Mandatory MFA should be required for every user accessing the accounting software.
Employees should operate on a "least privilege" basis, meaning they only see the specific client data required to do their job. how secured is your outsourced bookkeeping operations?
Give your bookkeeper "view-only" access to bank accounts. They do not need the authority to transfer funds or wire money. Mandatory MFA should be required for every user