Skip to main content

How to Vet Your Outsourced Bookkeeper's IT Security: 10 Questions

Published 11 min readMike ThriftMike Thrift
How to Vet Your Outsourced Bookkeeper's IT Security: 10 Questions
On this page

Your bookkeeper holds the keys to your entire financial life: your employer ID number, your bank logins, your payroll records with every employee's Social Security number, and your tax returns. Now ask yourself an uncomfortable question — do you have any idea how that firm protects all of it? Most small business owners vet their bookkeeper's credentials, pricing, and responsiveness, then hand over complete financial access without a single question about cybersecurity. That trust gap is exactly what attackers count on.

The stakes are not abstract. Financial services remained the most-targeted sector for data breaches in 2025, with 739 reported compromises, according to the Identity Theft Resource Center's annual report. The average small-business breach now costs around $149,000, and an estimated 60 percent of small businesses close within six months of a major cyberattack. When the breached system belongs to your bookkeeper rather than to you, the damage lands on your accounts, your employees' identities, and your tax filings all the same.

This guide explains why bookkeeping firms are such attractive targets, what federal law already requires of them, how to tell a firm running serious security from one running on shared passwords and hope, and which protections to write into your engagement letter.

Why Bookkeepers Are Prime Targets

Attackers follow the data, and a bookkeeping firm concentrates more sensitive data per employee than almost any other small business. A single compromised bookkeeper workstation can yield dozens of clients' bank credentials, tax IDs, payroll files, and prior-year returns — everything needed for business identity theft, fraudulent tax filings, and wire fraud. Breaching one firm can be more profitable than breaching any one of its clients directly.

The IRS has been warning about this for years. Its Security Summit alerts tax professionals to sustained phishing campaigns designed specifically to steal their credentials, noting that thieves target preparers precisely because one intrusion unlocks many taxpayers at once. Your bookkeeper may do excellent reconciliations and still be one convincing phishing email away from handing attackers your QuickBooks login, your bank portal session, and your payroll file in a single afternoon.

There is a second, quieter risk: access sprawl inside the firm itself. Many bookkeeping practices share client portal passwords among staff in spreadsheets or chat messages, keep former contractors' logins active for months, and let staff work from personal devices with no encryption or remote-wipe capability. Every one of those shortcuts multiplies the number of people and machines standing between your bank account and whoever wants into it.

The Law Already Requires Your Bookkeeper to Be Secure

Here is the part most clients never hear: a bookkeeping firm with sloppy IT is not just careless, it is likely breaking federal law. Under the FTC Safeguards Rule, which implements the Gramm-Leach-Bliley Act, accountants, bookkeepers, and tax preparers count as "financial institutions" and must maintain a written information security program protecting client data. This has been enforceable since June 2023, and it applies regardless of firm size.

The rule requires nine specific elements, including a designated Qualified Individual in charge of the program, a written risk assessment, encryption of customer data, multi-factor authentication (MFA) on systems accessing that data, staff security training, oversight of the firm's own vendors, and a written incident response plan. Since May 2024, firms must also notify the FTC within 30 days of discovering a breach affecting 500 or more consumers. Firms maintaining records on fewer than 5,000 consumers get a partial exemption from some procedural elements — but the core duty to safeguard client data applies to everyone.

On top of that sits the IRS layer. Every paid preparer must maintain a Written Information Security Plan (WISP) — the IRS publishes a free template in Publication 5708 — and implement the baseline "Security Six" controls: antivirus or endpoint protection, a firewall, MFA, encrypted backups, drive encryption, and a VPN for remote access. The IRS ties this to the PTIN renewal process, meaning a preparer who cannot show a data security plan risks losing the credential that lets them file for clients at all.

Why does this matter to you as a client? Because it turns your vetting questions from awkward interrogation into simple compliance verification. You are not asking your bookkeeper for favors. You are asking whether they follow the same federal rules that govern every firm in their profession.

DIY IT vs. Purpose-Built Security: What Changed in 2026

For years, the typical small bookkeeping firm secured itself the way most small businesses do: a consumer antivirus subscription, passwords in a shared spreadsheet, client documents arriving as plain email attachments, and whoever set up the Wi-Fi doubling as the IT department. That model is collapsing under the weight of credential phishing, offshore contractors, and a dozen cloud apps per client.

The industry's answer is the purpose-built security platform: a single managed environment that replaces the patchwork of DIY tools with centralized access control, credential masking (staff log into your bank portal without ever seeing the actual password), one-click onboarding and offboarding across every system, and an audit trail showing exactly who touched your data and when. In mid-2026, accounting cloud provider Rightworks joined this push by launching a bookkeeper-specific edition of its platform at the Scaling New Heights conference, aimed at firms that manage sensitive client data, work with contractors or offshore staff, and juggle multiple cloud accounting applications. The pitch is enterprise-grade security without an in-house IT department — fully managed, with no DIY assembly required.

You do not need to care which vendor your bookkeeper uses. What matters is the architectural shift these platforms represent: individual passwords replaced by centrally managed access, invisible logins replaced by audit trails, and "trust us" replaced by controls you can verify. When you vet a firm in 2026, you are really asking which side of that shift it sits on.

Ten Questions to Ask Before You Hand Over Access

Use these questions when hiring a bookkeeping firm — or at your next review with the one you already have. A secure firm will answer quickly and in writing. Evasion is itself an answer.

1. Do you have a Written Information Security Plan, and who is your Qualified Individual? This is the federal baseline. The firm should be able to confirm it maintains a WISP and name the person responsible for it. If the owner has never heard the term, nothing else on this list matters.

2. Is multi-factor authentication enforced on everything that touches my data? Not "available" — enforced. That includes the bookkeeping software, email, cloud storage, remote access, and the IRS e-Services account used for your filings. MFA is both an FTC requirement and part of the IRS Security Six, and its absence is the single most common finding in small-firm breaches.

3. How are my bank and portal credentials stored? Acceptable answers: a business password manager with masked credentials, or single sign-on through a managed platform where staff never see the underlying password. Unacceptable answers: a spreadsheet, a shared document, a chat thread, or "we each keep our own copy."

4. Who exactly can see my data — including contractors and offshore staff? Many firms outsource data entry or overnight processing. That is legitimate, but every person with access should be individually authenticated, covered by the same security policies, and removable with one action when the engagement ends. "A contractor helps out sometimes" without named accounts is a red flag.

5. How fast can you revoke someone's access? When an employee quits or a contractor engagement ends, their access to every client system should die the same day — ideally through one-click offboarding. Ask what the firm's actual process is and how long it takes. Lingering logins from departed staff are a classic breach vector.

6. Is my data encrypted at rest and in transit, and how are backups handled? Look for drive encryption on all workstations, encrypted connections (no working over open Wi-Fi without a VPN), and encrypted backups stored separately from the live systems. Then ask the follow-up most firms dread: when did you last test restoring from those backups?

7. Can you show me an audit trail of who accessed my accounts? Centralized platforms log every login and action. If the firm cannot tell you who opened your file last Tuesday, it cannot detect misuse either — and after an incident, neither of you will know what the attacker saw.

8. What is your incident response plan, and how quickly will you tell me about a breach? The firm needs a written plan, not an intention to figure it out. Pin down a notification commitment: you want to hear about a suspected breach affecting your data within days, not after the firm's own investigation concludes weeks later. Your state may also impose its own breach-notification deadlines on you as the data owner.

9. Do you train your staff against phishing, and do you test them? Phishing remains the most common path into a breach, and tax and bookkeeping firms are deliberately targeted. Annual training is the minimum; simulated phishing tests are the sign of a firm that takes the threat seriously.

10. Do you carry cyber liability insurance? Insurance does not prevent breaches, but carrying it signals that the firm has been through an insurer's security questionnaire — which asks many of these same questions — and that there is a funded response plan if something goes wrong.

Red Flags That Should Stop You Signing

Some warning signs are visible before you ask a single formal question. If your prospective bookkeeper asks you to email sensitive documents as unprotected attachments rather than uploading them to a secure portal, that tells you how every other client's documents travel too. If onboarding involves texting passwords or sharing one login "for the team," the firm's access controls are decorative. If the engagement letter says nothing about confidentiality, data handling, or breach notification, security was not an oversight — it was never on the agenda.

Other red flags emerge in conversation: vague answers about who does the actual work, reluctance to put security commitments in writing, no process for returning or deleting your data if you leave, and personal devices used for client work with no mention of encryption or mobile-device management. Any one of these is fixable. The pattern of all of them together is a firm to walk away from.

Put It in the Engagement Letter

Verbal assurances evaporate the day something goes wrong. Whatever the firm promises about security, capture the essentials in your engagement letter or a data-processing addendum:

  • A commitment to maintain a Written Information Security Plan and comply with the FTC Safeguards Rule and applicable IRS requirements.
  • A breach-notification clause with a specific timeline (for example, notice within 72 hours of discovering a suspected incident affecting your data).
  • Limits on subcontracting: no offshore or third-party access to your data without your prior written consent.
  • A data return-and-deletion clause: when the engagement ends, the firm returns your records in a usable format and certifies deletion of its copies within a set period.
  • Confidentiality terms that survive termination.

You are not drafting enterprise vendor contracts — a few plain sentences added to a standard engagement letter will do. The point is not to litigate later; it is to make sure both sides discussed security before access changed hands.

Keep Your Financial Management Secure From Day One

Vetting your bookkeeper's IT is part of the same discipline as keeping clean books: knowing exactly where your financial data lives, who can touch it, and what happens when something goes wrong. As you tighten that oversight, maintaining clear financial records of your own is essential. Beancount.io provides plain-text accounting that gives you complete transparency and control over your financial data — no black boxes, no vendor lock-in. Get started for free and see why developers and finance professionals are switching to plain-text accounting.

Share this article

Source: https://beancount.io/blog/2026/09/22/outsourced-bookkeeper-it-security-vetting-guide

Published: September 22, 2026