FTC Safeguards Rule Audit Checklist for Tax Professionals: Are You Actually Ready?
The FTC Safeguards Rule doesn't give you advance notice before an examination. When a data breach occurs — or when the FTC decides to audit your compliance — you either have your documentation or you don't.
This checklist covers every major requirement of the FTC Safeguards Rule so you can assess exactly where you stand right now, before it matters.
How to Use This Checklist
Go through each section and mark items as Complete, In Progress, or Not Started. Any "Not Started" item is a compliance gap. The goal isn't a perfect score today — it's knowing what you need to fix and in what order.
Section 1: Written Information Security Plan (WISP)
The WISP is the foundation of your compliance. Everything else documented below should be reflected in it.
- You have a written WISP that covers your specific practice
- Your WISP is customized to your firm (not a generic template copied word-for-word)
- Your WISP has been formally adopted — signed by the firm owner or partner
- Your WISP is dated and shows the most recent review date
- Your WISP has been reviewed or updated within the last 12 months
- Your WISP covers all 7 required policy areas (see Section 3 below)
Why it matters: The FTC Safeguards Rule requires a written, comprehensive information security program. A WISP that hasn't been updated since 2022 or was copied from a generic template is not a compliant WISP.
Section 2: Qualified Individual / Designated Security Coordinator
- You have named a specific individual responsible for your information security program
- Their name and responsibilities are documented in your WISP
- For firms: this person has the authority to make and enforce security decisions
- For solo practitioners: you have documented that you serve as your own security coordinator
Why it matters: The FTC requires a designated "Qualified Individual" to oversee your security program. This can be you, an employee, or a qualified third-party service provider — but someone must be named and accountable.
Section 3: Written Security Policies (All 7 Required Areas)
Your WISP must contain written policies for each of the following:
Password and Authentication Policy
- Minimum password length and complexity requirements are documented
- Multi-factor authentication (MFA) is required for all systems accessing client data
- If MFA is not in use for any system, a written exception approved by your Qualified Individual exists
Data Protection Policy
- Client data is encrypted at rest (on hard drives, servers, cloud storage)
- Client data is encrypted in transit (secure email, HTTPS, SFTP)
- Backup procedures are documented
- Secure disposal of client data (paper shredding, digital wiping) is documented
Access Control Policy
- Only authorized individuals can access client data
- Access is granted on a need-to-know basis (least privilege)
- Procedures exist for granting access to new employees
- Procedures exist for revoking access when employees leave
Physical Security Policy
- Computers and servers are physically secured
- Filing cabinets with client data are locked
- Visitor access to work areas is controlled
- Clean desk policies are documented
Remote Access and Mobile Device Policy
- VPN or equivalent security is required for remote access to firm systems
- Mobile devices used for work are covered by your security policy
- Lost or stolen device procedures are documented
Vendor and Service Provider Policy
- You have a written list of all vendors with access to client data
- Each vendor's access level and data type is documented
- You have verified that key vendors maintain adequate security (written agreements or SOC 2 reports)
Incident Response Policy
- You have a written step-by-step incident response plan
- The plan identifies who to notify internally when an incident occurs
- The plan includes IRS Stakeholder Liaison contact information
- The plan covers notification to affected clients
- The plan addresses FTC reporting (required within 30 days if 500+ individuals affected)
- The plan covers state tax authority notification
Section 4: Risk Assessment
- You have completed a formal written risk assessment
- The assessment identifies where client data is stored (systems, locations, cloud services)
- The assessment identifies who has access to client data
- The assessment identifies potential threats (hacking, phishing, theft, natural disaster)
- The assessment evaluates your current safeguards against each threat
- Gaps identified in the risk assessment have been documented with remediation plans
- Your risk assessment has been updated within the last 12 months
Why it matters: The risk assessment is often the first document an FTC examiner requests. It demonstrates that you've systematically evaluated your security posture — not just written policies without understanding your actual risks.
Section 5: Employee Training
- All employees with access to client data have received security awareness training
- Training covered phishing, social engineering, and password hygiene
- Training covered your firm's specific security policies
- Training covered what to do when a security incident is suspected
- New employees received training before accessing client data
- Training is conducted at least annually
- Training completion is documented with dates and employee signatures
Why it matters: Untrained employees are the #1 cause of data breaches. The FTC expects documented evidence that your staff knows your security policies and procedures — not just that the policies exist.
Section 6: Vendor Management
- You have a current list of all third-party vendors that access, store, or transmit client data
- Common vendors to check: tax software, cloud storage, email, payment processing, IT support, document management
- Each vendor's role and data access is documented
- You have reviewed each vendor's security practices (website security page, SOC 2, written agreement)
- Your contracts or agreements with key vendors include data security obligations
- Your vendor list is reviewed and updated at least annually
Section 7: Annual Review Documentation
- You have a documented process for annual WISP review
- Each completed review is recorded with the date, reviewer, and changes made
- Your WISP has been updated to reflect any changes to your practice in the past year
- New software, employees, or office changes have triggered a WISP update
- Your annual review is scheduled (not just "whenever I get to it")
Section 8: Incident History
- You have a system for logging security incidents (even minor ones)
- Past incidents are documented with dates, descriptions, and resolution steps
- Near-misses (phishing emails, suspicious login attempts) are logged
- Your incident log demonstrates ongoing security awareness
Scoring Your Results
Count up your gaps and prioritize:
0-5 gaps: You're in strong shape. Focus on keeping documentation current.
6-15 gaps: Moderate risk. Prioritize Section 1 (WISP), Section 4 (Risk Assessment), and Section 5 (Training) first — these are the most commonly examined.
16+ gaps: High risk. Start with getting a WISP in place immediately, then work through each section systematically.
The Fastest Path to Closing Your Gaps
Working through this checklist manually — writing policies, conducting a risk assessment, building a vendor registry — takes most tax professionals 20-40 hours spread across days or weeks. The documentation has to be specific to your practice, not generic language that won't survive scrutiny.
WISP Creator is built specifically to close these gaps fast. Answer questions about your practice, and the AI generates customized policies for every section in this checklist — risk assessment, vendor registry, incident response plan, and the complete WISP document. The whole process takes about 20 minutes.
Start your free WISP Creator account →
This checklist is for informational purposes and does not constitute legal advice. Requirements may vary based on your specific circumstances. Always consult the official FTC Safeguards Rule and IRS publications for authoritative guidance.