By Nate Olson, Fractional CIO & IT Director | N.O. IT Strategy LLC

The Risk Assessment: What It Is and What It Looks At (Part 2 of 3)

This is Part 2 of a three-part series on the FTC Safeguards Rule. I’m writing it because the rule affects a lot of firms that aren’t clear on what it actually says, and the material available on it tends to be either legal text or a sales page.

Part 1 covered who it applies to. That one’s settled. The rule states directly that an accountant or other tax preparation service in the business of completing income tax returns is a financial institution under the rule, because tax preparation is a listed financial activity. If you prepare returns for compensation, you’re covered. There’s no interpretation to do and no way around it.

There’s one piece from Part 1 worth pulling forward before we go on, because it’s where most of the confusion sits: the five thousand consumer threshold.

If your firm maintains customer information concerning fewer than five thousand consumers, four specific provisions of the rule don’t apply to you.

  1. The written risk assessment requirements in 314.4(b)(1).
  2. The prescribed continuous monitoring, or annual penetration testing paired with vulnerability assessments every six months, in 314.4(d)(2).
  3. The written incident response plan in 314.4(h).
  4. The annual written report to your board in 314.4(i). 

All four of those are real exemptions and they matter.

The exemption reaches documentation and prescribed testing. It doesn’t reach the work itself. The remaining requirements still apply, scaled to the size and complexity of your firm, the nature and scope of your activities, and the sensitivity of the information you hold. The underlying risk assessment is one of them. Being under the threshold means you don’t have to meet the written requirements in 314.4(b)(1). It doesn’t mean you don’t have to assess your risk.

Counting your consumers is less obvious than it sounds. I have a consumer count worksheet I use with clients during an FTC Safeguards Rule Readiness Review. If your firm needs to determine its consumer count, I’ll make it available upon request.

Which brings us to what this part is about. Line 11 of Form W-12 asks you to acknowledge you’re required to create and maintain a written information security plan. 

So what exactly is that plan supposed to be built on? The risk assessment. It’s the piece almost nobody talks about, and it’s the one the rule leans on hardest.

Start with what the rule actually says

16 CFR 314.4(b) says you base your information security program on a risk assessment.  There are two halves to it.

First, identify reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information. Second, assess whether the safeguards you already have in place are sufficient to control those risks.

That second half is where most internal assessments stop short. Listing threats is the easy part. Anyone can write down ransomware, phishing, a lost laptop. Judging whether what you’re running today actually holds up against them is a different exercise, and it’s the one the rule is asking for.

The more common version I run into is a firm that assumes their IT provider has this handled. Someone manages the computers, the backups run, there’s antivirus on everything, so the assessment must be covered.

That’s a reasonable assumption, however it often isn’t true. Most IT providers are contracted to keep systems running, not to assess a firm against 16 CFR 314. Those are different jobs producing different deliverables. And even where a provider does the work, the rule is direct about where responsibility sits: if your Qualified Individual is an employee of a service provider or affiliate, you retain responsibility for compliance, you have to designate a senior member of your own staff to direct and oversee that person, and you have to require the provider to maintain a program that protects you. The obligation doesn’t transfer with the work.

What has to get looked at

Here’s the 10,000 foot view. Five questions, and every one of them traces back to the risks and safeguards the rule requires you to examine.

What client data do you actually hold?

Not what you think you hold. What’s actually there. Returns going back years, prior-year files you kept for convenience, scanned IDs, bank details from direct deposit setups, documents clients emailed you that never got moved anywhere. The rule requires you to identify and manage your data, and it generally requires secure disposal no later than two years after last use, subject to limited exceptions for legitimate business needs, legal retention requirements and situations where targeted disposal isn’t reasonably feasible. You can’t dispose of what you never inventoried, and you can’t protect a file you forgot exists.

Where does it live?

Your tax software. Your document management system. Local drives. A cloud storage account somebody set up years ago. Email. A laptop that goes home. A phone with the mail app on it. A USB drive in a desk. Each location is a place the data can leave from, and each one has its own controls or lack of them.

Who can reach it?

Staff, seasonal preparers, a spouse who helps during filing season, a former employee whose account was never disabled. The rule requires access controls limiting people to what their role requires, periodically reviewed. Most firms have never done that review, and the answer surprises them.

What’s protecting it right now?

Encryption at rest and in transit. Multi-factor authentication. Logging of who did what. Backups you’ve actually restored from rather than assumed were running. This is the sufficiency half of 314.4(b), and it takes real examination. A control that exists isn’t the same as a control that works, and a control that works isn’t the same as one you can demonstrate.

Who else can get to your client data?

Your tax software vendor. Your cloud host. Your IT provider. The e-signature platform. The portal your clients upload through. The rule requires you to select service providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess them. A breach at one of those providers can become your notification obligation if it involves your customer information and meets the rule’s threshold. Their weak controls are your exposure.

Those five questions aren’t the assessment. They’re the shape of it. The work is in the answers, and the answers are specific to your firm.

Why this is harder than it looks

You could do this yourself. The rule permits it, and plenty of firms do.

An individual can file their own taxes, too. It’s allowed and plenty of people do it. What they’re missing isn’t intelligence or diligence. It’s the professional judgment that comes from doing the work every day: knowing what to look for, what an answer implies, and which detail matters in a way it wouldn’t appear to.

The same is true in reverse. A CPA, a bookkeeper or a preparer isn’t going to read a security environment the way someone who works in it does. That takes nothing away from what you do. Cybersecurity controls carry different requirements than financial controls, and neither profession is expected to cover the other.

There’s a wrinkle that catches people. Both professions work in controls, so the vocabulary is familiar. You already understand segregation of duties, access restrictions, review cycles, documented evidence. Every one of those concepts exists in security work. What doesn’t carry over is what the controls defend against, how they fail, and what counts as proof that one is working. The familiarity makes a security question feel answered when the standard for an answer is different.

This is also why the rule allows the Qualified Individual to be a member of your staff, an affiliate or a service provider. The regulation assumes this expertise has to exist somewhere and doesn’t much care where you get it. If you have it in-house, use it. If you don’t, that’s a gap worth naming rather than working around.

What you end up holding

Done properly, a risk assessment gives you a clear picture of what you have, what’s protecting it, where it’s thin, and which of those gaps matter enough to address first.

Some of what you find you’ll fix. Some you’ll decide to live with. The rule contemplates both. 314.4(b)(1) requires the written assessment to record how each risk gets mitigated or accepted, which means accepting a risk is a legitimate outcome. It just has to be a decision someone made, rather than a gap nobody looked at.

One more thing about writing it down. Even if you’re under the threshold and the written version isn’t required of you, it’s the thing that tells you where you stand and what to work on next. A determination you made and didn’t record is one you get to make again next year from scratch.

That’s why I deliver a written risk assessment in every FTC Safeguards Rule Readiness Review, whether the firm is above or below the consumer count. A firm that doesn’t understand its own risk is working from someone else’s assumptions about it.

So now you have findings. What you hold, where it sits, who touches it, what’s protecting it, and what isn’t. That’s the raw material, and it isn’t a WISP yet.

Part 3 covers how the two connect. What actually belongs in the written plan, what the IRS sample template gives you and where it falls short, and why a WISP that doesn’t match what your firm is running is a worse position than not having one.

If you’d rather have someone else do the looking, that’s what our FTC Safeguards Rule Readiness Review service is about. 

Sources

• 16 CFR Part 314, Standards for Safeguarding Customer Information. Electronic Code of Federal Regulations. https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314
• 16 CFR 314.2, Definitions. https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314/section-314.2
• 16 CFR 314.4, Elements. https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314/section-314.4
• 16 CFR 314.6, Exceptions. https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314/section-314.6
• Instructions for Form W-12, IRS Paid Preparer Tax Identification Number (PTIN) Application and Renewal, Rev. October 2025. https://www.irs.gov/pub/irs-pdf/iw12.pdf