Skip to the main content.
ABT / Security / Tax Preparer WISP Requirement
FTC Safeguards Rule for Accounting and Tax Firms

If your firm prepares tax returns, it is a financial institution. The rule says so in writing.

If your firm is in the business of completing income tax returns, then not in a vendor's interpretation but in the text of 16 CFR 314.2, which names an accountant or other tax preparation service as an example of a financial institution, and in an IRS release from August 2026 that opens with the sentence federal law requires tax and accounting professionals to keep a Written Information Security Plan. Your people keep working in the Outlook, Teams, and Excel they already know. What changes is underneath them, and most of it is configuration rather than a project.

  • The load-bearing legal claims are quoted from the rule text, the FTC, or the IRS, our own readings are labelled as readings, and every source is linked at the foot of the page
  • Includes the part most WISP articles leave out: exactly which four paragraphs the under 5,000 consumer exemption lifts, and the obligations that stay behind
  • Written by a Tier 1 Microsoft Cloud Solution Provider. ABT has served financial institutions since 1999 and today manages Microsoft 365 for more than 750 of them
Featured Short

We recorded this one for mortgage lenders. Swap borrower for client and loan file for return, and the sentence does not change.

13
Examples of a financial institution listed in the rule, with tax preparation firms among them
FTC Safeguards Rule guidance, on 16 CFR 314.2(h)
9
Elements the FTC says a covered firm's security program must include, at 314.4(a) through (i), before any exception applies
FTC Safeguards Rule guidance, on 16 CFR 314.4
5,000
The consumer count below which exactly four requirements lift, and no others
16 CFR 314.6
30 days
To notify the FTC after discovering the unauthorized acquisition of unencrypted customer information on 500 or more consumers
16 CFR 314.4(j)

Is a CPA firm a financial institution under the FTC Safeguards Rule?

Yes, if the firm completes income tax returns as a business. The rule does not infer it or imply it. It uses your profession as the worked example.

The Gramm-Leach-Bliley Act asked the Federal Trade Commission to protect the data held by companies engaged in activities that are financial in nature. The FTC wrote that into 16 CFR Part 314, the Safeguards Rule, and then did something unusual: rather than leaving the definition abstract, it listed thirteen worked examples of what counts. One of them is you.

"An accountant or other tax preparation service that is in the business of completing income tax returns is a financial institution."

16 CFR 314.2(h)(2)(viii)

The FTC's own plain-language guidance is equally direct about why this catches people off guard. It warns that the Rule "defines 'financial institution' in a way that's broader than how people may use that phrase in conversation," and its list of covered examples runs well past the businesses with vaults in them: mortgage lenders, payday lenders, finance companies, mortgage brokers, account servicers, check cashers, wire transferors, collection agencies, credit counselors and other financial advisors, tax preparation firms, non-federally insured credit unions, and investment advisors that are not required to register with the Securities and Exchange Commission. The last of those thirteen is finders, which the FTC's guidance says the 2021 amendments to the rule added.

There is no size threshold on the definition. A sole practitioner who prepares returns is inside it on the same footing as a hundred-person firm. The rule scales what it asks of you, which is a different thing from exempting you, and the section further down explains precisely where that scaling starts and stops.

Two clarifications worth making early, because both cause confusion. First, the Safeguards Rule is the FTC's arm of Gramm-Leach-Bliley, and it applies to financial institutions that are not already answering to a banking regulator. A community bank is under its federal banking regulator; your firm is under the FTC. Second, this is not the same obligation as the confidentiality duty in Internal Revenue Code section 7216 that you already know about. The Safeguards Rule is about the security of the data rather than the disclosure of it, and satisfying one does not satisfy the other.

Does a tax preparer need a Written Information Security Plan?

Yes. The IRS put it in a single sentence in August 2026, and the word it used was required, not recommended.

On 18 August 2026 the IRS and its Security Summit partners published a reminder aimed squarely at the profession. The release does not hedge.

"Federal law requires tax and accounting professionals to create and maintain a Written Information Security Plan to help protect client information from identity thieves and data breaches."

IRS news release IR-2026-92, 18 August 2026

Later in the same release, in case the first sentence left room: "Tax professionals are legally required to have a written, accessible plan and should review, test, and update it regularly." The IRS also names where the obligation comes from, which closes the loop back to the section above: "The Gramm-Leach-Bliley Act requires all financial institutions to protect customer data." The IRS landing page for the profession says the same thing from the other direction, that Federal Trade Commission regulations require professional tax preparers to create and enact security plans to protect client data.

So two federal agencies are describing one obligation. The FTC owns the rule. The IRS reminds the profession that the rule is theirs, every year, because every year a meaningful number of practitioners learn it for the first time.

The requirement that the program be written is not the IRS being stylistic. It is 16 CFR 314.3(a), which requires each covered institution to "develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts." Readily accessible is doing real work in that sentence. A plan nobody can produce on request is close enough to no plan that the distinction will not help you.

The IRS also removed the most common excuse by publishing the templates itself. Publication 5708, "Creating a Written Information Security Plan for Your Tax and Accounting Practice," is a fill-in template built for smaller practices. Publication 5709 covers how to create one. Publication 4557, "Safeguarding Taxpayer Data," is the reference guide underneath both. All three are free.

Which raises the question that actually decides whether any of this works. A template gives you a document that describes controls. It does not give you the controls. Somebody still has to go into the tenant and configure the things the document promises, and then keep them configured.

The gap this page exists to name

Find out what your plan is actually promising

Our engineers read your Microsoft 365 tenant and report what is switched on, what is not, and how each finding maps to the elements the rule requires. No charge, no obligation, and you keep the report whether or not you ever work with us.

The nine elements, and where Microsoft 365 can support each one

Section 314.4 today runs from paragraph (a) to paragraph (j). The FTC's own guidance describes the first nine of those, (a) through (i), as the "nine elements that your company's information security program must include," and paragraph (j), added later, is a breach notification duty rather than a program element. That is the structure this table follows. Some of the nine are configuration you can verify from tenant data, some are organizational and no product can do them for you, and several are genuinely both. Being honest about which is which is the difference between a plan that survives a question and a plan that reads well. One caveat on the right-hand column below. These are the Microsoft 365 capabilities that support each element, not a claim that switching a feature on satisfies the law. Availability also varies by plan, so several of the capabilities named need a particular Microsoft 365 licence tier rather than coming with every subscription.

Citation What the rule requires Where it actually lives
314.4(a) Designate a Qualified Individual to implement and supervise the program. A person, not a product. The rule permits that person to work for a service provider, which is covered below.
314.4(b) Base the program on a risk assessment that identifies reasonably foreseeable internal and external risks. Partly tooling, mostly judgment. Microsoft Purview inventories where client data actually sits, which is usually the surprise. Deciding what the risks mean is yours.
314.4(c) Design and implement safeguards to control the risks identified, including access controls, encryption, and multifactor authentication. Configuration. Microsoft Entra ID Conditional Access for access control and multifactor authentication, Microsoft Purview Information Protection for encryption. This is the densest element and the most verifiable.
314.4(d) Regularly test or otherwise monitor the effectiveness of the safeguards. Configuration plus cadence. Microsoft Defender and Microsoft Intune report the state; somebody has to read the report on a schedule and act on it.
314.4(e) Implement policies and procedures so personnel can carry out the program, including security awareness training. People. Attack Simulation Training runs the phishing exercise and records who clicked. Deciding what happens next is a management question.
314.4(f) Oversee service providers: select them for their safeguards, require compliance by contract, and assess them periodically. Contracts and diligence. Your tax software vendor, your document portal, your cloud provider. Ask each for its attestation report and keep the answers.
314.4(g) Evaluate and adjust the program in light of testing results and any material change to your operations. Drift monitoring. Settings move over time, quietly. The check that matters is comparing the tenant against the configuration your plan claims.
314.4(h) Establish a written incident response plan for responding to and recovering from a security event. A document plus the logs behind it. Microsoft 365 audit logging is what turns the plan from narrative into evidence when it is needed.
314.4(i) Require the Qualified Individual to report in writing, regularly and at least annually, to your board or governing body. Reporting. For a partnership without a board, we would read the partner group as the governing body, and would confirm that with counsel. The report still has to be written.

A tenth paragraph, 314.4(j), was added later and sits outside the nine: notice to the Federal Trade Commission within 30 days of discovering a breach affecting 500 or more consumers. It is covered in its own section below.

The nine elements required by 16 CFR 314.4 listed a through i, each paired with the Microsoft 365 control that answers it, with element j on FTC notification shown at the foot
The nine elements of 16 CFR 314.4, and the Microsoft 365 capability that supports each. Capability is not the same as compliance, and some items depend on your plan.

My firm has fewer than 5,000 clients. Does the rule still apply?

The rule still applies. Four specific requirements lift, and only four. The written plan is not one of them.

This is the single most misread sentence in the Safeguards Rule, and it is misread in the direction that gets small firms in trouble. There is a real exemption. It is at 16 CFR 314.6 and it reads, in full:

"Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers."

16 CFR 314.6

Read what it actually lists. Four paragraph references, and each one is narrower than the element it sits inside.

1

The risk assessment does not have to be written down

314.6 lifts 314.4(b)(1), which is the requirement that the risk assessment be in writing and address specified criteria. It does not lift 314.4(b), the requirement to base your program on a risk assessment at all. You still have to think it through. You are excused from documenting it in the prescribed form.

2

No mandatory penetration test or vulnerability scanning schedule

314.4(d)(2) is the specific instruction to run continuous monitoring, or failing that an annual penetration test plus vulnerability assessments at least twice a year. That lifts. 314.4(d), the duty to regularly test or monitor the effectiveness of your safeguards, stays exactly where it was. What lifts is the prescribed method, not the obligation.

3

No written incident response plan

314.4(h) lifts. Note what this does not do: it does not lift 314.4(j), the duty to notify the FTC within 30 days of a qualifying breach. So a small firm is excused from writing the plan and is not excused from executing one under time pressure, which is an unusual place to want to be. Most firms that understand the trade decide to write it anyway.

4

No annual written report to the governing body

314.4(i) lifts. The Qualified Individual still has to exist under 314.4(a), and still has to implement and supervise the program. What lifts is the formal reporting ritual, which for a small partnership was often the least useful of the four anyway.

Now the part that matters more than any of the above. 16 CFR 314.6 does not mention 16 CFR 314.3. That is the section requiring a comprehensive information security program "that is written in one or more readily accessible parts." It is untouched by the exemption at every firm size. This is exactly why the IRS can tell a two-person practice that it is legally required to have a written plan without contradicting the FTC: the exemption lifts two specific written artifacts inside the program, and never the written program itself.

Everything else in the rule stays exactly where it was, including the residual duties described above to base the program on a risk assessment and to monitor whether your safeguards work. Among the obligations that apply at any firm size, these eight are the ones small practices most often assume they have been excused from: the written information security program at 314.3(a), a designated Qualified Individual at 314.4(a), multifactor authentication at 314.4(c)(5), encryption of customer information at 314.4(c)(3), access controls at 314.4(c)(1), staff security training at 314.4(e), service provider oversight at 314.4(f), and notice to the FTC within 30 days of a breach affecting 500 or more consumers at 314.4(j). Not one of those paragraphs appears in 314.6, and that list is illustrative rather than complete. A firm of six people preparing four hundred returns owes every one of them.

One more practical note on the threshold itself. It counts consumers whose information you maintain, not clients you billed this year. A firm carrying seven years of retained returns is holding information on seven years of people. Our reading is that a single return can carry information about more than one person, so the count is rarely the same as the client list, and we would want a firm to confirm the scope with its own counsel before relying on the exemption. Firms that assume they are comfortably under the threshold are sometimes counting the wrong number, and the honest move is to count before relying on it.

Two column comparison showing the four requirements lifted below 5,000 consumers under 16 CFR 314.6 against the eight requirements that still apply at every firm size
What 16 CFR 314.6 lifts, and eight important obligations that remain at any size.

The permission most firms miss, and the clock most firms have not read

Your Qualified Individual does not have to be your employee

The FTC states it plainly: the Qualified Individual "can be an employee of your company or can work for an affiliate or service provider." For a ten-person firm with no security specialist on payroll, that one sentence is the most useful thing in the entire rule. There is a condition attached and it is fair. If that person works for a service provider, the FTC requires that the provider "also must maintain an information security program that protects your business," and your firm keeps the accountability regardless. You can borrow the expertise. You cannot outsource the responsibility.

FTC Safeguards Rule guidance, on 16 CFR 314.4(a)

Thirty days, five hundred consumers, and the conditions worth reading slowly

Since 2024 the rule has carried a notification duty at 314.4(j). The FTC must be told "as soon as possible, and no later than 30 days after discovery" of a notification event, which the FTC defines as "a security breach involving the unauthorized acquisition of at least 500 consumers' unencrypted information." Read the conditions rather than the headline. A notification event requires unauthorized acquisition, of customer information, affecting at least 500 consumers, and the FTC treats information as unencrypted where the encryption key was accessed too. Discovery starts the clock, which means you need to be able to detect an event in the first place. Encryption is not a blanket exemption from reporting, and whether any particular incident is a notification event is a determination for your firm and your counsel. What encryption reliably does is reduce what an attacker walks away with, which is worth having in place before an incident rather than after.

FTC Safeguards Rule guidance, on 16 CFR 314.4(j)

The order that gets a firm from template to something true

Most practices do this backwards. They download Publication 5708, fill it in, file it, and have a document describing a firm that does not exist yet. The document is the last step, not the first.

1

Count the consumers, honestly

Before anything else, find out which side of five thousand you are on, counting every person whose information you still hold rather than this season's client list. The answer changes four of your obligations. Getting it wrong in the optimistic direction is the expensive error, so if the number is close, plan as though you are over.

2

Name the Qualified Individual out loud

One person accountable for the program, internal or from a service provider. The rule requires you to designate them. We would put that designation in writing, because a designation nobody can produce is hard to evidence later. This takes an afternoon and it unblocks everything after it, because every later decision needs an owner who can make it.

3

Find out where client data actually is

Not where policy says it is. Where it is. Returns emailed as attachments, a spreadsheet of Social Security numbers on somebody's desktop, three years of organizers in a personal cloud folder from the year the portal went down. This is the risk assessment the rule asks for, and for most firms it is also the most uncomfortable hour of the project.

4

Turn on the controls the plan will claim

Multifactor authentication on every account with no exception for partners, because attackers read org charts too. Encryption for client information in transit and at rest. Access controls that actually revoke when somebody leaves. Audit logging switched on and retained, because it is what makes the difference between knowing you had an incident and guessing.

This is the part that is genuinely configuration rather than procurement. Most of it happens inside the Microsoft 365 your firm already runs, though some controls need a particular plan or add-on, and finding out which is one of the things an assessment settles. Your staff keep working in the same applications throughout.

5

Ask your vendors for their homework

314.4(f) makes your service providers your problem. Your tax software, your document portal, your backup provider, your cloud platform. Ask each for its current attestation report, keep what comes back, and note who did not answer. That file is the evidence that the oversight element is real.

6

Now write the plan

With the previous five steps done, Publication 5708 stops being a creative writing exercise and becomes a description. Every claim in it is a thing you can point at. That is the version that holds up when a client's insurer, a prospective partner, or the aftermath of an incident asks to see it.

7

Diary the review, because settings drift

The IRS asks you to review, test, and update it regularly, and 314.4(g) requires the program to be adjusted as things change. Configurations move quietly: an exclusion added for one person during a busy week and never removed, a policy switched to report-only for troubleshooting and left there. The plan is only true on the days somebody checks.

Free security assessment

We read the tenant, and tell you what your plan can honestly claim.

ABT is a Tier 1 Microsoft Cloud Solution Provider. We manage Microsoft 365 tenants for more than 750 banks, credit unions, and mortgage companies, and we host the Azure environments behind the applications those institutions run every day. All of them live under the same statute your firm does, the Gramm-Leach-Bliley Act. The banks and credit unions among them answer to their federal banking regulators rather than to the FTC, while our non-bank mortgage clients sit under this same FTC rule, with the same nine elements and the same citations. Mapping that regulation onto Microsoft 365 configuration is work we do continuously rather than research we would have to start.

  • What is actually switched on. Multifactor authentication coverage including the accounts quietly excluded from it, encryption, access controls, audit logging and retention, and where client data has ended up across the Microsoft 365 workloads, enrolled devices, and connected applications we can see. Read from the tenant rather than from a questionnaire, with the limits of that view stated plainly: a tenant assessment cannot reach an unmanaged home computer or a personal cloud account, and those gaps get named rather than glossed.
  • Each finding mapped to the element it belongs to. Our Microsoft 365 security baseline includes 62 policies formally mapped to Gramm-Leach-Bliley Safeguards Rule requirements at 16 CFR 314.4, which is the same citation set this page has been quoting.
  • An honest split between configuration and judgment. Roughly half the rule's top-level requirements have substantial automated coverage. The rest are organizational and stay with your firm. We will tell you which is which rather than implying software closes all of it.
  • The gaps, in the order they are worth fixing. Not an undifferentiated list of everything imperfect. What would matter most on the worst day, first.
  • Yours to keep. The report is yours whether or not you ever engage us, and it is written to be readable by the partner who has to sign the plan rather than only by an engineer.

To be plain about what this is and is not. The assessment is a free technical review of your Microsoft 365 tenant against the control expectations in the Safeguards Rule. It is not legal advice, and it is not a determination of whether your firm complies with any regulation, which is a judgment for your firm and your counsel. We do not write your Written Information Security Plan, and we would be cautious of anyone selling you a plan without first looking at what your systems actually do. We can tell you accurately what your systems do, which is the input the plan needs and the part most firms are missing. Where the honest answer is that you are in reasonable shape, we will say that too. Credit unions, banks, and mortgage companies are our core practice, and the same review runs for professional firms outside financial services. If your situation calls for something we do not do, we will tell you before you spend time on it rather than after.

Where the facts on this page come from

The load-bearing legal claims above are quoted directly from the regulation, from the FTC's published guidance, or from an IRS news release, and each source is linked below so you can read the sentence in context rather than take our summary of it. Where the page moves from quoting to reading, on how the exemption paragraphs interact, on who counts toward five thousand, and on the practical order of the work, that is our interpretation and is written as such rather than presented as rule text. All were read on 25 August 2026. ABT's own claims, our Tier 1 CSP status, the institutions we serve, and the terms of the assessment, come from ABT and are marked as such.

  • 16 CFR 314.2, Definitions is the source for the accountant and tax preparation service example at paragraph (h)(2)(viii), and for the definitions of customer information and nonpublic personal information.
  • 16 CFR 314.3, Standards for safeguarding customer information is the source for the requirement that the program be "written in one or more readily accessible parts," which the small-firm exemption never touches.
  • 16 CFR 314.4, Elements is the source for the nine elements listed in the table above and for the notification duty at paragraph (j).
  • 16 CFR 314.6, Exceptions is the source for the exemption quoted in full above, and for the fact that it names exactly four paragraphs.
  • FTC Safeguards Rule: What Your Business Needs to Know is the source for the thirteen examples including tax preparation firms, the finders addition, the statement that the definition is broader than conversational use, the confirmation that Section 314.4 identifies nine elements, the Qualified Individual service provider permission, and the 30-day and 500-consumer notification thresholds.
  • IRS news release IR-2026-92, 18 August 2026 is the source for the statement that federal law requires tax and accounting professionals to create and maintain a Written Information Security Plan, for the legally required wording, for the Gramm-Leach-Bliley attribution, and for Publications 5708 and 5709.
  • IRS, Protect Your Clients; Protect Yourself is the source for the statement that Federal Trade Commission regulations require professional tax preparers to create and enact security plans, and for Publication 4557.

WISP questions, answered from the rule text

Yes, if the firm completes income tax returns as a business. The rule text at 16 CFR 314.2(h)(2)(viii) states that "an accountant or other tax preparation service that is in the business of completing income tax returns is a financial institution." The FTC's own guidance lists tax preparation firms among the thirteen examples in that section and warns that the definition is "broader than how people may use that phrase in conversation." There is no minimum size on the definition, so a sole practitioner is covered on the same basis as a large firm.

Yes. In news release IR-2026-92, published 18 August 2026, the IRS and its Security Summit partners stated that "federal law requires tax and accounting professionals to create and maintain a Written Information Security Plan to help protect client information from identity thieves and data breaches," and that "tax professionals are legally required to have a written, accessible plan." The underlying requirement is 16 CFR 314.3(a), which requires a comprehensive information security program "written in one or more readily accessible parts." The IRS publishes free templates in Publication 5708 and Publication 5709, with Publication 4557 as the reference guide.

The FTC states that "Section 314.4 of the Safeguards Rule identifies nine elements that your company's information security program must include." They are: designating a Qualified Individual, basing the program on a risk assessment, designing and implementing safeguards including access controls, encryption and multifactor authentication, regularly testing or monitoring those safeguards, training personnel, overseeing service providers, evaluating and adjusting the program, keeping a written incident response plan, and requiring the Qualified Individual to report to the governing body at least annually. A tenth paragraph, 314.4(j), adds notice to the FTC after a qualifying breach.

No. The rule still applies, and a narrow exemption lifts four specific paragraphs. 16 CFR 314.6 states that "Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers." That means the written risk assessment, the prescribed penetration testing and vulnerability assessment schedule, the written incident response plan, and the annual written report to your governing body. It does not touch 16 CFR 314.3, so the written program itself is still required, and it does not touch multifactor authentication, encryption, access controls, training, service provider oversight, or the duty to notify the FTC of a qualifying breach. The threshold also counts every consumer whose information you maintain, including prior years, rather than this season's client count.

Yes. The FTC states that the Qualified Individual "can be an employee of your company or can work for an affiliate or service provider." Two conditions come with it. The FTC requires that if the Qualified Individual works for an affiliate or service provider, "that affiliate or service provider also must maintain an information security program that protects your business," and your firm keeps accountability for the program regardless of who supervises it day to day. The FTC also notes that the Qualified Individual at a small business may have a different background from someone running a large corporation's systems, so the bar is fitness for your firm rather than a specific credential.

Under 16 CFR 314.4(j) the FTC must be notified "as soon as possible, and no later than 30 days after discovery" of a notification event, which the FTC defines as "a security breach involving the unauthorized acquisition of at least 500 consumers' unencrypted information." Reports are made through the FTC's online reporting form. Two details decide whether that clock ever starts: discovery, which depends on your firm being able to detect an event at all, and unencrypted, which is why encrypting customer information changes the exposure of an incident before one happens. State breach notification laws, client contracts, and your insurer may impose separate obligations on their own timetables, and the IRS asks tax professionals to understand security event reporting requirements as part of their overall plan. Confirm your specific obligations with counsel.

No, and be wary of anyone who says otherwise. Compliance is a property of your firm's program, not of any product. What Microsoft 365 gives you is the place several of the nine elements are actually satisfied: Microsoft Entra ID for access controls and multifactor authentication, Microsoft Purview for encryption and data classification, Microsoft Defender and Microsoft Intune for monitoring and device state, and audit logging for the evidence an incident response depends on. Those capabilities have to be configured, verified, and kept configured, and buying the licence does not switch them on. Four of the nine elements are organizational rather than technical, including naming a Qualified Individual, training staff, overseeing service providers, and reporting to your governing body, and no software closes those.

Talk to an Expert

Find out what your plan
can honestly claim.

Tell us roughly how many people are in the firm and how many consumers' information you still hold. Our engineers will read the tenant and come back with what is switched on, what is not, and which element of the rule each finding belongs to.

SOC 1 Type 2
SOC 2 Type 1
Tier-1 CSP
Zero Trust Baseline
25+
Years on Microsoft
750+
Institutions Served
$0
Assessment Cost
Get Your Free Security Assessment
Response within one business day. No obligation.
I am interested in... (optional)
First name is required
Last name is required
Valid email is required
Response within 1 business day. No obligation.
You are in.
An ABT security specialist will review your request and reach out within one business day.