It is the question every firm asks on the second call, and most providers answer it the same way. Encrypted servers. Certified processes. Policies aligned with recognised standards. All true, all reassuring, and all describing the same underlying arrangement: your data leaves your systems and goes to live on theirs.
There is a different model. Your data stays exactly where it is, in your own cloud folder and your own accounting software, and the offshore team is given access to work inside it. Nothing is transferred, nothing is stored on the provider’s side, and every action stays visible in your own access log.
Worried about handing over financial records? WhatsApp us and we will walk you through exactly what access we would need, and what we would not.
Quick Summary — Two Models
| Transfer model | Access model | |
| Where data lives | Provider’s systems | Your systems, unchanged |
| Who holds the software | Provider’s subscription | Yours |
| Audit trail | Provider’s logs | Your logs |
| Ending the engagement | Request deletion, then trust it | Revoke access |
| What you rely on | Their security | Your own controls |
What the Transfer Model Actually Involves
You send documents. Bank statements, invoices, payroll files, sometimes credentials. They land in the provider’s drive, get worked on in the provider’s software, and copies remain wherever their systems keep them.
The security around that can be genuinely good. Encryption, access control, signed confidentiality terms. None of it is theatre.
But look at what you are actually relying on. You are relying on their controls, their staff turnover, their offboarding discipline, and their deletion policy. When the engagement ends you ask them to delete your data, and then you take their word for it. If they are breached, your records are in the blast radius of an event you had no visibility over.
The Access Model
Nothing moves.
Your accounting software stays on your subscription, under your administration. Your document folder stays in your own cloud storage. You grant the offshore team access to that folder and a user login in your own software, with whatever permissions you decide.
They work inside your environment. The file they open is your file. The entry they post appears in your system. The document they file goes into your folder.
Three things follow from that, and they matter more than any certificate.
You can see what happened. Cloud storage and accounting software both log activity by user. Who opened what, who changed what, when. You do not ask for a report — you look.
You control the permissions. Read-only where that is enough. No access to payroll if payroll is not in scope. Restricted to one entity where a group has several.
Ending it takes one click. Revoke the login. There is no deletion request, no waiting, no trusting. Access ends because access is all there ever was.
For European and UK Firms
Under GDPR, sending personal data outside the UK or EEA engages transfer obligations, and those are a genuine piece of work — the correct mechanism, documentation, and a record that stands up if anyone asks.
Where the data never leaves your systems, the analysis is different, though it is not nothing. Remote access by a team outside the region still needs to be thought about and documented properly. What changes is that you are not shipping a copy of your client data to a third country and hoping the paperwork holds.
The honest position is that the access model narrows the question rather than removing it, and narrower questions are easier to answer.
What Good Access Looks Like
Named users, not shared logins. You need to know which person did which thing, and a shared account destroys that.
Permissions scoped to the work. If the engagement is bookkeeping, there is no reason for access to payroll records or banking credentials.
Written scope and confidentiality before anything begins, setting out what the team may access and what it may not.
A named point of contact, so access questions have an owner rather than going to whoever answers.
And periodic review. Access granted in March and never looked at again is how most problems start.
What This Does Not Cover
Two things worth being straight about.
Banking credentials stay with you. An offshore bookkeeper does not need payment authority to record transactions, and no legitimate provider should ask for it.
And access is not the same as trust. The model removes the transfer risk, not the need to check who you are working with. Scope, confidentiality terms and references still matter.
Frequently Asked Questions
Do you keep a copy of our data?
In the access model, no. Work happens inside your systems, so there is no copy on the provider’s side to keep or delete.
What software do we have to use?
Yours. Whatever you already run — QuickBooks, Xero, Zoho, Sage or anything else — the team works in your login.
Can we see what the team has been doing?
Yes. Your cloud storage and your accounting software both log activity by named user, and those logs are yours.
How do we end the engagement?
Revoke the access. Nothing has to be returned or deleted.
Does this satisfy GDPR?
It narrows the question considerably, because there is no transfer of data to a third country. Remote access still needs to be documented properly. Take advice on your own position rather than assuming either way.
Do you need our bank login?
No. Recording transactions does not require payment authority, and it should not be granted.
References
- UK GDPR and EU GDPR — provisions on international transfers of personal data
- Digital Personal Data Protection Act, 2023 — obligations of data fiduciaries and processors
- Engagement and confidentiality terms, agreed in writing before access is granted
⚠️ Data protection obligations depend on your jurisdiction, your clients and the nature of the data. This is general guidance. Confirm your own position with your advisor before relying on it.
Related Reading: You Pick the Software. We Work in Your Login. · What an Offshore Bookkeeping Engagement Actually Includes · Outsourcing Accounting to India: Cost, Quality and Safety
Call or WhatsApp: +91 7448200422 Email: info@taxkitab.com See our Global Desk service, or get in touch to talk through what access an engagement would actually need.
Related Reading
- How US & UK CPA Firms Can Outsource Bookkeeping to India
- What an Offshore Bookkeeping Engagement Actually Includes
- You Pick the Software. We Work in Your Login.
Need help with this? TaxKitab handles Global Desk for businesses across India and overseas. You may also find our Outsourced Accounting useful. Talk to us.


