Global Delivery / Data Security & Confidentiality
The security question, answered properly.
Handing client financial data to an offshore team is a real risk, and you are right to interrogate it.
Our IT governance function is led by a certified specialist holding ISO 27001, COBIT, NIST and SOC 2 credentials and more than fifteen industry certifications — in-house, not outsourced. Confidentiality here isn't a policy document nobody reads; it's built into how the work is actually done.
We need to know exactly who can see our client data, not just that "access is controlled."
Role-based access control, permissioned per engagement, not a blanket grant.
We've been burned by a vendor that didn't take confidentiality seriously.
Signed NDAs at firm and individual level, not just a clause buried in a master agreement.
We're worried about data walking out on a USB drive or a personal laptop.
Controlled workstations — no removable media, no local client-data storage.
We need to know data is encrypted, not just "sent securely."
Encrypted transfer and storage, with audit-logged access.
Our compliance team needs to see actual certifications, not a claim.
ISO 27001, COBIT, NIST and SOC 2 credentials, held by our IT governance lead in-house.
We want to know what happens to our data after the engagement ends.
Retained for 10 years under the same access controls, with confidentiality obligations that survive permanently.
How client data is actually protected
Specific controls, not a policy statement — this is what's actually in place.
Access Control & Confidentiality Agreements
Access is scoped to the engagement, not the organisation, and backed by signed commitments at every level.
- Role-based access control, per-engagement permissioning
- Signed NDAs at firm and individual level
- Confidentiality protocols under ICAP's ethical framework
Workstation & Physical Controls
Controlled environments, not a policy that assumes good behaviour.
- Controlled workstations
- No removable media
- No local client-data storage
Encryption & Audit Logging
Every transfer and every access event is encrypted and logged, not just described as secure.
- Encrypted transfer and storage
- Audit-logged access
- ISO 27001-aligned information security practices
Governance & Certifications
Led in-house by a certified specialist, not outsourced to a third party.
- ISO 27001, COBIT, NIST and SOC 2 credentials
- Fifteen-plus industry certifications
- In-house IT governance function
This applies across every Global Delivery engagement — UK, US, Canada and the Middle East — not just the markets with formal data protection regimes.
What happens after the engagement ends
Confidentiality doesn't expire when the file closes.
Retention and ongoing confidentiality
Data is retained for 10 years in accordance with professional and statutory record-retention requirements, under the same access controls that applied during the engagement. Confidentiality obligations under the ICAP Code of Ethics survive the end of the engagement permanently — not just for the duration of the contract.
This is the same retention and confidentiality standard applied to every MAC engagement, not a separate policy for Global Delivery clients.
Start with one file
A no-cost pilot — one month of books or ten hours of work — so you can assess the output before committing to anything. Talk to a partner to arrange one, or reach the Global Delivery team directly at global@mac.org.pk.
Questions we are asked
How long is client data retained after an engagement ends?
10 years, in accordance with professional and statutory record-retention requirements, under the same access controls that applied during the engagement.
Do confidentiality obligations end when the engagement ends?
No. Confidentiality obligations under the ICAP Code of Ethics survive the end of the engagement permanently.
Is your IT governance function outsourced?
No, it's led in-house by a certified specialist holding ISO 27001, COBIT, NIST and SOC 2 credentials.
Can data be accessed from personal devices?
No. Work is done on controlled workstations only — no removable media, no local client-data storage.
Are NDAs signed at the individual level, or just the firm level?
Both. NDAs are signed at firm and individual level.
Does this apply to every Global Delivery market?
Yes, the same standard applies across the UK, US, Canada and the Middle East.
Related
Find your page
Let's work together
Have more security questions?
A partner can walk through the specifics with your compliance or IT team before anything is scoped. There is no charge for the first conversation.
