Cartoon: What Does the FTC Safeguards Rule Require All Tax Preparers to Do?

What Does the FTC Safeguards Rule Require All Tax Preparers to Do?

August 31, 2026

The FTC Safeguards Rule requires all tax preparers to develop and implement a written information security plan that includes administrative, technical, and physical safeguards to protect customer information. Tax preparers must designate a qualified individual to oversee the program, conduct annual risk assessments, encrypt sensitive data both in transit and at rest, implement multi-factor authentication, and provide security awareness training to all employees who handle client information. The rule became fully enforceable in June 2023.

Who Must Comply With the FTC Safeguards Rule?

The FTC Safeguards Rule applies to all tax preparation businesses that qualify as "financial institutions" under the Gramm-Leach-Bliley Act (GLBA). This includes sole proprietors, small CPA firms, large accounting practices, and franchised tax preparation services.

If your firm prepares tax returns, offers tax planning advice, or handles client financial information as part of your accounting services, you fall under this regulation. The rule applies regardless of firm size - a solo practitioner working from home faces the same compliance obligations as a 50-person firm.

Salt Lake City CPA firms serving Utah's growing tech sector and real estate investment community handle particularly sensitive financial data. Utah's data breach notification laws add an additional layer of state-level compliance requirements that work alongside federal FTC mandates.

The rule became fully enforceable in June 2023, with enhanced requirements that significantly raised the bar for tax preparer cybersecurity practices.

What Are the Core Requirements of the Safeguards Rule?

The Safeguards Rule establishes nine specific security requirements that every tax preparation business must implement. These requirements form the foundation of your compliance program.

  1. Designate a qualified individual to implement and supervise your information security program with sufficient authority and resources to enforce security policies across your entire organization.
  2. Conduct written risk assessments that identify reasonably foreseeable internal and external risks to customer information, documented and updated at least annually or whenever significant changes occur.
  3. Design and implement safeguards to control identified risks, addressing access controls, data encryption, secure development practices, multi-factor authentication, data disposal, and change management procedures.
  4. Monitor and test effectiveness through continuous monitoring, annual penetration testing, and vulnerability assessments (biannual for firms with complex systems).
  5. Train staff on security awareness ensuring all personnel understand their role in protecting customer information, with documented and updated training as threats evolve.
  6. Oversee service providers who access customer information, maintaining appropriate contractual protections and monitoring vendor compliance.
  7. Develop incident response plans that document detection, response, and recovery procedures for security events.
  8. Update programs regularly based on monitoring results, testing outcomes, and changes to your business operations.
  9. Maintain detailed documentation of your entire security program, including risk assessments, training records, and testing results.

Kari, who manages an accounting firm in Salt Lake City, shared her experience: "911 IT has been an invaluable partner for our accounting firm, especially when it comes to meeting strict IRS and PCI security requirements. They've helped us implement and maintain backend network protocols and compliance measures that are far beyond our technical understanding."

These nine requirements work together to create a comprehensive security framework that protects client data throughout its lifecycle.

What Technical Safeguards Must Tax Preparers Implement?

The FTC Safeguards Rule mandates specific technical controls that go beyond general best practices. These requirements reflect the current threat landscape facing financial services firms.

Encryption is mandatory for all customer information, both in transit and at rest. This means client tax returns stored on your server must be encrypted, and any data transmitted via email or file sharing must use encrypted channels.

Multi-factor authentication (MFA) is required for any individual accessing customer information on your systems. Simple username and password combinations no longer meet compliance standards. MFA must be implemented for remote access, email systems, and any application containing client data.

Secure access controls must limit employee access to only the customer information necessary for their job functions. This principle of least privilege prevents unauthorized internal access and limits damage if credentials are compromised.

Secure data disposal procedures must ensure that customer information is rendered unreadable when no longer needed. This applies to both electronic data and physical documents, requiring secure deletion methods or professional shredding services.

Many Salt Lake City CPA firms struggle with these technical requirements during tax season when temporary staff are onboarded quickly. The complexity of implementing enterprise-grade encryption and authentication systems while maintaining accessibility for legitimate users requires specialized IT expertise.

Technical safeguards must be continuously monitored and updated as new vulnerabilities emerge and threat actors develop more sophisticated attack methods.

How Do You Create a Compliant Written Information Security Plan?

Your written information security plan (WISP) serves as the central compliance document that demonstrates your adherence to the Safeguards Rule. The FTC requires this plan to be comprehensive, current, and actively maintained.

The plan must document your designated qualified individual by name and title, clearly establishing who holds ultimate responsibility for your security program. This individual must have sufficient authority to implement changes and allocate resources.

Your WISP must include a detailed description of your risk assessment methodology, the specific risks identified, and the safeguards implemented to address each risk. Generic templates fail compliance audits - your plan must reflect your actual systems, processes, and client data flows.

The plan must outline your procedures for evaluating and monitoring service providers who access customer information. This includes cloud storage providers, email hosting services, software vendors, and IT support firms. You remain liable for security failures by your vendors.

Your incident response plan must be integrated into your WISP, documenting how you will detect, respond to, and recover from security events. This includes notification procedures for affected clients and regulatory authorities under both federal and Utah state breach notification laws.

The plan must establish a schedule for regular testing, monitoring, and updating of safeguards. Many firms tie these reviews to their annual tax season debrief, ensuring continuous improvement based on operational experience.

Documentation requirements extend beyond the plan itself - you must maintain records of risk assessments, training sessions, testing results, and any security incidents. These records demonstrate ongoing compliance during FTC examinations.

What Are the Consequences of Non-Compliance?

The FTC can impose civil penalties up to $50,120 per violation.

Each day of continued non-compliance can constitute a separate violation, allowing penalties to accumulate rapidly. For a firm that discovers a compliance gap during tax season and takes weeks to remediate, the theoretical penalty exposure can reach hundreds of thousands of dollars.

Beyond FTC enforcement, data breaches resulting from inadequate safeguards expose firms to client lawsuits, professional liability claims, and state attorney general actions under Utah's data breach notification statute. The average cost of a data breach for small businesses exceeds $120,000 when factoring in forensic investigation, legal fees, client notification, credit monitoring services, and business interruption.

Professional reputation damage often exceeds direct financial costs. CPA firms depend on trust and confidentiality - a publicized data breach can destroy client relationships built over decades. In Salt Lake City's tight-knit business community, word travels quickly when a firm experiences a security incident.

State licensing boards may also take disciplinary action against CPAs whose firms fail to protect client data, potentially affecting individual licenses in addition to firm-level penalties.

Insurance complications add another layer of risk. Many professional liability and cyber insurance policies include compliance warranties - failure to maintain required safeguards can void coverage precisely when you need it most.

How Can Salt Lake City CPA Firms Achieve and Maintain Compliance?

Achieving FTC Safeguards Rule compliance requires both initial implementation and ongoing maintenance. Most CPA firms lack the internal IT expertise to handle this alone, particularly given the technical depth required for encryption, penetration testing, and continuous monitoring.

The most effective approach involves partnering with an IT services provider that understands both the technical requirements and the operational realities of tax preparation businesses. Specialized IT support for CPA and financial firms addresses the unique challenges of securing client data while maintaining the accessibility needed during busy season.

A qualified IT partner can conduct your required risk assessment, identifying vulnerabilities in your current systems and data handling procedures. They document your existing security posture and create a prioritized remediation roadmap that addresses the highest risks first.

Implementation services should include deploying encryption solutions, configuring multi-factor authentication across all systems, establishing access controls, and setting up continuous monitoring tools. These technical safeguards must integrate seamlessly with your existing tax preparation software and workflows.

Ongoing managed IT services provide the continuous monitoring, regular testing, and timely updates required by the rule. This includes monthly vulnerability scans, annual penetration testing, security patch management, and immediate response to emerging threats.

Staff training programs should be delivered regularly and documented thoroughly. Effective training goes beyond generic cybersecurity awareness to address the specific threats facing tax preparers - phishing emails impersonating the IRS, business email compromise targeting client funds, and social engineering attacks during tax season chaos.

Service provider management requires vetting and monitoring all vendors who access customer information. Your IT partner should help you assess vendor security practices, establish appropriate contractual protections, and monitor vendor compliance over time.

Lee, a financial services professional, noted the value of the right partnership: "Yes, there are bigger companies out there, but 911 IT offers that small business touch that makes a big difference. Their team is not only knowledgeable but also friendly and approachable, which makes working with them easy and enjoyable."

Comprehensive cybersecurity services that include managed detection and response, security awareness training, and compliance management provide the full spectrum of protection required by the Safeguards Rule.

Why 911 IT Is the Right Compliance Partner for Salt Lake City CPA Firms

When selecting an IT partner to help achieve FTC Safeguards Rule compliance, Salt Lake City CPA firms face a critical choice. Large national MSPs treat small and mid-sized accounting firms as just another ticket in the queue - you're one account among thousands, often assigned to rotating junior technicians who lack context about your practice and the regulatory pressures you face.

911 IT operates at the ideal scale for CPA firms in the Mountain West region. The team is large enough to provide enterprise-grade security tools, 24-7 monitoring, and deep compliance expertise, yet small enough that every client is known by name and genuinely matters to the business.

The firm's experience with financial services compliance extends beyond generic IT support. 911 IT has helped multiple accounting firms implement and maintain IRS and PCI security requirements, understanding the backend network protocols and compliance measures that protect client data while supporting the intense workflow demands of tax season.

Unlike break-fix shops that respond only when systems fail, 911 IT's proactive approach identifies and resolves vulnerabilities before they become compliance violations or security incidents. Continuous monitoring, regular testing, and documented procedures ensure your security program remains current as threats evolve and regulations tighten.

The firm's 100% Satisfaction Guarantee and flat-rate transparent pricing eliminate the uncertainty that plagues many IT relationships. You know exactly what you're paying and can count on responsive support when issues arise - whether small, big, or catastrophic, as one client put it.

For Salt Lake City CPA firms navigating FTC Safeguards Rule compliance while managing the operational demands of serving Utah's growing business community, 911 IT provides the specialized expertise, proactive support, and genuine partnership that turns compliance from a burden into a competitive advantage. Visit Salt Lake City IT support to learn how 911 IT can protect your practice and your clients.

Frequently Asked Questions

What are the requirements of the FTC safeguards rule?

The FTC Safeguards Rule requires tax preparers to designate a qualified security individual, conduct annual written risk assessments, implement administrative and technical safeguards including encryption and multi-factor authentication, monitor and test security systems regularly, train employees on data protection, oversee service providers, develop incident response plans, and maintain a comprehensive written information security program that documents all compliance efforts and is updated as risks change.

What is the major requirement of the safeguards rule?

The major requirement is developing and implementing a written information security plan that protects customer information through administrative, technical, and physical safeguards. This plan must be comprehensive, regularly updated, and actively enforced across the organization. It must include documented risk assessments, specific security controls addressing identified risks, employee training programs, service provider oversight, and incident response procedures that together demonstrate a systematic approach to data protection.

What are the GLBA safeguards rule requirements?

The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requirements include designating a qualified individual to oversee security, conducting risk assessments, implementing access controls and encryption, deploying multi-factor authentication, regularly testing security systems through penetration testing and vulnerability assessments, training staff on security awareness, monitoring service providers, establishing incident response procedures, and maintaining detailed documentation. These requirements apply to all financial institutions, including tax preparers, that handle consumer financial information.

Can tax preparers be held liable for data breaches?

Yes, tax preparers face multiple liability exposures for data breaches including FTC civil penalties up to $50,120 per violation, client lawsuits for negligence and breach of fiduciary duty, state attorney general enforcement actions under data breach notification laws, professional liability claims, and potential state licensing board discipline. Tax preparers remain liable even when breaches result from service provider failures if they failed to properly vet and monitor those vendors under Safeguards Rule requirements.

Who is responsible if a tax preparer makes a mistake?

The tax preparer bears primary responsibility for errors in tax return preparation, including professional liability for financial harm caused to clients. However, responsibility for data security failures under the FTC Safeguards Rule falls on the firm itself and the designated qualified individual responsible for the security program. Both the business entity and responsible individuals can face penalties. Clients may also bear some responsibility for providing inaccurate information, but preparers must exercise due diligence.

What are the red flags of a bad tax preparer?

Red flags include refusing to sign returns they prepare, promising unrealistic refunds, basing fees on refund percentages, lacking a Preparer Tax Identification Number (PTIN), requesting clients sign blank returns, using unsecured email for sensitive documents, lacking basic cybersecurity measures like encryption and multi-factor authentication, having no written engagement letter, being unavailable after filing season, and showing unfamiliarity with FTC Safeguards Rule requirements or other compliance obligations that protect client data.