FTC Safeguards Rule compliance and security for California CPA, tax and bookkeeping practices.
If your firm prepares tax returns or provides financial services, the FTC defines you as a non-bank financial institution and the Safeguards Rule binds you. Most firms discover this when an insurer or a client asks, rather than when the obligation started.
The IRS reinforces it from a different direction: a Written Information Security Plan is tied to PTIN obligations, and IRS Publication 4557 sets out what the Service expects of tax professionals safeguarding client data. Firms treat this as paperwork right up until a client questionnaire, an insurance renewal or a breach makes it evidentiary.
The exposure is not theoretical. Tax and accounting firms hold Social Security numbers, bank details, payroll records and full financial histories for hundreds of clients in one place. That concentration is precisely why the sector is targeted, and why the regulatory attention exists.
The Safeguards Rule is not prescriptive about products. It is prescriptive about programme elements, which is why buying tools without documenting a programme leaves a firm non-compliant while feeling secure.
| Requirement | What it means in practice | Common gap |
|---|---|---|
| Written Information Security Plan | A documented plan describing how client financial data is protected in your actual environment | A downloaded template with the firm name inserted, describing controls the firm does not have |
| Qualified individual | One named person accountable for the programme — employee or designated service provider | Nobody named, or someone named who was never told and has no authority |
| Risk assessment | Written identification of where client data lives and what could compromise it | Never performed, or performed once and never revisited after systems changed |
| Access controls | Staff limited to the client data their role requires, reviewed periodically | Everyone can reach every client file because it is simpler during busy season |
| Encryption | Client data protected at rest and in transit | Laptops unencrypted; client documents emailed as plain attachments |
| Multi-factor authentication | Explicitly named in the Rule for systems holding customer information | SMS codes only, which do not survive a real-time credential phish |
| Vendor oversight | Documented due diligence on service providers handling client data | The most commonly missing element entirely — no inventory, no assessment, no contract terms |
| Incident response plan | A written plan that exists before it is needed | Improvised during the incident, when nobody can think clearly |
Most of what the Rule requires is configurable inside Microsoft 365 Business Premium, which the majority of firms in this market already license. The gap here is configuration and documentation, not budget — which is good news, because it means compliance is mostly a decision rather than a purchase.
Phishing-resistant MFA on every account with access to client data, conditional access by device, and removal of standing administrative rights.
Encryption at rest and in transit, data-loss policy to stop client financial data leaving by email, and retention configured deliberately rather than by default.
Role-based permissions so seasonal staff reach only the clients they work on, with periodic review rather than a one-time setup.
Audit logging with retention long enough to investigate after the fact, plus the written control record your WISP references.
Between January and April a firm moves more client financial data, onboards temporary staff, and works longer hours under time pressure — the exact conditions phishing and business email compromise exploit. Attackers know the calendar as well as you do.
Seasonal staff are the specific structural weakness. They are onboarded quickly, often granted broad access because narrowing it takes time nobody has in February, and then frequently not offboarded properly in May. A year later those credentials still work.
The direct costs are the visible part and rarely the largest. A firm that loses client financial data faces a sequence of obligations and consequences that compound.
Set against that, the cost of configuring controls you already license and writing the programme down is not a close call. The reason firms delay is not economics — it is that the work is unglamorous and nothing forces the deadline until something does.
Most firms evaluate providers on price and response time. Those are the two things every provider claims and neither predicts the outcome. The questions below are harder to answer well, which is exactly why they are worth asking.
Ask for the answers in writing. A provider who will commit to them in an email is a different proposition from one who will only say them on a call.
Engagements fail most often in the transition, not the steady state — because nobody agreed who owned what while it was moving. This is the shape of a Cobrix onboarding.
We inventory the environment: identities, devices, licences, data locations, vendor access and current configuration. Output is a written findings document with gaps ranked by exploitability, not by severity label. You keep it whether or not you continue.
The high-exploitability items first — typically phishing-resistant MFA, removal of standing admin rights, audit logging with deliberate retention, and closing whatever access should have been revoked and was not.
The written programme, policies and risk analysis your obligations actually require as artefacts, reflecting your real environment rather than a template with your name inserted.
Steady-state support, review cadence agreed, and the accepted-risk register written down with reasoning so the next audit or renewal has something honest to work from.
Nothing here requires you to replace working systems. Most of it is configuration of platforms you already own, which is why the first 90 days rarely involve capital expenditure.
For the documented programme and WISP, see IT compliance services. For the security layer, see cybersecurity services. For day-to-day support, see managed IT. Staff training is a named requirement — see security awareness training. If client data may already be exposed, see incident response.
Almost certainly yes. The Rule defines non-bank financial institutions broadly enough to cover most CPA, tax and bookkeeping practices, and it does not exempt firms on size alone — though certain requirements scale for firms below 5,000 consumer records. If you prepare returns or handle client financial data, assume it applies and document accordingly.
A Written Information Security Plan documents how your firm protects client financial data. It is required under the FTC Safeguards Rule, and the IRS ties having one to PTIN obligations. It must describe your actual environment and controls — a generic template with your firm name inserted does not satisfy the requirement and reads badly under scrutiny, because it describes controls you may not have.
One named person accountable for the information security programme. It can be a partner, a staff member, or a designated employee of a service provider such as your MSP — but accountability stays with the firm, and the person must actually be positioned to oversee the programme rather than named on paper and never told.
Enforcement exposure under the Safeguards Rule is separate from, and additional to, the costs of the breach itself — notification, client remediation, IRS and state reporting, and civil liability from affected clients. In practice the largest cost most firms face is client attrition, which no penalty schedule captures.
For financial data under the Safeguards Rule, yes, with MFA and access controls configured. For Protected Health Information it is not appropriate — Intuit will not sign a Business Associate Agreement, so PHI does not belong there. That distinction matters for firms serving medical practices, where the two data types can end up in the same system.
Provision with an expiry date from the outset so revocation is automatic, scope permissions to the specific clients they work on rather than the whole file store, and run the offboarding as a documented checklist in May rather than from memory. Seasonal credentials that still work a year later are one of the most common findings in this sector.
The Rule names MFA; it does not itemise acceptable factors. But SMS codes do not survive a real-time credential phish, which is the attack actually used against firms. Phishing-resistant methods — authenticator apps with number matching, or hardware keys — are the defensible choice, and they are included in licensing most firms already hold.
Most of the technical requirements are configurable in Microsoft 365 licensing you likely already hold, so the cost is largely configuration and documentation rather than new products. The variables are firm size, how many systems hold client data, and current state — inheriting a well-run environment costs less than remediating a neglected one. We quote after assessing rather than from a list.
Not necessarily, but you do need someone accountable for the programme rather than the tickets, and the boundary has to be written down. A common arrangement is the incumbent keeping day-to-day support while a second party takes the security and compliance layer. It works when the split is documented and fails when it is assumed.
Schedule a free consultation today.