Vendor Management for Tax Firms: What the FTC Safeguards Rule Actually Requires

Most tax professionals think about security in terms of their own systems — their computers, their passwords, their office. What they often miss is the vendor problem.

Your tax software provider has your client data. Your cloud storage service has your client data. Your IT support company can access your systems. Your email provider routes sensitive financial documents every day.

If any of those vendors have a breach, it's your clients' data that gets exposed — and under the FTC Safeguards Rule, it's your responsibility to show that you did your due diligence.

Here's exactly what the FTC requires when it comes to vendor management, and how to get compliant.


Why Vendor Management Is a Safeguards Rule Requirement

The FTC Safeguards Rule requires covered financial institutions — which includes tax preparers — to oversee their service providers. Specifically, the Rule requires that you:

  1. Select and retain service providers that maintain appropriate safeguards for customer information
  2. Require service providers by contract to implement and maintain appropriate safeguards
  3. Periodically review your service providers based on the risk they present

This isn't just a checkbox. The FTC's position is that you are responsible for the security practices of the vendors you choose to work with. Handing client data to a vendor and hoping for the best is not a compliance strategy.


Step 1: Build Your Vendor Registry

The first step is knowing who actually has access to your client data. Most tax firms are surprised by how many vendors qualify once they think through it carefully.

Go through every system and ask: does this vendor have access to client names, SSNs, financial data, or tax information?

Common vendors for tax practices include:

Tax Preparation Software ProConnect, Drake, UltraTax, Lacerte, TaxSlayer Pro, and similar platforms store and process your clients' most sensitive data. These are your highest-risk vendors.

Cloud Storage and File Sharing Dropbox, Google Drive, OneDrive, ShareFile, SmartVault — if you store client documents here, it qualifies.

Email Providers Google Workspace, Microsoft 365, and similar services route client communications. Encrypted email services like ProtonMail or Virtru also qualify.

Document Management Systems Canopy, TaxDome, FileCenter — platforms that store client documents and communications.

Payment Processing Square, Stripe, CPACharge — these handle client payment information.

IT Support and Managed Services Any IT company or contractor with remote access to your systems has access to everything on those systems. This is often the highest-risk vendor relationship because IT providers have broad access and are frequently overlooked.

Video Conferencing and Communication Zoom, Microsoft Teams, or similar tools used to share or discuss client information.

Accounting and Practice Management QuickBooks, Karbon, Practice Ignition — platforms that may store client financial data.

For each vendor, document:


Step 2: Assess Each Vendor's Security

Once you know who your vendors are, you need to evaluate whether they're actually protecting your clients' data.

For high-risk vendors (tax software, cloud storage, IT support):

Look for evidence of strong security practices:

If a vendor can't tell you how they protect client data, that's a red flag.

For medium-risk vendors (email, payment processing):

Review their published security documentation and ensure:

For lower-risk vendors:

Basic due diligence — confirm they have a privacy policy and some security documentation. Document your review.


Step 3: Get the Right Contracts in Place

The FTC Safeguards Rule requires that you "require service providers by contract" to maintain appropriate safeguards. In practice, this means your agreements with vendors should include:

For major vendors: Request or review their Data Processing Agreement or Business Associate Agreement. Most enterprise-grade vendors have standard DPAs available.

For smaller vendors or contractors: Include data security language in your engagement letter or service agreement. At minimum, require that they maintain appropriate security safeguards and notify you promptly of any breach.

For IT support companies: This is critical. Your IT provider has access to everything. Make sure your agreement with them explicitly addresses data security, confidentiality, and breach notification.


Step 4: Document Everything in Your WISP

Your vendor management activities need to be reflected in your Written Information Security Plan. At minimum, your WISP should include:

Without this documentation, you have no evidence that vendor management is part of your security program — even if you're doing everything right.


Step 5: Review Your Vendors Annually

Vendor risk isn't static. Companies get acquired, change their security practices, experience breaches, or go out of business. The FTC Safeguards Rule requires periodic review of your service providers.

Build an annual vendor review into your WISP review process:

Document the date of each review and any changes made.


The Minimum Viable Vendor Registry

If you're starting from scratch, here's what a basic vendor registry entry looks like:

Field Example
Vendor Name ProConnect Tax
Service Tax preparation software
Data Accessed Client SSNs, income, tax returns
Risk Level High
Security Doc SOC 2 Type II — reviewed 1/15/2026
Agreement Intuit Data Processing Agreement signed
Last Reviewed January 15, 2026

Five to eight vendors documented at this level is a solid foundation for most small practices.


How WISP Creator Handles Vendor Management

Building and maintaining a vendor registry manually — tracking agreements, review dates, risk levels, and documentation — is ongoing work that's easy to let slip.

WISP Creator includes a built-in Vendor Registry that guides you through documenting each vendor, assessing risk levels, tracking agreements, and generating the vendor management policy section of your WISP automatically. It flags when vendors are due for review and keeps your documentation audit-ready.

Start your free account →


This article is for informational purposes and does not constitute legal advice. Always refer to the official FTC Safeguards Rule text for authoritative requirements.