Your bookkeeper gave two weeks notice on a Friday. By Monday morning, did anyone disable her access to QuickBooks Online, the client portal, and the shared Google Drive folder with five years of tax returns? For most small CPA firms, the honest answer is no, and that gap is exactly where CPA firm data security employee offboarding breaks down.
Most small accounting firms treat employee departures as an HR event: collecting a key fob, processing final pay, and updating org charts. The IT security side of offboarding rarely happens on the same timeline, and the window between an employee's last day and credential revocation is one of the highest-risk periods a financial firm can create.
In This Article
- What Data Is Actually at Risk When Someone Walks Out the Door
- The FTC Safeguards Rule Makes This a Compliance Problem, Not Just a Risk
- A 5-Step IT Offboarding Checklist for Accounting Firms
- Why This Is Harder Than It Looks Without a Managed IT Partner
- Not Sure Your Last Employee Departure Left Your Client Data Secure?
Why Credential Revocation Rarely Happens on Day One
Firm owners are managing client work, not monitoring access logs. When a senior accountant gives notice, the immediate priority is covering the transition, not auditing platform permissions. Access revocation gets added to a mental to-do list and frequently slips.
The result is predictable: a departing employee's accounts stay active in platforms like Canopy or Karbon, cloud-based practice management tools used by accounting firms, for days or weeks after their last day. One firm owner reviewing a software bill two weeks after a departure notices the former employee's Canopy seat is still billable and active. That is the moment the access question gets asked, which is far too late.
The offboarding gap is not a staffing problem. It is a systems problem. Without dedicated IT infrastructure in place, most small firms have no reliable way to close it consistently.
What Data Is Actually at Risk When Someone Walks Out the Door
A departing CPA firm employee typically has access to some of the most sensitive data categories that exist: client tax returns, Social Security numbers, bank account details, payroll records, and multi-year financial statements. The risk is not theoretical, it is a function of how much access accounting staff require to do their jobs.
Desktop Software vs. Cloud Platforms: Why the Distinction Matters
Data stored in desktop software like QuickBooks Desktop is only accessible from a specific machine on the firm's network. When an employee stops coming in, that access stops naturally.
Cloud platforms work differently. QuickBooks Online, Microsoft 365, and Google Workspace grant access through credentials, not physical presence. A former employee with an active login can access client data from any device, anywhere, long after their last day in the office.
| Platform Type | Example | Access After Departure? | Revocation Required? |
|---|---|---|---|
| Desktop Software | QuickBooks Desktop | No — tied to firm network | Low priority |
| Cloud Accounting | QuickBooks Online | Yes — credential-based | Immediate |
| Cloud Productivity | Microsoft 365, Google Workspace | Yes — credential-based | Immediate |
| Practice Management | Canopy, Karbon, Drake Tax | Yes — credential-based | Immediate |
The Data Exfiltration Pattern You Should Know About
A disgruntled employee forwarding a client list to a personal Gmail account before their last day is not a hypothetical, it is a documented pattern in professional services departures. The forwarding happens silently, leaves no obvious trace without audit logging, and is nearly impossible to detect without cybersecurity controls that monitor outbound data movement.
By the time the firm realizes a client list has moved, the damage is already done. Accounting firm data breach offboarding scenarios almost always follow this pattern: the departure looks clean on the surface, and the exposure surfaces weeks later.
The FTC Safeguards Rule Makes This a Compliance Problem, Not Just a Risk
The FTC Safeguards Rule, updated in 2023, requires financial institutions (a category that includes most CPA firms and tax preparation businesses) to maintain a written information security program that explicitly covers access controls and employee offboarding procedures. Failing to revoke a former employee's access in a documented, timely manner is not just a security gap, it is a potential Safeguards Rule violation.
What "Written Information Security Program" Means for Offboarding
The FTC Safeguards Rule does not just require that a firm have good intentions about security. The Safeguards Rule requires documented policies, designated personnel responsible for the program, and evidence that access controls are being enforced.
FTC Safeguards Rule employee offboarding compliance means your firm must be able to demonstrate in writing that a departed employee's access was revoked, when it was revoked, and who was responsible for doing it. A verbal confirmation that someone "took care of it" does not meet that standard.
Firms that need to build or audit their Safeguards compliance program can start with FTC Safeguards Rule compliance support from Shift Computer Services, which covers the access control documentation the rule requires.
FTC Enforcement Is a Real Consequence
The FTC has enforcement authority over Safeguards Rule violations and has pursued action against financial services firms that failed to implement adequate security controls. A documented failure to revoke a former employee's access, especially if that access is later traced to a data exposure, creates significant enforcement exposure for a firm of any size.
A 5-Step IT Offboarding Checklist for Accounting Firms
CPA firm data security employee offboarding requires action on the day notice is given, not the day someone remembers to change a password. These five steps give firm owners a process they can assign, track, and document, covering every major access vector a departing employee controls.
-
Disable all cloud platform accounts on the day notice is given or the day of termination.
Accounts to disable include Microsoft 365 and Google Workspace access management, QuickBooks Online, Canopy, Karbon, Drake Tax, and any client-facing portals the employee used. Cloud access persists independently of physical presence, disabling the account is the only action that stops access.
-
Change all shared passwords and revoke shared mailbox access.
Shared email accounts, billing logins, and any credentials the employee knew but did not personally own must be rotated immediately. A former employee who memorized a shared password retains effective access even after their personal account is disabled.
-
Transfer ownership of any files or drives the employee controlled.
In Google Workspace and Microsoft 365, files and folders owned by a departing user can become inaccessible to the firm if the account is deleted without first transferring ownership. Ownership transfer must happen before account deletion to avoid data loss.
-
Audit login history for the 30 days prior to departure.
Review login records across all major platforms for unusual download volumes, after-hours access, or email forwarding rules that point to personal accounts. This step requires audit logging to be enabled in advance. It cannot be retroactively turned on after a departure if logging was never configured. Managed IT services ensure this logging is always active and reviewable on demand.
-
Retrieve or remote-wipe any firm-issued laptops or mobile devices.
Firm-issued devices must be physically recovered or remotely wiped using endpoint management software. If the device contained cached credentials, local copies of client files, or VPN client configuration, a remote wipe eliminates those access vectors. This step requires endpoint management tooling, not a manual request to the departing employee.
Steps 1, 4, and 5 specifically require IT-level tools and administrative access that most small CPA firms do not have configured in-house. Without those tools, the checklist stalls at the point of execution.
Why This Is Harder Than It Looks Without a Managed IT Partner
The five-step checklist above is straightforward in principle. In practice, it breaks down immediately for firms without dedicated IT infrastructure because completing the checklist requires tools and administrative access that small CPA firms rarely have configured on their own.
The Three Infrastructure Gaps That Break Offboarding
- No centralized identity management: Without Azure Active Directory or a similar identity platform, user accounts exist separately across every platform: QuickBooks Online, Google Workspace, Canopy, client portals, and more. Disabling one does not disable the others. There is no single off switch.
- No endpoint management: Without a mobile device management or endpoint management solution, the firm cannot remotely wipe a laptop or revoke access from a personal device that had the firm's VPN client installed. Retrieving the device physically becomes the only option and that depends entirely on the departing employee's cooperation.
- No audit logging: Without active audit logging configured across Microsoft 365, Google Workspace, and cloud accounting platforms, the firm has no evidence of what a departing employee accessed, downloaded, or forwarded in the weeks before leaving. Employee termination IT security for CPA firms is unenforceable without a documented evidence trail.
What a Managed IT Partner Changes
Shift Computer Services maintains the infrastructure (Azure Active Directory, endpoint management, cloud access controls, and audit logging) that reduces employee offboarding from a week-long scramble to a 15-minute process. When an employee gives notice, every platform access point is mapped, logged, and revocable from a single management console.
For Orange County CPA and accounting firms managing sensitive client data under FTC Safeguards requirements, IT services for financial and accounting firms in Orange County from Shift provide the controls that make this level of offboarding consistently executable, not dependent on whoever happens to remember to check.
Not Sure Your Last Employee Departure Left Your Client Data Secure?
In a free 15-minute discovery call, Shift Computer Services will review your current access controls and offboarding process and show you exactly where former employees may still have a door open to your firm's data.
Book Your Free 15-Minute Discovery Call
