Tier Providers by Access and Business Consequence
A tax platform hosting taxpayer records requires a different review than an office-supply vendor. Prioritize providers that store customer information, administer identities or networks, maintain backups, process payroll, transmit returns, provide remote support, or could interrupt tax-season operations.
Critical data custodians
Tax platforms, portals, payroll, document management, cloud storage, and backup providers.
Privileged operators
MSPs, security providers, application support, hosting administrators, and remote-access vendors.
Operational dependencies
E-signature, communication, payment, scanning, shredding, and workflow providers.
Due Diligence Before Production Access
Confirm the exact service, data types, administrative access, authentication options, encryption, logging, incident-notification terms, subcontractors, data locations, resilience, retention, return, and deletion obligations. Review the contract and tenant configuration, not only a certification or generic questionnaire.
Material gaps should be resolved through configuration, contract language, compensating controls, reduced access, or provider replacement before sensitive information is introduced.
Oversight Continues After Contract Signature
Reassess providers after major service changes, incidents, acquisitions, control-report exceptions, changes in subcontractors, or material security findings. Offboarding should revoke accounts and integrations, recover required records, confirm contractual deletion obligations, and document completion.
A Risk-Tier Model for Tax-Firm Providers
Tier 1: Critical or privileged
Hosts substantial taxpayer information, administers identity or infrastructure, operates backups, or can materially interrupt filing. Require detailed due diligence, contract review, access design, incident coordination, recurring reassessment, and tested exit planning.
Tier 2: Elevated
Processes limited customer information or supports an important workflow without broad administrative control. Review data minimization, authentication, encryption, incident terms, subcontractors, resilience, and termination.
Tier 3: Standard
Has no customer-information access and limited operational consequence. Document the classification and monitor for changes in service, integration, or access that would raise the tier.
Tiering should consider confidentiality, integrity, availability, privileged access, concentration risk, substitutability, and the timing of disruption during tax season.
Monitor the Provider Without Repeating the Entire Audit
Use event-driven and periodic monitoring. Review material service changes, new integrations, administrator access, assurance-report exceptions, disclosed incidents, financial or ownership changes, unresolved findings, support performance, and upcoming renewals. Depth should match the risk tier.
Evidence can include assurance reports, penetration-test summaries, certifications, security questionnaires, architecture discussions, incident exercises, access reviews, and contract attestations. No single artifact proves the exact service remains adequate.
The FTC explains that covered firms must take steps to ensure service providers safeguard customer information. Use the current FTC Safeguards Rule guidance when defining selection, contract, and assessment practices.
Exit Planning Is Part of Due Diligence
Before onboarding, determine how the firm will export records, replace integrations, revoke credentials, transfer encryption keys where applicable, maintain legal holds, obtain deletion confirmation, and continue critical operations. A provider that cannot explain termination may create unacceptable lock-in or residual-data risk.
Authoritative Guidance
Use current official guidance when determining applicability and designing safeguards. This educational page does not replace legal, regulatory, tax, or professional compliance advice.