Data security while outsourcing the accounting function requires a combination of contractual, technical and organisational controls that protect client financial and personal data. This usually happens once it leaves a UK practice’s systems and lands with a third-party provider. In short, it is everything that has to hold together when the firm no longer has physical control of the file.

An easy way to picture data security is a set of keys. Outsourcing does not hand over the building. It hands a copy of the keys to somebody else, and the practice remains the named leaseholder. If the alarm is left off, the landlord comes to the leaseholder first.

That is not a metaphor stretched for effect. Under the UK GDPR, the practice is almost always the controller and the outsourcing provider is the processor, and the controller carries the accountability. The Information Commissioner’s Office does not accept “our supplier handled that” as a defence, and the practical consequences reach past regulatory fines into professional indemnity claims, PII renewals, client attrition and awkward conversations with the ICAEW or ACCA.

This blog explains what UK accounting practices should check before, during and after an outsourcing engagement. It looks at the current legal position, the standards that carry weight, and the numbers a partner should take note of. The checks hold for any data security accounting outsourcing UK review, whether the delivery team sits in Leeds or Lucknow.

What does data security in accounting outsourcing actually cover?

Most partners think of it as encryption and firewalls. Those matter, but they are one layer of four.

Layer What it covers Typical evidence a firm should request
Legal Controller and processor roles, Article 28 contract terms, international transfer route Signed data processing agreement, IDTA or UK Addendum, transfer risk assessment
Technical Encryption, access control, endpoint hardening, logging Certification scope statement, penetration test summary, control matrix
Organisational Screening, training, segregation of duties, clear desk and clear screen HR screening policy, training completion records, floor plan of the delivery area
Operational Incident detection, notification timing, exit and deletion Incident response plan, breach notification SLA, data return and destruction certificate

Weak providers are usually strong on layer two and thin on layers one and four. The contract is generic, and nobody has ever tested what happens on the day the relationship ends.

Who is the controller and who is the processor?

The practice decides why and how client data gets processed, so the practice is the controller. The outsourcing provider acts on documented instructions, so the provider is the processor. ICAEW’s Technical Advisory Service publishes a helpsheet on exactly this question, because firms get it wrong often enough to warrant one.

Why the split matters more than firms expect

Controllers must appoint only processors that provide sufficient guarantees about their security measures. That is an active duty, not a box on a form. A firm that accepted a provider’s marketing claims and never asked for evidence has not discharged it, and the ICO has said so repeatedly in its enforcement notices.

Why does the liability sit with the UK firm?

Because the law puts it there, and because the regulator has started demonstrating the point with penalties large enough to notice.

On 15 October 2025, the ICO fined outsourcing group Capita plc and Capita Pension Solutions Limited a combined £14 million after a March 2023 ransomware attack exposed the personal data of 6,656,037 people. The original proposed penalty was £45 million, reduced through a voluntary settlement in which Capita waived its right to appeal. The breach reached 325 of the 600-plus organisations that relied on Capita Pension Solutions. Each of those organisations was a client that had, at some point, decided the provider looked safe enough.

The detail that should interest accountancy partners is the cause of the data leak. A staff member downloaded a malicious file. The infected device was not quarantined for 58 hours. Information Commissioner John Edwards described it as a failure to protect data entrusted to the firm by millions of people.

How large is third-party risk in the UK right now?

The Department for Science, Innovation and Technology published the Cyber Security Breaches Survey 2025/2026 on 30 April 2026, based on fieldwork with 2,112 UK businesses between August and December 2025. The findings give firms a defensible benchmark.

Measure (UK businesses, 2025/2026) Figure
Identified a cyber breach or attack in the last 12 months 43% (around 612,000 businesses)
Finance or insurance sector breach rate 44%
Phishing as the most prevalent attack type 38% of all businesses
Formally review cyber risks posed by immediate suppliers 15%
Formally review risks across the wider supply chain 6%
Hold a formal incident response plan 25%
Require two-factor authentication anywhere 47%
Hold personal data with no encryption or anonymisation applied 14%
Hold Cyber Essentials certification 5%
Did not know whether their organisation held Cyber Essentials, Cyber Essentials Plus or ISO 27001 18%

It’s important to note that only 15% of UK businesses formally review the risk posed by the suppliers they already use, and only 6% look beyond the first tier. Among medium businesses the figure rises to 30%, and among large businesses to 48%, which tells you that supplier due diligence is a discipline that arrives with scale rather than with common sense.

For a practice weighing up secure accounting outsourcing data UK arrangements, the benchmark cuts both ways. It sets a low bar for what competitors are doing. It sets no bar at all for what the ICO expects.

What must UK firms check before signing?

Before a UK practice decides to sign the dotted line, here are seven checks to consider. This is the the order they should happen.

1. Does the contract meet Article 28 of the UK GDPR?

A data processing agreement is a legal requirement, not a courtesy document. Article 28 requires the contract to set out the subject matter, duration, nature and purpose of processing, the types of personal data and categories of data subject, and the processor’s obligations on confidentiality, security, sub-processors, data subject rights, deletion and audit.

Clauses worth arguing over

Sub-processor approval is the clause most firms wave through. If the provider can appoint a new sub-processor by posting a notice on a webpage, the practice has lost sight of its own data map. Insist on prior written notice with a right to object.

Liability caps come second. A cap set at three months of fees, against a UK GDPR maximum penalty of £17.5 million or 4% of global turnover, is not a commercial position. It is a transfer of risk back onto the practice.

2. Where does the data physically sit, and how does it get there?

This is where GDPR outsourcing accounting UK arrangements most often break down. India, the Philippines and South Africa hold no UK adequacy regulations. A transfer of UK personal data to a delivery centre in any of them is a restricted transfer, and it needs a lawful route.

That route is the ICO’s International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, supported by a transfer risk assessment. The ICO updated its international transfer guidance in January 2026, and the rules governing that assessment, now referred to in UK legislation as the data protection test, took effect on 5 February 2026. Transfer risk assessments completed before that date should be reviewed rather than assumed to still be sound.

India’s Digital Personal Data Protection Act 2023 does not change the position. A local law in the receiving country does not create a UK adequacy finding, and it does not remove the exporter’s obligation.

Firms should ask three specific questions and get them answered in writing:

  • Where is data processed
  • Where is it backed up
  • Which entity in the provider’s group signs the transfer agreement

3. Is the ISO 27001 certificate genuine, current and in scope?

ISO 27001 accounting outsourcing UK claims deserve more scrutiny in 2026 than they did two years ago, for a reason many buyers have missed.

The International Accreditation Forum set 31 October 2025 as the final deadline for transition from ISO/IEC 27001:2013 to ISO/IEC 27001:2022. Certificates issued against the 2013 edition expired or were withdrawn on that date, regardless of the expiry date printed on the certificate itself. Any provider still circulating a 2013 certificate is circulating a document with no standing.

Certificate check What to verify
Edition ISO/IEC 27001:2022 only. A 2013 certificate has been invalid since 31 October 2025
Accreditation Issued by a body accredited by UKAS or an equivalent national accreditation body, not a self-declared certifier
Scope statement Names the delivery centres and the accounting and financial data processing that the firm’s work will sit inside
Statement of Applicability Available on request, showing which of the 93 Annex A controls apply and which have been excluded
Surveillance status Last surveillance audit within 12 months, no open major nonconformities

Scope is where most certificates fail during a serious review. A certificate covering a head office in one city says nothing about the delivery of service in another. SOC 2 Type II reports carry similar weight and cover a defined period rather than a point in time, which makes them useful alongside ISO 27001 rather than instead of it. Cyber Essentials Plus adds an independently tested baseline, and only 2% of UK businesses hold it.

4. Who can see the data, and how quickly do they stop seeing it?

Role-based access on the principle of least privilege, multi-factor authentication on every account, and quarterly access reviews. Those are the entry requirements.

The question that separates providers is the leaver process. When an offshore team member resigns on a Friday, when does the account get disabled? A provider that cannot answer in hours has an access control problem it has not noticed yet.

5. What happens in the first 72 hours of a breach?

Under UK GDPR, a controller has 72 hours to notify the ICO of a reportable personal data breach. The processor must notify the controller without undue delay, which means the practice needs its own clock to start well inside that window.

A contractual notification SLA of 24 hours from detection is reasonable. A named contact reachable outside Indian or UK working hours is essential. The Capita penalty turned partly on a 58-hour delay in quarantining one infected device, which is a useful number to quote in a negotiation.

6. Who has been screened, and what have they been trained on?

Background verification before access, confidentiality undertakings signed individually rather than at company level, and annual UK GDPR training tied to the data the team actually handles.

DSIT found that only 19% of UK businesses ran any staff training or awareness activity in the last 12 months. Providers who exceed that materially should be able to prove it with completion records and phishing simulation results, not a slide in a pitch deck.

7. What happens to the data at the end?

Exit provisions get drafted last and tested never. The contract should state the return format, the deletion timetable including backups and archives, and the certificate of destruction the provider will issue.

Retention rules complicate this. HMRC requires most business records to be kept for at least six years, and money laundering regulations require records for five years after the end of the business relationship. Deletion at the provider must respect what the practice is separately obliged to retain.

Which answers should worry a partner?

A short diagnostic for the due diligence call.

Question Weak answer Strong answer
Where is our data stored and backed up? “Secure servers” Named data centre locations, named group entity, backup region stated
Which ISO 27001 edition are you certified to? “We’re ISO certified” 2022 edition, certificate number, accreditation body, scope statement supplied
How fast do you tell us about a breach? “As soon as possible” Contractual hours from detection, named 24-hour contact, tested plan
Can we audit you? “We provide a report annually” Right to audit in the DPA, plus recent penetration test and SOC 2 Type II
Who are your sub-processors? “We may use partners” Current list, prior notice, right to object
What insurance do you carry? “We’re fully insured” Professional indemnity and cyber liability limits stated, certificate names the firm

What changed in UK data protection law during 2026?

The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025 and has been commenced in stages. The principal data protection provisions came into force on 5 February 2026, introducing recognised legitimate interests, a revised approach to automated decision-making under new Articles 22A to 22D, and clarified rules on subject access request searches and the stop-the-clock mechanism.

From 19 June 2026, individuals hold a statutory right to complain directly to a controller under section 164A of the Data Protection Act 2018. Controllers must provide an accessible complaints route, acknowledge a complaint within 30 days and respond without undue delay. Practices that outsource need a process capable of pulling information back from the provider fast enough to meet that timetable.

The ICO’s updated international transfer guidance, published in January 2026, changed how transfer risk assessments are documented. Historic assessments and vendor questionnaires prepared before it should be revisited.

How should firms monitor a provider after go-live?

Due diligence at selection is the easy part. Governance across the following three years is where practices drift.

Frequency Activity
Monthly Log review of access exceptions and failed authentication attempts
Quarterly Access recertification, sub-processor list reconciliation, security review call
Annually Certificate and insurance renewal check, refreshed transfer risk assessment, DPA review against current guidance
Every two years Tabletop breach exercise run jointly with the provider

This is by no means expensive. It is calendar discipline, and it produces the audit trail that answers the ICO’s first question after an incident, which is always some version of “what did you check, and when?”

What does a well-run arrangement look like?

Secure accounting outsourcing data UK arrangements come down to something a partner can recite from memory. The practice knows which entity holds its data, in which building, under which certificate, on which contract, and by which transfer route, and can produce the paperwork on request within a day.

That is the standard. Firms that reach it usually find the outsourced environment holds tighter controls than their own office, because the provider’s commercial survival depends on the certificate and the practice’s does not.