Skip to content
Back to blog
accountants

Secure password sharing for accountants

P
PassTransfer
Published May 17, 20254 min read

Accountants occupy a position of significant trust. Clients share not just financial data, but access credentials to their banking systems, accounting software, payroll platforms, and tax portals. The way an accounting firm handles these credentials directly affects their professional obligation to protect client confidentiality.

The accounting firm credential landscape

A typical accounting practice manages credentials for multiple client systems:

Accounting software. Access to clients' QuickBooks, Xero, Sage, or similar platforms to review records, prepare filings, or manage bookkeeping.

Banking and financial platforms. Read-only access to client banking for reconciliation, or transactional access for payment processing services.

Tax authority portals. Government tax portals often issue credentials per filing agent. Managing these across a client base creates significant credential overhead.

Payroll systems. Access to client payroll platforms for preparation, review, or submission.

Business registries and filing systems. Access credentials for company secretarial work, regulatory filings, and business registry access.

Each client might have five to ten separate credential sets. Multiply that across a practice with 50, 100, or 500 clients, and credential management becomes a significant operational function.

Regulatory and professional obligations

Accounting professionals are subject to professional standards that include obligations around client data protection. While specific regulations vary by jurisdiction, the general principle is consistent: you have a duty of care for client information, including the credentials that grant access to that information.

Privacy regulations (GDPR, CCPA, and their equivalents) are increasingly interpreted to cover credential handling. A firm that stores client credentials in plain text email threads, accessible to anyone who gains access to an email account, faces real regulatory and professional liability.

Professional indemnity insurers are also increasingly asking about data handling practices. A firm with documented, systematic credential security processes is in a better position both legally and in terms of insurance risk.

Common risks in accounting practices

Email threads. "Here are our Xero credentials: [username] / [password]" exists in email threads across thousands of accounting firms right now. Each of those is a liability.

Shared spreadsheets. A central spreadsheet of client credentials, shared among staff, is a frequent audit finding. It's convenient but represents a catastrophic single point of failure.

Former staff access. Credentials that were sent to staff who have since left the firm are still in their email archives unless those credentials have been rotated.

Client-side exposure. When a client's email is compromised, any credentials they sent to their accountant via email are now exposed.

Implementing secure credential sharing in an accounting practice

Incoming credentials (client to firm). Provide clients with instructions for sharing credentials securely: "For security purposes, please share access credentials using this link rather than via email." Include the PassTransfer URL in your client onboarding documentation.

Internal sharing. When credentials need to move between staff (a partner delegates a filing to a junior, a colleague is covering an absence), use one-time links rather than email or message attachments.

Credential storage. The credential sharing tool handles transmission; a proper password manager handles storage. These are complementary tools. Credentials delivered via secure link should be saved to the firm's password manager, not retained in email.

Offboarding. When staff leave, any credentials shared with them via one-time links are already expired. But credentials stored in shared systems should be rotated as part of the offboarding process.

The client relationship benefit

Clients who are told "we handle all credential exchanges through encrypted, one-time-use links" receive a powerful signal about your firm's approach to their data. In an industry where trust is everything, demonstrating systematic security practice reinforces confidence. It's also a useful differentiator in a competitive market where most practices haven't yet formalized their credential handling. See PassTransfer for accountants for how this works in practice.

Share this article
P
PassTransfer

The team behind PassTransfer writes about secure sharing, compliance and practical security for teams and agencies.

Ready to get started?

Sharing securely takes 10 seconds

Paste your password, pick an expiry time and share the link. Free and without an account.

Share a password