Playbook, accounting firm

When the security questionnaire is about somebody else's financial data

These arrive from people who are not your clients. A group auditor, a client's largest customer, a lender looking at a set of management accounts: they want to know where the bookkeeping sits, who at the practice can see it and what happens when a member of staff leaves. They usually arrive as a spreadsheet with a date on it, and the worst possible response is a confident one nobody at the practice has checked.

Why this is not the general answer

The handling pattern for security questionnaires holds across every trade. What follows is the part that does not.

  • The data being asked about belongs to a client rather than to the practice, so a careless answer discloses something about that client's arrangements to a third party with no relationship to the practice at all.
  • The person asking is usually checking the practice on somebody else's behalf, which means the answer is read by an audit team rather than by a buyer, and it will be set against whatever the client already said.
  • Practices are supervised for anti money laundering purposes and are usually members of a professional body, and everybody involved conflates those facts with information security certifications, so the material has to hold them apart.
  • Bookkeeping frequently lives in a system the client owns and the practice merely holds a user account in, which makes where is the data a question with two answers, and only one of them is the practice's to give.

How it arrives

  • where do you store our bookkeeping data
  • who at your firm can see our ledger
  • do you have a security policy we can see
  • our auditor needs to know about your controls
  • can you complete our supplier questionnaire
  • what happens to our data when one of your staff leaves

What has to be indexed for this to work

Material behind this answer
Your published statement on how client information is heldWhere records sit, who has access, how access is removed when somebody leaves, and what you do about backups. Written to be read by somebody outside the practice, because that is exactly who reads it.
The difference between supervision, membership and certificationWhat the practice is supervised for, which body it belongs to, and what none of that means about information security. Everybody conflates the three, and a page that separates them saves an argument later.
Where the practice is a user rather than the holder of a systemWhich records live in a client's own bookkeeping system and which the practice holds itself. This is the answer that is genuinely different at a practice, and it is worth writing before anybody asks for it.
Who answers a questionnaire, and how long it takesThe named person, what you need from the enquirer first, and whether the client has to authorise the response. A questionnaire answered by whoever opened the email is how a practice makes a statement it cannot support.

The reply

A reply worth copying
Our published statement on how client information is held is on our site and covers where records sit and who has access [1]. Two things I cannot do. I cannot complete a questionnaire, and I cannot say anything about a particular client's records, including whether they are a client at all, because that is theirs rather than ours [2]. Leave me your name, an email and the organisation you are asking on behalf of, and it will go to the person who deals with these.

It gives the published material first so the enquirer leaves with something. It then refuses two distinct things, completing the document and saying anything about a client, and gives the reason for the second, which is the one that would otherwise read as obstruction. Asking who they act for is what lets the practice check with the client before anybody answers.

Where it stops

The trigger. Any request to complete a document, any question about a named client's records, and any question the published statement does not already answer in its own words.

The handover, worded
Questionnaires are answered by a person here rather than from a page, and anything about a specific client has to be checked with that client first. Leave me your name, an email and who you are acting for, and it will be picked up.

It stops answering before it guesses, says who will pick it up, and asks for the one thing that makes a reply possible. Nothing about it reads as a dead end.

Never say this here

Out of bounds

  • Never confirm or deny that a named business is a client of the practice.
  • Never claim a certification, standard or accreditation that is not named in your own published material.
  • Never describe where a particular client's bookkeeping is held or who at the practice can see it.
  • Never present anti money laundering supervision or professional body membership as an information security standard.

Questions

Should the assistant answer these at all?
It should answer the easy half, which is pointing at a published statement, and refuse the rest. That covers most of the volume, and the remainder is precisely where a wrong sentence ends up quoted in somebody else's audit file.
Can it fill in the spreadsheet if the answers are all in our policy?
No. It cannot receive a file, open one or write anything. It reads what you have indexed and replies in the chat, so a document always finishes with a person.
What if the enquirer says the client authorised it?
It should still hand over. It cannot verify a claim like that, and confirming a client relationship on the strength of an assertion in a chat window is itself the disclosure, whatever the questionnaire goes on to ask.

Keep reading

Try it on your own material

Upload a document or point it at your site, paste one line of HTML, then ask it something only your business could answer.