Every provider will tell you they take security seriously. The useful question is not whether they say it, but whether they can evidence it without a delay while somebody writes something.
Below is the list we would use if we were buying rather than selling. Ask them in a call, not by email — the hesitations are informative.
First, establish which kind of provider you are talking to
This question determines which of the others actually matter, and almost nobody asks it first:
Does our data get copied into a system you control, or do you work inside our existing software?
Providers who host your data — importing your ledger into their own platform, portal or data warehouse — are taking custody of it. For them, hosting certifications like ISO 27001 and SOC 2 are the right thing to ask about, because those audits examine exactly that: how a provider stores and protects data it holds.
Providers who work inside your own subscription under named logins never take custody. There is no copy of your ledger anywhere else, so there is nothing of yours for them to lose. The controls that matter shift entirely to access: who holds a login, what it can do, and how fast you can switch it off.
Both models can be run well or badly. But asking a non-hosting provider for a SOC 2 report tells you very little, and a provider who cheerfully waves one at you without explaining which model they operate is telling you something about how carefully they are answering.
If they host your data
- Which certifications do you currently hold, and what is the scope statement on each? Scope matters more than the badge. An ISO 27001 certificate covering only the head office is not the same as one covering the delivery floor your work runs on.
- When was your last external audit and who performed it? A certificate more than a year old without a surveillance audit is a flag.
- Will you share the SOC 2 report itself, under NDA, not just the badge? Anyone genuinely certified will say yes immediately.
- Where is the hosted copy physically located, and what happens to it when we leave? Get the deletion timetable in writing.
- Have you had a reportable security incident in the last three years, and what changed afterwards? “Never had one” is a less credible answer than a specific, well-handled incident with a documented remediation.
If they work inside your systems
- Will every person use a named individual login that we create? A shared credential destroys your audit trail. This is a hard no.
- What is the minimum permission set you need? A provider who asks for full admin on everything has not thought about it.
- Can we revoke access unilaterally, without contacting you? The answer should be yes, immediately, with no consequences beyond the work stopping.
- Is anything downloaded to local machines? And if so, what governs it.
- Will you commit to all of the above in the contract? Willingness here is the whole test.
Access architecture
- Do your staff access our systems through a virtual desktop, or from local machines?
- Can client data be downloaded to a local drive at all? If so, under what controls?
- Are USB ports and external storage disabled at endpoint level?
- Do staff use named individual logins in our systems, or a shared credential? (A shared login destroys your audit trail. This is a hard no.)
- Is MFA enforced on every account, without exception?
- Can you provide session logs for our engagement on request?
People
- What background checks are performed before someone gets system access?
- Are NDAs signed individually by each person working on our files, or only at company level?
- How quickly is access revoked when someone leaves, and how is that verified?
- Is access reviewed periodically, and how often?
- Will the same named people work on our files, or is work pooled across a floor?
Physical
- Is the delivery floor segregated by client, or open plan across all engagements?
- Are printers available on the floor? Is there any paper at all?
- Are personal phones permitted at desks?
Data protection and contracts
- Will you execute a Data Processing Agreement, and can we see the template now?
- Where is our data processed, and what covers any transfer out of the UK or EEA?
- Can you provide your sub-processor register? (If they say they have no sub-processors, ask about their cloud hosting, email provider and backup vendor — everyone has some.)
- What is your documented retention and deletion schedule at the end of an engagement?
Reading the answers
Three patterns are worth attending to.
Speed of response. Providers with genuine controls answer these instantly because they field them weekly. Long pauses and “let me check with our IT team” on basic questions suggest the controls exist on paper rather than in operation.
Specificity. “We’re fully GDPR compliant” is not an answer. “We’re a processor under Article 28, here’s our DPA template, transfers are covered by the UK IDTA, and our sub-processor register is appendix C” is an answer.
Willingness to be checked. The best signal is a provider who volunteers evidence before you ask for it, and who offers to complete your security questionnaire rather than insisting you accept their summary.
One last thing worth saying plainly: your professional indemnity insurer may have a view on all of this, and it is much cheaper to ask them before you sign than after something goes wrong.