Outsourcing Security Diligence FAQ

Honest security diligence questions for US CPA firms evaluating India accounting outsourcing — no invented SOC or ISO claims.

PJRJ & AssociatesChartered Accountants
Blog
BPO · Security

Outsourcing Security Diligence FAQ

Questions US CPA firms should ask any India or offshore accounting partner — answered honestly

Brochure badges are not diligence. Ask how access is granted, who sees which clients, what happens when someone leaves, and whether the partner will put controls in the engagement letter.

PJRJ discusses access controls, NDAs, and data-handling practices during scoping. We do not invent SOC 2, ISO, or IRS opinions on this page. If a control is not in your engagement, do not assume it.

Who this is for

  • US CPA partners running first-time vendor diligence
  • Firms updating security questionnaires for India capacity
  • Ops leads comparing staffing vendors vs CA-firm delivery
  • Anyone told “we are SOC / ISO certified” without evidence

How we work

  1. 01

    Map data and systems

    List ledgers, portals, PII, and tax data the partner will touch — then require least-privilege access and MFA where available.

  2. 02

    Write consent and NDA terms

    Confirm client consent where required, mutual NDAs, and how subcontractors (if any) are disclosed.

  3. 03

    Test attrition and offboarding

    Ask how access is revoked, how work is reassigned, and what evidence you get when someone leaves the delivery team.

What you receive

  • Reusable security diligence question set
  • Topics to put in the engagement letter
  • Pilot access checklist
  • Optional PJRJ scoping call for India CA capacity

Common questions

Direct answers for searchers and answer engines

5 topics

No. Do not cite invented badges. Ask for the access, logging, and contractual controls that apply to your engagement — and verify them.

Prefer named users, least privilege, MFA on cloud ledgers, no shared passwords, and a written list of systems in scope. Revoke access promptly at offboarding.

Ask whether teams can see only assigned clients, how folders are named, and whether export rights are limited. Weak vendors share broad drives “for convenience.”

Consent and disclosure rules depend on your facts and jurisdiction. PJRJ does not publish IRS attorney opinions here — route consent design to your counsel and engagement letter.

WhatsApp +91-8882913461 with your questionnaire, software stack, and whether white-label delivery is in scope. Pair this FAQ with the partner checklist and pilot guide.

Get in touch

Ready to discuss your requirements?

Speak directly with a partner at PJRJ & Associates — audit, tax, advisory, or FinTech.