If you prepare tax returns or keep financial records for clients, federal law treats your practice as a financial institution, and you need a written information security plan. IRS Publication 5708 is a good template; the plan only protects you if the controls it describes are real.
Who needs one
The Gramm-Leach-Bliley Act treats tax and accounting professionals as financial institutions, and the FTC’s Safeguards Rule (16 CFR Part 314) requires financial institutions to protect customer information under a written information security program. The IRS and its Security Summit partners repeated the point in news release IR-2026-92 in August 2026. Firm size doesn’t change the requirement.
What goes in it
The Safeguards Rule sets out the elements. In plain terms, the plan should:
- Name a qualified individual who is responsible for the program.
- Assess the risks to customer information, in writing.
- Put safeguards in place: access controls, an inventory of where data lives, encryption, multi-factor authentication, secure disposal, change management and monitoring of who does what.
- Test and monitor the safeguards regularly.
- Train staff and keep their knowledge current.
- Oversee service providers who touch customer data.
- Plan the response to a security event.
- Report on the program, in writing, at least once a year.
Practices that hold information on fewer than 5,000 consumers are exempt from some of these elements, including the written risk assessment, the incident response plan and the annual report, but not from having the program itself.
IRS Publication 5708, Creating a Written Information Security Plan for Your Tax & Accounting Practice, is a template written with small practices in mind. It’s a good place to start.
The FTC notification rule
From May 2024, a security event involving the information of 500 or more people has to be reported to the FTC, generally within 30 days of discovery. Your plan should say who makes that call.
Making it true
A template filled in and filed away doesn’t protect anyone. The plan only works if the controls it describes are in place and somebody keeps them there. The technical side usually means:
- Multi-factor authentication on email, tax software and remote access.
- Encrypted laptops and phones.
- Access that starts and ends on the right day, including seasonal staff.
- Backups kept apart from the network and restore-tested.
- Email authentication, so nobody can send as your firm.
- Monitoring and logging of access to client data.
Keeping it current
Review the plan every year, before the season, and whenever something material changes: new software, a new office, a new provider. Our monthly report doubles as evidence that the controls are still in place.
Sources: IRS, IR-2026-92; 16 CFR Part 314, Standards for Safeguarding Customer Information. This guide is general information, not legal advice.
Read us first when you search.
GoogleAdd OpsWorq as a preferred source

