FTC Safeguards Rule Audit Checklist for Tax Professionals: Are You Actually Ready?

The FTC Safeguards Rule doesn't give you advance notice before an examination. When a data breach occurs — or when the FTC decides to audit your compliance — you either have your documentation or you don't.

This checklist covers every major requirement of the FTC Safeguards Rule so you can assess exactly where you stand right now, before it matters.


How to Use This Checklist

Go through each section and mark items as Complete, In Progress, or Not Started. Any "Not Started" item is a compliance gap. The goal isn't a perfect score today — it's knowing what you need to fix and in what order.


Section 1: Written Information Security Plan (WISP)

The WISP is the foundation of your compliance. Everything else documented below should be reflected in it.

Why it matters: The FTC Safeguards Rule requires a written, comprehensive information security program. A WISP that hasn't been updated since 2022 or was copied from a generic template is not a compliant WISP.


Section 2: Qualified Individual / Designated Security Coordinator

Why it matters: The FTC requires a designated "Qualified Individual" to oversee your security program. This can be you, an employee, or a qualified third-party service provider — but someone must be named and accountable.


Section 3: Written Security Policies (All 7 Required Areas)

Your WISP must contain written policies for each of the following:

Password and Authentication Policy

Data Protection Policy

Access Control Policy

Physical Security Policy

Remote Access and Mobile Device Policy

Vendor and Service Provider Policy

Incident Response Policy


Section 4: Risk Assessment

Why it matters: The risk assessment is often the first document an FTC examiner requests. It demonstrates that you've systematically evaluated your security posture — not just written policies without understanding your actual risks.


Section 5: Employee Training

Why it matters: Untrained employees are the #1 cause of data breaches. The FTC expects documented evidence that your staff knows your security policies and procedures — not just that the policies exist.


Section 6: Vendor Management


Section 7: Annual Review Documentation


Section 8: Incident History


Scoring Your Results

Count up your gaps and prioritize:

0-5 gaps: You're in strong shape. Focus on keeping documentation current.

6-15 gaps: Moderate risk. Prioritize Section 1 (WISP), Section 4 (Risk Assessment), and Section 5 (Training) first — these are the most commonly examined.

16+ gaps: High risk. Start with getting a WISP in place immediately, then work through each section systematically.


The Fastest Path to Closing Your Gaps

Working through this checklist manually — writing policies, conducting a risk assessment, building a vendor registry — takes most tax professionals 20-40 hours spread across days or weeks. The documentation has to be specific to your practice, not generic language that won't survive scrutiny.

WISP Creator is built specifically to close these gaps fast. Answer questions about your practice, and the AI generates customized policies for every section in this checklist — risk assessment, vendor registry, incident response plan, and the complete WISP document. The whole process takes about 20 minutes.

Start your free WISP Creator account →


This checklist is for informational purposes and does not constitute legal advice. Requirements may vary based on your specific circumstances. Always consult the official FTC Safeguards Rule and IRS publications for authoritative guidance.