Hiring guide
Giving a fractional CFO system access without sharing every password
By CFO Index · Published
An external CFO needs enough information to do the agreed work, not unrestricted access to every system. Start with an access register that ties each permission to a task. This is an operational checklist for discussion with your IT and security owners, not a security certification.
Map the task before selecting a permission
For each system, record the required activity: view transactions, export a report, edit a forecast, prepare a payment or approve it. These are different permissions. A reporting assignment may need read-only access where the product supports it. Ask the CFO to identify any task that genuinely needs more. Keep a named internal owner responsible for granting and reviewing access.
Use individual identities and MFA
Avoid sharing the founder's credentials. Use named accounts and enable multi-factor authentication where available. NIST's small-business guidance recommends MFA and limiting access to appropriate users. Ask your security owner to choose the actual controls for your environment. Record which provider staff and subcontractors need access rather than assuming that permission for one firm should extend to everyone in it.
Keep payment approval separate from analysis
Write down who can prepare, change and authorise payments. Where possible, use the system's supported approval workflow and independent review. A CFO may identify a payment priority without needing authority to release money. Discuss emergency coverage in advance so absence does not become a reason to circulate shared credentials. Confirm the design with the person responsible for your banking controls.
Control where financial data is copied
List approved storage locations and the purpose of exports. Request aggregated or redacted data for early analysis where detailed records are unnecessary. Ask whether files will be uploaded to external AI tools or shared with subcontractors, and require approval before expanding destinations. Retention and cross-border privacy obligations depend on the facts; have the appropriate adviser review them rather than relying on this checklist.
Test the workflow with a limited first task
Start with one authorised report or reconciliation. Confirm that the CFO can complete it without requesting unrelated permissions. If exports lose important fields, solve that specific problem instead of granting administrator access by default. Keep the access register current as the scope changes. A narrow pilot also reveals whether the person expected to do the work can actually use the proposed systems.
Plan removal on the first day
Give each access entry a review owner and an end-of-engagement action. At offboarding, transfer agreed working files, revoke accounts and review connected applications or tokens through the relevant system owners. Verify completion rather than accepting a verbal statement that access is no longer used. Keep required records under your organisation's retention rules, with professional advice where necessary.