The FTC Safeguards Rule for tax preparers is the reason your practice needs a written security plan, and it is more specific than most summaries suggest. It is not general advice about being careful with client data. It is ten named obligations at 16 CFR 314.4, each of which a practice either meets or does not.
The short version: preparing tax returns for compensation makes you a financial institution under the Gramm-Leach-Bliley Act, which puts you inside the Rule. The Rule then tells you what your information security programme must contain.
What this guide covers
- Why a tax practice is a “financial institution”
- What the Rule actually requires
- The eight safeguards at 314.4(c)
- What changed on 13 May 2024
- The exemption for smaller practices
- Where practices most often fall short
Why a tax practice is a “financial institution”
The phrase reads oddly the first time. The Gramm-Leach-Bliley Act uses “financial institution” far more broadly than everyday usage: it covers businesses significantly engaged in activities that are financial in nature. Tax preparation for compensation qualifies, which is why the FTC’s Safeguards Rule reaches practices that would never describe themselves as financial institutions.
The IRS states the consequence directly — federal law requires tax and accounting professionals to create and maintain a Written Information Security Plan — and the Security Summit reissues that reminder to practitioners each year.
What the Rule actually requires
16 CFR 314.3 requires a comprehensive information security programme, written in one or more readily accessible parts. 16 CFR 314.4 then lists what that programme must contain, in ten lettered elements:
| Element | Obligation |
|---|---|
| (a) | Designate a Qualified Individual to oversee, implement and enforce the programme |
| (b) | Base the programme on a risk assessment, and periodically reassess |
| (c) | Design and implement safeguards to control the identified risks |
| (d) | Regularly test or monitor the effectiveness of key controls |
| (e) | Train personnel and use qualified information security people |
| (f) | Oversee service providers, including by contract |
| (g) | Evaluate and adjust the programme in light of testing, changes and new risks |
| (h) | Establish a written incident response plan |
| (i) | Report in writing, at least annually, to a board or senior officer |
| (j) | Notify the FTC about notification events |
The Qualified Individual may sit with a service provider — an MSP or a fractional CISO — but three conditions attach: the practice keeps responsibility for compliance, it must designate a senior member of its own personnel to direct and oversee that individual, and it must require the provider to maintain its own programme protecting the practice. Outsourcing the work does not outsource the accountability.
The eight safeguards at 314.4(c)
Element (c) is where most of the work sits, and it names eight specific things:
- Access controls, reviewed periodically, limiting each user to the information they need
- Inventory of the data, personnel, devices, systems and facilities involved
- Encryption of customer information in transit over external networks and at rest
- Secure development practices for anything built in-house, and evaluation of applications you buy
- Multi-factor authentication for any individual accessing any information system
- Secure disposal, with a default of two years after last use, and periodic review of retention
- Change management procedures
- Logging and monitoring of authorised user activity, and detection of unauthorised access
Two carry a written escape hatch and only one person can use it. Where encryption at rest is infeasible, or where MFA is not implemented, the Qualified Individual may approve alternative or equivalent controls — in writing. Without that written approval the safeguard is simply absent. Note also that the encryption obligation covers information at rest, which is where the practice mailbox usually fails: TLS in transit is common, while the mailbox itself holds years of returns in readable form.
What changed on 13 May 2024
Element (j), FTC notification, took effect on that date. Where a notification event involves the information of at least 500 consumers, the practice must notify the Commission as soon as possible and no later than 30 days after discovery, electronically on a form on the FTC’s website. The notice has to carry six specified items, including the types of information involved, the number of consumers affected or potentially affected, and whether a law enforcement official has issued a written determination that public notice would impede an investigation.
A notification event turns on acquisition of unencrypted customer information without authorisation. That makes the encryption position of each store worth establishing in advance rather than during an incident — it is the difference between a bad week and a regulatory filing.
Discovery is defined broadly: the event is treated as discovered on the first day it is known to any employee, officer or other agent of the practice, other than whoever committed the breach.
The exemption for smaller practices
16 CFR 314.6 disapplies four elements for a practice maintaining customer information on fewer than five thousand consumers: the requirement that the risk assessment be written at 314.4(b)(1), the penetration testing and vulnerability assessment route at 314.4(d)(2), the written incident response plan at 314.4(h), and the annual written report at 314.4(i).
It removes the writing, not the doing. A practice under the threshold still has to base its programme on a risk assessment, still has to test or monitor its key controls under 314.4(d)(1), and still has to respond to security events. Nothing else is disapplied — MFA, encryption, disposal, training, service provider oversight and FTC notification all apply to a sole practitioner exactly as they apply to a large firm. We cover the counting and the consequences in WISP for a sole practitioner.
Where practices most often fall short
Four gaps recur, and none of them is exotic:
- Service provider contracts. The Rule requires the safeguards obligation to be imposed by contract. A general IT support agreement that never mentions safeguards does not satisfy 314.4(f)(2), however capable the provider is.
- MFA on the forgotten systems. The tax software usually has it. The backup console, the domain registrar and the router admin usually do not — and those are exactly where an attacker goes to make an incident unrecoverable.
- Access after the season. Accounts opened quickly in January, granted broad access so nobody is blocked, and never removed in May.
- Evidence. A control that is genuinely performed but leaves no record cannot be produced to an examiner, an insurer or an acquirer.
If you want the whole thing laid out document by document, our WISP Toolkit maps 74 editable templates directly onto the ten elements, and the written information security plan template guide covers what the document itself has to contain.