The FTC Rule That Applies to Your CPA Firm and Nobody Told You
The Safeguards Rule covers tax preparers, accountants, and many financial advisers. What the written information security program requires and how to build one.
The short answer
The FTC Safeguards Rule under the Gramm-Leach-Bliley Act defines financial institution broadly enough to cover most firms that prepare returns or provide financial advice. It requires a written information security program with nine elements, including a designated qualified individual, a written risk assessment, mandatory multi-factor authentication, and an incident response plan.
A meaningful number of Arizona accounting firms, tax preparers, and financial advisory practices are subject to a federal information security regulation they have never heard of. The Federal Trade Commission's Safeguards Rule, made under the Gramm-Leach-Bliley Act, defines financial institution broadly enough to include most firms that prepare returns or provide financial advice, not just banks.
The rule was substantially amended and the current requirements have been in force since 2023. The IRS also expects tax professionals to maintain a written security plan, and has tied it to PTIN renewal messaging.
This is a summary, not legal advice. Confirm applicability with your own counsel.
The core obligation
You must maintain a written information security program, commonly called a WISP, that is appropriate to your size and complexity, the nature of your activities, and the sensitivity of the information you handle.
Written matters. An undocumented set of good practices does not satisfy the rule, and in an FTC inquiry the document is the first request.
Nine elements the rule expects
Designate a qualified individual responsible for the program. One named person. In a small firm this can be a partner, and the function can be supported by an outside provider, but accountability stays with you and cannot be outsourced away.
Conduct a written risk assessment. Identify reasonably foreseeable internal and external risks to customer information, evaluate the sufficiency of your existing safeguards, and document it. This drives everything else.
Implement safeguards to address the identified risks, including specific ones the rule names: access controls, an inventory of data and the systems that hold it, encryption of customer information in transit and at rest, secure development practices where applicable, multi-factor authentication for anyone accessing customer information, secure disposal of information generally within two years of last use, change management, and monitoring of authorized user activity.
Multi-factor authentication is worth pausing on. It is not conditional and it applies to any individual accessing customer information on your systems. Firms with a remote-access path that still uses a password alone are out of compliance today.
Regularly test or monitor the effectiveness of your safeguards. Either continuous monitoring, or annual penetration testing plus vulnerability assessments at least twice a year and after material changes.
Train your staff, and use qualified security personnel.
Oversee your service providers. Select them based on their ability to safeguard information, require it by contract, and periodically assess them.
Keep the program current, and evaluate and adjust it based on testing results, changes in your business, and new threats.
Establish a written incident response plan covering goals, internal processes, roles and responsibilities, communications, remediation, documentation, and post-incident evaluation.
Report to the board or a senior officer at least annually, in writing.
The breach reporting obligation people miss
An amendment requires notice to the FTC of a security event involving unencrypted customer information of 500 or more consumers, submitted through the FTC's online form, generally as soon as possible and no later than 30 days after discovery.
That is a short clock and it runs from discovery, not from the end of your investigation. Knowing this before an incident is the difference between a filing and a late filing.
The exemption that may or may not help you
Firms that maintain customer information on fewer than 5,000 consumers are exempt from a subset of requirements: the written risk assessment, continuous monitoring or penetration testing, the incident response plan, and the annual reporting.
Two cautions. Count carefully, because the threshold counts consumers whose information you maintain, which includes prior year clients and the individuals inside business returns. And note that the exemption removes documentation requirements, not the underlying obligation to have a security program. Most firms near the line should build the full program anyway, since the exempted items are the ones that actually reduce risk.
What good looks like in a 15-person firm
A ten to fifteen page WISP that names the qualified individual, references your actual systems, and is signed and dated. A risk assessment refreshed annually. MFA everywhere, particularly on email and remote access, since compromised firm email is the leading cause of tax-related client fraud. Encrypted laptops. A written data map showing where client information lives. Vendor agreements with security terms. An incident response plan with the FTC form URL and your carrier's number already in it. An annual memo to the partners.
That is achievable in a few weeks of focused work and it is the difference between a defensible position and an indefensible one.
Get the template
The WISP Template and Gap Assessment includes a fillable written program mapped to each element of the rule, a risk assessment worksheet, a data inventory sheet, the service provider oversight register, an incident response plan with the reporting timeline built in, and the annual report format for your partners.
Run the gap assessment first. Most firms discover they have six of nine elements informally and no documentation of any of them.
Frequently asked questions
Does the FTC Safeguards Rule apply to accounting firms?
In many cases yes. The rule defines financial institution broadly enough to include tax preparers, accountants, and many financial advisory practices, not just banks. Confirm applicability with your own counsel, and note that the IRS also expects tax professionals to maintain a written security plan.
What is a WISP and what must it contain?
A written information security program. It must designate a qualified individual, include a written risk assessment, implement named safeguards including access controls, data inventory, encryption, and multi-factor authentication, provide for testing, train staff, oversee service providers, include a written incident response plan, and require annual written reporting.
Is multi-factor authentication required under the Safeguards Rule?
Yes, and it is not conditional. It applies to any individual accessing customer information on your systems. A firm with a remote access path still using a password alone is out of compliance today.
Does the under-5,000 consumer exemption help my firm?
It removes four documentation requirements: the written risk assessment, continuous monitoring or penetration testing, the incident response plan, and annual reporting. Count carefully, because the threshold includes prior year clients and individuals inside business returns. Most firms near the line should build the full program anyway, since the exempted items are the ones that actually reduce risk.
