Accounting File Sharing: Best Practices Guide
Share accounting files securely with clients and auditors. Organize financial documents and maintain compliance with industry standards.
Accounting files move between a firm and its clients constantly — QuickBooks backups, tax organizers, bank statements, payroll registers, and 1099 source data — and each transfer needs to satisfy AICPA confidentiality rules, IRS Circular 230 standards, and state accountancy board privacy requirements. The core stack for most small-to-midsize firms: SmartVault or ShareFile for the main client portal, Intuit's Lacerte or UltraTax for tax prep with built-in encrypted exchange, DocuSign for signature workflows, and an encrypted ad-hoc service for the late-March crunch when the client forgets one more K-1 and emails don't cut it.
Client Portals: SmartVault, ShareFile, Canopy, TaxDome
SmartVault starts at $25 per user per month, ShareFile at $50 per user per month for advanced. Canopy and TaxDome target accounting firms specifically, bundling portal + practice management + billing. A typical small firm (3 to 10 CPAs, 200 to 800 clients) lands on one of these based on workflow fit. Key features to compare: bank-grade encryption (AES-256 at rest, TLS 1.3 in transit), SSO integration, Advisor/Client role separation, integrated e-signature, mobile upload for receipt photos, and retention policies per document type. Test the client side — if the portal UX is painful, clients revert to emailing attachments and your security posture collapses.
Data Categorization by Sensitivity
Not all accounting files are equally sensitive. A blank organizer template is public. A trial balance is confidential business info. A W-2 with an SSN is high-risk PII under the FTC Safeguards Rule and state breach notification laws. A 1040 with bank account numbers is financial PII triggering GLBA for covered firms. Classify documents at upload into Public / Internal / Confidential / Restricted tiers, and enforce the classification in retention and access policies. AICPA's SSAE 18 and SSAE 21 SOC 2 audits push firms toward this structured approach.
Tax Season Scaling Problems
January through April 15, a CPA firm's file transfer volume spikes 10x. A single return packet can include 80 to 200 documents per client — W-2s, 1099s, K-1s, 1098 mortgage statements, charitable receipts, daycare receipts. For a firm with 500 tax clients, that's 40,000 to 100,000 documents across 90 days. Portals with bulk upload, automatic OCR into the tax software (Intuit's Link, Lacerte's SmartVault bridge), and mobile-app photo upload cut processing time dramatically. Fee structures that scale with upload volume (like some API-metered transfer services) destroy your margins — pick flat per-client pricing where possible.
The IRS and State Tax Authority Channel
The IRS e-Services Secure Object Repository (SOR) handles IRS communications securely. Preparers with e-file enrollment can access transcripts, CAF listings, and notices through SOR. State tax authorities have similar portals — California FTB, New York DTF, Texas Comptroller. Avoid faxing — fax servers sit in clear on the network, and many modern fax systems just relay to email, which means your client's SSN went through someone's Outlook in cleartext. When the IRS asks for documentation responding to a CP2000 notice, use SOR or mail with certified return receipt. Never email tax authority documents unencrypted.
Engagement Letters and Section 7216 Consents
IRC Section 7216 prohibits tax preparers from disclosing tax return information without written consent. Consent language requirements are detailed in Rev. Proc. 2013-14 — specific fonts, specific disclosures, timestamped client sign-off. For disclosure to third parties (a mortgage lender requesting tax returns, a divorce attorney), get the consent signed via DocuSign or Adobe Sign before any transfer. Violations carry criminal penalties up to $1,000 and one year imprisonment per count plus civil penalties. Keep signed consents in the client file for the statute of limitations, which extends to 6 years for substantial understatement cases.
Bank Statement and Transaction Data Import
Bookkeeping pulls bank data via Plaid, Yodlee, or Finicity (now Mastercard Open Banking) connecting to 12,000+ financial institutions. Client grants OAuth consent, the app reads transactions for the authorized period, and data flows into QuickBooks Online, Xero, or Sage. For banks not on the aggregator network, clients upload PDF or CSV statements manually. PDF bank statements often exceed 20 MB per year for a business account — above Gmail's attachment limit. A portal with bulk folder upload handles this, or an encrypted link for one-off catch-up batches when onboarding a new client.
Year-End Audit and Review Engagement Files
For firms providing attest services, audit workpapers need durable storage through the retention period — typically 7 years under PCAOB AS 1215 for public company audits, 5 years for AICPA peer-reviewed private firms. Workpapers include lead schedules, supporting calculations, management representation letters, and inquiry notes. CaseWare and Wolters Kluwer's ProSystem fx Engagement dominate audit software. For the file exchange between audit senior and client controller, the firm's portal handles the inbound; internal Microsoft 365 or CaseWare Cloud handles the workpaper management. Restrict access to the engagement team plus reviewer.
Client Exits and Successor CPA Handoffs
When a client leaves for another CPA firm, the successor requests records under AICPA Rule 501. The outgoing firm must provide client-owned records (their source documents, prior tax returns) but can withhold firm-owned workpapers. Delivery usually means a secure portal handoff or an encrypted link — never a USB stick handed to the client because USB drives get lost. Keep your own archival copy per retention rules. Under state accountancy rules (e.g., California Accountancy Act Section 5037), there are specific timelines — typically 10 days to respond to records requests — so have a workflow ready, not improvised.
Encrypted Ad-Hoc for Tax Season Surprises
April 14, 8 PM. A client just realized they forgot the Roth conversion 1099-R. The portal is indexed for morning; the return files at 11:59 tomorrow. A quick encrypted link with 24-hour expiry gets the file to your desk without opening a ticket in the portal system. Services like HexaTransfer, SwissTransfer, and Dropbox Transfer handle this. Log the file into your practice management after-the-fact so the audit trail stays consistent. Don't accept tax documents over SMS, WhatsApp, or personal Gmail — those channels aren't Safeguards Rule compliant and your E&O carrier will ask about them after a breach.
Try it at hexatransfer.com — free, no account, 10 GB max. For the April 14 client who's finally found the missing K-1 at 10 PM, a zero-knowledge link lets you file on time without breaking your Safeguards Rule posture.
Send large files securely with end-to-end encryption
Transfer files up to 10 GB for free with end-to-end encryption. No account required. Your files are encrypted in your browser before upload — no one else can read them.
Send a file