Bay Geeks logoTampa Bay IT Support · Since 2004
Bay Geeks Guide · Compliance For Tax Pros

WISP for Accounting Firms: The FTC Safeguards Rule, Explained

If you prepare tax returns for money, federal law already treats your firm as a financial institution, and the FTC Safeguards Rule requires a written information security plan. Most small firms find out from the PTIN renewal or a client's insurance form. Here's what it actually says.

The Safeguards Rule has been on the books since the early 2000s, but the 2021 rewrite is the one that put specific technical requirements in it, and the 2024 amendment added a breach-notification clock. The IRS reinforces it through Publication 4557 and provides a fill-in template for the plan in Publication 5708. None of that requires a compliance department. It requires a plan, a name on it, and a short list of controls most of which you can turn on this month.

The Short Version

You need a written plan (the WISP), a named person responsible for it, a handful of technical controls (encryption, multi-factor authentication, access limits, monitoring, secure disposal), staff training, oversight of the vendors who touch client data, and a written procedure for a breach. Firms holding data on fewer than 5,000 people are excused from some of the paperwork, but not from the plan or the controls.

Who It Applies To

Anyone the Gramm-Leach-Bliley Act calls a financial institution, which the FTC reads broadly: tax preparers, CPAs and bookkeepers who prepare returns, enrolled agents, and payroll providers, at any size. The rewritten rule took full effect in June 2023, and the breach-notification requirement in May 2024.

What Has to Be in the Plan

ElementWhat it means in a small firm
1. A Qualified IndividualOne named person responsible for the program. It can be an outside provider, but the firm still designates a senior person to oversee them and keeps the responsibility.
2. A written risk assessmentWhere client data lives (tax software, email, the scanner, laptops, cloud storage, the copier's hard drive) and what could go wrong with each.
3. SafeguardsAccess limited to who needs it, a data inventory, encryption in transit and at rest, MFA for anyone reaching client information, secure disposal of data no longer needed (two years by default), change management, and logs of who accesses what.
4. Regular testingContinuous monitoring, or an annual penetration test plus vulnerability scans every six months.
5. Staff trainingSecurity awareness, with a record of who attended and when.
6. Service provider oversightA list of vendors that touch client data, and contract terms requiring them to protect it.
7. Keeping it currentRevisit after any change in the business, and after any incident.
8. A written incident response planWho does what, in what order, and who gets notified.
9. An annual written reportTo the owner, partners or board, on the state of the program.

The Small-Firm Exemptions

A firm that holds information on fewer than 5,000 consumers is exempt from four of those: the written risk assessment, the continuous monitoring or annual penetration test, the written incident response plan, and the annual written report. Everything else applies, including the plan itself, the Qualified Individual, MFA, encryption, training and vendor oversight. Most firms below the threshold write the exempt pieces anyway, because insurers ask for them and the IRS template includes them.

The Breach Notice

Since May 2024, a firm that discovers unauthorized access to unencrypted client information affecting 500 or more people must notify the FTC within 30 days, through the FTC's online form. Florida's own law, the Florida Information Protection Act, separately requires notifying affected individuals within 30 days for most breaches. And the IRS asks preparers to report client data theft to their local Stakeholder Liaison right away, because stolen preparer data is used to file fraudulent refunds within days. Three short clocks, which is why the incident plan gets written before the incident.

What This Looks Like for a Three-Person Firm

  1. Name the owner as the Qualified Individual, with your IT provider as the technical resource, in writing.
  2. Inventory where client data lives: tax software, email, the scanner, laptops, the cloud drive, the client portal, and the old drives in the closet.
  3. Turn on MFA or passkeys everywhere client data is reachable: the tax software, email, the portal, the cloud drive.
  4. Encrypt the laptops with BitLocker or FileVault, and enroll the phones in Mobile Device Management.
  5. Put EDR, automated patching and versioned backups on every machine. That's the Automated plan.
  6. Add monitoring and logging, which cover the activity-monitoring and testing elements. That's the Advanced plan's SOC, vulnerability scanning and 90-day log retention.
  7. Write a disposal rule: shred paper, wipe or destroy drives, and delete returns past your retention period.
  8. List the vendors and check their security terms: tax software, portal, cloud storage, IT provider, payroll.
  9. Write a one-page incident plan: who calls the IRS, the FTC, the insurer and the clients, and in what order.
  10. Run fifteen minutes of training at tax-season kickoff, with a sign-in sheet.
  11. Fill in the Publication 5708 template with all of the above, date it, and put a reminder in the calendar to review it next year.
Elements coveredBay Geeks plan
EDR, patching, versioned backups, system lockdownAutomated, $75/mo per computer
Help desk, remote support, Mobile Device ManagementPremium, $125/mo per computer
Monitoring, logging, vulnerability scanning, dark-web credential checksAdvanced, $150/mo per device
Evidence for the annual report and the insurerOne-Click Compliance reporting on Advanced

Quick Self-Check

QuestionIf “no” or “not sure”...
Do you have a WISP you could email to a client today?Start from Publication 5708
Is MFA on the tax software, the email and the portal?Do this first
Do you know where every old drive with client returns is?Inventory this month
Would you know within 30 days if client data left the building?Worth a call
FIXED ✓

Build the WISP Around the Controls You Already Have

We map what's in place to the nine elements, fill the gaps, and hand you the evidence for the annual report and the insurance form.

Frequently Asked Questions

Do I need a WISP if I'm a solo preparer?

Yes. The small-firm exemption removes four elements of the program, not the plan itself. A solo preparer still needs the written plan, a named responsible person, MFA, encryption, a disposal rule and vendor oversight.

Does anyone actually check?

The IRS asks about data security when you renew your PTIN and apply to e-file, and the FTC enforces the rule. The more immediate check is a client's or an insurer's questionnaire. The expensive check is having no plan after a breach.

Can Bay Geeks be my Qualified Individual?

The rule allows the Qualified Individual to sit with a service provider, but your firm still names a senior person to oversee them and keeps the responsibility. In practice we act as the technical resource, named in the plan, and the owner signs the annual report.

What counts as a notification event?

Unauthorized acquisition of unencrypted client information. Five hundred or more affected consumers triggers the FTC notice; Florida's law and the IRS have their own thresholds and clocks. When in doubt, call the same day.

Is this the same as HIPAA?

Different law, same shape: a written program, a responsible person, specific controls and a breach clock. Our compliance guide covers HIPAA, PCI DSS and NIST; the Safeguards Rule is the accounting-firm version.

Insurance & Compliance Hub

Where cyber insurance, HIPAA, PCI DSS and GLBA overlap, and which page covers which.

One-Click Compliance

What HIPAA, PCI DSS and NIST reporting should actually look like.

Cyber Insurance Questionnaire

What carriers ask about MFA, backups and EDR, and how to get to an honest yes.

IT for Accounting Firms

What we set up for firms that handle financial data.

📞 727-579-4335  ·  ✉️ support@baygeeks.com  ·  Privacy Policy  ·  Terms of Service

Call Now Schedule