US CPA Firms · Cross-border Practice

When a US CPA firm moves bookkeeping to India, its IT lead asks one question first: where does client data go, who can see it, and what do we show if something goes wrong? The answer starts with your own obligations, not a vendor brochure. Under the FTC Safeguards Rule, an offshore team is a "service provider" inside your security program. Under IRC section 7216, a preparer in India falls outside the US auxiliary-services exception. Under the AICPA Code, the client must be told before data moves. This article maps each rule to a control and the evidence to keep on file.

TL;DR
  • An offshore team with access to client data is a service provider under 16 CFR 314.2. Your WISP must cover it: select, contract, reassess (314.4(f)).
  • Classify data in three tiers: tax return information, other client financial data and firm-only data.
  • Disclosure to a preparer in India needs written s.7216 consent. The auxiliary-services exception in 301.7216-2(d) covers only preparers located in the United States.
  • The Safeguards Rule does not require SOC 2. It is one form of evidence among several.
  • Two breach clocks run: your FTC notice (30 days, 500+ consumers) and the Indian provider's CERT-In report (6 hours). Your contract must link them.
  • Firms with fewer than 5,000 consumers get relief from four elements only (314.6). Encryption, MFA and provider oversight still apply.

1. Why the offshore team sits inside your WISP

The IRS and the Security Summit reminded practitioners in IR-2025-79 (29 July 2025) that tax and accounting professionals are financial institutions under the Gramm-Leach-Bliley Act and must keep a written information security plan (WISP). The FTC Safeguards Rule, 16 CFR Part 314, sets out what that plan must contain.

The rule defines a service provider as any person or entity that receives, maintains, processes or is otherwise permitted access to customer information through services provided directly to the financial institution. A team in India that logs in to your clients' QuickBooks Online files meets it on day one, even if it never downloads a file. Section 314.4(f) then gives you three duties:

  1. Select and retain providers capable of appropriate safeguards.
  2. Require the provider, by contract, to implement and maintain those safeguards.
  3. Periodically assess the provider based on its risk.

Responsibility stays with your firm. The offshore relationship is a standing WISP entry with its own risk rating, contract terms and review date, not a one-time procurement sign-off.

2. Three data tiers and how each travels

Treating all client data the same causes most confusion. Three tiers are enough.

TierExamplesGoverning rulesOffshore handling
1. Tax return informationReturn workpapers, organizers, prior-year returnsIRC s.7216; Treas. Reg. 301.7216-2, -3; Rev. Proc. 2013-14Written consent on a separate document, signed and dated before disclosure. SSNs of 1040 filers masked unless both sides meet the Rev. Proc. 2013-14 safeguard standard. Consent without a stated term lapses after one year
2. Other client financial dataBank feeds, bills, invoices and ledgers for monthly bookkeeping and closeFTC Safeguards Rule; AICPA ET 1.150.040 and 1.700.040; state privacy and breach lawsEngagement-letter disclosure plus a confidentiality contract with the provider. Access through your systems with MFA
3. Firm-only dataStaff records, billing, other clients' files, internal credentialsYour WISP; employment and privacy lawNo offshore access. Segregate folders and ledger subscriptions so the team cannot reach them

A ledger coded for monthly financials is often outside s.7216; once pulled into 1120-S workpapers, it can fall inside. Our CPA firm's guide to outsourcing bookkeeping to India explains why most firms start with tier 2 work only. Write down which files are tier 1 and keep offshore permissions away from them until consents are signed.

3. The 16 CFR 314.4 control map for an offshore engagement

Each Safeguards Rule element, read for an offshore engagement, with the evidence to keep in your oversight file.

ElementWhat the rule requiresEvidence
314.4(a) Qualified IndividualOne person oversees the program; the firm stays responsibleNamed contact in the contract
314.4(b) Risk assessmentWritten assessment of internal and external risks, re-examined periodicallyRisk register entry with a rating
314.4(c)(1) Access controlsAuthenticate users; limit access to what each needsUser list per client file, reviewed monthly
314.4(c)(3) EncryptionEncrypt customer information in transit over external networks and at restProvider's encryption policy; device inventory
314.4(c)(5) MFAMulti-factor authentication for anyone accessing an information systemScreenshot or admin report of MFA status
314.4(c)(6) DisposalDispose of customer information no later than two years after last use, unless still needed for business purposes or required by lawContract clause plus a written destruction confirmation
314.4(c)(8) LoggingMonitor and log authorized users' activityLedger audit log; portal access log
314.4(d)(2) TestingAnnual penetration test and vulnerability assessments at least every six months (unless continuous monitoring)Test reports and remediation notes
314.4(e) TrainingSecurity awareness training for personnelAttendance record with dates
314.4(f) Service providersSelect, contract, periodically assessQuestionnaire, contract, annual review memo
314.4(h) Incident responseWritten plan: roles, communications, remediation, documentationPlan with provider contact tree
314.4(j) FTC noticeNotify the FTC within 30 days of discovering a notification event involving 500+ consumersContract notice clause (see section 6)

Small-firm relief is narrower than many assume. Under 16 CFR 314.6, a firm that maintains customer information on fewer than 5,000 consumers is exempt from only four items: the written risk assessment (314.4(b)(1)), the testing schedule (314.4(d)(2)), the written incident response plan (314.4(h)) and the annual board report (314.4(i)). Encryption, MFA, access controls, training and service-provider oversight apply at any size.

4. SOC 2 and the other evidence you can rely on

A SOC 2 report is a licensed CPA firm's examination of a service organization's controls against the AICPA Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy). Type 1 covers control design at a date; Type 2 also tests operating effectiveness over a period.

The Safeguards Rule does not require SOC 2, and many smaller offshore providers, including Indian CA firms, do not hold one. Your file must support the judgment you made. The options, in order of assurance:

EvidenceWhat it tells youLimits
SOC 2 Type 2 reportIndependent testing of controls over a periodRead the scope, exceptions and complementary user-entity controls
SOC 2 Type 1 reportIndependent view of control design at one dateSays nothing about whether controls ran all year
ISO/IEC 27001 certificateA certified information security management systemCheck the scope covers the delivery site
Security questionnaire plus policy setThe provider's own description of its controlsSelf-reported; add a screen-share walkthrough and sample logs
Your own testingDirect evidence: MFA status, user lists, audit logs from your ledgersCovers only your own systems

For SSNs of 1040 filers, the bar is set separately. Rev. Proc. 2013-14 defines an "adequate data protection safeguard" as a management-approved and implemented security program with administrative, technical and physical safeguards, conforming to one of the frameworks it lists (including the AICPA/CICA Privacy Framework and IRS Publication 1075). Both the US preparer and the offshore preparer must meet it. If you cannot document that for both sides, mask the SSN.

5. Access architecture: keep data in your systems

The first control is design: the offshore team works inside systems your firm or client controls, so data need not leave them. A well-run offshore engagement should look like this:

  • Cloud ledgers with named users. Each offshore staff member gets a named login in the client's QuickBooks Online or Xero file, with the narrowest role that allows the work. No shared "bookkeeper" logins.
  • Documents through your portal, not email attachments.
  • No local copies. Where files must be opened, a virtual desktop or browser-only workspace keeps them off the provider's devices. Where that is not in place, a written rule on local storage, with device encryption, is the minimum.
  • Tier 1 data walled off. Tax software and return workpapers sit outside the offshore team's permissions until s.7216 consents are signed.
  • Same-day offboarding. When someone leaves the provider's team, every login is removed that day. Ask for the leaver notice in the contract.
  • Monthly user review. Compare each ledger's user list with the provider's roster.

6. Incident response across two jurisdictions

A security event at an Indian provider sets two separate clocks running.

DutyWhoTriggerDeadline
FTC notification, 16 CFR 314.4(j)Your firmUnauthorized acquisition of unencrypted customer information involving 500 or more consumersAs soon as possible, and no later than 30 days after discovery
IRS contactYour firmData theft affecting taxpayer dataPromptly, through your IRS Stakeholder Liaison, as the IRS recommends
State breach lawsYour firmDepends on residents' statesVaries by state
CERT-In Directions of 28 April 2022The Indian providerCyber incidents listed in Annexure IWithin 6 hours of noticing
CERT-In log retentionThe Indian providerStanding requirementLogs of ICT systems kept for a rolling 180 days within India

The risk: the provider reports to CERT-In within hours but tells you days later. Your contract should require notice to your Qualified Individual within a short fixed window (24 hours is a common choice), cooperation with your investigation, and access to the relevant logs. India's DPDP Rules, 2025 (notified 14 November 2025, phased over 18 months) will add Indian-side duties, but your contract is what makes the provider answer to you.

7. Worked example: an annual oversight file

Facts (illustrative). A 9-person Texas CPA firm holds data on about 3,400 individuals. An India-based team does monthly bookkeeping on 40 QuickBooks Online clients. Returns stay in-house.

Step 1: size the obligations. 3,400 consumers is under the 314.6 threshold, so four elements drop away. Section 314.4(c) (access, encryption, MFA, disposal, logging), (e) training and (f) provider oversight still apply.

Step 2: classify. The 40 bookkeeping files are tier 2. The tax software and return workpapers are tier 1 and are excluded from the offshore team's access. No s.7216 consent is needed for the current scope.

Step 3: build the file.

DocumentRule it supportsReview
Engagement-letter clause sent to all 40 clientsET 1.150.040At each renewal
Confidentiality agreement / MSA with security scheduleET 1.700.040; 314.4(f)(2)Annually
Completed security questionnaire and walkthrough notes314.4(f)(1)Annually
Monthly ledger user-list reconciliation (12 sign-offs)314.4(c)(1), (c)(8)Monthly
MFA status report for all offshore users314.4(c)(5)Quarterly
Training attendance for offshore staff314.4(e)Annually and at onboarding
Annual provider assessment memo with rating314.4(f)(3)Annually

Result. Seven short documents cover the relationship. Adding return preparation later means signed s.7216 consents, a masking procedure and a re-rating before tier 1 data moves.

8. Contract clause checklist

Before live client data moves, the contract with the offshore provider should cover each point below.

  • Confidentiality of all client information, surviving termination (ET 1.700.040).
  • Security schedule mapped to 314.4(c): named access, MFA, encryption, logging.
  • Data location, and no personal devices or personal email.
  • No subcontracting without your written approval.
  • Incident notice to your Qualified Individual within a fixed window, with cooperation and log access.
  • Same-day removal of access for leavers, with notice to you.
  • Return or destruction of data at exit, confirmed in writing.
  • Your right to assess, at least annually.
  • For tier 1 work: use limited to the signed s.7216 consent, and SSNs masked.

9. Frequently asked questions

Is an offshore bookkeeping team a service provider under the FTC Safeguards Rule?

Yes, if it receives, processes or is permitted access to customer information through services to your firm (16 CFR 314.2). Section 314.4(f) then requires you to select capable providers, require safeguards by contract and assess them periodically.

Does the Safeguards Rule require our offshore provider to have a SOC 2 report?

No. It requires reasonable selection steps, contractual safeguards and periodic assessment. A SOC 2 Type 2 report is strong evidence; without one, a documented questionnaire, policy review and control walkthrough can support your file.

Can we send tax return information to India without client consent?

Generally no. The auxiliary-services exception in Treas. Reg. 301.7216-2(d) covers only preparers located in the United States. Disclosure to a preparer abroad needs written consent under 301.7216-3, signed before disclosure.

Can client SSNs be shared with the offshore team?

For Form 1040 series filers, 301.7216-3(b)(4) requires the SSN to be masked before it goes to a preparer outside the US, unless both preparers maintain an adequate data protection safeguard under Rev. Proc. 2013-14. Bookkeeping rarely needs SSNs, so mask them.

We have fewer than 5,000 clients. Which Safeguards Rule elements still apply?

Section 314.6 removes only the written risk assessment, the testing schedule, the written incident response plan and the annual board report. Access controls, encryption, MFA, training and provider oversight still apply.

Who reports a breach at the offshore provider?

Your firm notifies the FTC within 30 days of discovering a notification event involving 500 or more consumers. The Indian provider reports specified incidents to CERT-In within 6 hours. Your contract should require prompt notice to you.

What should the engagement letter say about offshore work?

AICPA ET 1.150.040 requires you to inform the client, preferably in writing, that a third-party provider may be used before confidential information is shared. State that a provider outside the US may be used and that safeguards are required by contract.

How often should we reassess the offshore provider?

Section 314.4(f)(3) requires periodic assessment based on risk. Annually, and whenever the provider changes systems, subcontractors or staff with access, is a reasonable cadence.

10. Sources

Planning an offshore bookkeeping engagement and building the oversight file first?

Somesh Chandak & Associates, Chartered Accountants (FRN 158694W), Thane, supports accounting firms abroad with bookkeeping, reconciliations and month-end close on QuickBooks Online and Xero. We can walk through scope, access design and the documents your firm will want in place before any client data moves.

Outsourced Bookkeeping for Foreign Firms Talk to us

This article is for general information for accounting professionals and is not legal, tax, data-protection or cybersecurity advice. Federal, state and Indian requirements depend on facts and change over time. Confirm your position with your own counsel and IT security adviser before sharing client data with any third party.