Assurance · Tax · Advisory · Corporate · TechnologyPakistan · Gulf · UK · US · Canada+92-51-6138902WhatsAppinfo@mac.org.pk

Global Delivery / Data Security & Confidentiality

The security question, answered properly.

Handing client financial data to an offshore team is a real risk, and you are right to interrogate it.

Our IT governance function is led by a certified specialist holding ISO 27001, COBIT, NIST and SOC 2 credentials and more than fifteen industry certifications — in-house, not outsourced. Confidentiality here isn't a policy document nobody reads; it's built into how the work is actually done.

IWhere we come in

The questions we're asked before anyone commits

We need to know exactly who can see our client data, not just that "access is controlled."

Role-based access control, permissioned per engagement, not a blanket grant.

We've been burned by a vendor that didn't take confidentiality seriously.

Signed NDAs at firm and individual level, not just a clause buried in a master agreement.

We're worried about data walking out on a USB drive or a personal laptop.

Controlled workstations — no removable media, no local client-data storage.

We need to know data is encrypted, not just "sent securely."

Encrypted transfer and storage, with audit-logged access.

Our compliance team needs to see actual certifications, not a claim.

ISO 27001, COBIT, NIST and SOC 2 credentials, held by our IT governance lead in-house.

We want to know what happens to our data after the engagement ends.

Retained for 10 years under the same access controls, with confidentiality obligations that survive permanently.

IIWhat we do

How client data is actually protected

Specific controls, not a policy statement — this is what's actually in place.

01

Access Control & Confidentiality Agreements

Access is scoped to the engagement, not the organisation, and backed by signed commitments at every level.

  • Role-based access control, per-engagement permissioning
  • Signed NDAs at firm and individual level
  • Confidentiality protocols under ICAP's ethical framework
02

Workstation & Physical Controls

Controlled environments, not a policy that assumes good behaviour.

  • Controlled workstations
  • No removable media
  • No local client-data storage
03

Encryption & Audit Logging

Every transfer and every access event is encrypted and logged, not just described as secure.

  • Encrypted transfer and storage
  • Audit-logged access
  • ISO 27001-aligned information security practices
04

Governance & Certifications

Led in-house by a certified specialist, not outsourced to a third party.

  • ISO 27001, COBIT, NIST and SOC 2 credentials
  • Fifteen-plus industry certifications
  • In-house IT governance function

This applies across every Global Delivery engagement — UK, US, Canada and the Middle East — not just the markets with formal data protection regimes.

IIIHow we work

What happens after the engagement ends

Confidentiality doesn't expire when the file closes.

Retention and ongoing confidentiality

Data is retained for 10 years in accordance with professional and statutory record-retention requirements, under the same access controls that applied during the engagement. Confidentiality obligations under the ICAP Code of Ethics survive the end of the engagement permanently — not just for the duration of the contract.

This is the same retention and confidentiality standard applied to every MAC engagement, not a separate policy for Global Delivery clients.

Start with one file

A no-cost pilot — one month of books or ten hours of work — so you can assess the output before committing to anything. Talk to a partner to arrange one, or reach the Global Delivery team directly at global@mac.org.pk.

IVCommon questions

Questions we are asked

How long is client data retained after an engagement ends?

10 years, in accordance with professional and statutory record-retention requirements, under the same access controls that applied during the engagement.

Do confidentiality obligations end when the engagement ends?

No. Confidentiality obligations under the ICAP Code of Ethics survive the end of the engagement permanently.

Is your IT governance function outsourced?

No, it's led in-house by a certified specialist holding ISO 27001, COBIT, NIST and SOC 2 credentials.

Can data be accessed from personal devices?

No. Work is done on controlled workstations only — no removable media, no local client-data storage.

Are NDAs signed at the individual level, or just the firm level?

Both. NDAs are signed at firm and individual level.

Does this apply to every Global Delivery market?

Yes, the same standard applies across the UK, US, Canada and the Middle East.

Let's work together

Have more security questions?

A partner can walk through the specifics with your compliance or IT team before anything is scoped. There is no charge for the first conversation.