The FTC Safeguards Rule & IRS Pub 4557 Checklist for Tax & Accounting Firms — Ma3SP Technology
For Tax & Accounting Firms

The FTC Safeguards Rule & IRS Pub 4557 Checklist — In Plain English

What every paid tax preparer is actually required to have in place, according to the FTC Safeguards Rule (16 CFR Part 314) — plus the preparer-specific guidance IRS Publication 4557 adds on top of it. No jargon, no upsell. Just the list.

This is an educational summary, not legal advice. It's written in plain language to help you understand what the rule and IRS guidance generally cover and where your firm might have gaps. It does not cover every detail of 16 CFR Part 314 or Publication 4557, and it doesn't certify compliance. For a legal determination of your firm's specific obligations, talk to an attorney or compliance professional who handles tax-preparer regulatory matters.

Who this applies to: Any business that handles taxpayer financial data as part of preparing returns — solo preparers and multi-partner firms alike — regardless of who manages your IT. Where it comes from: the first four groups below summarize the FTC Safeguards Rule (16 CFR Part 314), amended in 2023. The fifth group covers guidance specific to tax preparers straight out of IRS Publication 4557 — the IRS's own "Security Six," breach warning signs, and who to call when something goes wrong.

Ownership & Assessment

Someone is officially responsible for this.

Your firm has designated a specific person — a "Qualified Individual" in the rule's language — responsible for your information security program. For a solo practice, that's usually you. It just needs to be a named person, not an assumption.

16 CFR §314.4(a)

You've written down what could actually go wrong.

A risk assessment, in writing, that names realistic threats to client data — a lost laptop, a phishing email, ransomware, an employee mistake — and roughly how serious each one would be. It gets revisited periodically, not written once and forgotten.

16 CFR §314.4(b)
The Actual Safeguards

Access to client data is limited by role, not open to everyone.

Staff can see the client files relevant to their work — not the entire client base by default, just because it's convenient.

16 CFR §314.4(c)(1)

Multi-factor authentication (MFA) is required wherever client data can be reached.

Email, practice management software, cloud storage, remote access — anywhere someone could get to client tax or financial data. This is the single most common gap we see in small firms.

16 CFR §314.4(c)(5)

Client data is encrypted — in transit and at rest.

Both while it's being sent (email attachments, file transfers) and while it's sitting on a server, a laptop, or a backup drive.

16 CFR §314.4(c)(3)

Old client data actually gets deleted.

A real retention and secure-disposal schedule — not keeping every file forever because deleting anything feels risky.

16 CFR §314.4(c)(6)

Activity on your systems is logged and monitored for anything unusual.

Someone — or something automated — would actually notice if an account started behaving strangely, instead of finding out from a client first.

16 CFR §314.4(c)(8)
Verification & People

Someone actually tests whether all of this is working.

Ongoing monitoring, or at minimum annual penetration testing plus vulnerability scans twice a year — not a plan that sits in a drawer untested.

16 CFR §314.4(d)

Staff have been trained — for real, on a schedule.

Not a one-time "be careful with email" comment years ago. Ongoing security awareness training, and whoever owns your security program stays current on new threats.

16 CFR §314.4(e)

Outside vendors with access to client data are vetted, not just trusted.

Your software vendors, IT provider, and any other outside party that can touch client data are contractually required to protect it — not just assumed to be handling it responsibly.

16 CFR §314.4(f)
Staying Current

The plan gets updated when things change.

New software, new staff, a new office, a past incident — any of these should trigger a real review of the plan, not a "we'll get to it" mental note.

16 CFR §314.4(g)

A written incident response plan exists — before you need it.

A real, specific answer to "what do we do in the first hour after we learn about a breach," decided in advance instead of figured out in a panic.

16 CFR §314.4(h)

Someone reports on the program's status at least once a year.

Even in a small firm, this means actually sitting down once a year and reviewing, in writing, whether the plan is still accurate and whether anything needs to change.

16 CFR §314.4(i)
Tax-Practice-Specific Practices (IRS Publication 4557)

The "Security Six" baseline tools are all in place.

Antivirus software, a firewall, multi-factor authentication, backup software, drive encryption, and a VPN for remote access — the six basic tools the IRS specifically names as the starting point for every preparer, regardless of firm size.

IRS Pub 4557, "Security Six"

Staff can recognize phishing built specifically to target tax preparers.

"New client" scams, and emails spoofing your e-Services account, tax software provider, or the IRS asking you to "verify" your EFIN or login. These don't look like generic spam, and they're the leading actual cause of preparer data breaches.

IRS Pub 4557

EFIN and PTIN credentials are protected like the keys to the business — because they are.

E-Services login credentials aren't shared between staff, and someone actually checks the account periodically for signs it's been used without authorization.

IRS Pub 4557

You'd actually recognize the warning signs of a breach.

Client e-files rejected because a return was already filed under their SSN. IRS notices about returns you didn't prepare. More transcripts pulled through your account than you actually requested. These are often the first sign something's wrong — before anything else would tip you off.

IRS Pub 4557

You know exactly who to call in the first hour — including the IRS.

Beyond your internal incident response plan, the IRS specifically directs preparers to contact their local IRS Stakeholder Liaison immediately, in addition to the FTC and any state tax agencies where you prepare returns.

IRS Pub 4557, Data Theft Information for Tax Professionals

You know whether your state's breach notification law applies to you.

Indiana and Michigan each have their own data breach notification requirements, separate from federal rules — worth confirming with a professional if your firm operates across both, or if you've simply never checked.

Ind. Code §24-4.9; Mich. Comp. Laws §445.72

Not sure how many of these your firm can actually check off?

Book a free 25-minute Security Plan Check. Bring whatever plan you have — or nothing at all — and Graham will walk through this exact list with you, in plain English.

Book Your Free Security Plan CheckNo pitch. No obligation. Keep what we find, either way.