One client. Many systems. One firm's responsibility.
Follow a single client's documents as they move through email, WhatsApp, Tally, cloud drives, tax software, government portals and a decade of archives - and count every place they end up, and where you lose control of them.
- 1
Client onboarding & engagement control breaks
+7 places · 7 so farA new client is signed. Basic identity, contact and engagement details are captured - often over email or WhatsApp before any secure system exists.
Where control breaks: PAN, Aadhaar and bank statements arrive over WhatsApp · Client files on personal laptops · Shared drive access that outlives the staff
Moving hereIdentity data (new at this stage)Contact data (new at this stage)Bank & financial statements (new at this stage)DPDPATell the client what you collect and why, at or before collection, and record the engagement's purpose.
- 2
KYC collection
+2 places · 9 so farPAN, Aadhaar, and for companies the MCA and board documents are collected to establish identity for filings and portal access.
Moving hereCorporate & MCA records (new at this stage)Identity dataBank & financial statementsDPDPACollect only the identity documents the filing actually needs; Aadhaar is high-impact and often over-collected.
- 3
Document collection control breaks
+1 place · 10 so farBank statements, Form 16, salary sheets, invoices and investment proofs arrive - by email, WhatsApp, a shared drive or a portal - and copies scatter immediately.
Where control breaks: Outsourced data entry with no written contract
Moving hereTax documents (new at this stage)Investment & loan documents (new at this stage)Medical & insurance data (new at this stage)Identity dataBank & financial statementsDPDPAPrefer one controlled intake channel; every extra copy is a place a deletion request must later reach.
- 4
Accounting & bookkeeping
+2 places · 12 so farTransactions are entered into Tally or Busy. For business clients this pulls in employee payroll - salary, bank and PF data for people who are not your clients.
Moving herePayroll & salary data (new at this stage)GST & indirect-tax data (new at this stage)Bank & financial statementsDPDPAPayroll data belongs to the client's employees; you are handling it on the client's instructions, so agree the terms in writing.
- 5
Tax preparation & computation
+2 places · 14 so farReturns and computations are prepared in Winman or ClearTax. Working papers, drafts and the computed tax position are created and copied to laptops.
Moving hereComputed tax position· inferred (new at this stage)Identity dataBank & financial statementsTax documentsGST & indirect-tax dataDPDPAThe computed position is derived personal data about the client - protect it like the source documents.
- 6
GST / TDS compliance control breaks
+3 places · 17 so farGST returns and TDS statements are prepared and uploaded to the GST portal and TRACES, using credentials the firm holds on the client's behalf.
Where control breaks: Client portal passwords in a shared sheet
Moving herePortal credentials (new at this stage)Identity dataPayroll & salary dataGST & indirect-tax dataDPDPAPortal credentials held for a client are a serious custody responsibility - store them like the data they unlock.
- 7
ITR filing control breaks
+2 places · 19 so farReturns are filed on the Income Tax portal, e-verified with the client's DSC or OTP. The firm often holds the DSC token physically.
Where control breaks: The firm holds the client's digital signature
Moving hereDigital Signature Certificate (new at this stage)Identity dataTax documentsPortal credentialsComputed tax position· inferredDPDPAA DSC is signing authority, not just data - holding it means you can act legally as the client, so control it tightly.
- 8
Client review & sign-off
+2 places · 21 so farDrafts and filed returns are sent back to the client for confirmation - usually as email or WhatsApp attachments, creating another copy outside the firm.
Moving hereBank & financial statementsTax documentsComputed tax position· inferredDPDPAShare the minimum needed for sign-off, over a channel you can later account for.
- 9
Government submission
Filings reach the Income Tax department, GSTN and MCA. Documents may also go to banks or statutory auditors who receive them without a processing contract.
Moving hereBank & financial statementsPayroll & salary dataCorporate & MCA recordsDPDPAStatutory disclosures are lawful, but a bank or auditor receiving data without a contract needs minimisation and a protected channel.
- 10
Archive, retention & deletion control breaks
+1 place · 22 so farEverything is retained - and then kept. A decade of ITRs, Form 16s and bank statements accumulates in folders and inboxes that are never cleared, and next year the cycle starts again.
Where control breaks: A decade of client folders, never deleted
Moving hereIdentity dataBank & financial statementsTax documentsPayroll & salary dataDPDPAKeep records only as long as the law or the engagement needs; set a deletion schedule, because the default here is 'forever'.
Top risk hotspots - where control usually breaks
The seven places recruitment agencies most often lose track of candidate data. Each links to the matching check in the readiness assessment.
- Hotspot 1 Critical risk
Clients' DSC USB tokens and PINs are kept at the firm so returns can be e-signed and filed without chasing the client each time.
Why this matters
A DSC is signing authority, not just a document - whoever holds the token and PIN can legally sign and file as the client, so its custody deserves the same care as the signature itself.
Fix: Keep tokens in named custody with a signing log, store the PIN separately, and return or destroy tokens when the engagement ends.
Check this in the assessment - Hotspot 2 Critical risk
Income Tax, GST and TRACES logins for hundreds of clients sit in one spreadsheet so any staff member can file for anyone.
Why this matters
A single file unlocks government portals for every client at once; if it leaks, so does the ability to log in as each of them.
Fix: Move credentials into a proper password manager with per-user access and logging, and stop keeping portal logins in a shared file.
Check this in the assessment - Hotspot 3 High risk
Clients send their most sensitive documents to staff personal phones, where they auto-download and back up to personal cloud accounts.
Why this matters
The firm cannot find, protect or delete these copies - an erasure request cannot reach a staff member's personal phone backup.
Fix: Move document intake to a secure portal or an official channel, and stop accepting IDs and statements over personal chat.
Check this in the assessment - Hotspot 4 High risk
Documents are downloaded onto unmanaged laptops to work on, and simply stay there after the return is filed.
Why this matters
There is no wipe when an article assistant leaves and no record of what they took - the firm's most sensitive data walks out with the device.
Fix: Work from managed devices or the drive, disable local downloads where you can, and collect or wipe devices on exit.
Check this in the assessment - Hotspot 5 High risk
A single drive holds every client's documents, and access granted to article assistants and staff is rarely reviewed when they leave.
Why this matters
Ex-staff and old trainees can retain access to every client's financial documents long after they have gone.
Fix: Review and revoke drive access quarterly, remove leavers immediately, and scope folders so access can be limited per client.
Check this in the assessment - Hotspot 6 High risk
ITRs, Form 16s and bank statements are kept year on year, in drives, folders and inboxes, with no deletion schedule.
Why this matters
The firm does not have a deletion problem, it has an accumulation one - ten years of the most sensitive documents multiplies the damage of any breach.
Fix: Set a retention schedule tied to the statutory period and securely delete client data once the engagement and the law no longer require it.
Check this in the assessment - Hotspot 7 High risk
Bulk data entry and document processing is handed to a freelancer or agency, often on trust with nothing in writing.
Why this matters
A processor handling client financial documents without a contract leaves the firm liable, with no agreed controls, deletion duties or breach obligations.
Fix: Put a data-processing agreement in place before sharing anything, and limit the vendor's access to only what the task needs.
Check this in the assessment
How to read this journey
The places add up
Each stage shows the new places the data reaches - inboxes, WhatsApp, Tally, drives, laptops, portals, backups. Every place is counted once, so the running counter always matches the systems listed above it.
When it leaves you
A violet left edge and a tag mark systems outside your firm - the client business, cloud vendors, government portals, banks and auditors. Once data lands there your control is indirect: it runs through your contract and instructions, not your admin panel. Risk is shown separately, as an amber or red fill - so an outside system can be low risk, and an in-house one high risk.
Where control breaks
Red flags mark the hotspots - the places CA firms most often lose control of client data, from the DSC token to a decade of undeleted folders. Tap any system to see what it holds and how to fix it.
Now check whether your controls hold up
The map shows where client data travels in a typical firm. The 3-minute readiness scan checks whether your firm has the controls that matter at each hotspot - and the Discovery tool builds your own data inventory.
Educational reference model - not legal advice, and not a scan of your actual systems.