FTC Safeguards Rule: What Tax Professionals Need to Know
You're legally classified as a financial institution. Here's what that means for your practice.
What Is the FTC Safeguards Rule?
The FTC Safeguards Rule (16 CFR Part 314) is a federal regulation that requires "financial institutions" to develop, implement, and maintain comprehensive security programs to protect customer data.
Here's the catch: Under the Gramm-Leach-Bliley Act, tax preparers are legally classified as financial institutions — the same category as banks, credit unions, and investment firms.
This means if you prepare tax returns for compensation, you must comply with the same data protection standards as major financial institutions.
Does the FTC Safeguards Rule Apply to Me?
If you answer "yes" to any of these, the Safeguards Rule applies:
- Do you prepare tax returns for clients?
- Do you collect Social Security numbers?
- Do you handle bank account or financial information?
- Do you have a PTIN?
The rule applies regardless of:
- Your firm size (solo practitioners included)
- How many clients you serve
- Whether you work from home or an office
- Your revenue or years in business
There is no small business exemption. If you handle taxpayer data, you're covered.
Key Requirements of the Safeguards Rule
The 2021 amendments (effective June 2023) significantly strengthened requirements. Here's what you must do:
1. Designate a Qualified Individual
Appoint someone to oversee your information security program. For solo practices, this is you. Document this designation in writing.
2. Conduct a Written Risk Assessment
Formally evaluate:
- What sensitive data you collect and store
- Where that data lives (computers, cloud, paper files)
- What threats could compromise it
- What vulnerabilities exist in your current setup
This must be documented — not just thought about.
3. Implement Specific Safeguards
The FTC now mandates specific technical controls:
Access Controls
- Limit data access to employees who need it
- Use unique user accounts (no shared logins)
- Implement role-based permissions
Multi-Factor Authentication
- Required for accessing customer data
- Required for remote access to systems
- Not optional — it's mandatory
Encryption
- Data at rest must be encrypted
- Data in transit must be encrypted
- This includes emails containing sensitive information
Secure Development (if applicable)
- If you develop software, follow secure coding practices
- Applies to custom tools or macros handling client data
Change Management
- Document changes to your systems
- Evaluate security impact of changes
4. Regularly Test Your Safeguards
For practices with 5,000+ clients:
- Annual penetration testing
- Vulnerability assessments every 6 months
For smaller practices:
- Continuous monitoring or annual testing
- Regular review of access logs
5. Train Your Personnel
Every employee with access to customer data must receive security training covering:
- How to identify phishing attempts
- Proper data handling procedures
- Password security
- What to do if they suspect a breach
You must document this training.
6. Monitor Your Service Providers
Using tax software? Cloud storage? IT support? You're still responsible for protecting data they access.
You must:
- Select providers capable of maintaining appropriate safeguards
- Require safeguards by contract
- Periodically assess their security
7. Maintain Your Program
Security isn't "set and forget." You must:
- Review your program at least annually
- Update when business changes occur
- Adjust based on new threats or vulnerabilities
- Document all updates
8. Create an Incident Response Plan
Have a written plan for when (not if) something goes wrong:
- How to detect and contain incidents
- Who to notify (FTC, clients, state AG)
- How to document and preserve evidence
- Recovery procedures
9. Report to Your Board/Leadership
If you have partners or stakeholders, the Qualified Individual must provide at least annual reports on:
- Overall status of the security program
- Compliance with the Safeguards Rule
- Material matters (incidents, risks, violations)
May 2024 Update: Breach Notification Requirement
As of May 13, 2024, the Safeguards Rule includes mandatory breach notification:
When to report to the FTC:
- Security incident affecting 500+ people
- Must report within 30 days of discovery
What to report:
- Description of what happened
- Types of information involved
- Number of people affected
- What you're doing about it
This is in addition to any state notification laws that may apply.
Penalties for Non-Compliance
The FTC has enforcement authority with real teeth:
Civil Penalties
- Up to $53,000 per violation (as of 2025, adjusted annually for inflation)
- Penalties can be per violation, per day
- A single data breach can result in multiple violations
Enforcement Actions
- Consent orders requiring specific security measures
- Mandatory third-party audits (at your expense)
- Public disclosure of violations
Criminal Liability
- Officers and directors can be held personally liable
- Fines up to $10,000 per individual
- False statements to investigators: separate charges
Real-World Consequences
Beyond FTC penalties:
- PTIN revocation — Can't legally prepare returns
- Malpractice insurance denial — Claims rejected without documented compliance
- Client lawsuits — Personal liability for breach damages
- Reputation destruction — 89% of breached practices lose over half their clients within 6 months
Common Compliance Mistakes
Mistake #1: "I'm too small to be a target"
Reality: Small practices are easier targets. Criminals know you likely have weaker security than large firms.
Mistake #2: "My software handles security"
Reality: Your software may be secure, but you're responsible for how you use it. Are you enforcing MFA? Training staff? Documenting access controls?
Mistake #3: "I have a WISP document, so I'm compliant"
Reality: A document alone isn't compliance. You must actually implement what's documented — and prove it.
Mistake #4: "I checked 'yes' on Form W-12, so I'm covered"
Reality: Checking "yes" without actual compliance is perjury on a federal form. It provides zero legal protection.
Mistake #5: "I'll deal with it after tax season"
Reality: Breaches don't wait for convenient timing. And regulators don't accept "I was busy" as an excuse.
How to Comply: Your Roadmap
Step 1: Acknowledge Your Status
Accept that you are legally a financial institution. This isn't optional or debatable.
Step 2: Conduct a Risk Assessment
Document:
- What data you collect (SSNs, bank info, income data)
- Where it's stored (computers, cloud, paper)
- Who has access (you, staff, software vendors)
- What could go wrong (theft, hacking, employee error)
Step 3: Implement Required Safeguards
At minimum:
- Enable MFA everywhere
- Encrypt all devices (BitLocker, FileVault)
- Use encrypted email or secure portals for sensitive data
- Create unique accounts for each user
- Install and update antivirus/antimalware
Step 4: Create Your WISP
Document your security program in writing:
- Security policies and procedures
- Employee responsibilities
- Technical safeguards in place
- Incident response plan
Step 5: Train Your Team
- Initial training for all employees
- Annual refresher training
- Document who was trained and when
Step 6: Monitor and Test
- Review access logs regularly
- Test your backup restoration
- Assess your security at least annually
Step 7: Review and Update
- Annual WISP review
- Update when things change
- Document all updates
How WISP Creator Makes Compliance Simple
Implementing all this sounds overwhelming. That's because it is — if you're doing it manually.
WISP Creator helps you document your compliance quickly and thoroughly:
Your Written Information Security Plan — Done
| Safeguards Rule Requirement | How WISP Creator Helps |
|---|---|
| Written security plan | ✅ Generate your customized WISP in minutes |
| Risk assessment | ✅ Guided questionnaire documents your risks |
| Qualified Individual | ✅ Properly designated in your WISP |
| Employee training | ✅ Training tracking with completion records |
| Incident response plan | ✅ Included in generated WISP |
| Vendor management | ✅ Third-party guidelines included |
| Annual review | ✅ Automated reminders and update workflows |
What You Get
- Customized WISP document — Not a generic template, but a document tailored to your specific practice
- Risk assessment documentation — Formal, written assessment as required by the FTC
- Staff training tracking — Proof that your team completed security awareness training
- Annual review system — Reminders and checklists to keep your WISP current
- Audit-ready records — Timestamped documentation when regulators come calling
Designed for Tax Professionals
WISP Creator was built specifically for tax preparers:
- Plain English questions (no security jargon)
- Tax-industry-specific risks and safeguards pre-loaded
- Aligned with IRS Publication 4557 guidance
- Affordable for solo practitioners and small firms
Frequently Asked Questions
What's the difference between the Safeguards Rule and GLBA?
The Gramm-Leach-Bliley Act (GLBA) is the federal law that established privacy and security requirements for financial institutions. The FTC Safeguards Rule (16 CFR 314) is the regulation that implements GLBA's security requirements. Think of GLBA as the law, and the Safeguards Rule as the specific rules enforcing it.
Is there a size exemption for small practices?
No. The Safeguards Rule applies to all covered financial institutions regardless of size. Some specific requirements (like annual penetration testing) only apply to organizations serving 5,000+ customers, but the core requirements apply to everyone.
What's the "5,000 customer" threshold I've heard about?
Organizations serving fewer than 5,000 customers have slightly reduced testing requirements — they're exempt from mandatory annual penetration testing and biannual vulnerability assessments. However, they must still conduct continuous monitoring or periodic testing. All other requirements apply fully.
How does this relate to IRS requirements?
The IRS reinforces FTC Safeguards Rule compliance through:
- Publication 4557 (Safeguarding Taxpayer Data guide)
- Publication 5708 (WISP template)
- PTIN renewal Question 11 (WISP certification)
IRS requirements align with FTC requirements. If you're compliant with the Safeguards Rule, you should meet IRS expectations.
Can I be fined even without a breach?
Yes. The FTC can take enforcement action for inadequate security practices even before a breach occurs. Non-compliance itself is a violation — you don't have to wait for something bad to happen to face consequences.
What if I use cloud-based tax software?
Using compliant software helps, but doesn't automatically make you compliant. You're responsible for:
- How you configure and use the software
- Enforcing MFA (if optional, you must enable it)
- Training employees on proper use
- Managing access permissions
- Your overall security program (documented in your WISP)
How quickly can I create my WISP with WISP Creator?
Most users complete the questionnaire and generate their WISP in 30-45 minutes. You'll have a customized, compliant document ready the same day.
Take Action Today
Every day without proper compliance is a day of risk — legal, financial, and reputational.
WISP Creator helps you create the documentation you need to comply with the FTC Safeguards Rule. Stop wondering if your documentation is in order. Know it is.
[Create Your WISP Now] — Build your documented WISP today
[See How It Works] — Watch WISP Creator in action
Resources
- FTC Safeguards Rule Full Text
- FTC Safeguards Rule: What Your Business Needs to Know
- FTC Small Business Compliance Guide
- IRS Publication 4557
- IRS Publication 5708: WISP Template
WISP Creator helps tax professionals create compliant Written Information Security Plans as required by the FTC Safeguards Rule. Generate your customized WISP, track staff training, and maintain audit-ready documentation.
SEO Metadata
Title Tag (60 chars): FTC Safeguards Rule for Tax Preparers | 2025 Guide | WISP Creator
Meta Description (155 chars): Tax preparers are financial institutions under federal law. Learn FTC Safeguards Rule requirements and create your compliant WISP in minutes.
URL: https://wisp-creator.com/ftc-safeguards-rule
Target Keywords:
- Primary: "FTC Safeguards Rule tax preparers"
- Secondary: "Safeguards Rule requirements", "FTC compliance tax preparer", "financial institution tax preparer", "WISP FTC Safeguards"
- Long-tail: "does FTC Safeguards Rule apply to tax preparers", "FTC Safeguards Rule small business exemption", "FTC Safeguards Rule WISP"