Outsourcing Tax Prep to India: Risks CPA Firms Must Vet
Before you outsource tax preparation to India, use this risk-assessment framework to vet data security, IRS liability exposure, and mandatory client disclosure rules—no vendor pitch included.
Every January, the same problem resurfaces at firms across the country: not enough hands to prepare returns before the deadline. PTIN holders are harder to find, seasonal staffing is unreliable, and the EA/CPA pipeline hasn't kept pace with demand. That gap is exactly why searches for outsource tax preparation India and "outsource tax return preparation India" spike every fall and winter — firm owners are looking for capacity they can't hire domestically.
Before going further, it helps to separate two terms that get used interchangeably but carry different risk profiles. Outsourcing means contracting with a third-party firm — often based in India — that employs its own staff and controls its own systems. Offshoring typically refers to a firm setting up its own overseas subsidiary or hiring dedicated overseas staff directly, sometimes through an employer-of-record arrangement. The distinction matters because liability, data control, and contractual leverage look different depending on which model you choose.
This article isn't a list of vendors to call. Plenty of sites already rank vendor roundups and promotional comparisons, and most of them lean heavily on one provider's pitch. What's missing from that content is a neutral framework for the due diligence a firm owner actually needs to do before signing a contract, regardless of which provider they're evaluating — or before deciding not to outsource at all. That's what follows: the legal requirements, the liability exposure, the data security questions, and the decision matrix to score any provider against. If your firm decides outsourcing makes sense, look for a provider built around the controls this article describes — domestic review, documented consent workflows, and audited data handling.
Is Outsourcing Tax Prep to India Legal? What the IRS Actually Requires
Yes, outsourcing tax preparation to India is legal — but it's conditional, not automatic. The governing rule is IRC Section 7216 and its companion Treasury Regulation 301.7216-3, which require tax return preparers to obtain written client consent before disclosing return information to any person located outside the United States, including its territories.
This isn't a formality you can skip by mentioning "third parties" somewhere in your engagement letter. Section 7216 disclosure has specific procedural requirements, and the IRS has published detailed guidance on the exact format and content mandated for consent forms, including offshore-specific language. If your consent form doesn't meet these standards, the disclosure is unauthorized regardless of your intent.
The penalties are not trivial. Under Section 7216, a knowing or reckless unauthorized disclosure of taxpayer information can result in criminal penalties — a misdemeanor, up to one year imprisonment, and fines up to $1,000 per disclosure. Separately, the civil penalty provisions under Section 6713 impose a $250 penalty per unauthorized use or disclosure, capped at $10,000 per year — though these figures periodically get adjusted for inflation, and the specific caps in effect matter, so confirm current amounts with a qualified tax professional before relying on them. Either way, "per violation" language means the numbers compound fast if a firm has been sending client data offshore without proper consent for a full season's worth of returns.
State boards of accountancy layer on additional obligations in some jurisdictions. A handful of states require CPAs to disclose the use of offshore preparers as part of professional conduct rules, separate from the federal 7216 requirement. If your firm is licensed in multiple states, check each board's rules — a consent form that satisfies the IRS doesn't necessarily satisfy every state licensing authority.
Client Disclosure Requirements: What Must Be in Writing
The written consent required for offshore tax preparation isn't optional boilerplate — it has to say specific things, and it has to say them clearly.
At minimum, a compliant disclosure for offshore preparation should include:
- A clear statement that the client's tax return information will be disclosed to a preparer located outside the United States
- Identification of the country (or countries) where the data will be sent
- A statement that the client can refuse to consent, and that refusal will not affect the firm's willingness to provide services (this is a specific 7216 requirement — you cannot condition service on offshore consent)
- The scope of information being disclosed
- A separate signature or acknowledgment line — this cannot be a single checkbox buried inside a 12-page engagement letter template
Timing matters as much as content. Consent must be secured before any data leaves the United States. Firms sometimes treat this as a post-hoc formality — get the return prepared, then have the client sign something during the review call. That sequence is backward and it's a violation regardless of whether the client ultimately signs. The consent has to precede the disclosure, full stop.
You also need a documented process for clients who decline. If a client opts out, the firm needs a workflow that routes that return to a domestic preparer instead — which means your outsourcing arrangement can't assume 100% participation. Build capacity assuming some percentage of clients will say no, and have a plan for handling withdrawn consent mid-engagement too, since clients can revoke consent even after initially agreeing.
A basic disclosure checklist to build into your intake process:
- Consent form uses IRS-compliant language (not a generic "we may use third parties" clause)
- Country of disclosure named explicitly
- Signed and dated before any data transmission
- Refusal option stated in writing, with no penalty to the client
- Record retention: keep signed consents for at least the same period you retain the return itself
- Separate consent obtained if you later switch providers or countries
PTIN, Preparer-of-Record, and Liability: Who's Actually on the Hook
Here's the part firm owners sometimes underestimate: outsourcing the labor doesn't outsource the liability. The PTIN holder who signs the return — the U.S.-based EA or CPA listed as preparer of record — remains fully responsible for its accuracy under Circular 230, regardless of who actually keyed in the numbers.
Circular 230's due-diligence standards don't have a carve-out for offshore-prepared work. If a return signed by your firm contains an error that a reasonably diligent preparer should have caught, "our overseas team made the mistake" is not a defense against an IRS penalty or a state board complaint. The review obligation sits with the signing preparer, which means your firm needs an actual review protocol — not a rubber stamp — for every return that comes back from an outsourced provider.
This has a few practical implications:
Malpractice insurance. Call your E&O carrier before you sign an outsourcing contract, not after a claim. Some policies have exclusions or notification requirements tied to the use of offshore subcontractors, and you don't want to discover a coverage gap while defending a claim.
Review protocol. Treat every offshore-prepared return the way you'd treat work from a first-year associate: full review against source documents, not a spot-check. Many firms formalize this as a two-tier sign-off — the offshore preparer completes the return, a domestic EA or CPA reviews line-by-line against the client's source documents, and only the domestic reviewer's PTIN goes on the return.
Documentation of review. Keep a record showing who reviewed each return and what was checked. If the IRS or a state board ever questions how your firm handles outsourced work, "we have a documented review process" is a much stronger position than "we trust our vendor."
The bottom line: outsourcing changes who does the data entry. It does not change who owns the risk.
Data Security Due Diligence: Questions to Ask Before You Sign
Robo AI Tax Preparation
Reduce up to 90% of human effort.
The automation of tax preparation — done for you.
Tax returns carry Social Security numbers, income data, bank account and routing numbers, and dependent information — exactly the kind of data that makes a breach catastrophic for a small firm's reputation and legal exposure. Offshore tax preparation compliance isn't just about Section 7216 consent; it's also about whether the provider's security posture actually protects that data once it crosses a border.
SOC 2 Type II reports. A SOC 2 badge on a vendor's homepage means very little on its own. Ask for the actual report — Type II specifically, which reflects controls tested over a period of months, not a point-in-time snapshot (Type I). Read the auditor's exceptions section. Every SOC 2 report has some noted exceptions; what matters is whether they're minor or whether they touch access controls and data handling directly.
Data residency. Ask exactly where data is stored and processed — not just "in the cloud," but which country, which data center, and whether any subcontractors or sub-processors are involved. Confirm encryption at rest and in transit, and ask what encryption standard is used (AES-256 is the common baseline).
Access controls. Every individual preparer who touches client data should have their own login — not a shared credential. Ask for role-based permission structures and whether the provider maintains audit logs showing who accessed which client file and when. If a provider can't produce an access log after the fact, they don't actually have adequate access controls, whatever they claim.
IRS Publication 4557 alignment. IRS Publication 4557, Safeguarding Taxpayer Data, sets the baseline the IRS expects preparers to meet, and it directly informs the Written Information Security Plan (WISP) that every paid preparer is required to maintain under the FTC Safeguards Rule. If you outsource, your WISP needs to account for the outsourced provider's practices — you can't maintain an internal WISP that ignores where a chunk of your data actually lives. Ask the provider directly how their controls map to Pub 4557's categories: employee training, information system security, and detecting/managing system failures.
Breach notification terms. This should be in the contract, not a verbal assurance. Specify a notification timeline (24 hours, 48 hours — whatever you negotiate) and spell out liability allocation if a breach originates on the provider's side. If the contract is silent on breach notification, that silence becomes your problem the day something goes wrong.
Vetting Framework: A Risk-Assessment Checklist for Any Provider
Whether you're evaluating a big-name outsourcing brand or a smaller boutique shop, run the same checklist. Firms that decide to outsource tax preparation to India-based providers get the best results when they apply this checklist consistently, rather than trusting a sales deck to answer it for them.
Corporate structure. Is this a genuine third-party vendor, or is it effectively your own controlled entity operating under a different name? The distinction changes your liability posture — a true third party carries independent obligations under its own contracts and insurance, while a controlled subsidiary may expose the parent firm more directly, similar to having direct employees.
Individual-level vetting, not just company-level. A vendor's marketing material describes the company. Ask about the individual preparers who will actually touch your clients' returns: background checks, confidentiality agreements signed personally (not just corporate NDAs), and turnover rates. High turnover among offshore preparers is common in this industry and worth asking about directly.
Trial batch before commitment. Don't sign a firm-wide contract on the strength of a sales call. Request a small trial batch — a handful of straightforward 1040s, maybe a couple of business returns — and have your own reviewers grade the work for accuracy, formatting, and turnaround time before scaling up.
Contract terms to insist on:
- Indemnification language covering errors and data breaches originating from the provider
- Data destruction commitments upon contract termination, with written confirmation
- Jurisdiction and dispute resolution terms — know where you'd actually have to litigate if something goes wrong
- Named points of contact, not a generic support queue
Red flags:
- Vague or shifting answers about where data is physically stored
- Reluctance to share the actual SOC 2 report (not just a summary or logo)
- No named account manager or reviewer you can reach directly
- Pressure to sign a full-season contract without a trial period
- Consent language that the provider tells you is "handled on our end" — it isn't; that obligation sits with your firm as the preparer of record
Quality Control and Workflow Risks Beyond Data Security
Even a fully compliant, well-secured provider introduces operational friction that firms underestimate until they're mid-season.
Time zone gaps. India is roughly 9.5 to 10.5 hours ahead of U.S. time zones depending on the season and coast. During crunch weeks — late March, early April, mid-September and mid-October for extensions — that gap means a question sent at 4 p.m. Eastern might not get answered until the next U.S. morning. Build that lag into your turnaround expectations rather than discovering it during the busiest week of the year.
Version control. Returns moving back and forth between offshore preparers and domestic reviewers create real risk of working from an outdated file, especially if a client sends amended documents mid-process. A clear system of record — one place where the current version lives, with change tracking — prevents a reviewer from signing off on stale data.
The "who prepared my return" question. Some clients will ask directly whether their return was prepared overseas, especially after signing a 7216 consent form. Have a straightforward, honest answer ready for your staff to use, and don't let ambiguity there create an awkward moment during a client call.
Two-tier review as standard practice. The firms that manage offshore outsourcing well treat the offshore-prepared return as a first draft, not a finished product. A domestic EA or CPA reviews every return against source documents before it goes out the door. That extra step costs time, but it's the mechanism that actually protects your PTIN and your malpractice coverage.
Alternatives to Consider Before Sending Data Overseas
Offshore outsourcing isn't the only lever available for capacity problems, and it's worth pricing out the alternatives honestly before committing.
Domestic outsourcing networks. Contract preparer marketplaces that connect firms with U.S.-based EAs and CPAs working remotely solve the seasonal capacity problem without triggering Section 7216's offshore consent requirements at all. Rates run higher than offshore providers, but the compliance burden is lighter and the "who prepared my return" question disappears.
Managed, U.S.-supervised outsourcing. Some providers structure their services around a domestic review layer built into the engagement itself, rather than leaving that review entirely to the client firm. That doesn't eliminate your due-diligence obligation, but it does mean the two-tier review this article recommends is already part of the engagement rather than something you have to build from scratch. Worth asking any provider directly whether that structure exists before assuming you'll need to build it yourself.
Part-time and returning preparers. Retired EAs, CPAs on reduced schedules, and preparers returning from leave are an underused domestic pool. A part-time hire at competitive hourly rates can absorb overflow without any offshore consent process, though the total capacity is naturally smaller than a dedicated offshore team.
Software-driven efficiency gains. Before assuming the only fix is more hands, audit where your current staff's time actually goes. Firms that haven't updated their document-collection or workpaper workflow in a few years often find that fixing intake bottlenecks recovers meaningful capacity without adding headcount at all.
None of these alternatives make outsourcing to India the wrong choice — for many firms, it's still the most cost-effective way to close a real capacity gap. But running the numbers on the alternatives first puts you in a better position to negotiate with any provider, and it makes clear whether outsourcing is solving a genuine structural problem or just papering over a workflow issue that a domestic fix would solve just as well.
As always, the specifics of consent requirements, penalty amounts, and state board rules change over time — confirm current requirements with a qualified tax attorney or your state board before finalizing any outsourcing arrangement.
Written & reviewed by
Wendie Mayers
Editorial Team · UpTax.AI
Part of the UpTax.AI research desk covering U.S. tax, accounting, and automation for CPA and tax-prep firms.

Automate Your CPA or Tax Practice with UpTax.ai
Reduce up to 90% of human effort.
Book a demoSOC 2 · human sign-off on every return