Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

Who Can Access Federal Tax Information (FTI)?

August 11, 2026
hero-who-can-access-federal-tax-information-1.png

Who can access federal tax information (FTI) comes down to one standard: need-to-know. Under IRC 6103(p)(4)(C), only people whose official duties actually require FTI can access it. An agency must evaluate that need first. It must document the decision before handing FTI over to anyone.

That standard sits inside a bigger framework. IRS Publication 1075 lays out the physical, technical, and background-check controls every agency handling FTI has to run. Access isn’t a policy statement. It’s a specific set of barriers, checks, and paperwork that has to happen before anyone touches the data.

This page is for government agencies and their contractors. It walks through who qualifies for FTI access. It also covers what has to happen first. And it covers what’s at stake if the rules slip.

Key Takeaways

  • FTI access is limited to people whose job duties genuinely require it, the “need-to-know” standard under IRC 6103(p)(4)(C).
  • Anyone with FTI access must clear a Tier 2 background investigation first, including FBI fingerprinting and a local law enforcement check.
  • Physical FTI storage requires two independent barriers, not one lock and not a login password.
  • Contractors and subcontractors are bound by the same rules the agency is, and the agency must notify the IRS before FTI reaches a new contractor.
  • Unauthorized access to FTI carries real federal criminal exposure, not just an internal policy violation.

What Counts as FTI, Briefly

Federal Tax Information is any tax return or return-related data the IRS obtained from a taxpayer. It also includes data the IRS generated itself and then shared with an agency. FTI can be paper records, digital files, or verbal disclosures. It can even be data embedded inside a report someone built using FTI. Every format gets the same protection.

Icon grid of the four FTI formats — paper records, digital files, verbal disclosures, and data embedded in reports — each receiving the same level of protection under Pub 1075.

Pub 1075 also treats FTI as a full chain of custody. An agency must track FTI from receipt through processing, storage, transmission, and final destruction. For the complete definition and the wider Pub 1075 framework, see our plain-English guide to Publication 1075.

The Need-to-Know Standard, Explained

Need-to-know isn’t a job title. It’s a documented decision the agency makes about each person, before they ever see FTI. Publication 1075 defines this standard in its Section 1.4 definitions.

The agency has to ask a simple question: does this person’s actual job require FTI to do the work? If the answer is yes, access can be granted. The agency documents why. If the answer is no, or unclear, access doesn’t happen. This evaluation happens before FTI is requested or shared, never as a formality after the fact.

That’s a narrower bar than “works in this department” or “has a login to the system.” A caseworker processing child support enforcement needs FTI. The IT help desk technician who fixes that caseworker’s laptop usually doesn’t need it. An exception applies only if their specific role requires touching FTI directly.

The Two-Barrier Rule (and Why It’s Not the Same as MFA)

Pub 1075’s physical security rules include the two-barrier rule. It’s part of what Pub 1075 calls the Minimum Protection Standards. At least two independent physical barriers must separate FTI from anyone without a need-to-know.

Two-barrier means two separate physical obstacles, like a locked restricted-access room plus a locked file cabinet inside it, not one lock and not a password.

This is a physical-security concept. It is not the same thing as multi-factor authentication (MFA). MFA is a technical login control. Agencies need both. Each one solves a different problem.

ConceptTwo-Barrier RuleMulti-Factor Authentication
Type of controlPhysicalTechnical (login/system access)
What it protectsPaper FTI, servers, physical mediaDigital systems and accounts holding FTI
Typical exampleLocked door to a restricted room, plus a locked cabinet insidePassword plus a one-time code or security key
PurposeDeter, delay, and detect physical intrusionVerify the identity of whoever is logging in

Both are required under Pub 1075. Neither substitutes for the other.

Before Anyone Gets Access: The Background Investigation

Treasury classifies FTI as Moderate Risk Public Trust data. That classification triggers a mandatory Tier 2 background investigation. Every employee and contractor must clear it before accessing FTI.

FTI Background Investigation Steps

The investigation has to happen in this order:

  1. The individual completes SF-85P, the Questionnaire for Public Trust Positions.
  2. FBI fingerprinting (form FD-258) is submitted and reviewed for suitability issues through the Identity History Summary.
  3. Local law enforcement checks cover every place the person lived, worked, or attended school in the last five years.
  4. Citizenship or work-authorization status is verified, typically through Form I-9 and E-Verify.
  5. The investigation clears, and the person enrolls in the FBI’s Rap Back program for continuous monitoring.

That last step matters. A one-time background check isn’t enough. Investigations must stay current. The minimum recheck cycle is five years, met through Rap Back enrollment.

ComponentWhat It Verifies
SF-85P questionnaireBaseline public trust suitability information
FBI fingerprinting (FD-258)Criminal history via the Identity History Summary
Local law enforcement checksRecords from every location lived, worked, or attended school (5-year lookback)
Citizenship/work authorizationLegal eligibility, via I-9 and E-Verify
Rap Back enrollmentContinuous monitoring, minimum 5-year recheck

Contractors and Third Parties: Same Rules, Extra Notice

The same core rules apply to contractors and subcontractors as they do to agency employees:

Contractor Access Approval Steps
  • The need-to-know standard
  • The two-barrier physical security rule
  • The background investigation requirement

FTI access doesn’t get looser because the person on the other end works for a different employer.

There’s one more step for contractors. Before FTI can reach a new contractor or agent, the agency has one more job to do. It generally must notify the IRS Office of Safeguards well in advance of that disclosure. This gives the IRS a chance to confirm the contractor’s environment is ready before FTI ever touches it.

For the fuller checklist agencies and their vendors work through to prepare, see the IRS Pub 1075 / FTI Safeguards checklist.

What Happens Without Need-to-Know

Accessing FTI without a documented need-to-know isn’t a paperwork slip. It’s unauthorized access. It carries federal criminal exposure for the individual involved. That’s separate from whatever internal discipline the agency applies.

The IRS Office of Safeguards also reviews every agency’s access controls directly. It does this during its on-site review cycle. It increasingly uses hybrid remote-plus-onsite reviews too. Either way, it checks whether access was truly restricted to people with a documented need. Gaps here are a common finding. For what that review actually looks like, see what to expect during an IRS Safeguard Review.

There’s no shortcut around any of this by hiring the right vendor either. There’s no official “Pub 1075 certified” status a business can buy. Compliance is demonstrated on an ongoing basis. It runs through the agency’s Safeguard Security Report and the IRS’s own review, not a one-time certificate.

See Where You Stand

Not sure whether your current access controls, background-investigation process, and physical barriers would hold up under an IRS Safeguards review? Find out in two minutes.

Take the free 2-minute IRS Pub 1075 / FTI Safeguards Risk-Check

Frequently Asked Questions

Only employees and contractors whose official duties genuinely require it. This is the need-to-know standard. The agency must evaluate and document that need before access is granted. Job title or department alone doesn’t qualify someone.

Internal Revenue Code section 6103(p)(4) is the statutory basis for FTI confidentiality. IRS Publication 1075 implements that requirement as a detailed security standard. Together they govern who can access FTI and how it must be protected.

Unauthorized disclosure of FTI is a federal felony. Unauthorized inspection without a permitted purpose is a separate federal misdemeanor. The affected taxpayer can also sue the United States for civil damages. Consequences apply to individuals, not just the agency.

FTI is any tax return or return-related information the IRS obtained from a taxpayer or generated itself. It includes paper records, electronic files, and verbal disclosures. It also includes data embedded in reports built from FTI. Every format gets the same level of protection.

Examples include copies of tax returns and taxpayer ID numbers tied to a return. They also include income and filing status information. State agencies use FTI to verify eligibility for programs like Medicaid or unemployment insurance.

The two-barrier rule requires at least two independent physical barriers between FTI and anyone without a need-to-know. One example is a locked restricted room plus a locked cabinet inside it. It’s a physical security requirement, separate from technical controls like multi-factor authentication. The goal is to deter, delay, and detect unauthorized physical access.

At minimum, two independent physical barriers must stand between FTI and anyone without a documented need-to-know. A single locked door isn’t enough on its own. Agencies typically pair a restricted-access room with a separate locked container or cabinet inside it.

Get Your Access Controls Reviewed

Getting FTI access control right matters for any agency or contractor handling FTI. That means:

  • Background investigations for anyone with FTI access
  • The two-barrier physical security rule
  • Documented need-to-know decisions

Get these right. You’ll be in a strong position for an IRS Safeguards review.

LeadingIT operates the technical environment behind these controls for compliance-focused clients. That includes access controls tied to background-checked staff. It also includes audit logging and monitoring built around the standards Pub 1075 requires.

See our compliance-focused managed IT services. Book a call to talk through your environment. Or contact us with questions.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.