Outsource Tax Return Prep: State Compliance Rules to Know
Before you outsource tax return preparation, firms must navigate state-specific disclosure and consent laws—this guide breaks down California, Texas, and other key requirements no competitor covers.
Every firm owner who's priced out offshore or third-party tax prep has run the cost-benefit math. Fewer do the legal math. When you outsource tax return preparation — a staffing firm in Ahmedabad, a contract preparer in Ohio, an AI-assisted platform based in the U.S., doesn't matter — you're handing taxpayer information to someone outside your firm's four walls. That single act triggers a federal consent requirement under IRC Section 7216. Depending on where your clients live, it may also trigger a second layer of state-specific disclosure rules stacked on top.
Most outsourcing guidance online focuses on cost savings, staffing models, vendor comparisons. Almost none of it touches the compliance layer that actually determines whether your arrangement is legal. That gap matters. State boards of accountancy and consumer protection statutes don't care how fast your offshore team turns returns around. They care whether you got consent, documented it correctly, and disclosed what needed disclosing.
Skip these steps and you're not just exposed in theory. Picture a client who finds out — after the fact — that their return went to a third party overseas, and nobody told them. Grounds for a board complaint in most states, right there. Add a data breach or an error on the return, and now you've got the makings of a malpractice claim. This doesn't scale down for smaller firms, either. A two-partner shop in Sacramento carries the same California Business & Professions Code obligations as a 200-person regional firm. Size buys you nothing here. It just changes how many client files get swept up when something goes wrong.
This article maps the actual legal requirements — federal and state — firms need to clear before they outsource tax return preparation. Already read the vendor comparisons and the "10 ways to outsource" listicles? Treat this as the missing chapter. The one that keeps you out of a board inquiry.
Federal Baseline: IRS Section 7216 Consent Rules for Outsourcing
Before any state law enters the picture, IRC Section 7216 sets the federal floor. It makes it a criminal offense for a tax return preparer to disclose or use taxpayer information without consent, subject to narrow exceptions. Sending a client's W-2s, 1099s, K-1s, or full return data to a preparer outside your firm counts as a disclosure. Consent comes first. Not after.
The consent has to be written. Treasury Regulation 301.7216-3 spells out what belongs in it: the name of the firm making the disclosure, the name of the recipient (or a category description, like "a tax return preparation service"), the purpose, and a statement that the taxpayer isn't required to sign as a condition of service. Got a boilerplate engagement letter clause that vaguely mentions "third parties may assist"? That almost certainly falls short.
There's a stricter layer once the receiving preparer sits outside the United States. Under Revenue Procedure 2013-14 (which updated 2008-35), any consent to disclose information to an offshore preparer must say so explicitly, and that consent must be obtained separately from consent to any use of the data. Plainly: you can't bury "we may send your data to India" inside a generic authorization. It needs its own line. The client has to affirmatively agree to it.
Noncompliance carries real teeth. A knowing or reckless violation is a misdemeanor — up to $1,000 per violation, up to a year in prison, or both — and Section 6713 adds a civil penalty for merely negligent disclosures. Multiply that across a batch of returns sent overseas without proper consent, and the exposure stacks up fast.
Practically speaking, your consent form should stand alone, not hide on page six of your engagement letter. Get it signed and dated before any data leaves your systems. Keep a copy for at least three years, or longer if your state board's recordkeeping rule says so. Want the operational picture too, not just the legal one? See Outsourcing Tax Prep to India: Risks CPA Firms Must Vet.
California Rules: B&P Code 22593 and Client Consent for Outsourced Tax Prep
California is the one state that turned outsourcing disclosure into an actual statute — which is exactly why "outsource tax preparation services near California" searches turn up so much confusion. Business & Professions Code Section 22593 requires any tax preparer doing business in California — CPAs, CTEC-registered preparers, enrolled agents, all of them — to give clients written notice before disclosing return information to a preparer located outside the United States.
Form matters here, not just substance. The notice has to be a separate document, signed by the client, stating plainly that return information may cross the border. Naming the specific country isn't spelled out word-for-word in the statute, but firms have largely landed on identifying it anyway — hard to argue a client meaningfully consented to something described only as "outside the U.S."
A few things firms consistently botch under 22593:
- Verbal consent doesn't count. Client says "sure, fine" on a call? Doesn't matter. You need a signature.
- It follows the data, not the contract. Staffing agency, independent contractor, platform with an offshore production team — doesn't matter who you've got a contract with. What matters is where the person touching the return actually sits.
- CTEC registration doesn't exempt you. Some CTEC preparers assume this is a CPA-board-only rule. Wrong. It's a Business & Professions Code provision, and it applies broadly.
- It stacks on 7216 — doesn't replace it. Satisfying the federal consent requirement doesn't automatically satisfy 22593. Draft language covering both, ideally in one signed document, so clients aren't stuck signing overlapping forms.
Searching "outsource tax preparation services near California"? Here's the practical checklist:
- Confirm where the vendor's preparers physically sit — not where the company's headquartered.
- If any work happens outside the U.S., draft a standalone combined 22593/7216 consent form naming the country.
- Get it signed before transmitting anything. Not during. Not after.
- Store signed consents in the client file, tagged separately, so you can produce them fast if the California Board of Accountancy or the Franchise Tax Board's preparer oversight unit ever comes knocking.
- Re-confirm consent annually or per engagement. A signature from three tax seasons ago, covering a different vendor, doesn't carry forward.
Texas Rules: What CPA Firms Near Texas Must Know Before Outsourcing
Texas has no B&P Code 22593 equivalent. No standalone statute requiring written client consent before sending data offshore or to a third party. That absence trips a lot of firms into assuming Texas is a free-for-all. It isn't.
The Texas State Board of Public Accountancy enforces confidentiality through its Rules of Professional Conduct — specifically the client confidential information rules under 22 TAC Chapter 501, Subchapter C. Disclosure without client consent is prohibited, with narrow exceptions for things like peer review or legal process. Outsourcing counts as disclosure under an ordinary reading of that rule, even when the vendor is domestic. TSBPA guidance and enforcement actions make one thing clear: firms stay responsible for how client data gets handled once it leaves the building, statute or no statute.
So Texas firms operate under a due-diligence standard rather than a bright-line consent law. Expected of you:
- Obtain consent to disclosure — Section 7216's federal requirement still applies in full, state law or not.
- Maintain confidentiality safeguards over the relationship. Engagement letters and vendor contracts should spell out data protection, access controls, and what happens if the vendor subcontracts further.
- Exercise ongoing oversight of the third party's output. TSBPA holds the signing CPA responsible for accuracy and confidentiality — not the vendor.
No statute dictating exact language means more flexibility in how Texas firms document authorization. More flexibility isn't the same thing as no obligation, though. Safest move for firms near Texas outsourcing 1040, 1065, or 1120 volume: build a 7216-compliant process as if you operated under a stricter statute, then layer in contractual protections — data location commitments, subcontracting disclosure, breach notification terms written into the agreement, not promised verbally by a sales rep.
Operating in both Texas and California? Common enough for regional and multi-office practices. Build around California's stricter standard. Running one compliant workflow beats maintaining two.
Other States with Notable Disclosure or Consent Requirements
Outside California, no state has a statute as explicit as 22593. But absence of a dedicated law doesn't mean absence of obligation. A few states deserve a specific flag.
New York has no outsourcing-specific tax preparer statute, but its SHIELD Act — an amendment to the state's data breach notification law — imposes security requirements on any business handling New York residents' private information, Social Security numbers and financial account data included. That's basically every tax return. Vendor gets breached? SHIELD Act notification timelines apply regardless of where that vendor sits. CPA firms licensed in New York also answer to the State Board for Public Accountancy's confidentiality rules, structured much like Texas's approach.
Illinois runs its own Personal Information Protection Act with breach notification requirements, and the Illinois Board of Examiners' conduct rules reinforce client confidentiality separately. Again — no outsourcing-specific consent statute, but a real data-privacy backstop underneath it.
Everywhere else tends to follow the same pattern: state CPA board codes of conduct (loosely modeled on the AICPA Code's confidentiality rule, ET 1.700) require consent before disclosing confidential information to third parties, and state breach notification statutes — nearly universal at this point — create downstream obligations when an outsourced vendor mishandles data. None of this is unique to tax prep. It's the general confidentiality and privacy framework, and tax returns happen to sit squarely inside the data these statutes were built to protect.
Practical lesson for multi-state firms: don't build fifty compliance policies. Build one, calibrated to the strictest state you touch — usually California, if you've got even one California client — and apply it everywhere. A "highest common denominator" consent form covering both 7216 and California's offshore language will satisfy Texas, New York, Illinois, and virtually every other state's framework by default. Running a lighter-touch process for non-California clients creates more risk than it saves in paperwork.
Building a Compliant Outsourcing Consent Process
Robo AI Tax Preparation
Reduce up to 90% of human effort.
AI drafts the return, your team reviews and files.
Here's a step-by-step approach that holds up under federal and state scrutiny alike.
Step 1: Map where the work actually happens. Get a straight answer from your vendor — country, ideally city or region. Vendors sometimes call themselves "U.S.-based" when only account management sits stateside and preparation happens elsewhere. Get the real answer in writing before drafting anything.
Step 2: Draft a standalone consent document. Don't bury it in the engagement letter. Build a separate, single-purpose form that:
- Names your firm and describes the outsourcing arrangement in general terms — "a third-party tax return preparation service," or the vendor's name if you disclose specifics.
- States plainly whether any preparer sits outside the U.S., naming the country if so.
- Includes the 7216 language: purpose of disclosure, statement that consent isn't a condition of service, a signature-and-date line.
- Where applicable, adds California B&P 22593 language as its own paragraph — even for non-California clients, since consistency across your book reduces error.
Step 3: Get the signature before data moves. Obvious, sure. Still the most common failure point. Firms send data first, chase down consent later, once the client starts asking questions. Consent precedes disclosure. Full stop.
Step 4: Disclose the arrangement more than once. Mention outsourcing in three spots — the engagement letter (general acknowledgment), the standalone consent form (specific, signed), and, for firms outsourcing routinely, a brief note on the website or intake materials. Nobody should be surprised by fine print.
Step 5: Retain records methodically. Keep signed consents in a separate, searchable file — not buried in a general client folder where nobody can find them fast during an audit or inquiry. Track by tax year and engagement. Consent covering the 2023 return doesn't automatically extend to 2024 if your vendor or process changed.
Here's a sample clause firms can adapt (get counsel to review the exact wording for your situation):
"[Firm Name] may use the services of a third-party tax return preparation provider to assist in the preparation of your tax return. [If applicable: This provider's tax return preparers are located in [country].] Your tax return information will be disclosed to this provider solely for the purpose of preparing your return. You are not required to consent to this disclosure to receive tax preparation services from [Firm Name], and your consent, once given, is valid for one year from the date of signature unless revoked in writing. I have read and understand this disclosure and consent to it."
One clause, bracketed country disclosure included, satisfies both 7216's offshore consent requirement and the core of California's 22593 — and it exceeds what Texas, New York, or Illinois currently require. Build around the strictest standard, and you're covered wherever you have clients now or later.
Vetting Outsourcing Partners for Legal and Data-Security Compliance
Consent forms only hold up if your vendor relationship backs them up. Before signing anything, get answers — in the contract, not a sales call — to these:
- Where exactly is the work performed? Country and facility-level specificity. In writing, as a contractual representation, not a marketing line.
- Does the vendor subcontract? Some outsourcing firms resell capacity to smaller shops or freelance networks. Subcontract without telling you, and your consent disclosures may go stale the moment a client signs.
- What's the data storage policy? Where does the data live at rest — U.S. servers, offshore, some mix? Affects both your 7216 disclosure and your breach exposure.
- What are breach notification timelines? Your contract should specify how fast the vendor tells you about a suspected breach — 24 hours is reasonable to ask for — because your own state's notification clock starts when you knew or should've known. Not when the vendor gets around to calling.
- Who's legally responsible for accuracy and confidentiality? The signing preparer is always on the hook with the IRS and state boards. Make sure your contract includes indemnification for vendor errors and mishandling.
Here's where offshore staffing models and U.S.-based, AI-assisted platforms actually diverge — not just in marketing, but in compliance burden. Preparation happening on U.S. soil, with American preparers and AI-assisted review, sidesteps the entire offshore-disclosure layer under 7216 and 22593 alike. General 7216 consent is still required — any outside disclosure triggers it — but you skip the country-specific line, the separate offshore signature, and a meaningful chunk of data-security risk. UpTax's model is built around exactly that: U.S.-based, AI-assisted preparation, so firms aren't managing offshore consent paperwork file by file. For a broader checklist before adopting any outsourced or AI-assisted tool, see Tax Season Software Checklist: What CPA Firms Must Vet.
Compliance Risks of Getting Outsourcing Wrong
None of this is hypothetical. State boards investigate confidentiality complaints regularly, and an undisclosed outsourcing arrangement makes for an easy one to file — no forensic accounting needed, just "I found out my return was prepared by someone I never agreed to." That can lead to a board inquiry, a consent order, a fine, or in repeat or egregious cases, license discipline.
Civil exposure runs right alongside. Say an outsourced preparer makes an error — a missed deduction, a misapplied credit, a data entry mistake that triggers a notice — and the client later learns nobody they authorized touched the return. Error plus undisclosed outsourcing makes for a much stronger malpractice claim than the error alone. Plaintiffs' attorneys know "you didn't tell me" plays well in front of a judge or jury. "You didn't tell me, and it's illegal under Section 7216" plays even better.
The most common mistakes aren't malicious. They're shortcuts:
- Verbal-only consent. "Sure, that's fine" on a phone call satisfies nothing — not 7216, not any state statute requiring a signature.
- Generic boilerplate. "We may use outside resources to complete your engagement" doesn't meet the specificity bar for 7216's offshore rule or California's 22593.
- Stale consent. A signed form from two tax seasons back, before the firm switched vendors or added an offshore component that didn't exist yet.
- No tracking. Consent forms scattered across email threads and general folders instead of tracked systematically — good luck producing them fast when someone asks.
Run a self-audit before the next season ramps up. Pull ten client files, at random. For each: can you produce a signed, dated, 7216-compliant consent form that predates any data transmission to your vendor? Serving California clients? Does that consent specifically name the country where preparation happened? Can't answer yes across all ten? There's a gap worth closing now, before it turns into a complaint.
FAQ: State Compliance for Outsourced Tax Preparation
What are the state disclosure requirements for outsourced tax prep? Varies by state, but the pattern holds steady: federal IRC Section 7216 sets a baseline written-consent requirement for disclosing taxpayer information to any outside preparer, with a stricter, separately-signed consent required once the recipient sits outside the United States. California stands alone with a dedicated statute — B&P Code 22593 — requiring a signed, standalone notice before outsourcing offshore. Texas, New York, Illinois, and most others lean on CPA board confidentiality rules and general data-privacy statutes instead of a tax-prep-specific law, but the practical consent obligation still applies through those broader frameworks.
Do I need California client consent to outsource tax preparation under B&P Code 22593? Yes — if any part of the preparation happens outside the United States and you serve California clients. The statute demands a separate, signed written disclosure, not a verbal mention or a buried engagement letter line, before that data crosses the border. Applies to CPAs, CTEC-registered preparers, and enrolled agents doing business in California, regardless of firm size.
What are the Texas CPA firm rules for outsourcing tax preparation? No 22593 equivalent exists in Texas. Instead, the Texas State Board of Public Accountancy's Rules of Professional Conduct require CPAs to protect confidentiality and get consent before disclosing information to third parties — a rule the board has treated as extending to outsourcing. Texas firms still owe federal Section 7216 consent and are expected to exercise due diligence over any vendor's data handling and work quality, statute or not.
Does IRS Section 7216 apply to domestic outsourcing, not just offshore? Yes. Written consent is required before disclosing return information to any outside preparer, U.S.-based or not. The additional, separately-signed offshore requirement under Revenue Procedure 2013-14 only kicks in once the recipient sits outside the United States — but basic consent applies to domestic arrangements just the same.
Can I outsource tax return preparation without disclosing it to clients? No. Doing so violates IRC Section 7216 at the federal level, and depending on your state, may separately violate board confidentiality rules or, in California, B&P Code 22593. Undisclosed outsourcing brings criminal misdemeanor exposure, civil penalties under Section 6713, board discipline, and heightened malpractice risk if the outsourced work contains errors.
The Takeaway
Outsourcing tax return preparation isn't purely a staffing decision. It's a compliance decision, layered federal-then-state, and most vendor pitches skip right past that part. Section 7216 sets the floor everywhere. California raises it with a specific statute demanding signed, standalone offshore disclosure. Texas and most other states lean on board confidentiality rules and general privacy law instead of a dedicated outsourcing statute — but the underlying consent obligation doesn't vanish just because there's no bright-line rule spelling it out. Firms that get this right build one consent process, calibrated to the strictest standard they touch, document it consistently, and vet outsourcing partners on data location and subcontracting — not just price and turnaround.
Evaluating outsourcing options and want a model built around U.S.-based, AI-assisted preparation that sidesteps the offshore-disclosure layer entirely? Book a demo and see how UpTax handles the compliance side without piling extra paperwork onto your busy season.
Written & reviewed by
Wendie Mayers
Editorial Team · UpTax.AI
Part of the UpTax.AI research desk covering U.S. tax, accounting, and automation for CPA and tax-prep firms.

Automate Your CPA or Tax Practice with UpTax.ai
Reduce up to 90% of human effort.
Book a demoSOC 2 · human sign-off on every return