FTC Safeguards Rule Checklist for Accounting and Tax Firms

JD Sentz
October 5, 2026
Slate 360 Business Solutions card reading FTC Safeguards Rule checklist, nine requirements in plain English

This FTC Safeguards Rule checklist is for small accounting, tax and financial firms. The Federal Trade Commission names tax preparation firms as one of the businesses the rule covers, and it requires a written information security program built on nine elements. Below are all nine in plain English, what changes if you keep data on fewer than 5,000 people, and which items your IT provider can handle.

Does the Safeguards Rule apply to your firm?

The rule covers "financial institutions," and the FTC's definition is much wider than banks. Its own list of examples includes tax preparation firms, credit counselors and other financial advisors, mortgage brokers, collection agencies, and investment advisors that aren't required to register with the SEC.

What matters is the work you do, not what you call your business. As JD Sentz, COO and CTO of 360 Business Solutions, puts it: "Tax preparers and many other financial firms are subject to the FTC Safeguards Rule."

The IRS says the same thing from its side. Its Publication 5708 on written information security plans for tax and accounting practices states that the law requires you to have one.

If you're unsure whether your firm is covered, ask your attorney. This post explains the requirements. It isn't legal advice.

The FTC Safeguards Rule checklist: all nine requirements

Section 314.4 of the rule lists nine elements your information security program must include. The program has to be in writing and sized to your firm, the work you do and how sensitive your client data is. Here are the FTC Safeguards Rule requirements, all nine, in the FTC's order:

  1. Name a Qualified Individual. One person runs and supervises the program. No degree or title is required. That person can be an employee or can work for your IT provider, but a senior person at your firm still has to supervise them.
  2. Do a written risk assessment. List what client information you hold and where it lives, then assess what could expose, change or destroy it. Reassess when your operations or the threats change.
  3. Put safeguards in place for the risks you found. The rule spells out eight of them:
    • Access controls, reviewed regularly, so only people who need client data can reach it
    • An inventory of your data, systems, devices and the people who use them
    • Encryption of client information on your systems and in transit
    • A security review of any app that stores or sends client data
    • Multi-factor authentication for anyone who accesses client information
    • Secure disposal of client information no later than two years after you last used it to serve that client, unless you have a business or legal reason to keep it
    • Change management, so a new server or system doesn't quietly open a hole
    • Logs of user activity, with monitoring for unauthorized access
  4. Monitor and test your safeguards. Either monitor your systems continuously or run a penetration test every year plus vulnerability scans every six months.
  5. Train your staff. Security awareness training for everyone, with regular refreshers, and deeper training for the people who run the program.
  6. Oversee your service providers. Choose vendors who can protect the data, put your security expectations in the contract, and check their work over time.
  7. Keep the program current. Update it when your staff, systems, risks or business change.
  8. Write an incident response plan. Goals, roles, who decides what, how you communicate, how you fix weaknesses, how you document the event, and a review afterward.
  9. Report to leadership in writing. At least once a year, the Qualified Individual reports on the program to your board, or to a senior officer if you don't have one.

That list is a summary. The FTC's small business guide walks through each element in more detail, and it's worth reading once in full.

What changes if you keep data on fewer than 5,000 people

Small firms get a partial break. Under 16 CFR 314.6, a financial institution that maintains customer information on fewer than 5,000 consumers is exempt from four pieces:

  • The written risk assessment
  • Continuous monitoring, or the annual penetration test and twice-yearly scans
  • The written incident response plan
  • The annual written report to leadership

Everything else on the checklist still applies, including the Qualified Individual, multi-factor authentication, encryption, training and vendor oversight.

The count is where firms trip up. The exemption is based on how many people you maintain information about, which is a different number from this year's client list. Old returns from clients who left five years ago still count if they're sitting on a server or in a cloud folder. That's one more reason the two-year disposal rule matters: deleting what you no longer need can be the difference between qualifying for the exemption and not.

Our advice: even if you qualify, write the incident response plan anyway. It's a few pages, and it's the document you'll want on the worst day of the year.

The breach reporting rule

Since May 2024, covered firms have to notify the FTC within 30 days of discovering a breach that involves the unencrypted information of at least 500 people. Encrypted data counts as unencrypted if the encryption key was also taken. The report goes through an online form on the FTC's site, and the FTC notes that reports may be made public.

Encryption is the practical takeaway here. Client data that's properly encrypted, with the key kept safe, keeps a stolen laptop from becoming a reportable event.

What your IT provider can do, and what stays with you

A lot of this checklist is technical work, and a good IT provider should be doing it for you every day. Multi-factor authentication, encryption, access controls, activity logs, monitoring, patching, vulnerability scans, secure wiping of old devices and staff phishing training all fall on the IT side. At 360, most of that is already part of our managed IT services, and the compliance pieces sit with our compliance and security team for accounting and tax firms. If you're still deciding how to get IT help at all, we compared the four IT support options for accountants.

Some of it can't be handed off. The FTC is direct about this: if a service provider runs your program, "the buck still stops with you." Your firm decides which risks it accepts, supervises the Qualified Individual, signs off on vendor contracts and receives the annual report.

JD describes 360's part this way: "We help identify gaps, develop the required documentation, and implement and manage the technical controls behind it."

We hold one firm view on the paperwork. A downloaded template plan that nobody follows is worse than an honest short one, because it tells an examiner or an insurer exactly what you said you'd do and didn't. The IRS sample in Publication 5708 is a good starting point, and the IRS itself says it isn't meant to replace a plan built around your own practice. Write down what your office actually does, then close the gaps between that and the rule.

What does an FTC Safeguards Rule checklist need to cover?

An FTC Safeguards Rule checklist needs the nine elements of 16 CFR 314.4: a Qualified Individual, a written risk assessment, safeguards including multi-factor authentication and encryption, monitoring and testing, staff training, service provider oversight, regular updates, an incident response plan, and an annual written report. Firms with data on fewer than 5,000 consumers are exempt from four of those pieces. For accounting and tax firms in Buffalo and Western New York, 360 Business Solutions in Amherst finds the gaps, builds the documentation and runs the technical controls. Call (716) 650-7200 or book a 30-minute assessment to talk it through.

FTC Safeguards Rule questions

Does the Safeguards Rule apply to CPA firms?

Tax preparation firms are named in the rule's own examples, so a CPA firm that prepares returns is very likely covered. Other financial work, like advisory services, can bring a firm in as well. Coverage depends on the activities, so confirm your situation with your attorney.

Is a WISP the same as the Safeguards Rule's information security program?

The IRS calls the written plan a WISP (written information security plan), and its Publication 5708 includes a sample template for tax and accounting practices. The FTC rule calls it a written information security program. For a small firm, the WISP is the document that captures that program.

Can our IT company be our Qualified Individual?

Yes. The FTC allows the Qualified Individual to work for a service provider. Two strings come with it: a senior person at your firm has to supervise them, and the provider has to keep its own information security program that protects your firm.

How often do we have to test our security?

Continuously, through ongoing monitoring, or with a penetration test every year and vulnerability scans every six months. You also need to test after major changes to your systems or business. Firms with data on fewer than 5,000 consumers are exempt from this testing requirement.

How long can we keep old client files?

The rule says to securely dispose of client information no later than two years after you last used it to serve that client, unless you have a legitimate business need or a legal requirement to keep it longer.

Can 360 certify that we're compliant?

No, and you should be wary of any IT company that says it can. We help you find the gaps, build the documentation, and put the technical controls in place and keep them running. The regulator is the one that judges whether you comply, and your attorney can advise on that.

Ready to Talk?

Your first conversation is on us.

Free 30-Minute Technology Assessment

  • Review your current IT setup
  • Identify compliance gaps and quick wins
  • Explore AI & automation opportunities
  • No pitch. No pressure. Just clarity.
Loading booking calendar...