United Kingdom / Guides / Outsourcing bookkeeping as a UK company: what to check
United Kingdom · guideOutsourcing bookkeeping as a UK company: what to check
The short answer
Yes, a UK company can lawfully outsource its bookkeeping to a provider based anywhere, in the UK or abroad — there is no rule requiring a company to keep transaction recording in-house or inside a particular country. Before appointing one, three things are worth checking rather than assuming: whether any UK-facing accountancy service provider in the arrangement is registered for anti-money laundering (AML) supervision under the Money Laundering Regulations 2017, whether personal data leaving the UK is covered by a recognised UK GDPR transfer mechanism, and who actually holds the login credentials to the company's banking, accounting and payroll systems. None of these checks turn on where the provider is physically located — they turn on what the provider is being asked to do and how the data is handled.
Key facts — verified dates on each
Outsourcing itself is not restricted
UK law does not reserve bookkeeping to a licensed or regulated person. Recording transactions, reconciling bank feeds, coding expenses to a chart of accounts, running payroll data entry and producing management reports are ordinary commercial activities, and nothing in company law or tax law requires the person performing them to hold a professional qualification, be a member of a UK accountancy body, or work from a UK address. A company is free to move that work to an external provider — in-house, UK-based, or offshore — the same way it is free to outsource payroll processing, IT support or any other back-office function.
What changes with outsourcing is not the legality of the activity but the questions worth asking of whoever is doing it. Those questions cluster around three areas: whether a regulated activity sits anywhere in the engagement and, if so, whether the entity performing it is properly supervised; whether personal data is moving across a border in a way UK data protection law recognises; and who controls the systems the data lives in day to day.
Check one: anti-money laundering supervision
The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 set out who counts as a "relevant person" subject to AML supervision. Regulation 8 includes, among other categories, external accountants and tax advisers — a firm or sole practitioner that, by way of business, provides accountancy services or tax advice to other people. A business falling into that category has to register with a supervisory authority, most commonly HMRC or a recognised accountancy body, and is breaking the law if it carries on that activity unsupervised.
The practical point for a company appointing a bookkeeping provider is to work out which parts of the engagement, if any, amount to providing accountancy services by way of business to UK clients, and whether the entity performing those parts is registered. For a dedicated bookkeeping or accountancy provider, registration turns on whether the activity is being carried on by way of business, not on how large the firm is — there is no general size or turnover exemption. (HMRC does recognise one narrow carve-out for a "virtual assistant" whose accountancy work is incidental to an unrelated main business under £30,000 turnover, with accountancy services capped at 5% of that turnover — a fact pattern that does not describe an outsourced bookkeeping provider.) A company can ask a prospective provider directly which supervisory body it is registered with, and HMRC publishes a Supervised Business Register precisely so that status can be checked rather than taken on trust.
This check sits alongside, not instead of, the ordinary question of who is actually preparing and filing the company's statutory accounts, Corporation Tax return, VAT returns or payroll submissions. Those filing functions carry their own qualification and agent-authorisation considerations that are separate from AML supervision, and a company should still confirm who is doing that work and on what basis, independent of whatever bookkeeping arrangement sits underneath it.
Check two: a lawful mechanism for moving data across a border
If a bookkeeping provider is based outside the UK, some personal data — employee names in a payroll file, a director's bank details, a customer's invoice address — is likely to move with the engagement. UK GDPR does not prohibit that, but it does require a company making what the law calls a "restricted transfer" of personal data to a country outside the UK to have an appropriate safeguard in place, unless an exception applies.
The Information Commissioner's Office (ICO) sets out the safeguards a UK organisation can rely on for a restricted transfer, including the UK International Data Transfer Agreement (IDTA) and the UK Addendum to the EU's Standard Contractual Clauses — both mechanisms a company and an overseas provider can put in place through their contract. The check worth making before data starts moving is not "is this provider trustworthy" in the abstract, but "does a recognised transfer mechanism exist between us and this provider, and is it actually in the contract" — a specific, verifiable fact rather than a general impression.
This mechanism requirement applies regardless of whether the provider is a large firm or a single practitioner, and regardless of which country it operates from. A company that has never asked an existing offshore or overseas provider this question has an open question to close, not necessarily a problem — the fix, where a mechanism is missing, is putting one in place through the contract rather than assuming informal assurances are sufficient.
Check three: who holds the keys
The AML and data-transfer questions above are legal checks. This one is operational, and it matters just as much in practice: who controls the credentials to the company's accounting software, business bank feeds and payroll system once a provider is engaged. This is not something UK law standardises for bookkeeping specifically, which is exactly why it is worth asking a provider directly rather than assuming a sensible default.
Reasonable practice, applicable to any provider regardless of location, includes individually attributable logins rather than one shared password across a provider's staff, access limited to the people actually working on the file at any given time, multi-factor authentication where the software supports it, and prompt removal of access when someone leaves the engagement or the provider's team changes. A company that has granted broad, shared, long-lived access to a provider it can no longer clearly account for has created an exposure that has nothing to do with whether the provider is AML-supervised or has a data-transfer mechanism in place — it is a separate, purely practical gap worth closing on its own terms.
Putting the three checks together
None of the three checks above depend on each other, and a provider can pass one while failing another — a well-supervised UK firm can still have poor access controls, and an overseas provider with a solid data-transfer agreement and tight access controls can still be outside AML supervision if it is performing regulated accountancy services. Treating them as three separate, specific questions, rather than one general impression of whether a provider "seems reliable," is what actually lets a company verify rather than assume.
- Which supervisory authority is any UK-facing accountancy service provider in the arrangement registered with under the Money Laundering Regulations 2017, and can that registration be checked
- Where personal data leaves the UK, is a recognised UK GDPR transfer mechanism — the IDTA or the UK Addendum to the EU SCCs — actually documented in the contract
- Who holds login credentials to the company's accounting software, banking feeds and payroll system, and are those credentials individually attributable
- What access controls apply, and how quickly is access removed when someone leaves the engagement
- Which specific person or firm is preparing and filing statutory accounts, Corporation Tax and VAT returns, and on what qualification or agent-authorisation basis — a separate question from bookkeeping and from AML supervision
The figures, and when we checked them
These numbers change by year or by notification. Each one shows the date we last verified it against the source — if that date looks old, check the source before relying on it.
Questions on this
Is it legal for a UK company to outsource its bookkeeping?
Yes. Bookkeeping — recording transactions, reconciling accounts, processing payroll data, preparing reports — is not a restricted activity under UK law, and there is no requirement that it be performed in-house, by a qualified accountant, or by a UK-based provider.
Does a bookkeeper need to be a member of ICAEW, ACCA or another accountancy body?
No general law requires it for bookkeeping itself. Membership of a UK accountancy body is separate from AML supervision, though several of those bodies also act as AML supervisors for their members, which is one route (not the only one) to being properly supervised.
What is AML supervision and why does it matter for outsourced bookkeeping?
The Money Laundering Regulations 2017 require firms providing accountancy services by way of business to be supervised by a recognised body, most commonly HMRC or a professional accountancy body. It matters because operating unsupervised in that category is unlawful for the firm doing it — a fact worth confirming rather than assuming when appointing a provider.
Does outsourcing bookkeeping to an offshore provider automatically breach UK GDPR?
No. UK GDPR permits transferring personal data outside the UK where an appropriate safeguard is in place, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. The requirement is that a recognised mechanism exists and is documented, not that the transfer is prohibited outright.
What is the difference between the IDTA and the UK Addendum?
The IDTA is a standalone UK agreement covering a restricted transfer on its own. The UK Addendum attaches to the EU's Standard Contractual Clauses and is often used where a provider already has EU SCCs in place, so the two together cover both EU and UK transfer obligations without duplicating agreements.
Does the size of a bookkeeping provider affect whether it needs AML supervision?
Generally no. The Money Laundering Regulations 2017 apply based on the activity being carried on by way of business, not on the size, turnover or headcount of the firm performing it, so a sole practitioner providing accountancy services is covered on the same basis as a large firm. HMRC recognises one narrow exception for a "virtual assistant" doing incidental accountancy work under £30,000 total turnover — a fact pattern that does not describe a dedicated bookkeeping provider.
Who should control login credentials to accounting software when bookkeeping is outsourced?
UK law does not standardise this, so it is a question to put to a provider directly. Reasonable practice is individually attributable logins rather than one shared password, access limited to people actively working on the file, and prompt removal of access when someone leaves the engagement.
Is outsourced bookkeeping the same as filing statutory accounts or tax returns?
No. Bookkeeping produces the underlying records; filing statutory accounts, Corporation Tax returns and VAT returns is a separate function with its own qualification and agent-authorisation questions. Outsourcing one does not answer who is responsible for the other.
How can a company check whether a provider is registered for AML supervision?
By asking the provider directly which supervisory authority it is registered with, and by using HMRC's registration service, which exists so that a firm's money laundering supervision status can be checked rather than taken on trust.
Does CapEasy provide bookkeeping services in the UK?
Not currently. CapEasy serves the United States and Australia today; UK services are under consideration but not offered, and this guide is provided as general orientation for a company choosing any bookkeeping provider, not a description of a CapEasy UK service.
Primary sources
- legislation.gov.uk — Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, regulation 8 (Relevant persons)
- GOV.UK — Register or update your money laundering supervision with HMRC
- GOV.UK — Anti-money laundering registration
- ICO — International transfers guidance
- ICO — A guide to international transfers (safeguards including the IDTA and UK Addendum)
Last reviewed 2026-08-14. Statutes and schedules change — the sources above are authoritative, this page is orientation.
This page is information, not an offer of services. CapEasy serves the US and Australia today; UK services are under consideration.