Cartoon: What Are the Requirements for the FTC Safeguards Rule

What Are the Requirements for the FTC Safeguards Rule

August 22, 2026

The FTC Safeguards Rule requires financial institutions - including CPA firms - to develop, implement, and maintain a comprehensive written information security program. The rule mandates 9 specific elements: risk assessments, access controls, encryption of customer data, multi-factor authentication, incident response plans, vendor management, employee training, continuous monitoring, and annual reporting to senior management or the board. Penalties reach $50,685 per violation per day.

Who Must Comply with the FTC Safeguards Rule?

The Safeguards Rule applies to any business classified as a "financial institution" under the Gramm-Leach-Bliley Act. This definition extends far beyond banks and credit unions.

CPA firms, tax preparers, bookkeepers, and accounting practices that handle client financial data fall squarely under this requirement. If your firm prepares tax returns, manages payroll, provides financial planning advice, or stores bank account information, you're subject to the rule.

The Federal Trade Commission enforces compliance for non-bank financial institutions. Utah CPA firms must comply regardless of firm size, though some provisions scale based on employee count and complexity.

Penalties for non-compliance reach $50,685 per violation per day, plus potential state enforcement under Utah's data breach notification laws.

The rule applies to all customer information you collect, store, or transmit - whether in paper files, on workstations, in cloud accounting software, or in client portals. Every firm handling taxpayer data needs a compliance strategy that addresses all nine mandated elements.

What Are the Nine Core Requirements of the Safeguards Rule?

The updated 2023 Safeguards Rule specifies nine mandatory security elements that every covered financial institution must implement in their written information security program.

  1. Designate a Qualified Individual to oversee your information security program. This person coordinates all security efforts and reports directly to senior management or your board. For small CPA firms, this might be a managing partner working with an external IT provider.
  2. Conduct Risk Assessments that identify reasonably foreseeable internal and external risks to customer information. Assessments must evaluate your current safeguards and document how you'll address identified vulnerabilities.
  3. Design and Implement Safeguards to control the risks identified in your assessment. This includes technical controls like firewalls and encryption, plus administrative controls like policies and procedures.
  4. Monitor and Test the effectiveness of your safeguards regularly. You must conduct continuous monitoring or periodic penetration testing and vulnerability assessments at least annually.
  5. Train Your Staff on your information security program. Every employee who handles customer data needs training appropriate to their role, covering security risks and proper data handling procedures.
  6. Oversee Service Providers who access customer information. You must select vendors capable of maintaining appropriate safeguards, require them contractually to protect data, and periodically assess their security measures.
  7. Keep Your Program Current by evaluating and adjusting it in response to changes in your business, technology, or emerging threats. This isn't a set-it-and-forget-it requirement.
  8. Create an Incident Response Plan that defines how you'll respond to a security event affecting customer information. The plan must include containment, notification procedures, and business continuity measures.
  9. Report to Your Board or senior management at least annually. Your qualified individual must provide written reports on the overall status of your information security program and compliance.

These nine elements form the foundation of a defensible security posture that protects client data and satisfies regulatory expectations.

What Specific Technical Controls Does the Rule Require?

Beyond the nine structural requirements, the Safeguards Rule mandates specific technical safeguards that CPA firms must implement to protect customer information.

Encryption is mandatory for all customer information in transit over external networks and at rest. This means encrypting email attachments containing tax documents, securing client portal connections with TLS, and encrypting laptop hard drives and backup media.

Multi-factor authentication (MFA) is required for any individual accessing customer information on your systems. This applies to staff logging into workstations, accessing cloud accounting software, connecting via remote desktop, and retrieving files from your document management system.

Access controls must limit information access to authorized individuals based on business need. You need systems that authenticate users, restrict access by role, log all access to sensitive data, and promptly revoke access when employees leave.

Secure development practices are required if you develop applications that handle customer data. Most CPA firms rely on commercial software, but if you build custom tools or databases, they must follow secure coding standards.

Change management procedures ensure that system changes don't introduce security vulnerabilities. You need documented processes for testing updates, approving changes, and maintaining audit trails of modifications to systems handling customer data.

Kari, who manages technology for a Salt Lake City accounting firm, shared: "911 IT has been an invaluable partner for our accounting firm, especially when it comes to meeting strict IRS and PCI security requirements. They've helped us implement and maintain backend network protocols and compliance measures that are far beyond our technical understanding."

The technical requirements demand expertise that most CPA firms don't have in-house, making specialized IT support essential.

How Do CPA Firms Document Compliance?

The Safeguards Rule requires a written information security program - documentation is not optional. Your compliance documentation serves as evidence during audits and proof of due diligence if a breach occurs.

Your written program must describe your safeguards in sufficient detail that an auditor can understand what you're doing and why. It should identify your qualified individual, document your risk assessment methodology, list the safeguards you've implemented for each identified risk, and outline your monitoring and testing procedures.

Risk assessment documentation should catalog the systems and processes that handle customer information, identify threats and vulnerabilities for each, evaluate the likelihood and potential damage of each risk, and document the safeguards you've chosen to address each risk.

Policies and procedures translate your program into actionable guidance. You need acceptable use policies, data classification standards, access control procedures, incident response playbooks, vendor management processes, and employee training curricula.

Evidence of implementation proves you're actually following your written program. Maintain logs of security monitoring, records of vulnerability scans and penetration tests, training completion certificates, vendor security assessments, and incident response reports.

Annual reports to leadership must document the overall status of your program, material changes since the last report, risk assessment findings, security incidents and responses, and recommendations for program improvements.

Salt Lake City CPA firms should align their Safeguards Rule documentation with Utah's data breach notification requirements under Utah Code § 13-44-201, which may require notification within specific timeframes. Comprehensive documentation protects your firm legally and operationally.

What Are the Consequences of Non-Compliance?

The FTC actively enforces the Safeguards Rule, and the consequences of non-compliance extend beyond regulatory penalties to include reputational damage and client loss.

Civil penalties reach $50,685 per violation, and each day of continued non-compliance can constitute a separate violation. For a firm that fails to implement required safeguards for months, penalties can quickly escalate into six or seven figures.

The FTC can issue cease and desist orders requiring specific corrective actions, mandate third-party audits at your expense, and impose ongoing monitoring and reporting requirements that last for years.

State enforcement adds another layer. Utah's Division of Occupational and Professional Licensing can investigate complaints, impose additional sanctions, and even suspend or revoke CPA licenses for egregious data security failures.

Data breaches at non-compliant firms trigger mandatory notification to affected clients under Utah Code § 13-44-202. You must notify individuals without unreasonable delay, and if more than 1,000 Utah residents are affected, you must also notify consumer reporting agencies and the Utah Attorney General.

Client trust evaporates when taxpayer data is compromised. CPA firms depend on confidentiality - a publicized breach can destroy practices built over decades. Clients will ask whether you were compliant with the Safeguards Rule, and "no" is a career-ending answer.

Professional liability insurance may not cover breaches resulting from failure to implement required safeguards, leaving you personally liable for damages. Compliance is fundamental to protecting your practice and your clients.

How Can Salt Lake City CPA Firms Achieve and Maintain Compliance?

Most CPA firms lack the in-house expertise to implement and maintain the technical safeguards the rule requires. The solution is partnering with an IT provider that understands both the regulatory requirements and the unique workflows of accounting practices.

Start with a compliance gap analysis. A qualified IT partner will assess your current security posture against all nine Safeguards Rule requirements, identify specific gaps, prioritize remediation based on risk, and create a roadmap to full compliance.

Implement the required technical controls. This includes deploying enterprise-grade encryption for data at rest and in transit, enforcing multi-factor authentication across all systems, implementing role-based access controls with audit logging, establishing continuous security monitoring, and creating secure backup and disaster recovery systems.

Develop comprehensive documentation. Your IT partner should help you create your written information security program, document risk assessments with identified safeguards, develop policies and procedures in plain language, establish vendor management processes, and prepare annual compliance reports for leadership.

Establish ongoing monitoring and testing. Compliance isn't a one-time project. You need continuous security monitoring and alerting, quarterly vulnerability assessments, annual penetration testing, regular policy reviews and updates, and documented evidence of all testing activities.

Train your team continuously. Employees are your first line of defense. Training should cover phishing recognition, secure password practices, proper handling of client data, incident reporting procedures, and compliance responsibilities specific to each role.

Lee, a financial professional in Salt Lake City, noted: "Yes, there are bigger companies out there, but 911 IT offers that small business touch that makes a big difference. Their team is not only knowledgeable but also friendly and approachable. It's clear they understand our industry and the security standards required to keep client data safe."

911 IT provides specialized IT support for CPA firms throughout Salt Lake City and the Mountain West region. We implement and maintain all nine Safeguards Rule requirements, from encryption and MFA to risk assessments and incident response planning. Our team understands the unique pressures of tax season, the security requirements of cloud accounting platforms, and the compliance demands facing Utah financial professionals.

Unlike national IT providers where your firm is one ticket among thousands, 911 IT knows your systems, your team, and your compliance obligations. We provide 24-7 monitoring and support with rapid response when issues arise - critical during busy season when every minute of downtime costs billable hours.

Our compliance services for CPA firms include comprehensive security assessments, implementation of all required technical controls, development of written security programs and policies, continuous monitoring and quarterly testing, employee security awareness training, vendor security management, incident response planning and support, and annual compliance reporting to your leadership.

We also provide advanced cybersecurity services that go beyond baseline compliance, protecting your firm from the ransomware and phishing attacks that increasingly target accounting practices with valuable financial data.

Our flat-rate, transparent pricing eliminates surprise bills, and our 100% satisfaction guarantee means you can count on responsive, knowledgeable support when you need it most. We're big enough to implement enterprise-grade security for firms of any size, yet small enough that every client is known by name and genuinely matters.

For Salt Lake City CPA firms serious about protecting client data and meeting FTC requirements, 911 IT delivers the expertise, responsiveness, and industry-specific knowledge you need to achieve and maintain compliance confidently.

Frequently Asked Questions

Does the FTC Safeguards Rule apply to small CPA firms?

Yes, the Safeguards Rule applies to all financial institutions regardless of size, including solo practitioners and small CPA firms. While some technical requirements scale based on complexity, all nine core elements are mandatory. Small firms must designate a qualified individual, conduct risk assessments, implement appropriate safeguards, and maintain written documentation. The rule recognizes that smaller firms may implement less complex solutions, but compliance is not optional based on firm size.

What is the penalty for violating the FTC Safeguards Rule?

The FTC can impose civil penalties up to $50,685 per violation, with each day of continued non-compliance potentially constituting a separate violation. Beyond monetary penalties, the FTC can issue cease and desist orders, require third-party audits at your expense, and impose ongoing monitoring requirements. State regulators may add additional sanctions, and data breaches at non-compliant firms trigger mandatory client notification under Utah law, resulting in reputational damage and potential client loss.

How often must CPA firms update their Safeguards Rule compliance?

The Safeguards Rule requires continuous compliance, not periodic certification. You must evaluate and adjust your program whenever there are material changes to your business operations, technology infrastructure, or emerging threats. At minimum, you must conduct annual risk assessments, perform vulnerability testing at least yearly, provide regular employee training, report to senior management annually, and maintain ongoing monitoring of security controls. Compliance is an ongoing operational requirement, not a one-time project.

Can cloud accounting software help CPA firms meet Safeguards Rule requirements?

Cloud accounting platforms can support compliance but don't automatically satisfy all requirements. While reputable providers offer encryption, access controls, and security monitoring, you remain responsible for your overall information security program. You must assess cloud vendors as service providers, ensure contractual protections for customer data, implement MFA for all user access, maintain your own incident response plan, and document how cloud services fit into your comprehensive security program under the Safeguards Rule.

What documentation must CPA firms maintain for FTC Safeguards Rule compliance?

You must maintain a written information security program describing your safeguards in detail, documented risk assessments identifying threats and your responses, written policies and procedures for data handling and security, evidence of safeguard implementation including monitoring logs and test results, records of employee security training, vendor security assessments and contracts, incident response plans and any incident reports, and annual reports to senior management on program status. This documentation proves compliance during audits and demonstrates due diligence.