Client Offboarding IT Checklist: How Arizona CPA Firms Should Handle Departing Clients

Why CPA Firms Need a Formal Client Offboarding Process

When a client relationship ends at your CPA firm, what happens to their data? If the answer is “nothing,” you have a compliance problem.

Most Arizona CPA firms have a solid client onboarding process. New engagement letters, portal setup, document collection. But when a client leaves? Their login credentials sit active in your portal. Their tax documents remain in shared drives. Their personal information lives in email archives nobody remembers to clean out.

Under the FTC Safeguards Rule, your firm is required to have documented procedures for managing access to client information, including revoking that access when the business relationship ends. Arizona’s ARS 18-552 adds liability if unencrypted personal information is breached, even from a former client’s records sitting forgotten on a shared drive.

The Client Offboarding IT Checklist

1. Revoke portal and system access

Disable the client’s login to your client portal, document sharing platform, and any other system they had access to. Don’t just change passwords. Disable the account entirely. This should happen within 24 hours of the engagement ending.

2. Archive client files

Move all client documents from active shared drives to a secure archive. Your WISP should define how long you retain client records (typically 7 years for tax returns) and where archived files are stored. The archive location should be encrypted and access-restricted.

3. Remove client data from email

Search your firm’s email for the client’s name, SSN fragments, and account numbers. Archive or delete emails containing sensitive information. This is the step most firms skip, and it’s the one most likely to create a breach exposure.

4. Update your access control list

Remove the client from any access control lists, distribution groups, or shared calendars. Document who had access to this client’s information and confirm all access has been revoked.

5. Purge temporary files

Check for client data in temporary locations: desktop folders, downloads directories, personal OneDrive or Google Drive accounts, and any local copies on staff laptops. Tax season creates data sprawl. Offboarding is when you clean it up.

6. Send a data disposition notice

Notify the departing client in writing about what data you’re retaining, for how long, and how it’s protected. This is both a professional courtesy and a compliance safeguard that documents your firm’s data handling practices.

7. Document the offboarding

Create a record showing the date of offboarding, what access was revoked, what data was archived, and who performed each step. This documentation is your evidence of compliance if questions arise later.

The Compliance Connection

A documented client offboarding process satisfies multiple compliance requirements:

  • FTC Safeguards Rule: Access control and data disposal procedures
  • IRS Publication 4557: Protection of client tax information
  • ARS 18-552: Protection of personal information under Arizona law
  • Professional liability: Reduces exposure from former client data breaches

Making It Automatic

The best offboarding processes are triggered automatically when a client is marked as inactive in your practice management software. Your IT provider can configure automated workflows that revoke access, move files to archive, and generate the documentation, so your team doesn’t have to remember every step manually.

Asteroid IT works with CPA firms across the Gilbert, Mesa, and Phoenix metro area to build compliance-ready IT systems including automated client offboarding. If your firm doesn’t have a formal process, we can help you build one.

Call us at 480-937-7021 or schedule a conversation.

Scroll to Top