Cartoon: FTC Safeguards Rule Compliance Checklist for CPA Firms

FTC Safeguards Rule Compliance Checklist for CPA Firms

August 25, 2026

The FTC Safeguards Rule requires CPA firms to implement a written information security plan covering 9 specific elements: designating a qualified individual to oversee the program, conducting risk assessments, designing and implementing safeguards, regularly monitoring effectiveness, training staff, selecting qualified service providers, keeping the plan current, creating an incident response plan, and reporting security events within 72 hours of discovery.

What Does the FTC Safeguards Rule Require from CPA Firms?

The FTC Safeguards Rule applies to any business that is a "financial institution" under the Gramm-Leach-Bliley Act. CPA firms fall under this definition because they regularly handle customer financial information during tax preparation, bookkeeping, and advisory services.

The rule mandates a comprehensive written information security program tailored to your firm's size, complexity, and activities. This isn't a one-time checklist but an ongoing obligation to protect client data from unauthorized access.

Salt Lake City CPA firms must also comply with Utah's data breach notification law, which requires notification to affected individuals when computerized personal information is compromised. The FTC Safeguards Rule sets the baseline security standard that helps prevent breaches in the first place.

Kari from a local accounting firm explains the challenge: "911 IT has been an invaluable partner for our accounting firm, especially when it comes to meeting strict IRS and PCI security requirements. They've helped us implement and maintain backend network protocols and compliance measures that are far beyond our technical understanding."

The rule's requirements touch every aspect of your IT infrastructure, from how you store engagement files to how employees access client portals remotely during busy season.

What Are the 9 Required Security Elements?

The FTC Safeguards Rule specifies nine security elements that every covered financial institution must address. Each element requires documentation, implementation, and ongoing monitoring.

Element 1: Designate a Qualified Individual. You must appoint someone to oversee your information security program. For smaller CPA firms, this might be a managing partner or office manager, but they need either expertise or access to expertise. Many firms partner with a managed IT provider to fill this role or support the designated individual.

Element 2: Conduct a Risk Assessment. You must identify reasonably foreseeable internal and external risks to customer information. This includes evaluating where client data lives (servers, workstations, cloud applications, email, backup systems), who has access, and how it's transmitted.

Element 3: Design and Implement Safeguards. Based on your risk assessment, you must implement controls to address identified risks. This includes access controls, data encryption, secure development practices if you use custom software, and multi-factor authentication for any system accessing customer information.

Element 4: Monitor and Test Effectiveness. Regular monitoring of your security controls is mandatory. This includes continuous monitoring or periodic penetration testing and vulnerability assessments at least annually.

Element 5: Train Your Staff. All personnel must receive security awareness training appropriate to their role. During tax season when you might bring on seasonal staff or work with remote contractors, training becomes even more critical.

Element 6: Select Qualified Service Providers. Any vendor with access to customer information must maintain appropriate safeguards. You must have written contracts requiring them to protect client data and periodically assess their security measures.

Element 7: Keep Your Plan Current. Your information security plan must be a living document that evolves as your firm grows, technology changes, and new threats emerge. Regular reviews and updates are required.

Element 8: Create an Incident Response Plan. You need documented procedures for responding to security events, including how you'll contain breaches, notify affected parties, and restore operations.

Element 9: Report Security Events. If you experience a security event affecting 500 or more consumers, you must notify the FTC within 72 hours. This tight deadline requires having detection and notification procedures already in place.

These nine elements work together as an integrated security framework, not isolated checkboxes.

How Do You Implement Technical Safeguards for Client Data?

Technical safeguards form the backbone of FTC Safeguards compliance. These are the actual security controls protecting client data from unauthorized access, whether from external attackers or internal mistakes.

Encryption Requirements. The rule specifically requires encryption of customer information at rest (stored on servers, workstations, and backup systems) and in transit (moving across networks or to cloud services). For CPA firms, this means encrypting tax returns, engagement files, bank reconciliations, and any other documents containing client financial data.

Your secure file sharing system, client portal, and email must all use encryption. Many firms discover their existing tools don't meet this standard when they conduct their first compliance assessment.

Multi-Factor Authentication. MFA is mandatory for any system accessing customer information. This includes your tax software, practice management system, remote desktop access, email, and cloud storage. A username and password alone no longer satisfies the rule.

During busy season when staff work remotely or access systems from home, MFA becomes your critical defense against compromised credentials.

Access Controls. You must limit access to customer information based on job function. Not every employee needs access to every client file. Role-based access controls ensure tax preparers see only their assigned clients, administrative staff access only what they need for billing, and partners maintain oversight visibility.

Secure Development Practices. If your firm uses any custom applications or macros to process client data, you must follow secure development procedures. Most CPA firms rely on commercial software, but this becomes relevant if you've built Excel tools, Access databases, or custom integrations.

Network Security. Firewalls, intrusion detection systems, and network segmentation protect the infrastructure housing client data. Your wireless network requires enterprise-grade security, not the consumer-grade router that came from your internet provider.

Dianna from an accounting firm experienced the value of proactive technical safeguards: "They are proactive and always looking towards the future to solve potential problems before they become actual problems. I was very impressed before quarantine was implemented: 911 IT reached out to us to develop a plan to be able to move all of our employees home if the need arose. Of course, the need did come, and we were able to continue operations."

Technical safeguards require ongoing maintenance, not one-time setup. Software updates, security patches, and configuration reviews must happen regularly.

What Documentation Does the FTC Require?

The FTC Safeguards Rule is documentation-heavy by design. Written policies prove you've thought through security systematically and provide accountability when incidents occur.

Written Information Security Plan. Your core compliance document must describe your security program, identify the qualified individual overseeing it, document your risk assessment process and findings, list the safeguards you've implemented, and explain how you monitor effectiveness.

This isn't a generic template downloaded from the internet. The FTC expects a plan specific to your firm's actual systems, data flows, and risk profile.

Risk Assessment Documentation. You must document what customer information you collect and store, where it's located (on-premises servers, cloud applications, employee devices), who has access, how it's transmitted, and what threats you've identified. This assessment must be updated when your business changes significantly.

Service Provider Agreements. Every vendor with access to customer information needs a written contract requiring them to maintain appropriate safeguards. This includes your tax software vendor, cloud backup provider, IT support company, and even your copier lease company if the device stores scanned client documents.

For Salt Lake City CPA firms, this often includes relationships with local banks, investment firms, and business clients where data flows both directions.

Training Records. You must document that employees received security awareness training and when. This protects you if an employee causes a breach by falling for a phishing email or mishandling client data.

Testing and Monitoring Reports. Your vulnerability scans, penetration tests, and security monitoring reviews must be documented with dates, findings, and remediation actions taken.

Incident Response Plan. This written plan outlines who does what when a security event occurs, how you'll investigate and contain the incident, your notification procedures, and how you'll restore normal operations.

Documentation serves two purposes: it forces you to think through security systematically, and it provides evidence of compliance if the FTC investigates a breach at your firm.

How Do You Maintain Ongoing Compliance Throughout the Year?

FTC Safeguards compliance isn't a project with an end date. The rule requires continuous monitoring, regular assessments, and updates as your firm and the threat landscape evolve.

Annual Risk Assessments. At least once per year, you must review your risk assessment. Has your firm added new cloud services? Do you have new employees? Have you started offering new services that involve different types of client data? Each change potentially introduces new risks.

Many CPA firms schedule this review for summer after tax season ends, when there's bandwidth to think strategically about security rather than just surviving the next deadline.

Quarterly Security Reviews. While not explicitly required on a quarterly basis, best practice involves regular check-ins on your security program. Review access logs for unusual activity, verify that departed employees no longer have system access, confirm backups are running successfully, and check that security patches are current.

Continuous Monitoring. Your network security tools should provide ongoing visibility into potential threats. This includes monitoring for malware, unusual login attempts, large data transfers, and configuration changes to critical systems.

For firms without in-house IT staff, this monitoring typically comes from a managed IT services provider with 24-7 security operations capabilities.

Staff Training Refreshers. Security awareness training isn't one-and-done. Phishing tactics evolve, new scams emerge, and employees forget. Plan for at least annual training, with more frequent reminders during tax season when everyone is rushed and more likely to click without thinking.

Plan Updates. Your written information security plan must be updated whenever you make significant changes to your business or security measures. Added a new office location? Implemented a new practice management system? Experienced a security incident that revealed gaps? Each triggers a plan update.

Vendor Reviews. Periodically assess whether your service providers still maintain appropriate safeguards. This might involve reviewing their SOC 2 reports, asking about their security practices, or conducting your own assessment of how they handle your client data.

The ongoing nature of compliance is why many CPA firms partner with specialized IT providers who understand financial services requirements and can maintain the technical infrastructure while the firm focuses on serving clients.

Firms working with 911 IT for CPA and financial firm IT support receive continuous compliance monitoring as part of their managed services, ensuring the technical safeguards remain effective year-round.

Who Should CPA Firms in Salt Lake City Work With for FTC Safeguards Compliance?

Most CPA firms lack the in-house IT expertise to implement and maintain FTC Safeguards compliance on their own. The question becomes whether to hire internal IT staff or partner with a managed service provider.

For firms with fewer than 50 employees, hiring a full-time IT person rarely makes financial sense. The salary, benefits, and training costs exceed what you'd pay for comprehensive managed IT services, and one person can't provide the breadth of expertise needed for security, compliance, cloud services, and day-to-day support.

Salt Lake City CPA firms have several local IT providers to consider:

  • 911 IT: Specializes in financial services compliance including FTC Safeguards, with proactive monitoring, 24-7 support, and a 100% satisfaction guarantee. Serves CPA firms across Utah, Wyoming, and Arizona with deep understanding of tax season demands and client data protection requirements.
  • Executech: Large regional MSP serving multiple industries with enterprise-scale capabilities.
  • Wasatch I.T.: Utah-based provider offering managed services and cybersecurity.
  • Nexus IT Consultants: Local MSP with business technology focus.
  • INTELITECHS: Regional provider with compliance expertise.
  • A national-chain MSP: Enterprise-focused providers with standardized service delivery models.

The right fit depends on your firm's size, complexity, and how much attention you need. At large national providers, a 12-person CPA firm is one account among thousands, often routed through ticket queues and served by rotating junior technicians. When you call during a tax season crisis, you're competing with hundreds of other tickets for attention.

911 IT operates at the sweet spot for CPA firms: large enough to handle everything an enterprise provider can, including complex compliance requirements and 24-7 monitoring, but small enough that every client is known by name and genuinely matters. When Kari's firm needs help with IT issues, she doesn't need to explain everything from scratch because the team already knows their setup.

This matters enormously during tax season when downtime costs you client relationships. Mark from an insurance firm (facing similar compliance requirements) explains: "Their responsiveness is the best I've seen in the industry. Phone calls are answered and with their online support capabilities, most issues are resolved within minutes."

For FTC Safeguards compliance specifically, you need a provider who understands financial services regulations, can document everything the FTC requires, and maintains the technical safeguards continuously rather than just checking boxes during an initial setup.

911 IT's process-driven approach to cybersecurity and compliance ensures your firm meets all nine required elements with documented evidence, ongoing monitoring, and regular reviews that keep your information security plan current as threats evolve.

What Does FTC Safeguards Compliance Cost?

The cost of FTC Safeguards compliance depends on your firm's size, existing security posture, and whether you need to remediate significant gaps or just formalize what you're already doing.

For most CPA firms, compliance costs fall into three categories: initial assessment and implementation, ongoing technical safeguards, and annual maintenance.

Initial Assessment and Gap Remediation. A thorough compliance assessment identifies where your current security measures fall short of FTC requirements. This typically costs between $3,000 and $8,000 depending on firm size and complexity. If the assessment reveals significant gaps (no encryption, weak access controls, missing documentation), remediation might add another $5,000 to $15,000 in project work.

Firms that have been working with a proactive IT provider often discover they're closer to compliance than they thought, reducing initial costs.

Ongoing Technical Safeguards. The technical infrastructure required for compliance (encryption, MFA, network security, monitoring, backup) typically comes through managed IT services. For a 10-person CPA firm, expect $500 to $2,000 monthly for the technical compliance infrastructure.

This covers the continuous monitoring, security updates, access management, and incident response capabilities that the rule requires.

Annual Compliance Maintenance. Your annual risk assessment, plan updates, penetration testing, and compliance documentation review might cost $2,000 to $5,000 per year if handled separately, though many firms include this in their managed services agreement.

The FTC can impose civil penalties up to $50,120 per violation for Safeguards Rule non-compliance, with each affected customer potentially representing a separate violation.

A breach affecting 200 clients could theoretically result in penalties exceeding $10 million, though actual penalties vary based on circumstances. More realistically, the reputational damage from a client data breach during tax season could cost you client relationships worth far more than compliance would have cost.

911 IT's flat-rate, transparent pricing model makes compliance costs predictable, eliminating surprise bills during tax season when you can least afford distractions from serving clients.

Frequently Asked Questions

Does the FTC Safeguards Rule apply to all CPA firms?

The FTC Safeguards Rule applies to CPA firms that regularly handle customer financial information, making them "financial institutions" under the Gramm-Leach-Bliley Act. This includes firms offering tax preparation, bookkeeping, payroll services, or financial advisory services. Firms exclusively performing audits without handling ongoing financial data may have different compliance obligations, but most CPA practices fall under the rule's scope.

What happens if a CPA firm experiences a data breach?

If your firm experiences a security event affecting 500 or more consumers, you must notify the FTC within 72 hours of discovery. You must also notify affected clients under Utah's breach notification law. The FTC will investigate whether you had reasonable safeguards in place. Documented compliance with the Safeguards Rule demonstrates you took security seriously, potentially reducing penalties. Lack of compliance can result in significant fines and enforcement actions.

Can we use consumer-grade tools like Dropbox for client files?

Consumer-grade file sharing tools typically don't meet FTC Safeguards requirements unless configured properly with business accounts, encryption, access controls, and appropriate service provider agreements. The rule requires encryption at rest and in transit, multi-factor authentication, and documented vendor security assessments. Business-grade secure file sharing solutions designed for financial services better satisfy these requirements with built-in compliance features and appropriate vendor contracts.

How often must we conduct security awareness training?

The FTC Safeguards Rule requires security awareness training for all personnel but doesn't specify frequency. Best practice for CPA firms includes comprehensive training at hire, annual refresher training for all staff, and targeted reminders during tax season when phishing attacks increase. Training must be appropriate to each employee's role, with more detailed security training for staff handling sensitive client data versus administrative personnel with limited system access.

Do we need a full-time IT person to be the qualified individual?

The qualified individual overseeing your information security program doesn't need to be a full-time IT employee. Many CPA firms designate a managing partner or office manager who works with an external managed service provider for technical expertise. The key requirement is that the qualified individual has sufficient knowledge or access to expertise to implement and supervise the security program effectively. Documented partnership with a qualified IT provider satisfies this requirement.

What's the penalty for non-compliance with the FTC Safeguards Rule?

The FTC can impose civil penalties up to $50,120 per violation for Safeguards Rule non-compliance. Each affected customer can potentially represent a separate violation, making penalties for breaches affecting hundreds of clients extremely severe. Beyond monetary penalties, the FTC can require corrective actions, ongoing compliance monitoring, and public disclosure of security failures. The reputational damage to a CPA firm from publicized non-compliance often exceeds direct financial penalties.