Security & data protection
The objection that should come first.
Under UK GDPR your practice remains the data controller. If client data is compromised, “the provider did it” is not a defence available to you, to your regulator or to your professional indemnity insurer. This page is written for whoever is doing the diligence.
- UK GDPR Article 28 DPA
- ISO 27001-aligned controls
- Named-login working
- Documented breach procedure
Your legal position
Controller, processor, and what that obliges you to do
It is worth being precise, because mistakes here land on your firm.
Where we work for an accountancy practice, your firm is the data controller and B4ES is a processor acting only on your documented instructions. That relationship must be governed by a written agreement meeting the requirements of Article 28 of the UK GDPR, which covers subject matter, duration, purpose, categories of data, confidentiality, security measures, sub-processing, assistance, deletion and audit rights.
Because processing takes place outside the UK, you also need an appropriate transfer mechanism and a transfer risk assessment on file. Accountancy work routinely involves special category data, and the risk assessment needs to reflect that.
Separately, your engagement letters and privacy notice need to reflect that client data may be processed by a third party outside the UK. ICAEW and ACCA guidance both address this, and your professional obligations of confidentiality under the relevant Code of Ethics apply in addition to your data protection obligations.
We provide the documentation to make that straightforward, but the obligation stays with you. Be wary of any provider that implies otherwise.
Diligence pack
Available before any commercial discussion
We expect to be assessed properly. Ask and we will send:
- Draft UK GDPR Article 28 data processing agreement for your legal review
- Information security policy summary and control framework overview
- Support for your international transfer risk assessment and transfer mechanism
- Sub-processor disclosure and the notification process for any change
- Business continuity and disaster recovery outline with recovery objectives
- Incident response and breach notification procedure with defined timescales
- Confidentiality and non-solicitation terms in the draft services agreement
- Sample working paper file and a completed quality control checklist
Controls
Four control domains, described specifically
The typical failure points in offshore processing are well documented: weak access management, uncontrolled data export, personal devices on the floor, insecure file transfer and limited monitoring. Each domain below addresses one of them directly.
Access control
- Work performed inside your systems under named user accounts you create and revoke
- Role-based permissions granted on least-privilege principles
- Multi-factor authentication enforced on every account and system
- Access reviewed at defined intervals and revoked immediately on team change
- Session and access logging retained and available for your review
Physical and endpoint
- Controlled delivery floor with access restricted to authorised personnel
- No personal devices, mobile phones or removable media on the processing floor
- Printing disabled by default and permitted only by documented exception
- Company-managed endpoints with full-disk encryption and centralised patching
- Clear desk and clear screen policy enforced and monitored
Technical
- Encryption in transit and at rest across all systems handling client data
- Secure file transfer only, with no client data sent as an unencrypted email attachment
- Endpoint protection, centralised logging and vulnerability management
- Segregated environments so one client's data is never visible to another's team
- Backup and recovery tested against defined recovery objectives
People
- Background verification appropriate to the role before access is granted
- Individual confidentiality undertakings signed by every team member
- Information security and data protection training at induction and annually
- Documented joiner, mover and leaver process tied to access revocation
- Disciplinary consequences for security breach set out in employment terms
Certification
What we hold, and what we do not
B4ES is a new venture. We will not claim certifications we have not earned, and we encourage you to verify every certification claim made by any provider you assess, including the well-established ones.
Our operating controls are built to align with the ISO 27001 Annex A control set and with UK GDPR requirements. Alignment is not the same as certification. Independent certification is on our roadmap and we will publish it here when it is held, dated and verifiable.
In the meantime, what we can offer a diligence process is documentation, contractual commitment and access: the draft DPA, the control framework, the incident procedure, and direct access to the people responsible, so you can put your questions to them.
A fair question to ask us
“Why should we accept controls that are aligned rather than certified?” You may reasonably decide not to. If your firm's supplier policy requires certification, we are not yet the right provider. We would ask only that the assessment is applied consistently: a certificate confirms that a management system was audited on a certain date. It does not show that a specific engagement is well run.
Position and roadmap
Update this table as each item is achieved. Do not list anything here before it is held.
| Item | Status |
|---|---|
| UK GDPR Article 28 DPA | Provided on every engagement |
| Transfer risk assessment support | Provided on request |
| Confidentiality undertakings | Signed by all delivery personnel |
| ISO 27001 control alignment | Operating framework aligned |
| ICO registration | Roadmap: on UK incorporation |
| Cyber Essentials | Roadmap: targeted in first year |
| ISO 27001 certification | Roadmap: under assessment |
| ISO 9001 certification | Under consideration |
Current status is confirmed in writing at proposal stage and updated here as it changes.
Questions
What your diligence process will want to know
Does client data leave our systems?
No. Our teams work inside your software under named logins that you create, permission and revoke. We do not export client data into a B4ES environment and we do not hold copies of your clients' records. Where a file has to be transferred, it goes through an encrypted channel you have approved, never as an email attachment.
Who exactly can see our clients' data?
Only the named individuals assigned to your engagement, and only for as long as they are assigned. Environments are segregated so one client's work is not visible to another client's team. You receive the list of named individuals at transition and are notified before it changes.
What happens if there is a breach?
We notify you without undue delay under a documented procedure with defined timescales, and provide the information you need to meet your own obligations, including any 72-hour notification you may owe the ICO. We pass on the facts as we establish them, without waiting for the investigation to finish, because your clock starts when you become aware.
Do you use sub-processors?
Delivery is provided through our named partner operation, disclosed to you at contract. Any change to sub-processing is notified in advance with a right to object, as Article 28 requires.
Can we audit you?
Yes. The draft agreement includes audit and inspection rights. In practice most firms are satisfied by documentation review and a call with the people responsible, but the right is contractual rather than discretionary.
What happens to data when we leave?
Access is revoked by you. Any working papers or files held on our side are returned or securely deleted to your instruction, with written confirmation of deletion. There is no charge for this. We see no justification for an exit fee on data return.
Is our professional indemnity position affected?
You should check with your insurer, and we would encourage you to do so before contracting rather than after. Most policies contemplate the use of subcontractors provided the work is reviewed by the practice and the practice retains responsibility, which is how our engagements are structured. Even so, your policy wording governs, not our description of it.
Diligence
Ask for the documents before you ask for a price.
Start by asking for the draft DPA and the control framework. If our security position does not meet your firm's supplier policy, we both find out in week one instead of week twelve.
What to expect
- Draft DPA and control documentation issued before commercial discussion
- Direct access to the people responsible
- Written confirmation of certification status at proposal stage
