Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

The IRS Publication 1075 / FTI Safeguards Checklist

August 11, 2026
hero-irs-1075-fti-safeguards-checklist-1.png

This IRS Publication 1075 / FTI Safeguards Checklist helps you prepare for an upcoming audit. It covers exactly what federal, state, and local agencies must have in place. It also applies to any contractors or IT providers handling Federal Tax Information (FTI).

You can use this guide to prepare for your Safeguard Security Report. The IRS calls this document the SSR. It is your primary proof of compliance. You submit the SSR to the IRS Office of Safeguards.

This checklist also helps you get ready for an IRS on-site review. The IRS reviews agencies at least once every three years. We built this list to help you spot gaps before an auditor does.

Key Takeaways

  • Every agency or contractor touching FTI must follow these rules.
  • You must protect FTI with physical, technical, and operational controls.
  • Technical rules require specific FIPS 140-validated encryption.
  • You must keep audit logs for six full years.
  • Access requires a strict background check and a valid need-to-know.

Not the FTC Safeguards Rule

This guide covers IRS rules for tax data. It does not cover the financial rules for auto dealers or accountants. Many people confuse the two standards. They sound very similar. However, they are completely different laws.

If you need help with financial data rules, read the FTC Safeguards Rule explainer. You can also read our main guide, What Is IRS Publication 1075?, to learn more about the tax data rules. This checklist focuses strictly on protecting FTI.

Checklist Section 1: Physical Safeguards

Diagram of the IRS Publication 1075 two-barrier rule: a locked door to a restricted area, then a separate locked cabinet inside it, to deter and detect break-ins.

Physical security is your first layer of defense. You must control who can walk up to a screen or server holding FTI. The IRS requires strict physical barriers. You also need a formal process to vet your staff.

The IRS requires a Tier 2 background investigation before any employee or contractor can access FTI.

You must limit access to people who actually need the data. The IRS calls this the “need-to-know” standard. You have to document this need before you grant access. You cannot just approve people after the fact.

Background Investigations

Every person touching FTI needs a deep background check. This is the Questionnaire for Public Trust Positions. The investigation has three required parts.

Second, you must run local law enforcement checks. This covers everywhere the person lived or worked in the last five years. Third, you must verify their citizenship or work authorization.

You must renew these checks every five years. Most agencies use the FBI Rap Back program to meet this rule.

The Two-Barrier Rule

The IRS enforces a strict two-barrier rule. You must place at least two independent physical barriers between FTI and unauthorized people. The goal is to deter and detect break-ins.

A single locked door is not enough. You might use a locked door to a restricted area. Then, you place the FTI inside a separate locked cabinet.

Physical Security Checklist

Here is what you need to check off for physical safeguards.

RequirementWhat You Must Have in Place
Background ChecksComplete a Tier 2 background investigation for all FTI staff.
RechecksRenew background checks every five years.
Need-to-KnowDocument why each person needs FTI access before granting it.
Two-Barrier RulePlace at least two physical barriers between FTI and unauthorized people.
Internal InspectionsCreate a schedule for regular internal physical security inspections.
Secure MediaStore and transport all physical media securely.

Make sure your restricted areas are clearly marked. You must track visitors and escort them at all times. Do not let unvetted staff wander near FTI systems.

Checklist Section 2: Technical Safeguards

Technical controls protect FTI inside your network. These rules apply to your servers, databases, and applications. Specifically, it uses the moderate baseline.

You cannot just buy a basic antivirus program. You need enterprise-grade security tools. You also need a team to manage them. If you need help building this, look into LeadingIT’s compliance-focused managed IT services. We help Chicagoland organizations run compliant environments.

Strict Encryption Rules

The IRS does not accept basic encryption. You must use FIPS 140-validated cryptographic modules for FTI. You must encrypt this data at rest. You must also encrypt it in transit.

If you want more details on the cryptography rules, read our encryption requirements deep-dive. The IRS is very strict about FIPS 140 validation. You will fail an audit if you use unapproved encryption.

Audit Logging and Retention

You must record exactly who accesses FTI. You must also record what they do with it. The IRS requires an end-to-end audit trail.

This trail must cover the operating system layer. It must cover the database layer. It must also cover the application layer.

You face a massive storage burden for these logs. You must keep all audit log data for six full years. You cannot delete older logs to save space.

Technical Security Checklist

Review these technical controls carefully. The IRS expects exact matches for these rules.

RequirementWhat You Must Have in Place
EncryptionUse FIPS 140-validated modules for FTI at rest and in transit.
Multi-Factor AuthenticationRequire MFA for all users accessing FTI systems.
Configuration ManagementDocument system setups and track all network changes.
Audit LoggingCapture events across OS, database, and application layers.
Log RetentionKeep all audit logs for six years without exception.
Malware ScanningRun active virus and malware scanning on all systems.

Check your MFA settings today. You must enforce MFA for both local and remote access. A simple password is never enough to protect tax data.

Checklist Section 3: Operational Safeguards

Operational safeguards dictate how your team works every day. These rules cover the lifecycle of your hardware and data. You must track FTI from the moment it arrives. You must also prove you destroyed it properly.

Your agency must document the full chain of custody. You must know exactly where FTI lives in every format. This includes paper files. It includes electronic files. It includes verbal sharing. It also includes data embedded inside derived reports.

Continuous Monitoring

You cannot just set up a firewall and walk away. You must monitor your network for strange activity. The IRS requires you to use a SIEM system.

SIEM stands for Security Information and Event Management. This software collects log data from across your network. It analyzes the data in real time. It alerts your team to potential threats instantly.

Media Sanitization

Do not guess about media destruction. You must follow strict wiping standards before you throw away an old hard drive. You must sanitize any device that ever held FTI.

If a drive held tax data, it is a major risk. Treat every old server and laptop with extreme care. You need a formal written procedure for this process.

Operational Security Checklist

Use this list to verify your daily operations.

RequirementWhat You Must Have in Place
Chain of CustodyDocument the complete data flow for all FTI from receipt to destruction.
Media SanitizationCreate a formal procedure to wipe decommissioned devices.
Continuous MonitoringDeploy a SIEM system to monitor your network around the clock.
Incident ResponseBuild a plan to report breaches within 24 hours.

Your incident response plan is critical. You must report any suspected loss of FTI very quickly. You have exactly 24 hours from discovery to notify the IRS.

You must notify both the IRS Office of Safeguards and the Treasury Inspector General for Tax Administration. Read our guide on building an FTI incident response plan for help meeting this tight deadline.

Checklist Section 4: 2025 Enhancements

New rules took effect on January 1, 2025. The IRS added these requirements to the existing NIST baseline. You must update your compliance program to match them.

You must train staff based on their specific roles. Staff must finish this training before they touch FTI. They must also retake it every single year. You will lose compliance status if training lapses.

You must also build an insider threat awareness program. You must document this program clearly. Finally, your incident response plan must be tested. You cannot just write a plan and file it away. You must rehearse it with your team.

2025 Enhancements Checklist

Review these new requirements carefully.

RequirementWhat You Must Have in Place
Role-Based TrainingTrain all staff on security before granting FTI access.
Annual RefresherRequire all staff to retake security training every year.
Insider ThreatsDocument a formal insider threat awareness program.
Tested ResponseRehearse your incident response plan with your actual team.

Do not wait for an auditor to ask about these rules. Start testing your response plan today.

Checklist Section 5: Documentation and Reporting Readiness

Your paperwork must be perfect before an audit. The Safeguard Security Report is your main proof of compliance. The IRS calls this the SSR. You submit it to the IRS Office of Safeguards.

The SSR describes your processes and security controls. You must use IRS-approved encryption methods if you email your SSR. You must keep a current copy on file at all times.

You must also track your on-site review cycle. The IRS reviews agencies at least once every three years. You need to know when your next review is due.

Documentation Checklist

Make sure your files are ready for an auditor.

RequirementWhat You Must Have in Place
Current SSRKeep an updated Safeguard Security Report on file.
Secure SubmissionUse IRS-approved encryption when emailing the SSR.
Review TrackingTrack your three-year on-site review cycle dates.
Reporting DrillRehearse your 24-hour IRS and TIGTA reporting procedure.

Your team must know exactly who to call during a breach. Rehearse the 24-hour reporting drill until it becomes automatic.

The Consolidated FTI Safeguards Checklist

Use this master table to track your progress. You can print this list and work through it with your IT team.

CategoryRequirementStatus
PhysicalComplete Tier 2 background checks for all staff.[ ]
PhysicalDocument the need-to-know for every user.[ ]
PhysicalEnforce the two-barrier rule for restricted areas.[ ]
TechnicalUse FIPS 140-validated encryption for all FTI.[ ]
TechnicalRequire MFA for all local and remote access.[ ]
TechnicalKeep audit logs across all layers for six years.[ ]
OperationalDocument the full chain of custody for FTI.[ ]
OperationalDeploy a SIEM for continuous network monitoring.[ ]
OperationalBuild a strict media sanitization procedure.[ ]
2025 RulesComplete role-based training before granting access.[ ]
2025 RulesTest your incident response plan with a live drill.[ ]
DocumentationKeep a current Safeguard Security Report on file.[ ]
DocumentationRehearse the 24-hour breach reporting process.[ ]

Gap Discovery Before vs. During a Review

The IRS Office of Safeguards uses a hybrid review model. This process combines remote work with an on-site visit. The IRS conducts these reviews at least once every three years.

Matrix comparing outcomes when an FTI safeguards gap is found before an IRS review versus during an IRS review.

Finding a gap before your review is a good thing. You can fix the problem quietly. You update your controls and document the fix. You do not face a penalty for self-remediation.

Finding a gap during a review is much worse. The auditor will put the failure on your permanent record. You will also receive a Corrective Action Plan. You must then spend time and money proving you fixed the issue.

See Where You Stand

Free 2-minute IRS Pub 1075 / FTI Safeguards Risk-Check: run your current setup against this checklist in plain English and see exactly which gaps to close first. No sign-up to see your result. Take the Free FTI Safeguards Risk-Check

Frequently Asked Questions

Every federal, state, and local government agency that receives FTI must comply. This obligation also flows down to their contractors. Any cloud service provider or data center touching FTI must follow the rules.

FTI is a tax return or return information obtained from a taxpayer or the IRS. It must be protected in every format. This includes paper files, electronic data, verbal conversations, and derived reports.

There is no official certification a business can buy. Agencies prove compliance through their Safeguard Security Report. They also prove it during their IRS on-site reviews.

You must report any suspected loss or theft of FTI within 24 hours of discovery. You must notify the IRS Office of Safeguards. You must also notify the Treasury Inspector General for Tax Administration.

You must place at least two independent physical barriers between FTI and unauthorized people. A single locked door is not enough. You need a locked door to a restricted area plus a locked cabinet inside.

Secure Your FTI Environment Today

Managing IRS compliance takes constant work. You cannot afford to fail an on-site review. LeadingIT helps you become and stay compliant. We are a Chicagoland managed IT and cybersecurity provider with offices in Woodstock and Manteno.

We operate the technical controls your agency needs to pass an audit. We manage your MFA, FIPS 140-validated encryption, and SIEM monitoring. Reach out to contact us or book a call today to secure your network.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.