Outsource the processing, keep the authorisation, and write the approval matrix before the first invoice moves, because almost every failed outsourcing arrangement failed on control design rather than on the vendor.
Last verified: 5 September 2026 · Applies to: FY 2025-26 and Tax Year 2026-27
Contents
- The decision, process by process
- The one rule you cannot break
- What has to exist before day one
- The transition, week by week
- SLAs that matter and SLAs that sound good
- Data security and access control
- The compliance calendar the outsourced team must own
- How it interacts with the statutory audit
- Frequently asked questions
- How BVACA can help
The decision, process by process
"Should we outsource accounting" is the wrong question. Accounting is eight or nine distinct processes with different risk profiles, and the right answer differs for each.
| Process | Call | Why |
|---|---|---|
| Transaction processing and book-keeping | Outsource | Volume-driven, rule-driven, no judgement in the routine case |
| Bank and vendor reconciliations | Outsource | A detective control, best done by someone with no stake in the entries |
| Accounts payable: invoice capture, three-way match, payment file preparation | Co-source | Prepare externally, approve internally. Never both outside |
| Payment authorisation and bank release | Keep | This is your money leaving your account. It stays with your authorised signatories |
| Accounts receivable: invoicing, ledger, ageing, dunning | Co-source | Invoicing and ledger outside; credit limits, credit holds and write-offs inside |
| Payroll processing and statutory computation | Outsource | Confidentiality is better protected outside the office, and the rules move often |
| Salary structure, increments, final settlement approvals | Keep | Employment decisions, not accounting |
| GST returns and reconciliation | Outsource | Specialist, deadline-driven, penalty-bearing; needs people who file every month |
| TDS computation, deposit and returns | Outsource | Same reasoning; section selection is the judgement point, and must be documented |
| MIS and management reporting | Co-source | The pack is built outside, the commentary and the decisions are yours |
| Budgeting and forecasting | Keep, with support | Owned by the people accountable for the numbers |
| Master data: vendor and customer creation, bank details changes | Keep | The single highest-fraud-risk field in your system is a vendor bank account |
| Internal controls and approval matrix design | Co-source | Designed jointly, owned by management, never by the processor |
Two patterns run through that table. Anything rule-based and high volume goes out and gets cheaper and more accurate. Anything that authorises money, changes master data or commits the business stays in, however small the task looks.
A third is less obvious: deadline-bearing statutory work benefits most from outsourcing, not because it is cheap but because a specialist team files hundreds of returns a month and knows what the portal is doing this week. An in-house accountant filing one GSTR-3B a month meets the same deadline with far less protection against edge cases.
The one rule you cannot break
Never let one party both prepare a payment and authorise it.
This is segregation of duties, and outsourcing tempts people to break it for convenience: the provider already has the invoice, knows the vendor and has bank access for reconciliation, so why not let them release the payment. Because at that point one party can create a vendor, raise an invoice against it, approve it and pay it, and your only detection mechanism is the annual audit.
The workable structure:
- The provider receives the invoice, matches it to the purchase order and goods receipt, codes it and books it.
- The provider prepares a payment proposal: vendor, invoice reference, amount, due date.
- Your authorised person checks the proposal against the approval matrix and approves it in your banking platform.
- Release uses your credentials, on your device, by someone on your board-approved signatory list.
- The provider reconciles the bank statement afterwards and reports exceptions.
Steps 1, 2 and 5 are the provider's. Steps 3 and 4 are yours, always. The same logic governs master data: vendor bank account creation and amendment must be an internal maker-checker action, with the provider raising a request rather than making the change. Diverted-payment fraud almost always runs through a changed bank account on an existing, trusted vendor.
What has to exist before day one
Providers who start work before these exist are the reason transitions fail. Each is a document with a version number and a named owner.
Chart of accounts. Restructured to your reporting, not inherited from a template, with a written rule for anything ambiguous. If the chart is wrong, every downstream report is wrong and no service level will save it.
Approval matrix. Who approves what, by value band and expense type, and who acts when they are unavailable. One page. Without it the provider ends up asking the founder about every invoice, which is what you were trying to avoid.
Cut-off calendar. The dates by which expense claims, purchase invoices, sales data, payroll inputs and bank statements must reach the provider. A provider cannot deliver a day-5 close on day-9 data.
Access register. Every system, user, access level and business reason, reviewed quarterly. It also makes offboarding a five-minute task rather than a forensic exercise.
Document flow and archive rule. How invoices arrive, where they are stored, who can retrieve them and for how long. Records must stay retrievable by you, including after the relationship ends.
Opening balance sign-off. A reconciled trial balance at the transition date, signed by both sides. Skip it and every later difference becomes an argument about who created it.
The transition, week by week
A realistic transition runs six to eight weeks. Compressing it below four is where the problems come from.
| Week | Work | Output |
|---|---|---|
| 1 | Discovery: process walkthroughs, system review, volume counts, every current filing and due date | As-is process note and risk list |
| 2 | Design: chart of accounts, approval matrix, cut-off calendar, document flow, exception routes | Signed design pack |
| 3 | Access: user creation, portal access, DSC protocol, secure document channel | Access register v1, restricted rights |
| 4 | Opening balances: every control account reconciled, AR and AP ageing, fixed asset register tie-out | Signed opening trial balance |
| 5 | Parallel run against the incumbent team, outputs compared | Variance log, each difference explained |
| 6 | First independent close, incumbent team reviewing rather than doing | First MIS pack on the new calendar |
| 7 to 8 | Stabilisation, SLA baselining, first statutory filings under the new arrangement | Steady-state runbook |
The week 5 parallel run gets cut for cost reasons and should not be. It is the only mechanism that surfaces the undocumented conventions an incumbent accountant has applied for years, and those are invisible until the numbers disagree.
One rule worth stating plainly: do not transition in the two months before a statutory deadline. Starting a handover in September, with the tax audit report and the AGM both due 30 September 2026, means the first close happens under maximum pressure with nothing documented.
SLAs that matter and SLAs that sound good
| SLA that matters | Why | SLA that sounds good |
|---|---|---|
| Books closed and trial balance delivered by day X | The date every other deliverable depends on | "24-hour response time" |
| Bank reconciliations complete for every account by day X | The core detective control | "Dedicated account manager" |
| Statutory return filed at least 2 working days before the due date | Portal outages on the due date are routine | "99.9% accuracy" with no definition of an error |
| Error rate defined, measured and reported monthly, with a rework commitment | Meaningless unless "error" is defined in the contract | "Unlimited support" |
| Named team, with notice and a documented handover before any change | Continuity is the real outsourcing risk | "Experienced professionals" |
| Exception reporting: unmatched items, unapproved entries, ageing breaches, reported not asked for | Turns the provider into a control | "Proactive communication" |
| Data return and deletion on exit, in a defined format | The clause you will be glad of | "Long-term partnership approach" |
Insist on the two-working-day buffer before every statutory due date. It converts a portal outage from a penalty into an inconvenience, and it is the most useful line in the contract.
Data security and access control
The controls that matter, roughly in the order they get breached:
- Individual named logins only. Shared credentials make every access untraceable and offboarding meaningless.
- Least privilege, reviewed quarterly. A processor needs neither administrator rights nor the ability to delete posted entries; keep audit trails enabled.
- DSC custody. A digital signature certificate left with a provider is a live risk to the person whose name is on it. Agree a usage protocol and log every use.
- One defined document channel, not personal email or a consumer chat app carrying salary data and bank details.
- Payroll data to a named team, not a general processing queue.
- Offboarding within 24 hours, recorded on the access register, when a person leaves the provider's team or the engagement ends.
- Confidentiality that survives the engagement, covering employees and subcontractors, with a stated position on where data is hosted.
Ask one question directly: what happens to our data on the day we terminate? A specific answer with a format and a timeline is a good sign; a reassuring one is not.
The compliance calendar the outsourced team must own
Outsourcing does not transfer legal liability. The company and its officers remain answerable for filings; you are buying execution, not indemnity. The tracker is therefore a joint document with dates, owners and a status column.
GST, monthly cycle. GSTR-1 by the 11th of the following month (13th of the month after the quarter under QRMP); GSTR-3B by the 20th (22nd or 24th under QRMP, by state category); GSTR-7 and GSTR-8 by the 10th; CMP-08 by the 18th after the quarter. GSTR-9 and GSTR-9C for FY 2025-26 fall due 31 December 2026: GSTR-9 above ₹2 crore turnover, GSTR-9C above ₹5 crore, self-certified.
Three mechanics an outsourced team must handle without being asked. From the July 2025 tax period the outward supply figures auto-populated into Table 3 of GSTR-3B are non-editable, so corrections run through GSTR-1A filed before the corresponding 3B. The Invoice Management System has been live since 1 October 2024 and inaction is deemed acceptance at GSTR-2B generation, so supplier documents are actioned monthly, not reviewed at year end. And returns cannot be filed more than three years after their original due date, a bar GSTN operationalised from the 1 August 2025 tax period with no condonation mechanism; see the three-year bar on GST returns. Where e-invoicing applies, the ₹5 crore aggregate turnover threshold is sticky once crossed in any year from 2017-18 onward, and the 30-day reporting limit applies only at ₹10 crore and above.
TDS. Deposit by the 7th of the following month, and 30 April for March deductions. Quarterly returns for Tax Year 2026-27 on 31 July, 31 October, 31 January and 31 May, on Forms 138, 140, 144 and 143 (the successors from 1 April 2026 to Forms 24Q, 26Q, 27Q and 27EQ).
ROC and MCA, FY 2025-26. AGM by 30 September 2026; AOC-4 within 30 days of the AGM, around 30 October 2026; MGT-7 or MGT-7A within 60 days, around 29 November 2026; ADT-1 within 15 days of the AGM; MSME-1 on 30 April and 31 October. The late fee on AOC-4 and MGT-7 is ₹100 per day with no cap, which is why these belong on a tracker and not in someone's memory. DIR-3 KYC is no longer annual: under Rule 12A as amended with effect from 31 March 2026, DIN holders file once every three consecutive financial years, so a director who filed for FY 2025-26 is next due 30 June 2028. DPT-3 is due 30 June, extended to 31 July 2026 for FY 2025-26 by General Circular 02/2026. Detail in the ROC annual filing calendar.
Income tax, current season. The tax audit report on Form 3CA or 3CB with 3CD is due 30 September 2026 and the audit-case ITR on 31 October 2026, with no CBDT extension announced as at 5 September 2026.
How it interacts with the statutory audit
A well-run outsourced function makes the audit shorter, because the auditor's first requests are reconciliations, scrutiny schedules and supporting documents, and a disciplined monthly process produces those as a by-product. Three boundaries to hold.
Independence. Your statutory auditor should not be the firm keeping your books. Appoint separate firms and keep the separation clean from the first year, because unpicking it later means changing auditor at an inconvenient moment. Section 144 of the Companies Act, 2013 prohibits the statutory auditor from providing accounting and book-keeping services (among other listed services) to the company or its holding / subsidiary. That is the statutory anchor for the independence rule — appoint separate firms.
Management responsibility. The financial statements are management's, not the provider's and not the auditor's. Someone inside your business must be able to explain the judgements: provisioning, revenue cut-off, capitalisation, related-party disclosure. If nobody in-house can do that, you have outsourced too far up the stack and need the virtual CFO layer above the accounting team.
Audit readiness as a deliverable. Write it into the contract: a year-end file of reconciled control accounts, ageing schedules, the fixed asset register with additions and disposals, statutory dues reconciliations, related-party schedules and confirmations. Agreed in advance it costs the provider a week; requested in October it costs everyone a month.
Illustrative example. A company with ₹60 crore turnover, two GSTINs and 120 employees moves book-keeping, AP processing, payroll and GST filing outside, and keeps payment authorisation, vendor master data, credit decisions and budgeting in-house. Two internal roles remain: a finance manager who approves and reviews, and an authorised signatory who releases payments. The measurable outcome is not headcount but timing: the close moves from day 22 to day 6, and the statutory audit begins with reconciliations already prepared rather than requested.
Frequently asked questions
What should a small business outsource first?
Book-keeping and reconciliations, then GST and TDS compliance, then payroll: rule-based, deadline-bearing, volume-driven. Keep payment authorisation, vendor master data and credit decisions in-house from day one whatever your size, because those are the controls that prevent loss. Allow six to eight weeks for a full transition, and never start one in the two months before a major deadline.
Is it safe to outsource accounts payable?
Yes, if you split it. Invoice capture, matching, coding and payment file preparation can sit outside. Approval against the matrix and release from the bank must stay with your authorised signatories, and vendor bank account changes must be an internal maker-checker action. Outsourcing preparation is efficiency; outsourcing authorisation is exposure.
Who is liable if the outsourced provider misses a GST return?
The registered person and its officers remain liable for the filing, the late fee and the interest. A contract can allocate commercial responsibility, but it does not move the statutory obligation. That is why the two-working-day buffer and a shared due-date tracker matter more than an indemnity clause.
Can our statutory auditor also do our book-keeping?
Treat these as separate firms. Preparing the records and forming an independent opinion on them are incompatible roles, and the separation is far easier to establish at the start than to fix later. Section 144 of the Companies Act, 2013 prohibits the statutory auditor from providing accounting and book-keeping services (among other listed services) to the company or its holding / subsidiary. That is the statutory anchor for the independence rule — appoint separate firms.
What happens to our data if we end the engagement?
Contract it before you start: a full data return in a defined usable format, the document archive, all working papers, confirmation of deletion from the provider's systems, and revocation of every access on the register. Ask for specifics in writing at proposal stage, not at termination.
How BVACA can help
We run outsourced accounting, payroll and compliance for businesses across Panchkula, Chandigarh, Mohali and pan-India, scoped around the process split in the table above rather than taking the whole function by default. A transition starts with a written as-is process note, a signed approval matrix and a reconciled opening trial balance before any live processing begins, and statutory work including GST return filing and reconciliation is filed against a shared tracker with a working-day buffer ahead of each due date. Where a business also needs the layer above the accounting team, we run that as a separate CFO engagement so reporting and processing never sit in the same pair of hands. Fees are scoped to volume and entity count and quoted against a written scope.
Book a consultation · WhatsApp
Author box: CA Vijender Singh Bachhal, Managing Partner, Bachhal Vijender & Associates (FRN 028355N), Panchkula. About the firm
Disclaimer: This article is general information current as at 5 September 2026, not advice for a specific situation. Tax and corporate law in India changed materially on 1 April 2026; verify the position before acting. Illustrative examples are not client matters.
Talk to a CA about this
Every situation has its own facts. A short call establishes what applies to you and what it will cost — before anything is commissioned.
Stay Updated on Tax & Compliance
Get expert insights, deadline reminders, and practical guides delivered to your inbox every week.