The IRS Publication 1075 / FTI Safeguards Checklist
This IRS Publication 1075 / FTI Safeguards Checklist helps you prepare for an upcoming audit. It covers exactly what federal, state, and local agencies must have in place. It also applies to any contractors or IT providers handling Federal Tax Information (FTI).
You can use this guide to prepare for your Safeguard Security Report. The IRS calls this document the SSR. It is your primary proof of compliance. You submit the SSR to the IRS Office of Safeguards.
This checklist also helps you get ready for an IRS on-site review. The IRS reviews agencies at least once every three years. We built this list to help you spot gaps before an auditor does.
Key Takeaways
- Every agency or contractor touching FTI must follow these rules.
- You must protect FTI with physical, technical, and operational controls.
- Technical rules require specific FIPS 140-validated encryption.
- You must keep audit logs for six full years.
- Access requires a strict background check and a valid need-to-know.
Not the FTC Safeguards Rule
This guide covers IRS rules for tax data. It does not cover the financial rules for auto dealers or accountants. Many people confuse the two standards. They sound very similar. However, they are completely different laws.
If you need help with financial data rules, read the FTC Safeguards Rule explainer. You can also read our main guide, What Is IRS Publication 1075?, to learn more about the tax data rules. This checklist focuses strictly on protecting FTI.
Checklist Section 1: Physical Safeguards

Physical security is your first layer of defense. You must control who can walk up to a screen or server holding FTI. The IRS requires strict physical barriers. You also need a formal process to vet your staff.
The IRS requires a Tier 2 background investigation before any employee or contractor can access FTI.
You must limit access to people who actually need the data. The IRS calls this the “need-to-know” standard. You have to document this need before you grant access. You cannot just approve people after the fact.
Background Investigations
Every person touching FTI needs a deep background check. This is the Questionnaire for Public Trust Positions. The investigation has three required parts.
Second, you must run local law enforcement checks. This covers everywhere the person lived or worked in the last five years. Third, you must verify their citizenship or work authorization.
You must renew these checks every five years. Most agencies use the FBI Rap Back program to meet this rule.
The Two-Barrier Rule
The IRS enforces a strict two-barrier rule. You must place at least two independent physical barriers between FTI and unauthorized people. The goal is to deter and detect break-ins.
A single locked door is not enough. You might use a locked door to a restricted area. Then, you place the FTI inside a separate locked cabinet.
Physical Security Checklist
Here is what you need to check off for physical safeguards.
| Requirement | What You Must Have in Place |
|---|---|
| Background Checks | Complete a Tier 2 background investigation for all FTI staff. |
| Rechecks | Renew background checks every five years. |
| Need-to-Know | Document why each person needs FTI access before granting it. |
| Two-Barrier Rule | Place at least two physical barriers between FTI and unauthorized people. |
| Internal Inspections | Create a schedule for regular internal physical security inspections. |
| Secure Media | Store and transport all physical media securely. |
Make sure your restricted areas are clearly marked. You must track visitors and escort them at all times. Do not let unvetted staff wander near FTI systems.
Checklist Section 2: Technical Safeguards
Technical controls protect FTI inside your network. These rules apply to your servers, databases, and applications. Specifically, it uses the moderate baseline.
You cannot just buy a basic antivirus program. You need enterprise-grade security tools. You also need a team to manage them. If you need help building this, look into LeadingIT’s compliance-focused managed IT services. We help Chicagoland organizations run compliant environments.
Strict Encryption Rules
The IRS does not accept basic encryption. You must use FIPS 140-validated cryptographic modules for FTI. You must encrypt this data at rest. You must also encrypt it in transit.
If you want more details on the cryptography rules, read our encryption requirements deep-dive. The IRS is very strict about FIPS 140 validation. You will fail an audit if you use unapproved encryption.
Audit Logging and Retention
You must record exactly who accesses FTI. You must also record what they do with it. The IRS requires an end-to-end audit trail.
This trail must cover the operating system layer. It must cover the database layer. It must also cover the application layer.
You face a massive storage burden for these logs. You must keep all audit log data for six full years. You cannot delete older logs to save space.
Technical Security Checklist
Review these technical controls carefully. The IRS expects exact matches for these rules.
| Requirement | What You Must Have in Place |
|---|---|
| Encryption | Use FIPS 140-validated modules for FTI at rest and in transit. |
| Multi-Factor Authentication | Require MFA for all users accessing FTI systems. |
| Configuration Management | Document system setups and track all network changes. |
| Audit Logging | Capture events across OS, database, and application layers. |
| Log Retention | Keep all audit logs for six years without exception. |
| Malware Scanning | Run active virus and malware scanning on all systems. |
Check your MFA settings today. You must enforce MFA for both local and remote access. A simple password is never enough to protect tax data.
Checklist Section 3: Operational Safeguards
Operational safeguards dictate how your team works every day. These rules cover the lifecycle of your hardware and data. You must track FTI from the moment it arrives. You must also prove you destroyed it properly.
Your agency must document the full chain of custody. You must know exactly where FTI lives in every format. This includes paper files. It includes electronic files. It includes verbal sharing. It also includes data embedded inside derived reports.
Continuous Monitoring
You cannot just set up a firewall and walk away. You must monitor your network for strange activity. The IRS requires you to use a SIEM system.
SIEM stands for Security Information and Event Management. This software collects log data from across your network. It analyzes the data in real time. It alerts your team to potential threats instantly.
Media Sanitization
Do not guess about media destruction. You must follow strict wiping standards before you throw away an old hard drive. You must sanitize any device that ever held FTI.
If a drive held tax data, it is a major risk. Treat every old server and laptop with extreme care. You need a formal written procedure for this process.
Operational Security Checklist
Use this list to verify your daily operations.
| Requirement | What You Must Have in Place |
|---|---|
| Chain of Custody | Document the complete data flow for all FTI from receipt to destruction. |
| Media Sanitization | Create a formal procedure to wipe decommissioned devices. |
| Continuous Monitoring | Deploy a SIEM system to monitor your network around the clock. |
| Incident Response | Build a plan to report breaches within 24 hours. |
Your incident response plan is critical. You must report any suspected loss of FTI very quickly. You have exactly 24 hours from discovery to notify the IRS.
You must notify both the IRS Office of Safeguards and the Treasury Inspector General for Tax Administration. Read our guide on building an FTI incident response plan for help meeting this tight deadline.
Checklist Section 4: 2025 Enhancements
New rules took effect on January 1, 2025. The IRS added these requirements to the existing NIST baseline. You must update your compliance program to match them.
You must train staff based on their specific roles. Staff must finish this training before they touch FTI. They must also retake it every single year. You will lose compliance status if training lapses.
You must also build an insider threat awareness program. You must document this program clearly. Finally, your incident response plan must be tested. You cannot just write a plan and file it away. You must rehearse it with your team.
2025 Enhancements Checklist
Review these new requirements carefully.
| Requirement | What You Must Have in Place |
|---|---|
| Role-Based Training | Train all staff on security before granting FTI access. |
| Annual Refresher | Require all staff to retake security training every year. |
| Insider Threats | Document a formal insider threat awareness program. |
| Tested Response | Rehearse your incident response plan with your actual team. |
Do not wait for an auditor to ask about these rules. Start testing your response plan today.
Checklist Section 5: Documentation and Reporting Readiness
Your paperwork must be perfect before an audit. The Safeguard Security Report is your main proof of compliance. The IRS calls this the SSR. You submit it to the IRS Office of Safeguards.
The SSR describes your processes and security controls. You must use IRS-approved encryption methods if you email your SSR. You must keep a current copy on file at all times.
You must also track your on-site review cycle. The IRS reviews agencies at least once every three years. You need to know when your next review is due.
Documentation Checklist
Make sure your files are ready for an auditor.
| Requirement | What You Must Have in Place |
|---|---|
| Current SSR | Keep an updated Safeguard Security Report on file. |
| Secure Submission | Use IRS-approved encryption when emailing the SSR. |
| Review Tracking | Track your three-year on-site review cycle dates. |
| Reporting Drill | Rehearse your 24-hour IRS and TIGTA reporting procedure. |
Your team must know exactly who to call during a breach. Rehearse the 24-hour reporting drill until it becomes automatic.
The Consolidated FTI Safeguards Checklist
Use this master table to track your progress. You can print this list and work through it with your IT team.
| Category | Requirement | Status |
|---|---|---|
| Physical | Complete Tier 2 background checks for all staff. | [ ] |
| Physical | Document the need-to-know for every user. | [ ] |
| Physical | Enforce the two-barrier rule for restricted areas. | [ ] |
| Technical | Use FIPS 140-validated encryption for all FTI. | [ ] |
| Technical | Require MFA for all local and remote access. | [ ] |
| Technical | Keep audit logs across all layers for six years. | [ ] |
| Operational | Document the full chain of custody for FTI. | [ ] |
| Operational | Deploy a SIEM for continuous network monitoring. | [ ] |
| Operational | Build a strict media sanitization procedure. | [ ] |
| 2025 Rules | Complete role-based training before granting access. | [ ] |
| 2025 Rules | Test your incident response plan with a live drill. | [ ] |
| Documentation | Keep a current Safeguard Security Report on file. | [ ] |
| Documentation | Rehearse the 24-hour breach reporting process. | [ ] |
Gap Discovery Before vs. During a Review
The IRS Office of Safeguards uses a hybrid review model. This process combines remote work with an on-site visit. The IRS conducts these reviews at least once every three years.

Finding a gap before your review is a good thing. You can fix the problem quietly. You update your controls and document the fix. You do not face a penalty for self-remediation.
Finding a gap during a review is much worse. The auditor will put the failure on your permanent record. You will also receive a Corrective Action Plan. You must then spend time and money proving you fixed the issue.
See Where You Stand
Free 2-minute IRS Pub 1075 / FTI Safeguards Risk-Check: run your current setup against this checklist in plain English and see exactly which gaps to close first. No sign-up to see your result. Take the Free FTI Safeguards Risk-Check
Related Guides
- What Is IRS Publication 1075? The Plain-English Guide to FTI Safeguards
- What Is the FTC Safeguards Rule? (Not the Same as IRS Pub 1075)
Frequently Asked Questions
Every federal, state, and local government agency that receives FTI must comply. This obligation also flows down to their contractors. Any cloud service provider or data center touching FTI must follow the rules.
FTI is a tax return or return information obtained from a taxpayer or the IRS. It must be protected in every format. This includes paper files, electronic data, verbal conversations, and derived reports.
There is no official certification a business can buy. Agencies prove compliance through their Safeguard Security Report. They also prove it during their IRS on-site reviews.
You must report any suspected loss or theft of FTI within 24 hours of discovery. You must notify the IRS Office of Safeguards. You must also notify the Treasury Inspector General for Tax Administration.
You must place at least two independent physical barriers between FTI and unauthorized people. A single locked door is not enough. You need a locked door to a restricted area plus a locked cabinet inside.
Secure Your FTI Environment Today
Managing IRS compliance takes constant work. You cannot afford to fail an on-site review. LeadingIT helps you become and stay compliant. We are a Chicagoland managed IT and cybersecurity provider with offices in Woodstock and Manteno.
We operate the technical controls your agency needs to pass an audit. We manage your MFA, FIPS 140-validated encryption, and SIEM monitoring. Reach out to contact us or book a call today to secure your network.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
