The first flag is human · CPA & tax preparation firms

The rule doesn’t care how many people you employ.

The FTC Safeguards Rule has required a written information security program at every tax and accounting firm since June 2023 — sole practitioners included. Most firms that got the memo built a policy. Fewer built a program anyone actually runs.

The regulatory backdrop

A one-person firm has the same obligation as a fifty-person one.

The FTC Safeguards Rule (16 CFR Part 314) has applied to “financial institutions” — a category the FTC explicitly defines to include tax preparers — since it became enforceable on June 9, 2023. It requires a written information security program (WISP), a named Qualified Individual responsible for it, and safeguards around client financial data. Firm size changes the paperwork, not the obligation.

Firms with a real, maintained WISP vs. a policy on the shelf

FTC Safeguards Rule, 16 CFR Part 314

Every tax and accounting firm subject to the Rule needs a Written Information Security Program (WISP). What examiners and cyber insurers increasingly check for isn’t whether a document exists — it’s whether the risk assessment, access controls, and incident-response plan inside it are current and actually followed.

1.1M+

tax returns the IRS flagged for potential identity fraud in a single filing season, stopping $105.3 million in improper refunds — each one tied to a compromised identity or preparer account.

IRS, reported by CNBC, May 2023
16 CFR 314

requires a written security program, a named Qualified Individual, and documented safeguards — enforceable against tax preparers of every size since June 9, 2023.

FTC Safeguards Rule
63%

of breached organizations across sectors had no AI governance policy, or were still drafting one, when client data was exposed — relevant wherever a firm uses AI to draft returns or summarize filings.

IBM, Cost of a Data Breach Report 2025
What actually goes wrong

The breach is rarely the firewall. It’s the inbox.

Preparer credential theft, phishing emails impersonating the IRS or a client, and W-2 scams targeting HR and payroll staff drive most tax-season fraud — not a sophisticated network intrusion.

What examiners and insurers actually check for

FTC Safeguards Rule, 16 CFR Part 314 requirements
Written Information Security Program (WISP) on filerequired
Named Qualified Individual accountable for itrequired
Access controls & encryption for client tax datarequired
Documented incident-response plan, tested annuallyrequired
Source: FTC Safeguards Rule, 16 CFR Part 314, enforceable since June 9, 2023. Requirement scope, not a compliance-rate statistic.

A policy in a drawer isn’t a program

The Rule expects an annual risk assessment and a Qualified Individual who can explain the program — not a document nobody’s reopened since it was written.

Preparer credentials are the real target

A stolen e-file PIN or software login can generate fraudulent returns under your firm’s name before anyone notices.

AI drafting tools are a new, unwritten risk

Pasting client financials into a general AI tool to draft a letter or summarize a return moves that data outside any safeguard the Rule assumes you have.

Who this is for

Handling the most sensitive financial data a small business touches.

CPA & tax preparation firms

Sole practitioners, small and mid-size accounting & tax firms

Firms preparing individual and business tax returns, or providing accounting and advisory services, that handle Social Security numbers, bank details, and full financial pictures for every client. You're squarely inside the FTC Safeguards Rule's definition of a covered “financial institution” — regardless of headcount.

Services

Three ways to work together.

Same arc every time: find the gaps, train the eyes, build the program that holds.

Start here 01 · Workshop

Before the Breach

Train the eyes

A half-day session for partners, preparers, and admin staff — what a WISP actually requires in practice, plus a one-page escalation playbook for a phishing attempt or a client-data concern.

From $7,000Founding rate $5,000 for the first cohorts
02 · Assessment

Safeguards Rule Readiness Assessment

Find the gaps

2–3 weeks: review your WISP (or build the gap list if you don't have one), access controls, vendor agreements, and AI tool usage against the Rule's requirements, with a prioritized roadmap.

From $11,000Fixed fee · scope set before we start
03 · Retainer

Program Advisory

Build it for real

A monthly advisor serving as, or supporting, your Qualified Individual — annual risk assessment, staff training refreshers, and incident-response testing before tax season, not during it.

From $6,000/mo6-month minimum
Let's talk

Confident your WISP would hold up to a real look?

A 20-minute call, no pitch. Tell us where you're exposed and what your next insurance renewal requires — we'll tell you honestly where we'd start.

Book a 20-minute call