Law and Accounting Office Cleaning in NJ: Key Control, Alarm Codes, and the Duty a Vendor's Confidentiality Agreement Does Not Discharge
By Chris, Owner
Published September 13, 2026
A key, a code, and a room full of files
The arrangement is usually settled in about five minutes. Someone hands over a key, writes the alarm code on a card, mentions that the corner office stays locked, and the cleaning starts the following week. Two decisions get made in those five minutes, usually without being recognized as decisions: which rooms the crew can enter, and which credential each person carries.
A vendor's agreement helps establish its obligation to protect information. It does not discharge the firm's own duty to take reasonable precautions against unauthorized access, including access to rooms the crew can unlock but has no reason to enter.
New Jersey's Rules of Professional Conduct and the ethics opinions interpreting them do not address cleaning contractors, building staff, or after-hours access by name. What they address is unauthorized access to client information, without regard to how it happens. RPC 1.6(f) obliges the lawyer to make reasonable efforts against inadvertent or unauthorized disclosure, and against unauthorized access to information relating to a representation. The wording turns on access, and it does not distinguish a server from a file room.
What signing the vendor's confidentiality agreement settles
It settles something real. ACPE Opinion 701 reaches information entrusted outside the firm even temporarily, and requires that the outside party be aware of the lawyer's confidentiality obligation and be under an enforceable obligation to help preserve it, "whether by contract, professional standards, or otherwise." A written agreement is the ordinary way to create one; the opinion does not say it is the only way.
What it does not do is move the duty. Under Opinion 701 the outside party's obligation is a condition of the lawyer's own reasonable care rather than a substitute for it, and nothing in the confidentiality or supervision rules provides for transferring or ending that duty by agreement with a third party.
Opinion 701 is also clear that the standard is one of care rather than result. A lawyer can no more guarantee that client information will be invulnerable to unauthorized access than guarantee that a burglar will not break into the file room. What gets examined afterward is the precautions taken.
An undertaking to preserve confidentiality does not tell you whether the key you issued opens the records room, or whether a replacement crew member will use the same alarm code.
New Jersey's supervision rule, RPC 5.3, reaches a nonlawyer employed or retained by or associated with a lawyer, but whether it extends to a building-services contractor rather than a vendor engaged on firm matters is a question New Jersey has not addressed. The access duty does not depend on the answer.
Tax preparation brings in a federal rule with three parts
Accounting practices work under a different regime, more specific than the ethics rules and federal rather than state. New Jersey's accountancy rules on client confidentiality and records, and the confidentiality provision in the Accountancy Act, address consent to disclosure and a client's right to obtain records; none imposes a physical-security or vendor-access requirement of the kind discussed here.
The FTC Safeguards Rule treats tax preparation as a financial activity, which makes a firm in the business of completing income tax returns a financial institution under it. The trigger is the tax work rather than the CPA license. See 16 CFR 314.1(b) and 314.2(h)(2).
Physical security is inside the rule. Covered firms must maintain a written information-security program under 314.3(a); 314.4(c)(1) covers technical and, as appropriate, physical access controls; 314.4(c)(2) includes facilities among the resources to manage; and customer information is defined to include paper records. Much of the surrounding subsection is information-systems material, so this is no physical-security code, but paper and premises are within its reach.
The Safeguards Rule defines a service provider by reference to whether it is permitted access to customer information through services it provides to the firm; the FTC has not published guidance applying that definition to building-services vendors, which leaves the judgment with the firm. A vendor with a key and unescorted after-hours access to a room of open files is, factually, permitted access. Whether that access comes through its provision of services is the arguable part, and the firm has to make the call and defend it.
If the vendor falls within the definition, 314.4(f) requires the firm to:
- take reasonable steps to select and retain a provider capable of maintaining appropriate safeguards;
- require that provider by contract to implement and maintain those safeguards; and
- periodically assess the provider against the risk it presents and the continued adequacy of its safeguards.
The third limb starts after the contract is signed, which calls for a decision about how changes in access and personnel will be reviewed rather than treating the opening paperwork as the assessment.
Small practices should not assume they are outside this. As Part 314 reads in 2026, the exception for institutions maintaining customer information concerning fewer than five thousand consumers exempts only 314.4(b)(1), (d)(2), (h) and (i): the written risk assessment, continuous monitoring or penetration testing, the incident-response plan, and the annual governing-body report. Neither the access controls in (c) nor provider oversight in (f) is exempted, and the threshold counts consumers whose information is maintained, not partners in the office. A two-partner tax practice in Hackensack owes both in full. See 16 CFR 314.6.
The IRS written-plan template at Publication 5708 carries the most concrete physical-security language a firm is likely to find: restricted access to areas where personal information is stored, including file rooms and cabinets; escorted visitors inside restricted areas; paper records secured when not in use; surrender of all keys and access codes on termination. Those examples belong to the template, not to Part 314, which enumerates no physical control at all. The template never mentions cleaning or custodial staff, while describing controls that an after-hours crew with a key touches at several points.
A "Do Not Duplicate" stamp is not a control
A "Do Not Duplicate" stamp is an instruction to whoever is asked to cut the copy. It is not a control, because it is not what determines whether a copy can be made.
What determines that is the blank. A conventional keyway's blanks are stocked by hardware stores and by locksmiths generally, so possession of the key is usually enough to have it copied. A restricted keyway works because the blank is not sold through open channels; Natural Resources Canada's Key Control Plan Guideline defines the restriction in terms of duplication and availability. A key machine cannot cut a blank it cannot get. Ask whoever administers the locks whether the issued key runs on a restricted keyway, because the stamp does not establish that it does.
The second decision is which key. ANSI/BHMA A156.28 defines masterkeying as combinating a group of cylinders so each is operated by its own change key and by a master key for the whole group, and cautions that this leaves a cylinder more susceptible to manipulation and increases the number of keys that operate it. A change key operates one cylinder. A master handed to a vendor opens every door the master opens, including doors nobody intended to include, and if it is lost or copied the exposure runs to all of them. That is the reach of the key, not a separate legal rule about vendors.
The administrative half is what a firm will wish it had: keys individually numbered, a record of who holds which one signed by the holder and by whoever authorized it, and a return arrangement that takes effect when access ends.
Alarm codes, and who the panel says disarmed it
Commercial alarm systems can support individual user codes, arm-and-disarm event records, and partitioning that lets a user disarm only part of a building. Capabilities depend on the installed system, so ask the alarm administrator what this panel records and which areas the proposed code can disarm.
One shared code given to a vendor gives up both. The log shows that someone using that code disarmed the system, without distinguishing among the people who know it, and the code cannot be withdrawn from one person without changing it for everyone who has it.
There is a local wrinkle. In the Bergen County ordinances reviewed, including Hackensack, Paramus, Fort Lee, and Teaneck, the alarm permit and the responsibility for false alarms sit with the alarm user rather than with whoever tripped it. Teaneck's false-alarm definition names the owner's employees or agents specifically. A vendor agreement can allocate responsibility between the parties, but it does not change whom the municipality holds responsible, so agree in advance on who the crew calls when the panel goes off.
The limits of an access record
An access record can establish which credential, code, or key was used, at which point, and when.
It cannot establish who was holding the credential. NIST SP 800-116 distinguishes authenticating a credential from establishing a person's identity and authorization. It cannot say anything about a door with no logging mechanism. A key-issuance log establishes custody rather than every use of the key, and an alarm disarm event does not establish that anyone entered a particular room inside the disarmed area.
None of that argues against having the record. It argues for setting it up while there is nothing to investigate, because a firm's ability to answer later is fixed when the credentials are issued.
Naming the rooms is the easy part
Published institutional specifications show the pattern. The GSA's National Custodial Specification carves laboratories, health units, restricted areas, and containment spaces out of custodial scope entirely and treats key control as a defined contractor responsibility; its National Consolidated Maintenance Specification adds key logs and restrictions on transferring keys. These are institutional arrangements, not rules binding a New Jersey professional office.
What those specifications leave to the buyer is the connection between four things: the named rooms, who holds the key, what happens to ordinary trash generated inside them, and who is responsible for the shred bin. A firm has to connect them for its own premises, because the last three are what quietly reopen an exclusion. A room that is out of scope still fills a wastebasket. Somebody empties it, and if the scope never said who, the answer is whoever is standing there.
Confidential waste is the sharpest version. McMaster University's waste guidance assigns it to the occupant or department rather than housekeeping. New Jersey ethics authority points the same direction: Opinion 692 requires that the destruction of client files conform to RPC 1.6 and says placing them in the trash is insufficient. That bears directly on what may go into the ordinary waste stream.
Bergen's scope for law and accounting accounts is built on that logic. Desks are a no-touch zone, so papers are never moved, stacked, read, or discarded. Locked offices stay secured per the firm's rules. Shredding bins and their contents are never touched. Those lines are worth writing into any vendor's scope, because an exclusion that is not written down is a preference.
New Jersey's identity-theft statute will not fill the gap either. N.J.S.A. 56:8-162 governs the destruction of customers' records containing the statute's defined personal information once they are no longer to be retained, which makes it a disposal provision rather than an in-use access rule, and it does not reach every confidential document simply because the firm considers it sensitive. The same statute imposes no notification duty when a paper file is exposed; its breach-notification provision runs to computerized records. The federal Disposal Rule has the same shape: 16 CFR 682.3(a) reaches firms holding consumer-report information, attorneys included on the FTC's own list of covered entities, but binds only the measures taken in connection with disposal.
Bonded, insured, and certificate on file
Three documents get collected at the start of a vendor relationship, and each covers less than its name suggests.
The Surety and Fidelity Association of America describes today's fidelity bonds as two-party insurance policies, protecting the employer rather than its customer. ISO crime form CR 00 23 11 15 says the policy benefits the insured, gives no rights to any other person or organization, and requires the insured to present the claim. If a firm's property goes missing, the firm cannot bring that claim; separate Clients' Property coverage is what reaches a customer's belongings. What the form does not impose is a conviction requirement: the base Employee Theft agreement responds whether or not the individual is identified.
General liability does not fill the gap. ISO CG 00 01 defines an occurrence as an accident, and exclusion j. addresses personal property in the insured's care, custody, or control. There is no blanket dishonest-acts exclusion; theft is simply not what the form was built to answer. The specific policy governs.
The certificate of insurance is evidence and nothing more. ACORD 25 confers no rights, does not amend coverage, and is not a contract. Under ISO IL C 001 11 11, additional-insured status must come from an endorsement or from specific policy language; a certificate alone cannot create it.
What a firm can require is contractual. GSA's National Consolidated Maintenance Specification and Augusta, Georgia's published janitorial contract both carry the useful clauses: a key control log and a bar on transferring keys, contractor liability for re-keying where key integrity is lost, notice before substituting assigned personnel, and removal of a worker on request. Those are negotiated terms, not legal minimums applying to every cleaning vendor.
Two questions are worth asking alongside them:
- Ask what a certification actually certifies. CIMS, the cleaning industry's main management-systems certification, is administered by ISSA, a not-for-profit trade association, and participation is voluntary. It is not a government license or an accreditation. Across ISSA's published certifications and standards, none addresses building security or key control, so a certification logo answers a different question than the one a firm handing over a key is asking.
- Ask what happens when the crew assigned to the account changes. A key issued to one person, and a code shared among several, both outlive whoever first received them. The published contracts above require notice before assigned personnel are substituted. What follows from that is the firm's own question: who withdraws the old access, and how the firm learns the change happened at all.
Decide these two things before the first visit
Which rooms are out of scope, and which credential each person gets. Settle the ordinary-waste and confidential-waste assignments for those rooms at the same time, and do it before access is distributed rather than after.
Bergen's law and accounting office cleaning service signs the firm's own NDA or vendor confidentiality terms before the first visit, and budgeting for professional offices is covered in the pricing guide. If a scope is ready to price, request a quote.