The rule doesn’t care how many people you employ.
The FTC Safeguards Rule has required a written information security program at every tax and accounting firm since June 2023 — sole practitioners included. Most firms that got the memo built a policy. Fewer built a program anyone actually runs.
A one-person firm has the same obligation as a fifty-person one.
The FTC Safeguards Rule (16 CFR Part 314) has applied to “financial institutions” — a category the FTC explicitly defines to include tax preparers — since it became enforceable on June 9, 2023. It requires a written information security program (WISP), a named Qualified Individual responsible for it, and safeguards around client financial data. Firm size changes the paperwork, not the obligation.
Firms with a real, maintained WISP vs. a policy on the shelf
FTC Safeguards Rule, 16 CFR Part 314Every tax and accounting firm subject to the Rule needs a Written Information Security Program (WISP). What examiners and cyber insurers increasingly check for isn’t whether a document exists — it’s whether the risk assessment, access controls, and incident-response plan inside it are current and actually followed.
tax returns the IRS flagged for potential identity fraud in a single filing season, stopping $105.3 million in improper refunds — each one tied to a compromised identity or preparer account.
requires a written security program, a named Qualified Individual, and documented safeguards — enforceable against tax preparers of every size since June 9, 2023.
of breached organizations across sectors had no AI governance policy, or were still drafting one, when client data was exposed — relevant wherever a firm uses AI to draft returns or summarize filings.
The breach is rarely the firewall. It’s the inbox.
Preparer credential theft, phishing emails impersonating the IRS or a client, and W-2 scams targeting HR and payroll staff drive most tax-season fraud — not a sophisticated network intrusion.
What examiners and insurers actually check for
A policy in a drawer isn’t a program
The Rule expects an annual risk assessment and a Qualified Individual who can explain the program — not a document nobody’s reopened since it was written.
Preparer credentials are the real target
A stolen e-file PIN or software login can generate fraudulent returns under your firm’s name before anyone notices.
AI drafting tools are a new, unwritten risk
Pasting client financials into a general AI tool to draft a letter or summarize a return moves that data outside any safeguard the Rule assumes you have.
Handling the most sensitive financial data a small business touches.
Sole practitioners, small and mid-size accounting & tax firms
Firms preparing individual and business tax returns, or providing accounting and advisory services, that handle Social Security numbers, bank details, and full financial pictures for every client. You're squarely inside the FTC Safeguards Rule's definition of a covered “financial institution” — regardless of headcount.
Three ways to work together.
Same arc every time: find the gaps, train the eyes, build the program that holds.
Before the Breach
A half-day session for partners, preparers, and admin staff — what a WISP actually requires in practice, plus a one-page escalation playbook for a phishing attempt or a client-data concern.
Safeguards Rule Readiness Assessment
2–3 weeks: review your WISP (or build the gap list if you don't have one), access controls, vendor agreements, and AI tool usage against the Rule's requirements, with a prioritized roadmap.
Program Advisory
A monthly advisor serving as, or supporting, your Qualified Individual — annual risk assessment, staff training refreshers, and incident-response testing before tax season, not during it.
Confident your WISP would hold up to a real look?
A 20-minute call, no pitch. Tell us where you're exposed and what your next insurance renewal requires — we'll tell you honestly where we'd start.
Book a 20-minute call