What Is the IRS Safeguard Review? What to Expect During an Audit
An IRS Safeguard Review is the audit the IRS Office of Safeguards runs on any agency that receives Federal Tax Information (FTI). It checks whether your physical, technical, and operational controls actually protect that data.
If your agency handles FTI, this review is not optional. It runs on a fixed cycle, not a one-time flag triggered by suspicion.
Most guides on IRS Publication 1075 explain the rule itself. Fewer explain what happens during the review, and how to get ready before it starts. That’s what this guide covers.
Key Takeaways
- The IRS Office of Safeguards reviews every FTI-receiving agency at least once every three years.
- Reviews now follow a hybrid model: part remote, part on-site.
- You get a Safeguard Review Report (SRR) and Corrective Action Plan (CAP) within 45 days of the closing conference.
- A CAP finding is a documented item to fix. It’s not a fine and not proof of a breach.
- There’s no “Pub 1075 certified” credential. Compliance shows up through your SSR and the review itself.
What Triggers an IRS Safeguard Review?
A Safeguard Review isn’t triggered by suspicion, the way a tax audit might be. It’s scheduled.
The IRS Office of Safeguards reviews every agency that receives FTI at least once every three years. Agencies bound by this cycle include:
The review tracks FTI through its full lifecycle. That runs from receipt to final disposal, not just a snapshot at one point in time.
New to the underlying rule? Our companion guide, What Is IRS Publication 1075?, explains it in plain terms.
The Hybrid Review Model: Remote First, Then On-Site
The IRS Office of Safeguards now runs hybrid reviews for its three-year cycle. Part of the review happens remotely. Part happens on-site.

The IRS adopted this model to cut down how often reviewers must visit in person. It still collects data before and during the on-site visit. Here’s the rough shape of the process:
- The IRS gathers information about your systems and controls, largely remotely, ahead of any visit.
- Reviewers evaluate your physical and logical controls, including an on-site component.
- Your agency and the review team hold a closing conference to discuss what was found.
- You receive the Safeguard Review Report and Corrective Action Plan within 45 days of that conference.
- Your agency works through each item on the CAP.
After the closing conference, your agency receives its Safeguard Review Report and Corrective Action Plan within 45 days.
What Reviewers Actually Evaluate
Pub 1075 groups its requirements into physical, technical, and operational safeguards. A review checks all three, plus your audit trail.
| Review Area | What It Covers | What Reviewers Look For |
|---|---|---|
| Physical safeguards | Where FTI is stored and who can reach it | Locked rooms, the two-barrier rule, visitor controls |
| Technical safeguards | How FTI is protected inside your systems | Encryption, multi-factor authentication, access restrictions |
| Operational safeguards | How FTI is used and disposed of day to day | Media sanitization, continuous monitoring, incident readiness |
| Audit trail | Whether you can prove who touched FTI and when | OS, database, and application logs, kept for 6 years |
That audit-trail row matters most. Pub 1075 requires logs across the OS, database, and application layers, kept for six years. Good controls without logs to prove it still count as a finding.
Want to see where you’d stand today? Our Pub 1075 FTI Safeguards checklist walks through these same areas.
The CAP Isn’t a Penalty, But It Isn’t Optional
A Corrective Action Plan lists gaps to fix. It documents what reviewers found. It is not a fine, and it doesn’t mean FTI was exposed.
Real penalties do exist elsewhere in the law, separate from a CAP finding.
A CAP finding is what happens when a gap gets caught early. Treat it as the cheaper outcome, not the bad one.
Who Can Touch FTI: Background Checks and the Two-Barrier Rule
Reviewers also check who has access to FTI. Two rules drive most of what they look for.
Your agency has to document that need before access is granted. – The two-barrier rule. At least two independent physical barriers must separate FTI from anyone without a need-to-know. Think a locked door to a restricted area, plus a locked cabinet inside it. – Background investigations. FTI is Moderate Risk Public Trust data.
This is a deep topic on its own. Our guide on who can access Federal Tax Information covers the full background-check and access-control picture.
How an MSP Helps You Prepare Before the Review
There’s no official “Pub 1075 certified” label a vendor can sell you. Your agency proves compliance through its SSR and the review itself, not a one-time certificate.
A managed IT provider can make sure the environment your SSR describes is actually true on the day reviewers show up. That includes:
Your agency stays the accountable party. It’s the one that files the SSR and sits through the review. LeadingIT’s role is operating the controls underneath that filing, so there are fewer surprises at the closing conference.
If you want to talk through your specific setup, you can contact us directly.
See Where You Stand
A Safeguard Review isn’t the moment to find out your controls have gaps. See where your setup stands first, in about two minutes, no sign-up required.
Take the free 2-minute IRS Pub 1075 FTI Safeguards Risk-Check
Related Guides
- What Is IRS Publication 1075? The Plain-English Guide to FTI Safeguards
- The IRS Publication 1075 / FTI Safeguards Checklist
- Who Can Access Federal Tax Information (FTI)?
Frequently Asked Questions
It’s the audit the IRS Office of Safeguards runs on agencies that receive Federal Tax Information. It checks physical, technical, and operational controls. It combines remote data collection with an on-site visit and ends with a closing conference. Your agency then gets a formal report and any required corrective actions.
There isn’t a specific trigger event. The IRS Office of Safeguards reviews every agency that receives FTI on a set cycle. That cycle runs at least once every three years. If your agency handles FTI, a review is scheduled, not conditional.
The review itself combines remote and on-site work under the current hybrid model. After the closing conference, your agency gets its Safeguard Review Report and Corrective Action Plan within 45 days. How long remediation takes after that depends on what the CAP finds.
No. A Corrective Action Plan documents gaps to fix. It isn’t a penalty or proof of a breach. Actual penalties under federal law apply to unauthorized disclosure or inspection of FTI. That’s a separate, more serious matter than a documented gap found during a review.
Yes. Publication 1075’s requirements flow down contractually to any contractor, subcontractor, or cloud provider that touches FTI on your agency’s behalf. Reviewers can evaluate those relationships as part of your overall control environment.
The SSR is the document your agency submits to the IRS Office of Safeguards. It describes the processes and controls you have in place to protect FTI. It’s your core evidence of compliance, and it must be sent using IRS-approved encryption when submitted by email.
Ready to Get Ahead of Your Next Review?
A Safeguard Review moves fast once the closing conference happens. Forty-five days isn’t much time to fix gaps you didn’t know about. LeadingIT helps Chicagoland agencies and their contractors get the technical and physical controls in place before that clock starts.
See our compliance-focused managed IT services, or book a call to walk through your specific setup.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
