Internal Revenue Code Section 7216 requires a tax return preparer to get the client’s signed consent before disclosing tax return information to a preparer located outside the United States. If the client declines, the firm must not send that return offshore. For 1040-series returns, Revenue Procedure 2013-14 dictates the consent’s exact language and format.
Key takeaways
Section 7216 makes unauthorized disclosure of tax return information a crime: up to a $1,000 fine, up to a year in prison, or both, per violation.
Consent must be signed before any offshore disclosure, and a client who refuses cannot be outsourced.
Rev. Proc. 2013-14 sets the mandatory consent language for 1040-series returns.
A consent that names no duration expires one year after signing.
The consent records who may receive the data. Access controls decide who can actually reach it.
Table of Contents
When does a tax firm need Section 7216 consent for offshore work?
Section 7216 of the Internal Revenue Code requires signed client consent before a preparer discloses tax return information to a preparer located outside the United States. The consent must come first, it cannot be granted after the fact, and a knowing or reckless violation carries up to a $1,000 fine and a year in prison.
The scope is wider than many firm owners expect. Tax return information covers everything a client hands over or the firm derives from it: names, Social Security numbers, income figures, dependents, the return itself. And the rule doesn’t distinguish between a third-party preparation service and the firm’s own overseas office. If the recipient prepares returns and sits outside the United States, the IRS Section 7216 rules require the client’s consent before anything is sent.
Two features of the rule do the real work. Consent must exist before the disclosure, not after; a form signed in April doesn’t cure a file sent in March. And the client holds a veto: a taxpayer who declines to sign cannot have their return sent offshore. The CPA Journal’s analysis of overseas outsourcing treats that veto as the operational starting point: a firm needs a plan for the clients who say no before it signs the outsourcing contract.
What does Rev. Proc. 2013-14 require in the consent form?
For 1040-series returns, Rev. Proc. 2013-14 prescribes the consent’s mandatory statements word for word, along with its format: a separate written document, 12-point type on paper consents, and the taxpayer’s signature and date. A consent that omits the required language or gets signed after the disclosure does not count.
The requirements are specific:
Signed before disclosure. The taxpayer signs and dates the consent before any tax return information leaves the firm. There is no retroactive consent.
A separate written document. On paper, that means 12-point type on 8.5 x 11 inch paper.
Mandatory statements, word for word. Rev. Proc. 2013-14 dictates required language, including a specific statement that must appear when the recipient is a preparer located outside the United States.
A stated duration. A consent that names no time period is effective for one year from the date the taxpayer signs it.
Social Security number handling. A consent can authorize sending an unmasked SSN offshore only when both firms maintain adequate data protection safeguards as the revenue procedure defines them and the consent specifically says so. Otherwise, the SSN must be redacted before the file goes.
A consent that misses these requirements doesn’t count, so build the form once from the revenue procedure’s own text, available through the IRS Section 7216 Information Center, and reuse it.
Why isn’t a signed consent form enough on its own?
Because the consent only records permission. It does not limit anything. IRS Publication 4557 expects firms to restrict client data to the people who need it, so the practical test of a defensible offshore arrangement is whether the firm can name exactly who could reach a given client’s file, and show that the list matches the consent.
The paperwork leaves a gap: a consent names who may receive the client’s data, but says nothing about who can open it. An examiner asks the second question: “Who could actually reach this client’s file?”
IRS Publication 4557 closes the loop. The IRS checklist for safeguarding taxpayer data expects firms to limit access to client data to the people who need it for their jobs. Next to Section 7216, that expectation gets concrete: if 60 clients signed offshore consents and 340 didn’t, the offshore preparers should be able to open 60 files and no others. A shared server login where every user sees every folder can’t honor that split. Neither can a consent binder, however complete.
The consent is the permission; the access list is the proof it was respected.
What does a defensible access setup look like for offshore staffing?
Four controls turn a signed consent into an arrangement the firm can defend: per-user accounts scoped to specific clients, geographic restrictions on where the server accepts logins, multi-factor authentication on every account, and same-day revocation when an engagement ends. Each one answers a question Section 7216 or Publication 4557 raises.
None of these controls is exotic. They’re the access hygienePublication 4557 already expects, pointed at the consent file:
Control
What it does
The question it answers
Per-user accounts, scoped by client
Each offshore preparer signs in under their own name and sees only the clients whose consents cover them
Does access match the consents on file?
Geo-restricted server access
The server accepts logins only from approved locations, so credentials that leak elsewhere don’t work
Could this file be opened from a country the consent never named?
Multi-factor authentication
A stolen password alone can’t open client files
Is the person logging in the person the consent authorized?
Engagement-end revocation
The account is disabled the day the engagement closes
Who can reach this file today, not last season?
One workflow rule sits alongside these controls rather than in the access list: full SSNs go offshore only under the specific authorization Rev. Proc. 2013-14 requires; otherwise they’re redacted before the file leaves.
The first two rows carry the most weight. Per-user scoping is what lets a firm honor a single client’s refusal without unwinding the whole engagement, and geographic restriction is what makes “only our contracted preparers in one location can log in” a system property instead of a policy sentence.
“The firm and I use Verito every day and the security features are great, it is easy to manage.”
Denise M., Owner, RG Taxes LLC · G2, Mar 2025
How does a dedicated private server make offshore consent defensible?
On a dedicated private server, the access rules belong to one firm. VeritSpace hosting starts at $69 per user per month, every plan runs on a single-tenant server with per-user accounts, 2FA, and 256-bit encryption, and the firm sets the access policy, so the login list can mirror the consent file.
On shared infrastructure, the access policy is whatever the platform gives every tenant. A dedicated private server flips that: VeritSpace puts each firm on its own single-tenant server with per-user accounts, 2FA on every login, and 256-bit encryption, in an environment that is SOC 2 Type II and ISO 27001 certified and designed to support IRS Pub 4557 and FTC Safeguards requirements.
Each offshore preparer gets an individual account, and the firm scopes what that account can reach to the clients whose consents cover it. Geographic login restrictions belong in the setup conversation: a firm can ask for its server to accept sessions only from the locations its consents name. When the engagement ends, the firm revokes those accounts, and the answer to “who could reach this client’s file?” shrinks back to the in-house roster.
Pricing is per user, per month: VeritSpace starts at $69, and firms on UltraTax run on the Pro tier from $99. Both plans carry the same access controls; the difference is capacity, not security.
“I have been using Verito for over five years to host our tax software, and it has allowed me to work easily from anywhere.”
Walter M., Owner, The Bottom Line Inc · G2, Oct 2025
What should a firm do when a client refuses consent?
Keep that return in the firm. Section 7216 leaves no workaround: without a signed consent, the return cannot go to a preparer outside the United States, so the firm prepares it with its own staff, documents the refusal, and confirms no offshore account can reach that client’s file.
A refusal is a workflow branch, not a problem to argue with. Section 7216 doesn’t allow sending the return anyway, or consent after the fact, so the return stays with the firm’s own preparers. Document the refusal in the client file, then make sure the offshore accounts can’t reach it. Per-client scoping earns its keep here: the firm leaves that client out of the offshore preparers’ scope, something a shared login can’t do.
The pattern is checkable end to end: consent signed first, access scoped to match it, accounts revoked when the work ends. A firm that can show those three has its answer ready before anyone asks.
Camren Majors is co-founder and Chief Revenue Officer of Verito Technologies, a cloud hosting and managed IT company built exclusively for tax and accounting firms. He is the co-author of Beyond Best Practices: Modernizing the Successful Accounting Firm (2026). His work has been featured in NATP TAXPRO Magazine and he has presented for NATP, NAEA, and NSA.
Verito ranked #1 in 21 G2 reports this summer across Managed Hosting and Cloud Application Hosting. Here is what the verified customer reviews behind those rankings actually say.