Federal tax law draws exactly one geographic line around your clients' data, and it isn't the one the outsourcing industry sells you. Treasury Regulation §301.7216-3 splits the world into tax return preparers "located within the United States, including any territory or possession of the United States," and preparers "located outside of the United States." That's the whole distinction. Guadalajara and Bengaluru fall on the same side of it.
The nearshore vs offshore outsourcing comparison is a software-industry argument about sprint velocity and daily standups. Your deliverable isn't a sprint. It's a return with your signature on it.
So the axis everyone compares on is not the axis that decides your exposure.
If the law treats them the same, what actually differs?
Time zones, travel, talent pool, culture, and cost are all real differences. They just aren't legal differences, and for a firm they aren't the first-order question.
One scheduling difference, two legal identities
The top row rests on a scheduling assumption. The two rows beneath it are the law, and the law does not see a difference.
How much overlap does geography buy you?
Overlap assumes a 9:00 a.m. to 5:00 p.m. Eastern workday and a 9:00 to 6:00 local workday at the provider.
| Provider location | UTC offset | Overlap with a 9:00 to 5:00 Eastern day (winter) | Overlap (summer) |
|---|---|---|---|
| Bogota, Colombia | UTC-5 | 8 hours | 7 hours |
| Mexico City, Mexico | UTC-6 | 7 hours | 6 hours |
| San José, Costa Rica | UTC-6 | 7 hours | 6 hours |
| Bengaluru / Mumbai, India | UTC+5:30 | 0 hours | 0 hours |
| Manila, Philippines | UTC+8 | 0 hours | 0 hours |
Those zeros are the strongest argument nearshore has.
But look at what the table holds fixed. It assumes the provider works a local 9:00 to 6:00 day. Geography sets the raw gap. Your vendor's shift policy sets the actual overlap, and a shift policy is a staffing decision rather than a fact of the earth's rotation.
So don't ask a vendor where their office is. Ask what hours their team actually works, and whether that's contractual.
When is nearshore the better answer for an accounting firm?
Nearshore wins when the work generates constant questions. Some categories where we'd tell you to look nearshore first:
- Client advisory services (CAS) and outsourced controller work, where the accountant needs to be on live client calls in the client's own business hours.
- Messy cleanup and diagnostic engagements, where the books are a wreck and every hour produces three questions that only the client can answer.
- Work you plan to visit. Latin American destinations sit a few hours' flight from most US hubs, so a site visit is a day trip rather than an expedition. If you intend to walk your team's floor twice a year, that matters.
- Client-facing roles where a smaller cultural and linguistic distance genuinely reduces friction, and where your clients will meet the person.
In each of those, the conversation is the work. A shared workday is what lets it happen.
When is offshore the better answer?
Offshore wins when the work has a defined specification and a review step. That describes most of what buries a firm in March.
Individual and business return preparation against a documented workpaper standard. Bookkeeping and monthly close on established SOPs. Workpaper preparation, tie-outs, depreciation schedules, K-1 assembly. Work where the input is a document set and the output is a reviewable file.
For that work, the overnight handoff stops being a tax and becomes a second shift. Your reviewer closes their laptop at 6 p.m. and the file is prepared by the time they open it. A nearshore team is awake when you are, which is pleasant, and which also means they're producing during the same 8 hours you are.
Bench depth is the other factor, and it's the one that decides what happens when someone quits in February. Rather than take a vendor's word for it, near or far, ask how many people sit on their bench today and how fast they last replaced someone mid-season.
What does a cheap preparer cost you?
More than the rate card says, and the rate card is the wrong line item to compare anyway. The cost you carry is what the work costs your reviewer.
A partner's hour is the most expensive hour in the building. Every return that comes back needing rework spends that hour, and rework scales with volume in a way a per-hour rate never shows you. So the variable that decides your economics is how much partner review the work still needs after it arrives.
That's not a theoretical point. A cheaper preparer whose work comes back needing more partner review can cost a firm more than a pricier one whose work arrives close to signable, because the expensive hour is the reviewer's, not the preparer's. The rate card never shows you that hidden line, but your reviewer's calendar does.
What is nearshore outsourcing?
Nearshore outsourcing is the practice of contracting work to a provider in a nearby country, usually one within a few time zones of your own. For a US accounting firm, that typically means Mexico, Costa Rica, Colombia, or a Caribbean nation. The pitch is proximity: overlapping business hours, a short flight, and a smaller cultural gap.
The model sits between two extremes. Onshore hiring is expensive. Offshore hiring is cheaper but pushes most collaboration into an overnight handoff. Nearshore splits the difference.
What does nearshore outsourcing look like for a CPA firm?
Consider a Denver CPA firm that engages a bookkeeping team in Guadalajara, Mexico to run monthly closes for 40 small-business clients. The Mexican team works 9:00 to 6:00 local, which overlaps the Denver office for most of the day. When a bank feed breaks at 11 a.m., someone picks up the phone and it's fixed before lunch.
That same-day fix is the entire nearshore value proposition. It's real, and for some kinds of work it's decisive.
What is offshore outsourcing?
Offshore outsourcing is the practice of contracting work to a provider in a distant country, typically one with a large time-zone gap and a materially lower cost of labor. For a US accounting firm, that usually means India or the Philippines. India runs on UTC+5:30 and Manila on UTC+8, far enough ahead that the provider's workday closes before the East Coast opens.
That gap is the model's defining feature, and it cuts both ways. Real-time conversation is hard. Overnight production is easy.
What does offshore outsourcing look like for a CPA firm?
Consider a New Jersey firm that places two trained tax preparers in India to prepare individual returns on the firm's own UltraTax setup, following the firm's own workpaper standards. The preparers work while the New Jersey office sleeps. A US-based reviewer opens the file the next morning, reviews it, and the partner signs.
For defined-spec compliance work, the overnight handoff isn't friction. It's a second shift.
What are the four types of outsourcing?
Four, grouped by location: onsite, onshore, nearshore, and offshore. There's no single official taxonomy, though, and none of these labels appear in IRC §7216 or its regulations, the rules that decide where a client's tax return information may travel. Ordered by distance from your office:
- Onsite. The provider's people work in your office.
- Onshore (also called domestic). The provider is in your own country.
- Nearshore. The provider is in a nearby country, usually within a few time zones.
- Offshore. The provider is in a distant country.
Some lists swap "onsite" for "multisourcing," which describes using several providers rather than a location. Others split offshore into "offshore" and "farshore." The variation is a hint that these categories are marketing conventions rather than legal ones.
Four labels on one axis, and the two the industry keeps rewriting
The location labels, ordered by distance from your office.
Where does US tax law draw the line?
US tax law draws its line at the US border. It does not recognize "nearshore." A tax return preparer in Mexico City and a tax return preparer in Manila are, under Internal Revenue Code (IRC) §7216 and its regulations, the same thing: a preparer located outside of the United States.
The category was built to sell software teams, so its vocabulary never had to survive a tax regulation.
What does §7216 require when a preparer sits outside the United States?
Consent. Treasury Regulation §301.7216-3 requires the taxpayer's written consent before a US preparer discloses tax return information to a preparer located outside the United States. Paragraph (a)(3)(i)(D) states it plainly:
"If a tax return preparer to whom the tax return information is to be disclosed is located outside of the United States, the taxpayer's consent under § 301.7216-3 prior to any disclosure is required."
Source: 26 CFR §301.7216-3(a)(3)(i)(D).
The consequences for getting this wrong are not administrative.
IRC §7216(a) makes a knowing or reckless unauthorized disclosure a misdemeanor, punishable by a fine of "not more than $1,000 ($100,000 in the case of a disclosure or use to which section 6713(b) applies), or imprisoned not more than 1 year, or both." IRC §6713(a) adds a civil penalty of $250 for each such disclosure or use, and the total for any calendar year "shall not exceed $10,000." Where the disclosure or use is made in connection with a crime relating to the misappropriation of another person's taxpayer identity, §6713(b)(1) substitutes $1,000 for the $250 and $50,000 for the $10,000.
The IRS collects its §7216 guidance and FAQs at its Section 7216 Information Center.
A nearshore vendor is subject to every word of this. So are we.
Can you send a 1040 client's Social Security number outside the US?
Generally, no. Not without a specific safeguard in place first. This is the sharpest edge in the whole rule set, and it applies identically to a preparer in Mexico and a preparer in India.
Treas. Reg. §301.7216-3(b)(4)(i) says a preparer "located within the United States, including any territory or possession of the United States, may not obtain consent to disclose the taxpayer's social security number (SSN) with respect to a taxpayer filing a return in the Form 1040 Series" to a preparer located outside the United States. That preparer "must redact or otherwise mask the taxpayer's SSN before the tax return information is disclosed outside of the United States."
There's one exception, in paragraph (b)(4)(ii). A US preparer may obtain that consent only if the SSN travels "through the use of an adequate data protection safeguard as defined by the Secretary in guidance published in the Internal Revenue Bulletin," and only if the preparer "verifies the maintenance of the adequate data protection safeguards in the request for the taxpayer's consent."
So there are two workable paths, and a firm has to pick one deliberately.
Path 1, mask the SSN. The team outside the US receives tax return information with the SSN redacted or fully masked. Per Rev. Proc. 2013-14 §5.04(1)(e)(i), the consent must contain this statement:
"This consent to disclose may result in your tax return information being disclosed to a tax return preparer located outside the United States."
Source: Rev. Proc. 2013-14 §5.04(1)(e)(i).
Path 2, an adequate data protection safeguard. The team outside the US receives tax return information including the SSN. Per §5.04(1)(e)(ii), the consent must contain this longer statement:
"This consent to disclose may result in your tax return information being disclosed to a tax return preparer located outside the United States, including your personally identifiable information such as your Social Security Number ("SSN"). Both the tax return preparer in the United States that will disclose your SSN and the tax return preparer located outside the United States that will receive your SSN maintain an adequate data protection safeguard (as required by the regulations under 26 U.S.C. section 7216) to protect privacy and prevent unauthorized access of tax return information. If you consent to the disclosure of your tax return information, federal agencies may not be able to enforce United States laws that protect the privacy of your tax return information against a tax return preparer located outside of the United States to whom the information is disclosed."
Source: Rev. Proc. 2013-14 §5.04(1)(e)(ii).
Both statements are prescribed word for word. You don't get to paraphrase them.
Two workable paths for a 1040 client's SSN
Both begin at the same gate. A firm has to pick one deliberately.
If a vendor has never mentioned this to you, that tells you something about how many US firms they've served.
Which security frameworks does the IRS name?
Six. Rev. Proc. 2013-14 §5.07 defines an "adequate data protection safeguard" as a management-approved and implemented security program, policy, and practice that includes administrative, technical, and physical safeguards to protect tax return information from misuse, unauthorized access, or disclosure, and that "meets or conforms to one of the following privacy or data security frameworks":
(1) The United States Department of Commerce "safe harbor" framework for data protection (or a successor program);
(2) A foreign law data protection safeguard that includes a security component (e.g., the European Commission's Directive on Data Protection);
(3) A framework that complies with the requirements of a financial or similar industry-specific standard that is generally accepted as best practices for technology and security related to that industry (e.g., the BITS, Financial Services Roundtable, Financial Institution Shared Assessment Program);
(4) The requirements of the AICPA/CICA Privacy Framework;
(5) The requirements of the most recent version of IRS Publication 1075, Tax Information Security Guidelines for Federal, State and Local Agencies and Entities; or
(6) Any other data security framework that provides the same level of privacy protection as contemplated by one or more of the frameworks described in (1) through (5).
Source: Rev. Proc. 2013-14 §5.07.
Two of those six deserve a practitioner's note. The Court of Justice of the European Union declared the European Commission's US Safe Harbour Decision invalid on 6 October 2015; that decision was the Commission's finding of adequacy for the safe harbour privacy principles issued by the US Department of Commerce, which is the framework item (1) names.
The Data Protection Directive named as the example in item (2) was repealed with effect from 25 May 2018 by the General Data Protection Regulation, though item (2) names a category rather than that one directive, and the GDPR carries a security-of-processing article of its own.
The revenue procedure anticipated some of this: item (1) says "or a successor program," and item (6) is a catch-all rather than a named framework.
What it means for you is practical. When a vendor tells you their controls are "aligned" with something, ask which of these six they're claiming under, who approved the program, and when. Then hand the answer to your counsel. Notice that a certification, of any kind, is not one of the six.
Is Puerto Rico offshore?
No. Not for this purpose. Treas. Reg. §301.7216-3(b)(4)(i) covers a preparer "located within the United States, including any territory or possession of the United States," and draws its line against a preparer "located outside of the United States or any territory or possession of the United States." A tax return preparer in San Juan is inside the line.
That produces a result worth sitting with. A preparer in Puerto Rico is treated as domestic. A preparer in the Dominican Republic, on the next island west across the Mona Passage, is treated exactly like a preparer in India. Distance is doing no work here at all. Confirm how this applies to your facts with counsel before you rely on it.
Do the AICPA's outsourcing rules depend on where the provider is?
No. They don't mention geography once. The AICPA Code of Professional Conduct governs your use of any third-party service provider, wherever that provider sits.
Three interpretations do the work, and every partner considering either model should read them:
- ET 1.150.040 says that "before disclosing confidential client information to a third-party service provider, the member should inform the client, preferably in writing, that the member may use a third-party service provider." If the client objects, you either don't use the provider or you decline the engagement. That notice duty doesn't reach a provider used only for administrative support, such as record storage, software application hosting, or authorized e-file tax transmittal (1.150.040.03), which is not what a preparation team is.
- ET 1.700.040 says you should do one of two things before disclosing: enter into a contractual agreement with the provider to maintain confidentiality and "provide reasonable assurance that the third-party service provider has appropriate procedures in place to prevent the unauthorized release of confidential information to others," or obtain specific consent from the client.
- ET 1.300.040 is the one people skip. Before using a provider, "the member should ensure that the third-party service provider has the required professional qualifications, technical skills, and other resources." And "the member must adequately plan and supervise the third-party service provider's professional services so that the member ensures that the services are performed with competence and due professional care."
The full text is in the AICPA Code of Professional Conduct.
Read 1.300.040 twice. Note that the Code says should about vetting the provider and must about planning and supervising the work. The obligation to plan and supervise doesn't transfer to the vendor when the vendor is closer to you. It stays with you at any distance.
Three shoulds and one must
The modals are the Code's own words.
Why is the review chain the real decision, not the time zone?
Because the regulation that decides whether you're personally exposed says nothing about time zones and everything about supervision.
Treasury Circular 230 §10.22(a) requires a practitioner to exercise due diligence "in preparing or assisting in the preparation of, approving, and filing tax returns, documents, affidavits, and other papers relating to Internal Revenue Service matters." Paragraph (b), applicable beginning June 12, 2014, is the one that should govern this entire buying decision:
"Except as modified by §§10.34 and 10.37, a practitioner will be presumed to have exercised due diligence for purposes of this section if the practitioner relies on the work product of another person and the practitioner used reasonable care in engaging, supervising, training, and evaluating the person, taking proper account of the nature of the relationship between the practitioner and the person."
Source: Circular 230 §10.22(b).
Read what that's saying. The presumption attaches to what you did: how you engaged them, how you supervised them, how you trained them, how you evaluated them.
A preparer's resume protects nobody. What protects your name is the layered review standing between their mistake and your signature. That's true whether the preparer works in the next state or on the other side of the planet, and it's the reason "closer is safer" is a comfortable idea rather than a true one.
Which reframes the vendor question completely. You are not buying labor in a location. You are buying a review process, and then supervising it.
How do you grade a nearshore or offshore partner before you sign?
Ask these five questions, in this order, and ask for the answers in writing. A vendor's address answers none of them.
- "Which side of the §301.7216-3 line does the team sit on, and what consent language do you expect us to use?" Any provider outside the US, near or far, means you need consent. If they can't produce the Rev. Proc. 2013-14 §5.04(1)(e) language on request, treat that as a sign they have not done this for a US firm before.
- "Do you receive unmasked SSNs on Form 1040 series work? If yes, which of the six frameworks in Rev. Proc. 2013-14 §5.07 does your data protection program conform to, who approved it, and when?" Push past the word "aligned." Get the framework name.
- "Walk me through the review chain on a single return, by role." You want named layers. Ask who catches what, and what happens on the second occurrence of the same error. Vague answers here are the answer.
- "How do you satisfy our obligation under AICPA ET 1.300.040 to plan and supervise your work?" The obligation is yours, not theirs, so the right answer describes what they give you to discharge it: workpaper standards, review sign-offs, error logs, visibility.
- "Show me, don't tell me. What will you do on real work of ours before we commit a client file?" A mock return. A pilot. A block of representative work put through full review and graded by your reviewer. If a vendor won't prove it on your work before your name is attached, you've learned everything you need.
Question five is the one that separates the field. Everything before it can be answered by a well-briefed salesperson.
How we handle this at Accountably
We're offshore. Our accountants and tax preparers work from our own offices in India, which means the consent, masking and safeguard obligations apply to an engagement with us in full.
Take question two, the framework question. Our controls are SOC 2-aligned, not certified, and SOC 2 is not one of the six frameworks in Rev. Proc. 2013-14 §5.07. We won't present it as one. The rest of our data security and compliance posture: NDA-backed confidentiality, background-verified staff, role-based access, secure VPN, encrypted file exchange, audit logs, and zero local storage. Put question two to us in writing and hold it to the standard you'd hold anyone's.
Question three is the one we built the firm around. Every file moves through four sets of eyes before it reaches yours: preparer, senior, quality, final. The signature, the opinion, and the final judgment stay with your firm. You sign; we make it signable.
Since 2022 we've made 30-plus placements across 20-plus US firms. If someone isn't the right fit in the first 30 days, we replace them free, from our bench or recruited to your spec. That's our 30-Day Fit Guarantee. It's a replacement, not a refund.
Before any signature-bearing work, you can run a Free 40-Hour Proof Pilot: a fixed block of your own representative work, prepared on your SOPs and software and put through the full review chain, so your reviewer grades real output before you commit. The consent and masking rules attach to the pilot like any other engagement outside the US. The trial is free, and the point is the proof, not a discount.
Frequently asked questions
What is the difference between nearshore and offshore outsourcing?
Nearshore outsourcing uses a provider in a nearby country, usually within a few time zones. Offshore outsourcing uses a provider in a distant one. For a US accounting firm the practical difference is overlap hours, travel time and cultural distance. Under IRC §7216 and Treas. Reg. §301.7216-3, there is no difference: every preparer outside the United States is treated the same way.
Does the IRS treat nearshore differently from offshore?
No. The regulation's only geographic distinction is between preparers "located within the United States, including any territory or possession of the United States," and preparers located outside of it. A preparer in Mexico and a preparer in India are on the same side of that line, and both trigger the taxpayer-consent requirement before any tax return information is disclosed.
What is an example of nearshore outsourcing?
A US accounting firm contracting a bookkeeping team in Guadalajara, Mexico or Bogota, Colombia to run monthly closes, with the team working hours that overlap the firm's own. With 6 to 8 shared hours a day, a broken bank feed gets resolved by phone the same morning, rather than waiting for an overnight cycle.
What is an example of offshore outsourcing?
A US accounting firm placing trained tax preparers in India or the Philippines who prepare returns on the firm's own software and workpaper standards, with a US-based reviewer signing off. With 0 shared hours, the work is prepared during the US firm's night and reviewed the following morning, which turns the time gap into a second shift on defined-spec compliance work.
What are the four types of outsourcing?
By location, the industry commonly names four: onsite, onshore (domestic), nearshore, and offshore. The taxonomy is a marketing convention rather than a legal one. Some lists substitute "multisourcing" for onsite, others split offshore into offshore and farshore, and no version of it appears in IRC §7216 or its regulations.
