Before sending client data to an offshore accounting partner, ask eight questions: where the data lives, who can see it, how access is granted and revoked, where the work is physically done, what the people have signed, how a breach would be handled, what the partner is insured and certified for, and what happens on exit. The answers you want are specific and boring. Vague reassurance is the warning sign.
Use these questions with any partner, including Cadence. The Cadence notes describe what to request for a proposed engagement; they do not verify controls or documents that have not been supplied.
1. Where does our data live?
The answer you want: in your own systems. The partner logs in to your Xero, QuickBooks, Sage, CCH or payroll software and works there. Working papers are saved where you specify: your shared drive, your practice management system, your document portal. Nothing is copied to the partner's own servers, laptops or cloud storage as a matter of routine.
The warning sign: "We take a backup of your file so we can work offline," or a workflow that involves emailing spreadsheets of client data back and forth.
For a Cadence engagement: agree where working papers are created, stored, transferred and deleted. Ask for the current process in writing before sharing records.
2. Who can see it?
The answer you want: a named list of people and roles with access to your records, the reason each needs it, and how access is reviewed. Use individual logins and the minimum permissions needed for the work.
The warning sign: a shared login, a generic "team@" account, or an inability to tell you who exactly has access.
For a Cadence engagement: agree named users, permitted roles and an access list that your firm can review before work begins.
3. How is access granted, and how is it taken away?
The answer you want: you control named users on your subscription, enable two-factor authentication where available, and can revoke access promptly. Agree when team changes must be reported and how access removal will be confirmed on exit.
The warning sign: the partner owns the software subscription, or access removal depends on the partner remembering to do it.
For a Cadence engagement: agree who creates and removes each login, how team changes are reported, and what written evidence is provided when access ends.
4. Where is the work physically done?
The answer you want: in an office, on devices the partner manages, with the controls you would expect: disk encryption, screen locks, no personal devices, no removable media, restricted printing, and a clean-desk policy for anything on paper. If home working is permitted, ask what the controls are and whether client data is ever on a personal device.
The warning sign: a network of freelancers on their own laptops, or no clear answer about devices.
For a Cadence engagement: ask for current written details of work locations, staff arrangements, device controls and any certification before granting access. This article does not verify those controls.
5. What have the people signed?
The answer you want: evidence that people with access are bound by confidentiality, trained for the work and checked where your policy requires it. Agree processing terms for the actual data flow, applicable law, permitted subcontractors and the firm's client obligations; add client-contact restrictions where needed.
The warning sign: an NDA with the partner's company but nothing with the individuals, or a refusal to sign your data processing terms.
For a Cadence engagement: review the current confidentiality and data-processing terms, and ask for evidence of staff checks and training where your firm's policy requires them.
6. What happens if something goes wrong?
The answer you want: a written incident process with a named contact and a notification time agreed for the data and legal duties involved. Ask how incidents are identified, contained and documented, and how the partner would help with any notification you must make to a client or regulator.
The warning sign: "That has never happened," offered as the whole answer.
For a Cadence engagement: agree incident contacts, response steps and notification timing in the contract before work begins. Do not rely on a website statement for the notification period.
7. What are you insured and certified for?
The answer you want: current evidence for any insurance or certification the partner claims, including the policy schedule, exclusions and the scope of any certificate. Decide what cover your firm needs before relying on a badge or a verbal assurance.
The warning sign: badges on the website with no documents behind them.
For a Cadence engagement: request the current policy schedule and any certificate before relying on insurance or certification. No cover or certification is claimed here until supporting documents are verified.
8. What happens on exit?
The answer you want: an agreed notice period, handover of working papers in a usable format, access revocation and written deletion or return terms. Specify any retention required by law or the engagement, so the exit plan covers copies and backups too.
The warning sign: exit terms that are silent on data, or a partner that resists agreeing them upfront.
For a Cadence engagement: set notice, working-paper handover, access removal, deletion evidence and retention terms in the signed agreement.
The pattern behind the answers
Ask for the specific people, systems, controls and documents that apply to your engagement. Check them against your firm's own requirements and follow up where an answer is incomplete. A written policy helps, but the firm also needs to know how it is used in practice.
A note on jurisdiction
Cross-border access needs a check for the specific data, location and roles involved. Keeping files in your software does not by itself settle international-transfer or subcontracting obligations. For UK personal data, the ICO's transfer guide explains when making data accessible outside the UK may be a restricted transfer, and its processor-contract guidance covers required terms and checks. Determine the actual roles and mechanism with your privacy adviser before sharing client records.
Ask Cadence these questions. Request the current controls and any supporting documents during a proposal review, then agree the processing and access terms before sharing records. Ask a question or request a proposal.



