Build a stronger firm / A practical guide

How should an accounting firm prepare system access for succession?

Prepare access succession through a current system inventory, named accounts, limited permissions, secure recovery arrangements, and a tested handover plan. Identify owner-only administration and contractual transfer restrictions before closing. A password list alone does not establish lawful access, client permissions, reliable recovery, or safe removal of the seller after the transition.

Why is access a business continuity issue?

An accounting practice can be operationally dependent on one person’s phone, email address, or administrator account. Staff may complete daily work normally while the owner alone can restore access, approve a subscription, or recover a locked system. The operations hub treats those dependencies as part of succession preparation because a buyer needs a controlled path to continue the service.

Access succession is the planned transfer of authorized system administration, user permissions, authentication, and recovery responsibilities as ownership or operating roles change.

It is broader than saving passwords. A credential may work technically while its use violates provider terms or exposes information beyond the user’s permitted role. Conversely, a valid successor may be unable to operate because the recovery method still belongs to the seller. Identify legal permission, technical control, and continuity separately.

What belongs in the system inventory?

List practice management, tax preparation, accounting platforms, payroll systems, document storage, email, domains, billing, banking interfaces, e-signature, backup, and security administration where relevant. Record the business purpose, contract owner, administrator, authorized users, data category, and recovery path. Do not include live passwords in the ordinary inventory.

Map connected services. A payroll platform may depend on an email account, which depends on a domain administrator, whose recovery uses a personal phone. A list of standalone applications can miss that chain. Identify the systems that could prevent work across the practice if their administrative access fails.

How should permissions be described?

Use named accounts where available and define roles according to the work required. Distinguish ordinary user, reviewer, billing, security administrator, and recovery authority. Record temporary privileges and the reason for them. Broad access given years ago should not be assumed necessary because no incident has been observed.

IRS Publication 4557 discusses taxpayer data safeguards, including limiting access, authentication, backups, employee training, and service provider arrangements. Professional tax preparers should evaluate their actual security obligations and written security plans. A sale does not suspend those obligations during diligence or transition.

Review privileged accounts first, including vendor support access. Identify who can add users, change permissions, export records, modify payment details, or delete information. These powers can be more consequential than daily access to a single client file. Preserve an approval record for changes and use monitoring appropriate to the system and risk.

What should a handover register show?

Create a register of access dependencies and planned actions. It should explain what is controlled now, what the successor needs, how the transfer is authorized, and how completion will be verified. Keep sensitive credential material in the approved secure system rather than attaching it to a general transaction checklist.

Access dependencies to resolve before a practice handover
DependencyQuestionEvidence of completion
Administrator roleWho can manage authorized users?Tested successor administration
MFA and recoveryCan access survive the seller’s departure?Approved recovery test
Contract ownershipIs consent or migration needed?Reviewed provider arrangement
Client permissionsWhich access is authorized?Documented permission process
OffboardingWhich rights should end?Verified removal or limited continuation

For each action, identify the responsible person and the earliest appropriate date. Some tasks can be prepared before closing, while actual control changes may depend on conditions and permissions. Do not grant premature access merely to mark the register complete. The plan should fit the transaction, not force the transaction to fit the checklist.

How should owner-only recovery be addressed?

Identify personal email addresses, phones, payment cards, devices, and security keys supporting business systems. Use the provider’s approved process to establish business-controlled and authorized successor arrangements. Confirm that backup recovery is available and appropriately protected. Avoid disabling multifactor authentication simply because ownership is changing.

Test recovery in a controlled manner appropriate to the system. The objective is to show that the authorized team can regain access without relying on an unavailable seller. Do not conduct a disruptive live lockout experiment during a filing deadline. Record what was tested and any limitations or unresolved dependencies.

How does the cybersecurity framework help organize the work?

The NIST small business Cybersecurity Framework 2.0 guidance organizes cybersecurity outcomes around Govern, Identify, Protect, Detect, Respond, and Recover. It is a voluntary framework, not a certificate that a practice is secure. Use it to ask coherent questions about responsibility, inventory, controls, monitoring, incidents, and restoration.

Compare the current arrangement with the intended post-closing arrangement. A new owner may use different software or security administration, creating a migration period with additional dependencies. Describe the target state and the interim controls. A planned improvement should not be represented as already operating in the seller’s historical practice.

What does a fictional dependency test demonstrate?

Suppose a fictional firm has six critical systems. Four have two authorized administrators, one has a seller-only recovery email, and one subscription is held personally by the seller. The six-system count is illustrative. It does not prove that the first four are safe or that the other two can be transferred without provider review.

The exercise identifies two specific questions: how to establish authorized recovery and how the subscription should continue. Confirm the actual terms and test the approved process. A successful login by a staff member is not sufficient evidence of recovery capability, administrative authority, or permission to transfer the account.

Which contract and client restrictions must be checked?

The vendor transfer review guide covers assignment, change of control, subscriptions, data export, and migration costs. Review the actual provider documents instead of assuming all cloud systems follow the same rules. Determine whether the transaction involves account continuation, a new agreement, or a controlled move to another system.

For tax return information, the IRS Section 7216 information center addresses restrictions, exceptions, and consent requirements for use and disclosure. Technical access does not itself authorize every use. Qualified advisors should evaluate the proposed transfer and support arrangements before sensitive information is made available.

How should staff be prepared?

Explain the authorized process for requesting access, recovering accounts, reporting suspicious activity, and removing privileges. Test that staff know where to escalate a problem. The cross-training guide emphasizes observed readiness rather than attendance alone. Security responsibilities should have competent backups without spreading administrator rights unnecessarily.

Update onboarding and role-change procedures. The client onboarding guide connects client permissions to service readiness. Staff joining a new engagement or changing roles should receive the access they need through the approved process, rather than inheriting a shared credential that conceals who performed an action.

What should happen at and after closing?

Follow the agreed control-change sequence, verify authorized successor access, and confirm recovery and backup arrangements. Review seller access against any continuing responsibilities and remove unnecessary privileges. Preserve relevant logs and approvals. A consulting transition may justify limited access, but it does not automatically justify unrestricted administration of every system.

After the handover, reconcile the inventory to actual accounts and provider billing. Check that former personnel, temporary diligence users, and unused integrations have been addressed. Access succession is complete only when the approved arrangement works in practice and the remaining dependencies are visible to the people responsible for continuity.

A few common questions

What else should you know?

Should a seller put passwords in the buyer data room?

Avoid exposing live credentials in an ordinary diligence data room. Provide an appropriately limited system and role inventory first. Plan authorized access transfer through approved secure methods, applicable permissions, and provider procedures. The buyer needs evidence of continuity and dependencies, but that does not require broad credential disclosure before the relevant handover step.

Does ownership of the practice automatically transfer every software account?

No. Provider terms, contract structure, account ownership, client permissions, and transaction form can affect the process. Some accounts require consent, new subscriptions, or a separate migration. Review the actual agreements and obtain provider guidance where necessary. Do not infer that buying the business automatically gives unrestricted access to every hosted account or dataset.

What if multifactor authentication uses the seller’s personal phone?

Identify the dependency and use the provider’s approved process to establish authorized successor authentication and recovery. Test the arrangement before relying on it. Do not simply disable protections or share personal authentication codes broadly. The timing should follow the transaction plan, permissions, and continuity needs while preserving appropriate control over sensitive information.

When should the seller’s access be removed?

Set the timing according to the closing and transition arrangements, actual responsibilities, professional requirements, and permissions. Reduce unnecessary privileges and record authorized continuing access where needed. Test successor control before removing essential recovery paths, then verify offboarding. A seller’s consulting role does not necessarily require the same administrator rights held before the sale.

Which sources support this guide?

Primary rules and guidance support the factual statements in this article. The worked examples and decision frameworks are original educational analysis.

  1. Publication 4557: Safeguarding Taxpayer Data — Internal Revenue Service
  2. NIST Cybersecurity Framework 2.0 for small businesses — National Institute of Standards and Technology
  3. Section 7216 Information Center — Internal Revenue Service

Your next chapter starts with a conversation

Talk through the deal.
Before you make the decision.

Bring your questions about value, timing, buyers, or what comes next. Start with a confidential intro call with Jason Taken.

Book a confidential intro call