- Home
- Accountants
IT support for accountants, built around your filing calendar
Remedian supports accountants and bookkeepers across Manchester and the North West with helpdesk support, Microsoft 365, HMRC agent account security, practice software, backup and onsite engineering.
Your year has fixed, immovable dates in it. We plan the work around them, and we treat anything that blocks a submission as business critical.
See what practice IT support includes Book a practice IT review
01
Most businesses can absorb a bad IT week. An accountancy practice cannot absorb a bad January.
Every business says its IT is critical. In a practice it is measurable. A file server that is slow in June costs you some patience. The same server slow on 29 January costs you filings, fee-earner hours you cannot bill and clients who watch you miss a statutory date on their behalf.
That should change how the work is scheduled. Firmware updates, migrations, licence changes and hardware swaps belong in the quiet weeks. If your provider is proposing a server move in the third week of January, they are not thinking about your business.
We hold a copy of your filing calendar and schedule changes against it. Nothing disruptive lands in the fortnight before a deadline unless it is fixing something worse.
A printer fault in November is a printer fault. The same fault on the last Friday in January, when the practice is producing signed accounts, is not. Priorities move with the calendar.
Peak weeks are when practices add temporary staff, extend hours and put more load on the same systems. That is a planning question, and it is easier answered in October than in January.
A named engineer who understands your software, your hosting arrangement and which partner needs what, rather than a call queue that starts from nothing every time.
The day-to-day service behind this is described on our Managed IT Support page. Practices in the city centre can also use our IT Support Manchester team for onsite work.
02
What IT support for an accountancy practice should cover
A useful agreement covers the user, the device, the identity, the practice software, the network and the recovery position together. It should also state plainly where our responsibility stops and where a software vendor, hosting provider or your professional body takes over.
Outlook, Microsoft 365, devices, printing, access problems and daily faults, with a defined route from first-line triage to senior engineering.
Networks, servers, wireless, office moves, meeting rooms and the faults that cannot be fixed down a wire.
Microsoft Entra ID, multi-factor authentication, admin roles, and documented joiner, mover and leaver processes covering HMRC and software portals as well as email.
The controls around the accounts that reach every one of your clients' tax records. Covered properly in section 03.
The devices, hosting, Microsoft 365, network and integration requirements around your practice suite, with vendor coordination where the fault sits inside the product.
Endpoint protection, email security, patching, firewall management and support towards Cyber Essentials.
Agreed scope, retention matched to your statutory record-keeping period, isolated copies and restores that have actually been tested. See secure backup.
Open actions, recurring faults, renewals, budget and a roadmap the partners can read without translation.
Permissions, data boundaries and an approved-tool position before staff put client financial data into an AI tool. See AI Solutions.
Broadband, leased lines and resilience, which matter more once submissions are quarterly rather than annual. See connectivity.
03
Your agent services account is the most valuable thing on your network
Not your accounts files. Not your email. The credentials that let you act for every client you hold. An attacker who reaches them can file returns, alter figures and redirect repayments across your entire client base from one login.
HMRC has said openly that agent online service accounts and agent services accounts are a target for fraudsters, and that where it believes an account has been compromised it will act quickly, in some cases suspending the account without notice. A practice suspended in the run-up to a deadline cannot file for anyone.
Two HMRC account models, with different permission controls
In HMRC online services for agents, administrators can allocate clients and tax services to named users. In the Agent Services Account, HMRC's current guidance says the option to allocate clients and services is not available. Once a staff member is given direct access to the Agent Services Account, you cannot use that account to restrict them to an assigned client list.
That makes the controls around the service unusually important: give each person their own sign-in, use HMRC multi-factor authentication, limit direct access to the people who need it, and remove access on the day someone leaves or changes role.
HMRC recommends individual credentials for every member of staff. Shared logins remove accountability and make a compromised account much harder to contain.
The email addresses, telephone numbers and authenticator methods used for recovery must belong to the practice, stay current and be removed when a member of staff leaves.
A common route in is a phishing email that persuades someone to install genuine remote-support software. It is not malware, so it does not always trip antivirus. We alert on unexpected remote-access installs.
Review the list of staff with direct account access at least each quarter, and remove it the day someone changes role or leaves rather than at the next audit.
The account is only as safe as the laptop it is opened on. Patching, encryption, endpoint protection and controlled admin rights on every device that signs in.
If a return appears in your agent account with no matching receipt in your practice software, that is a signal worth acting on the same day.
HMRC explains the permission difference in its guidance on giving staff access to online tax agent accounts. ICAEW also covers keeping HMRC agent account details safe. If you want the surrounding configuration tested rather than assumed, see our penetration testing service or start with the free cyber risk check.
04
Practice software problems usually sit between suppliers, not inside one
A typical practice runs a tax and accounts suite, a bookkeeping platform, payroll software, a document portal, a receipt-capture tool and Microsoft 365, some hosted by the vendor and some on your own kit. When something breaks, each supplier can reasonably say the problem is somewhere else.
We support the environment and chase the vendor
For suites such as IRIS, CCH, Xero, Sage, QuickBooks, TaxCalc and BrightPay, we handle the devices, identities, Microsoft 365, network path, hosting connection, printing, browser requirements and integrations. Where the fault is genuinely inside the product, we open the vendor case and keep it moving rather than handing you a reference number.
At onboarding we record, for each application: who owns it, the support contact, the licence position, how staff authenticate, what it integrates with, who backs it up and what the escalation route is. Most practices have never had that written down in one place.
Hosted does not mean handled
- If the suite is hosted by the vendor, confirm what they back up and for how long.
- If it runs on your server, confirm it is in your backup scope and that a restore has been tested.
- Either way, confirm who holds the administrator account. It should be the practice.
Microsoft 365 configured for a practice
- Shared mailboxes for tax, payroll and accounts with permissions that reflect who should see what.
- SharePoint and Teams structured by client or department rather than one open library.
- External sharing controlled, so client records are not sent as unmanaged attachments.
- Retention and audit settings that match how long the practice keeps records.
- Copilot readiness assessed against the permissions staff already hold, not assumed.
05
Making Tax Digital turns one annual peak into five
Making Tax Digital for Income Tax started on 6 April 2026 for sole traders and landlords with qualifying income over £50,000. HMRC put more than 864,000 taxpayers in scope for the first year, and the first quarterly update is due by 7 August 2026. The threshold falls to £30,000 in April 2027 and £20,000 in April 2028.
The tax return has not gone away. Quarterly updates sit on top of it. For a practice that means four additional submission windows a year, each with its own crunch, and a client base that is about to get considerably larger as the thresholds drop.
The infrastructure question nobody asks until the week before
Quarterly filing multiplies the number of times your staff need software to be responsive, your connection to be up and your authorisations to be in order. A hosted desktop that is merely tolerable in a normal week becomes the bottleneck when forty people are submitting at once.
Worth checking before the next window rather than during it: connection capacity and whether there is a fallback, hosted-desktop performance under real concurrent load, device age across the team, licence coverage for temporary staff, and whether agent authorisations are actually in place for every client you expect to file for.
| Threshold | Qualifying income above | Mandated from |
|---|---|---|
| Phase 1 | £50,000 | 6 April 2026 |
| Phase 2 | £30,000 | 6 April 2027 |
| Phase 3 | £20,000 | 6 April 2028 |
HMRC has confirmed there are no penalty points for late quarterly updates during the first year, which buys the profession one cycle of grace and no more. The habits and systems set now carry into a regime with real penalties.
Details are on GOV.UK: find out if and when you need to use Making Tax Digital for Income Tax and the first quarterly update deadline.
06
Anti-money laundering duties put a pile of identity documents on your network
Customer due diligence means collecting passports, driving licences, proof of address, ownership structures and source-of-funds evidence, then keeping it for as long as the regulations require. That obligation quietly turns every accountancy practice into a holder of exactly the material identity thieves want most.
In a lot of practices those documents end up as email attachments, phone photographs and files in a general shared folder. That is a problem you can fix without changing a single AML procedure.
Where the line sits
Your AML obligations under the Money Laundering Regulations belong to the practice and its supervisor, whether that is HMRC or a professional body. We do not advise on compliance. We build and evidence the technical controls around the records, so that when a compliance visit asks how the material is protected, the answer exists in writing.
The sector guidance is published by GOV.UK: accountancy sector guidance for money laundering supervision, alongside HMRC's risk assessment for accountancy service providers.
07
Microsoft 365 keeps the service running. It does not keep your records.
Microsoft undertakes to keep the platform available. It does not undertake to hand back a mailbox a leaver deleted eight months ago, or a client folder someone overwrote in March. Retention policies help, but a policy is a setting, and settings can be changed by anyone holding the right admin role.
A practice has to keep records for statutory periods measured in years. Backup retention should be set against that period deliberately, as a decision the partners have made, rather than left at whatever the software defaulted to.
| What needs protecting | Typical approach | What we actually check |
|---|---|---|
| Exchange Online mailboxes | Daily backup, retention matched to the practice's record-keeping period | A single-item restore and a full mailbox restore, not a green tick on a dashboard |
| SharePoint, OneDrive and Teams | Versioned backup of libraries, channel files and permissions | Whether permissions return with the data, which is where most restores disappoint |
| Practice and tax software | Scope agreed with the vendor, since it varies by product and hosting model | Who holds the backup, where it sits, and how a restore is requested in practice |
| Servers and local data | A local copy for speed plus an offsite copy unreachable from the production network | Recovery time measured against what the practice can tolerate in January |
An isolated copy is the part that matters
Attackers look for the backup before they encrypt anything. A backup reachable with the same administrator credentials as the live environment is not a recovery position, it is a second target. Immutable or network-isolated copies with separate credentials are what turn a serious incident into a bad week.
Test the restore in the quiet months
The only meaningful test of a backup is a restore. We schedule those deliberately, in the parts of the year where the practice can afford the attention, and we write down how long it took. A recovery time nobody has measured is a guess.
Scope, retention and restore testing are described further on our secure backup page.
08
Peak season adds people, hours and devices, usually at short notice
Practices flex. Temporary staff arrive for the busy period, existing staff work late from home, and someone always needs access to a client's records from a kitchen table at nine in the evening. The security model has to handle that without either blocking the work or quietly opening the practice up.
Temporary staff need accounts created quickly and removed the day they finish. The removal is the half that gets forgotten, and it is the half that matters.
Access granted on the strength of the account and the device rather than the network. Multi-factor passed, device known and encrypted, sign-in not obviously unreasonable.
A stated position on what may be done on an unmanaged laptop or phone, whether practice data can be stored locally, and how it is removed when someone goes.
Short-term licences added for the season and removed afterwards, so the practice is not still paying in June for people who left in February.
Draft accounts and client correspondence printed on a domestic printer create a paper file nobody is tracking. Worth an explicit rule.
Hosted desktops and connections behave differently with everyone on them at once. Better to find the ceiling in a test than in a submission window.
09
Partners should be able to see the IT position without asking for it
Practices get asked to evidence their controls more than they used to. Professional indemnity renewals ask. Cyber insurance asks. Larger clients send security questionnaires before they instruct. A practice that has to chase its IT provider for answers each time is paying twice for the same information.
What you own, who uses it, how old it is, what it costs and when support ends. This is the document that makes a capital budget possible.
Tickets grouped by cause rather than counted. Twelve tickets about one scanner is one problem, and it should be fixed rather than reported every month.
Multi-factor coverage, admin accounts, patch status, backup success and the date of the last tested restore, stated plainly enough for a partners' meeting.
When an insurer or a client sends a security questionnaire, we complete the technical sections with evidence rather than leaving the practice to guess at the answers.
Software, connectivity, hardware warranties and licences tracked so nothing auto-renews unnoticed at a price nobody agreed.
What needs doing, what it costs, what the risk is of leaving it, and which financial year it belongs in.
Logging turns a suspicion into an answer
When a practice needs to establish whether a mailbox was read or a client file was copied, the answer depends entirely on what was being logged at the time and how long it was kept. Default retention in Microsoft 365 is shorter than most people assume. We set this at onboarding rather than discovering the gap mid-incident.
Practices working towards Cyber Essentials find most of this reporting is already what the assessment asks for. The scheme covers five technical controls, is renewed annually, and starts at £320 plus VAT through the NCSC scheme.
10
Practices stay with a provider they have outgrown because the handover looks risky
The risk is real, but it is rarely the cutover itself. It is discovering afterwards that the outgoing provider still holds the domain, that the Microsoft tenant was created under their account, that nobody has the practice software support contact, or that a backup everyone assumed was running stopped two years ago.
We work through it in a fixed order and write down what we find, including the things we cannot get.
We request access, documentation and system ownership from the outgoing provider, and give the practice a date by which it knows what has and has not been supplied.
We confirm the practice owns its Microsoft tenant, domains, DNS, backups, licences and software accounts. Ownership sitting in a provider's name is the most common problem we find.
Support routes go live, urgent faults are cleared and monitoring is deployed before the previous provider steps back, not after.
We produce the first roadmap, so the change leaves the practice in a better position rather than with a different number to ring.
We will not move a practice in January
Transitions belong in the quiet part of the year. If you are unhappy with your current provider in the middle of a filing peak, the right answer is usually to start the groundwork now and cut over once the deadline has passed. Any provider that offers to migrate you next week during peak season is selling, not planning.
What the practice should own at the end
- The Microsoft 365 tenant, in the practice's name, with the practice holding a global administrator account.
- The domain registration and DNS control.
- Direct contracts with the practice software and hosting vendors.
- Backups the practice can have restored on request, with retention it has agreed.
- Documentation good enough for a third provider to pick up if the practice ever leaves us.
The same principle runs through our Managed IT Support service. We also support neighbouring professions, including solicitors and law firms and insolvency practitioners.
11
Book a practice IT review
A working session, not a sales call. We look at how the practice is actually set up and tell you what we find, including the parts that are fine.
- Who holds HMRC agent account access, and what protects the mailbox behind it.
- Microsoft 365 configuration, admin roles, multi-factor coverage and external sharing.
- Backup scope, retention against your record-keeping period, and whether a restore has been tested.
- Practice software hosting, performance under load and who owns the contracts.
- Where client identity documents are stored and who can reach them.
You get a written summary of the gaps, ranked by risk, with an honest note on which ones cost money and which are a configuration change.
Or call 0330 66 00 281 and ask for the business team. If you would rather start anonymously, our free cyber risk check takes a few minutes.
12
IT support for accountants: FAQs
References and useful links
- GOV.UK, Find out if and when you need to use Making Tax Digital for Income Tax
- GOV.UK, Deadline approaches for first Making Tax Digital quarterly update
- ICAEW, How to keep HMRC agent account details safe
- GOV.UK, How to give staff access to HMRC online tax agent accounts
- GOV.UK, Accountancy sector guidance for money laundering supervision
- GOV.UK, Risks common to accountancy service providers
- HMRC, Anti-money laundering guidance for supervised businesses
- NCSC, Cyber Essentials overview and requirements
- IASME, Cyber Essentials certification
- Remedian, Managed IT Support
- Remedian, Cyber Security
- Remedian, Cyber Essentials
- Remedian, Secure Backup
- Remedian, IT Support for Solicitors

.png?width=150&height=64&name=output-onlinepngtools%20(2).png)
.png?width=229&height=97&name=output-onlinepngtools%20(2).png)