United Kingdom / Guides / Outsourcing bookkeeping as a UK company: what to check

United Kingdom · guide

Outsourcing bookkeeping as a UK company: what to check

Updated 2026-08-14 · 9-min read · 5 primary sources

The short answer

Yes, a UK company can lawfully outsource its bookkeeping to a provider based anywhere, in the UK or abroad — there is no rule requiring a company to keep transaction recording in-house or inside a particular country. Before appointing one, three things are worth checking rather than assuming: whether any UK-facing accountancy service provider in the arrangement is registered for anti-money laundering (AML) supervision under the Money Laundering Regulations 2017, whether personal data leaving the UK is covered by a recognised UK GDPR transfer mechanism, and who actually holds the login credentials to the company's banking, accounting and payroll systems. None of these checks turn on where the provider is physically located — they turn on what the provider is being asked to do and how the data is handled.

Key facts — verified dates on each

AML supervision threshold for accountancy service providersNo general size or turnover exemption for a dedicated bookkeeping or accountancy provider. Any firm or sole practitioner providing accountancy services or tax advice to other persons by way of business is a "relevant person" under regulation 8 of the Money Laundering Regulations 2017 and must be registered with a supervisory authority. (A single narrow HMRC carve-out exists for incidental accountancy work by a "virtual assistant" under £30,000 total turnover — not applicable to an outsourced bookkeeping engagement.) · 2026-08-14

Outsourcing itself is not restricted

UK law does not reserve bookkeeping to a licensed or regulated person. Recording transactions, reconciling bank feeds, coding expenses to a chart of accounts, running payroll data entry and producing management reports are ordinary commercial activities, and nothing in company law or tax law requires the person performing them to hold a professional qualification, be a member of a UK accountancy body, or work from a UK address. A company is free to move that work to an external provider — in-house, UK-based, or offshore — the same way it is free to outsource payroll processing, IT support or any other back-office function.

What changes with outsourcing is not the legality of the activity but the questions worth asking of whoever is doing it. Those questions cluster around three areas: whether a regulated activity sits anywhere in the engagement and, if so, whether the entity performing it is properly supervised; whether personal data is moving across a border in a way UK data protection law recognises; and who controls the systems the data lives in day to day.

Check one: anti-money laundering supervision

The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 set out who counts as a "relevant person" subject to AML supervision. Regulation 8 includes, among other categories, external accountants and tax advisers — a firm or sole practitioner that, by way of business, provides accountancy services or tax advice to other people. A business falling into that category has to register with a supervisory authority, most commonly HMRC or a recognised accountancy body, and is breaking the law if it carries on that activity unsupervised.

The practical point for a company appointing a bookkeeping provider is to work out which parts of the engagement, if any, amount to providing accountancy services by way of business to UK clients, and whether the entity performing those parts is registered. For a dedicated bookkeeping or accountancy provider, registration turns on whether the activity is being carried on by way of business, not on how large the firm is — there is no general size or turnover exemption. (HMRC does recognise one narrow carve-out for a "virtual assistant" whose accountancy work is incidental to an unrelated main business under £30,000 turnover, with accountancy services capped at 5% of that turnover — a fact pattern that does not describe an outsourced bookkeeping provider.) A company can ask a prospective provider directly which supervisory body it is registered with, and HMRC publishes a Supervised Business Register precisely so that status can be checked rather than taken on trust.

This check sits alongside, not instead of, the ordinary question of who is actually preparing and filing the company's statutory accounts, Corporation Tax return, VAT returns or payroll submissions. Those filing functions carry their own qualification and agent-authorisation considerations that are separate from AML supervision, and a company should still confirm who is doing that work and on what basis, independent of whatever bookkeeping arrangement sits underneath it.

Check two: a lawful mechanism for moving data across a border

If a bookkeeping provider is based outside the UK, some personal data — employee names in a payroll file, a director's bank details, a customer's invoice address — is likely to move with the engagement. UK GDPR does not prohibit that, but it does require a company making what the law calls a "restricted transfer" of personal data to a country outside the UK to have an appropriate safeguard in place, unless an exception applies.

The Information Commissioner's Office (ICO) sets out the safeguards a UK organisation can rely on for a restricted transfer, including the UK International Data Transfer Agreement (IDTA) and the UK Addendum to the EU's Standard Contractual Clauses — both mechanisms a company and an overseas provider can put in place through their contract. The check worth making before data starts moving is not "is this provider trustworthy" in the abstract, but "does a recognised transfer mechanism exist between us and this provider, and is it actually in the contract" — a specific, verifiable fact rather than a general impression.

This mechanism requirement applies regardless of whether the provider is a large firm or a single practitioner, and regardless of which country it operates from. A company that has never asked an existing offshore or overseas provider this question has an open question to close, not necessarily a problem — the fix, where a mechanism is missing, is putting one in place through the contract rather than assuming informal assurances are sufficient.

Check three: who holds the keys

The AML and data-transfer questions above are legal checks. This one is operational, and it matters just as much in practice: who controls the credentials to the company's accounting software, business bank feeds and payroll system once a provider is engaged. This is not something UK law standardises for bookkeeping specifically, which is exactly why it is worth asking a provider directly rather than assuming a sensible default.

Reasonable practice, applicable to any provider regardless of location, includes individually attributable logins rather than one shared password across a provider's staff, access limited to the people actually working on the file at any given time, multi-factor authentication where the software supports it, and prompt removal of access when someone leaves the engagement or the provider's team changes. A company that has granted broad, shared, long-lived access to a provider it can no longer clearly account for has created an exposure that has nothing to do with whether the provider is AML-supervised or has a data-transfer mechanism in place — it is a separate, purely practical gap worth closing on its own terms.

Putting the three checks together

None of the three checks above depend on each other, and a provider can pass one while failing another — a well-supervised UK firm can still have poor access controls, and an overseas provider with a solid data-transfer agreement and tight access controls can still be outside AML supervision if it is performing regulated accountancy services. Treating them as three separate, specific questions, rather than one general impression of whether a provider "seems reliable," is what actually lets a company verify rather than assume.

  • Which supervisory authority is any UK-facing accountancy service provider in the arrangement registered with under the Money Laundering Regulations 2017, and can that registration be checked
  • Where personal data leaves the UK, is a recognised UK GDPR transfer mechanism — the IDTA or the UK Addendum to the EU SCCs — actually documented in the contract
  • Who holds login credentials to the company's accounting software, banking feeds and payroll system, and are those credentials individually attributable
  • What access controls apply, and how quickly is access removed when someone leaves the engagement
  • Which specific person or firm is preparing and filing statutory accounts, Corporation Tax and VAT returns, and on what qualification or agent-authorisation basis — a separate question from bookkeeping and from AML supervision

The figures, and when we checked them

These numbers change by year or by notification. Each one shows the date we last verified it against the source — if that date looks old, check the source before relying on it.

AML supervision threshold for accountancy service providers
No general size or turnover exemption for a dedicated bookkeeping or accountancy provider. Any firm or sole practitioner providing accountancy services or tax advice to other persons by way of business is a "relevant person" under regulation 8 of the Money Laundering Regulations 2017 and must be registered with a supervisory authority. (A single narrow HMRC carve-out exists for incidental accountancy work by a "virtual assistant" under £30,000 total turnover — not applicable to an outsourced bookkeeping engagement.) · verified 2026-08-14

Questions on this

Is it legal for a UK company to outsource its bookkeeping?

Yes. Bookkeeping — recording transactions, reconciling accounts, processing payroll data, preparing reports — is not a restricted activity under UK law, and there is no requirement that it be performed in-house, by a qualified accountant, or by a UK-based provider.

Does a bookkeeper need to be a member of ICAEW, ACCA or another accountancy body?

No general law requires it for bookkeeping itself. Membership of a UK accountancy body is separate from AML supervision, though several of those bodies also act as AML supervisors for their members, which is one route (not the only one) to being properly supervised.

What is AML supervision and why does it matter for outsourced bookkeeping?

The Money Laundering Regulations 2017 require firms providing accountancy services by way of business to be supervised by a recognised body, most commonly HMRC or a professional accountancy body. It matters because operating unsupervised in that category is unlawful for the firm doing it — a fact worth confirming rather than assuming when appointing a provider.

Does outsourcing bookkeeping to an offshore provider automatically breach UK GDPR?

No. UK GDPR permits transferring personal data outside the UK where an appropriate safeguard is in place, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. The requirement is that a recognised mechanism exists and is documented, not that the transfer is prohibited outright.

What is the difference between the IDTA and the UK Addendum?

The IDTA is a standalone UK agreement covering a restricted transfer on its own. The UK Addendum attaches to the EU's Standard Contractual Clauses and is often used where a provider already has EU SCCs in place, so the two together cover both EU and UK transfer obligations without duplicating agreements.

Does the size of a bookkeeping provider affect whether it needs AML supervision?

Generally no. The Money Laundering Regulations 2017 apply based on the activity being carried on by way of business, not on the size, turnover or headcount of the firm performing it, so a sole practitioner providing accountancy services is covered on the same basis as a large firm. HMRC recognises one narrow exception for a "virtual assistant" doing incidental accountancy work under £30,000 total turnover — a fact pattern that does not describe a dedicated bookkeeping provider.

Who should control login credentials to accounting software when bookkeeping is outsourced?

UK law does not standardise this, so it is a question to put to a provider directly. Reasonable practice is individually attributable logins rather than one shared password, access limited to people actively working on the file, and prompt removal of access when someone leaves the engagement.

Is outsourced bookkeeping the same as filing statutory accounts or tax returns?

No. Bookkeeping produces the underlying records; filing statutory accounts, Corporation Tax returns and VAT returns is a separate function with its own qualification and agent-authorisation questions. Outsourcing one does not answer who is responsible for the other.

How can a company check whether a provider is registered for AML supervision?

By asking the provider directly which supervisory authority it is registered with, and by using HMRC's registration service, which exists so that a firm's money laundering supervision status can be checked rather than taken on trust.

Does CapEasy provide bookkeeping services in the UK?

Not currently. CapEasy serves the United States and Australia today; UK services are under consideration but not offered, and this guide is provided as general orientation for a company choosing any bookkeeping provider, not a description of a CapEasy UK service.

This page is information, not an offer of services. CapEasy serves the US and Australia today; UK services are under consideration.