TL;DR
- Your firm does not just protect its own financial data. As a firm focused on strategic finance, your obligations extend beyond your internal systems to include bank feeds, payroll files, and clients’ ledgers. This makes data protection a custodial responsibility rather than merely a technical one. Yet most guidance on data security assumes a business is protecting only its internal data.
- The FTC Safeguards Rule requires you to securely dispose of customer information within two years of last use, under 16 CFR 314.4(c)(6)(i). Certain IRS-governed records can require three to seven years, or longer. Most firms have never worked out, on a record-by-record basis, which rule actually governs.
- This guide outlines six key record classes, provides a retention comparison table, and features a 12-item checklist you can review in about ten minutes.
The FTC Safeguards Rule gives your firm two years to securely dispose of a client’s financial data after you stop using it for that engagement. The IRS can require you to hold a specific tax record for seven years or more. Both are legally binding. I have yet to meet a firm that has worked out, record by record, which one actually applies.
That gap matters more for your firm than for almost any other vendor your clients engage. You are not simply protecting internal financial metrics; you are holding third-party assets that clients entrust to your care.
Most data protection resources focus on businesses safeguarding their own. Very few address the unique risk profile of a firm managing client bank feed credentials, payroll files, and general ledgers alongside its own operational data.
You Cannot Protect What You Have Not Inventoried
Before implementing controls, inventory the specific data assets in your possession. While most firms can detail their month-end close process, few can immediately pinpoint the storage location of a former client’s payroll records.
The table below outlines where these primary operational risks reside:
| Record Class | What Makes It Sensitive | Where It Typically Lives | Who Touches It |
| Bank feeds and aggregator connections | A live, standing connection to the client’s real accounts through a third-party aggregator | Practice management or accounting software integrations | Staff assigned to reconciliation |
| General ledger and financial statements | The firm’s core work product and the client’s financial truth | Accounting software, exported reports | Preparers, reviewers, partners |
| Payroll files | Names, addresses, Social Security numbers, and bank routing details for people who never engaged your firm directly | Payroll platform, HR folders | Payroll staff, sometimes the client’s own HR contact |
| AP and AR records | Vendor banking details are a preferred target for payment redirection fraud | AP/AR modules, vendor files | Bookkeepers, AP staff |
| Tax returns and source documents | Governed by their own federal retention clock, separate from everything else on this list | Tax software, document management system | Preparers, reviewers |
| Entity and beneficial ownership records | Formation documents, ownership percentages, and identification collected at onboarding | Client files, onboarding folders | Onboarding staff, partners |
Your firm holds all six for every client on your roster. Managing this data is a fundamental component of the strategic finance solutions you deliver. That is a much bigger surface than most owners picture when they think about client financial records.
Collection: The Most Secure Record Is the One You Never Took
The cheapest control in this entire article costs nothing to implement. Stop collecting data you do not need.
Firms routinely ask for more financial detail than an engagement actually requires. This often complicates financial operations without adding value.
They might ask for:
- A full bank statement, when one line item would do.
- A voided check, when the routing and account numbers are enough.
- A complete Social Security number, when the last four digits would confirm identity just as well.
Every unnecessary field you collect is a permanent liability with no offsetting value. It sits in your systems and requires the same encryption and access controls as everything else, all for a field that never helps the work get done.
Look at your intake process this quarter and make three substitutions:
- Ask for routing and account numbers directly instead of a scanned check image.
- Ask for the last four digits of a Social Security number when that is all reconciliation requires.
- Ask for a single account balance instead of a full statement when only the balance is needed.
None of this weakens the engagement. It shortens the list of things you have to protect. It also shortens the retention argument you will need to make later.
Encryption: At Rest, In Transit, and the Gap in Between
The Safeguards Rule requires you to encrypt customer information both at rest and in transit, under 16 CFR 314.4. It allows a narrow exception. Your qualified individual can approve compensating controls when encryption is genuinely not feasible. Most firms satisfy this at the platform layer and leak at the edges.
Most data exposure occurs along perimeter workflows rather than within the core platform. Common vulnerability points include ledgers sent as unencrypted email attachments, offline downloads stored on local laptops, exported spreadsheets created for custom analysis, screenshots shared in team chat channels, and files temporarily saved to personal cloud drives. While core platforms remain encrypted, these local copies frequently lack at-rest encryption once exported.
Access: Scope by Engagement, Not by Employment
Access management encompasses two primary challenges. First, overall client record access should be scoped strictly to current engagement requirements, not to staff tenure. Second, firms must address the narrower, high-stakes challenge of managing live client bank feed connections.
Least Privilege Across a Client Roster
The primary access challenge for accounting firms stems from lateral reach across client portfolios. This risk is heightened in outsourced financial management practices, where client assignments change regularly. Team members frequently retain access to accounts from previous engagements long after their active involvement ends.
To mitigate this, align system permissions strictly with current client assignments rather than overall employee tenure. Conduct access reviews whenever staffing changes occur, and treat offboarding, whether for a client or an employee, as an immediate trigger to revoke permissions rather than waiting for scheduled periodic audits.
Bank Feed Credentials and Aggregator Tokens
Bank feed credentials are among the highest-risk access categories held by accounting firms. Unlike standard passwords, aggregator connections function as persistent authorization tokens that remain active until explicitly revoked.
Decide, in writing, who owns three decisions for every aggregator connection your firm creates:
- Who can establish a new connection?
- Who can view or export data from an existing one?
- What happens to that connection the day an engagement ends?
Using shared credentials creates significant risk compared to maintaining individually scoped aggregator tokens tied to specific team members and engagements. Maintaining strict oversight of these connections is vital for reliable financial reporting.
This approach aligns with the Consumer Financial Protection Bureau’s consumer protection principles for data aggregation, which emphasize purpose-scoped access, clear user accountability, and defined remediation procedures for unauthorized access.
Apply these same access standards consistently to remote personnel. Permissions should match active engagement requirements, with any exceptions explicitly documented. Firms that scale distributed teams effectively, including those utilizing remote staffing models, integrate role-based access controls from initial onboarding rather than reconfiguring systems later.
Retention: Where the Two-Year Clock Meets the Seven-Year Rule
This is where two federal obligations pull in opposite directions. Almost no published article reconciles them.
Under the Safeguards Rule, once you stop using a client’s information for that engagement, the clock for secure disposal runs for 2 years.
Three exceptions can extend it, per 16 CFR 314.4(c)(6)(i):
- You have a legitimate business reason to keep it.
- You have a legal requirement to retain it longer.
- Disposal genuinely is not practical given how the data is stored.
Separately, IRS retention guidance sets its own floors depending on the record:
- Three years, in general
- Six years if the income was understated by more than 25%
- Seven years for a bad debt or worthless securities deduction
- Indefinite for an unfiled or fraudulent return
- Four years for employment tax records
To balance these obligations, a recommended operational policy is to retain general client records for 30 days following engagement termination. This grace period allows the former client sufficient time to transition to a new provider.
After 30 days, client data is systematically deleted, except for tax returns and supporting source documents. These tax records are retained for seven years to cover the maximum standard IRS audit window under a single uniform rule.
| Record Class | Federal Retention Floor | Does the 2-Year Disposal Clock Apply? | Exception Relied On |
| Bank feeds and aggregator access | No specific federal floor. This is a firm policy call, not a retention question. | Access ends at engagement end | Revocation, per firm policy |
| General ledger and financial statements | No independent floor beyond the engagement | Applies once no longer needed for business operations | Business operations, while active |
| Payroll files | Employment tax records, 4 years | Displaced for 4 years | Legal retention requirement |
| AP and AR records | 3 years generally | Displaced for 3 years | Legal retention requirement |
| Tax returns and source documents | 3 to 7 years, indefinite if unfiled or fraudulent | Displaced for the applicable period | Legal retention requirement |
| Entity and beneficial ownership records | No specific federal floor found. Most firms hold these for the life of the engagement plus a short buffer, as a firm policy call. | Applies once the relationship ends, by policy | Business operations, per firm policy |
Two rows above, bank feeds and aggregator access, and entity and beneficial ownership records, reflect firm policy judgment rather than a specific federal retention floor. Neither the FTC Safeguards Rule nor IRS guidance addresses these record classes directly, so your firm sets the standard for them, as we do at Nimbl.
While legitimate business exceptions allow firms to retain data, using cloud accounting platforms does not automatically relieve firms of their retention obligations. Indefinite data retention without a documented legal basis does not constitute compliance. In the event of an audit or regulatory inquiry, firms must be prepared to justify their data retention policy across each specific record class.
Disposal: Deletion Is Not Destruction
Deleting a file from a primary workspace does not guarantee that all instances have been removed. Duplicate copies often persist across system backups, email archives, integrated accounting applications, local drives, and unmapped working folders.
A secure disposal process must be backed by verifiable documentation. Standard evidence includes system log entries, automated deletion records, or formal certificates of destruction from hardware recycling vendors. In the event of an inquiry from a client or insurer, firms must be able to demonstrate precise dates and methods of data destruction.
Breach Response: Your Firm Holds Two Sets of Obligations
A firm holding client records is often the entry point to a client’s own breach. One incident starts two separate clocks at once.
Your clock runs first. Under 16 CFR 314.4, once you discover an incident affecting 500 or more consumers, you have to notify the FTC quickly. You are working against a 30-day window from the discovery date.
The same rule’s definitions section adds a twist. If someone unauthorized also obtains the encryption key, the data is treated as unencrypted for notification purposes, even though it was technically encrypted.
Your client’s clock runs separately. It is not yours to control. Their notification duty to their own employees and customers is triggered by where each affected individual lives, not by where your firm is headquartered.
Washington State’s breach law, for example, requires that notice be given to affected residents within 30 days of discovery. Another state’s deadline may run longer. Your client must comply with the laws of every state where an affected person lives. Your firm holds the facts they need to do it.
Establish a comprehensive incident response plan prior to any security event. Clearly define roles for client communications, technical scoping, insurance notifications, and regulatory documentation. Establishing these workflows in advance helps prevent operational delays and preserves client trust during critical incident management.
The Owner’s Checklist
Run down this list and answer yes or no to each one:
- We have a written inventory of every record class we hold and where each one lives.
- We collect the minimum data an engagement requires, not the maximum a client happens to send us.
- Customer information is encrypted at rest and in transit across every system we use.
- We have named every edge where that encryption stops (email, downloads, exports, screenshots, personal cloud folders) and have a rule for each one.
- Access to client records is scoped to the current engagement, not to how long someone has worked here.
- Bank feed and aggregator access is reviewed and revoked the day an engagement ends.
- Remote team members hold the same engagement-scoped access as onshore staff, no more and no less.
- We can state, per record class, which retention exception we rely on and for how long.
- We have a documented disposal procedure and can produce evidence that a specific record was destroyed on a specific date.
- We decided in advance who calls the client, who scopes an incident, and who contacts our insurer.
- We know which state’s notification law applies to each client’s affected individuals before a breach happens, not during one.
- Someone at the firm owns this checklist and reviews it at least once a year.
How Nimbl Tech Secures the Layer These Records Live On
The division of labor here matters. Your firm sets the retention schedule and makes all custody decisions.
Those are judgment calls about your own client relationships and your own legal exposure. Exactly which regulatory regimes apply to your firm specifically is a separate question, one to work through with whoever handles your compliance program.
What we own is the layer underneath those decisions. We enforce encryption across the systems that store these six record classes, and we manage access to ensure it matches the scoping described above. We also execute secure disposal according to the schedule your firm sets, and we maintain the evidence trail that proves it happened.
It is delivered as a single component of your managed IT services, not a separate product bolted onto your existing IT setup. And it works from the same access management discipline described in this piece, not a generic vendor template. You can see how the cost of that layer compares to building it yourself.
Your Client Trusts You With the Numbers; That Includes the Records
Your client handed you their financial truth. The records behind that truth, the bank feeds, the payroll files, the ledgers, are part of the same trust.
They are not paperwork sitting off to the side. Custody sits inside the engagement, whether anyone at your firm ever named it that way or not.
You already run a disciplined close process. Most firms never extend that same discipline to the records themselves. That means what you collect, how long you keep it, and how you prove you disposed of it correctly.
Talk through your data posture with our team.
FAQs
How Long Should Our Firm Keep a Client’s Financial Records Before Securely Destroying Them?
It depends on the record. The FTC Safeguards Rule generally requires disposal within two years of last use, but tax returns and related documents can require three to seven years under IRS rules, and fraudulent or unfiled returns have no time limit at all. Decide the applicable period per record class, not for your files as a whole.
In practice, we handle this by holding records for 30 days after an engagement ends, then removing everything except tax returns and their source documents, which we keep for seven years, since that covers the longest IRS timeframe without tracking every rule separately. Building a written schedule now removes the guesswork so nobody at your firm has to make that call under pressure during an actual departure or audit.
Does the FTC Safeguards Rule Require Us to Encrypt Client Financial Data at Rest?
Yes. The rule requires encryption of customer information both at rest and in transit, with a narrow exception that permits compensating controls if your qualified individual determines that encryption is genuinely not feasible.
Most firms meet this at the platform level but miss it in downloads, exports, and email attachments. Those gaps matter because a compliant platform does not, on its own, make a downloaded spreadsheet or an emailed ledger compliant.
The safest approach is to name every place a copy of client data can leave your core system and confirm that encryption follows it there as well, rather than assuming platform-level protection covers everything downstream.
Is It Safe for Our Firm to Hold Bank Feed Credentials or Aggregator Tokens for Client Accounts?
It can be, if access is scoped to one person and one engagement rather than shared broadly, and if the connection is reviewed and revoked the day the engagement ends. A shared login with no clear owner is the version that creates risk.
The safest setup treats every aggregator connection like a standing key to a client’s real accounts, because that is functionally what it is. Write down who can create a new connection, who can view or export from an existing one, and who is responsible for closing it out, so the decision does not default to whoever happens to still have access months after an engagement ends.
If Our Firm Is Breached, Do We Notify the Client’s Employees and Customers, or Does the Client?
Your firm notifies the FTC directly under the Safeguards Rule. Your client typically holds the separate legal duty to notify their own affected employees and customers, based on where those individuals live, and your firm holds the facts they need to do it. That means your incident response has to answer two separate questions at once.
One is what you owe the FTC. The other is what your client needs from you to meet their own state-by-state notification deadlines. Firms that plan for both obligations ahead of time, rather than during an active incident, are the ones that keep the client’s trust throughout the process, rather than losing it to confusion and delay.
What Client Financial Data Should We Decline to Collect in the First Place?
Anything beyond what the engagement actually requires. A full bank statement when one line item would do, a voided check image when routing and account numbers are enough, or a full Social Security number when the last four digits confirm identity just as well.
Every field you never collect is one less thing you have to encrypt, control access to, and eventually prove you destroyed. Reviewing your intake forms and templates once a year and asking whether each requested field is truly necessary for that engagement is a low-cost way to reduce your risk before it ever becomes a security problem.
