Is offshore
actually safe?
Yes, with controls — and the controls are the same ones you should already apply to local staff. Here are the five real risks, and what specifically addresses each.
This question usually means one of five different things, and they have different answers. Can they steal money? Can they leak client data? Are we breaching a regulation? What happens if they disappear? Will the work be any good?
Most content on this subject answers with reassurance, which is worthless. So instead: each risk named, and the specific control that addresses it. Where a risk is real, we say so.
The honest summary is that location is rarely the risk factor. Standing admin access, shared passwords and undocumented processes are — and they are just as dangerous in your own office.
Who this is for
✓Worth your time if
- You are seriously considering offshore support and want the risks named
- You are in a regulated profession
- Your board, partners or licensee will ask
- You already have offshore staff and have never audited the controls
✕Probably not if
- You want reassurance rather than controls
- You are unwilling to set up named accounts and scoped access
- You need legal advice for your specific situation
What could actually go wrong
Each risk, then the control. Two of these are real and commonly under-managed; the other three are largely solved by access design.
The most serious and the most easily eliminated. Control: no offshore team member holds a banking login, payment token, payment authorisation or trust account access. They prepare the payment file; your authorised person releases it. Reviewing a prepared run takes minutes and closes this risk entirely.
Real, common, and it happens with local staff constantly — a spoofed email changing supplier bank details. Control: a written rule that bank detail changes are verified by you, by phone, on a number from your own records. Tell your team member explicitly they will never be criticised for delaying a payment to verify.
Control: they work inside your systems as a named user with scoped access, so nothing is downloaded or stored elsewhere and every action is attributed. NDA and confidentiality agreement signed before day one. Access revocable instantly. Your Privacy Act obligations apply regardless of location.
Real in licensed professions, and it comes from an undocumented boundary rather than bad intent. Control: name the regulated act in writing, check your licensee's outsourcing policy first, and keep the attestation step in-house. Our boundary map covers each profession.
Control: they are employed and managed rather than freelancing, so there is a contract, an HR function and a free replacement behind them. Have them document their own process from week one — then a departure is an inconvenience rather than an emergency.
The four controls that do most of the work
If you implement nothing else, implement these. They apply equally to local staff.
- Named accounts, never shared passwordsTheir own login in every system. Every action attributed, access revocable in seconds, and nothing survives their departure.
- Least privilege, reviewedOnly the permissions the role needs. No owner accounts, no standing global admin, nothing touching payment or payout settings.
- Money movement stays with youPreparation travels; release does not. This single rule eliminates the worst-case outcome.
- The boundary written downWhat requires your licence, registration or signature, named on one page before day one. Undocumented boundaries are how good people create exposure.
What we do on our side
So you can see where our controls end and yours begin.
Screening before you see anyone
Work history verified with previous employers directly rather than from the CV, English confirmed, and identity checked. You then interview them yourself before deciding.
NDA and confidentiality before day one
Signed as part of engagement, covering your business and your clients, before any access is granted.
Employed and managed, not freelancing
A contract, an account manager and an HR manager behind every placement — which is what makes performance and continuity manageable rather than hopeful.
Equipment and connectivity checks
Verified before they start, so the arrangement does not fail on a bad connection.
A replacement guarantee
First week refunded if it is clearly wrong, and a free replacement any time after that. We carry the risk of a bad match rather than you.
What we do not do
We do not hold your credentials, store your client data on our systems, or take responsibility for your regulatory obligations. Those stay yours, and any provider claiming otherwise is worth avoiding.
Sharing a login because it was quicker
This is the actual security failure in most offshore arrangements, and it is entirely self-inflicted. Someone shares the owner account, or a password for a system that does not support multiple users, because creating a proper account takes ten minutes and the work is urgent. Now nothing is attributed, permissions cannot be scoped, payment settings are reachable, and revoking access means changing a password everyone uses. It is the same mistake businesses make with local staff — the difference is that offshore gets blamed for the consequence. Spend the ten minutes. Named account, least privilege, no exceptions, and check the audit log in the first fortnight.