best Practices

The State of Secure Document Sharing in Accounting Firms (2026)

Post 7 of 10: Best Practices for Secure Document Sharing

Part of the FileRecall Accounting Research Series

Understanding the threat landscape, compliance requirements, and available technology is one thing. Knowing what to actually do — in practical, operational terms — is another. This post translates the analysis from earlier in this series into a concrete best-practice framework for secure document sharing in accounting firms.

The framework is organised into four categories: technical controls, workflow controls, client experience controls, and implementation guidance.

Technical Controls

Use a no-download viewer for all sensitive client documents

The single most impactful technical control is ensuring that sensitive documents are viewed in a browser-based viewer rather than downloaded to a recipient’s device. This eliminates the most common leak vector — the downloaded file that gets forwarded, saved to an insecure device, or accessed by an unauthorised party.

FileRecall’s secure document viewer renders documents server-side and streams them as page images. The original file never reaches the recipient’s browser. This is the gold standard for document security — not hiding the download button, but ensuring there is nothing to download.

Enable expiry controls on all shared links

Every document shared with a client or third party should have an expiry date. Appropriate windows by document type:

  • Tax returns and financial statements — 30 days from delivery
  • Engagement letters and authorities — 14 days
  • BAS and IAS documents — 7 days
  • Due diligence materials — aligned to transaction timeline, typically 30-90 days
  • Temporary client access — 24-48 hours

Expiry controls should be set before the link is generated. Make time-limited access the default, not an optional extra.

Enable watermarking on all documents

Every document shared with a client or third party should carry a permanent watermark identifying the recipient. FileRecall’s watermarks are burned directly into the page image on the server — not overlaid using website code that can be removed with browser tools. The watermark includes the recipient’s email address and access timestamp, tiled diagonally across every page.

Maintain full audit trails

Every document sharing event should be logged automatically. Access tracking serves three purposes:

  • Compliance — regulators and auditors may ask for evidence of when and how documents were shared
  • Client service — staff can confirm at a glance whether a client has reviewed a document
  • Incident response — if a document surfaces somewhere it shouldn’t, the audit trail identifies who accessed it and when

Use password protection for highest-sensitivity documents

Password protection adds a second authentication layer before the viewer opens. The password should be communicated to the recipient through a separate channel — never in the same email as the link itself.

Workflow Controls

Make secure sharing the default, not the exception

The most common failure mode is a two-speed system: a secure platform exists, but staff default to email because it’s faster. The solution is to make secure sharing as frictionless as possible — no more steps than attaching a file to an email. Upload the document to FileRecall, copy the link, paste it into the email. The extra step takes ten seconds and delivers a fundamentally different security outcome.

Establish clear document classification

  • High sensitivity — tax returns, financial statements, payroll records, identity documents: always use secure link with expiry, watermarking, and download blocking
  • Medium sensitivity — engagement letters, correspondence, draft documents: use secure link with expiry; watermarking optional
  • Low sensitivity — general information, newsletters, public documents: email attachment acceptable

A simple classification system removes the need for staff to make case-by-case judgements under pressure.

Revoke immediately when circumstances change

Staff should be trained to use instant file recall immediately when:

  • A document was sent to the wrong recipient
  • A client relationship ends
  • A document has been superseded by a revised version
  • A transaction or engagement is terminated
  • A staff member who shared documents leaves the firm

Never send the same document twice — update the link

When a revised version is ready, revoke the old link and generate a new one. Never send the revised document as a new email attachment alongside the original — this creates version confusion and leaves both versions permanently accessible.

Client Experience Controls

Communicate the security benefit to clients

When clients ask why documents now arrive via a link rather than an attachment, use it as an opportunity:

“We’ve moved to a secure document delivery system. You’ll receive a link that opens the document in your browser — nothing is downloaded to your device, and your email address is watermarked on every page. The link expires after [X] days.”

This explanation reinforces trust and differentiates the firm from competitors still using email attachments.

Keep client friction minimal

  • Never require clients to create an account to view a document
  • Ensure the viewer works correctly on mobile devices
  • Use password protection selectively — not on every document
  • Set expiry windows long enough for comfortable review

Provide a clear call to action in the covering email

“Please find your [document type] accessible via the secure link below. The link will remain active until [date]. No download or account is required — simply click the link to view.”

Implementation Framework

Start with highest-risk documents

Begin with the documents that carry the highest risk — tax returns, financial statements, payroll files — rather than trying to change all document sharing at once. This creates immediate compliance improvement while giving staff time to build the habit.

Train staff in a single session

FileRecall’s workflow is simple enough to cover in a single 30-minute training session:

  • How to upload a document and generate a secure link
  • How to set expiry, password protection, and download permissions
  • How to check access tracking to confirm a document has been viewed
  • How to revoke a link
  • Which document types require secure sharing

Review the audit trail monthly

  • Which documents have been shared and with whom
  • Whether any links that should have been revoked are still active
  • Whether any documents have been accessed an unusual number of times or from unexpected locations
  • Whether expiry dates are being set consistently

Update your privacy policy

Once secure document sharing is in place, update the firm’s privacy policy to reflect the security measures used. Under APP 1 of the Australian Privacy Principles, firms must have a clearly expressed privacy policy that accurately describes how personal information is managed.

The Bottom Line on Best Practices

Secure document sharing best practice in accounting comes down to a small number of consistent behaviours: use a secure viewer, set expiry dates, enable watermarking, maintain audit trails, and revoke promptly when needed.

The technology to support these behaviours — FileRecall — is straightforward to implement and affordable at every practice size. The compliance and security benefits are immediate. The client experience improvement is measurable.

The firms that implement these practices now are building a security and compliance foundation that will serve them for years. The firms that don’t are accumulating risk with every uncontrolled document they send.

────────────────────────────────────────────────────────────

Next in this series: Post 8 — Strategic Implications for Accounting Firms →

← Back to: Post 6: The Technology Landscape

View the full series index →

Related Reading

FileRecall — Secure document sharing for accounting firms. filerecall.com

Leave a Reply

Your email address will not be published. Required fields are marked *

Scroll to top