The single most common objection to outsourcing accounting or bookkeeping work isn’t cost or quality; it’s trust. Handing your financial data, or your clients’ financial data, to a third party feels risky, and in an unregulated arrangement, it can be. The good news is that this is no longer a grey area. Between the Tax Practitioners Board’s (TPB) Code of Professional Conduct and AUSTRAC’s AML/CTF reforms taking effect through 2026, there is now a clearer regulatory framework for what a compliant outsourcing arrangement actually looks like and a useful checklist for anyone evaluating a provider.

What the TPB Requires When Tax Work Is Outsourced or Offshored

Under TPB(PN) 2/2018 and the Code of Professional Conduct, a registered tax or BAS agent who outsources or offshores client work doesn’t hand off their obligations along with the task. Two code items are directly relevant:

  • Code item 6 (confidentiality): the practitioner must obtain written client consent before disclosing information to a third party, and that disclosure must specify who the data is being shared with, where it will be handled, and where it will be stored, including whether that’s an overseas server.
  • Code item 7 (competent service delivery): when work is outsourced to an unregistered provider, the practitioner remains responsible for its accuracy. This means adequate supervision by registered practitioners, documented quality review, and staff trained in Australian tax law rather than a general offshore data-entry team.

In practice, this means an engagement letter or client agreement should plainly disclose the outsourcing arrangement, not bury it in fine print, and the provider should be able to show how registered practitioners review the work before it reaches the client or the ATO.

The AML/CTF Reform Accountants Can’t Ignore in 2026

Australia’s AML/CTF regime is being extended to a wider range of professional services in 2026 (often referred to as the “Tranche 2” reforms). Accountants and other professionals become a regulated “reporting entity” if they provide certain “designated services” for example, setting up companies, trusts, or partnerships, acting as a director, trustee, or nominee shareholder; managing client money or trust accounts, or handling real estate transactions on a client’s behalf. It applies based on the service provided, even occasionally, not on whether a firm markets itself as offering it.

The key dates: enrolment with AUSTRAC opened 31 March 2026, the compliance deadline for reporting entities was 1 July 2026, and the enrolment deadline for businesses already providing designated services was 29 July 2026. Firms that meet the definition need a written AML/CTF program, a nominated compliance officer, customer due diligence procedures, and seven years of record-keeping.

The part that matters most for outsourcing: the compliance obligation cannot be outsourced. A firm can use an outsourced or offshore team to help with the administrative workload, document collection, data entry, monitoring support, but the AML/CTF program, the risk assessment, and the accountability for it sit with the Australian reporting entity, not the outsourced provider. Any firm evaluating an outsourcing partner in this environment should ask directly how that provider supports (rather than sits inside) their AML/CTF obligations.

What a Genuinely Secure Outsourcing Partner Has in Place

A provider that takes this seriously will usually be able to point to a documented compliance review process rather than a verbal assurance:

  • Written client consent and disclosure built into the engagement process, not an afterthought
  • Registered, appropriately qualified practitioners reviewing and signing off on work before it’s finalised
  • Documented confidentiality agreements covering every staff member with access to client data
  • Role-based access controls, so staff only see the data relevant to their task
  • Encrypted, audited access to your systems, no shared logins or data leaving via personal devices or email
  • A clear data storage and retention policy, including where servers are physically located
  • Adequate professional indemnity insurance that explicitly covers outsourced service delivery

Questions to Ask Before You Sign

  • Where physically is our data stored, and who has access to it?
  • Will you disclose this arrangement in writing, in plain language, before we engage you?
  • Which of our tasks are handled by registered practitioners versus support staff, and how is that work reviewed?
  • What happens to our data and our access if the engagement ends?
  • Can you show us your confidentiality and data security policy, not just describe it?

Related on rvag.com.au

How RV Advisory Group Approaches This

RV Advisory Group operates as a CPA Australia member firm holding a Public Practice Certificate and AUSTRAC registration. You can read more about our practice with a dedicated shared services team in India operating under documented confidentiality and data-handling agreements. Outsourcing arrangements and how client data is handled are disclosed clearly as part of the engagement, not left for clients to ask about after the fact.

Frequently Asked Questions

It depends on the provider’s infrastructure; some use Australian-hosted systems with offshore staff accessing them remotely under controlled logins, rather than storing data offshore. Always ask specifically where data is stored, not just where staff are based.

If you’re a registered tax or BAS agent, yes, written disclosure specifying who, where, and how the data will be handled is a Code of Professional Conduct requirement, not an optional best practice.

No, it applies to firms providing specific “designated services” such as company/trust formation or managing client money. Firms that don’t provide those services aren’t automatically captured, though it’s worth checking against the current AUSTRAC guidance.

Sources checked for this draft: Tax Practitioners Board – TPB(PN) 2/2018 and outsourcing/offshoring guidance; AML/CTF Tranche 2 reform summaries from AUSTRAC-focused legal and compliance publishers, current as of September 2026. Please verify current deadlines directly on austrac.gov.au before publishing, as compliance dates can be subject to transitional guidance.