By Nate Olson, Fractional CIO & IT Director | N.O. IT Strategy LLC

 
I work with CPA firms, tax preparers and bookkeeping practices on data security compliance, and I keep running into the same confusion around the FTC Safeguards Rule. It isn’t coming from firms that are careless about protecting client data. It’s coming from firms that have been trying to get this right.
 

So before anything else, I want to explain, what is this rule and why does it exist?

The Safeguards Rule comes out of the Gramm-Leach-Bliley Act, and its purpose is straightforward. Businesses that handle people’s financial information have to actually protect it. In your case that means taxpayer data. Names, Social Security numbers, income, dependents, bank account details, everything a client hands you without thinking twice about it.

The rule’s own stated objectives are to keep that information secure and confidential, to protect it against anticipated threats, and to protect against unauthorized access that could cause substantial harm or inconvenience to your client. That’s the whole intent. It isn’t a filing requirement and it isn’t a form you send in. It’s a requirement that your firm have real security practices in place and be able to show what they are. The “rule”  in summary, is meant to ensure you protect your client data, following the “best practices” in the cyber security world, that’s it.

Everything else in this rule is detail underneath that idea.

So with that in mind, back to the confusion I mentioned.

I see it from firms that aren’t certain the rule reaches them at all. I see it from firms that know they have requirements, bought a WISP template a few years back, filled it in and have been under the assumption that document and one time action, made them compliant. I also see it from smaller firms that read the five thousand consumer line and came away believing they’re exempt from the whole thing.

None of those reads are unreasonable. The rule is written for lawyers, the IRS talks about it in different language than the FTC does. Some of what’s published on the subject is selling a document rather than explaining the obligation sitting underneath it. A few of the pages selling WISP templates describe Line 11 of Form W-12 as requiring you to confirm you have a documented plan in place, which isn’t what that line says. So part of the confusion firms are carrying was sold to them by the people offering the fix.

So I’m splitting this into three parts. This one, Part 1, answers whether the rule applies to you and what it asks of you if it does. Part 2 covers the risk assessment, which is the exercise of looking at how your firm actually handles client data and judging whether what you have in place is good enough. Part 3 covers the WISP, the written plan that documents what you found and what you do about it.

So let’s start with whether you’re covered.

Does this apply to you?

Fair warning before you keep going. The next stretch is regulatory text, and it reads like it. Dry, defined terms, lists inside lists. Stay with me, because there’s a point on the other side of it.

The rule lives at 16 CFR Part 314, and it applies to financial institutions under FTC jurisdiction. That phrase is doing more work than it appears to, because the rule’s definition of a financial institution is far wider than banks.

The rule itself names these professions as examples, however, it also says the list isn’t exhaustive:

• Tax preparation firms
• Mortgage lenders and mortgage brokers
• Payday lenders and finance companies
• Account servicers
• Check cashers and wire transferors
• Collection agencies
• Credit counselors and other financial advisors
• Investment advisors not required to register with the SEC
• Non-federally insured credit unions
• Travel agencies operated in connection with financial services
• Entities acting as finders

Elsewhere, the rule works through the examples with reasoning attached, and adds real estate and personal property appraisers, real estate settlement services, businesses that regularly wire money, check printers, and auto dealerships that lease on a nonoperating basis for longer than 90 days.

If you prepare returns, the rule addresses you directly. It states that an accountant or other tax preparation service in the business of completing income tax returns is a financial institution, because tax preparation is a listed financial activity. There’s no interpretation to do there.

If you don’t prepare returns, the question is harder, and I’m not going to answer it for you. The rule’s test is whether a business is significantly engaged in financial activity, and businesses that aren’t significantly engaged are excluded. Whether your practice clears that line depends on facts specific to your practice, and it’s a determination worth making deliberately rather than by assumption. If you’ve never made it, that’s the first thing to fix.

So what does that mean?

The rule reaches you. What does it actually ask of you?

The Safeguards Rule requires a comprehensive information security program, written in one or more readily accessible parts, and it names the elements that program has to contain. Here they are, in the order the rule lists them. After each one I’ve marked whether it applies to every covered firm or only to firms maintaining customer information concerning five thousand consumers or more.

  • Name a Qualified Individual. One person is responsible for overseeing, implementing and enforcing your program. It can be someone on your staff or a service provider, but you keep responsibility for compliance either way. (All firms)
  • Base your program on a risk assessment that identifies the risks your firm faces and judges whether what you already have in place is sufficient to control them. (All firms)
  • Put that risk assessment in writing, including criteria for evaluating risks, criteria for assessing your systems and existing controls, and a record of how each risk will be mitigated or accepted. (5,000 or more)
  • Perform additional risk assessments periodically. The rule assumes you’ll do this more than once. (All firms)
  • Design and implement safeguards to control what you found. The rule names specific ones: access controls, an inventory of your data, people, devices and systems, encryption in transit and at rest, secure development and evaluation of the applications you use, multi-factor authentication, secure disposal and retention review, change management, and logging of authorized user activity. (All firms)
  • Regularly test or monitor whether those safeguards are actually working. (All firms)
  • Run continuous monitoring, or else annual penetration testing plus vulnerability assessments every six months. (5,000 or more)
  • Train your staff on security awareness, and make sure whoever handles your security stays current. (All firms)
  • Oversee your service providers. Select them with care, require safeguards in the contract, and reassess them periodically. (All firms)
  • Evaluate and adjust the program when your testing, a material change in your business, or a new risk assessment tells you something has moved. (All firms)
  • Keep a written incident response plan covering seven specific areas. (5,000 or more)
  • Have your Qualified Individual report in writing at least annually to your board, or to a senior officer if you don’t have a board. (5,000 or more)
  • Notify the FTC within 30 days of a breach involving at least 500 consumers. Effective May 13, 2024. (All firms)

Nine of thirteen apply no matter how small you are. Of the four that come off, three are written artifacts and one is a testing regime. So what the exception removes below five thousand consumers is documentation and testing, not the underlying work.

Where this goes next

Every renewal season, Line 11 of Form W-12 asks you to check a box acknowledging you’re aware that paid tax return preparers are required by law to create and maintain a written information security plan to protect taxpayer information.

Maintain is doing real work in that sentence. But nothing on the form asks whether anything has changed since the last time you checked it. You can renew year after year without ever being asked whether the plan still describes the practice.

So what is that plan supposed to be built on?

That’s the risk assessment, and it’s where Part 2 picks up.

Sources