The CPA Firm’s Checklist: How to Evaluate and Choose an Offshore Staffing Partner
Summary
A vendor due diligence checklist helps a CPA firm verify that an accounting outsourcing provider is legally established, financially stable, operationally capable, properly insured, and able to protect client information before a contract is signed or access is granted. This practical framework covers scope, evidence, pass-or-fail gates, vendor scoring, references, pilot testing, contracts, security, insurance, and ongoing reassessment.
A vendor due diligence checklist helps a CPA firm verify that an accounting outsourcing provider is legally established, financially stable, operationally capable, properly insured, and able to protect client information before a contract is signed or access is granted. The review should examine evidence, not rely on a proposal, badge, or sales answer.
AICPA & CIMA's Private Companies Practice Section has published a due diligence checklist for CPA firms evaluating offshoring vendors. It is a useful starting point. This guide turns those evaluation areas into a practical process: what to ask, what proof to request, which warning signs matter, and how to reach a defensible decision.
Key Takeaways
- Define the engagement before evaluating the provider. The required review depends on the work, systems, data, locations, and subcontractors involved.
- Verify claims with current evidence. Policies, reports, certificates, contracts, insurance, references, and test records answer different questions.
- Treat critical weaknesses as disqualifiers. A low price or strong reference cannot offset an unacceptable security, legal, continuity, or insurance gap.
- Test the operating model. A controlled pilot reveals more about quality, communication, access, and escalation than a sales presentation.
- Repeat the review. Vendor due diligence continues through renewal, material scope changes, incidents, and changes in ownership or assurance coverage.
Your 60-Second Decision Path
Use the checklist in this order. The sequence matters because it prevents a polished proposal or low price from compensating for an unacceptable risk.
| Step | Action | Decision produced |
|---|---|---|
| 1. Scope | Define the work, data, systems, permissions, locations, people, and subprocessors involved. | The depth of review required |
| 2. Verify | Request current evidence for every material claim. | A documented fact base |
| 3. Apply gates | Stop if a critical legal, security, continuity, insurance, or exit requirement is unresolved. | Pass, conditional pass, or reject |
| 4. Compare and pilot | Score providers consistently, call references, and test representative work under controlled access. | A capability and fit decision |
| 5. Monitor | Track conditions, evidence expiry dates, incidents, material changes, and renewal reviews. | Continued approval or corrective action |
Evidence rule: For every important vendor claim, record the document reviewed, its scope and date, the reviewer, any exception, the decision owner, and the next review date.
What Is a Due Diligence Checklist for an Accounting Outsourcing Provider?
In this context, due diligence is the structured review a CPA firm performs before allowing another organization to handle work, enter systems, or receive client information. It is different from acquisition due diligence and from the paid-preparer checklist used for certain tax credits.
The objective is not to prove that a provider is risk-free. No provider can make that promise. The objective is to determine whether the remaining risk is understood, controlled, contractually addressed, and acceptable to the firm.
The checklist organizes the evidence and approvals. The vendor risk assessment records the likelihood and impact of the risks the evidence reveals. Used together, they create a decision the firm can explain later to leadership, an auditor, an insurer, or a client.
A complete vendor assessment considers four questions:
- Can the company be trusted to remain in business and honor the agreement?
- Can its people perform the work accurately and consistently?
- Can it protect the information and systems it will access?
- Can the CPA firm monitor, correct, or end the relationship without losing control?
Define the Scope Before You Send the Questionnaire
A generic vendor security questionnaire produces generic answers. First document the actual engagement. This follows the risk-based approach in the NIST Cybersecurity Framework 2.0 supply-chain guidance, which recommends setting supplier requirements according to criticality and potential impact.
| Scope question | What the firm should record |
|---|---|
| Work | Bookkeeping, tax preparation, audit support, payroll, reporting, or another defined process |
| Data | Tax returns, Social Security numbers, payroll records, bank information, credentials, workpapers, or financial statements |
| Systems | Accounting, tax, payroll, document, email, workflow, and practice-management applications |
| Access | View, create, edit, export, approve, administer, or communicate permissions |
| People and locations | Named workers, supervisors, administrators, offices, remote locations, and support teams |
| Dependencies | Cloud services, subprocessors, backup providers, internet links, and other fourth parties |
| Criticality | Maximum tolerable downtime, deadline exposure, replacement difficulty, and client impact |
An offshore team accessing live tax or accounting systems and sensitive client information should receive a deeper review than a vendor that never sees client data. The evaluation should be proportionate to access and impact, not simply the vendor's size.
For covered firms, the FTC Safeguards Rule requires service-provider oversight that includes selection, contractual safeguards, monitoring, and periodic reassessment. The relationship should also be reflected in the firm's written information security program where applicable.
The 11-Part Vendor Due Diligence Checklist
Use this table during initial screening, document review, reference calls, contract negotiation, and renewal. A confident answer is helpful. Current, relevant evidence is better.
| Area to assess | Evidence to request | Warning signs |
|---|---|---|
| 1. Company identity and history | Legal entity name, registration, ownership, office locations, leadership, operating history, and primary contacts | The proposal, invoice, certificate, and contract name different entities; unclear ownership; no verifiable office |
| 2. Legal and regulatory standing | Business registrations, relevant licenses, litigation and sanctions disclosures, regulatory history, and counsel-reviewed representations | Unresolved legal issues; refusal to identify the contracting jurisdiction; vague claims of being “fully compliant” |
| 3. Financial stability | For a critical provider, three years of financial statements or equivalent financial evidence, credit information, and continuity funding | Persistent losses without explanation; delayed payroll or vendor payments; dependence on one client; refusal to provide any evidence |
| 4. Technology and infrastructure | System inventory, software compatibility, connectivity design, backup process, recovery objectives, disaster-recovery plan, and latest test summary | Untested recovery plan; unsupported software; unclear data locations; one office, connection, or administrator with no alternative |
| 5. Data security and confidentiality | Data-flow diagram, access matrix, MFA and device controls, encryption standards, logging, retention, deletion, incident plan, and subprocessor list | Shared accounts; personal devices; uncontrolled downloads; unknown subprocessors; no notification commitment; no deletion evidence |
| 6. Quality assurance | Documented workflow, preparer and reviewer responsibilities, checklists, exception handling, quality metrics, corrective-action process, and sample deliverables | “Every employee checks their own work”; no defined reviewer; repeated errors treated only as training issues; no root-cause process |
| 7. Workforce and expertise | Role profiles, qualifications, screening, training, turnover, coverage plan, supervision, and joiner-mover-leaver procedure | The sales team cannot identify who will do the work; no interview access; frequent reassignment; delayed access removal after departure |
| 8. References and relevant experience | Two or three references from comparable CPA or accounting firms, plus examples of similar workflows and software | Testimonials replace reference calls; references do not resemble your firm; the provider prevents practical questions about quality and escalation |
| 9. SLA and contract | Scope, deliverables, service levels, escalation, confidentiality, audit rights, incident notice, subcontracting, intellectual property, jurisdiction, termination, transition, and data return or destruction | Material promises remain outside the contract; unclear liability; unilateral changes; automatic renewal traps; no transition obligation |
| 10. Independent assessments | Current SOC 2 Type II report where relevant, current ISO/IEC 27001 certificate, penetration-test summary, remediation status, and assurance scope | A logo instead of a report; expired evidence; exclusions covering the service or office you will use; serious findings with no remediation proof |
| 11. Insurance | Professional liability and cyber insurance certificates, carrier, policy period, limits, deductibles, territory, key exclusions, and sublimits | Expired policy; limits unrelated to the exposure; offshore or subcontractor exclusions; reliance on your firm's insurance |

The AICPA checklist advises firms to involve their attorney in legal and contract questions and to inform their professional liability carrier. That is sensible. A checklist helps organize the review, but it does not replace advice about the firm's obligations, engagement, clients, or jurisdiction.
See how Acculink answers these checks.
Get a concise overview of our security, quality, staffing, continuity, and engagement approach.
Give Tax Information Its Own Review
If an offshore provider will prepare or support tax returns, review the disclosure and consent workflow before any tax return information moves. The IRS Section 7216 Information Center is the authoritative starting point. IRS guidance generally requires taxpayer consent before a US tax return preparer discloses tax return information to a tax return preparer outside the United States. Specific consent language, timing, permitted use, and Social Security number safeguards depend on the facts and applicable guidance, so the firm should have qualified counsel confirm its workflow.
For a practical starting point, review the Section 7216 sample consent forms. These samples are illustrative, not a substitute for the regulations or advice based on the firm's facts. Confirm the final form, required language, delivery method, duration, recipient details, permitted information, and SSN safeguards before use.
There is no general “Section 7216 certification” that removes the CPA firm's responsibility. Evaluate the provider's process, training, masking controls, permissions, and records, then document what the firm must do before access is enabled.
For a deeper technical review of access, reports, incident response, and contracts, use the separate accounting outsourcing data-security guide.
That deeper vendor security assessment should be completed by someone able to interpret the report scope, exceptions, technical controls, and obligations assigned to the CPA firm. Collecting the document without reviewing it is not due diligence.
Use Pass-or-Fail Gates Before a Vendor Scorecard
A weighted vendor scorecard is useful only after critical risks have passed. Otherwise a provider can compensate for an unacceptable security gap with attractive pricing, references, or communication.
Treat these as decision gates:
- The contracting entity and jurisdiction are clear.
- The firm understands where work and data will be handled.
- Access, confidentiality, incident, and deletion requirements can be put in the contract.
- The provider supplies relevant, current security evidence.
- The Section 7216 workflow is acceptable for any offshore tax work.
- Professional liability and cyber insurance are adequate for the engagement.
- Business continuity and exit arrangements are workable.
If the provider passes, score the remaining fit on a consistent five-point scale.
| Scored category | Suggested weight |
|---|---|
| Security, privacy, and compliance evidence | 25% |
| Quality-control design and work sample | 20% |
| Workforce capability, supervision, and continuity | 15% |
| Operational resilience and technology fit | 15% |
| Contract, SLA, insurance, and exit terms | 15% |
| Comparable experience and reference calls | 10% |
Define what scores one, three, and five mean before reviewing proposals. Record who scored each category, the evidence relied upon, open conditions, the approval owner, and the next review date. Price should be compared after unacceptable risk and capability gaps have been removed.
Take This Framework Into Your Next Vendor Meeting
Ask every shortlisted provider to respond to the same evidence requests, pass-or-fail gates, scorecard, reference questions, and pilot measures. If Acculink is on your shortlist, request a due diligence and workflow walkthrough and use this framework during the conversation.
Validate the Provider Through References, a Pilot, and Reassessment
Documents show how a provider says it operates. References and a controlled pilot test whether the operating model works for your firm.
During reference calls, ask about first-pass quality, manager rework, staff continuity, deadline performance, communication during problems, and whether the reference would choose the provider again. Speak with the person who oversees the work, not only the executive who signed the agreement.
For the pilot, use a defined group of representative tasks. Measure accuracy, completion of the firm's checklist, questions raised, turnaround, communication, access discipline, reviewer corrections, and escalation. Do not expand because the first file arrived quickly. Expand when the work is consistently review-ready and the controls function as designed.
Due diligence is not finished at onboarding. Reassess at contract renewal and when there is a material change in scope, data, system access, work location, subprocessor, ownership, key personnel, insurance, assurance coverage, or incident history. Track evidence expiry dates so an old report or certificate does not silently remain the basis for approval.
For the operational handoff after approval, see how the accounting outsourcing process should move from scope and access through preparation, review, sign-off, and feedback.
How Acculink Responds to This Due Diligence Checklist
Any provider should be willing to undergo the same review it recommends. Acculink encourages CPA and accounting firms to assess the engagement, assigned team, access model, quality process, current assurance evidence, continuity plan, insurance, contract terms, and exit procedure before making a decision. Firms can first review Acculink's accounting outsourcing services, then test the proposed engagement against every control in this checklist.
Acculink's published IT and data-security approach describes centrally managed devices, individual access, multifactor authentication, restricted local transfer, monitored offices, training, and documented offboarding. Its certificates and alliances page identifies the assurance documents firms can request. Those pages are useful introductions, but the correct diligence standard is to review the current documents, scope, dates, exceptions, and responsibilities that apply to your engagement.
For offshore tax support, Acculink can walk through how its workflow supports the CPA firm's Section 7216 consent, masking, access, and recordkeeping steps. The firm retains its own legal obligations, client relationship, professional judgment, and final review.
If you are actively comparing providers, request an Acculink due diligence walkthrough. Bring this checklist and ask the same questions you would ask any other provider.
Frequently Asked Questions
What is a due diligence checklist?
A due diligence checklist is a structured list of information, evidence, risks, and approvals used before entering or continuing a business relationship. For a CPA firm evaluating an offshore accounting provider, it should cover legal identity, financial stability, technology, data security, quality control, workforce, references, contracts, independent assessments, insurance, continuity, and exit.
What documents should a CPA firm request from an outsourcing provider?
Request documents proportionate to the engagement. A high-access provider may need to supply legal-entity information, financial evidence, a data-flow diagram, access controls, a SOC 2 Type II report, an ISO/IEC 27001 certificate, penetration-test and incident-response summaries, continuity-test evidence, insurance certificates, quality procedures, reference contacts, subcontractor details, and proposed contract terms.
Is a SOC 2 Type II report enough to approve a provider?
No. Review the report's legal entity, systems, services, locations, period, exceptions, subprocessors, and complementary controls assigned to your firm. Then evaluate financial stability, workforce, quality, continuity, insurance, contract, and engagement-specific access. SOC 2 is one source of evidence, not approval by itself.
Does Section 7216 apply to every outsourced accounting engagement?
Section 7216 concerns the disclosure or use of tax return information by tax return preparers. It may not govern an engagement that involves no tax return information, but other confidentiality, privacy, contractual, professional, and state requirements may still apply. Obtain qualified advice for the actual work and data involved.
Is a vendor compliance checklist the same as a due diligence checklist?
No. A vendor compliance checklist usually tests whether a provider meets defined legal, policy, or contractual requirements. Due diligence is broader. It also examines financial stability, capability, quality, references, continuity, insurance, and whether the overall risk is acceptable. Compliance is one part of the final decision.
How should CPA firms compare two offshore providers?
Apply the same pass-or-fail requirements, evidence list, reference questions, pilot tasks, and scoring definitions to both providers. Compare verified facts rather than presentation quality. Document unresolved risks and contract conditions separately from the numerical score.
How often should vendor due diligence be repeated?
Set a schedule based on risk and repeat the review at renewal. Reassess sooner after a material change in services, data access, locations, ownership, subprocessors, certifications, insurance, key personnel, or incident history. High-impact providers generally require more frequent monitoring than low-risk vendors.
Should an outsourcing provider carry cyber insurance?
Appropriate cyber liability and professional liability coverage should be part of the review. Examine the carrier, dates, limits, territory, deductibles, exclusions, subcontractor coverage, and sublimits with your broker. The provider's policy does not replace the CPA firm's own coverage.
The Bottom Line
The best due diligence checklist does more than collect yes-or-no answers. It connects each important claim to evidence, a reviewer, a decision, a contract term, and a future reassessment date.
Use the framework before client data moves, compare providers on the same basis, and stop the evaluation when a critical gap cannot be resolved. A provider that is prepared for serious CPA-firm work should welcome that level of scrutiny.
Put Acculink through your due diligence process.
Bring your checklist. We will walk through the workflow, evidence, and pilot scope relevant to your firm.
Tags:
Related Posts
Top 10 Offshore Staffing Companies for Accounting Firms (2026)
Hiring an offshore team is one of the highest-leverage moves a short-staffed CPA firm can make, but the partne…
Top Outsourced Accounting Firms for CPA Practices (2026)
Choosing an outsourced accounting partner is a high-stakes call because the team touches your clients' data. T…
Top Tax Outsourcing Companies for CPA and Accounting Firms (2026 Rankings)
The top tax outsourcing companies for CPA firms in 2026 are Acculink CPA, QX Accounting Services, CapActix, Da…