I haven't tried it for accounting but I do know that with authorization we can add a separate authorization server (e..g ISE) from the authentication server (e.g. SAML). Just specify the accounting server separately in the tunnel-group (known as Connection Profile is ASDM).
Firewall config:
Specify server group and the host with key
aaa-server TACACS protocol tacacs+
aaa-server TACACS (inside) host <address>
key *****
Specify the accounting server group under the general attributes for the tunnel group:
tunnel-group <TG-name> general-attributes
accounting-server-group TACACS
(It could alternatively be a RADIUS server.)