Vendor Management for Tax Firms: What the FTC Safeguards Rule Actually Requires
Most tax professionals think about security in terms of their own systems — their computers, their passwords, their office. What they often miss is the vendor problem.
Your tax software provider has your client data. Your cloud storage service has your client data. Your IT support company can access your systems. Your email provider routes sensitive financial documents every day.
If any of those vendors have a breach, it's your clients' data that gets exposed — and under the FTC Safeguards Rule, it's your responsibility to show that you did your due diligence.
Here's exactly what the FTC requires when it comes to vendor management, and how to get compliant.
Why Vendor Management Is a Safeguards Rule Requirement
The FTC Safeguards Rule requires covered financial institutions — which includes tax preparers — to oversee their service providers. Specifically, the Rule requires that you:
- Select and retain service providers that maintain appropriate safeguards for customer information
- Require service providers by contract to implement and maintain appropriate safeguards
- Periodically review your service providers based on the risk they present
This isn't just a checkbox. The FTC's position is that you are responsible for the security practices of the vendors you choose to work with. Handing client data to a vendor and hoping for the best is not a compliance strategy.
Step 1: Build Your Vendor Registry
The first step is knowing who actually has access to your client data. Most tax firms are surprised by how many vendors qualify once they think through it carefully.
Go through every system and ask: does this vendor have access to client names, SSNs, financial data, or tax information?
Common vendors for tax practices include:
Tax Preparation Software ProConnect, Drake, UltraTax, Lacerte, TaxSlayer Pro, and similar platforms store and process your clients' most sensitive data. These are your highest-risk vendors.
Cloud Storage and File Sharing Dropbox, Google Drive, OneDrive, ShareFile, SmartVault — if you store client documents here, it qualifies.
Email Providers Google Workspace, Microsoft 365, and similar services route client communications. Encrypted email services like ProtonMail or Virtru also qualify.
Document Management Systems Canopy, TaxDome, FileCenter — platforms that store client documents and communications.
Payment Processing Square, Stripe, CPACharge — these handle client payment information.
IT Support and Managed Services Any IT company or contractor with remote access to your systems has access to everything on those systems. This is often the highest-risk vendor relationship because IT providers have broad access and are frequently overlooked.
Video Conferencing and Communication Zoom, Microsoft Teams, or similar tools used to share or discuss client information.
Accounting and Practice Management QuickBooks, Karbon, Practice Ignition — platforms that may store client financial data.
For each vendor, document:
- Vendor name and website
- What service they provide
- What client data they can access
- Risk level (High / Medium / Low)
- Whether a data security agreement is in place
- Date of last review
Step 2: Assess Each Vendor's Security
Once you know who your vendors are, you need to evaluate whether they're actually protecting your clients' data.
For high-risk vendors (tax software, cloud storage, IT support):
Look for evidence of strong security practices:
- SOC 2 Type II report — the gold standard for SaaS security. If a vendor has completed a SOC 2 audit, their security controls have been independently verified.
- Security page or trust center — most reputable vendors publish their security practices. Look for encryption standards, access controls, and incident response policies.
- Data Processing Agreement (DPA) — a contract that specifies how the vendor handles your client data, their security obligations, and their breach notification procedures.
If a vendor can't tell you how they protect client data, that's a red flag.
For medium-risk vendors (email, payment processing):
Review their published security documentation and ensure:
- Data is encrypted in transit and at rest
- They have a published breach notification policy
- Your agreement with them includes data security provisions
For lower-risk vendors:
Basic due diligence — confirm they have a privacy policy and some security documentation. Document your review.
Step 3: Get the Right Contracts in Place
The FTC Safeguards Rule requires that you "require service providers by contract" to maintain appropriate safeguards. In practice, this means your agreements with vendors should include:
- A commitment to protect customer information
- Security standards they agree to maintain
- Breach notification obligations (how quickly they'll notify you if there's an incident)
- What happens to your data when the relationship ends
For major vendors: Request or review their Data Processing Agreement or Business Associate Agreement. Most enterprise-grade vendors have standard DPAs available.
For smaller vendors or contractors: Include data security language in your engagement letter or service agreement. At minimum, require that they maintain appropriate security safeguards and notify you promptly of any breach.
For IT support companies: This is critical. Your IT provider has access to everything. Make sure your agreement with them explicitly addresses data security, confidentiality, and breach notification.
Step 4: Document Everything in Your WISP
Your vendor management activities need to be reflected in your Written Information Security Plan. At minimum, your WISP should include:
- A vendor management policy describing how you select, evaluate, and monitor vendors
- Your vendor registry (or a reference to where it's maintained)
- The criteria you use to assess vendor risk
- Your process for reviewing vendors annually
- Contract requirements for vendors with access to client data
Without this documentation, you have no evidence that vendor management is part of your security program — even if you're doing everything right.
Step 5: Review Your Vendors Annually
Vendor risk isn't static. Companies get acquired, change their security practices, experience breaches, or go out of business. The FTC Safeguards Rule requires periodic review of your service providers.
Build an annual vendor review into your WISP review process:
- Confirm each vendor is still being used
- Check for any security incidents or news about the vendor
- Review their current security documentation
- Confirm your agreements are still in place and current
- Add any new vendors that came on during the year
- Remove vendors you no longer use
Document the date of each review and any changes made.
The Minimum Viable Vendor Registry
If you're starting from scratch, here's what a basic vendor registry entry looks like:
| Field | Example |
|---|---|
| Vendor Name | ProConnect Tax |
| Service | Tax preparation software |
| Data Accessed | Client SSNs, income, tax returns |
| Risk Level | High |
| Security Doc | SOC 2 Type II — reviewed 1/15/2026 |
| Agreement | Intuit Data Processing Agreement signed |
| Last Reviewed | January 15, 2026 |
Five to eight vendors documented at this level is a solid foundation for most small practices.
How WISP Creator Handles Vendor Management
Building and maintaining a vendor registry manually — tracking agreements, review dates, risk levels, and documentation — is ongoing work that's easy to let slip.
WISP Creator includes a built-in Vendor Registry that guides you through documenting each vendor, assessing risk levels, tracking agreements, and generating the vendor management policy section of your WISP automatically. It flags when vendors are due for review and keeps your documentation audit-ready.
This article is for informational purposes and does not constitute legal advice. Always refer to the official FTC Safeguards Rule text for authoritative requirements.