FTC Safeguards Rule: What CPA & Financial Firms Must Have

If your firm prepares taxes, provides accounting services, brokers mortgages, or handles consumer financial data in almost any way, the FTC Safeguards Rule applies to you — and it requires nine specific, named security elements, not just "reasonable security." You need a designated qualified individual, a written risk assessment, access controls, encryption, multi-factor authentication, monitoring or penetration testing, staff training, vendor oversight, an incident response plan, and a written program tying it all together. Miss one and you're out of compliance.

That's the short version. The longer version — who's covered, what each element actually means for a 5- to 100-person firm, and how to close the gaps without hiring a security team — is below.

Who is covered by the FTC Safeguards Rule?

The rule covers "financial institutions" under FTC jurisdiction, and that term is far broader than banks. CPA firms, tax preparation businesses, mortgage brokers and lenders, investment advisors not covered by the SEC, collection agencies, and even auto dealers that arrange financing are all in scope. If your business is "significantly engaged" in providing financial products or services to consumers, assume you're covered.

The confusion is understandable. Banks answer to banking regulators, so many accountants assume financial data rules stop at the bank's front door. They don't. The Gramm-Leach-Bliley Act split the world: banks got the banking agencies, and everyone else handling consumer financial data got the FTC. The 2021 revision of the Safeguards Rule (with enforcement of the detailed requirements beginning in June 2023) replaced vague "reasonable safeguards" language with a concrete checklist — which is good news, in a way, because now you know exactly what's expected.

One size-based break exists: firms maintaining customer information on fewer than 5,000 consumers are exempt from the written risk assessment, the continuous monitoring/annual pen testing requirement, and the written incident response plan. Everything else still applies. And note that a tax practice with 600 clients can blow past 5,000 consumers faster than you'd think once you count years of returns, dependents, and prior clients whose data you still store.

What are the nine required elements?

Nine elements, each explicitly named in the rule. Designate a qualified individual to run the program. Perform a risk assessment. Implement access controls and data inventory. Encrypt customer data at rest and in transit. Require multi-factor authentication. Monitor systems continuously or run annual penetration tests. Train your staff. Oversee your service providers. Maintain a written incident response plan — all documented in a written information security program.

Here's the checklist in table form, with what each element looks like in practice for a small firm:

# Required element What it means for a small firm
1 Qualified individual One named person accountable for the security program; can be a partner supported by an outside IT provider
2 Risk assessment Written inventory of where client data lives and what could go wrong; updated periodically
3 Access controls & data inventory Staff can only reach the data their job requires; you know what data you hold and where
4 Encryption Client data encrypted at rest (laptops, servers, backups) and in transit (email, portals)
5 Multi-factor authentication MFA on email, tax/accounting software, remote access, and cloud storage — no exceptions without written justification
6 Monitoring or penetration testing Continuous monitoring of systems, or annual pen test plus vulnerability scans every six months
7 Security awareness training Regular, updated training so staff can spot phishing and handle data correctly
8 Service provider oversight Contracts and periodic review ensuring your vendors (software, IT, cloud) protect client data
9 Incident response plan A written plan covering detection, containment, notification, and recovery — plus annual reporting to leadership

Two of these deserve special attention because they're where small firms most often fail: MFA (element 5) is frequently enabled on email but forgotten on tax software, remote desktop, and file-sharing tools; and vendor oversight (element 8) is almost never documented, even at firms doing everything else right.

Doesn't the IRS already require this for tax preparers?

Largely, yes — and that's the point. The IRS requires every paid preparer with a PTIN to maintain a Written Information Security Plan, and its Publication 5708 template maps closely onto the FTC's nine elements. If you build one solid program, you satisfy both. If you downloaded a WISP template two years ago, signed it, and filed it away, you satisfy neither — regulators and breach investigators look at what you actually do, not what the binder says.

The practical approach is to treat the FTC checklist as the master list, use the IRS template as your documentation skeleton, and have someone technical verify that reality matches the paper. That last step is where an IT partner earns its keep: verifying encryption is actually on, MFA actually covers every system, and backups actually restore. Our IT compliance services are built around exactly that gap between documented policy and technical reality, and we work with CPA and financial firms across the Sacramento region on it.

Want to know exactly where your firm stands against all nine elements? Get a free IT assessment and we'll map your current setup to the checklist.

What does compliance actually cost a small firm?

Less than most firms fear, because much of it rides on tools you already pay for. Industry surveys typically put small-business security spending at roughly 5–15% of the overall IT budget, and third-party market data generally pegs managed IT with a security and compliance layer in the range of $125–$250 per user per month. Compare that with IBM's 2024 figure of $4.88 million as the average cost of a data breach — and even scaled way down to small-firm size, a single incident routinely runs into six figures.

Several elements are configuration, not purchase. Microsoft 365 Business Premium — which many firms already own — includes MFA, encryption, and conditional access; it just has to be turned on and enforced (see our cloud and Microsoft 365 services). Training platforms cost a few dollars per user per month. The bigger-ticket items are monitoring/EDR tooling and, if you opt out of continuous monitoring, annual penetration testing.

What you should not do is buy nine disconnected products. The rule asks for a program, not a shopping cart, and a program needs someone running it.

Where should a firm start if it's behind?

Start with the risk assessment, because everything else depends on it. You can't control access to data you haven't inventoried, and you can't prioritize spending without knowing your actual exposure. Then knock out the fast, high-impact items — MFA everywhere, encryption verified, offboarding process for departed staff — before tackling the program-level work of training, vendor review, and incident response planning.

A realistic 90-day sequence for a firm starting from scratch:

  • Weeks 1–2: Name your qualified individual. Inventory where client data lives — tax software, email, file server, cloud storage, old laptops, personal devices.
  • Weeks 3–6: Enforce MFA on every system touching client data. Verify disk and backup encryption. Remove access for former employees and tighten permissions to job-need.
  • Weeks 7–10: Complete the written risk assessment. Roll out security awareness training. Send security questionnaires to key vendors.
  • Weeks 11–13: Write (or rewrite) the incident response plan and the overall WISP so they describe what you now actually do. Schedule the recurring items — training refreshers, vulnerability scans, annual review.

Firms that follow a sequence like this typically reach defensible compliance in a quarter. The ones that stall are the ones that start with paperwork and never get to the technical enforcement — or start buying tools and never write anything down. You need both, which is exactly why the rule pairs a written program with named technical controls.

The Safeguards Rule isn't going away, cyber insurers increasingly ask the same nine questions on renewal applications, and your clients — who hand you their Social Security numbers and complete financial lives every spring — are the real reason the checklist exists. Treat it as a floor, not a ceiling, and it stops being a compliance burden and starts being a selling point for your practice.

Frequently asked questions

Does the FTC Safeguards Rule apply to small CPA firms?
Yes. The Safeguards Rule applies to CPA firms, tax preparers, and other financial institutions regardless of size. Firms that maintain information on fewer than 5,000 consumers are exempt from a few requirements — the written risk assessment, continuous monitoring or annual penetration testing, and the written incident response plan — but the core obligations, including a qualified individual, access controls, encryption, and multi-factor authentication, still apply to even the smallest firm.
What is a "qualified individual" under the Safeguards Rule?
The qualified individual is the single person your firm designates to oversee and implement your information security program and report on it to leadership. It does not have to be an employee or hold a specific certification — many small firms designate a partner and lean on an outside IT provider for the technical work. But accountability stays with your firm; you cannot outsource responsibility, only the hands-on tasks.
What are the penalties for violating the FTC Safeguards Rule?
The FTC can seek civil penalties of over $50,000 per violation, and in enforcement actions each day of noncompliance or each affected consumer record can count separately, so exposure adds up quickly. Beyond fines, firms face consent orders with decades of mandated audits, plus breach notification costs and client attrition. For a tax or accounting practice, the reputational damage from a publicized data breach often costs more than the penalty itself.
Do tax preparers need a Written Information Security Plan (WISP)?
Yes. The IRS requires all paid tax preparers to have a written data security plan as a condition of holding a PTIN, and IRS Publication 5708 provides a WISP template. The FTC Safeguards Rule requirements overlap heavily with the IRS mandate, so a well-built WISP can satisfy both. The plan must be written, kept current, and actually reflect what your firm does — a template nobody follows is worse than useless in an audit or breach investigation.
Is multi-factor authentication actually mandatory?
Yes. The Safeguards Rule explicitly requires multi-factor authentication for anyone accessing customer information on your systems — employees, contractors, and remote users alike. The only exception is if your qualified individual approves, in writing, a reasonably equivalent alternative control. In practice, MFA on email, tax software, remote access, and cloud file storage is the baseline examiners and cyber insurers expect, and it is one of the cheapest requirements to satisfy.
How often does the Safeguards Rule require testing and training?
The rule requires either continuous monitoring of your systems or, if you don't have that, annual penetration testing plus vulnerability assessments at least every six months. Security awareness training for staff must be provided and kept up to date, and your risk assessment and written program must be reviewed and adjusted as your business and threats change — most firms handle this on an annual cycle at minimum.

Find out what your IT should be doing for you

Get a free, no-obligation IT assessment — a plain-English report on your security, backups, and support gaps.

Get Your Free IT Assessment