← All Resources

CPA & Accounting

The FTC Safeguards Rule for CPA Firms: What It Means in Practice

For a covered accounting or tax practice, the FTC Safeguards Rule is not a single technology checklist. It calls for a written, risk-based information-security program that combines leadership, documentation, technical safeguards and ongoing verification.

Short answer

In practice, a covered CPA firm needs to designate program leadership, assess risk in writing, implement safeguards tied to that risk, train staff, oversee service providers, test and monitor controls, maintain an incident-response plan and report program status to management.

Why accounting firms should pay attention

The FTC’s definition of a financial institution is broader than the everyday use of that phrase and includes tax-preparation firms among its examples. Coverage depends on the activities an organization performs and the customer information it handles, so firms should confirm applicability in light of their own services rather than relying on a label such as “small CPA practice.”

The Rule requires covered financial institutions to develop, implement and maintain an information-security program with administrative, technical and physical safeguards. The program must be written and appropriate to the firm’s size and complexity, the nature and scope of its work and the sensitivity of the customer information involved.

The program begins with ownership and risk

A Qualified Individual (QI) implements and supervises the program. That person does not need a prescribed title or degree, but does need knowledge appropriate to the environment. In GO InfoTek’s service model, the client firm designates and retains its own QI; GO InfoTek supports that person with technical assessments, safeguards, monitoring, testing, documentation and recommendations.

The written risk assessment is the next foundation. It should identify customer information and the systems involved, consider foreseeable internal and external threats, evaluate the adequacy of existing safeguards and establish criteria for assessing risk. Periodic reassessment matters because staff, applications, vendors, locations and attack methods change.

Safeguards are broader than a security product

The Rule addresses access controls, data and system inventories, encryption, application security, multi-factor authentication, secure disposal, change management and monitoring for unauthorized access. Those controls have to be designed around the risks the firm identifies rather than installed as an unrelated bundle.

For example, “we have MFA” is incomplete. The firm needs to know which systems contain or connect to customer information, which users can reach them, whether legacy or service accounts bypass MFA and how exceptions are approved. Similar questions apply to encryption, endpoint protection, remote access and logging.

Monitoring, testing and remediation are ongoing work

A program cannot be evaluated only when the WISP is first written. The FTC calls for regular monitoring and testing of safeguards, with the specific testing path depending on how the firm monitors its systems and which provisions apply. Material operational changes or new circumstances may also require additional testing.

The practical management cycle is straightforward: identify a weakness, assign an owner, set a realistic priority, correct it, verify the correction and retain the result. A vulnerability report that nobody reviews is not risk management. Neither is a recurring alert that is silently ignored because ownership was never assigned.

People, providers and incident readiness are part of the Rule

Security-awareness training should prepare staff to recognize risks and follow firm procedures. People with hands-on program responsibilities need training appropriate to their roles. The firm should retain records showing who completed training and how important changes were communicated.

Service providers with access to customer information also require due diligence, contractual security expectations and periodic reassessment. An MSP, payroll platform, document portal or cloud provider can operate controls for the firm, but outsourcing the activity does not eliminate the firm’s oversight responsibility.

A written incident-response plan should establish goals, internal processes, roles, authority, communications, remediation, documentation and lessons learned. It should be usable during an event—not a policy that assumes the affected email system, server or office will still be available.

Florida firms may also have state breach-notification obligations under the Florida Information Protection Act (FIPA), Fla. Stat. §501.171, when an incident involves covered personal information. FIPA does not replace the firm’s federal requirements, and applicability and notification decisions should be reviewed separately with qualified counsel.

Do not overread the small-business exceptions

The FTC explains that financial institutions maintaining customer information concerning fewer than 5,000 consumers are exempt from certain provisions of the Rule. That is a limited exemption, not a statement that the entire Rule disappears for every small firm. Employee count, revenue or office size is not a substitute for reviewing the actual coverage and exceptions.

Firms should use qualified legal or compliance advice for applicability questions. From an operational perspective, the core disciplines—knowing the data, assigning responsibility, assessing risk, applying safeguards, training people and overseeing providers—remain sound security practices even when a particular provision is not applicable.

What this means for your firm

Treat the Safeguards Rule as a management system. Put the written program, technical configuration and evidence in the same review. If the risk assessment identifies remote access as important, the WISP should state the requirement, the technology should enforce it, monitoring should confirm it and management should be able to see the result.

The best starting point is a current-state assessment, not a promise of instant compliance. Document what exists, identify the highest-risk gaps, decide who owns each improvement and establish a repeatable review rhythm.

Related support

GO InfoTek supports CPA firms with WISP development, cybersecurity risk management, ongoing control verification and technical execution for the firm’s Qualified Individual. The firm retains governance, decision and approval authority. Legal applicability and interpretation remain matters for the firm and its counsel.

CPA & accounting firm servicesCybersecurity & risk managementvCISO services

This article provides general information to support technology, cybersecurity and compliance discussions. It is not legal advice and does not replace review of your organization’s specific obligations with qualified legal or compliance professionals.

Sources and Further Reading

A practical next step

Discuss Your Environment with GO InfoTek

Start with the systems, safeguards, documentation and questions your organization has today.

Schedule a Conversation