Howdy!

Client Data Security: Questions to Ask Any Software Vendor

Super Admin

Super Admin

Aug 30, 2026
Share this article
Client Data Security: Questions to Ask Any Software Vendor

The client data security questions accounting firms should ask every software vendor — hosting, encryption, access, logging, backups, breach process and exit.

An accounting firm that puts client data into a vendor's software has not outsourced the responsibility — it has added a party to it. The professional response is a written question set, asked of every vendor, with answers kept in the engagement file. Vendors comfortable with scrutiny answer quickly and specifically; vendors who answer with adjectives have answered too. Here is the set.

The Question Set

  1. Where is our data hosted? Jurisdiction and provider, stated plainly. Residency drives legal exposure and client-contract compliance — "the cloud" is not an answer.
  2. How is it encrypted? In transit and at rest, with key management described. The answer should be boringly standard; surprises here end the conversation.
  3. Who can access it — at your company? Which vendor roles can reach customer data, under what controls, with what logging. Support-access practices are where good products hide bad habits.
  4. What does your access model give us? Role-based permissions, per-client isolation in portals, two-factor enforcement — the controls the firm operates day to day.
  5. What is logged, and can we see it? Every access, change and delivery, with the firm able to read its own trail. An audit log the customer cannot query is a marketing feature.
  6. What is your backup and restore reality? Frequency, retention, and — the part that matters — tested restore time. Ask when they last restored for a real customer.
  7. What happens in a breach? Notification commitment in hours or days, what they disclose, who assists. A vendor without a written process will improvise one during your incident.
  8. What happens when we leave? Export formats, retrieval window, deletion confirmation. The exit answer prices your switching line and reveals how the vendor thinks about your data's ownership.

Reading the Answers

Specific, written, unhesitating answers are the pass mark — the content is usually standard; the manner is the signal. Keep the responses with your vendor file: they are part of your own duty-of-care evidence when a client or regulator asks how the firm chose its tools, and they pair with the internal habits in secure client document sharing. Risper CRM answers the set as a matter of routine — access isolation, activity logging and portal delivery trails are product features precisely because firms keep asking the right questions. See the features page.

Frequently Asked Questions

How often should we re-ask the questions?

At renewal, and on any material change — new modules, new hosting, an acquisition on either side. Vendor security is a relationship state, not a procurement checkbox.

What if a vendor's answers are good but informal?

Ask for them in writing. The request costs one email; the difference between told and documented is the difference between assurance and evidence.

Do these questions apply to small vendors and add-ons?

Most of all there — the smallest tool with client data in it carries the same duty as the platform. Every vendor with access to client data gets the set, or does not get the data.

Ask all eight — of every vendor, including us: rispercrm.com/contact.