Offshore Accounting Security in 2026: SOC 2, ISO 27001, GLBA and IRS Pub 4557 - A 25-Point Vendor Checklist
- By: Admin
The first question every finance leader asks about offshore accounting is some version of "is my data safe?" The second question, asked far less often, is the one that actually matters: "how would I know?"
Most security due diligence in this market stops at a logo on a website. A provider displays an ISO 27001 badge, the buyer feels reassured, and nobody asks which scope the certificate covers or whether it is still valid. That is not diligence. It is decoration.
This guide explains what each framework actually proves, what your own legal obligations remain regardless of your provider's certifications, and gives you 25 questions that will separate providers who have built a security programme from those who have bought a badge.
Quick answer
When evaluating an offshore accounting provider's security in 2026, request four things: a SOC 2 Type II report (not Type I, and not just a logo), a valid ISO/IEC 27001:2022 certificate with its scope statement, evidence that the provider's controls support your obligations under the FTC Safeguards Rule and IRS Publication 4557, and a written description of the technical controls - virtual desktop infrastructure, multi-factor authentication, blocked removable media, encryption at rest and in transit, and logged access.
Critically, none of these transfer your legal liability. Under the Gramm-Leach-Bliley Safeguards Rule you remain responsible for overseeing your service providers, and under IRC Section 7216 you remain responsible for the disclosure itself. A certified vendor reduces risk. It does not discharge duty.
Why accounting is a harder case than general outsourcing
Accounting outsourcing concentrates three categories of sensitive data in one workflow: personally identifiable information including Social Security Numbers, financial account credentials and balances, and in many cases payment execution capability.
That combination creates exposures that generic BPO security frameworks were not designed around:
- Business email compromise. An offshore AP team with vendor-master access is a high-value target for payment redirection fraud.
- Regulated disclosure. Tax return information carries specific federal restrictions that most data-protection frameworks do not address.
- Fraud opportunity. Segregation of duties is harder to maintain across an organisational boundary and a time zone.
So the security conversation needs to cover both information security in the conventional sense and financial process controls. Providers who can only talk about the former are answering half the question.
The four frameworks, decoded
|
Framework |
What it is |
Who issues it |
What it proves |
What it does not prove |
|
SOC 2 Type II |
An attestation report against AICPA Trust Services Criteria |
An independent CPA firm |
That specified controls operated effectively over a period, typically 3–12 months |
That controls cover the service you are buying, unless the scope says so |
|
SOC 1 Type II |
Attestation on controls relevant to clients' financial reporting |
An independent CPA firm |
That the provider's controls support your ICFR |
Anything about general information security |
|
ISO/IEC 27001:2022 |
Certification of an information security management system |
An accredited certification body |
That a managed ISMS exists and was audited |
That any particular control is strong - the scope may be narrow |
|
FTC Safeguards Rule / IRS Pub 4557 |
Legal obligations on you, not your vendor |
US regulators |
Nothing about the vendor |
- |
What SOC 2 Type II actually tells you
SOC 2 is not a certification and there is no pass mark. It is a report in which an auditor describes the provider's controls and states whether they operated effectively. Four things matter when you read one:
- Type I vs Type II. Type I says the controls were suitably designed on a single date. Type II says they actually worked over a period. Type I is close to worthless for vendor assurance.
- The scope. A report covering "the corporate IT environment" tells you nothing about the delivery floor where your work is done. Check that the report covers the specific service, location and systems that will handle your data.
- The Trust Services Criteria included. Security is the only mandatory one. Confidentiality and Privacy are optional and are the two most relevant to accounting data. A Security-only report is a partial answer.
- Exceptions. Auditors record control failures as exceptions. A report with zero exceptions across twelve months is unusual; a report you were given without exceptions being discussed is one nobody read properly.
The report itself is confidential and normally shared under NDA. A provider that will show you a logo but not the report has not given you anything.
ISO 27001 vs SOC 2 - which should you ask for?
Ask for both if available, but understand the difference. ISO 27001 certifies that a management system exists and is maintained - it is a statement about process discipline. SOC 2 Type II describes and tests specific controls - it is a statement about operational effectiveness.
For accounting work involving US taxpayer data, SOC 2 Type II with Confidentiality included is generally the more informative document. ISO 27001 is useful corroboration and is more common among India-based providers.
One detail worth checking: certificates issued against the older ISO 27001:2013 standard are no longer current. A provider showing a 2013-version certificate in 2026 either has not transitioned or is displaying an expired document. Ask for the certificate itself - it shows the standard version, the scope, the accreditation body and the expiry date.
Your obligations do not transfer
This is the section most buyers skip and most regulators focus on.
The FTC Safeguards Rule (16 CFR Part 314) treats accounting firms and tax preparers as financial institutions. Since the amended rule took effect, covered firms must maintain a written information security programme with a named qualified individual, a documented risk assessment, access controls, encryption of customer information in transit and at rest, multi-factor authentication, logging and monitoring, an incident response plan, and - specifically relevant here - oversight of service providers, including contractual security requirements and periodic assessment of whether the provider is meeting them.
Engaging a certified vendor does not satisfy that obligation. Documenting your assessment of that vendor does.
IRS Publication 4557 sets the IRS's expectations for safeguarding taxpayer data and is the practical checklist most firms work from. Publication 5708 provides a written information security plan template.
IRC Section 7216 governs disclosure of tax return information to preparers outside the United States and requires written client consent in a prescribed format. No certification substitutes for it.
India's Digital Personal Data Protection Act applies to your provider's handling of personal data in India and is worth asking about, though it protects data subjects rather than you as a client.
The 25-point vendor security checklist
Send this as written. How a provider responds is as informative as what they say.
Certifications and assurance (1–5)
- Will you provide your full SOC 2 Type II report under NDA, including the scope section and the list of exceptions?
- Does the SOC 2 scope cover the specific delivery location, team and systems that will handle our work?
- Which Trust Services Criteria are included - Security only, or also Confidentiality and Privacy?
- Provide your ISO/IEC 27001 certificate showing standard version, scope statement, accreditation body and expiry date.
- When was your last independent penetration test, and will you share the summary findings and remediation status?
Technical controls (6–12)
- Will our work be performed on a virtual desktop with no local data storage? Confirm that data cannot be saved to the endpoint.
- Is multi-factor authentication enforced for all access to client systems and data, without exception?
- Are USB ports, removable media, printing and screen capture disabled on delivery workstations?
- Is client data encrypted at rest and in transit, and by what standard?
- How is data transferred to and from us? Is email attachment of client data prohibited?
- Are access logs retained, and for how long? Can you produce an access log for a specific file on request?
- What data loss prevention controls block exfiltration through personal email, cloud storage and messaging applications?
People (13–18)
- What background verification is performed on staff before they access client data - identity, employment, criminal and education?
- Do individual employees sign confidentiality undertakings personally, in addition to your corporate NDA with us?
- What security and confidentiality training is mandatory, and how often is it refreshed?
- Describe your offboarding process. How quickly is access revoked when someone leaves?
- Are mobile phones permitted on the delivery floor? Is the floor physically segregated with access control and CCTV?
- How many other clients does each assigned person work on, and is client data segregated between them?
Financial process controls (19–22)
- For AP work, does your team have payment execution capability, or preparation only? Where does approval authority sit?
- What controls prevent vendor master file changes from being made without independent verification?
- How is segregation of duties maintained across our engagement?
- What is your process when a payment or bank detail change request arrives that appears legitimate but unverified?
Contract and continuity (23–25)
- What is your breach notification commitment to us, in hours, and what does the notification contain?
- Do you carry cyber liability and professional indemnity insurance? Provide the certificate and limits.
- On termination, in what format is our data returned, how quickly is it deleted from your systems, and will you certify the deletion in writing?
Five red flags
- A certification logo with no retrievable document behind it. Ask for the certificate or report. Hesitation is the answer.
- SOC 2 Type I presented as though it were Type II. Check the report title.
- Willingness to receive client data by email. A provider comfortable with this has not thought about exfiltration at all.
- No named security owner. If nobody can be identified as accountable for information security, the programme is nominal.
- Subcontracting without disclosure. Ask directly whether any work is subcontracted to a third party. Undisclosed subcontracting defeats every control above it.
How to verify rather than trust
- ISO certificates can usually be validated on the issuing certification body's public register. Look up the certificate number rather than accepting the PDF.
- SOC 2 reports are issued by CPA firms. The auditing firm is named in the report and can be verified.
- Request a controls walkthrough, ideally by video from the delivery floor. Ten minutes of seeing the environment is worth more than a fifty-page questionnaire.
- Include security terms in the contract, not just the sales conversation. Notification timelines, subcontracting prohibitions, audit rights and deletion obligations belong in the agreement.
- Reassess annually. The Safeguards Rule expects periodic assessment, and certifications expire.
Frequently asked questions
Is it safe to outsource accounting to India? It can be, provided the provider maintains verifiable controls and you perform and document your own vendor assessment. The risk is not geography - it is uncontrolled data handling, which occurs domestically as often as offshore. The meaningful differences are that offshore disclosure of tax return information triggers IRC Section 7216 consent requirements, and that enforcement of contractual remedies across jurisdictions is harder.
What is the difference between SOC 2 Type I and Type II? Type I reports whether controls were suitably designed at a single point in time. Type II reports whether those controls operated effectively across a period, usually three to twelve months. For vendor assurance, Type II is the meaningful report; Type I mainly indicates a provider early in its compliance journey.
Does SOC 2 or ISO 27001 make my firm compliant with the FTC Safeguards Rule? No. The Safeguards Rule places obligations on your firm, including maintaining a written security programme and overseeing service providers. A vendor's certification is evidence supporting your oversight assessment, not a substitute for having one.
Do I need client consent to send accounting data offshore? For tax return information, yes - IRC Section 7216 requires written client consent in a prescribed format before disclosure to a preparer outside the United States. For general bookkeeping where no tax service is provided, the position is more nuanced, but AICPA rules on third-party service providers and most engagement letters require the client to be informed.
What should an offshore provider's breach notification commitment be? A defined maximum, expressed in hours rather than "promptly." Twenty-four hours from detection is a reasonable contractual standard, with an initial notification containing what happened, what data was involved, and what has been contained. Note that US firms have their own downstream notification obligations, including to the FTC for qualifying events.
Should offshore staff have access to our bank accounts? Generally no. Best practice is preparation-and-submission only, with payment release authority retained by named individuals at the client. Read-only bank access for reconciliation is common and low-risk; payment execution authority is neither necessary nor advisable.
Security questions deserve documents, not reassurances. If you are evaluating Staunch Fintech, ask us all twenty-five of the questions above - we would rather answer them at the start than have you discover a gap six months in. Get in touch and we will send our written responses along with the supporting documentation.