Key takeaway: Before sending tax records, verify who requested them, why they are needed and the exact transfer channel. Use individual account access, send the requested records through the agreed protected method, and retain a submission record. Independently verify changes to a portal, recipient or payment instruction.
Tax files can contain Social Security numbers, bank details, payroll information and complete financial histories. A useful checklist helps you provide enough information for the work without scattering unnecessary copies across email, devices and shared folders.

Verify the request before opening the upload link
A familiar display name or an existing email thread does not prove that a request is authentic. An attacker can impersonate a firm or compromise an account. For an unexpected request or changed instructions, contact the firm using a number or channel already known to you, independently of the suspicious message. Do not verify by replying to that message or calling the number supplied in it. CISA’s phishing guidance recommends this independent contact approach.
Confirm the portal’s exact address and the intended recipient or account. Open a trusted bookmark or navigate through a previously verified route. A padlock or HTTPS connection protects a connection but does not establish that the destination belongs to your CPA. Stop and verify if the page unexpectedly asks for a different account, software installation or payment details.
Confirm protection and access, not just firm approval
A method is not automatically secure merely because someone claiming to be the CPA requests it. Ask how access is authenticated, who can view the documents, how the files are protected during transfer and storage, and how mistaken submissions are handled. A filename, PDF format or password prompt alone does not answer those questions.
IRS Publication 4557, Safeguarding Taxpayer Data, recommends protecting sensitive transmissions and using individual passwords and multifactor authentication. Keep full returns, identifiers and banking records out of ordinary unprotected email and general contact forms. Use the verified protected portal or other specifically agreed encrypted-transfer process. Do not send a decryption password alongside the encrypted file through the same exposed channel.
The FTC Safeguards Rule guidance identifies tax-preparation firms among covered financial institutions and explains information-security safeguards, including access controls and multifactor authentication requirements. Those requirements describe obligations; citing them does not prove that a particular firm’s systems have been independently tested or certified. Ask for an explanation of the actual process relevant to your engagement.
Prepare records around the business need
Confirm the requested entities, tax years and accounting periods. The following table is a preparation guide, not a demand to send every listed document. At an initial inquiry, a short description of the issue and deadline is usually enough to start scoping the work.
| Business need | Records to discuss with the CPA |
|---|---|
| Initial consultation | Business question, relevant deadline, entity context and available records. |
| Tax-return preparation | Prior returns, current books, supporting statements, owner information and payment records requested for the relevant returns. |
| Tax planning | Proposed transaction, timing, assumptions, projected income and cash, and prior payments. |
| Bookkeeping or QuickBooks work | Period to review, reports, reconciliations, source documents and any agreed account access. |
| Entity or ownership change | Existing structure, proposed change, ownership records and relevant agreements; identify any attorney involved. |
| Tax notice or representation | Complete notice, response deadline, relevant filed return and requested supporting evidence. |
Ask which formats are useful. A complete, readable PDF may work for a notice; a transaction analysis may need a structured export. Include all requested pages and schedules, identify draft versus final versions, and avoid putting full identifiers in filenames or subject lines. Confirm any redaction with the CPA so necessary tax information is not removed inadvertently.
Invite the accountant instead of sharing credentials
For QuickBooks Online, an authorized primary or company administrator can use the accountant invitation process documented by Intuit. Independently verify the accountant’s email address or firm ID before sending the invitation. Accountant access includes tools to inspect and correct the books, so confirm that this access fits the engagement.
Do not share your personal password, MFA code, recovery code or generic bank login, even through a protected upload. Use supported individual access and the minimum permissions appropriate to the work. If reports alone meet the need, discuss that option. Review access when the work ends or staffing changes; do not leave a former service provider connected indefinitely without a continuing purpose.
QuickBooks Desktop uses a different file and user workflow. Confirm the product, version and requested accountant-copy or backup procedure rather than assuming an Online invitation transfers a Desktop file. Sharing a report also is not the same as providing a restorable company backup.
Use one pre-send and follow-up checklist
- Confirm scope. Identify the entity, period, deliverable, deadline and responsible person.
- Verify the destination. Check the requester and any changed instructions through a known independent channel.
- Prepare the requested set. Confirm formats, completeness and version; list missing items.
- Check access. Use individual accounts and agreed permissions; keep passwords and authentication codes private.
- Submit through the verified protected process. Check the destination folder or client account before transferring.
- Retain confirmation. Keep a dated list of filenames and the submission receipt without duplicating sensitive contents unnecessarily.
- Resolve follow-up items. Confirm missing documents, next steps and who owns approaching deadlines.
An upload receipt confirms a transfer, not completion of the engagement, review of every file or filing of a return. Obtain the relevant review and filing confirmation when those steps occur. Keep your own required records; a firm’s portal is not automatically your permanent archive.
Handle mistakes and urgent notices promptly
If you send a file to the wrong recipient or notice suspicious account access, promptly contact the firm and the business’s IT or security contact through verified channels. Preserve the message and relevant details, and have qualified support assess access restriction, credential protection and notification obligations. Do not assume deleting your local copy or recalling an email removes every received copy. IRS Publication 4557 provides further guidance for tax professionals responding to data loss.
For an approaching tax deadline, communicate the date immediately without placing full taxpayer identifiers in the initial message. Confirm whether the firm has accepted responsibility for a response or filing. A request for a consultation or an uploaded notice does not extend the deadline or establish representation by itself.
Confirm the firm’s process and engagement
Contact CPA Firm South Florida with a brief description of the service needed and any deadline. Request the current document-transfer instructions before sending sensitive records. Confirm recipients, access, expected follow-up and the agreed service scope directly with the firm.
The firm’s pricing page distinguishes standard return preparation from separately scoped work such as ongoing bookkeeping, payroll, sales-tax returns, tax planning and representation. Record condition can affect the preparation quote. The engagement should identify the work, fee and responsibilities rather than leaving them to assumptions about what a document upload includes.
Frequently asked questions
Should I send a complete tax file with my first inquiry?
Start with a brief description of the business question, affected period and deadline. Confirm the engagement, requested records and verified transfer channel before sending sensitive files.
Should I give my CPA my QuickBooks password or authentication code?
No. For QuickBooks Online, use an authorized accountant invitation to the independently verified firm account when that access is appropriate. Each user should sign in with their own credentials and authentication factors.
What if I have only some of the requested records?
Identify what is available and what is missing, then agree on a partial submission if useful. Label it clearly and keep a dated list of outstanding items. Upload confirmation does not mean the records are complete or reviewed.
Does requesting help extend a tax-notice deadline?
No. State the deadline immediately and confirm who is responsible for the response. A consultation request, document upload or pending engagement does not itself extend a filing, response or appeal deadline.