What Changes the Moment Finance Data Leaves the Building
Outsourced accounting security is less about new risks than about relocating existing ones into a contract you have to write well. When books, bank feeds, payroll and vendor records move outside, the exposure doesn’t grow. What grows is the number of places an entitlement gets granted by default.
Is it safe to outsource accounting? There’s no general answer. Only a specific one, and it turns on what you grant, to whom, and how you verify it.
Four things change the week an engagement starts.
- Control over people becomes control over contract terms. An internal hire is governed by employment law and your own offboarding process. An outsourced team is governed by whatever the master services agreement says. Silence there is not neutral.
- Entitlements get granted all at once. A single finance as a service engagement touches the ledger, bank feeds, payroll, the AP tool, the card program, and the document store. Internally those permissions accumulate over years. In an onboarding they land in one week, which is exactly when over-provisioning happens.
- Visibility depends on someone else’s logging. You can’t walk over and ask. You need audit trails that name individuals.
- The legal duty doesn’t transfer. Under the FTC Safeguards Rule, the obligation to select a provider carefully, bind it by contract, and reassess it periodically sits on you.
The first fact worth holding is a baseline, not an accusation. The Association of Certified Fraud Examiners’ Occupational Fraud 2026 report analyzed 2,402 cases and put the median loss at $104,000, with the typical case running 12 months before detection. More than half involved internal controls that were missing or overridden. Access scoping is what moves that number, and an outsourced onboarding is a rare chance to design it deliberately instead of inheriting it.
The second is about who absorbs a loss. Regulation E protects consumer accounts and does not reach business accounts. Unauthorized ACH and wire transfers out of a commercial account fall under UCC Article 4A, where allocation turns largely on whether the bank offered a commercially reasonable security procedure and the customer used it. Declining dual control on your treasury platform can decide who eats the loss.
All of this sits next to the older question of which duties should never land on the same person. That’s a control design problem in its own right. The question here is narrower. Which rights does an outsourced team actually need?
If you’re still deciding whether to move the books outside at all, we covered that in our piece on working with a remote bookkeeping team. This page assumes the decision is made.
What a SOC 2 Report Proves, and What It Does Not
A SOC 2 report is an independent CPA’s attestation about a service organization’s controls. It’s not a certificate and it’s not a pass or fail. SOC engagements are examinations performed under AICPA attestation standards, delivered as a report containing the auditor’s opinion.
SOC 2 outsourced accounting is a phrase on nearly every provider page in this category. The report behind it is the only part that counts as evidence.
There are five trust services criteria. Security, Availability, Processing Integrity, Confidentiality, and Privacy. Only Security is required in every examination, which is why it’s called the common criteria. Two firms can both say they’re SOC 2 and have audited different things, so ask which criteria were in scope. For an accounting engagement, add Confidentiality and Processing Integrity to the Security baseline.
Type I tells you it exists. Type II tells you it held.
| Dimension | SOC 2 Type I | SOC 2 Type II |
|---|---|---|
| What it evaluates | Control design | Design and operating effectiveness |
| Time frame | A single date | A window, typically 3 to 12 months |
| Question answered | Would the control work if it ran as intended? | Did the control actually run, consistently? |
| Evidence | Inspection of design | Sampling and testing, exceptions disclosed |
A Type I is a reasonable answer from a firm in its first year of a program, and an unreasonable one from an established firm. For a provider holding standing access to your bank feeds for years, the Type II is the report that matters.
Then check the date. A Type II covers a period ending on a stated day and says nothing about the months after it. Where that period closes before your assessment date, the standard remedy is a bridge letter, issued by the provider rather than the auditor, attesting that nothing material changed in the interim. Practice caps it at roughly three months. A period that closed eleven months ago with no bridge letter is a finding, not a formality.
The two disclosures that change how you read a clean opinion
Complementary user entity controls. These are controls the service organization assumed you would run, necessary in combination with its own to meet the stated commitments. They’re a required disclosure. A clean opinion covers the provider’s controls on the assumption that yours are working. If the report says the user entity reviews access lists quarterly and approves disbursements, and you aren’t, the assurance doesn’t reach the gap you just created. Read that section first. It’s your own task list.
Carve-out versus inclusive method. Where a provider relies on a subservice organization, a cloud host or a payroll engine, the report either carves it out of scope or pulls it in and tests it. Carve-out is far more common. Under carve-out, what the provider expects that organization to have in place is a disclosure, not a tested assertion. A clean report that carves out the host tells you nothing tested about the host. Ask what was carved out, and how it’s monitored.
The badge isn’t the report
SOC 2 reports are restricted-use documents. They describe system architecture, control design, and any exceptions the auditor found, which is why firms release them under NDA rather than posting them publicly. So the NDA request is normal.
A provider that won’t release the report at all, to a named prospect, under NDA, is telling you something.
Indinero is SOC 2 compliant as of 2026. Whoever you’re evaluating, run the same read. The opinion and the exact period, the scope line, the description of the system for subservice organizations and user entity controls, then the exceptions. Exceptions are normal. What matters is whether the response is specific and whether the exception touches logical access.
Bank and Payroll Access: Read-Only, Initiate, or Approve
There are three levels of financial system access, and most buyers grant the third when the first would do. An outsourced provider needs to see transactions. It sometimes needs to stage payments. It should almost never hold the right to release them.
Most lists of outsourced bookkeeping security risks stop at the bank login. That’s one row in a table with at least five.
- Tier 1, read-only. See balances, transactions, and statements, and feed data into the ledger. Cannot move money or change payees.
- Tier 2, initiate. Build a payment batch, enter a bill, create a payment run, queue a payroll. Cannot release it.
- Tier 3, approve. Authorize the transaction, add or change a payee, release funds, add or modify users.
| System | Provider holds | Your team keeps |
|---|---|---|
| Bank | Read-only, plus initiate where AP is in scope | Approval and release, payee creation, user administration |
| Accounting ledger | Bank feeds, deposits, transfers, chart of accounts, journal entries | Primary admin and user management |
| Payroll | Prepare and stage the run as a collaborator or custom admin | Approve and submit, by a named employee |
| AP tool | Bill and invoice entry, plus the read-only audit role | Approver and payer roles, administration |
| Corporate card | Transaction visibility and receipt matching | Card issuance and limit changes |
Why approval stays inside the company
Banks already design for this. Dual control requires two different users to initiate and approve outgoing payment orders, and to make user authorization changes. One person is blocked from doing both on the same transaction. Commercial platforms expose those as separate entitlements, and most recommend dual approval thresholds on ACH and wire.
The second reason is loss allocation. Under UCC Article 4A, whether a commercially reasonable security procedure was offered and used bears on who absorbs an unauthorized transfer from a commercial account, as the Federal Reserve’s guidance on unauthorized payments from business bank accounts sets out. Collapsing initiation and approval into one external party weakens that position.
One test covers every system. Can this role cause money to leave the company, or create a new destination for money? Then it’s tier 3, and it stays inside.
Don’t overcorrect to read-only everywhere
Read-only everything is a real failure mode too. A provider that can’t stage a payment run can’t run your AP, and you’ll end up doing the work you outsourced. A ledger role too narrow to post journal entries or manage bank feeds turns every close into a queue of requests back to your team.
The correct answer is tier 2 with a client-side release, not tier 1 everywhere. Getting that split right is most of the setup work in any online bookkeeping services engagement, and it’s worth an hour on the kickoff call. Guessing costs you a correction in month four.
Provisioning, Offboarding, and the Access Review Nobody Runs
Access granted correctly on day one decays, which is why provisioning and offboarding matter more than the initial grant. What holds over a multi-year engagement is named individual accounts, MFA, role-based scoping, a process for staff rotation, and a review on a calendar.
Named accounts, MFA, and role-based scoping
The shared login is the most common ask and the most expensive convenience. If three people at the provider share one account, no audit trail can say who posted the entry, and no offboarding event can be enforced without disrupting the other two. Every person who touches the data gets their own account, in every system.
That isn’t a preference. NIST SP 800-53 AC-6, Least Privilege, requires that users and processes receive only the access needed for their authorized tasks, with periodic review of assigned privileges.
Multi-factor authentication is the other floor. The FTC Safeguards Rule requires MFA for anyone accessing an information system, absent written approval of an equivalent or stronger control. Ask whether the provider enforces it centrally through single sign-on or leaves it to each platform’s settings. The first is verifiable. The second is a promise.
When their staff rolls off your account
Here’s the question buyers almost never ask. When someone on the provider’s team leaves our account, what happens to their access, who triggers it, on what timeline, and how do we see evidence?
Anchor it to a standard so it can’t be answered vaguely. CIS Control 6, Access Control Management, calls for an established and preferably automated process to revoke access by disabling accounts immediately on termination, rights revocation, or role change, and notes that disabling rather than deleting preserves the audit trail.
Read the wording. CIS says role change, not just termination. A provider employee who moves from your account to another client’s is a role change, and it should trigger revocation on your systems that same day. Most contracts only address termination of employment.
The access review nobody runs
Quarterly is the right cadence for a finance stack, with a full review at fiscal year end and an event-driven review whenever scope changes. The artifact is short and boring.
- Pull the current user list from every system in scope. Bank, ledger, payroll, AP tool, card program, document store.
- Record the named individual, the employer, the role, the access tier, and the date last used.
- Confirm each account still has a business need.
- Remove or downgrade anything you can’t justify.
- Sign it, date it, keep it.
Step five is the one people skip, and it’s the one that matters when an auditor, an insurer, or an acquirer’s diligence team asks. If you’re not certain which platforms belong in scope, our walkthrough of an outsourced accounting system maps what a typical engagement touches.
Offboarding the engagement itself needs three contract terms buyers routinely omit. What data comes back, in what format, on what timeline. When the provider and its subprocessors destroy their copies, and whether you get written certification. And a joint access termination checklist, signed by both sides.
The Questions to Ask Before You Hand Over Credentials
These are the ten questions to ask before you hand over credentials to an outsourced accounting provider. Send them verbatim. A firm running a real program answers all ten in writing inside a week, and the speed of the answers is a second signal.
- Will you provide your most recent SOC 2 report under NDA, is it Type I or Type II, which criteria were in scope, and what period does it cover? Good answer: a Type II, Security plus at least Confidentiality, a period ending within the last twelve months. If it closed more than three months ago, ask for a bridge letter.
- What subservice organizations are carved out of that report, and how do you monitor them? Good answer: a named list and a described monitoring process, not a wave at the cloud provider.
- What complementary user entity controls does the report assign to us? Good answer: they point to the section without hunting, which tells you they’ve read their own report.
- Where are the people who will touch our financial data located, and are any of them contractors rather than employees? Good answer: a direct answer on both. If the provider also prepares your returns, disclosing return information to a preparer outside the United States requires your written, signed, advance consent under IRC Section 7216, and it can’t be given after the fact.
- Give us your full subprocessor list, and how will you tell us when it changes? Good answer: a maintained list, a defined notice period, and a right to object.
- How fast will you notify us of a security incident affecting our data, in writing, in the contract? Good answer: a number in hours, measured from discovery rather than confirmation. Roughly twenty states set a numeric notification deadline between 30 and 60 days, and a vendor clock measured in days makes yours impossible to hit.
- Is our data encrypted at rest and in transit, and how? Good answer: a named standard, covering backups and not just the production database. The Safeguards Rule requires both states of encryption.
- Do you enforce MFA and named individual accounts for everyone on our account, and will you give us the user list on request? Good answer: yes, enforced centrally, and no hesitation about the list. The willingness is the real answer.
- What is your access review cadence, who performs it, and will you share the result for our account? Good answer: quarterly, performed by someone outside the delivery team, producing an artifact you can keep.
- What cyber liability coverage do you carry, at what limits, and will you provide a certificate of insurance? Good answer: a certificate, not a claim. Ask whether the policy responds to social engineering and funds transfer fraud, which are frequently sub-limited or excluded.
None of these are gotcha questions. Every one has a normal, boring, correct answer. The signal isn’t whether the answers are perfect. It’s whether they’re specific, written, and fast.
Then get them into the master services agreement or a security exhibit. The FTC Safeguards Rule puts the obligation to bind a service provider by contract on you, not on the provider. Verbal assurance during a sales call is not a safeguard. Send the list to every firm on your shortlist, whether that’s a bookkeeping-only vendor or a full outsourced accounting services engagement.
How Indinero Handles Access and Controls
Indinero is SOC 2 compliant as of 2026, and the part of the access model worth your attention falls out of how a bundled finance team is built.
Here’s what’s easy to miss while comparing providers. Buy bookkeeping from one vendor, tax from a second, and fractional CFO help from a third, and you run this entire page three times. Three vetting processes. Three sets of credentials. Three offboarding events. Three notification clocks, and every quarterly review reconciling three user lists that don’t agree.
Indinero gives you the full finance function, bookkeeping through CFO advisory, without managing three separate vendor contracts and timelines. One team means one attestation to read, one set of named accounts to provision, one access review to run, and one contract carrying the notification and confidentiality terms.
The vetting work doesn’t go away. It gets done once.
The second difference is structural. Indinero is CPA-led and GAAP-first, so the people holding access are bound by the AICPA Code of Professional Conduct, including its confidentiality rule and its requirements around disclosing client information to a third-party service provider. That’s a professional obligation on top of a contractual one.
On approval authority, we’ll say here what we’d say on a call. The named employee who releases a payment should work for you, not for us.
Continuous operations since 2009, 500+ regular customers, 100+ years combined team experience, and a 5-star Clutch rating are the track record. The access design is the part you can verify yourself, before a single credential changes hands. If you’d rather run the vetting on this page once instead of three times, that’s the case for one engagement covering all four layers of finance as a service.
Frequently asked questions
A handful of questions come up in almost every vetting call, usually right after the access request lands on someone’s desk. Here are the short answers.
Is outsourcing your accounting safer than keeping it in-house?
Outsourcing accounting isn’t inherently safer or riskier than keeping it in-house. What decides it is control design, who holds which access tier, and whether you can verify both. An outsourced onboarding grants entitlements across the ledger, bank feeds, and payroll in a single week, which is exactly when over-provisioning happens. Ask for the SOC 2 report, keep payment approval inside your company, and review access quarterly. Indinero is SOC 2 compliant as of 2026, and we’d tell you to run this same read on us.
Should an outsourced accountant have authority to send payments?
An outsourced accountant shouldn’t hold authority to release payments. Staging a batch or queuing payroll is tier 2 access, and that’s normal. Releasing funds, adding a payee, or changing users is tier 3, and that stays inside your company. Banks build dual control for exactly this reason, and UCC Article 4A ties your loss position on an unauthorized commercial transfer to using it. Indinero’s position is the same. The named employee who releases a payment should work for you, not for your provider.
What is the difference between a SOC 2 Type I and a Type II report?
A SOC 2 Type I judges control design at a point in time, and a Type II tests whether those controls held over months. Type II covers a window of three to twelve months, with sampling, testing, and exceptions disclosed. For a provider holding standing access to your bank feeds, Type II is the one that matters. Indinero is SOC 2 compliant as of 2026. Ask any provider for the type, the criteria in scope, and the period end date.
What happens to our financial data if the provider has a breach?
After a provider breach, what you get depends on your contract, because the obligations owed to you are the ones you wrote down. Under the FTC Safeguards Rule, the duty to vet a provider and bind it by written contract sits with you. State notification deadlines vary, so ask for notice in hours, measured from discovery, not from confirmation. With indinero, bookkeeping, tax, and CFO advisory sit in one engagement, so that’s one notification clause to negotiate instead of three.
How often should a provider review who has access to our systems?
Quarterly is the right cadence for a finance stack, with a full review at fiscal year end and an event-driven review whenever scope changes. Revocation shouldn’t wait for that review. When a provider’s staffer moves off your account, that’s a role change, and it should trigger removal the same day, not just at termination. Ask for the artifact, a signed and dated user list for every system in scope. With indinero that’s one list, since one team covers bookkeeping through CFO advisory.
Who at the provider can see payroll and compensation data?
Payroll and compensation data should be visible only to the named individuals whose work requires it, scoped by role-based permissions and least privilege. Shared logins break this, because no audit trail can say who opened the record. Ask for the named user list on your payroll platform, confirm MFA is enforced, and check that the provider’s role is prepare and stage rather than approve and submit. Indinero is CPA-led, so the people holding that access also carry the AICPA confidentiality rule.
Does a provider need admin rights to our bank account?
An outsourced accounting provider almost never needs admin rights on your bank account. Read-only access, plus initiation where AP is in scope, covers the work. Admin rights let a user add payees, change limits, and create other users, which is the tier that stays with your team alongside approval and release. One test settles it. If a role can move money out or create a new destination for it, it stays inside. Indinero takes the same position. Approval and user administration stay on your side.