Security & data protection
The objection that should come first.
Under UK GDPR your practice remains the data controller. If client data is compromised, “the provider did it” is not a defence available to you, to your regulator or to your professional indemnity insurer. So this page is written for the person doing the diligence, not for the person reading the brochure.
- UK GDPR Article 28 DPA
- ISO 27001-aligned controls
- Named-login working
- Documented breach procedure
Your legal position
Controller, processor, and what that actually obliges you to do
Worth being precise, because the consequences of getting this wrong land on your firm rather than on ours.
Where we work for an accountancy practice, your firm is the data controller and B4ES is a processor acting only on your documented instructions. That relationship must be governed by a written agreement meeting the requirements of Article 28 of the UK GDPR — covering subject matter, duration, purpose, categories of data, confidentiality, security measures, sub-processing, assistance, deletion and audit rights.
Because processing takes place outside the UK, you also need an appropriate transfer mechanism and a transfer risk assessment on file. And because accountancy work routinely involves special category data, the risk assessment needs to reflect that rather than treat it as ordinary business data.
Separately, your engagement letters and privacy notice need to reflect that client data may be processed by a third party outside the UK. ICAEW and ACCA guidance both address this, and your professional obligations of confidentiality under the relevant Code of Ethics sit alongside — not instead of — your data protection obligations.
We provide the documentation to make all of that straightforward. We cannot discharge the obligation for you, and any provider implying otherwise is one to be careful with.
Diligence pack
Available before any commercial discussion
We would rather be assessed properly than sold to. Ask and we will send:
- Draft UK GDPR Article 28 data processing agreement for your legal review
- Information security policy summary and control framework overview
- Support for your international transfer risk assessment and transfer mechanism
- Sub-processor disclosure and the notification process for any change
- Business continuity and disaster recovery outline with recovery objectives
- Incident response and breach notification procedure with defined timescales
- Confidentiality and non-solicitation terms in the draft services agreement
- Sample working paper file and a completed quality control checklist
Controls
Four control domains, described specifically
The typical failure points in offshore processing are well documented: weak access management, uncontrolled data export, personal devices on the floor, insecure file transfer and limited monitoring. Each domain below addresses one of them directly.
Access control
- Work performed inside your systems under named user accounts you create and revoke
- Role-based permissions granted on least-privilege principles
- Multi-factor authentication enforced on every account and system
- Access reviewed at defined intervals and revoked immediately on team change
- Session and access logging retained and available for your review
Physical and endpoint
- Controlled delivery floor with access restricted to authorised personnel
- No personal devices, mobile phones or removable media on the processing floor
- Printing disabled by default and permitted only by documented exception
- Company-managed endpoints with full-disk encryption and centralised patching
- Clear desk and clear screen policy enforced and monitored
Technical
- Encryption in transit and at rest across all systems handling client data
- Secure file transfer only — no client data sent by unencrypted email attachment
- Endpoint protection, centralised logging and vulnerability management
- Segregated environments so one client's data is never visible to another's team
- Backup and recovery tested against defined recovery objectives
People
- Background verification appropriate to the role before access is granted
- Individual confidentiality undertakings signed by every team member
- Information security and data protection training at induction and annually
- Documented joiner, mover and leaver process tied to access revocation
- Disciplinary consequences for security breach set out in employment terms
Certification
What we hold, and what we do not
B4ES is a new venture. We will not claim certifications we have not earned, and we would encourage you to verify every certification claim made by any provider you are assessing — including the well-established ones.
Our operating controls are built to align with the ISO 27001 Annex A control set and with UK GDPR requirements. Alignment is not certification, and we are explicit about the difference. Independent certification is on our roadmap and we will publish it here when it is genuinely held, dated and verifiable.
In the meantime, what we can offer a diligence process is documentation, contractual commitment and access: the draft DPA, the control framework, the incident procedure, and the ability to put questions directly to the people responsible rather than to a sales team.
A fair question to ask us
“Why should we accept controls that are aligned rather than certified?” The honest answer: you may reasonably decide not to, and if certification is a hard requirement in your firm's supplier policy then we are not yet the right provider. What we would ask is that the assessment is applied consistently — a certificate confirms a management system was audited on a date, not that a specific engagement is well run.
Position and roadmap
Update this table as each item is achieved. Do not list anything here before it is held.
| Item | Status |
|---|---|
| UK GDPR Article 28 DPA | Provided on every engagement |
| Transfer risk assessment support | Provided on request |
| Confidentiality undertakings | Signed by all delivery personnel |
| ISO 27001 control alignment | Operating framework aligned |
| ICO registration | Roadmap — on UK incorporation |
| Cyber Essentials | Roadmap — targeted in first year |
| ISO 27001 certification | Roadmap — under assessment |
| ISO 9001 certification | Under consideration |
Current status is confirmed in writing at proposal stage and updated here as it changes.
Questions
What your diligence process will want to know
Does client data leave our systems?
No. Our teams work inside your software under named logins that you create, permission and revoke. We do not export client data into a B4ES environment and we do not hold copies of your clients' records. Where a file genuinely must be transferred, it goes through an encrypted channel you have approved — never as an email attachment.
Who exactly can see our clients' data?
Only the named individuals assigned to your engagement, and only for as long as they are assigned. Environments are segregated so one client's work is not visible to another client's team. You receive the list of named individuals at transition and are notified before it changes.
What happens if there is a breach?
We notify you without undue delay under a documented procedure with defined timescales, and provide the information you need to meet your own obligations — including any 72-hour notification you may owe the ICO. You receive the facts as we establish them rather than a summary after the investigation concludes, because your clock starts when you become aware.
Do you use sub-processors?
Delivery is provided through our named partner operation, disclosed to you at contract. Any change to sub-processing is notified in advance with a right to object, as Article 28 requires. We do not add sub-processors quietly.
Can we audit you?
Yes. The draft agreement includes audit and inspection rights. In practice most firms are satisfied by documentation review and a call with the people responsible, but the right is contractual rather than discretionary.
What happens to data when we leave?
Access is revoked by you. Any working papers or files held on our side are returned or securely deleted to your instruction, with written confirmation of deletion. There is no charge for this — an exit fee on data return is a practice we regard as indefensible.
Is our professional indemnity position affected?
You should check with your insurer, and we would encourage you to do so before contracting rather than after. Most policies contemplate the use of subcontractors provided the work is reviewed by the practice and the practice retains responsibility, which is exactly how our engagements are structured — but your policy wording governs, not our description of it.
Diligence
Ask for the documents before you ask for a price.
We would rather your first request was the draft DPA and the control framework than a quote. If our security position does not satisfy your firm's supplier policy, both of us find that out in week one instead of week twelve.
What to expect
- Draft DPA and control documentation issued before commercial discussion
- Direct access to the people responsible, not a sales team
- Written confirmation of certification status at proposal stage