- Outsourcing tax return preparation offshore is legal – the IRS has permitted it since 2006 – but only with proper client consent under IRC Section 7216 obtained before any data leaves the United States.
- Consent is triggered by the preparer’s location, not the employment relationship – even your own firm’s offshore employees require client consent, while U.S.-based outsourcing does not.
- A compliant consent form must be a standalone document naming the specific purpose, the specific recipient, and the exact data involved, plus explicit language stating the data is leaving the U.S. and that U.S. privacy protections may not apply abroad.
- Skipping it isn’t a minor paperwork gap – violations carry criminal penalties of up to one year in prison and a $1,000 fine per taxpayer affected, plus civil exposure and lost client trust.
- Get the consent right and pair it with a security-certified outsourcing partner (SOC 2, ISO 27001/27701, WISP-aligned), and offshore tax prep is a fully compliant way to manage tax season capacity.
Ask any CPA firm, Enrolled Agent, or tax firm owner what stops them from outsourcing tax preparation, and the answer usually isn’t cost, and it isn’t quality. It’s a version of this question: “Is this even legal?”
The short answer is yes – outsourcing tax return preparation offshore is permitted by the IRS and has been for nearly two decades. The longer answer is that it’s permitted only if your firm follows a specific federal rule: IRC Section 7216. Get it right, and offshore outsourcing is a fully compliant, mainstream way to manage tax season capacity. Get it wrong, and you’re looking at criminal penalties, not just an awkward client conversation.
Here we covers exactly what Section 7216 requires, what a compliant consent form has to contain, and the mistakes that get firms into trouble.
What Is IRS Section 7216?
Internal Revenue Code Section 7216 makes it a federal crime for a tax return preparer to knowingly or recklessly disclose or use a taxpayer’s tax return information for any purpose other than preparing that return – without the taxpayer’s consent (IRC §7216(a)).
The rule dates back decades, but the IRS explicitly addressed offshore outsourcing in its 2006 regulations, confirming that foreign outsourcing of tax return preparation is not prohibited outright – it’s simply conditioned on the taxpayer’s informed consent. That framework is still the law today, spelled out in 26 CFR §301.7216-2 (permissible disclosures without consent) and 26 CFR §301.7216-3 (consent requirements), with the mandatory consent wording prescribed in Revenue Procedure 2013-14.
In plain terms:
- You can always use a client’s tax data to prepare and file their return.
- The moment you want to disclose that data to someone else – including an offshore team – for any reason, you need the client’s written, informed consent first.
Get Ready for the Upcoming Tax Season Today!
Don’t wait for deadlines
Start early with a free tax prep trial ↗When You Need 7216 Consent for Outsourcing
The trigger isn’t “are we hiring a third party.” It’s “is anyone outside the United States going to see this taxpayer’s information.” That distinction catches a lot of firms off guard.
Domestic outsourcing: If you disclose a client’s tax return information to another preparer located within the United States (including its territories) for the purpose of preparing the return, no 7216 consent is required. This narrower exception is carved out in 26 CFR §301.7216-2(d)(1).
Offshore outsourcing: If any part of that preparation work is going to be seen by someone located outside the United States, consent is required under §301.7216-3.
Does it matter if the offshore preparer is our own employee?
No – and this is the single most common misunderstanding firms have. Some firms assume that if their offshore staff are direct employees of the firm (rather than a separate outsourcing company), the consent requirement doesn’t apply. It does. Under 26 CFR §301.7216-2(c)(2), the location of the preparer is what matters, not the employment relationship. An officer, employee, or member of your own firm who is located outside the United States still triggers the consent requirement before that person can see a client’s tax return information.
Does “data entry only” change anything?
No, or at least not safely. Even if the offshore team’s role is limited to data entry rather than substantive tax decisions, most practitioners treat this the same way – any offshore access to tax return information is a disclosure that requires consent. The IRS hasn’t published guidance carving out a data-entry exception, so the cautious and standard practice is to obtain consent for any offshore involvement, regardless of how limited the role is.
What a Compliant Consent Form Must Include
The IRS does not publish a fill-in-the-blank 7216 consent form. Preparers draft their own, and it must meet the requirements in 26 CFR §301.7216-3(a)(3)(i) and Revenue Procedure 2013-14, Section 5. A consent that’s missing even one required element is treated, legally, as no consent at all.
Every consent, regardless of destination, must contain (§301.7216-3(a)(3)(i)):
- The name of the tax return preparer and the name of the taxpayer. [§301.7216-3(a)(3)(i)(A)]
- The intended purpose of the disclosure, and the specific recipient(s) of the tax return information. [§301.7216-3(a)(3)(i)(B)]
- A specific description of the tax return information that will be disclosed or used. [§301.7216-3(a)(3)(i)(C)]
If the recipient is located outside the United States, additional mandatory disclosures apply (Rev. Proc. 2013-14, §5.04(1)(e)). The consent must also explicitly state:
- That the taxpayer’s information will be disclosed to a preparer located outside the United States.
- That U.S. legal protections regarding taxpayer privacy may not apply in the recipient’s country.
- That the firm has safeguards in place to protect the taxpayer’s data during that disclosure.
How consent must be obtained:
- It must be knowing and voluntary – the client has to actually understand what they’re agreeing to.
- It must be signed and dated by the taxpayer, on paper or through a permitted electronic signature process under Rev. Proc. 2013-14, Section 6, before any disclosure takes place.
- It cannot be bundled into a broader engagement letter or terms of service. It has to stand on its own as a distinct document the client is actually asked to review and sign.
- It cannot be coerced or made a condition the client feels pressured into. If a client declines, the firm cannot threaten to drop them or make consent feel mandatory to receive service.
What Happens If You Skip It
This isn’t a “fix it if a client complains” situation. Section 7216 violations carry real criminal exposure:
- Criminal penalty: A misdemeanor under IRC §7216(a), punishable by up to one year of imprisonment and a fine of up to $1,000 – per violation, meaning per taxpayer whose information was improperly disclosed.
- Civil exposure: Separate civil penalties can apply under IRC §6713, along with the malpractice and reputational fallout of a client discovering their data was sent overseas without their knowledge.
- Practical fallout: Beyond the legal exposure, this is the fastest way to destroy the trust that took years to build with a client – and it’s entirely avoidable with a properly drafted, properly executed consent form.
What to Do If a Client Declines Consent
This has to be planned for, not improvised in the moment. If a client won’t sign, that specific client’s return needs to be prepared entirely by domestic staff, with no offshore team involvement at any stage – even if every other client that season is being routed through your outsourcing partner. Firms that outsource well typically build this into their intake process from day one, so declining consent doesn’t create a scramble during peak season.
A Consent-Form Self-Audit Checklist
Before this tax season, pull your firm’s current 7216 consent language (if you have one) and check it against this list. If you can’t check every box, it’s time to have your consent form reviewed by counsel before your next offshore engagement.
- Is it a standalone document, separate from the engagement letter?
- Does it name the specific tax return preparer and the taxpayer?
- Does it state the specific purpose of the disclosure?
- Does it identify the specific recipient of the information (not just “a third party”)?
- Does it describe exactly what tax return information will be disclosed?
- If the recipient is offshore, does it explicitly say the data is going outside the United States?
- Does it state that U.S. privacy protections may not apply once the data leaves the country?
- Does it describe the safeguards protecting that data?
- Is it signed and dated by the taxpayer before any disclosure happens?
- Is there a documented process for what happens if a client declines?
How This Fits With WISP, SOC 2, and Your Outsourcing Partner’s Security Posture
Section 7216 consent answers the legal question of whether you’re allowed to send data offshore. It doesn’t, by itself, answer the separate question of how safely that data is being handled once it gets there – that’s where your firm’s Written Information Security Program (WISP) and your outsourcing partner’s certifications (SOC 2, ISO 27001/27701) come in. A firm can have airtight consent language and still be exposed if the offshore partner’s actual data-handling practices are weak, or the reverse – strong security with no valid consent still leaves you in violation.
Both pieces have to be in place together. If your firm hasn’t reviewed its WISP requirements recently, or wants a refresher on what the IRS expects from tax preparer data security more broadly, that’s covered in depth in AcoBloom’s WISP compliance guide and IRS tax preparer security requirements posts.
Frequently Asked Questions
Yes. The IRS has permitted offshore outsourcing of tax return preparation since 2006, provided the preparer obtains proper client consent under Section 7216 before disclosing any tax return information outside the United States, and maintains adequate data security safeguards.
Yes. Consent is triggered by the preparer’s physical location, not by whether they’re your direct employee or a third-party vendor’s staff. If they’re outside the United States, consent is required regardless of the employment relationship.
The regulations don’t specify a fixed renewal period, but best practice is to review and re-confirm consent whenever the outsourcing arrangement, provider, or scope of disclosed information changes – and to obtain fresh consent for each new engagement rather than relying on old paperwork from a prior tax season. Confirm your specific renewal cadence with your tax attorney.
That client’s return must be prepared without any offshore involvement. You cannot proceed with offshore disclosure for a client who hasn’t consented, no matter how minor the offshore role would be.
Yes, electronic signatures are permitted under the framework in Revenue Procedure 2013-14, provided the process meets the same requirements as a paper consent – informed, voluntary, and completed before any disclosure occurs.
No. The consent requirement specifically targets disclosure to a preparer located outside the United States. Domestic outsourcing arrangements fall under a separate, narrower exception.
The Bottom Line
Section 7216 isn’t a reason to avoid outsourcing tax preparation – it’s a solvable compliance requirement that thousands of CPA and tax firms already navigate successfully every season. The firms that get into trouble aren’t the ones who outsource; they’re the ones who treat the consent requirement as paperwork to get out of the way rather than a real legal obligation.
A properly drafted consent process, paired with an outsourcing partner that can demonstrate real security certifications (SOC 2, ISO 27001/27701, GDPR-ready, WISP-aligned practices), removes the legal risk entirely and lets your firm focus on what outsourcing is actually meant to solve: getting through tax season without burning out your team.