Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

What Is the IRS Safeguard Review? What to Expect During an Audit

August 11, 2026
hero-irs-safeguard-review-process-1.png

An IRS Safeguard Review is the audit the IRS Office of Safeguards runs on any agency that receives Federal Tax Information (FTI). It checks whether your physical, technical, and operational controls actually protect that data.

If your agency handles FTI, this review is not optional. It runs on a fixed cycle, not a one-time flag triggered by suspicion.

Most guides on IRS Publication 1075 explain the rule itself. Fewer explain what happens during the review, and how to get ready before it starts. That’s what this guide covers.

Key Takeaways

  • The IRS Office of Safeguards reviews every FTI-receiving agency at least once every three years.
  • Reviews now follow a hybrid model: part remote, part on-site.
  • You get a Safeguard Review Report (SRR) and Corrective Action Plan (CAP) within 45 days of the closing conference.
  • A CAP finding is a documented item to fix. It’s not a fine and not proof of a breach.
  • There’s no “Pub 1075 certified” credential. Compliance shows up through your SSR and the review itself.

What Triggers an IRS Safeguard Review?

A Safeguard Review isn’t triggered by suspicion, the way a tax audit might be. It’s scheduled.

The IRS Office of Safeguards reviews every agency that receives FTI at least once every three years. Agencies bound by this cycle include:

The review tracks FTI through its full lifecycle. That runs from receipt to final disposal, not just a snapshot at one point in time.

New to the underlying rule? Our companion guide, What Is IRS Publication 1075?, explains it in plain terms.

The Hybrid Review Model: Remote First, Then On-Site

The IRS Office of Safeguards now runs hybrid reviews for its three-year cycle. Part of the review happens remotely. Part happens on-site.

Hybrid IRS Review Steps

The IRS adopted this model to cut down how often reviewers must visit in person. It still collects data before and during the on-site visit. Here’s the rough shape of the process:

  1. The IRS gathers information about your systems and controls, largely remotely, ahead of any visit.
  2. Reviewers evaluate your physical and logical controls, including an on-site component.
  3. Your agency and the review team hold a closing conference to discuss what was found.
  4. You receive the Safeguard Review Report and Corrective Action Plan within 45 days of that conference.
  5. Your agency works through each item on the CAP.

After the closing conference, your agency receives its Safeguard Review Report and Corrective Action Plan within 45 days.

What Reviewers Actually Evaluate

Pub 1075 groups its requirements into physical, technical, and operational safeguards. A review checks all three, plus your audit trail.

Review AreaWhat It CoversWhat Reviewers Look For
Physical safeguardsWhere FTI is stored and who can reach itLocked rooms, the two-barrier rule, visitor controls
Technical safeguardsHow FTI is protected inside your systemsEncryption, multi-factor authentication, access restrictions
Operational safeguardsHow FTI is used and disposed of day to dayMedia sanitization, continuous monitoring, incident readiness
Audit trailWhether you can prove who touched FTI and whenOS, database, and application logs, kept for 6 years

That audit-trail row matters most. Pub 1075 requires logs across the OS, database, and application layers, kept for six years. Good controls without logs to prove it still count as a finding.

Want to see where you’d stand today? Our Pub 1075 FTI Safeguards checklist walks through these same areas.

The CAP Isn’t a Penalty, But It Isn’t Optional

A Corrective Action Plan lists gaps to fix. It documents what reviewers found. It is not a fine, and it doesn’t mean FTI was exposed.

Real penalties do exist elsewhere in the law, separate from a CAP finding.

A CAP finding is what happens when a gap gets caught early. Treat it as the cheaper outcome, not the bad one.

Who Can Touch FTI: Background Checks and the Two-Barrier Rule

Reviewers also check who has access to FTI. Two rules drive most of what they look for.

Your agency has to document that need before access is granted. – The two-barrier rule. At least two independent physical barriers must separate FTI from anyone without a need-to-know. Think a locked door to a restricted area, plus a locked cabinet inside it. – Background investigations. FTI is Moderate Risk Public Trust data.

This is a deep topic on its own. Our guide on who can access Federal Tax Information covers the full background-check and access-control picture.

How an MSP Helps You Prepare Before the Review

There’s no official “Pub 1075 certified” label a vendor can sell you. Your agency proves compliance through its SSR and the review itself, not a one-time certificate.

A managed IT provider can make sure the environment your SSR describes is actually true on the day reviewers show up. That includes:

Your agency stays the accountable party. It’s the one that files the SSR and sits through the review. LeadingIT’s role is operating the controls underneath that filing, so there are fewer surprises at the closing conference.

If you want to talk through your specific setup, you can contact us directly.

See Where You Stand

A Safeguard Review isn’t the moment to find out your controls have gaps. See where your setup stands first, in about two minutes, no sign-up required.

Take the free 2-minute IRS Pub 1075 FTI Safeguards Risk-Check

Frequently Asked Questions

It’s the audit the IRS Office of Safeguards runs on agencies that receive Federal Tax Information. It checks physical, technical, and operational controls. It combines remote data collection with an on-site visit and ends with a closing conference. Your agency then gets a formal report and any required corrective actions.

There isn’t a specific trigger event. The IRS Office of Safeguards reviews every agency that receives FTI on a set cycle. That cycle runs at least once every three years. If your agency handles FTI, a review is scheduled, not conditional.

The review itself combines remote and on-site work under the current hybrid model. After the closing conference, your agency gets its Safeguard Review Report and Corrective Action Plan within 45 days. How long remediation takes after that depends on what the CAP finds.

No. A Corrective Action Plan documents gaps to fix. It isn’t a penalty or proof of a breach. Actual penalties under federal law apply to unauthorized disclosure or inspection of FTI. That’s a separate, more serious matter than a documented gap found during a review.

Yes. Publication 1075’s requirements flow down contractually to any contractor, subcontractor, or cloud provider that touches FTI on your agency’s behalf. Reviewers can evaluate those relationships as part of your overall control environment.

The SSR is the document your agency submits to the IRS Office of Safeguards. It describes the processes and controls you have in place to protect FTI. It’s your core evidence of compliance, and it must be sent using IRS-approved encryption when submitted by email.

Ready to Get Ahead of Your Next Review?

A Safeguard Review moves fast once the closing conference happens. Forty-five days isn’t much time to fix gaps you didn’t know about. LeadingIT helps Chicagoland agencies and their contractors get the technical and physical controls in place before that clock starts.

See our compliance-focused managed IT services, or book a call to walk through your specific setup.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.