Is it safe and IRS-compliant for a US CPA firm to outsource bookkeeping and tax preparation support offshore?
Yes. A US CPA or accounting firm can outsource bookkeeping and tax preparation support to an offshore team, but the firm stays fully responsible under US federal rules, AICPA professional standards, and state privacy laws. Outsourcing moves the workload, not the liability. The requirements below apply whether your firm is a solo practitioner in Texas or a multi-office firm in New York.
1. Taxpayer consent under IRC §7216
Internal Revenue Code §7216 and Treasury Regulation §301.7216 restrict how tax return preparers may use or disclose tax return information. Sending client tax return information to a preparer located outside the United States generally requires the taxpayer's written consent. Disclosing a Social Security number abroad is subject to stricter conditions, including verifying that the offshore preparer maintains adequate data protection safeguards. IRS Revenue Procedure 2013-14 provides sample consent language. Pure bookkeeping work often does not involve tax return information, but tax preparation support does, so update your engagement letters accordingly.
2. The FTC Safeguards Rule (GLBA)
Under the Gramm-Leach-Bliley Act, the FTC Safeguards Rule (16 CFR Part 314) treats tax preparers and accounting firms that handle customer financial information as financial institutions. It requires a written information security program, a designated qualified individual, a risk assessment, multi-factor authentication, encryption of customer information, staff training, and oversight of service providers who can access client data. If unencrypted information of 500 or more consumers is compromised, the firm must notify the FTC as soon as possible and no later than 30 days after discovery.
3. IRS guidance for tax professionals
The IRS expects preparers to protect taxpayer data. IRS Publication 4557 (Safeguarding Taxpayer Data) outlines the security steps, and Publication 5708 provides a template for a Written Information Security Plan (WISP). Your offshore partner's controls should be documented inside your WISP. Treasury Department Circular 230 also holds practitioners to due diligence and competence standards, and that includes supervising work delegated to others.
4. AICPA professional standards
CPAs who are AICPA members must follow the AICPA Code of Professional Conduct, including the Confidential Client Information Rule and the requirements for using third-party service providers. In practice, that means informing clients when outside providers will handle their information, obtaining consent where required, and staying responsible for supervising and reviewing the work. Your state board of accountancy may add its own rules.
5. State privacy and breach laws
All 50 US states have data-breach notification laws, and several add security requirements. For example, Massachusetts (201 CMR 17.00) requires a written information security program for anyone holding a Massachusetts resident's personal information, and the New York SHIELD Act requires reasonable safeguards for New York residents' data. Your obligations follow your clients' state of residence, not only where your office is.
Due-diligence checklist before you outsource
- Signed NDA and service agreement covering confidentiality, data handling, and breach notification
- Written client consent for offshore access to tax return information, using compliant §7216 language
- Access control: unique logins, role-based permissions, and multi-factor authentication
- Work inside your systems: QuickBooks Online, Xero, Sage, or your tax software (such as Drake, Lacerte, UltraTax, or ProConnect) with no client files downloaded to local devices
- Encryption of data in transit and at rest
- Independent security assurance such as a SOC 2 report or a clear written description of equivalent controls
- Staff vetting and training in confidentiality and phishing awareness
- Incident response plan with clear notification timelines that fit the FTC and state deadlines
- Review and sign-off: a US-licensed professional in your firm reviews all work before it goes to the client or the IRS
How Exuberant Global approaches data security for US firms
At Exuberant Global, protecting your clients' data is built into how we work from day one:
- Confidentiality first: every engagement starts with a signed NDA, and every team member is bound by confidentiality obligations.
- Work inside your systems: we work directly in your accounting and tax software, so client files stay in your environment instead of being copied to ours.
- Controlled access: we use unique logins, role-based permissions, and multi-factor authentication, and access is removed as soon as an engagement or task ends.
- No data on local devices: client information is not downloaded, stored, or shared through personal email or messaging apps.
- Trained team: our staff are trained in data handling, phishing awareness, and secure working practices.
- You stay in control: your firm reviews and approves all work, and you decide who has access and when.
We are happy to walk through our security practices with you and align them with your firm's Written Information Security Plan before any work begins.
This article is general information, not legal or tax advice.