More accounting and tax firms are moving client data into hosted or cloud-based environments every year—not by choice alone, but because remote staff, multi-office teams, and modern tax software increasingly demand it. That shift raises a fair question every firm leader should be asking before signing anything: How do we actually know this environment protects client data the way we’re telling clients it does?
The honest answer is that most vendor sales pages aren’t built to answer that question. They’re built to reassure. Getting a real answer means asking more specific questions—the kind that separate a genuinely secure environment from one that simply says the word “secure” a lot.
Here are five worth bringing into any vendor conversation, regardless of who’s on the other side of the table.
1. Who exactly can access our data, and how is that access controlled? “Only authorized staff” is not an answer—it’s a placeholder for one. Ask for specifics: Is access role-based, so a support technician doesn’t have the same reach as a systems administrator? Is multi-factor authentication required for every account with access, not just recommended? Is there a log of who accessed what, and when, that your firm could review if you ever needed to?
2. How is data backed up, and has recovery actually been tested? Nearly every provider will tell you backups are automatic and daily. Fewer can tell you when a backup was last successfully restored—not just taken, but proven to work. Ask how often recovery is tested and what that timeline realistically looks like on a Tuesday afternoon in the middle of March, not in a best-case demo.
3. What compliance standards or third-party audits does the environment maintain? Ask whether the environment has been through an independent security audit (SOC 2 is a common baseline), whether data is encrypted both in transit and at rest, and how often those controls are reassessed.
4. What happens to our data if we ever decide to leave? Can your firm export its data in a usable format on its own schedule? Is there a deletion policy once you’re transferred out?
5. How is the environment monitored, and how would we find out if something went wrong? Ask whether monitoring is continuous, who’s watching for unusual activity, and what the actual notification process looks like if an incident occurs.
The bigger point
None of these questions are designed to catch a vendor doing something wrong. They’re designed to give your firm the same specific answers you’d want to hand a client if they asked how their own information is protected. Client trust in an accounting or tax firm ultimately rests on how carefully that firm protects what’s been shared with it—a hosted environment doesn’t change that responsibility, it just moves where the infrastructure lives.
ABOUT THE AUTHOR:
Mark Johnson, CPA, is an accounting and technology advisor to Cloud Innovics, where he advises on secure hosting and remote-access infrastructure for accounting and tax firms.
Photo credit: magnific/Freepik
Sign in to get access to this free resource, and all of our whitepapers and reports.
Download this content today!
Register Now Already registered? Click here to Log In