When a US CPA firm moves bookkeeping to India, its IT lead asks one question first: where does client data go, who can see it, and what do we show if something goes wrong? The answer starts with your own obligations, not a vendor brochure. Under the FTC Safeguards Rule, an offshore team is a "service provider" inside your security program. Under IRC section 7216, a preparer in India falls outside the US auxiliary-services exception. Under the AICPA Code, the client must be told before data moves. This article maps each rule to a control and the evidence to keep on file.
- An offshore team with access to client data is a service provider under 16 CFR 314.2. Your WISP must cover it: select, contract, reassess (314.4(f)).
- Classify data in three tiers: tax return information, other client financial data and firm-only data.
- Disclosure to a preparer in India needs written s.7216 consent. The auxiliary-services exception in 301.7216-2(d) covers only preparers located in the United States.
- The Safeguards Rule does not require SOC 2. It is one form of evidence among several.
- Two breach clocks run: your FTC notice (30 days, 500+ consumers) and the Indian provider's CERT-In report (6 hours). Your contract must link them.
- Firms with fewer than 5,000 consumers get relief from four elements only (314.6). Encryption, MFA and provider oversight still apply.
1. Why the offshore team sits inside your WISP
The IRS and the Security Summit reminded practitioners in IR-2025-79 (29 July 2025) that tax and accounting professionals are financial institutions under the Gramm-Leach-Bliley Act and must keep a written information security plan (WISP). The FTC Safeguards Rule, 16 CFR Part 314, sets out what that plan must contain.
The rule defines a service provider as any person or entity that receives, maintains, processes or is otherwise permitted access to customer information through services provided directly to the financial institution. A team in India that logs in to your clients' QuickBooks Online files meets it on day one, even if it never downloads a file. Section 314.4(f) then gives you three duties:
- Select and retain providers capable of appropriate safeguards.
- Require the provider, by contract, to implement and maintain those safeguards.
- Periodically assess the provider based on its risk.
Responsibility stays with your firm. The offshore relationship is a standing WISP entry with its own risk rating, contract terms and review date, not a one-time procurement sign-off.
2. Three data tiers and how each travels
Treating all client data the same causes most confusion. Three tiers are enough.
| Tier | Examples | Governing rules | Offshore handling |
|---|---|---|---|
| 1. Tax return information | Return workpapers, organizers, prior-year returns | IRC s.7216; Treas. Reg. 301.7216-2, -3; Rev. Proc. 2013-14 | Written consent on a separate document, signed and dated before disclosure. SSNs of 1040 filers masked unless both sides meet the Rev. Proc. 2013-14 safeguard standard. Consent without a stated term lapses after one year |
| 2. Other client financial data | Bank feeds, bills, invoices and ledgers for monthly bookkeeping and close | FTC Safeguards Rule; AICPA ET 1.150.040 and 1.700.040; state privacy and breach laws | Engagement-letter disclosure plus a confidentiality contract with the provider. Access through your systems with MFA |
| 3. Firm-only data | Staff records, billing, other clients' files, internal credentials | Your WISP; employment and privacy law | No offshore access. Segregate folders and ledger subscriptions so the team cannot reach them |
A ledger coded for monthly financials is often outside s.7216; once pulled into 1120-S workpapers, it can fall inside. Our CPA firm's guide to outsourcing bookkeeping to India explains why most firms start with tier 2 work only. Write down which files are tier 1 and keep offshore permissions away from them until consents are signed.
3. The 16 CFR 314.4 control map for an offshore engagement
Each Safeguards Rule element, read for an offshore engagement, with the evidence to keep in your oversight file.
| Element | What the rule requires | Evidence |
|---|---|---|
| 314.4(a) Qualified Individual | One person oversees the program; the firm stays responsible | Named contact in the contract |
| 314.4(b) Risk assessment | Written assessment of internal and external risks, re-examined periodically | Risk register entry with a rating |
| 314.4(c)(1) Access controls | Authenticate users; limit access to what each needs | User list per client file, reviewed monthly |
| 314.4(c)(3) Encryption | Encrypt customer information in transit over external networks and at rest | Provider's encryption policy; device inventory |
| 314.4(c)(5) MFA | Multi-factor authentication for anyone accessing an information system | Screenshot or admin report of MFA status |
| 314.4(c)(6) Disposal | Dispose of customer information no later than two years after last use, unless still needed for business purposes or required by law | Contract clause plus a written destruction confirmation |
| 314.4(c)(8) Logging | Monitor and log authorized users' activity | Ledger audit log; portal access log |
| 314.4(d)(2) Testing | Annual penetration test and vulnerability assessments at least every six months (unless continuous monitoring) | Test reports and remediation notes |
| 314.4(e) Training | Security awareness training for personnel | Attendance record with dates |
| 314.4(f) Service providers | Select, contract, periodically assess | Questionnaire, contract, annual review memo |
| 314.4(h) Incident response | Written plan: roles, communications, remediation, documentation | Plan with provider contact tree |
| 314.4(j) FTC notice | Notify the FTC within 30 days of discovering a notification event involving 500+ consumers | Contract notice clause (see section 6) |
Small-firm relief is narrower than many assume. Under 16 CFR 314.6, a firm that maintains customer information on fewer than 5,000 consumers is exempt from only four items: the written risk assessment (314.4(b)(1)), the testing schedule (314.4(d)(2)), the written incident response plan (314.4(h)) and the annual board report (314.4(i)). Encryption, MFA, access controls, training and service-provider oversight apply at any size.
4. SOC 2 and the other evidence you can rely on
A SOC 2 report is a licensed CPA firm's examination of a service organization's controls against the AICPA Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy). Type 1 covers control design at a date; Type 2 also tests operating effectiveness over a period.
The Safeguards Rule does not require SOC 2, and many smaller offshore providers, including Indian CA firms, do not hold one. Your file must support the judgment you made. The options, in order of assurance:
| Evidence | What it tells you | Limits |
|---|---|---|
| SOC 2 Type 2 report | Independent testing of controls over a period | Read the scope, exceptions and complementary user-entity controls |
| SOC 2 Type 1 report | Independent view of control design at one date | Says nothing about whether controls ran all year |
| ISO/IEC 27001 certificate | A certified information security management system | Check the scope covers the delivery site |
| Security questionnaire plus policy set | The provider's own description of its controls | Self-reported; add a screen-share walkthrough and sample logs |
| Your own testing | Direct evidence: MFA status, user lists, audit logs from your ledgers | Covers only your own systems |
For SSNs of 1040 filers, the bar is set separately. Rev. Proc. 2013-14 defines an "adequate data protection safeguard" as a management-approved and implemented security program with administrative, technical and physical safeguards, conforming to one of the frameworks it lists (including the AICPA/CICA Privacy Framework and IRS Publication 1075). Both the US preparer and the offshore preparer must meet it. If you cannot document that for both sides, mask the SSN.
5. Access architecture: keep data in your systems
The first control is design: the offshore team works inside systems your firm or client controls, so data need not leave them. A well-run offshore engagement should look like this:
- Cloud ledgers with named users. Each offshore staff member gets a named login in the client's QuickBooks Online or Xero file, with the narrowest role that allows the work. No shared "bookkeeper" logins.
- Documents through your portal, not email attachments.
- No local copies. Where files must be opened, a virtual desktop or browser-only workspace keeps them off the provider's devices. Where that is not in place, a written rule on local storage, with device encryption, is the minimum.
- Tier 1 data walled off. Tax software and return workpapers sit outside the offshore team's permissions until s.7216 consents are signed.
- Same-day offboarding. When someone leaves the provider's team, every login is removed that day. Ask for the leaver notice in the contract.
- Monthly user review. Compare each ledger's user list with the provider's roster.
6. Incident response across two jurisdictions
A security event at an Indian provider sets two separate clocks running.
| Duty | Who | Trigger | Deadline |
|---|---|---|---|
| FTC notification, 16 CFR 314.4(j) | Your firm | Unauthorized acquisition of unencrypted customer information involving 500 or more consumers | As soon as possible, and no later than 30 days after discovery |
| IRS contact | Your firm | Data theft affecting taxpayer data | Promptly, through your IRS Stakeholder Liaison, as the IRS recommends |
| State breach laws | Your firm | Depends on residents' states | Varies by state |
| CERT-In Directions of 28 April 2022 | The Indian provider | Cyber incidents listed in Annexure I | Within 6 hours of noticing |
| CERT-In log retention | The Indian provider | Standing requirement | Logs of ICT systems kept for a rolling 180 days within India |
The risk: the provider reports to CERT-In within hours but tells you days later. Your contract should require notice to your Qualified Individual within a short fixed window (24 hours is a common choice), cooperation with your investigation, and access to the relevant logs. India's DPDP Rules, 2025 (notified 14 November 2025, phased over 18 months) will add Indian-side duties, but your contract is what makes the provider answer to you.
7. Worked example: an annual oversight file
Facts (illustrative). A 9-person Texas CPA firm holds data on about 3,400 individuals. An India-based team does monthly bookkeeping on 40 QuickBooks Online clients. Returns stay in-house.
Step 1: size the obligations. 3,400 consumers is under the 314.6 threshold, so four elements drop away. Section 314.4(c) (access, encryption, MFA, disposal, logging), (e) training and (f) provider oversight still apply.
Step 2: classify. The 40 bookkeeping files are tier 2. The tax software and return workpapers are tier 1 and are excluded from the offshore team's access. No s.7216 consent is needed for the current scope.
Step 3: build the file.
| Document | Rule it supports | Review |
|---|---|---|
| Engagement-letter clause sent to all 40 clients | ET 1.150.040 | At each renewal |
| Confidentiality agreement / MSA with security schedule | ET 1.700.040; 314.4(f)(2) | Annually |
| Completed security questionnaire and walkthrough notes | 314.4(f)(1) | Annually |
| Monthly ledger user-list reconciliation (12 sign-offs) | 314.4(c)(1), (c)(8) | Monthly |
| MFA status report for all offshore users | 314.4(c)(5) | Quarterly |
| Training attendance for offshore staff | 314.4(e) | Annually and at onboarding |
| Annual provider assessment memo with rating | 314.4(f)(3) | Annually |
Result. Seven short documents cover the relationship. Adding return preparation later means signed s.7216 consents, a masking procedure and a re-rating before tier 1 data moves.
8. Contract clause checklist
Before live client data moves, the contract with the offshore provider should cover each point below.
- Confidentiality of all client information, surviving termination (ET 1.700.040).
- Security schedule mapped to 314.4(c): named access, MFA, encryption, logging.
- Data location, and no personal devices or personal email.
- No subcontracting without your written approval.
- Incident notice to your Qualified Individual within a fixed window, with cooperation and log access.
- Same-day removal of access for leavers, with notice to you.
- Return or destruction of data at exit, confirmed in writing.
- Your right to assess, at least annually.
- For tier 1 work: use limited to the signed s.7216 consent, and SSNs masked.
9. Frequently asked questions
Is an offshore bookkeeping team a service provider under the FTC Safeguards Rule?
Yes, if it receives, processes or is permitted access to customer information through services to your firm (16 CFR 314.2). Section 314.4(f) then requires you to select capable providers, require safeguards by contract and assess them periodically.
Does the Safeguards Rule require our offshore provider to have a SOC 2 report?
No. It requires reasonable selection steps, contractual safeguards and periodic assessment. A SOC 2 Type 2 report is strong evidence; without one, a documented questionnaire, policy review and control walkthrough can support your file.
Can we send tax return information to India without client consent?
Generally no. The auxiliary-services exception in Treas. Reg. 301.7216-2(d) covers only preparers located in the United States. Disclosure to a preparer abroad needs written consent under 301.7216-3, signed before disclosure.
Can client SSNs be shared with the offshore team?
For Form 1040 series filers, 301.7216-3(b)(4) requires the SSN to be masked before it goes to a preparer outside the US, unless both preparers maintain an adequate data protection safeguard under Rev. Proc. 2013-14. Bookkeeping rarely needs SSNs, so mask them.
We have fewer than 5,000 clients. Which Safeguards Rule elements still apply?
Section 314.6 removes only the written risk assessment, the testing schedule, the written incident response plan and the annual board report. Access controls, encryption, MFA, training and provider oversight still apply.
Who reports a breach at the offshore provider?
Your firm notifies the FTC within 30 days of discovering a notification event involving 500 or more consumers. The Indian provider reports specified incidents to CERT-In within 6 hours. Your contract should require prompt notice to you.
What should the engagement letter say about offshore work?
AICPA ET 1.150.040 requires you to inform the client, preferably in writing, that a third-party provider may be used before confidential information is shared. State that a provider outside the US may be used and that safeguards are required by contract.
How often should we reassess the offshore provider?
Section 314.4(f)(3) requires periodic assessment based on risk. Annually, and whenever the provider changes systems, subcontractors or staff with access, is a reasonable cadence.
10. Sources
- FTC Safeguards Rule, 16 CFR Part 314: ecfr.gov
- Treas. Reg. 301.7216-2: ecfr.gov
- Treas. Reg. 301.7216-3: ecfr.gov
- Rev. Proc. 2013-14: irs.gov/pub/irs-drop/rp-13-14.pdf
- IRS IR-2025-79, WISP reminder, Publications 5708 and 4557: irs.gov newsroom
- AICPA SOC 2 and Trust Services Criteria: aicpa-cima.com
- AICPA Code ET 1.150.040 and 1.700.040: pub.aicpa.org/codeofconduct; summary in the AICPA's Journal of Accountancy: journalofaccountancy.com
- CERT-In Directions, 28 April 2022: cert-in.org.in
- DPDP Rules, 2025 (PIB, Government of India): pib.gov.in
Somesh Chandak & Associates, Chartered Accountants (FRN 158694W), Thane, supports accounting firms abroad with bookkeeping, reconciliations and month-end close on QuickBooks Online and Xero. We can walk through scope, access design and the documents your firm will want in place before any client data moves.
Outsourced Bookkeeping for Foreign Firms Talk to usThis article is for general information for accounting professionals and is not legal, tax, data-protection or cybersecurity advice. Federal, state and Indian requirements depend on facts and change over time. Confirm your position with your own counsel and IT security adviser before sharing client data with any third party.