FTC Safeguards Rule Checklist for CPA Firms and Tax Preparers
CPA firms and tax preparers handle some of the most sensitive financial information a business or household can share. The FTC Safeguards Rule turns that responsibility into a formal security obligation: covered firms need a written information security program, practical safeguards, trained employees, vendor oversight, and a plan for responding when something goes wrong.
What the FTC Safeguards Rule Means for CPA Firms
The FTC Safeguards Rule is part of the Gramm-Leach-Bliley Act framework. It applies to financial institutions under FTC jurisdiction, and the FTC specifically lists tax preparation firms as covered examples. The IRS also tells tax professionals that protecting client data is required by law and points firms to WISP resources.
For CPA firms, enrolled agents, bookkeepers offering tax services, and independent tax preparers, the practical takeaway is straightforward: if your firm collects, stores, transmits, or processes taxpayer or client financial information, you need a documented and operational security program that reflects how your systems actually work.
There is one important nuance for smaller firms. The FTC notes that financial institutions maintaining customer information concerning fewer than 5,000 consumers are exempt from certain provisions. That is not a blanket exemption from security or written planning.
FTC Safeguards Rule Checklist for CPA Firms and Tax Preparers
Use this checklist to review whether your firm has a working security program. The goal is to protect client data in the real places where it lives: tax software, document portals, Microsoft 365, email, workstations, file shares, backups, mobile devices, paper records, and vendor platforms.
| Checklist area | What to verify | Evidence to keep |
|---|---|---|
| Written security plan | Current WISP that reflects the firm, systems, client data, vendors, and responsibilities. | Approved WISP, revision history, annual review notes. |
| Qualified Individual | A responsible person oversees the program and reports to ownership or leadership. | Role assignment, reporting notes, meeting minutes. |
| Risk assessment | Client data locations, threats, vulnerabilities, and safeguards are identified and reviewed. | Risk register, data inventory, remediation plan. |
| Access controls | Users only have access needed for their job, with prompt removal when roles change. | User access reviews, onboarding and offboarding records. |
| Multi-factor authentication | MFA is enforced for systems that access customer information, including email and remote access. | MFA policy, admin screenshots, exception approvals. |
| Encryption | Client data is encrypted in transit and at rest where feasible. | Device encryption reports, portal settings, email encryption process. |
| Monitoring and testing | Controls are monitored, vulnerabilities are reviewed, and testing occurs on a schedule. | Security reports, vulnerability scans, remediation tickets. |
| Vendor oversight | Vendors with client data access are reviewed and contractually required to safeguard information. | Vendor list, due diligence notes, signed agreements. |
| Incident response | The firm has a written plan for security events, breach triage, notifications, and recovery. | Incident response plan, tabletop exercise notes, contact list. |
| Tip: Evidence matters. If your firm says a control exists, keep a record that shows when it was reviewed, tested, updated, or enforced. | ||
1. Maintain a written WISP that matches your actual firm
Your Written Information Security Plan should describe how your firm protects customer information, who is responsible for the program, how risks are assessed, which safeguards are used, how vendors are managed, and how incidents are handled. Avoid a generic template that names systems you do not use or skips systems you rely on every day.
For a CPA firm, the WISP should address tax software, accounting platforms, Microsoft 365 or Google Workspace, client portals, remote access, scanned documents, local file storage, backups, mobile devices, paper files, and key vendors.
2. Designate a Qualified Individual
The FTC requires covered firms to designate a Qualified Individual to implement and supervise the information security program. This does not have to be a person with a specific degree or title. For a small firm, it may be an owner, operations manager, internal technology lead, or an outside provider. What matters is that the role is assigned, competent, and accountable.
If an outside IT provider helps implement the program, firm leadership still needs internal ownership and regular reporting.
3. Complete and update a written risk assessment
A risk assessment starts with a practical inventory. What client information do you collect? Where is it stored? Who can access it? Which vendors touch it? Which systems transmit it? Once that is clear, identify foreseeable threats such as phishing, stolen passwords, compromised tax software accounts, lost laptops, misdirected emails, weak vendor controls, ransomware, and unauthorized employee access.
Update the assessment when your firm changes tax software, adds a portal, moves files to the cloud, hires seasonal staff, changes vendors, or experiences a security incident.
4. Lock down access to client information
Access controls are one of the most visible signs of a mature security program. Each user should have a unique account. Shared logins should be eliminated wherever possible. Administrative access should be limited to the few people who need it. Seasonal workers should receive only the access they need, and that access should be removed promptly when their work ends.
Review access at least annually, and consider quarterly reviews for tax software, email, portals, backups, and administrator consoles.
5. Enforce MFA for email, tax software, portals, and remote access
Multi-factor authentication is a central safeguard because stolen passwords are common in phishing and credential theft attacks. The FTC describes MFA as authentication using at least two factors, such as something a user knows, something a user has, or something a user is. For CPA firms, MFA should be enforced on email, remote access, tax software, client portals, cloud storage, password managers, and administrator accounts.
Administrator accounts and remote access should receive the strongest controls the firm can reasonably support.
6. Encrypt client information where feasible
Client information should be encrypted in transit and at rest where feasible. In practical terms, this means using secure portals instead of unprotected email attachments, ensuring laptops and desktops have disk encryption enabled, verifying that cloud platforms use modern encryption, and protecting backup media. If encryption is not feasible for a specific workflow, the exception should be documented and approved with an alternative safeguard.
A secure client portal, properly configured, is usually safer and easier to document than ad hoc email attachments.
7. Train employees before and during tax season
Security awareness training should cover the threats your staff actually sees: phishing emails, fake IRS notices, vendor impersonation, fraudulent direct deposit changes, malicious attachments, suspicious portal uploads, fake client requests, and social engineering by phone. Training should happen before tax season, when seasonal staff are onboarded, and again when new threats appear.
Keep attendance records, topics covered, phishing test results, and follow-up coaching.
8. Monitor, test, and improve safeguards
The FTC expects firms to monitor and test the effectiveness of safeguards. For many small firms, that means reviewing endpoint protection, backup status, vulnerability scan results, patching, conditional access policies, failed login activity, administrative changes, and suspicious mailbox activity. Where continuous monitoring is not in place, the FTC describes annual penetration testing and vulnerability assessments, including system-wide scans every six months, as required alternatives for covered information systems.
Testing only helps when issues are assigned and corrected. Track findings, owners, target dates, remediation, and validation.
9. Review service providers that touch client data
Your firm may outsource IT support, payroll processing, cloud hosting, document management, secure shredding, tax software, bookkeeping platforms, and marketing systems. If a vendor receives, maintains, processes, or can access customer information, it should be part of your vendor oversight process.
Keep a vendor list, review available security materials, make sure contracts require safeguards, and reassess critical vendors annually or when services change.
10. Maintain secure disposal and retention practices
CPA firms often keep records longer than many other businesses because of tax, audit, professional, insurance, or litigation reasons. The Safeguards Rule requires secure disposal of customer information no later than two years after the most recent use to serve the customer, unless a legitimate business need, legal requirement, or technical limitation justifies retaining it. Your retention schedule should align legal obligations with secure storage and secure destruction.
Paper records should be locked and shredded securely when eligible for destruction. Digital records should be deleted according to a documented process.
11. Prepare an incident response plan
An incident response plan should identify who makes decisions, who investigates, who contacts IT, who communicates with clients, who contacts insurance, and who coordinates with legal counsel. It should also describe how the firm isolates affected systems, preserves evidence, restores data, documents decisions, and updates safeguards after the event.
For tax professionals, the plan should also include IRS, state tax agency, cyber insurance, legal, IT, and executive contacts.
12. Understand FTC breach reporting requirements
The FTC further amended the Safeguards Rule to require covered financial institutions to report certain notification events. FTC guidance states that firms must notify the FTC as soon as possible, and no later than 30 days after discovery, when a notification event involves unauthorized acquisition of at least 500 consumers’ unencrypted customer information. The FTC explains that the breach notification requirements took effect in May 2024.
This does not replace legal advice, state breach notification review, IRS reporting, insurance obligations, or client communication planning. It does mean FTC reporting should be part of incident triage.
How to Prioritize the Checklist Before Tax Season
CPA firms face a timing problem. The highest-risk season is also the busiest season. Waiting until February or March to overhaul security is usually unrealistic. A better approach is to prioritize controls that reduce the most likely and most damaging risks first.
Start with identity and access. Enforce MFA, remove stale users, eliminate shared accounts, protect administrator accounts, and review access to tax software and email. Next, focus on data movement. Move client document exchange into a secure portal, reduce unencrypted attachments, confirm device encryption, and verify backup recoverability. Then address documentation. Update the WISP, risk assessment, vendor list, training records, and incident response contact sheet.
Finally, schedule the work: review access quarterly, test backup recovery quarterly, review vendors annually, update the WISP annually, train staff before tax season, and run an incident response tabletop once a year.
Documentation Your Firm Should Keep
Documentation is not just for regulators. It helps owners, partners, managers, and IT providers make better decisions. If an employee leaves, a vendor changes, or an incident occurs, records help the firm respond faster and more defensibly.
Keep these records in a secure, organized location:
- The current WISP and prior versions.
- Written risk assessments and remediation plans.
- Data inventory showing where customer information is stored and transmitted.
- System inventory for workstations, servers, cloud applications, and network equipment.
- User access reviews and administrative account reviews.
- MFA enforcement records and approved exceptions.
- Employee security training records.
- Vendor due diligence and contracts with security obligations.
- Vulnerability scan results, monitoring reports, and remediation notes.
- Incident response plan, tabletop exercise notes, and post-incident review records.
The best documentation is short, current, and usable. A plan the firm reviews every year is more valuable than a longer plan no one can explain.
Common Gaps We See in CPA Firms
Many CPA firms have pieces of a compliance program but have not connected them into a complete system. They may have MFA on tax software but not on email. They may use a secure portal but still send sensitive attachments when clients resist the portal. They may have an IT provider but no internal owner. They may have policies but no evidence that the policies are reviewed or followed.
Other common gaps include old employee accounts, excessive administrator rights, unencrypted laptops, undocumented vendor access, weak backup testing, unmanaged home computers, and missing seasonal staff offboarding.
Start by documenting the current state honestly. Then close the gaps that expose client data to the greatest risk.
Frequently Asked Questions
Bottom Line: Make the Checklist Operational
The FTC Safeguards Rule checklist is not just a compliance exercise. It is a practical roadmap for protecting the trust your clients place in your firm. For CPA firms and tax preparers, that trust depends on secure systems, trained staff, disciplined vendor management, and clear documentation.
Urban IT helps professional services firms in Ventura County, Los Angeles County, and beyond turn security requirements into manageable IT operations. If your CPA firm needs help reviewing Microsoft 365 security, endpoint protection, backups, access controls, vendor risk, or WISP readiness, talk to Urban IT.
Sources & Further Reading
- FTC Safeguards Rule: What Your Business Needs to Know – Federal Trade Commission
- Standards for Safeguarding Customer Information, 16 CFR Part 314 – eCFR
- Protect Your Clients; Protect Yourself – Internal Revenue Service
- IRS, Security Summit Remind Tax Pros They Must Have a Written Information Security Plan – Internal Revenue Service