
The FTC Safeguards Rule requires your CPA firm to build, implement, and maintain a written information security program that protects client financial data. If your firm handles tax returns, manages client financial records, or offers any financial services, the Rule almost certainly applies to you. "Almost certainly" is not a hedge: the FTC defines "financial institution" broadly, and tax-preparation and accounting firms fall within that definition.
What the Rule does not do is specify exactly which software to buy. It sets seven required program elements and then holds your firm accountable for the outcome. A Managed Service Provider (MSP) can implement and operate the technical controls that underpin several of those elements. The firm itself must own the program, the written documentation, and the designated coordinator.
This article walks through each element, translates it into the operational reality of a CPA firm, and clarifies which responsibilities belong to your firm and which can be supported by a technology partner.
Who Must Comply With the FTC Safeguards Rule
The Rule applies to "financial institutions" under the Gramm-Leach-Bliley Act (GLBA). The FTC's definition of that term includes any business that is "significantly engaged" in providing financial products or services to consumers. Tax preparation, tax filing assistance, accounting services, and financial record-keeping all meet that threshold. If your Phoenix CPA firm touches client tax files, prepares individual or business returns, or accesses IRS e-Services on behalf of clients, the Safeguards Rule applies.
The Rule was substantially updated in 2023, tightening requirements that had previously been somewhat open-ended. Firms that built a loose "security policy" years ago and never revisited it should treat this as a gap.
The Seven Required Elements — Translated for a CPA Firm
The Safeguards Rule requires a written information security program built around seven elements. Here is what each element demands in practice, using the vocabulary of a CPA firm rather than the FTC's regulatory phrasing.
1. Designate a Qualified Individual
The Rule requires you to name a specific person who is responsible for overseeing, implementing, and enforcing the information security program. The Rule calls this person a "Qualified Individual." This responsibility cannot be spread across a committee or left unassigned because "everyone is responsible for security."
For a smaller CPA firm, this is often a managing partner or a senior operations person. The Qualified Individual does not need to be a technical expert, but they do need to understand the program, receive regular reports, and be accountable for its status. A managed IT provider can support this person with technical data, but the designation itself is a firm responsibility. You cannot outsource the role.
Practical connection: If your firm uses IRS e-Services for e-filing or electronic return originator credentials, the person who owns those credentials and the access controls around them should have a direct line to your Qualified Individual.
2. Conduct a Written Risk Assessment
Before you can design a safeguards program, you need to know what you are protecting and where it is at risk. The Rule requires a written risk assessment that identifies the client data your firm collects and stores, the internal and external risks to that data, and how effective your current controls are against those risks.
For a CPA firm, this means thinking through: Where do client tax files live? Are they in your tax software's local database, in cloud storage, or both? Who has access to them and from which devices? What happens when a staff accountant works from home? What would a phishing email targeting your e-filing credentials actually be able to reach?
The risk assessment must be documented. A verbal understanding of your environment does not satisfy the requirement. Your technology partner can contribute technical findings, such as a vulnerability scan or an access-control audit, that feed into the written assessment. The firm is responsible for completing the document and revisiting it regularly.
3. Design and Implement Safeguards
Once you know your risks, the Rule requires you to implement safeguards that address them. The updated Rule is specific about several controls that are now mandatory rather than optional. They include:
- Access controls limiting who can reach client financial data, using the principle of least privilege.
- Encryption of client data, both in transit and at rest.
- Multi-factor authentication (MFA) for any system holding or providing access to customer information.
- Patch management to keep systems and software current.
- Secure development practices if your firm builds or customizes any software.
- Data disposal procedures so client files and devices are securely wiped when no longer needed.
- Change management to track modifications to your information systems.
This is the element where technical operations matter most. Encrypting endpoints, enforcing MFA across Microsoft 365 and tax software portals, patching workstations consistently, and controlling which devices can access client data are exactly the kind of recurring operational work a managed IT program handles. Implementing these controls once and walking away is not sufficient. The Rule expects ongoing operation and monitoring.
At Onsite Technical Services, the technical controls in a properly scoped managed IT program address a significant portion of this element: endpoint encryption, patch management, access controls, advanced email protection, and continuous monitoring are part of the operational work performed on behalf of the firm. What remains a firm responsibility is documenting those controls in the program, ensuring the controls actually match the risk assessment findings, and verifying that coverage extends to every system that touches client data, including your tax software and any third-party portals.
4. Oversee Service Providers
If your firm shares client financial data with any third party, or if a third party provides services that could affect the security of that data, the Rule requires you to select those providers carefully, contractually require them to implement appropriate safeguards, and periodically review their performance.
For a CPA firm, this includes: cloud-based tax software vendors, document management platforms, e-signature services, payroll processors, and your managed IT provider. The requirement is not simply to have a contract. The contract must address security, and someone at the firm must actually review whether the provider is holding up its end.
This means asking vendors for their security documentation, reviewing their subcontractor relationships, and keeping records of that due diligence. It also means that if you are using a tax software platform that stores client files, your risk assessment needs to account for that vendor's environment, not just your own office network.
5. Train and Manage Your Staff
The Rule requires ongoing security awareness training for your employees. "Ongoing" matters: a one-time orientation video when a new hire joins does not satisfy the requirement. Training must be updated to reflect current threats and must reach all staff who handle client data, including seasonal tax-season staff.
Phishing is the most common way attackers reach CPA firm data. A credential-theft email targeting a staff accountant's Microsoft 365 login or tax software password is a realistic attack vector, not a theoretical one. Training staff to recognize phishing, impersonation attempts, and business email compromise is both a regulatory requirement and a direct operational defense.
Security awareness training with simulated phishing campaigns is a component Onsite Technical Services operates as part of a managed security program. The firm remains responsible for ensuring that training reaches every applicable staff member, including temporary or seasonal employees.
6. Keep the Program Current: Monitor, Test, and Update
The Rule requires you to monitor and test the effectiveness of your safeguards, and to update the program when circumstances change. "Circumstances change" covers: your firm adds a new service, you bring on a new software vendor, you have a security incident, there is a change in law, or you identify a new risk during a periodic review.
Practically, this means your safeguards program cannot be a document that is written once, filed, and forgotten. Continuous monitoring, regular log review, and periodic testing are all part of maintaining the program. A managed security program that includes 24/7 monitoring, alert triage, and regular reporting gives your Qualified Individual the technical data needed to demonstrate ongoing program operation. But someone at the firm must review those reports, act on recommendations, and update the written program accordingly.
7. Create and Maintain a Written Incident Response Plan
The Rule requires a written plan describing how your firm will respond if a security incident occurs. The plan must address the goals of the response, the internal processes for responding, the roles and responsibilities of everyone involved, communication and notification procedures (including when and how to notify affected clients or regulators), and a process for post-incident review.
An incident response plan is not the same as a backup plan or a disaster recovery plan, although both of those matter too. The incident response plan is specifically about what happens when client data may have been exposed or compromised. For a CPA firm, that scenario includes a ransomware attack against your tax software database, a phishing email that resulted in a compromised staff login, or an unauthorized third party accessing your client portal.
Onsite Technical Services can help define the technical response steps and contribute to the plan's structure. The plan itself, however, must be owned and approved by the firm, because it includes decisions about client notification, regulatory reporting, and business continuity that are not technical decisions alone.
The Written Information Security Program (WISP): What It Is and Why It Is Not Optional
The seven elements above must be documented in a Written Information Security Program, commonly called a WISP. The WISP is not a generic template downloaded from the internet. It must reflect your firm's actual environment: the data you hold, the systems you use, the vendors you rely on, the staff who have access, and the controls you have implemented.
The IRS has independently reinforced the WISP requirement for tax professionals. Both the FTC Safeguards Rule and IRS guidance for tax preparers point to the same destination: a written, maintained security program that is specific to your practice.
The WISP is a firm responsibility. Your IT provider can inform it with technical documentation. Your compliance advisor can help structure it. But the firm must own it, sign off on it, and keep it current. Signing a managed IT agreement does not produce a WISP.
What OTS Implements and Operates vs. What the Firm Must Own
| Program Element | OTS Technical Operations | Firm Responsibility |
| Designated Qualified Individual | Provides reports and data to support the role | Names the individual, maintains accountability |
| Risk Assessment | Contributes vulnerability scan, access-control audit, technical findings | Produces the written document, signs off on scope |
| Safeguards (technical controls) | Implements and operates encryption, MFA, patching, endpoint security, monitoring, advanced email protection, access controls | Documents controls in the WISP, verifies coverage extends to all applicable systems including tax software |
| Service-Provider Oversight | Can provide its own security documentation as a vendor | Reviews all vendors (including OTS), maintains contracts with security terms, documents due diligence |
| Staff Training | Operates security awareness training and phishing simulations | Ensures all staff (including seasonal) complete training, maintains records |
| Monitoring and Testing | Continuous 24/7 monitoring, alert triage, periodic reporting | Reviews reports, acts on findings, updates program when risks change |
| Incident Response Plan | Contributes technical response procedures, provides forensic support during an incident | Owns the written plan, decides on client/regulator notification, approves post-incident review |
| WISP (the written program) | Provides technical documentation and supporting detail | Produces, maintains, and signs off on the WISP as a firm document |
How IT Fits Into a Safeguards Program (and What It Cannot Replace)
A well-managed IT program handles the technical controls that are the backbone of several Safeguards Rule elements: encrypting every endpoint, enforcing MFA, monitoring for threats, patching software consistently, filtering malicious email before it reaches staff, and maintaining backup copies of client data that are independent of your primary systems. These are not small tasks. Done correctly and continuously, they represent a significant portion of the operational work the Rule expects.
What IT services cannot replace is the administrative layer: the written program, the risk assessment, the documented vendor reviews, the named Qualified Individual, the incident response plan, and the WISP. Those are firm-owned documents and decisions. No IT agreement produces them automatically.
A Phoenix CPA firm that has solid technical controls but no written program is exposed. A firm with a written program but weak technical controls is equally exposed. The Rule expects both. Getting IT right is a necessary condition, not a sufficient one.
Practical Starting Points for a Phoenix CPA Firm
- Name your Qualified Individual now, in writing, even if the rest of the program is still being built.
- Map where client tax files actually live: local workstations, tax software databases, cloud storage, portals, and any backup locations.
- Confirm MFA is enforced on every system that touches client data, including Microsoft 365, your tax software login, and IRS e-Services.
- Review your vendor list. If a vendor holds or can access client financial data, there should be a written agreement with security terms.
- Inventory your training program. When did your seasonal staff last complete it? Is there a record?
- Pull out your incident response plan. If you cannot find it quickly, that is the answer.
- Engage a compliance advisor or attorney who works with financial services firms to help build or audit your WISP. This is a legal and administrative task, not just a technical one.
Frequently Asked Questions
Does the FTC Safeguards Rule apply to my CPA firm if I only do individual tax returns?
Almost certainly yes. The FTC defines 'financial institution' broadly under GLBA to include any business significantly engaged in providing financial products or services to consumers. Tax preparation and filing for individuals meets that definition. If you handle client tax files and assist with IRS e-filing, the Rule applies to your firm regardless of size.
Do I need a WISP even if I already have a managed IT provider handling my security?
Yes. A Written Information Security Program (WISP) is a firm-owned administrative document, not a byproduct of an IT agreement. Your managed IT provider can contribute technical documentation and operate the controls described in the WISP, but the firm must produce, maintain, and sign off on the written program. Having managed IT without a WISP leaves a compliance gap.
What counts as a 'security incident' under the FTC Safeguards Rule for a CPA firm?
An incident is any unauthorized acquisition, access, use, or disclosure of customer information that could harm clients. For a CPA firm this includes a ransomware attack against your tax software database, a phishing email that compromised a staff login with access to client files, or unauthorized access to your client portal. Your written incident response plan must address what steps to take, who is responsible, and when clients or regulators must be notified.
What is the difference between the FTC Safeguards Rule and IRS data security requirements for tax professionals?
They are separate but overlapping. The FTC Safeguards Rule applies to financial institutions under GLBA and is enforced by the FTC. The IRS also requires tax professionals to have a Written Information Security Program and has published its own guidance reinforcing that requirement. Both point to the same destination: a documented, maintained security program specific to your practice. Satisfying one does not automatically satisfy the other, but a well-built program designed around the seven Safeguards Rule elements will address much of what both require.
Can the Qualified Individual under the FTC Safeguards Rule be an outside vendor or consultant?
The Rule permits the Qualified Individual to be a third party, such as a consultant, but it requires the firm to monitor that person's activities, and the firm's senior management must receive regular reports on the program's status. The designation and accountability cannot simply be delegated and forgotten. Someone at the firm remains responsible for understanding the program and acting on what the Qualified Individual reports.
How much does managed IT cost for a CPA firm that needs to support FTC Safeguards Rule compliance?
For professional services firms like CPA practices, managed IT with the security stack needed to support a Safeguards Rule program runs approximately $200-$250 per user per month as a planning range. That covers the ongoing technical operations: endpoint security, monitoring, patching, MFA enforcement, email protection, backup, and security awareness training. Network management is a separate line item that depends on who owns the hardware and the size and complexity of the network. These are planning figures, not a quote. Contact Onsite Technical Services for a scope-specific conversation.

