Data security when offshoring tax preparation is the objection that stops most CPA firms before they start — and it is the right instinct. But security is not a feature you buy from an offshore provider. It is a set of obligations that stay with your firm no matter who does the keystrokes, and two of them are already US law. Get those right, and offshoring 1040s, 1120s and the rest of the return volume is no less secure than handing the same files to a seasonal hire down the hall. Get them wrong, and the exposure is yours, not the vendor’s.
What data security when offshoring tax preparation actually requires
Before you evaluate a single provider, two federal rules already govern what you may do with a client’s tax information — and both apply the moment that information would leave your walls. Treat them as the floor, not the finish line.
Client consent before the data leaves the United States
Internal Revenue Code Section 7216 governs how a preparer may use or disclose a client’s tax information. On sending that information abroad, the IRS is explicit: “The new rules will require preparers to inform taxpayers and obtain their consent before sending their tax information outside the United States.” The IRS frames the whole regime around one idea — “informed consent by the taxpayer is the key.”
In practice that means a written consent, obtained before any data crosses the border, in the specific form the IRS prescribes. It is not a line buried in an engagement letter, and it is not something the offshore partner can obtain on your behalf. This is your disclosure to make, to your client, up front.
The FTC Safeguards Rule — your written security program
The FTC lists tax preparation firms among the “financial institutions” covered by its Safeguards Rule. That rule requires you to “develop, implement, and maintain an information security program with administrative, technical, and physical safeguards.” It names specific controls a program must contain, and each one is a question you should be able to answer about the offshore setup as easily as your own office:
- Encryption. “Encrypt customer information on your system and when it’s in transit.”
- Multi-factor authentication. “Implement multi-factor authentication for anyone accessing customer information on your system” — which now includes the offshore preparer.
- A named owner. “Designate a Qualified Individual to implement and supervise your company’s information security program.”
- Access controls. “Implement and periodically review access controls. Determine who has access to customer information and reconsider on a regular basis whether they still have a legitimate business need for it.”
- Activity logging. “Maintain a log of authorized users’ activity and keep an eye out for unauthorized access.”
The controls to look for in an offshore partner
Read that list again and it becomes your checklist for any prospective partner. The offshore team should work inside your environment — your tax software, your document portal — over an encrypted connection, with multi-factor authentication on every login, rather than pulling client files down to a local machine. Access should be least-privilege: a preparer sees the returns assigned to them and no more, and that access is reviewed and revoked as engagements end. Activity should be logged so you can see who opened what, and when.
The Safeguards Rule is just as direct about the vendor relationship itself: “Select service providers with the skills and experience to maintain appropriate safeguards. Your contracts must spell out your security expectations.” So the security clauses belong in the contract, not in a sales deck — who may access data, from where, under what controls, and what happens to it when the engagement ends. Ask for independent evidence of those controls; do not accept a verbal assurance in place of a document.
Why the responsibility stays with your firm
Here is the line every partner should sit with before signing anything. The FTC could not be plainer: “If your company brings in a service provider to implement and supervise your program, the buck still stops with you.” Delegating the work does not delegate the duty. The same logic runs through professional standards — your firm remains responsible for supervising the work and for the returns that go out under its name, wherever the preparation happened.
That is not a reason to avoid offshoring. It is the reason to structure it properly: the offshore team carries the volume, your firm keeps the client relationship, the review and the sign-off. Handled that way, a well-run offshore arrangement often applies more discipline to access and encryption than an in-house season staffed by temporary hires on shared logins.
How Indefine approaches it
Indefine builds its work for US CPA firms around exactly this division of labour. Our teams operate inside your systems and your controls, so client data stays where your security program governs it, and the review and the sign-off never leave your firm. Whether the work is tax preparation through the season or year-round accounting and bookkeeping support, the arrangement is designed to fit the consent and safeguards obligations you already answer to — not to sit outside them.
Offshoring tax work does not have to mean loosening your grip on client data. Done right, it means qualified capacity behind the same controls, the same consent, and the same accountability you would apply to any member of your own staff.
