The FTC Safeguards Rule for Tax Preparers and CPA Firms: Are You Covered?

If you handle client tax returns, the FTC safeguards rule for tax preparers treats your business as a financial institution. This means your tax preparation firm or CPA practice must comply with strict federal cybersecurity mandates under the Gramm-Leach-Bliley Act (GLBA).
The Gramm-Leach-Bliley Act is a 1999 US federal law that requires financial institutions to explain how they share and protect their customers’ nonpublic personal information. Its data security piece is implemented for non-bank businesses by the FTC Safeguards Rule (16 CFR Part 314).
The FTC Safeguards Rule requires non-bank financial institutions under FTC jurisdiction to develop, implement, and maintain a comprehensive written information security program to protect customer information. The Rule has tightened steadily, and every deadline that matters to your firm has already passed:
| Date | What Changed |
|---|---|
| 1999 | The Gramm-Leach-Bliley Act (GLBA) becomes federal law. |
| 2021 | The FTC amends the Safeguards Rule. |
| June 9, 2023 | The key prescriptive provisions of the amended Rule become mandatory. |
| May 13, 2024 | The breach notification requirement takes effect. Covered businesses must report to the FTC, within 30 days of discovery, any security event involving the unencrypted information of 500 or more consumers. |
Many firm owners are surprised to learn they fall under these regulations. If you run a tax practice, you hold a massive amount of highly sensitive financial and personal data. Hackers know this, and federal regulators know this. You are required by law to lock that data down.
Tax Preparation and Accounting Firms Are Covered Financial Institutions
The Rule covers non-bank financial institutions as the FTC defines them. This broad definition catches many business owners off guard. Use the quick check below to see whether your business type is on the list.
| Business Type | Covered by the Safeguards Rule? |
|---|---|
| Tax preparation firms | Yes |
| Accountants and CPA firms | Yes |
| Auto dealers that arrange financing | Yes |
| Mortgage brokers | Yes |
| Payday lenders | Yes |
| Debt collectors | Yes |
| Real estate settlement services | Yes |
If your business is significantly engaged in providing financial products or services to consumers, you must assume you are covered until proven otherwise. The GLBA requirements for accounting firms are not optional guidelines. They are mandatory federal regulations.
Unlike some industry standards, the Safeguards Rule is enforced directly by the federal government. The FTC can investigate your firm, bring enforcement actions, impose consent orders with years of oversight obligations, and seek civil penalties.
Achieving FTC Safeguards Rule compliance CPA firm status means you must treat your IT infrastructure with the same level of security as a regional bank. You can no longer rely on basic antivirus software and a consumer-grade router. You must implement enterprise-grade security controls, document your policies, and prove that you are actively protecting your clients’ financial data.
The IRS Connection: E-file Providers and the WISP Expectation
While the FTC enforces the Safeguards Rule, the Internal Revenue Service (IRS) serves as the primary enforcement mechanism for many tax professionals. The IRS states that data security is now a necessity for every tax professional, from sole practitioners to Authorized IRS e-File Providers. When you renew your PTIN or apply to become an authorized IRS e-file provider, you must acknowledge your responsibility to protect client data.
The IRS security requirements for tax preparers align directly with the FTC mandates. In fact, many tax professionals first hear the acronym WISP when reading IRS guidance on e-file requirements. The written information security program (WISP) is the core Safeguards Rule deliverable. It is a written document describing how your business protects customer information, built on a written risk assessment, and covering all required technical safeguards.
IRS Publication 4557 guidelines provide a framework for safeguarding taxpayer data, but they point back to your legal obligations under the FTC Safeguards Rule. The IRS expects every e-file provider to have a documented data security plan for tax preparers in place. Failing to meet these protecting taxpayer data requirements carries severe consequences.
Beyond FTC civil penalties, tax preparer data breach penalties can include IRS investigations and potential suspension of your PTIN or e-file privileges, putting your ability to prepare returns at risk.
The FTC Safeguards Rule’s Nine Elements Translated to a Tax Office
Section 314.4 of the FTC Safeguards Rule requires nine specific elements. Meeting these requirements means translating technical mandates into the daily operations of a tax office.
Your firm deals with client Social Security numbers on a daily basis, relies on seasonal staff, uses client document portals, and heavily utilizes specialized tax software. Here is how the nine elements apply to your practice, as a checklist you can work through one item at a time.
- 1. Designate a Qualified Individual. Name a single person to implement and supervise your information security program. It can be an employee, or a person at an affiliate or service provider. Because most tax firms lack an internal IT department, many covered SMBs designate a role supported by their managed service provider (MSP). Your business always retains legal responsibility for compliance.
- 2. Base the program on a written risk assessment. You cannot protect data if you do not know where it lives. Conduct a formal, written risk assessment to identify internal and external risks to the security, confidentiality, and integrity of customer information. For a tax firm, this means evaluating how you collect W-2s, where you store completed returns, and who has access to your tax preparation software.
- 3. Implement specific technical safeguards. This is the most technically demanding element of cybersecurity for tax preparers. Implement access controls, maintain a data inventory, and use secure development practices. The amended Rule specifically requires encryption of customer information both at rest and in transit, plus multi-factor authentication (MFA) for any individual accessing any information system that holds customer information, unless the Qualified Individual approves in writing a reasonably equivalent control. In practice, that means MFA on your tax software, your email, your document portals, and your remote desktop access. You must also ensure the secure disposal of customer information no longer needed, manage system changes securely, and monitor authorized user activity.
- 4. Regularly test the safeguards. Prove your defenses actually work. The Rule requires either continuous monitoring of your systems or annual penetration testing coupled with vulnerability assessments at least every six months. If you host your own servers or allow remote access for staff, this testing is critical to find loopholes before hackers do.|
- 5. Train staff on security awareness. Human error is the top cybersecurity risk facing tax professionals, per the IRS Security Summit. Train your staff on security awareness and update that training as threats evolve. This is especially critical for tax firms that hire seasonal administrative staff or temporary preparers during the spring rush. Seasonal workers are prime targets for phishing emails disguised as urgent client documents.
- 6. Oversee service providers. You are responsible for the vendors you use. Oversee service providers by contract and periodic assessment. Verify the security practices of your cloud storage providers, your IT support vendors, and the companies that build your tax preparation software.
- 7. Keep the program current. The written information security plan tax professionals rely on is a living document. If you open a new branch office, switch to a new cloud-based tax platform, or hire a new IT vendor, update your WISP and your risk assessment accordingly.
- 8. Maintain a written incident response plan. Document exactly what to do if a breach occurs, including internal processes for responding to a security event, roles and responsibilities, and communication strategies. The plan must also account for the 30-day FTC breach reporting requirement covered in the timeline above.
- 9. Report to the board annually. The Qualified Individual must report in writing to your board of directors or senior leadership at least annually. The report must detail the overall status of the information security program and your compliance with the Rule, so the firm’s owners remain fully aware of their cybersecurity posture.
Off-Season is the Time to Fix This
Tax season is chaotic. Between January and April, your sole focus is processing returns and serving your clients. You do not have the time or bandwidth to overhaul your IT infrastructure, deploy new MFA protocols, or write a comprehensive WISP for tax preparers during the busy season.
The off-season is the time to fix your compliance gaps. The months between May and November provide the operational breathing room necessary to conduct a proper risk assessment, implement encryption standards, and train your staff. Waiting until December to address your FTC obligations guarantees a rushed, stressful, and likely incomplete implementation just as your busy season begins.
The compliance lifecycle for a tax firm follows the calendar year:
- January-April (Tax Season). Focus on processing returns. Compliance work is on hold.
- May-June (Post-Season). Conduct or update your formal written risk assessment.
- July-August (Mid Off-Season). Draft or revise your WISP. Implement technical safeguards: MFA, encryption, monitoring, access controls.
- September-October (Pre-Filing Season). Train your staff and test your safeguards. Run vulnerability assessments.
- November-December (Year-End). Submit the annual report to leadership. Verify everything is current before the next tax season begins.
LeadingIT is a Chicagoland managed it and cybersecurity provider that has helped Illinois businesses since 2010. We serve roughly 200 organizations and 2,500+ users from our offices in Woodstock and Manteno.
LeadingIT implements and operates the technical safeguards the Rule requires, including MFA, encryption, continuous monitoring, testing, and incident response planning. We can serve as or support your Qualified Individual role, taking the technical burden off your shoulders so you can focus on your accounting practice. LeadingIT does not “certify” FTC compliance (no such certification exists), but we help you become and stay compliant with every technical mandate.
See Where You Stand
Free 2-minute Safeguards Rule self-check: 8 plain-English questions, your risk level and the gaps to fix. No sign-up to see your result. free Safeguards Rule compliance self-assessment
Related Guides
- What Is the Gramm-Leach-Bliley Act (GLBA)? Plain English
- How to Write a WISP for the FTC Safeguards Rule
- GLBA Compliance: Who it Covers and What it Requires
- What Is the FTC Safeguards Rule? Who it Covers, What Changed
Frequently Asked Questions
What does the FTC safeguards rule require all tax preparers to do?
The Rule requires tax preparers to develop, implement, and maintain a comprehensive written information security program (WISP). You must also designate a Qualified Individual to oversee the program and conduct a formal written risk assessment. Additionally, you must implement specific technical controls like multi-factor authentication and data encryption.
What are the requirements for the FTC safeguards rule?
Covered businesses must fulfill nine specific elements outlined in Section 314.4 of the Rule. These include designating a Qualified Individual, performing risk assessments, implementing technical safeguards, testing those safeguards regularly, and training staff. You must also oversee your service providers, maintain an incident response plan, keep your program updated, and submit an annual written report to senior leadership.
Is WISP mandatory for tax preparers?
Yes, a written information security program is a mandatory legal requirement under the FTC Safeguards Rule. The IRS also expects all paid tax preparers with a PTIN to have a data security plan in place. Failing to maintain a WISP can result in federal investigations, civil penalties, and the revocation of your e-file privileges.
What are examples of safeguards?
Technical safeguards required by the Rule include multi-factor authentication (MFA) for anyone accessing customer information and the encryption of customer data both at rest and in transit. Other examples include strict access controls, continuous system monitoring, secure disposal of unneeded data, and regular vulnerability assessments.
What is the customer safeguard rule?
The FTC Safeguards Rule (16 CFR Part 314) is a federal regulation enacted under the Gramm-Leach-Bliley Act. It requires non-bank financial institutions to actively protect the security, confidentiality, and integrity of consumer data. The rule applies to a wide range of businesses, including tax preparation firms, CPA practices, mortgage brokers, and auto dealers.
Secure Your Firm and Stay Compliant
Protecting your clients’ financial data is federal law, and it is also good business practice. If you need help building your WISP or deploying the required technical controls, explore LeadingIT’s FTC Safeguards compliance services. To discuss your firm’s specific compliance gaps, book a call or contact us directly at 815-788-6041.
