To comply with the FTC Safeguards Rule, a tax or accounting firm maintains a written information security plan (WISP) under 16 CFR Part 314. That plan needs a named Qualified Individual, a written risk assessment, MFA and encryption, staff training, vendor oversight, a written incident response plan, and FTC notification within 30 days of a qualifying breach. If your firm already keeps the WISP that IRS Publication 4557 expects, you’re building on the same document, not starting a second one.
Key takeaways
The FTC Safeguards Rule (16 CFR Part 314) covers tax preparers, CPAs, EAs, and bookkeepers at any firm size.
Compliance is a written program: Qualified Individual, risk assessment, MFA, encryption, training, vendor oversight, incident response.
Breaches of unencrypted data affecting 500 or more consumers must reach the FTC within 30 days of discovery.
Firms holding data on fewer than 5,000 consumers skip some written sub-elements, never the program itself.
VeritShield WISP delivers the written plan for $999 per year with unlimited revisions.
Table of Contents
Does the FTC Safeguards Rule apply to your accounting firm?
Yes. The FTC Safeguards Rule, at 16 CFR Part 314, treats professional tax preparers, CPAs, EAs, and bookkeeping firms as financial institutions. The rule’s own examples name tax preparation firms as covered entities. The trigger is the client data a firm handles, not its size, credential, or revenue.
The rule’s definition of “financial institution” is broader than banks and lenders. It reaches any business significantly engaged in activities financial in nature, and the definitions at 16 CFR 314.2(h) list tax preparation firms as a worked example of a covered entity. The FTC’s own business guidance answers the coverage question the same way.
The practical test is the data. If you handle Social Security numbers, bank and routing numbers, payroll records, or business financials that feed a tax filing, you’re covered. Any one of those is enough, PTIN or no PTIN, solo or 50-person firm. IRS Publication 4557 makes the same point from the other direction: it names the FTC Safeguards Rule as a requirement that applies to tax professionals.
What does an FTC Safeguards Rule compliance checklist include?
Compliance means a written program your firm can produce on request. The elements at the heart of the rule: a Qualified Individual, a written risk assessment, access controls, encryption, MFA, secure disposal, monitoring and testing, staff training, service provider oversight, a written incident response plan, an annual report, and FTC breach notification within 30 days.
Here’s the element list from 16 CFR Part 314, translated into what a tax or accounting firm does about each one:
Requirement
What your firm does
Written information security program
Keep the whole program in writing. For a tax firm, this is the WISP the IRS also expects.
Qualified Individual (§314.4(a))
Name one person who owns the program. You can outsource the work to a qualified service provider, but the firm still designates an internal point of contact.
Written risk assessment
List the client data you hold, where it lives, and what threatens it, in writing.
Access controls and data inventory
Limit who can reach client data, and keep an inventory of the systems and devices that store it.
Encryption
Encrypt customer information in transit and at rest.
Multi-factor authentication (§314.4(c)(5))
Require MFA for anyone accessing your information systems, unless your Qualified Individual approves an equivalent control in writing.
Secure disposal
Dispose of customer information within two years of its last use to serve the client, with limited exceptions.
Monitoring and testing
Test or monitor your safeguards on a regular schedule and keep the results.
Staff training (§314.4(e))
Run security awareness training and keep the sign-offs.
Service provider oversight (§314.4(f))
Pick capable vendors, require safeguards by contract, and reassess them periodically. Your software vendor’s security doesn’t replace this step.
Written incident response plan (§314.4(h))
Write down who does what when a security event hits.
Annual report
Have your Qualified Individual put a written report on the program’s status on file at least once a year.
Breach notification
Notify the FTC no later than 30 days after discovering a security event involving unencrypted information of at least 500 consumers.
One size nuance helps small practices: firms maintaining customer information on fewer than 5,000 consumers are exempt from a handful of written sub-elements (the written risk assessment, written incident response plan, annual report, and penetration testing) under 16 CFR 314.6. Everything else on the checklist still applies.
What does a WISP have to contain?
A WISP is the written program in one document. IRS Publication 5708 and practitioner convention organize it into nine sections: a security coordinator, a risk assessment, safeguards, training and access controls, a device inventory, failure detection procedures, disposal and retention policies, an incident response plan, and an annual review cycle.
IRS Publication 4557 and Publication 5708 both state that tax professionals are required by law to maintain a WISP, and Publication 5708 includes a free template you can start from. Our own explainer on Publication 4557 covers what the publication requires in more detail. The standard nine sections:
A named security coordinator
A documented risk assessment covering the data you handle and the threats to it
Administrative, technical, and physical safeguards
Employee training, sign-offs, and access controls
An inventory of every device storing client data, with MFA and encryption documented
Procedures for detecting and managing system failures
Data disposal and retention policies for paper and electronic records
A step-by-step incident response plan
An annual review cycle with dates and changes recorded
The plan scales with the firm. A solo preparer’s WISP is shorter than a 30-person firm’s, but both exist in writing, get reviewed at least annually, and get updated when technology, staff, or offices change. The IRS’s Taxes-Security Together checklist walks the same ground, and our explainer on what a WISP is goes deeper on the document itself.
What happens if your firm has a data breach?
Two clocks start. The FTC Safeguards Rule requires notice to the FTC as soon as possible, and no later than 30 days after discovery. The trigger is a security event involving unencrypted information of at least 500 consumers. The IRS separately asks tax professionals to report data theft to their Stakeholder Liaison right away.
The FTC notification duty has been in effect since May 13, 2024. Two details decide most cases. First, unauthorized access to unencrypted customer information is presumed to be acquisition unless you have reliable evidence the data was never taken. Second, the trigger is written around unencrypted data: encrypted files, with the key protected, don’t create the notification event.
The IRS layer runs on its own track: tax professionals report data theft to their IRS Stakeholder Liaison immediately so fraudulent returns can be flagged, and notify state tax agencies. Neither step waits on the FTC analysis, and neither has a 500-consumer floor.
Our companion piece on the FTC’s 30-day breach notification rule walks both duties step by step; your WISP’s incident response section should name each one and who owns it.
What happens if you skip FTC Safeguards compliance?
The FTC has enforcement authority over covered firms, and the breach notification duty makes gaps visible. A firm that can’t produce a WISP after an incident answers to the FTC, the IRS, its insurance carrier, and its clients at the same time. PTIN holders also certify their data security responsibilities on Form W-12.
The realistic exposure isn’t a surprise audit. It’s the day something goes wrong. The 30-day notification duty puts your program in front of the FTC with a deadline attached, and the first document anyone asks for is the written plan.
Form W-12, the PTIN renewal application, includes a data security responsibilities checkbox and is signed under penalty of perjury. Renewing without a WISP on file creates a gap between what you certified and what exists in your practice. That gap can cost a preparer their PTIN. If your firm carries cyber liability coverage, expect the renewal application to ask for the WISP, the MFA setup, and the risk assessment.
Every item on the checklist is a known quantity with a template behind it; most firms close the gap in weeks, not months.
How does Verito support FTC Safeguards compliance?
VeritShield WISP delivers the written plan: $999 per year, custom to your firm, delivered in 5 business days, with unlimited revisions as your software, staff, or offices change. VeritGuard covers the technical elements from $79 per device per month. VeritComplete bundles hosting and IT from $129 per user per month.
Mapped against the rule’s elements:
The written program.VeritShield WISP is a done-for-you WISP built around your firm’s size, software, and workflow after a 30-minute scoping call. $999 per year, per firm, with unlimited revisions, so the plan stays current when you add a preparer in February or swap tax software in June. You don’t need to be a Verito hosting customer.
Encryption, MFA, and backups.VeritSpace hosting puts your tax applications on a dedicated private server with 256-bit encryption in transit and at rest, 2FA/MFA, and backups four times a day, in an environment that is SOC 2 Type II and ISO 27001 certified.
Device security, training, and audits.VeritGuard managed IT is priced at $79 to $199 per device per month (priced per device, not per user), with antivirus and EDR on every tier. Pro and Elite add security training, email anti-phishing, the full WISP included, and an FTC Safeguards audit (annual on Pro, twice a year on Elite). Elite adds 24/7 SOC monitoring and dark web monitoring.
One agreement for both.VeritComplete combines hosting and managed IT at $129 to $249 per user per month, devices included, with the full WISP included on every tier.
No product makes your firm compliant on its own; the program is yours. What these do is put the controls the rule names in place and keep the paperwork current, designed to support IRS Publication 4557 and FTC Safeguards requirements. That’s the setup 1,000+ tax and accounting firms run on, with 100% uptime since 2016 and support that picks up in under 60 seconds.
“The data security Verito provides is immense; it ensures my tax data is secure, eliminating worries about hackers, natural disasters, or computer crashes, offering immense peace of mind.”
Robin R., Owner, Robin M Rudisill CPA PC · G2, Oct 2025
If you’d rather start with a gap check than a purchase, a 30-minute security assessment shows where your current setup stands against the element list.
Camren Majors is co-founder and Chief Revenue Officer of Verito Technologies, a cloud hosting and managed IT company built exclusively for tax and accounting firms. He is the co-author of Beyond Best Practices: Modernizing the Successful Accounting Firm (2026). His work has been featured in NATP TAXPRO Magazine and he has presented for NATP, NAEA, and NSA.
Standardizing IT across accounting firms in a PE portfolio -- a phased playbook from discovery to full portfolio management, delivered in weeks, not months.
A direct posture update for VeritSpace and VeritGuard clients on the Anthropic Mythos disclosure, the regulator response, and what we are doing in response.
1 comment
Comments are closed.