Industry Guides
IT support for accountants: what an accountancy practice actually needs
What UK accountancy firms need from IT support: HMRC agent services, Making Tax Digital, January peaks, IRIS, Sage, Xero and CCH, client data and backup.
By Dig IT SolutionsUpdated 8 September 20267 min read
Short answer
An accountancy practice needs IT support that keeps HMRC agent access, tax and accounts software and client data available and secure through the January and April peaks. That means MFA on every account, a tested backup of practice data, patched and monitored workstations, and a provider who understands IRIS, Sage, Xero, CCH and Making Tax Digital workflows.
Accountants hold the information criminals most want: bank details, payroll data, tax records and the credentials that file returns on behalf of hundreds of clients. They also work to immovable deadlines. This guide explains what an accountancy practice of 5 to 100 people should expect from IT support, and which controls matter most for the sector.
Where accountancy practices are exposed
Three things distinguish an accountancy practice from a typical small office.
Concentration of client data. A single compromised mailbox can expose years of correspondence containing bank details, payroll files and identity documents for every client the fee earner handles.
Agent credentials. HMRC agent services accounts, Government Gateway logins and Companies House authentication codes let staff act for clients. In the wrong hands they enable fraudulent repayment claims and changes to company records.
Deadline concentration. The Self Assessment deadline on 31 January, the tax year end on 5 April, payroll year-end, VAT quarters and the flow of Making Tax Digital submissions mean that an outage on the wrong day costs clients penalties and costs the practice its reputation.
How we support practices is described on our IT support for accountants page. This article is about the standards you should hold any provider to.
HMRC agent services, Government Gateway and access control
Agent credentials deserve the same treatment as the firm's bank login. In practice that means:
- Individual accounts wherever the service allows. Shared logins make it impossible to know who submitted what, and impossible to remove one person's access without resetting everyone's.
- Multi-factor authentication on every login, including the practice suite, cloud bookkeeping platforms and the agent services account itself.
- A password manager, not a spreadsheet or a shared document. This also solves the problem of client Government Gateway details that staff need occasionally.
- Same-day leaver process. When someone leaves, their Microsoft 365 account, practice software licence, agent access and any client portal logins are removed the same day. Our onboarding and offboarding process exists because this step is so often missed.
- Conditional access that blocks sign-ins from countries the practice does not operate in and from unmanaged devices.
HMRC publishes guidance for agents on GOV.UK, and it is worth reading what HMRC will and will not do if an agent account is misused.
Making Tax Digital changes the rhythm of the year
Making Tax Digital for Income Tax began mandating sole traders and landlords above the first income threshold from April 2026, with lower thresholds following in later years. For practices the effect is practical rather than technical: more clients on cloud bookkeeping (Xero, QuickBooks, Sage, FreeAgent), quarterly submissions in addition to the annual return, and many more logins to protect.
The IT consequences are:
- Reliable internet becomes essential. A practice that files everything through the cloud cannot work through a broadband fault. A second line or 4G failover is cheap insurance.
- Bandwidth and Wi-Fi in the office need to cope with every desk running browser-based software all day.
- Client permissions inside bookkeeping platforms need reviewing. Staff should see the ledgers they work on, not every client in the practice.
Supporting IRIS, Sage, Xero, CCH and the rest
Most practices run a core suite (IRIS, CCH, Sage, TaxCalc, Digita or BTCSoftware) alongside cloud bookkeeping platforms, a document management system and Microsoft 365. Your IT provider does not need to be a tax expert, but they do need to understand how these products are deployed and where they fail.
| Question to ask | Why it matters |
|---|---|
| Where does the practice suite run: local server, vendor-hosted or cloud? | Determines who patches it, who backs it up and what happens when the office loses power |
| How are annual software updates handled? | Tax software updates land before filing seasons and often need server work and testing |
| Who owns vendor tickets? | Staff should not be relaying messages between the software vendor and the IT company |
| How does document management integrate with Outlook and SharePoint? | Broken add-ins mean correspondence stops being filed |
| Can the suite run on managed laptops for remote work? | Some older products need a remote desktop server rather than direct installation |
An on-premises server is not wrong. Many practices run a well-maintained Windows server with local and cloud backup for years. The mistake is running one that nobody patches, monitors or tests restores from.
A worked example: a twelve-person practice runs IRIS on a five-year-old server, Xero for most bookkeeping clients, Microsoft 365 for email and a document portal. The server is backed up nightly to a local NAS and to the cloud, IRIS updates are applied by the IT provider in early December and early April after testing, and every login, including the agent services account, sits behind MFA. That practice is in a good position. The same practice with the backup job silently failing since March and a shared Government Gateway password on a sticky note is one phishing email away from a very bad January.
Planning for January and April
The busiest weeks of the year are the wrong time to discover a problem. A practical pre-season checklist:
- Freeze changes. No server upgrades, migrations or major software changes from mid-December to early February, or in the last two weeks before 5 April.
- Test a restore. Restore a real client file from backup and open it. Confirm how long a full server restore would take.
- Check capacity. Disk space on the server, mailbox sizes approaching quota, and licences for temporary staff.
- Confirm failover. If the internet line fails on 30 January, what happens? Test the 4G backup or the ability to work from home.
- Brief staff on phishing. HMRC impersonation emails peak in January. A ten-minute reminder with current examples reduces the risk on the worst possible day.
- Agree an escalation path. Everyone should know who to call and what counts as an emergency.
Our managed IT support contracts include monitoring and patching so that most of this happens routinely, but the checklist is useful whoever supports you.
Cloud, remote working and client collaboration
Practices have moved much of their work to the cloud already, often without a plan. The typical result is Microsoft 365 for email, a cloud bookkeeping platform per client, a client portal for document exchange, and a server in the office holding the practice suite and years of files.
The risk in this pattern is identity. When everything is a browser login, the account that signs in is the whole security model. Multi-factor authentication, conditional access and managed devices are the controls that make cloud working safe. A remote worker on an unmanaged home PC with a password saved in the browser undoes the benefit of every other control.
Client portals deserve a mention. Sending accounts and tax returns as email attachments exposes them to interception and mistakes. Portals built into most practice suites, or a properly configured SharePoint client site, give clients a secure place to upload records and approve documents.
Backup, retention and the ransomware question
Ransomware is the incident that closes practices. The defence is layered: patched systems, endpoint detection and response on every machine, email filtering and MFA reduce the chance of infection. Backups determine whether an infection is a bad week or a business-ending event.
The backup design should answer four questions: what is backed up (server data, Microsoft 365, document management), how often, where the copies live (local for fast restores, cloud for site loss, at least one copy offline or immutable), and when a restore was last tested. Microsoft's own documentation at Microsoft Learn is clear that Microsoft 365 provides availability rather than a backup service for your data.
Retention is a separate question. Working papers and client records are kept for the periods your professional body and HMRC require. That is a document management policy, not a backup policy, and the two should not be confused.
The NCSC's small business guide is a good plain-English baseline for the controls above, and Cyber Essentials gives a recognised way to evidence them to clients and insurers.
Choosing IT support for an accountancy practice
The right provider will already support practices running the same software as yours, will own vendor tickets rather than pass them back, and will plan work around your filing calendar without being told. They will also be able to produce the evidence a professional body review or cyber insurance renewal asks for: patching status, MFA coverage, backup test results and access reviews.
Practices considering a change can read our guide to switching IT provider, which covers how to time a handover away from deadlines.
What to do next
If you cannot say with confidence that MFA covers every login in the practice, that a restore has been tested since the last busy season, or that a leaver's agent access is removed the same day, an independent review will tell you where you stand. Book an IT health check and we will report the gaps in order of risk to client data and filing deadlines.

