IT & Cyber Security Compliance Guide for Accountants
Accountants hold clients' financial lives: bank details, payroll, tax returns and identity documents. That makes firms a high-value target, and it makes secure, well-run IT part of professional duty.
Confidentiality is a professional duty
Professional bodies such as ICAEW, ACCA and AAT set ethical standards that include confidentiality. Losing client financial data to a breach is a professional and reputational problem as well as a legal one.
Protect HMRC and Government Gateway access
Agent credentials for HMRC services, and clients' own Government Gateway details, are high-value. Criminals use them to file false returns and redirect refunds.
- Treat Government Gateway and practice-software logins as privileged accounts.
- Use multi-factor authentication everywhere it's offered, and never share logins between staff.
- Remove access promptly when someone leaves, and review who holds agent authorisations.
Anti-money-laundering records
Accountancy service providers must be supervised for anti-money-laundering purposes and keep customer due diligence records for a set period after the relationship ends. In IT terms, that means identity documents and checks are stored securely, access-controlled and backed up, but also disposed of properly when no longer required.
UK GDPR and Making Tax Digital
Firms are data controllers (and often processors) for client data, with duties to keep it secure and to report notifiable breaches to the ICO within 72 hours. Making Tax Digital, which is being phased in for Income Tax, increases reliance on software and digital records, so the security of those systems matters more each year.
If your firm carries out FCA-regulated activity, it will have additional expectations around operational resilience and outsourcing. Check with your compliance officer.
Your practical checklist
- Multi-factor authentication on email, practice software and HMRC access
- Unique logins for every member of staff, with no shared accounts
- Encrypted storage and secure client portals for sending documents
- Tested offsite backups of practice-management and accounting data
- Email security that blocks spoofing and phishing
- Documented joiner and leaver process with prompt access removal
- Secure storage and disposal for identity and AML records
- Staff trained to spot fake HMRC and bank messages
- An incident response and breach-reporting plan
- Cyber Essentials certification to reassure clients and insurers
Go to the source
- ICAEW
Professional body and AML supervisor for many chartered accountants. Other bodies (ACCA, AAT, CIOT) have equivalent standards.
- HMRC
Agent services, Government Gateway access and Making Tax Digital.
- Information Commissioner's Office (ICO)
UK GDPR and data protection, including breach reporting.
This guide is general information, not legal advice. Requirements change and depend on your circumstances, so check with your regulator or professional adviser.
Want your IT to stand up to scrutiny?
We help regulated firms put the right controls in place and keep the evidence ready.