The best practices for secure client document sharing in accounting — portals over attachments, access control, audit trails, expiry and what to stop doing today.
The single best practice for secure client document sharing is blunt: stop using email attachments for anything confidential. Financial statements, identity documents and tax files should move through a permissioned portal with an audit trail. Everything else in this guide is refinement; that one change removes the majority of real-world exposure.
Why Email Fails the Security Test
- No revocation. A misaddressed attachment is gone forever; a portal link can be withdrawn.
- No audit trail. You cannot say who opened a forwarded attachment. A portal records every access.
- Uncontrolled copies. Every attachment spawns copies in inboxes, downloads folders and phone caches — each one a breach waiting for a lost device.
- Phishing surface. Clients trained to open attachments from their accountant are exactly the clients who open the fake one.
The Best-Practice Stack
- Portal by default. All client documents — both directions — move through the portal. The firm's emails carry links, never files.
- Access by role and engagement. Staff see the clients they serve; clients see their own folder and nothing else; partner-only material is marked and enforced.
- Audit everything. Uploads, downloads, views and deletions logged with user and timestamp — this is both a deterrent and your evidence after any incident.
- Strong authentication. Enforced for staff, offered for clients — and required for high-sensitivity portals.
- Retention and cleanup. Shared items should not accumulate indefinitely; align portal contents with your retention policy.
Making Clients Actually Use It
Security that clients bypass is decoration. Adoption comes from three habits: invite every client to the portal at onboarding (not mid-relationship), reply to emailed attachments by filing them and pointing politely to the portal, and keep the upload flow phone-friendly — most identity documents are photographs. Firms running Risper CRM get the portal, permissions and activity logging as one system with the client record; the client portal guide covers selection in detail.
Frequently Asked Questions
Are password-protected PDFs a reasonable alternative?
They are better than nothing and worse than everything else: passwords get emailed alongside the file, protection is removable, and there is still no audit trail or revocation. Treat them as a stopgap, not a policy.
What about WhatsApp for document exchange?
Clients will always send things by WhatsApp. The practice is: accept it, file it into the system immediately, and route the reply through the portal. The firm's outbound channel is the one you control.
How do we handle third-party requests (banks, lawyers)?
Through time-limited, logged share links or a guest portal space — never by forwarding the client's file from an inbox. The audit trail must show what was shared with whom, and when access ended.
Move your firm's document exchange onto rails — see the portal features at rispercrm.com/feature.







