The IRS and the FTC both expect a written plan. Most firms do not have one.
Tax and accounting practices hold the cleanest identity data in existence: names, Social Security numbers, income, bank details, dependants. Federal expectations moved from best practice to requirement, and busy season leaves no room to build a program from scratch.
What you are carrying
- A written information security plan is expected of every tax preparer
- The FTC Safeguards Rule brings named responsibility and specific controls
- Busy season means zero tolerance for downtime between January and April
- Client data arrives by email, portal, USB stick and paper
- Preparer credentials are a direct target for refund fraud
What we do about it
- A written information security plan built to IRS Pub. 4557 and the Safeguards Rule
- Multi-factor authentication and monitoring on every preparer credential
- Secure client file exchange to replace email attachments
- Capacity and continuity planning sized for peak season, not the quiet months
- Annual risk assessment with tracked remediation, ready for review
- Retention and disposal rules applied to old returns and working papers
We prefer to start work with accounting clients in May. Nothing good gets built in February.
How it usually works
What we find in accounting and cpa firms
Two of these are federal requirements with your name on them. The others are what February does to a practice that has not planned for it.
A written information security plan is required of you by federal rule, not recommended.
IRS Publication 4557 (opens in a new tab)How it got that way
The FTC Safeguards Rule brought tax preparers in as financial institutions, and the IRS made a written plan a condition of holding a PTIN. Both landed on practices with no IT department to hand it to.
What we do
We build one that describes your actual configuration, and maintain it.
A plan that describes a configuration you do not run is worse than not having one. It documents the gap in your own words.
IRS Publication 5708 (WISP template) (opens in a new tab)How it got that way
Template plans are freely available and take an afternoon. The difficulty was never writing the document — it was keeping it true after the next change.
What we do
Ours is generated from what is actually configured, and it is revisited when that changes rather than annually.
Your busiest ten weeks are also the ten weeks when a lost day costs the most, and nothing about the technology calendar knows that.
How it got that way
Vendor maintenance windows, licence renewals and hardware end-of-life dates are set by other people, and none of them are set around filing season.
What we do
We work to your calendar rather than ours. Anything disruptive gets scheduled around your season, not around our week.
Every rule above links to the rule itself rather than to our summary of it. If something here does not apply to your firm, that is worth knowing before you budget for it.
Compared honestly
What a generalist provider brings to accounting and cpa firms
Most providers can secure an accounting practice. Fewer have read Publication 4557, and fewer still plan around February.
A generalist
Delivers a written information security plan as a document, and the document is where it ends.
CY6
Builds one to IRS Pub. 4557 and the FTC Safeguards Rule, then keeps the configuration underneath it matching — a plan that stops describing your firm has stopped being a plan.
A generalist
Schedules maintenance and projects on a standard calendar.
CY6
Works to your calendar rather than ours — we would rather start with an accounting client in May than in February, and we will say so.
A generalist
Secures the network and the endpoints.
CY6
Also treats preparer credentials as the target they are, because refund fraud goes through the preparer rather than the firewall.
Plenty of generalist providers are good at their job. The distinction here is context, not competence.
Rules in play
What you are likely to be measured against
We are not your compliance counsel, and we will say so. What we do is make sure the technical controls and the evidence behind them stand up when someone asks.
- IRS Publication 4557 (Safeguarding Taxpayer Data)
- FTC Safeguards Rule (16 CFR Part 314)
- IRS Publication 5708 (WISP template)
- State breach-notification law
Not sure where you stand?
Start with the six-point check, or book twenty minutes and talk it through with someone who will tell you plainly what needs doing and what does not.
Or call 1-855-966-2967