Skip to main content
Dig IT Solutions logo

Industry Guides

IT support for accountants: what an accountancy practice actually needs

What UK accountancy firms need from IT support: HMRC agent services, Making Tax Digital, January peaks, IRIS, Sage, Xero and CCH, client data and backup.

By Dig IT SolutionsUpdated 8 September 20267 min read

Short answer

An accountancy practice needs IT support that keeps HMRC agent access, tax and accounts software and client data available and secure through the January and April peaks. That means MFA on every account, a tested backup of practice data, patched and monitored workstations, and a provider who understands IRIS, Sage, Xero, CCH and Making Tax Digital workflows.

Accountants hold the information criminals most want: bank details, payroll data, tax records and the credentials that file returns on behalf of hundreds of clients. They also work to immovable deadlines. This guide explains what an accountancy practice of 5 to 100 people should expect from IT support, and which controls matter most for the sector.

Where accountancy practices are exposed

Three things distinguish an accountancy practice from a typical small office.

Concentration of client data. A single compromised mailbox can expose years of correspondence containing bank details, payroll files and identity documents for every client the fee earner handles.

Agent credentials. HMRC agent services accounts, Government Gateway logins and Companies House authentication codes let staff act for clients. In the wrong hands they enable fraudulent repayment claims and changes to company records.

Deadline concentration. The Self Assessment deadline on 31 January, the tax year end on 5 April, payroll year-end, VAT quarters and the flow of Making Tax Digital submissions mean that an outage on the wrong day costs clients penalties and costs the practice its reputation.

How we support practices is described on our IT support for accountants page. This article is about the standards you should hold any provider to.

HMRC agent services, Government Gateway and access control

Agent credentials deserve the same treatment as the firm's bank login. In practice that means:

  • Individual accounts wherever the service allows. Shared logins make it impossible to know who submitted what, and impossible to remove one person's access without resetting everyone's.
  • Multi-factor authentication on every login, including the practice suite, cloud bookkeeping platforms and the agent services account itself.
  • A password manager, not a spreadsheet or a shared document. This also solves the problem of client Government Gateway details that staff need occasionally.
  • Same-day leaver process. When someone leaves, their Microsoft 365 account, practice software licence, agent access and any client portal logins are removed the same day. Our onboarding and offboarding process exists because this step is so often missed.
  • Conditional access that blocks sign-ins from countries the practice does not operate in and from unmanaged devices.

HMRC publishes guidance for agents on GOV.UK, and it is worth reading what HMRC will and will not do if an agent account is misused.

Making Tax Digital changes the rhythm of the year

Making Tax Digital for Income Tax began mandating sole traders and landlords above the first income threshold from April 2026, with lower thresholds following in later years. For practices the effect is practical rather than technical: more clients on cloud bookkeeping (Xero, QuickBooks, Sage, FreeAgent), quarterly submissions in addition to the annual return, and many more logins to protect.

The IT consequences are:

  • Reliable internet becomes essential. A practice that files everything through the cloud cannot work through a broadband fault. A second line or 4G failover is cheap insurance.
  • Bandwidth and Wi-Fi in the office need to cope with every desk running browser-based software all day.
  • Client permissions inside bookkeeping platforms need reviewing. Staff should see the ledgers they work on, not every client in the practice.

Supporting IRIS, Sage, Xero, CCH and the rest

Most practices run a core suite (IRIS, CCH, Sage, TaxCalc, Digita or BTCSoftware) alongside cloud bookkeeping platforms, a document management system and Microsoft 365. Your IT provider does not need to be a tax expert, but they do need to understand how these products are deployed and where they fail.

Question to askWhy it matters
Where does the practice suite run: local server, vendor-hosted or cloud?Determines who patches it, who backs it up and what happens when the office loses power
How are annual software updates handled?Tax software updates land before filing seasons and often need server work and testing
Who owns vendor tickets?Staff should not be relaying messages between the software vendor and the IT company
How does document management integrate with Outlook and SharePoint?Broken add-ins mean correspondence stops being filed
Can the suite run on managed laptops for remote work?Some older products need a remote desktop server rather than direct installation

An on-premises server is not wrong. Many practices run a well-maintained Windows server with local and cloud backup for years. The mistake is running one that nobody patches, monitors or tests restores from.

A worked example: a twelve-person practice runs IRIS on a five-year-old server, Xero for most bookkeeping clients, Microsoft 365 for email and a document portal. The server is backed up nightly to a local NAS and to the cloud, IRIS updates are applied by the IT provider in early December and early April after testing, and every login, including the agent services account, sits behind MFA. That practice is in a good position. The same practice with the backup job silently failing since March and a shared Government Gateway password on a sticky note is one phishing email away from a very bad January.

Planning for January and April

The busiest weeks of the year are the wrong time to discover a problem. A practical pre-season checklist:

  1. Freeze changes. No server upgrades, migrations or major software changes from mid-December to early February, or in the last two weeks before 5 April.
  2. Test a restore. Restore a real client file from backup and open it. Confirm how long a full server restore would take.
  3. Check capacity. Disk space on the server, mailbox sizes approaching quota, and licences for temporary staff.
  4. Confirm failover. If the internet line fails on 30 January, what happens? Test the 4G backup or the ability to work from home.
  5. Brief staff on phishing. HMRC impersonation emails peak in January. A ten-minute reminder with current examples reduces the risk on the worst possible day.
  6. Agree an escalation path. Everyone should know who to call and what counts as an emergency.

Our managed IT support contracts include monitoring and patching so that most of this happens routinely, but the checklist is useful whoever supports you.

Cloud, remote working and client collaboration

Practices have moved much of their work to the cloud already, often without a plan. The typical result is Microsoft 365 for email, a cloud bookkeeping platform per client, a client portal for document exchange, and a server in the office holding the practice suite and years of files.

The risk in this pattern is identity. When everything is a browser login, the account that signs in is the whole security model. Multi-factor authentication, conditional access and managed devices are the controls that make cloud working safe. A remote worker on an unmanaged home PC with a password saved in the browser undoes the benefit of every other control.

Client portals deserve a mention. Sending accounts and tax returns as email attachments exposes them to interception and mistakes. Portals built into most practice suites, or a properly configured SharePoint client site, give clients a secure place to upload records and approve documents.

Backup, retention and the ransomware question

Ransomware is the incident that closes practices. The defence is layered: patched systems, endpoint detection and response on every machine, email filtering and MFA reduce the chance of infection. Backups determine whether an infection is a bad week or a business-ending event.

The backup design should answer four questions: what is backed up (server data, Microsoft 365, document management), how often, where the copies live (local for fast restores, cloud for site loss, at least one copy offline or immutable), and when a restore was last tested. Microsoft's own documentation at Microsoft Learn is clear that Microsoft 365 provides availability rather than a backup service for your data.

Retention is a separate question. Working papers and client records are kept for the periods your professional body and HMRC require. That is a document management policy, not a backup policy, and the two should not be confused.

The NCSC's small business guide is a good plain-English baseline for the controls above, and Cyber Essentials gives a recognised way to evidence them to clients and insurers.

Choosing IT support for an accountancy practice

The right provider will already support practices running the same software as yours, will own vendor tickets rather than pass them back, and will plan work around your filing calendar without being told. They will also be able to produce the evidence a professional body review or cyber insurance renewal asks for: patching status, MFA coverage, backup test results and access reviews.

Practices considering a change can read our guide to switching IT provider, which covers how to time a handover away from deadlines.

What to do next

If you cannot say with confidence that MFA covers every login in the practice, that a restore has been tested since the last busy season, or that a leaver's agent access is removed the same day, an independent review will tell you where you stand. Book an IT health check and we will report the gaps in order of risk to client data and filing deadlines.

Frequently asked questions

Why is basic break-fix IT support not enough for an accountancy firm?
Break-fix support responds after something has failed. For an accountancy practice the cost of failure is concentrated in a few weeks a year, around 31 January and the April year-end, when a dead server or a locked-out HMRC agent account means missed filings and penalties for clients. Managed support with monitoring, patching and tested backups reduces the chance of failure and shortens recovery when it happens.
What does Making Tax Digital mean for our IT?
Making Tax Digital requires digital record keeping and quarterly submissions through HMRC-recognised software. For a practice this means more clients on cloud bookkeeping platforms, more agent logins to protect, and a steadier stream of filing deadlines instead of one January peak. Your IT needs reliable internet, MFA on every software login, and a clear policy on which staff can access which client ledgers.
Should an accountancy practice move IRIS, Sage or CCH to the cloud?
Most major practice suites now offer hosted or cloud editions. Moving makes sense when your server is ageing, staff work remotely, or you want the vendor to handle patching. Check data export terms, whether the hosted version supports all the modules you use, and how the migration will be timed around filing deadlines. Some practices keep a hybrid setup for a period while they test performance.
How should an accountancy firm protect HMRC agent services logins?
Treat the agent services account and Government Gateway credentials as the most sensitive logins in the firm. Use individual logins rather than shared ones where the service allows, enable multi-factor authentication, store credentials in a password manager rather than a spreadsheet, and remove access on the day a staff member leaves. Log who submits what so you can answer HMRC if a submission is questioned.
What should be backed up in an accountancy practice?
Practice management and tax software data, the document management system, Microsoft 365 mailboxes and SharePoint, and any local shared drives. At least one copy should be offline or immutable so ransomware cannot reach it. Backups should be tested by restoring a real client file, not just by checking the job completed, and the test should be repeated before every busy season.
Do accountants need cyber security training for staff?
Yes. Phishing emails impersonating HMRC, clients or software vendors are the most common way into a practice, and they peak around filing deadlines when staff are busiest. Short, regular sessions using real examples caught by your email filter are more effective than an annual course. Training also supports professional body expectations and most cyber insurance applications.

Next step

Talk to an engineer, not a sales script

Tell us what is not working, or what you are planning, and we will give you a straight view on what it would take to fix.

WhatsApp us