|

FTC Safeguards Rule Checklist for CPA Firms and Tax Preparers

FTC Safeguards Rule Checklist for CPA Firms

FTC Safeguards Rule Checklist for CPA Firms and Tax Preparers

CPA firms and tax preparers handle some of the most sensitive financial information a business or household can share. The FTC Safeguards Rule turns that responsibility into a formal security obligation: covered firms need a written information security program, practical safeguards, trained employees, vendor oversight, and a plan for responding when something goes wrong.

Short answer: Most CPA firms and tax preparers should treat the FTC Safeguards Rule as a standing compliance and cybersecurity requirement, not a one-time tax-season project. A good checklist starts with a written information security plan, then proves that access, encryption, MFA, training, vendor controls, monitoring, testing, and incident response are actually in place.

What the FTC Safeguards Rule Means for CPA Firms

The FTC Safeguards Rule is part of the Gramm-Leach-Bliley Act framework. It applies to financial institutions under FTC jurisdiction, and the FTC specifically lists tax preparation firms as covered examples. The IRS also tells tax professionals that protecting client data is required by law and points firms to WISP resources.

For CPA firms, enrolled agents, bookkeepers offering tax services, and independent tax preparers, the practical takeaway is straightforward: if your firm collects, stores, transmits, or processes taxpayer or client financial information, you need a documented and operational security program that reflects how your systems actually work.

There is one important nuance for smaller firms. The FTC notes that financial institutions maintaining customer information concerning fewer than 5,000 consumers are exempt from certain provisions. That is not a blanket exemption from security or written planning.


FTC Safeguards Rule Checklist for CPA Firms and Tax Preparers

Use this checklist to review whether your firm has a working security program. The goal is to protect client data in the real places where it lives: tax software, document portals, Microsoft 365, email, workstations, file shares, backups, mobile devices, paper records, and vendor platforms.

Checklist areaWhat to verifyEvidence to keep
Written security planCurrent WISP that reflects the firm, systems, client data, vendors, and responsibilities.Approved WISP, revision history, annual review notes.
Qualified IndividualA responsible person oversees the program and reports to ownership or leadership.Role assignment, reporting notes, meeting minutes.
Risk assessmentClient data locations, threats, vulnerabilities, and safeguards are identified and reviewed.Risk register, data inventory, remediation plan.
Access controlsUsers only have access needed for their job, with prompt removal when roles change.User access reviews, onboarding and offboarding records.
Multi-factor authenticationMFA is enforced for systems that access customer information, including email and remote access.MFA policy, admin screenshots, exception approvals.
EncryptionClient data is encrypted in transit and at rest where feasible.Device encryption reports, portal settings, email encryption process.
Monitoring and testingControls are monitored, vulnerabilities are reviewed, and testing occurs on a schedule.Security reports, vulnerability scans, remediation tickets.
Vendor oversightVendors with client data access are reviewed and contractually required to safeguard information.Vendor list, due diligence notes, signed agreements.
Incident responseThe firm has a written plan for security events, breach triage, notifications, and recovery.Incident response plan, tabletop exercise notes, contact list.
Tip: Evidence matters. If your firm says a control exists, keep a record that shows when it was reviewed, tested, updated, or enforced.

1. Maintain a written WISP that matches your actual firm

Your Written Information Security Plan should describe how your firm protects customer information, who is responsible for the program, how risks are assessed, which safeguards are used, how vendors are managed, and how incidents are handled. Avoid a generic template that names systems you do not use or skips systems you rely on every day.

For a CPA firm, the WISP should address tax software, accounting platforms, Microsoft 365 or Google Workspace, client portals, remote access, scanned documents, local file storage, backups, mobile devices, paper files, and key vendors.

2. Designate a Qualified Individual

The FTC requires covered firms to designate a Qualified Individual to implement and supervise the information security program. This does not have to be a person with a specific degree or title. For a small firm, it may be an owner, operations manager, internal technology lead, or an outside provider. What matters is that the role is assigned, competent, and accountable.

If an outside IT provider helps implement the program, firm leadership still needs internal ownership and regular reporting.

3. Complete and update a written risk assessment

A risk assessment starts with a practical inventory. What client information do you collect? Where is it stored? Who can access it? Which vendors touch it? Which systems transmit it? Once that is clear, identify foreseeable threats such as phishing, stolen passwords, compromised tax software accounts, lost laptops, misdirected emails, weak vendor controls, ransomware, and unauthorized employee access.

Update the assessment when your firm changes tax software, adds a portal, moves files to the cloud, hires seasonal staff, changes vendors, or experiences a security incident.

4. Lock down access to client information

Access controls are one of the most visible signs of a mature security program. Each user should have a unique account. Shared logins should be eliminated wherever possible. Administrative access should be limited to the few people who need it. Seasonal workers should receive only the access they need, and that access should be removed promptly when their work ends.

Review access at least annually, and consider quarterly reviews for tax software, email, portals, backups, and administrator consoles.

5. Enforce MFA for email, tax software, portals, and remote access

Multi-factor authentication is a central safeguard because stolen passwords are common in phishing and credential theft attacks. The FTC describes MFA as authentication using at least two factors, such as something a user knows, something a user has, or something a user is. For CPA firms, MFA should be enforced on email, remote access, tax software, client portals, cloud storage, password managers, and administrator accounts.

Administrator accounts and remote access should receive the strongest controls the firm can reasonably support.

6. Encrypt client information where feasible

Client information should be encrypted in transit and at rest where feasible. In practical terms, this means using secure portals instead of unprotected email attachments, ensuring laptops and desktops have disk encryption enabled, verifying that cloud platforms use modern encryption, and protecting backup media. If encryption is not feasible for a specific workflow, the exception should be documented and approved with an alternative safeguard.

A secure client portal, properly configured, is usually safer and easier to document than ad hoc email attachments.

7. Train employees before and during tax season

Security awareness training should cover the threats your staff actually sees: phishing emails, fake IRS notices, vendor impersonation, fraudulent direct deposit changes, malicious attachments, suspicious portal uploads, fake client requests, and social engineering by phone. Training should happen before tax season, when seasonal staff are onboarded, and again when new threats appear.

Keep attendance records, topics covered, phishing test results, and follow-up coaching.

8. Monitor, test, and improve safeguards

The FTC expects firms to monitor and test the effectiveness of safeguards. For many small firms, that means reviewing endpoint protection, backup status, vulnerability scan results, patching, conditional access policies, failed login activity, administrative changes, and suspicious mailbox activity. Where continuous monitoring is not in place, the FTC describes annual penetration testing and vulnerability assessments, including system-wide scans every six months, as required alternatives for covered information systems.

Testing only helps when issues are assigned and corrected. Track findings, owners, target dates, remediation, and validation.

9. Review service providers that touch client data

Your firm may outsource IT support, payroll processing, cloud hosting, document management, secure shredding, tax software, bookkeeping platforms, and marketing systems. If a vendor receives, maintains, processes, or can access customer information, it should be part of your vendor oversight process.

Keep a vendor list, review available security materials, make sure contracts require safeguards, and reassess critical vendors annually or when services change.

10. Maintain secure disposal and retention practices

CPA firms often keep records longer than many other businesses because of tax, audit, professional, insurance, or litigation reasons. The Safeguards Rule requires secure disposal of customer information no later than two years after the most recent use to serve the customer, unless a legitimate business need, legal requirement, or technical limitation justifies retaining it. Your retention schedule should align legal obligations with secure storage and secure destruction.

Paper records should be locked and shredded securely when eligible for destruction. Digital records should be deleted according to a documented process.

11. Prepare an incident response plan

An incident response plan should identify who makes decisions, who investigates, who contacts IT, who communicates with clients, who contacts insurance, and who coordinates with legal counsel. It should also describe how the firm isolates affected systems, preserves evidence, restores data, documents decisions, and updates safeguards after the event.

For tax professionals, the plan should also include IRS, state tax agency, cyber insurance, legal, IT, and executive contacts.

12. Understand FTC breach reporting requirements

The FTC further amended the Safeguards Rule to require covered financial institutions to report certain notification events. FTC guidance states that firms must notify the FTC as soon as possible, and no later than 30 days after discovery, when a notification event involves unauthorized acquisition of at least 500 consumers’ unencrypted customer information. The FTC explains that the breach notification requirements took effect in May 2024.

This does not replace legal advice, state breach notification review, IRS reporting, insurance obligations, or client communication planning. It does mean FTC reporting should be part of incident triage.


How to Prioritize the Checklist Before Tax Season

CPA firms face a timing problem. The highest-risk season is also the busiest season. Waiting until February or March to overhaul security is usually unrealistic. A better approach is to prioritize controls that reduce the most likely and most damaging risks first.

Start with identity and access. Enforce MFA, remove stale users, eliminate shared accounts, protect administrator accounts, and review access to tax software and email. Next, focus on data movement. Move client document exchange into a secure portal, reduce unencrypted attachments, confirm device encryption, and verify backup recoverability. Then address documentation. Update the WISP, risk assessment, vendor list, training records, and incident response contact sheet.

Finally, schedule the work: review access quarterly, test backup recovery quarterly, review vendors annually, update the WISP annually, train staff before tax season, and run an incident response tabletop once a year.


Documentation Your Firm Should Keep

Documentation is not just for regulators. It helps owners, partners, managers, and IT providers make better decisions. If an employee leaves, a vendor changes, or an incident occurs, records help the firm respond faster and more defensibly.

Keep these records in a secure, organized location:

  • The current WISP and prior versions.
  • Written risk assessments and remediation plans.
  • Data inventory showing where customer information is stored and transmitted.
  • System inventory for workstations, servers, cloud applications, and network equipment.
  • User access reviews and administrative account reviews.
  • MFA enforcement records and approved exceptions.
  • Employee security training records.
  • Vendor due diligence and contracts with security obligations.
  • Vulnerability scan results, monitoring reports, and remediation notes.
  • Incident response plan, tabletop exercise notes, and post-incident review records.

The best documentation is short, current, and usable. A plan the firm reviews every year is more valuable than a longer plan no one can explain.


Common Gaps We See in CPA Firms

Many CPA firms have pieces of a compliance program but have not connected them into a complete system. They may have MFA on tax software but not on email. They may use a secure portal but still send sensitive attachments when clients resist the portal. They may have an IT provider but no internal owner. They may have policies but no evidence that the policies are reviewed or followed.

Other common gaps include old employee accounts, excessive administrator rights, unencrypted laptops, undocumented vendor access, weak backup testing, unmanaged home computers, and missing seasonal staff offboarding.

Start by documenting the current state honestly. Then close the gaps that expose client data to the greatest risk.


Frequently Asked Questions

Does the FTC Safeguards Rule apply to CPA firms?
It can. The FTC lists tax preparation firms as examples of financial institutions covered by the Safeguards Rule, and the IRS states that tax and accounting professionals are considered financial institutions under GLBA for purposes of protecting customer data. CPA firms should review their services and data handling with qualified counsel or compliance guidance.
What is a WISP?
A WISP is a Written Information Security Plan. For a CPA firm or tax preparer, it should explain how the firm protects client information through administrative, technical, and physical safeguards. It should also assign responsibility, document risks, describe controls, address vendors, and outline incident response.
Is MFA required for tax preparers?
The FTC Safeguards Rule requires multi-factor authentication for anyone accessing customer information on covered systems, unless the Qualified Individual has approved another equivalent secure access control in writing. In practice, CPA firms should enforce MFA for email, tax software, portals, remote access, cloud storage, and administrator accounts.
Do small tax practices need a written plan?
Yes, small practices should have a written, accessible plan. Some smaller financial institutions may be exempt from certain FTC provisions when they maintain customer information concerning fewer than 5,000 consumers, but that is not a blanket exemption from safeguarding client data or maintaining a practical security program.
How often should a CPA firm update its WISP?
At minimum, review it annually. Update it sooner when the firm changes systems, adds vendors, hires seasonal staff, changes remote work practices, identifies new risks, completes testing, or experiences a security incident.
What should a CPA firm do first?
Start with the highest-risk items: assign ownership, document where client data lives, enforce MFA, remove stale accounts, secure email and portals, confirm backups, train staff, and create an incident response plan. Then build the rest of the WISP around those operational controls.

Bottom Line: Make the Checklist Operational

The FTC Safeguards Rule checklist is not just a compliance exercise. It is a practical roadmap for protecting the trust your clients place in your firm. For CPA firms and tax preparers, that trust depends on secure systems, trained staff, disciplined vendor management, and clear documentation.

Urban IT helps professional services firms in Ventura County, Los Angeles County, and beyond turn security requirements into manageable IT operations. If your CPA firm needs help reviewing Microsoft 365 security, endpoint protection, backups, access controls, vendor risk, or WISP readiness, talk to Urban IT.

Similar Posts