Free Resource · guide

What Does the FTC Safeguards Rule Require of a CPA Firm?

The FTC Safeguards Rule requires a CPA firm to maintain a written information security program with a named person accountable for it, built on a risk assessment and backed by specific controls: access restrictions, encryption, multi-factor authentication, monitoring, vendor oversight, an incident response plan, and employee training. If your firm prepares tax returns or handles client financial data, you are covered. The rule applies to far more than banks.

If your firm prepares tax returns, keeps client books, or advises clients on their finances, the FTC Safeguards Rule applies to you. It requires a written, working information security program with a named person responsible for it, and it spells out the controls that program must contain. This article walks through who is covered, what each required element means in practice, how IRS Publication 4557 fits in, and which parts an IT provider can carry versus what the firm itself must own. One note up front: this is a practical overview from an IT provider, not legal advice, so bring your attorney into any question about your specific obligations.

Why does a rule about “financial institutions” apply to a CPA firm?

The Safeguards Rule comes out of the Gramm-Leach-Bliley Act, and GLBA defines “financial institution” much more broadly than everyday usage. It covers businesses significantly engaged in financial activities, which the FTC has long interpreted to include tax preparers, accountants who prepare returns, and financial advisors who handle customer financial information, not just banks and lenders. Banks answer to their own banking regulators; the FTC enforces the rule for the non-bank businesses, which is where a CPA firm sits.

The practical test is simple. If clients hand you Social Security numbers, income figures, bank account details, or investment information so you can perform a financial service for them, you should assume you are covered. The FTC’s own plain-language guide, FTC Safeguards Rule: What Your Business Needs to Know, lists the kinds of businesses in scope, and tax preparation is on it.

There is a partial carve-out worth knowing about: firms that maintain customer information on a relatively small number of consumers are exempt from a few of the formal elements, such as the written risk assessment and the written incident response plan. The core duty to actually safeguard the data applies regardless of size, so treat the exemption as a paperwork reduction, not a pass.

What does the rule actually require? The checklist

The rule requires an information security program that is written, appropriate to your firm’s size and complexity, and built around specific elements. Here is each one as it looks inside an accounting practice.

A written information security program (WISP). The umbrella document. It describes what data you hold, where it lives, who is accountable, what risks you identified, and what controls address them. Unwritten “we’re careful” practices do not count. If the program is not on paper, from the rule’s perspective it does not exist.

A designated qualified individual. One named person responsible for overseeing, implementing, and enforcing the program. At most firms this is a partner or the firm administrator. You can lean on outside help, but the designation is the firm’s.

A written risk assessment. An inventory of the client data you hold and the systems it touches, tax software, document portals, email, file shares, laptops, and an honest evaluation of what could go wrong with each. Every control that follows is supposed to trace back to a risk identified here.

Access controls. Client data restricted to the people who need it for their work. In a firm this means individual logins rather than shared ones, permissions on the tax and document systems that match roles, and access removed promptly when staff leave, including seasonal preparers.

Encryption in transit and at rest. Client information encrypted when it moves, which is why documents go through a secure portal instead of email attachments, and encrypted where it sits, on laptops, servers, and in cloud storage. A preparer’s laptop lost at an airport is a very different event depending on whether the drive was encrypted.

Multi-factor authentication. MFA for anyone accessing systems that hold customer information: email, tax software, portals, remote access. Stolen passwords are the most common way into a firm, and this is the control that blunts them.

Monitoring and logging. The rule expects you to monitor activity on your systems and to detect problems, through continuous monitoring or through periodic testing of your controls. Practically, that means logs someone actually reviews and alerting when something looks wrong, not software running unwatched.

Vendor oversight. Your tax software vendor, portal provider, cloud host, and IT provider all touch client data. The rule expects you to select providers capable of protecting it, to hold them to that in your agreements, and to check periodically that they still measure up.

A written incident response plan. Who does what when something goes wrong: who isolates systems, who calls the attorney and the insurer, who notifies clients and authorities if it comes to that. Written before the incident, because a firm improvising at 7 a.m. during filing season makes poor decisions.

Employee training. Staff trained on the program and on the attacks they will actually see, phishing and payment fraud above all. Seasonal staff need it too, and they are the group most often missed.

Periodic reassessment. The program adjusts as the firm changes: new software, new staff, a merger, an incident, or new threats. A WISP written once in 2023 and never touched no longer describes the firm it is supposed to protect.

How do IRS Publication 4557 and the tax preparer WISP fit in?

If your firm holds PTINs, you have seen the IRS side of this. IRS Publication 4557, Safeguarding Taxpayer Data, is the IRS guidance for tax professionals on protecting client information, and it points directly at the FTC Safeguards Rule as the legal requirement behind it. The IRS and the Security Summit have pressed the same message for years: every tax professional needs a written data security plan, and PTIN holders attest to their data security responsibilities as part of PTIN renewal.

So the two are not separate compliance projects. The FTC rule is the legal obligation, Pub 4557 is the IRS translating that obligation for tax practices, and the WISP is the document both point to. Build one program that satisfies the Safeguards Rule elements above and you have satisfied what Pub 4557 describes. The IRS and Security Summit have also published a WISP template for tax pros, which is a reasonable skeleton, though a template with your firm’s name typed in is only a starting point. The rule expects the program to reflect your actual systems and risks, which is where most templates end and real work begins.

What can an MSP do, and what must the firm own?

This division matters, because firms sometimes assume hiring an IT provider settles the question, and providers sometimes let them believe it.

The firm owns: the designation of the qualified individual, approval of the risk assessment and the written program, decisions about acceptable risk, oversight of service providers (including the MSP itself), and ultimate accountability if the FTC ever asks questions. None of that can be delegated away.

An MSP implements and evidences: the technical controls and the proof they are working. In a Safeguards engagement, that looks like deploying and enforcing MFA, encrypting laptops and servers, running monitoring and logging with someone watching it, managing access as staff come and go, keeping systems patched, delivering security awareness training with phishing simulation, maintaining tested backups, and producing the documentation, asset inventories, training records, monitoring reports, that turns “we have a program” into something you can show. That evidence trail is half the value: when a cyber insurance application or a client’s due diligence questionnaire asks the same questions the rule does, the answers are already on file.

The honest framing: the firm holds the pen and the accountability, the MSP does the daily work and generates the proof. Our cybersecurity services cover the control side, and the CPA and financial advisor industry page describes how we run this for accounting practices specifically. If you are evaluating providers, our guide to what belongs in a managed IT agreement for a CPA firm shows how these obligations should appear in the contract itself.

What happens if a firm ignores it?

The FTC can bring enforcement actions against covered businesses that fail to maintain a compliant program, and it has done so against non-bank financial institutions. Separately, an amendment to the rule added a reporting requirement: when a covered institution discovers a security event involving the unencrypted information of 500 or more consumers, it must notify the FTC as soon as possible and no later than 30 days after discovery. That changes the calculus after a breach. A firm with no program does not just have a security problem, it has a regulator notification with its name on it.

The quieter consequences arrive sooner. Cyber insurance applications now ask for the same controls the rule requires, and a firm that cannot attest to MFA and encrypted backups struggles to get covered at all. Business clients increasingly send security questionnaires before handing over their books. And the underlying attacks the rule guards against, phishing that leads to wire fraud and business email compromise, or ransomware that hits the firm’s tax software and QuickBooks data, are aimed at accounting firms regardless of what the FTC does.

Where should a firm start?

Start with the risk assessment, because everything else depends on it: list what client data you hold, where it lives, and who can touch it. Then close the highest-impact control gaps, MFA and encryption first, since they blunt the most common attacks and anchor every questionnaire you will ever fill out. Then write the program down, name the qualified individual, and put training and an incident response plan in place. A firm of typical size can get through that sequence in weeks, not a filing season.

Braintek has supported Texas businesses since 2002, with staff in Houston, DFW, and the Philippines, and we run this exact program for accounting and advisory practices. Phone calls are typically answered within about 60 seconds and emailed tickets typically get a response within about 2 hours, which matters most in the weeks when your firm can least afford downtime. If you want to know where your firm stands, start with the CPA and financial advisor page or send us a note through the form below, and we will walk the checklist with you.

Not sure where your firm stands on the Safeguards Rule?

Tell us a little about your firm and we'll walk through the required elements with you, point out which ones you already satisfy, and give you a straight list of what's missing. No scare tactics, just the checklist and where you sit on it.

By submitting, you agree to be contacted by Braintek about your inquiry.

FAQs

Does the FTC Safeguards Rule really apply to a small CPA firm?

Yes. The rule covers non-bank financial institutions, and the FTC's definition includes businesses that prepare tax returns or handle customer financial information. Firm size does not remove you from coverage. Firms that maintain information on a smaller number of consumers are exempt from a few of the formal documentation requirements, but the core security obligations still apply.

What is a WISP and do we need one?

A WISP is a written information security program: the document that describes how your firm protects client data, who is responsible for the program, what risks you identified, and what controls address them. The Safeguards Rule requires the program in writing, and the IRS reinforces the same expectation for tax professionals, so yes, a tax practice needs one.

Who should be our qualified individual?

Someone at the firm with the authority to run the program, often a partner or firm administrator. The rule allows you to use a service provider such as an MSP to help, but the designation and the accountability stay with the firm. You cannot outsource ownership of the program, only the technical work inside it.

How does IRS Publication 4557 relate to the Safeguards Rule?

Pub 4557, Safeguarding Taxpayer Data, is the IRS guidance that tells tax professionals how to protect client data, and it points directly at the FTC Safeguards Rule as the underlying legal requirement. It is guidance layered on the same obligation, not a separate competing standard. Meeting the Safeguards Rule properly puts you in line with what Pub 4557 describes.

We use an MSP. Doesn't that make us compliant?

Not by itself. An MSP can implement and monitor the technical controls, produce the evidence, and help maintain the documents, but the rule places the program on the firm. The firm designates the qualified individual, approves the risk assessment, and owns the program. A good MSP makes compliance practical. It does not make it automatic.

Do we have to report a breach to the FTC?

In some cases, yes. Under an amendment to the rule, covered institutions must notify the FTC when they discover a security event involving the unencrypted information of 500 or more consumers, as soon as possible and no later than 30 days after discovery. State breach notification laws and IRS reporting expectations for tax preparers can apply separately, which is a conversation to have with your attorney.

How often does the program need to be updated?

The rule expects the program to be reevaluated and adjusted as your firm, your systems, and the threats change, and the risk assessment is meant to be periodically revisited rather than written once and filed. In practice, an annual review plus updates after any material change, such as new software, a merger, or an incident, keeps you where the rule expects you to be.

Ready for IT that just works?

Book a no-pressure discovery call. We'll review your setup and show you exactly where you stand.