Global Delivery / Data Security & Confidentiality
Handing client financial data to an offshore team is a real risk, and you are right to interrogate it.
Our IT governance function is led by a certified specialist holding ISO 27001, COBIT, NIST and SOC 2 credentials and more than fifteen industry certifications — in-house, not outsourced. Confidentiality here isn't a policy document nobody reads; it's built into how the work is actually done.
We need to know exactly who can see our client data, not just that "access is controlled."
Role-based access control, permissioned per engagement, not a blanket grant.
We've been burned by a vendor that didn't take confidentiality seriously.
Signed NDAs at firm and individual level, not just a clause buried in a master agreement.
We're worried about data walking out on a USB drive or a personal laptop.
Controlled workstations — no removable media, no local client-data storage.
We need to know data is encrypted, not just "sent securely."
Encrypted transfer and storage, with audit-logged access.
Our compliance team needs to see actual certifications, not a claim.
ISO 27001, COBIT, NIST and SOC 2 credentials, held by our IT governance lead in-house.
We want to know what happens to our data after the engagement ends.
Retained for 10 years under the same access controls, with confidentiality obligations that survive permanently.
Specific controls, not a policy statement — this is what's actually in place.
Access is scoped to the engagement, not the organisation, and backed by signed commitments at every level.
Controlled environments, not a policy that assumes good behaviour.
Every transfer and every access event is encrypted and logged, not just described as secure.
Led in-house by a certified specialist, not outsourced to a third party.
This applies across every Global Delivery engagement — UK, US, Canada and the Middle East — not just the markets with formal data protection regimes.
Confidentiality doesn't expire when the file closes.
Data is retained for 10 years in accordance with professional and statutory record-retention requirements, under the same access controls that applied during the engagement. Confidentiality obligations under the ICAP Code of Ethics survive the end of the engagement permanently — not just for the duration of the contract.
This is the same retention and confidentiality standard applied to every MAC engagement, not a separate policy for Global Delivery clients.
A no-cost pilot — one month of books or ten hours of work — so you can assess the output before committing to anything. Talk to a partner to arrange one, or reach the Global Delivery team directly at global@mac.org.pk.
10 years, in accordance with professional and statutory record-retention requirements, under the same access controls that applied during the engagement.
No. Confidentiality obligations under the ICAP Code of Ethics survive the end of the engagement permanently.
No, it's led in-house by a certified specialist holding ISO 27001, COBIT, NIST and SOC 2 credentials.
No. Work is done on controlled workstations only — no removable media, no local client-data storage.
Both. NDAs are signed at firm and individual level.
Yes, the same standard applies across the UK, US, Canada and the Middle East.
Related
Let's work together
A partner can walk through the specifics with your compliance or IT team before anything is scoped. There is no charge for the first conversation.