education • education tips • SafetyStandards • •

FTC Safeguards Rule for Tax Preparers: Key Requirements

FTC Safeguards Rule for Tax Preparers: key requirements for WISP, MFA, employee training, service providers, small practices, and incident reporting.

 

Tax preparer reviewing client data security requirements for FTC Safeguards Rule compliance

The FTC Safeguards Rule for Tax Preparers sets information-security requirements for covered tax preparation firms that handle customer information. The Federal Trade Commission expressly identifies tax preparation firms as examples of financial institutions subject to the Rule.

For covered firms, compliance involves more than installing security software. The Rule requires a written information security program with administrative, technical, and physical safeguards appropriate to the size and complexity of the business, its activities, and the sensitivity of the customer information it handles, as explained in the FTC Safeguards Rule guidance.

Small and solo practices should not assume they are automatically exempt. The Rule provides limited relief from certain requirements for institutions that maintain customer information concerning fewer than 5,000 consumers. This is not a blanket exemption from the Safeguards Rule; the 16 CFR § 314.6 exception for certain requirements applies only to the specific provisions identified in that section.

For the broader framework, see USCI's FTC Safeguards Rule requirements

FTC Safeguards Rule for Tax Preparers: Key Requirements

The term “financial institution” sounds as though it should apply only to banks, lenders, or investment companies. Under the Safeguards Rule, however, the definition is broader.

The FTC says coverage depends on the financial activities a business performs, not simply on how the business describes itself. Its guidance specifically lists tax preparation firms among examples of financial institutions covered by the rule. See the FTC Safeguards Rule guidance on covered financial institutions for more information.

That means a tax practice should not dismiss the Rule simply because it is a small accounting office, an independent tax business, or a firm that primarily prepares returns.

Infographic showing tax preparation firms within the FTC Safeguards Rule financial institution framework

Why Tax Preparation Firms Can Be “Financial Institutions”

The Safeguards Rule implements provisions of the Gramm-Leach-Bliley Act, or GLBA, for financial institutions under FTC jurisdiction. A business can fall within that framework when it is significantly engaged in financial activities covered by the applicable definition.

For tax professionals, the practical point is straightforward: tax preparation is specifically identified by the FTC as a covered type of activity. Whether the Rule applies in a particular situation still depends on the firm's activities and regulatory circumstances.

What Customer Information Does the Rule Protect?

The Rule protects “customer information,” which includes records containing nonpublic personal information about customers, whether those records are kept on paper, electronically, or in another form. The FTC Safeguards Rule guidance on customer information provides further information about the information covered by the Rule. 

In a tax practice, that can include information stored or handled through:

  • tax preparation software;

  • client portals;

  • email and document-sharing systems;

  • local computers or cloud storage;

  • paper tax documents;

  • files maintained by service providers on the firm's behalf.

The important question is not only where data is stored. Tax firms should understand where customer information enters the business, who can access it, where it moves, and how it is eventually disposed of.

What Does the FTC Safeguards Rule Require Tax Preparers to Do?

The rule requires more than a single privacy policy or security tool. A covered tax practice needs an information security program that addresses the risks associated with the customer information it handles.

FTC Safeguards Rule compliance framework showing key requirements for tax preparation firms

At a high level, the requirements translate into the following responsibilities:

Requirement

What it can mean in a tax practice

Qualified Individual

Assign responsibility for overseeing the information security program

Risk assessment

Identify customer information, threats, vulnerabilities, and relevant risks

Safeguards

Use appropriate access controls, MFA, encryption, secure disposal, and related measures

Monitoring and testing

Check whether safeguards continue to operate effectively

Personnel

Train staff and manage access to customer information

Service providers

Evaluate and oversee vendors with access to customer information

Program updates

Adjust safeguards as systems, risks, and business operations change

Incident response

Prepare to respond to security events and applicable reporting duties

For a fuller treatment of the general framework, refer to USCI's FTC Safeguards Rule requirements.

Designate a Qualified Individual

Covered institutions must designate a Qualified Individual to implement and supervise the information security program.

The FTC does not require that person to hold a particular degree or job title. The qualified individual may be an employee, someone working for an affiliate, or someone working for a service provider. If the role is outsourced, the tax firm still retains responsibility for its program.

For a small tax practice, that role may look very different from the same position at a large national firm. The key is that the person has knowledge appropriate to the organization's systems, risks, and responsibilities.

Assess Risks and Put Appropriate Safeguards in Place

A covered institution needs to understand the information it maintains and the risks affecting that information.

Depending on which provisions apply to the firm, this can involve documenting risks and implementing safeguards such as

  • access controls that restrict customer information to people with a legitimate business need;

  • an inventory of systems, devices, platforms, and data;

  • encryption of customer information in storage and transmission, or qualifying alternative controls where permitted;

  • multi-factor authentication for access to customer information, subject to the Rule's written equivalent-control provision;

  • secure disposal practices;

  • procedures for evaluating applications that handle customer information;

  • logging, monitoring, and testing. 

These are regulatory requirements and categories of safeguards. They should not be confused with vendor-specific recommendations. The FTC does not require tax firms to buy one particular software platform or use one particular commercial cybersecurity product.

Manage Employees and Service Providers

Tax practices also need to consider the people and third parties that can reach customer information.

The rule calls for security awareness training for personnel and additional appropriate training for information security personnel. It also requires covered institutions to select service providers capable of maintaining appropriate safeguards and require them by contract to implement and maintain appropriate safeguards. 

For a tax firm, relevant service providers may include cloud platforms, managed IT providers, document-storage services, or other vendors that receive, maintain, process, or are permitted access to customer information.

Using an outside provider does not automatically transfer the tax firm's responsibilities to that provider.

Test, Review, and Update the Program

Information security programs cannot remain static while a tax firm's technology and operations change.

The Safeguards Rule addresses monitoring and testing, updates to the information security program, incident response, and reporting by the Qualified Individual. The exact requirements depend in part on whether the firm qualifies for the limited exception discussed below. 

Are Small or Solo Tax Preparers Exempt?

Not simply because they are small.

A one-person office, seasonal tax business, or small accounting practice should not assume that business size removes it from the Safeguards Rule.

What the Fewer-Than-5,000-Consumers Exception Actually Means

Under 16 CFR § 314.6, financial institutions that maintain customer information concerning fewer than 5,000 consumers are exempt from four specified provisions of the Rule:

  • the written risk assessment requirement in § 314.4(b)(1);

  • the prescribed testing requirement in § 314.4(d)(2);

  • the written incident response plan requirement in § 314.4(h); and

  • the annual written Qualified Individual report requirement in § 314.4(i). 

That is a limited exception, not an exemption from the entire Rule.

Other requirements can still apply, including maintaining an appropriate information security program, implementing applicable safeguards, managing service providers, and addressing personnel training.

So, “we have fewer than 5,000 consumers” should not be treated as shorthand for “the Safeguards Rule does not apply.”

Do Tax Preparers Need a Written Information Security Plan (WISP)?

Yes. Current IRS guidance tells tax professionals that they are required by law to create a Written Information Security Plan, commonly called a WISP, to protect client data.

The WISP is not simply a document to put on a shelf. It should reflect how the practice actually handles customer information and the safeguards it has adopted.

How FTC and IRS Guidance Fit Together

The FTC administers the Safeguards Rule for covered financial institutions under its jurisdiction.

The IRS, together with Security Summit partners, provides tax-professional-specific resources to help firms address data-security responsibilities. One of the most useful is IRS Publication 5708, Creating a Written Information Security Plan for Your Tax & Accounting Practice. The IRS also maintains Publication 4557 and Publication 5293 as data security resources for tax professionals.

IRS guidance is useful for implementation, but it does not replace the federal requirements in the FTC Safeguards Rule.

What Should a Tax Practice WISP Address?

A practical WISP should be tailored to the size, scope, complexity, and sensitivity of the information the practice handles.

IRS guidance highlights areas such as:

  • responsibility for coordinating the information security program;

  • risks to customer information;

  • safeguards used to control those risks;

  • employee training and management;

  • information systems;

  • service providers;

  • monitoring and testing;

  • adjustments when risks or operations change.

A small practice may have a simpler program than a large multi-office firm, but the program still needs to reflect the business's actual circumstances.FTC Safeguards Rule checklist for tax preparers covering WISP, MFA, employee training, safeguards, testing, and incident response

FTC Safeguards Rule Checklist for Tax Preparers

Use this as a practical starting point, not as a substitute for reviewing the Rule itself.

  1. Confirm whether your activities fall within FTC jurisdiction and Safeguards Rule coverage.

  2. Identify the customer information your practice handles and where it is stored or transmitted.

  3. Designate an appropriate Qualified Individual.

  4. Develop and maintain a written information security program or WISP.

  5. Identify and assess relevant risks as required for your firm.

  6. Implement appropriate access controls and multi-factor authentication.

  7. Protect customer information through encryption or permitted alternative controls where applicable.

  8. Review who has access to client and taxpayer information.

  9. Address secure disposal and legitimate retention requirements.

  10. Provide appropriate security awareness training to personnel.

  11. Evaluate and oversee service providers that handle customer information.

  12. Monitor and test safeguards as required.

  13. Update the program when systems, personnel, operations, or risks change.

  14. Prepare for security incidents and applicable notification obligations.

  15. Check whether additional federal or state requirements apply to your practice.

A checklist can organize the work, but compliance still depends on the firm's actual information, systems, risks, vendors, and applicable requirements.

Why Employee Awareness Matters for Tax Preparers

Tax data security is not only an IT issue.

Employees and seasonal staff may handle customer information every day, opening documents, accessing tax software, responding to client emails, using shared systems, and communicating with service providers.
Tax preparation employees receiving cybersecurity and information security awareness training

The Safeguards Rule addresses security awareness training for personnel, while IRS WISP guidance also identifies employee training and management as a central part of the security plan. 

Training should help employees understand responsibilities such as securing information handling, access controls, recognizing social-engineering attempts, following internal procedures, and reporting suspected security events promptly.

For teams that need a structured way to introduce these responsibilities, FTC Safeguards Rule Awareness Training can help employees build foundational awareness around information security, common risks, and their role in supporting the organization's program. The course provides a certificate of completion; it does not replace the organization's WISP, technical safeguards, risk-management responsibilities, or other compliance obligations. 

What If a Tax Practice Has a Data Breach or Security Incident?

The Safeguards Rule also contains a federal notification requirement for certain security events.

When FTC Notification May Be Required

The FTC's breach-notification requirement took effect in May 2024.

A covered financial institution must notify the FTC as soon as possible, and no later than 30 days after discovery, when it experiences a qualifying “notification event” involving the unauthorized acquisition of at least 500 consumers' unencrypted customer information. Under the rule, encrypted information can also be treated as unencrypted for this purpose when an unauthorized person accesses the encryption key. 

Not every security incident automatically meets that federal reporting threshold. Firms should evaluate the facts against the rule rather than assuming that every suspicious email or failed login creates an FTC notification obligation.

Federal Compliance Does Not Replace State Requirements

The FTC Safeguards Rule is a federal requirement.

A tax practice may also have obligations under state breach-notification, privacy, information-security, or professional rules. Which state requirements apply can depend on where the business operates, where affected individuals reside, and the information involved.

The FTC itself cautions that satisfying the Safeguards Rule does not replace other applicable federal or state obligations. 

For that reason, a tax firm dealing with an actual breach should evaluate both the FTC Rule and any other laws that may apply to the incident.

Build Compliance Around the Way Your Tax Practice Actually Works

The FTC Safeguards Rule is relevant to tax preparers because tax preparation firms are specifically identified within the Rule's financial-institution framework. For covered practices, compliance means maintaining an information security program that fits the business, not simply completing one document or installing one security tool.


Frequently Asked Questions

01 Does the FTC Safeguards Rule apply to solo tax preparers? +

It can. Being a sole practitioner does not automatically remove a tax preparation business from the Rule. The FTC specifically identifies tax preparation firms as examples of covered financial institutions. Firms maintaining customer information concerning fewer than 5,000 consumers may qualify for limited relief from four specified provisions, but not from the Rule as a whole.

02 Are tax preparers required to have a WISP? +

Yes. The IRS states that tax professionals are required by law to create a Written Information Security Plan to protect client data. IRS Publication 5708 provides tax- and accounting-specific guidance for developing one. 

03 Does the FTC Safeguards Rule require MFA? +

The Rule generally requires multi-factor authentication for people accessing customer information on covered systems. It also allows another form of secure access control if the Qualified Individual approves in writing an equivalent alternative.

04 Can an outside IT provider be the Qualified Individual? +

Yes. The Qualified Individual may work for the financial institution, an affiliate, or a service provider. However, outsourcing the role does not remove the tax firm's responsibility for its information security program.

05 Is the FTC Safeguards Rule the same as IRS Publication 4557 or Publication 5708? +

No. The Safeguards Rule is a federal regulation administered by the FTC for covered financial institutions under its jurisdiction. IRS Publications 4557 and 5708 are tax-professional-focused resources that help businesses understand and implement data-security practices, including development of a WISP.

Precision Compliance Training Built for Your Business.
We’re constantly expanding our U.S. compliance courses to fit your exact needs. Whether that’s state-specific mandates, niche industry standards, or scalable training for your workforce. Reach out today to build your custom plan.
Request Custom Training
Ready to Write Your Success Story?
Join thousands of students who have already transformed their careers. Start your learning journey today and become our next success story.