Most US CPA firms that look at India are trying to close the books for 40 or 60 clients a month with the staff they can actually hire. India has a deep pool of accountants who work on QuickBooks Online and Xero every day, and the time difference lets reconciliations get done while your office is closed. The catch is that the compliance layer is real: IRC section 7216, the AICPA Code's third-party service provider rules and the FTC Safeguards Rule all apply before a single bank statement leaves your portal. This guide sets out what to send first, what each rule requires, how to pay the provider, and a 90-day pilot you can run without putting client data or your peer review at risk.
- Start with bookkeeping and month-end close, not tax preparation. It carries the least section 7216 friction and is easiest to review.
- Before sharing data: tell clients in the engagement letter (AICPA ET 1.150.040) and sign a confidentiality agreement with the provider (ET 1.700.040).
- If any data feeds a tax return, get separate, signed section 7216 consent first. SSNs of 1040 filers must be masked unless both sides meet Rev. Proc. 2013-14's safeguard standard.
- Your WISP under the FTC Safeguards Rule (16 CFR 314.4) must cover the provider: MFA, encryption, contract terms and periodic assessment.
- Collect a Form W-8BEN-E from a foreign provider. Services performed in India are generally foreign-source and outside Form 1099 reporting.
- Run a 90-day pilot on 4 to 6 clients before scaling.
1. Why bookkeeping and close come first
Section 7216 makes it a crime for a tax return preparer to knowingly or recklessly disclose or use tax return information without authority. The fine runs up to $1,000 (up to $100,000 in the identity-theft cases covered by section 6713(b)), with imprisonment up to one year, or both. Section 6713 adds a civil penalty of $250 per disclosure, capped at $10,000 a year. "Tax return information" is defined in Treas. Reg. 301.7216-1(b)(3) as information furnished for, or in connection with, the preparation of a return.
That definition is why most firms start with bookkeeping. Coding transactions and reconciling accounts for a client's monthly financials is ordinarily a separate service from preparing that client's return. The line blurs when the same ledger is later used to prepare the 1120-S or Schedule C. So the practical rule is simple: map which data sets feed return preparation, and treat those as 7216 data. Everything else is still confidential client information under the AICPA Code and your WISP. It just does not need 7216 consent.
2. What to send offshore, and what stays with you
Good candidates for offshoring are high in volume, driven by rules, and easy to check against source documents. Judgment, signatures and client relationships stay onshore.
| Task | Offshore fit | What the US firm keeps |
|---|---|---|
| Bank and credit-card reconciliations (QBO / Xero) | High | Review of unreconciled items over a set threshold |
| Transaction coding and bank-rule maintenance | High | Chart of accounts design; rules that change tax treatment |
| AP entry, bill capture, vendor statement matching | High | Payment approval and release |
| AR application and aging review | Medium to high | Collections calls, write-off decisions |
| Month-end close checklist, accruals, prepaid and depreciation schedules | Medium to high | Close sign-off, materiality calls |
| Payroll journal entries from provider reports | Medium | Payroll processing and filings |
| Sales-tax and 1099 workpapers | Medium | Nexus conclusions, filing and signing |
| Tax-return preparation | Later stage, only with 7216 consent in place | Review, signature, e-file, client advice |
| Attest work | Support only | Engagement acceptance, independence, opinions |
3. Three engagement models
How you structure the relationship matters as much as who you pick. The three common models suit different firm sizes.
| Model | How it works | Suits | Watch for |
|---|---|---|---|
| Dedicated accountant | A named person (or team) works only on your files, inside your systems and your checklists | Firms with steady monthly volume and an in-house reviewer | Key-person risk; agree on a trained backup from day one |
| Managed bookkeeping and close, per entity | The provider owns the monthly deliverable for each client entity and delivers a close pack for your review | Firms that want an outcome, not headcount to manage | A tight scope sheet per entity, or scope creep hits turnaround |
| Seasonal capacity | Extra hands for defined windows, such as January to April or the September–October extension season | Firms whose bottleneck is seasonal | Onboarding time; start 6 to 8 weeks before the peak |
A white-label arrangement keeps your firm as the only name the client sees, but it does not change your disclosure duty. The client must still be told that a third-party provider may be used.
4. The compliance layer: 7216, AICPA and FTC
| Rule | What it requires | What to keep on file |
|---|---|---|
| AICPA ET 1.150.040 (Use of a third-party service provider) | Inform the client, preferably in writing, that a third-party provider may be used, before sharing confidential information | Engagement-letter clause, signed |
| AICPA ET 1.700.040 (Disclosing information to a third-party service provider) | Either a contract with the provider to keep the information confidential, or the client's specific consent | Signed confidentiality agreement or MSA with the provider |
| IRC s.7216; Treas. Reg. 301.7216-3 | Written consent, on a separate document and signed before disclosure, for any tax return information. For 1040 filers the SSN must be redacted before it goes outside the US, unless both preparers meet the safeguard standard | Signed consents using the Rev. Proc. 2013-14 wording; a masking procedure |
| Rev. Proc. 2013-14 | Mandatory consent statements. It also defines an "adequate data protection safeguard": a management-approved security programme with administrative, technical and physical safeguards that conforms to a recognised framework | Both parties' security policies, mapped to the framework relied on |
| FTC Safeguards Rule, 16 CFR 314.4 | A Qualified Individual, encryption in transit and at rest, MFA for anyone who accesses systems, and service-provider oversight: select capable providers, require safeguards by contract, reassess periodically. Notify the FTC within 30 days of discovering an event involving 500 or more consumers | WISP (IRS Publication 5708 is a template), provider risk assessment, access log |
A note on the India side. India's Digital Personal Data Protection Rules, 2025 were notified on 14 November 2025 with an 18-month phased timeline. Your contract with the provider, not Indian law, is the main control. The contract should state where data may be stored, who may access it, and how it is returned or destroyed when the engagement ends.
5. Paying an Indian provider: W-8BEN-E, not 1099
The IRS sources personal services income by where the services are performed. Work done by an Indian entity's staff in India is therefore generally foreign-source income. It is not subject to US withholding on payments to non-resident aliens. Collect a Form W-8BEN-E before the first payment. The IRS instructions for requesters say that a valid Form W-8 you can reliably associate with the payment exempts it from Form 1099 reporting and backup withholding under section 3406. A W-8 is generally valid until the last day of the third calendar year after the year it was signed, unless circumstances change. Diary the renewal.
6. Time zones and the daily workflow
India Standard Time is UTC+5:30 and does not observe daylight saving. It runs 9.5 hours ahead of US Eastern Daylight Time and 10.5 hours ahead of Eastern Standard Time. A well-run offshore engagement treats this as an overnight production shift:
- US end of day: staff log open questions and new documents in one shared tracker, not in email threads.
- India working day: reconciliations, coding and close tasks are done, with each exception tagged to a named reviewer.
- US morning: the reviewer clears the queue. A 30-minute overlap call, early morning Eastern, handles anything that needs discussion.
- Weekly: a status sheet per client shows the close stage, open items and review points raised. Rising review points are your early warning.
7. Worked example: a 90-day pilot
Facts (illustrative). A 12-person CPA firm in Ohio has 45 monthly bookkeeping clients on QuickBooks Online. It averages about 6 staff hours per client per month on reconciliations, coding and close, so roughly 270 hours a month. Its one senior reviewer spends evenings catching up. The firm does not want to send tax data offshore in year one.
Scope decision. Bookkeeping and close only. Returns stay in-house, so the pilot data set is kept apart from 7216 data. Client SSNs are never needed and are excluded from the shared folders.
| Window | Action | Output |
|---|---|---|
| Days 1–15 | Update the engagement letter (ET 1.150.040). Sign a confidentiality agreement with the provider (ET 1.700.040). Add the provider to the WISP. Set up named QBO user logins with MFA; no shared credentials | Signed documents; access list |
| Days 16–30 | Pick 5 clients with clean histories. Hand over the close checklist, chart of accounts notes and bank-rule logic. Provider shadows one close | Client-specific SOPs |
| Days 31–60 | Provider runs close 1 and close 2. The reviewer logs every review point by type | Review-point log |
| Days 61–90 | Close 3. Compare turnaround and review points with close 1. Assess the provider against the Safeguards Rule criteria | Go / adjust / stop decision |
Reading the result. If review points fall from, say, 14 in close 1 to 4 in close 3, and the reviewer's time per file drops, scale by 8 to 10 clients a quarter. If they do not fall, fix the SOPs before adding volume.
8. Due-diligence checklist
A well-run offshore engagement should let you tick every line below before live client data moves.
- The provider is a registered entity. For a Chartered Accountants firm, check its ICAI firm registration number (FRN) and the partners' membership details.
- Signed confidentiality agreement or MSA covering data location, subcontracting, breach notice to you, and return or destruction of data at exit.
- Access is through your systems or the client's cloud ledger, with named user IDs and MFA. No local downloads unless approved in writing.
- Written security policy that you can map to the Safeguards Rule elements, and, if you will rely on it for SSNs, to a Rev. Proc. 2013-14 framework.
- A named backup for every dedicated staff member, and documented SOPs per client.
- Engagement-letter disclosure sent to every client in scope, with 7216 consents on file wherever tax return information is involved.
- Form W-8BEN-E received and diarised for renewal.
- Periodic reassessment date set, as 16 CFR 314.4(f)(3) requires.
9. Frequently asked questions
Does section 7216 apply if we only outsource bookkeeping, not tax preparation?
Section 7216 protects tax return information, defined in Treas. Reg. 301.7216-1(b)(3) as information furnished for, or in connection with, the preparation of a tax return. Pure bookkeeping data furnished for bookkeeping is often outside that definition. Data your firm also uses to prepare the client's return can fall inside it. Map which data sets feed return preparation and treat those conservatively. Where in doubt, get written consent before any disclosure.
Can a US preparer send a client's Social Security number to a team in India?
For Form 1040 series filers, Treas. Reg. 301.7216-3(b)(4) says the preparer may not obtain consent to disclose the SSN to a preparer outside the United States and must redact or mask it. The exception applies where both preparers maintain an adequate data protection safeguard as defined in Rev. Proc. 2013-14. In that case the consent must carry the prescribed statement.
What does the AICPA Code require before we use an offshore provider?
ET 1.150.040 requires you to inform the client, preferably in writing, that a third-party service provider may be used before confidential information is shared. The engagement letter is the usual place. ET 1.700.040 requires either a contractual agreement with the provider to maintain confidentiality or the client's specific consent before disclosure.
Is a CPA firm covered by the FTC Safeguards Rule?
The IRS and the Security Summit state that tax and accounting professionals are financial institutions under the Gramm-Leach-Bliley Act and must have a written information security plan. The FTC Safeguards Rule at 16 CFR 314.4 sets out the elements, including a Qualified Individual, encryption, multi-factor authentication and oversight of service providers.
Do we issue Form 1099-NEC to an Indian bookkeeping provider?
Generally no, where the provider is a foreign entity performing the services outside the United States and gives you a valid Form W-8BEN-E. Personal services income is sourced where the services are performed. The IRS requester instructions say a valid W-8 you can rely on exempts the payment from Form 1099 reporting and backup withholding. Confirm the facts with your own tax adviser.
Which work should we send offshore first?
Start with high-volume, rules-based work that a reviewer can check against source documents: bank and card reconciliations, transaction coding, AP entry, AR application and month-end close checklists. Keep client advice, return signing, attest work and client relationship calls with the US firm.
How do time zones work with an India-based team?
India Standard Time is UTC+5:30 with no daylight saving. It runs 9.5 hours ahead of US Eastern Daylight Time and 10.5 hours ahead of Eastern Standard Time. A well-run engagement uses that gap. US staff queue questions by end of day, the India team works overnight, and a short overlap call handles exceptions.
How long should a pilot run before we scale?
Plan on about 90 days, or three month-end closes, on a small set of clients. One close shows set-up issues. Three show whether review points are falling, turnaround is steady and the documentation holds up to your firm's quality-management standards.
10. Sources
- 26 U.S.C. §7216 and §6713: law.cornell.edu/uscode/text/26/7216; /6713
- Treas. Reg. 301.7216-1 and 301.7216-3: ecfr.gov
- Rev. Proc. 2013-14: irs.gov/pub/irs-drop/rp-13-14.pdf
- FTC Safeguards Rule, 16 CFR 314.4: ecfr.gov
- IRS / Security Summit on WISPs and Publication 5708: irs.gov newsroom; Publication 5708
- AICPA Code ET 1.150.040 and 1.700.040, as summarised in the AICPA's Journal of Accountancy: journalofaccountancy.com; Code: pub.aicpa.org/codeofconduct
- IRS, Source of income (personal services): irs.gov; Instructions for the Requester of Forms W-8: irs.gov/instructions/iw8
- DPDP Rules, 2025 (PIB, Government of India): pib.gov.in
Somesh Chandak & Associates, Chartered Accountants (FRN 158694W), Thane, supports accounting firms abroad with bookkeeping, reconciliations and month-end close on QuickBooks Online and Xero. We can walk through scope, workflow and the documents your firm will need before any client data moves.
Outsourced Bookkeeping for Foreign Firms Talk to usThis article is for general information for accounting professionals and is not legal, tax or data-protection advice. US federal rules and state board requirements differ by facts and jurisdiction. Confirm your position with your own counsel and tax adviser before sharing client data with any third party.