← Back to the blog
Sunset Docs blog

How accountants can collect client documents more securely

A practical intake workflow for collecting financial documents without leaving attachments across staff and client inboxes.

Accountants and bookkeepers can reduce document sprawl by giving each client one intake route, requesting a precise set of records for a defined period and deleting the temporary submission after the required items enter the accounting or practice-management system.

The portal is the receiving desk, not the client file. That distinction prevents invoices, statements, payroll reports and identity evidence from settling into personal inboxes, download folders and long email threads.

Define the job before opening intake

"Send everything for the quarter" is quick to write and expensive to manage. Clients respond with duplicate exports, full statements when two pages would do, unrelated correspondence and records from the wrong period.

Create a request from the work program. For each item, state:

  • The exact document or report
  • The entity, account or period it should cover
  • The accepted format
  • Why the item is needed
  • Whether a redacted or partial copy is acceptable
  • Who will review it
  • Where the approved record will be kept
  • When the intake copy will be deleted

The GDPR's data minimisation principle applies when the records contain personal data: collect information that is adequate, relevant and limited to what the stated purpose needs. Tax, company and professional rules may require particular records to be retained. Those rules govern the official client file, not every attachment or temporary working copy.

Use an intake matrix

This example turns a recurring bookkeeping request into a controlled handoff. Adjust it to the engagement and local requirements.

Requested item Scope to state Intake reviewer Approved destination Intake end point
Sales invoices Entity and exact month or quarter Assigned bookkeeper Accounting ledger or document system After import and reconciliation
Supplier invoices Entity, period and supported formats Assigned bookkeeper Accounting ledger or document system After import and reconciliation
Bank evidence Named account and exact date range, with unrelated fields redacted where allowed Engagement team member Reconciliation record or approved client file After review and approved transfer
Expense evidence Named claimant, category and period Bookkeeper or expense reviewer Expense system After acceptance or rejection
Signed authority Named service and signatory Engagement lead Practice-management record After the official record is confirmed
Identity or ownership evidence Only when a defined check requires it Authorised compliance role Approved verification or compliance system As soon as the check and required record are complete

Add a row only when the engagement needs it. A blank destination is a warning: if nobody knows where the record belongs after review, the intake portal may become an accidental archive.

Keep the request and the document separate

Send a notification that identifies the firm, engagement and deadline without putting sensitive details in the subject line. The message can link to an upload page where the client sees the exact request and the firm's privacy information.

Avoid attaching a partially completed tax form or statement as an example if it contains real data. Use a blank template or describe the fields required. Do not place tax identifiers, bank-account numbers or filenames in reminders.

A dedicated document email address can help clients who cannot use a browser upload. It still creates copies in the client's Sent folder and mail systems. Explain that limitation and avoid forwarding the message internally. The comparison of upload portals and email attachments covers the tradeoffs.

The US Internal Revenue Service's Publication 4557, Safeguarding Taxpayer Data recommends that tax professionals know where sensitive information is stored, limit access to authorised employees, encrypt sensitive information in transit and dispose of records securely. Its legal references apply to US tax professionals, but the inventory and access questions are useful operational prompts elsewhere. Firms should follow their own regulator, professional body and applicable law.

Give each client a repeatable submission pattern

Clients make fewer mistakes when the pattern stays the same:

  1. The firm sends one request for one accounting period.
  2. The client uses the firm's recognisable upload page.
  3. The portal confirms receipt without listing filenames in email.
  4. The assigned reviewer checks completeness and rejects unusable files.
  5. The reviewer imports or records accepted information in the approved accounting system.
  6. The firm asks for replacements through the same route.
  7. The reviewer closes the checklist and removes the temporary intake copy.

Keep an engagement checklist outside the intake portal. It can show "March bank evidence received" without copying account numbers, balances or filenames. That gives the team a progress view while the documents follow their own deletion schedule.

Limit access by engagement and task

Reception may need to know that something arrived without reading it. A bookkeeper may need invoices but not beneficial-owner evidence. A partner may approve an exception without needing routine access to every statement. An external contractor should not inherit the full client list because they cover one week of work.

Use named accounts and review permissions after staff or engagement changes. Separate ordinary viewing from original downloads, deletion changes and member administration. The least-privilege checklist provides an access matrix that can be adapted to an accounting practice.

The European Data Protection Board's small-business security guidance recommends unique identifiers, differentiated authorisation profiles, removal of obsolete permissions and regular access reviews. It also stresses that controls should match the risk of the processing.

Treat bank-detail changes as a separate fraud control

A portal can receive a bank letter or mandate, but the upload does not prove the sender's identity or confirm that payment details are genuine. An attacker who controls a client's email may also receive or submit through links sent to that address.

Verify payment-detail changes through a separate, trusted route defined by the firm. For example, use an established telephone number from the client record and an authorised staff member. Do not use the number supplied in the same change request as the only check.

Document intake, malware scanning and file validation do not replace identity checks, anti-money-laundering procedures, electronic signatures or payment authorisation. Each needs its own approved control.

Check whether the service permits the records

Accounting work often involves documents that mix ordinary financial information with restricted categories. A personal tax return may contain information about dependants, health costs or criminal matters. Payroll records may include sickness or union deductions. A full payment-card statement may contain card data that a general intake product does not permit.

Sunset Docs is not authorised by default for children's data, criminal-conviction data, special-category data, biometric data used for unique identification, full payment-card data, credentials or secrets. Do not upload a whole return or payroll bundle until someone has checked its contents against those restrictions. Use an approved alternative or arrange the required written agreement where available.

The service also does not verify identity and is not a permanent tax, accounting or client-record archive. Its role is temporary intake of allowed documents. The 15-question portal evaluation helps teams assess this fit before use.

Close the loop after review

When a submission is complete, record the work outcome in the engagement system. Move only the documents the firm must retain into the approved client record. Then delete the temporary intake copy and any exceptional local downloads.

Do not promise that deleting the active submission instantly erases every protected backup. Check the provider's published backup cycle. Do not let subscription cancellation or a payment problem extend the document's deletion date either.

Sunset Docs schedules deletion at intake, lets authorised users delete earlier and keeps the retention process running through billing changes. Its viewer can reduce routine original downloads, but it cannot prevent screenshots, photographs, printing or transcription. Current controls and boundaries are published on the Security page.

A client request template

Please use our document upload page for the {month, quarter or engagement} records:

{upload_link}

Please provide {exact items} for {entity and date range} by {date}. Do not include records outside that period. You may redact {fields} if they are not needed for this work and the document remains usable.

{role or team} will review the submission. The temporary intake copy is scheduled for deletion {timing}. Records that we must retain will be placed in our approved client system under the retention information in {privacy notice or engagement link}.

Contact {firm contact} before uploading health information, children's data, criminal-record information, full payment-card data or account credentials.

Frequently asked questions

Is an upload portal a replacement for accounting software?

No. It receives files for review. Transactions, reconciliations, workpapers and retained client records belong in the firm's approved accounting, tax or practice-management systems.

Can clients email documents if they prefer?

The firm can offer approved email intake as a fallback. Explain that external mailbox copies remain, keep the subject generic and move the work into the same controlled review and deletion process.

Should the firm keep every original it receives?

No. Keep records the engagement, professional rules or law require. Remove duplicate and temporary intake copies when their purpose ends. The firm should document the distinction.

Can a portal complete customer due diligence?

No. Receiving a file does not verify identity, ownership, authenticity or sanctions status. Use the firm's approved compliance and verification process.

What if a document contains a dependant's information?

Stop before uploading it to a service that does not permit children's data. Use an approved route or collect a narrower record if the process and applicable rules allow it.

How should seasonal staff receive access?

Give each person a named account, the narrowest role needed and an end date tied to the assignment. Review recent activity and remove access as soon as the engagement ends.