It's the first question every partner asks, and the right one: our clients trust us with Social Security numbers, income details, and bank accounts — can that data safely flow through a preparation team on the other side of the world? The honest answer: yes, when specific controls are in place; no, when they aren't. Safety is a property of the engagement design, not the geography.
The Controls That Make It Safe
- No data at rest offshore: preparers work in your environment or a secured private cloud via controlled remote sessions — documents are never downloaded to local machines
- Locked-down facilities and devices: monitored floors, disabled USB and printing, no personal devices in the work area, screen-recorded sessions
- Access on a per-engagement basis: named individuals, least-privilege permissions, immediate revocation when someone rolls off
- Encryption everywhere: in transit and at rest, with your firm controlling the keys where possible
- Background-verified staff under NDA: with training on US confidentiality standards, including IRC 6713 and 7216 exposure
- Audited controls: SOC 2-type independent examination, plus alignment with IRS Publication 4557 and the GLBA Safeguards Rule (which your own WISP must reflect)
The Legal Layer
Offshore preparation is lawful and mainstream, with one bright-line requirement: Section 7216 client consent before return information is disclosed to a preparer outside the United States, using compliant language and timing. A capable provider delivers this as a ready-made workflow.
Red Flags That Should End the Conversation
- Files exchanged by email or consumer file-sharing links
- Vague answers about where data physically resides
- No named team — work distributed to anonymous, rotating preparers
- "We handle 7216 for you" with no documented consent process you can inspect
- No independent audit of controls, or reluctance to complete your security questionnaire
Perspective: Your Current Risk Baseline
Evaluate offshore controls against your actual baseline — not perfection. A small firm's reality is often unencrypted email attachments, a shared office drive, and no formal WISP. A well-run offshore environment with monitored access and audited controls is frequently a security upgrade over the status quo.
How GTPH Handles It
GTPH operates controlled preparation environments with no-local-storage policies, named teams under NDA, a documented 7216 consent kit, and security aligned to Pub 4557 and GLBA — and we expect, and welcome, your security review before the first return moves.
