The Federal Trade Commission Safeguards Rule requires tax and accounting practices to implement a comprehensive written information security plan, encrypt sensitive customer data, conduct annual risk assessments, designate a qualified individual to oversee the program, provide security awareness training, and maintain an incident response plan. Firms must also implement multi-factor authentication for systems accessing customer information, with civil penalties reaching up to $50,120 per violation for non-compliance.
What Does the FTC Safeguards Rule Cover for Accounting Firms?
The FTC Safeguards Rule applies to all tax preparers and accounting firms that handle customer financial information. This includes sole practitioners, small CPA firms, and large accounting practices across Salt Lake City and Utah.
The rule stems from the Gramm-Leach-Bliley Act and was significantly updated in 2021 with a compliance deadline that took effect in June 2023. It treats tax preparers as "financial institutions" under federal law, subjecting them to the same data protection standards as banks and credit unions.
Customer information covered includes Social Security numbers, tax identification numbers, income statements, bank account details, credit card numbers, and any other financial data collected during tax preparation or accounting services. Even firms that only prepare a handful of returns annually must comply.
Utah CPA firms must also navigate state-level data breach notification laws alongside federal requirements, creating a layered compliance obligation that demands careful coordination.
What Are the Core Requirements of the Safeguards Rule?
The rule mandates eight specific security requirements that every covered firm must implement. These aren't suggestions - they're enforceable obligations with significant penalties for non-compliance.
Firms must designate a qualified individual responsible for overseeing and implementing the information security program.
First, you must conduct a written risk assessment identifying reasonably foreseeable internal and external threats to customer information. This assessment must evaluate current safeguards and identify gaps in your security posture.
Second, implement safeguards to control the identified risks. This includes access controls, data encryption both in transit and at rest, secure development practices if you use custom software, and multi-factor authentication for any system accessing customer information.
Third, regularly monitor and test the effectiveness of your safeguards. This means penetration testing, vulnerability assessments, and continuous monitoring of your systems for unauthorized access attempts.
Fourth, train your staff. Every employee who handles customer information must receive security awareness training appropriate to their role. This training must be updated as threats evolve.
Fifth, select and oversee service providers. If you use cloud accounting software, backup services, or IT support, you must ensure these vendors have appropriate safeguards and include contractual obligations to protect customer information.
Sixth, maintain an incident response plan for data breaches or security events. This plan must include procedures for internal reporting, customer notification, and regulatory reporting as required by law.
Seventh, implement multi-factor authentication for all systems and applications that access customer information, unless your qualified individual approves a written exception based on specific risk factors.
Eighth, encrypt all customer information in transit and at rest, again unless your qualified individual documents a compensating control that provides equivalent protection.
The eight core requirements create a comprehensive security framework:
- Designate a qualified individual to oversee the security program
- Conduct written risk assessments of internal and external threats
- Implement safeguards including encryption and access controls
- Monitor and test safeguards through vulnerability assessments
- Provide security awareness training to all staff
- Select and oversee service providers with appropriate protections
- Maintain an incident response plan for security events
- Deploy multi-factor authentication across all customer information systems
Kari, who manages compliance for a Salt Lake City accounting firm, shared: "911 IT has been an invaluable partner for our accounting firm, especially when it comes to meeting strict IRS and PCI security requirements. They've helped us implement and maintain backend network protocols and compliance measures that are far beyond our technical understanding."
Who Qualifies as the Required Qualified Individual?
The Safeguards Rule requires you to designate a "qualified individual" to oversee your information security program. This person must have the knowledge, experience, and authority to implement and maintain the required safeguards.
For small firms, this might be the managing partner or owner, but only if they genuinely understand information security concepts. The FTC has made clear that simply appointing someone without the requisite expertise doesn't satisfy the requirement.
Many Salt Lake City CPA firms address this by partnering with a managed IT services provider who can serve as or support the qualified individual role. This approach brings enterprise-level security expertise to firms that can't justify a full-time information security officer.
The qualified individual must report directly to your board of directors or senior management at least annually on the status of the security program. This creates accountability and ensures security receives appropriate attention at the leadership level.
For firms with fewer than 5,000 customer records, certain requirements are scaled back, but the qualified individual designation remains mandatory regardless of firm size.
How Do You Implement Multi-Factor Authentication and Encryption?
Multi-factor authentication (MFA) is now mandatory for all systems accessing customer information unless you document a specific exception. This means your tax software, client portals, email systems, and remote access tools must all require at least two forms of verification.
Common MFA implementations include SMS codes, authenticator apps like Microsoft Authenticator or Google Authenticator, hardware security keys, or biometric verification. The key is that authentication requires something you know (password) plus something you have (phone or token) or something you are (fingerprint).
Encryption requirements apply both to data in transit (moving across networks) and data at rest (stored on servers or devices). Modern encryption standards like AES-256 for stored data and TLS 1.2 or higher for transmitted data meet the rule's requirements.
For accounting firms, this means encrypting engagement files, tax returns, client financial statements, and workpapers wherever they're stored - on local servers, in the cloud, or on employee devices.
The exception process requires your qualified individual to document in writing why MFA or encryption isn't feasible for a specific system and what compensating controls you've implemented instead. This exception must be based on a risk assessment, not convenience.
Many firms discover during implementation that their legacy systems don't support modern authentication or encryption standards. This often triggers necessary technology upgrades that improve security and efficiency simultaneously.
What Documentation Must You Maintain for Compliance?
The Safeguards Rule requires extensive written documentation. Your information security plan must be a formal, written document - mental policies and informal practices don't satisfy the requirement.
Your written plan must include your risk assessment results, the safeguards you've implemented to address identified risks, how you monitor and test those safeguards, your staff training program, your service provider oversight process, and your incident response procedures.
You must document your qualified individual designation in writing, including their qualifications and authority. Annual reports to senior management must also be documented and retained.
If you claim any exceptions to MFA or encryption requirements, those exceptions must be documented with detailed justification and the compensating controls you've implemented instead.
Service provider contracts must include specific language requiring them to maintain appropriate safeguards for your customer information. Generic confidentiality clauses aren't sufficient - the contract must specifically address information security.
Training records should document who received training, when, what topics were covered, and how you verified understanding. During an FTC examination, these records demonstrate your compliance efforts.
Dianna from a Utah accounting firm noted: "They are proactive and always looking towards the future to solve potential problems before they become actual problems. I was very impressed before quarantine was implemented: 911 IT reached out to us to develop a plan to be able to move all of our employees home if the need arose." This proactive documentation approach proved critical during the rapid shift to remote work.
What Are the Penalties for Non-Compliance?
The FTC has significant enforcement authority for Safeguards Rule violations. Civil penalties can reach up to $50,120 per violation, and each day of continued non-compliance can constitute a separate violation.
Beyond direct FTC enforcement, non-compliance creates liability exposure if a data breach occurs. Failing to implement required safeguards can be used as evidence of negligence in civil litigation by affected customers.
Professional liability insurance policies may exclude coverage for breaches resulting from failure to implement industry-standard or legally required security measures. This means non-compliance could leave you personally exposed to breach costs.
State regulators, including the Utah Division of Occupational and Professional Licensing, may also take disciplinary action against CPAs who fail to protect client data, potentially affecting your license to practice.
The reputational damage from a breach can be devastating for accounting firms, where trust is fundamental to client relationships. Salt Lake City's tight-knit business community means word travels quickly when a firm experiences a security incident.
How Can Salt Lake City CPA Firms Achieve and Maintain Compliance?
Most accounting firms lack in-house IT security expertise, making compliance challenging. The solution for many Salt Lake City practices is partnering with a specialized IT support provider for CPA firms who understands both the technical requirements and the accounting industry's workflow.
A compliance-focused IT partner can serve as or support your qualified individual, conduct required risk assessments, implement technical safeguards like MFA and encryption, provide security awareness training, and maintain the required documentation.
911 IT specializes in helping accounting firms navigate FTC Safeguards Rule compliance alongside other regulatory requirements like IRS Publication 4557 guidelines and PCI DSS for firms processing credit card payments. Their managed IT services include continuous monitoring, regular security assessments, and documented compliance reporting.
Unlike large national IT providers where your firm is one account among thousands, 911 IT's approach means your compliance needs receive personalized attention from a team that understands Utah's regulatory environment and accounting industry requirements.
The firm's 24-7 monitoring and rapid response support ensure security incidents are detected and addressed immediately - critical during tax season when downtime isn't an option. Their flat-rate, transparent pricing model makes compliance costs predictable rather than a surprise during budget planning.
With a 100% satisfaction guarantee and recognition as a 2024 MSP Titans award winner, 911 IT brings enterprise-level security capabilities scaled appropriately for small and mid-sized CPA firms across Salt Lake City, Utah, Wyoming, and Arizona.
For firms evaluating compliance partners, the key differentiator is finding a provider large enough to handle sophisticated security requirements but small enough that every client matters. At massive national providers, you're assigned to rotating junior technicians who don't know your systems or your busy season pressures. 911 IT's model ensures you work with a consistent team that knows your firm's setup, compliance obligations, and business priorities.
Frequently Asked Questions
Does the FTC Safeguards Rule apply to small tax preparation firms?
Yes, the Safeguards Rule applies to all tax preparers and accounting firms regardless of size, including sole practitioners. Even if you prepare just a few returns annually, you're considered a financial institution under the rule and must comply with all requirements, though some documentation requirements are scaled for firms with fewer than 5,000 customer records.
What is the deadline for FTC Safeguards Rule compliance?
The compliance deadline was June 9, 2023. All covered firms should already have their information security programs fully implemented and documented. If you're not yet compliant, immediate action is necessary to avoid enforcement penalties and reduce your liability exposure from potential data breaches or regulatory examinations.
Can I use my existing IT person as the qualified individual?
Your IT person can serve as the qualified individual only if they have genuine information security expertise, not just general IT support skills. The qualified individual must understand risk assessment, security controls, encryption, access management, and incident response. Many firms find their internal IT staff lack this specialized knowledge and partner with security-focused providers instead.
How often must I conduct risk assessments under the Safeguards Rule?
The rule requires periodic risk assessments but doesn't specify exact frequency. Industry best practice and FTC guidance suggest annual assessments at minimum, with additional assessments whenever you make significant changes to your systems, add new service providers, or experience security incidents. Your risk assessment must be documented in writing.
What happens if my cloud accounting software provider has a data breach?
You remain responsible for protecting customer information even when using third-party service providers. The Safeguards Rule requires you to select providers with appropriate security measures and maintain contracts requiring them to protect your data. If a provider breach exposes your customer data, you may face regulatory scrutiny regarding your vendor selection and oversight process.
Does the Safeguards Rule require penetration testing for accounting firms?
The rule requires regular monitoring and testing of safeguards but doesn't mandate specific testing methods. For most firms, annual penetration testing or vulnerability assessments are appropriate ways to satisfy this requirement. Your qualified individual should determine the appropriate testing frequency and methods based on your firm's risk profile and system complexity.
