FTC Safeguards Rule: What Tax Professionals Need to Know

You're legally classified as a financial institution. Here's what that means for your practice.


What Is the FTC Safeguards Rule?

The FTC Safeguards Rule (16 CFR Part 314) is a federal regulation that requires "financial institutions" to develop, implement, and maintain comprehensive security programs to protect customer data.

Here's the catch: Under the Gramm-Leach-Bliley Act, tax preparers are legally classified as financial institutions — the same category as banks, credit unions, and investment firms.

This means if you prepare tax returns for compensation, you must comply with the same data protection standards as major financial institutions.


Does the FTC Safeguards Rule Apply to Me?

If you answer "yes" to any of these, the Safeguards Rule applies:

The rule applies regardless of:

There is no small business exemption. If you handle taxpayer data, you're covered.


Key Requirements of the Safeguards Rule

The 2021 amendments (effective June 2023) significantly strengthened requirements. Here's what you must do:

1. Designate a Qualified Individual

Appoint someone to oversee your information security program. For solo practices, this is you. Document this designation in writing.

2. Conduct a Written Risk Assessment

Formally evaluate:

This must be documented — not just thought about.

3. Implement Specific Safeguards

The FTC now mandates specific technical controls:

Access Controls

Multi-Factor Authentication

Encryption

Secure Development (if applicable)

Change Management

4. Regularly Test Your Safeguards

For practices with 5,000+ clients:

For smaller practices:

5. Train Your Personnel

Every employee with access to customer data must receive security training covering:

You must document this training.

6. Monitor Your Service Providers

Using tax software? Cloud storage? IT support? You're still responsible for protecting data they access.

You must:

7. Maintain Your Program

Security isn't "set and forget." You must:

8. Create an Incident Response Plan

Have a written plan for when (not if) something goes wrong:

9. Report to Your Board/Leadership

If you have partners or stakeholders, the Qualified Individual must provide at least annual reports on:


May 2024 Update: Breach Notification Requirement

As of May 13, 2024, the Safeguards Rule includes mandatory breach notification:

When to report to the FTC:

What to report:

This is in addition to any state notification laws that may apply.


Penalties for Non-Compliance

The FTC has enforcement authority with real teeth:

Civil Penalties

Enforcement Actions

Criminal Liability

Real-World Consequences

Beyond FTC penalties:


Common Compliance Mistakes

Mistake #1: "I'm too small to be a target"

Reality: Small practices are easier targets. Criminals know you likely have weaker security than large firms.

Mistake #2: "My software handles security"

Reality: Your software may be secure, but you're responsible for how you use it. Are you enforcing MFA? Training staff? Documenting access controls?

Mistake #3: "I have a WISP document, so I'm compliant"

Reality: A document alone isn't compliance. You must actually implement what's documented — and prove it.

Mistake #4: "I checked 'yes' on Form W-12, so I'm covered"

Reality: Checking "yes" without actual compliance is perjury on a federal form. It provides zero legal protection.

Mistake #5: "I'll deal with it after tax season"

Reality: Breaches don't wait for convenient timing. And regulators don't accept "I was busy" as an excuse.


How to Comply: Your Roadmap

Step 1: Acknowledge Your Status

Accept that you are legally a financial institution. This isn't optional or debatable.

Step 2: Conduct a Risk Assessment

Document:

Step 3: Implement Required Safeguards

At minimum:

Step 4: Create Your WISP

Document your security program in writing:

Step 5: Train Your Team

Step 6: Monitor and Test

Step 7: Review and Update


How WISP Creator Makes Compliance Simple

Implementing all this sounds overwhelming. That's because it is — if you're doing it manually.

WISP Creator helps you document your compliance quickly and thoroughly:

Your Written Information Security Plan — Done

Safeguards Rule Requirement How WISP Creator Helps
Written security plan ✅ Generate your customized WISP in minutes
Risk assessment ✅ Guided questionnaire documents your risks
Qualified Individual ✅ Properly designated in your WISP
Employee training ✅ Training tracking with completion records
Incident response plan ✅ Included in generated WISP
Vendor management ✅ Third-party guidelines included
Annual review ✅ Automated reminders and update workflows

What You Get

Designed for Tax Professionals

WISP Creator was built specifically for tax preparers:


Frequently Asked Questions

What's the difference between the Safeguards Rule and GLBA?

The Gramm-Leach-Bliley Act (GLBA) is the federal law that established privacy and security requirements for financial institutions. The FTC Safeguards Rule (16 CFR 314) is the regulation that implements GLBA's security requirements. Think of GLBA as the law, and the Safeguards Rule as the specific rules enforcing it.

Is there a size exemption for small practices?

No. The Safeguards Rule applies to all covered financial institutions regardless of size. Some specific requirements (like annual penetration testing) only apply to organizations serving 5,000+ customers, but the core requirements apply to everyone.

What's the "5,000 customer" threshold I've heard about?

Organizations serving fewer than 5,000 customers have slightly reduced testing requirements — they're exempt from mandatory annual penetration testing and biannual vulnerability assessments. However, they must still conduct continuous monitoring or periodic testing. All other requirements apply fully.

How does this relate to IRS requirements?

The IRS reinforces FTC Safeguards Rule compliance through:

IRS requirements align with FTC requirements. If you're compliant with the Safeguards Rule, you should meet IRS expectations.

Can I be fined even without a breach?

Yes. The FTC can take enforcement action for inadequate security practices even before a breach occurs. Non-compliance itself is a violation — you don't have to wait for something bad to happen to face consequences.

What if I use cloud-based tax software?

Using compliant software helps, but doesn't automatically make you compliant. You're responsible for:

How quickly can I create my WISP with WISP Creator?

Most users complete the questionnaire and generate their WISP in 30-45 minutes. You'll have a customized, compliant document ready the same day.


Take Action Today

Every day without proper compliance is a day of risk — legal, financial, and reputational.

WISP Creator helps you create the documentation you need to comply with the FTC Safeguards Rule. Stop wondering if your documentation is in order. Know it is.

[Create Your WISP Now] — Build your documented WISP today

[See How It Works] — Watch WISP Creator in action


Resources


WISP Creator helps tax professionals create compliant Written Information Security Plans as required by the FTC Safeguards Rule. Generate your customized WISP, track staff training, and maintain audit-ready documentation.


SEO Metadata

Title Tag (60 chars): FTC Safeguards Rule for Tax Preparers | 2025 Guide | WISP Creator

Meta Description (155 chars): Tax preparers are financial institutions under federal law. Learn FTC Safeguards Rule requirements and create your compliant WISP in minutes.

URL: https://wisp-creator.com/ftc-safeguards-rule

Target Keywords: