Free Resource · guide

What Should a Managed IT Agreement for a CPA Firm Include?

A managed IT agreement for a CPA firm should put nine things in writing: covered users and devices, response expectations, data ownership and return on exit, confidentiality terms for client financial data, FTC Safeguards Rule responsibilities, backup and retention specifics, breach notification duties, tax season and after-hours coverage, and exit terms. If a promise only exists in a sales conversation, it is not part of the deal.

A managed IT agreement for a CPA firm should define, in writing, what is covered, how fast support responds, who owns the data and how it comes back on exit, how the provider protects client financial information, who does what under the FTC Safeguards Rule, how backups and retention work, who tells whom when something goes wrong, and how the relationship ends. We wrote a general version of this checklist for manufacturers, what a managed IT agreement should include, and this article is the accounting firm edition, because a firm holding client tax returns and financial records has contract needs an ordinary office does not.

One note before the list. This is practical guidance from an IT provider that works with accounting firms, not legal advice. Have your attorney review any agreement before you sign it.

What exactly is covered? Get the scope and device list in writing

The agreement should enumerate what the monthly rate covers:

  • Users, including how seasonal and part-time staff are counted
  • Workstations, laptops, and any home machines partners use for firm work
  • Servers, whether in the office or hosted
  • Microsoft 365 or Google Workspace tenants
  • Tax, accounting, and document management applications
  • Network equipment and firewalls

For a CPA firm, ask two scope questions directly. First, how are seasonal preparers handled, added and removed per season, or billed year round? Second, are your line-of-business applications, tax prep, accounting, document management, supported by name, or does the provider stop at “we support Windows”? A limited scope stated in writing beats a full scope implied in a sales call.

How fast will they respond? Ask for written numbers

“Responsive” and “unlimited support” describe intent, not commitment. The agreement should state:

  • Support hours, and what happens outside them
  • How your staff reaches a person, not just a portal
  • How priorities are assigned, and where “the tax software is down for the whole office” ranks
  • A response expectation for each priority, in numbers
  • How escalation works when the first response does not fix it

We will not tell you what those numbers should be, because inventing priority tiers for someone else’s contract is how vague agreements get written. As a reference point for what a written commitment can look like: Braintek typically answers the phone in about 60 seconds and responds to emailed tickets in roughly 2 hours. Those are measured typicals. Your provider’s numbers can differ, but they need to exist, on paper.

Who owns your data, and how do you get it back?

This clause matters more for a CPA firm than almost any other business, because “your data” includes your clients’ data. The agreement should state plainly:

  • The firm owns all firm and client data, full stop
  • Where that data lives, and whether any of it sits in systems only the provider controls
  • On termination, how data is returned: format, timeframe, and cost
  • When and how the provider deletes its copies after handoff
  • That administrative credentials, passwords, and documentation belong to the firm and are handed over on exit

A provider who resists putting data return in writing is telling you how the exit will go. You should be able to leave with everything you arrived with, plus everything created since.

How is client financial data kept confidential?

Your engagement letters promise clients confidentiality, and your IT provider’s staff can see everything. The agreement should cover:

  • A confidentiality clause binding the provider and its employees, including any offshore staff
  • Who at the provider can access your systems, and how that access is logged
  • A commitment not to use or disclose firm or client data outside of providing the service
  • How the provider secures its own remote access tools, since those are a path into every client file you hold

Ask where the provider’s support staff sit and how access is controlled. Braintek’s teams are in Houston, DFW, and the Philippines, and every technician works under the same confidentiality obligations and logged access regardless of location. Whatever a provider’s answer is, it belongs in the agreement rather than in a reassuring email.

Who handles FTC Safeguards Rule compliance, you or the provider?

Both, and the agreement should say which parts belong to whom. The Safeguards Rule under the Gramm-Leach-Bliley Act applies to financial institutions broadly, which includes tax preparers and CPA firms handling customer financial information. It requires a written information security program, a designated qualified individual, periodic risk assessments, and controls including multi-factor authentication, encryption of customer information, and monitoring.

Here is the division of labor that actually works, and that the agreement should reflect:

  • The firm owns its written information security program and names its qualified individual. Compliance obligations attach to the firm and cannot be outsourced away.
  • The provider implements the technical controls, MFA, encryption, access controls, monitoring, backup, and produces the evidence: reports and documentation showing each control is in place and working.
  • The agreement states which Safeguards controls the provider is responsible for implementing and documenting, so that when your qualified individual has to report on the program, the paperwork exists.

If a provider says “we handle Safeguards compliance for you,” ask what, specifically, they implement and document, and get that list into the contract. We cover the rule itself in more depth in our FTC Safeguards Rule guide for CPA firms, and our IT support for CPAs and financial advisors page describes how we structure this for accounting practices.

What do the backup and retention clauses need to say?

“Backups are included” is not a backup clause. For a firm whose files include years of client returns and workpapers, the agreement should specify:

  • What is backed up: servers, workstations if applicable, Microsoft 365 mail and files, and the data behind your tax and accounting applications
  • How often backups run
  • How long backups are retained, checked against your own document retention obligations
  • Where backups are stored, and whether a copy exists outside your office
  • Whether restores are tested, and how often
  • Who monitors backup success and what happens when a job fails

Retention deserves a direct conversation. CPA firms keep records for years; a provider’s default 30 or 90 day retention window may be shorter than what your firm’s retention policy assumes. Reconcile the two before signing, not after you need a file from two years ago.

Who tells whom when something goes wrong?

If the provider detects a breach or suspects one, what happens next should not depend on their judgment in the moment. The agreement should state:

  • The provider notifies the firm of any known or suspected security incident affecting your systems or data, within a stated timeframe
  • What that notification includes: what happened, what data was involved, what has been done
  • Who at the firm gets the call
  • That the provider will cooperate with your investigation, your attorney, your insurer, and any notification duties the firm has

The firm’s legal notification obligations to clients and regulators stay with the firm. What you need from the provider, in writing, is that you find out fast and get their full cooperation.

What about tax season and after-hours work?

An accounting firm’s calendar is not flat, and the agreement should acknowledge it:

  • After-hours and weekend support: is it included, on-call, or billed separately, and at what rate?
  • Can the provider hold non-urgent maintenance and changes during filing season, so an update does not take down the tax server the week of a deadline?
  • How are urgent issues handled the night before a filing deadline?

None of this requires special contract language so much as it requires asking, and writing down the answers. A provider who has supported accounting firms through a busy season will have ready answers.

How does the relationship end?

Exit terms are easiest to negotiate when nobody is leaving. The agreement should cover:

  • Contract length and renewal: does it auto-renew, and how much notice does cancellation take?
  • Early termination: what does leaving mid-term cost?
  • The offboarding handoff: credentials, documentation, license transfers, and data return, tied to the data ownership clause above
  • A commitment to cooperate with the incoming provider during transition

One useful signal of how a provider treats these terms: whether they show you their contract before you ask. We publish our client terms publicly at braintek.com/legal, because terms you can read before the first meeting are harder to quietly change later.

What is usually not included?

Every managed agreement has exclusions, and that is normal. Common items billed outside the monthly rate:

  • Major projects, like a server migration, office move, or new tax software rollout
  • Hardware purchases
  • Software licensing, including Microsoft 365 and your tax applications
  • Network cabling
  • After-hours project work

The problem is never the exclusions themselves. It is discovering them on an invoice. Get the list in writing, and when you compare quotes, compare scopes before prices. As context for the numbers, Braintek’s managed IT services run about $150 to $250 per device per month plus $15 to $35 per mailbox, with licensing separate, and we break down what that means for an accounting practice in our CPA firm cost guide.

Who does this for accounting firms in Houston and DFW?

Braintek has supported Texas businesses since 2002, with staff in Houston, DFW, and the Philippines. Fully managed support fits firms of roughly 10 to 50 employees; larger firms, up to around 1,500 employees, usually do better co-managed, with your internal IT handling day to day work while we cover security, projects, and escalations. If you are comparing agreements, or suspect your current one is thinner than you thought, send it over. We will tell you plainly what is covered, what is missing, and what to ask for in writing, whether or not you ever work with us. Start at our IT support for CPAs and financial advisors page or use the form below.

Want a second opinion on an IT agreement?

Send us the agreement or proposal your firm is looking at and we'll flag what's missing, what's vague, and what to ask for in writing before you sign.

By submitting, you agree to be contacted by Braintek about your inquiry.

FAQs

Who owns our client data if we leave our IT provider?

Your firm does, and the agreement should say so in plain language. It should also state how data is returned on exit, in what format, in what timeframe, and at what cost, and when the provider deletes their copies. If the contract is silent on this, ask for it in writing before signing.

Does the FTC Safeguards Rule apply to CPA firms?

Generally yes. The Safeguards Rule under the Gramm-Leach-Bliley Act covers financial institutions broadly, including tax preparers and accounting firms that handle customer financial information, not just banks. It requires a written information security program, a designated qualified individual, risk assessments, and controls like MFA, encryption, and monitoring.

Can our IT provider be our qualified individual under the Safeguards Rule?

The rule allows a service provider to serve in that role, but the firm keeps accountability either way: it must designate someone senior internally to oversee that provider, and the written program still belongs to the firm. The cleaner arrangement for most small firms is naming someone internal as the qualified individual while the MSP implements the controls and supplies the evidence.

What response times should the agreement include?

Whatever numbers the provider will actually commit to on paper. Verbal promises about being responsive do not count. As a reference point, Braintek typically answers phone calls in about 60 seconds and responds to emailed tickets in roughly 2 hours. Those are measured typicals, not guarantees, and other providers will have different numbers. What matters is that their numbers are written down.

Should tax season get its own terms in the agreement?

It helps. Your busiest weeks are when an outage costs the most, so ask how after-hours and weekend support works from February through April, what it costs, and whether the provider will hold changes and maintenance during filing crunch. A provider who supports accounting firms will have answers ready.

What is usually excluded from a managed IT agreement?

Major projects like server migrations or office moves, hardware purchases, software licensing, cabling, and after-hours project work are commonly billed outside the monthly rate. Exclusions are normal. The problem is exclusions you discover on an invoice, so ask for the list in writing.

How much does managed IT cost for a CPA firm?

As context, Braintek's managed IT runs about $150 to $250 per device per month plus $15 to $35 per mailbox, with Microsoft licensing billed separately. Any provider's number only means something once you can compare it against a written scope.

Ready for IT that just works?

Book a no-pressure discovery call. We'll review your setup and show you exactly where you stand.