation is a misdemeanor: up to a $1,000 fine and up to one year in prison.
  • The stakes are rising. Verizon’s 2025 report found third-party involvement in breaches doubled to 30%, and IBM put the 2025 U.S. average breach at $10.22 million, the highest of any region.

A CPA firm we spoke with last year had vetted an outsourcing partner on price, turnaround, and references, then signed. Six weeks in, a client asked a single question the firm could not answer: where, physically, does my tax data live, and who can see it? No one at the firm knew, because they had reviewed the work and never the controls. That gap is the one that quietly ends partnerships.

When your firm hands client records to an outside provider, you do not hand off the responsibility. Under the AICPA Code of Professional Conduct and most state board rules, the duty to protect client confidentiality stays with your firm. A vendor’s mistake becomes your firm’s liability.

So the question before you sign is not whether the partner can do the work. It is whether you can defend the relationship if a client, a regulator, or your malpractice carrier ever asks.

What is the difference between SOC 2 Type I and Type II?

A SOC 2 Type I report confirms the controls were designed correctly on a single date. A Type II report confirms those controls actually operated over a period of time, typically three to twelve months. Type II is the one that matters. It is the difference between a partner who drew up a sound security plan and one who proved they followed it for a year.

SOC 2 is an independent examination defined by the AICPA, measured against five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is the baseline; Confidentiality is the criterion most relevant to your clients’ records.

Ask for the report under NDA, not the badge on the website. Check that the period is recent, confirm which criteria it covers, and read the exceptions section. You want minor findings with a remediation plan, not a report that looks suspiciously spotless.

How should a partner protect data in transit and at rest?

Both. Encryption in transit protects data moving between your firm and the partner; encryption at rest protects the data sitting inside their systems. Both answers should come back as an immediate yes. Encryption is the floor, not the ceiling.

Then ask where the files actually live, because reputable cloud infrastructure carries its own security certifications and a shared drive nobody has audited in years does not. The exposure is measurable. Verizon’s 2025 Data Breach Investigations Report found the median time to remediate a leaked secret in a public code repository was 94 days. That is more than three months of open exposure.

When a partner treats these questions as a technicality, that reaction reveals how seriously security lives in the daily work rather than the sales deck.

Who on the partner’s team can see your clients’ files?

Fewer people than you would guess, in a well-run shop. Most real breaches are not sophisticated hacks; they happen when too many people hold access to too much. Verizon’s 2025 report found third-party involvement in confirmed breaches doubled from 15% to 30% in a single year, much of it through credential exposure and misconfigured systems at partners.

Ask how access is granted and removed. You want role-based access, where people see only what their job requires, multi-factor authentication on every account, and a documented process that cuts off access the day someone leaves.

If the partner offshores any part of the work, ask where the people touching the data are located and whether the same controls follow them there. Geography is not the issue; consistent controls everywhere the data travels is the issue.

What does IRS Section 7216 require for outsourced tax work?

If your firm prepares returns, IRS Section 7216 applies. It requires the taxpayer’s prior written consent before return information is disclosed to or used by a third party such as an outsourcing partner. This is not optional, and the penalty is criminal.

Under 26 CFR 301.7216-1, a knowing or reckless violation is a misdemeanor carrying a fine of up to $1,000, up to one year in prison, or both, per violation. A separate civil penalty under IRC 6713 adds $250 per improper disclosure, capped at $10,000 a year.

Your contract should reflect this. It needs a confidentiality clause and, ideally, a data processing agreement. That agreement should spell out what the partner may do with the data, what they may not, how long they keep it, and what happens when the engagement ends. A partner who knows exactly what Section 7216 means without you explaining it has handled regulated tax data before.

Separately, the FTC Safeguards Rule treats tax and accounting firms as financial institutions and requires a written information security program, including written contracts requiring service providers to protect customer information. Your vendor is one of those service providers.

The eight controls to vet before you sign

The diligence splits cleanly across eight controls, each paired below with the question to ask and the reason it matters. Run it as a checklist, and keep a short record of what you asked and what they answered. That file is cheap insurance if anyone ever questions the relationship.

ControlWhat to askWhy it matters
SOC 2 reportCan we review your SOC 2 Type II report under NDA?An independent auditor verified the controls held over time, not just on paper
EncryptionIs client data encrypted in transit and at rest?The baseline that protects data in motion and data at rest in their systems
Data locationWhere do the files physically live, and on what infrastructure?Certified cloud infrastructure beats an unaudited shared drive
Access controlsWho can see our files, and how is access granted and removed?Role-based access plus MFA is where most breaches are won or lost
Offshore controlsIf work is offshored, do the same controls apply there?Controls must follow the data wherever it travels
Section 7216 and contractHow do you handle Section 7216 consent and a data processing agreement?Tax data carries a criminal-penalty disclosure rule your firm owns
Data useDo you use our data to train models or build benchmarks?Anything beyond the work you hired them for needs to be in writing
Incident responseDo you carry cyber liability insurance and notify us within a set window?A partner who planned for the bad day is safer than one who insists it will not come
Sources: AICPA Trust Services Criteria; IRS Section 7216 (26 U.S.C. 7216); FTC Safeguards Rule.

Why does the partner’s posture tell you as much as the answers?

Because the posture is a preview of the relationship. A partner who treats your security questions as a welcome, expected part of diligence is showing you how they will steward your clients’ data after the contract is signed. A partner who turns impatient is signaling the opposite.

The cost of misjudging that is no longer abstract: IBM’s 2025 Cost of a Data Breach report put the U.S. average breach at $10.22 million, the highest of any region in the study.

In the engagements our senior controller Aaron Ressel runs, the firms that push hardest on security end up the easiest to serve, because the expectations are written down before the first file moves. When firms partner with us for white-label bookkeeping or white-label tax preparation, we would rather you push hard on the security conversation than skip it.

Every workflow runs through our Continuous Close Method™, documented into a Custom Playbook so the controls survive staff turnover and travel with the engagement, not with one person. As of 2026, that is the standard your clients should expect any partner to meet.

Questions firms ask before they outsource

Is SOC 2 Type I good enough, or do we need Type II?

Ask for Type II. A Type I report rates control design on a single day. A Type II report tests whether those controls operated over a three-to-twelve-month period, which is the evidence that the partner actually follows its own security plan. If a partner holds only a Type I, treat it as a starting point and ask when the Type II examination completes.

Do we need client consent to send tax data to an outsourcing partner?

Yes, in most cases. IRS Section 7216 requires the taxpayer’s prior written consent before a preparer discloses or uses return information through a third party. The penalty for a violation is a misdemeanor, up to $1,000 and up to one year in prison per violation. Build the consent into your engagement process, not as an afterthought once the work has already moved.

Who is liable if the outsourcing partner has a breach?

Your firm carries the duty to clients regardless of the vendor’s role. The AICPA Code of Professional Conduct and state board rules place confidentiality on the CPA, and the FTC Safeguards Rule requires you to bind service providers by written contract. A partner’s cyber liability insurance helps, but it does not transfer your professional obligation, which is why the vetting and the contract terms matter.

What if the partner offshores the work?

Offshoring is not the risk; inconsistent controls are. Ask where the people touching your clients’ data are located and whether role-based access, multi-factor authentication, and encryption apply equally to them. If the partner cannot describe how its controls follow the data offshore, treat that as a red flag.

Written by

Founding Partner & Senior Controller

Aaron leads quality assurance and oversight at Debit & Co. with 20 years building high-performing accounting teams. He reviews every client deliverable to ensure accuracy, GAAP compliance, and strategic value — turning good bookkeeping into Financial Clarity™.

LinkedIn →

More from Insights

  • Senior controller reviewing financial statements for period-cutoff and control gaps

    What a Controller Catches That a Bookkeeper Can’t

    Key takeaways A 12-person agency invoiced a client $90,000 in December for a project that finished in February. Cash arrived before year-end, so the bookkeeper booked it as December revenue. The books balanced. The bank reconciled. Nothing looked wrong. But December’s profit was overstated by $90,000. The next year started in a hole. When a…

    Read article

  • Calm minimalist horizon representing accurate, trustworthy financial reporting

    When ‘Good Enough’ Bookkeeping Starts Costing You

    Key takeaways A founder we met had a P&L showing a $42,000 profit for the quarter. The bank wanted accrual financials before extending a line. When we re-cut the same QuickBooks Online file on an accrual basis, that profit became an $18,000 loss. Nothing was late. Every account reconciled. The books were “done,” and also…

    Read article

  • An accountant reviewing stale financial records that have fallen months behind

    The Hidden Cost of Running QuickBooks Behind

    Key takeaways The median small business in America holds 27 days of cash. That figure comes from JPMorgan Chase Institute, which read 470 million transactions across 597,000 firms. Run that 27-day margin while your QuickBooks file is three months stale, and you are making payroll calls, pricing calls, and hiring calls against numbers that describe…

    Read article

Ready for Financial Clarity™?

Book a 30-minute discovery call. Tell us your situation, we’ll be honest about fit, and you get a custom proposal in 48 hours.