Checklist · Security and privacy

Ask for specifics, evidence and shared responsibilities.

Replace generic claims of “bank-grade security” with questions about the actual people, devices, identities, systems and cross-border data flow.

Finance work can expose personal information, supplier bank details, payroll, customer records and commercially sensitive reports. Due diligence should therefore describe the real engagement, not award points for a long list of unexplained security terms.

1. Map the information and systems

  • Which data types will the role access?
  • Which systems are client-controlled and which, if any, are provider-controlled?
  • Can data be downloaded, printed, copied or stored locally?
  • Which locations and devices are permitted?
  • Who owns backup, retention and deletion?

For Jade engagements, the intended model is client-controlled cloud applications or client-approved VPN access. The precise arrangement must still be documented for the role.

2. Test identity and access controls

  • Are accounts individual and protected by MFA?
  • Who approves access and reviews it?
  • How are privileged permissions restricted?
  • How quickly are access and sessions removed after a role change or exit?
  • Are logs available to the client?

3. Establish device responsibility

Ask who supplies the device, applies security settings, patches software, monitors endpoint health and responds to loss. Under Jade’s model the client supplies or specifies devices, software and security requirements. That boundary should appear in onboarding and support procedures.

4. Understand cross-border privacy

Australian Privacy Principle 8 addresses circumstances in which an APP entity discloses personal information to an overseas recipient and the steps required before disclosure. APP 5 notification and APP 11 security obligations may also be relevant. Whether a particular access arrangement constitutes disclosure is fact-dependent, so obtain appropriate legal advice.

The Philippine Data Privacy Act and its implementing rules create obligations for processing personal information in the Philippines. Contractual roles, purpose, security, incident handling and return or deletion should be clear between the parties.

5. For tax and accounting practices, include professional duties

The Tax Practitioners Board’s offshoring guidance highlights confidentiality, disclosure, supervision and competent service. A provider cannot absorb the registered practitioner’s responsibility merely by preparing workpapers elsewhere. Identify the Australian reviewer and keep advice and lodgement within authorised practice.

6. Ask how incidents are handled

  • What must an employee report, to whom and through which channel?
  • Can the client disable access immediately?
  • How will facts, logs and affected information be preserved?
  • Who assesses notification duties?
  • How will communication be coordinated without premature assurances?

7. Test business continuity and offboarding

Ask what happens during power, connectivity, device, platform or personnel disruption. Business continuity must fit the client’s recovery priorities; no generic arrangement guarantees uninterrupted service. Offboarding should cover identity removal, property return, data handling, documentation and reassignment of open work.

Primary sources

This checklist is general operational information, not legal, privacy or cyber-security advice. Apply it to the systems, data and regulated duties of the actual engagement.

Apply it to your team

Turn the questions into a practical role brief.

Discuss the work, systems, review points and operating model with Jade.

Start the conversation