What Is the IRS Data Security Rule?

If you prepare taxes or provide accounting services professionally, you are legally required to protect your clients' financial data. The requirement comes from two places: the Gramm-Leach-Bliley Act (GLBA), and the FTC's Safeguards Rule, which implements GLBA for financial service providers.

The IRS reinforces this through IRS Publication 4557, a document specifically aimed at tax professionals. Publication 4557 walks through what the IRS expects from practitioners and strongly recommends that every tax preparer maintain a Written Information Security Plan, commonly called a WISP.

These requirements apply to sole-practitioner CPAs, small bookkeeping firms, enrolled agents, and tax preparation offices. There is no "too small to comply" threshold.

What Is a WISP?

A Written Information Security Plan is a document that describes how your firm protects client data. It should identify who is responsible for data security, what risks your firm faces, what controls you have in place to address those risks, how you handle vendors who access client data, and what you would do if a breach occurred.

The IRS Data Security Summit, a coalition of the IRS, state tax agencies, and the tax software industry, publishes a WISP template that small firms can use as a starting point. You can find it through the IRS website.

The critical thing to understand: the WISP is a description of your security program. It only matters if the controls it describes are actually in place. A WISP that says "we use multi-factor authentication" but MFA was never turned on is worse than no WISP at all. It creates a false record.

What Technical Controls the Rule Actually Requires

The FTC Safeguards Rule (significantly updated in 2023) lists specific technical requirements. These are not suggestions. For firms covered by the rule, here is what the technical side of compliance looks like:

  • Multi-factor authentication on every system that accesses client data. This means your tax software, your Microsoft 365 or Google Workspace account, your cloud storage, your client portal, and your practice management system. MFA needs to be actively configured and enforced, not just available as an option.
  • Encryption of client data at rest and in transit. Laptops and workstations that hold client files should have full-disk encryption enabled. Data sent by email or shared via a portal should be encrypted in transit.
  • Access controls so that only the people who need access to client data can reach it. Each employee should have their own unique account with appropriate permissions. Shared passwords and shared logins are a compliance problem and a security problem.
  • Verified, tested backups stored separately from your primary systems. The rule requires a data recovery plan, and a backup that has never been tested is not a recovery plan.
  • Patch management keeping your operating systems and software updated. The Safeguards Rule specifically calls out the need to monitor for security vulnerabilities and address them promptly.
  • Vendor oversight documentation for any service provider that receives, maintains, processes, or transmits client information on your behalf. This includes cloud storage providers, payroll processors, and any software that syncs client data to a third-party server.
  • A designated information security coordinator: someone in your firm who is responsible for the security program. In a small firm, this is usually the owner.
  • An incident response plan describing what your firm does if client data is accessed without authorization. The IRS also requires tax professionals to report data thefts to the IRS within 24 hours of discovery.

The Gap Most Small Firms Have

The most common problem I see with accounting firms in North Idaho is not that they are unaware of these requirements. Most CPAs and tax preparers have heard of the WISP and many have one on file. The problem is the gap between the document and the reality.

Someone downloads a WISP template, fills in the firm name, and files it. The template says MFA is required, but nobody ever turned it on in Microsoft 365. The template says laptops are encrypted, but BitLocker was never enabled. The template says backups are tested regularly, but the last restore test was never scheduled.

If a breach occurs and an investigator finds that your WISP described controls that were not actually implemented, you are in a significantly worse position than a firm that had no WISP at all.

What to Do About It

The honest answer is that getting your technical controls actually in place is not especially complicated. It requires someone who knows what they are doing to go through your systems methodically and configure the things your WISP describes.

For most small accounting firms, the realistic list looks like this: turn on MFA everywhere, enable full-disk encryption on every device, set up encrypted automated backups and test them, create individual user accounts for every employee and remove old ones, deploy endpoint protection software, establish a patch management process, and document what you have done so you can show it.

Important: This article is written by an IT technician, not an attorney or compliance auditor. The information here is meant to help you understand the technical side of these requirements. For guidance on your specific compliance obligations, consult a qualified attorney or CPA compliance professional. For the technical implementation, that is where I can help.

Next Steps

If you run an accounting or tax preparation firm in North Idaho and are not sure whether your technical controls are actually in place, the best first step is a straightforward conversation. I offer a free 30-minute consultation where we can talk through your current setup and what it would take to close any gaps.

I am not a compliance auditor. I am the local IT technician who sets up and maintains the controls your compliance program requires. If you already have a WISP, I can help you make it real. If you do not, I can help you understand what the technical side needs to look like.

IT support for accounting firms