FTC Safeguards Rule: What CPA & Financial Firms Must Have
If your firm prepares taxes, provides accounting services, brokers mortgages, or handles consumer financial data in almost any way, the FTC Safeguards Rule applies to you — and it requires nine specific, named security elements, not just "reasonable security." You need a designated qualified individual, a written risk assessment, access controls, encryption, multi-factor authentication, monitoring or penetration testing, staff training, vendor oversight, an incident response plan, and a written program tying it all together. Miss one and you're out of compliance.
That's the short version. The longer version — who's covered, what each element actually means for a 5- to 100-person firm, and how to close the gaps without hiring a security team — is below.
Who is covered by the FTC Safeguards Rule?
The rule covers "financial institutions" under FTC jurisdiction, and that term is far broader than banks. CPA firms, tax preparation businesses, mortgage brokers and lenders, investment advisors not covered by the SEC, collection agencies, and even auto dealers that arrange financing are all in scope. If your business is "significantly engaged" in providing financial products or services to consumers, assume you're covered.
The confusion is understandable. Banks answer to banking regulators, so many accountants assume financial data rules stop at the bank's front door. They don't. The Gramm-Leach-Bliley Act split the world: banks got the banking agencies, and everyone else handling consumer financial data got the FTC. The 2021 revision of the Safeguards Rule (with enforcement of the detailed requirements beginning in June 2023) replaced vague "reasonable safeguards" language with a concrete checklist — which is good news, in a way, because now you know exactly what's expected.
One size-based break exists: firms maintaining customer information on fewer than 5,000 consumers are exempt from the written risk assessment, the continuous monitoring/annual pen testing requirement, and the written incident response plan. Everything else still applies. And note that a tax practice with 600 clients can blow past 5,000 consumers faster than you'd think once you count years of returns, dependents, and prior clients whose data you still store.
What are the nine required elements?
Nine elements, each explicitly named in the rule. Designate a qualified individual to run the program. Perform a risk assessment. Implement access controls and data inventory. Encrypt customer data at rest and in transit. Require multi-factor authentication. Monitor systems continuously or run annual penetration tests. Train your staff. Oversee your service providers. Maintain a written incident response plan — all documented in a written information security program.
Here's the checklist in table form, with what each element looks like in practice for a small firm:
| # | Required element | What it means for a small firm |
|---|---|---|
| 1 | Qualified individual | One named person accountable for the security program; can be a partner supported by an outside IT provider |
| 2 | Risk assessment | Written inventory of where client data lives and what could go wrong; updated periodically |
| 3 | Access controls & data inventory | Staff can only reach the data their job requires; you know what data you hold and where |
| 4 | Encryption | Client data encrypted at rest (laptops, servers, backups) and in transit (email, portals) |
| 5 | Multi-factor authentication | MFA on email, tax/accounting software, remote access, and cloud storage — no exceptions without written justification |
| 6 | Monitoring or penetration testing | Continuous monitoring of systems, or annual pen test plus vulnerability scans every six months |
| 7 | Security awareness training | Regular, updated training so staff can spot phishing and handle data correctly |
| 8 | Service provider oversight | Contracts and periodic review ensuring your vendors (software, IT, cloud) protect client data |
| 9 | Incident response plan | A written plan covering detection, containment, notification, and recovery — plus annual reporting to leadership |
Two of these deserve special attention because they're where small firms most often fail: MFA (element 5) is frequently enabled on email but forgotten on tax software, remote desktop, and file-sharing tools; and vendor oversight (element 8) is almost never documented, even at firms doing everything else right.
Doesn't the IRS already require this for tax preparers?
Largely, yes — and that's the point. The IRS requires every paid preparer with a PTIN to maintain a Written Information Security Plan, and its Publication 5708 template maps closely onto the FTC's nine elements. If you build one solid program, you satisfy both. If you downloaded a WISP template two years ago, signed it, and filed it away, you satisfy neither — regulators and breach investigators look at what you actually do, not what the binder says.
The practical approach is to treat the FTC checklist as the master list, use the IRS template as your documentation skeleton, and have someone technical verify that reality matches the paper. That last step is where an IT partner earns its keep: verifying encryption is actually on, MFA actually covers every system, and backups actually restore. Our IT compliance services are built around exactly that gap between documented policy and technical reality, and we work with CPA and financial firms across the Sacramento region on it.
Want to know exactly where your firm stands against all nine elements? Get a free IT assessment and we'll map your current setup to the checklist.
What does compliance actually cost a small firm?
Less than most firms fear, because much of it rides on tools you already pay for. Industry surveys typically put small-business security spending at roughly 5–15% of the overall IT budget, and third-party market data generally pegs managed IT with a security and compliance layer in the range of $125–$250 per user per month. Compare that with IBM's 2024 figure of $4.88 million as the average cost of a data breach — and even scaled way down to small-firm size, a single incident routinely runs into six figures.
Several elements are configuration, not purchase. Microsoft 365 Business Premium — which many firms already own — includes MFA, encryption, and conditional access; it just has to be turned on and enforced (see our cloud and Microsoft 365 services). Training platforms cost a few dollars per user per month. The bigger-ticket items are monitoring/EDR tooling and, if you opt out of continuous monitoring, annual penetration testing.
What you should not do is buy nine disconnected products. The rule asks for a program, not a shopping cart, and a program needs someone running it.
Where should a firm start if it's behind?
Start with the risk assessment, because everything else depends on it. You can't control access to data you haven't inventoried, and you can't prioritize spending without knowing your actual exposure. Then knock out the fast, high-impact items — MFA everywhere, encryption verified, offboarding process for departed staff — before tackling the program-level work of training, vendor review, and incident response planning.
A realistic 90-day sequence for a firm starting from scratch:
- Weeks 1–2: Name your qualified individual. Inventory where client data lives — tax software, email, file server, cloud storage, old laptops, personal devices.
- Weeks 3–6: Enforce MFA on every system touching client data. Verify disk and backup encryption. Remove access for former employees and tighten permissions to job-need.
- Weeks 7–10: Complete the written risk assessment. Roll out security awareness training. Send security questionnaires to key vendors.
- Weeks 11–13: Write (or rewrite) the incident response plan and the overall WISP so they describe what you now actually do. Schedule the recurring items — training refreshers, vulnerability scans, annual review.
Firms that follow a sequence like this typically reach defensible compliance in a quarter. The ones that stall are the ones that start with paperwork and never get to the technical enforcement — or start buying tools and never write anything down. You need both, which is exactly why the rule pairs a written program with named technical controls.
The Safeguards Rule isn't going away, cyber insurers increasingly ask the same nine questions on renewal applications, and your clients — who hand you their Social Security numbers and complete financial lives every spring — are the real reason the checklist exists. Treat it as a floor, not a ceiling, and it stops being a compliance burden and starts being a selling point for your practice.