Resources / Data & Security

What to Ask About Data Security Before Outsourcing Any Tax Prep Work

6 min read

Handing a client's tax documents to anyone outside the firm — even for a single return — puts data security questions on the table that don't come up in an internal hiring decision. Before a single file moves, it's worth having specific answers, not general reassurance.

"Secure" isn't a specific answer

Every prep service will say client data is handled securely. The useful question isn't whether it's secure — it's how: what transmission method is used to move documents, where they're stored during preparation, who has access to them, and what happens to them once the engagement ends. A specific answer to each of those is worth more than any general assurance.

Five questions worth asking directly

Before sending a single file

  1. How are documents transmitted? A secure upload link or encrypted portal is the baseline; email attachments are not.
  2. Where is data stored during preparation, and for how long? Data retained indefinitely after the engagement ends is a bigger exposure than data deleted on a defined schedule.
  3. Who has access to a given return? The preparer working the file should be the access boundary — not a wider team with standing access to everything in the queue.
  4. Is the preparer credentialed and individually accountable? A named, credentialed preparer working under a defined engagement is a different risk profile than an anonymous pool.
  5. What's the process if something goes wrong? A firm that can't describe an incident-response process hasn't thought about the question yet.
Worth noting: your firm's own data-handling obligations to its clients don't pause because part of the work is outsourced. Whatever standard your firm is held to, the partner handling the file needs to meet it too.

What "white-label" should mean for data, not just branding

White-label engagements are usually described in terms of what the client sees — no outside branding, no direct contact. The data side matters just as much: no retention beyond the engagement window, no use of client information for anything outside the return it was provided for, and no access that outlives the file being closed out.

Ask the data-handling questions directly

We'll walk through exactly how documents are transmitted, stored, and retained — before anything is sent.

Start a Conversation