First, a clarification that matters, because the terminology causes genuine confusion.
This is commonly called the "IRS Safeguards Rule." It is properly the FTC Safeguards Rule, issued under the Gramm-Leach-Bliley Act and codified at 16 CFR Part 314. The IRS enters the picture because it requires tax professionals to comply, and reinforces that through Publication 4557 and through the acknowledgement on PTIN renewal.
The practical upshot is the same: if you prepare tax returns, you need a written information security plan. But the rule reaches considerably further than tax preparers, and that is where most businesses are caught out.
Who this actually applies to
The rule covers non-bank "financial institutions," and the FTC defines that term far more broadly than ordinary usage suggests. It includes businesses that most people would never describe as financial:
- Tax preparers and CPA firms performing tax work
- Mortgage brokers and lenders
- Automobile dealerships that arrange financing or leasing
- Investment advisors not registered with the SEC
- Collection agencies
- Career counsellors serving people seeking employment in financial services
- Businesses that provide financing or credit to their own customers
- Real estate appraisers and settlement services
That auto dealership entry surprises people every time. If a dealership arranges financing, it is a financial institution for the purposes of this rule, with the same obligations as a mortgage broker.
If your business handles non-public personal information about consumers in connection with a financial service, assume you are covered until you have confirmed otherwise.
The small-business exemption, precisely
Businesses maintaining information on fewer than 5,000 consumers are exempt from several — not all — requirements. Specifically exempt: the written risk assessment, the written incident response plan, the annual written report to the governing body, and the continuous monitoring or penetration testing obligation.
Everything else still applies. The exemption reduces documentation burden; it does not remove the requirement to secure the data. Firms frequently misread this as a blanket exemption and implement nothing.
Note also that the threshold counts consumers whose information you maintain, not active clients. Records retained from prior years count. Many firms cross 5,000 without realising it.
| Requirement | Fewer than 5,000 consumers | 5,000 or more consumers |
|---|---|---|
| Designated Qualified Individual | Required | Required |
| Written risk assessment | Exempt | Required |
| Required safeguards (access controls, data inventory, encryption, MFA, disposal, change management, logging) | Required | Required |
| Continuous monitoring, or annual penetration test plus six-monthly vulnerability assessments | Exempt | Required |
| Staff training and service provider oversight | Required | Required |
| Written incident response plan | Exempt | Required |
| Annual written report to the board or equivalent | Exempt | Required |
| FTC notification of events affecting 500+ consumers | Required | Required |
What a WISP has to contain
The amended rule, effective June 2023, is prescriptive in a way the original was not. A compliant programme includes:
A designated Qualified Individual
One named person responsible for overseeing and enforcing the programme. They do not need a security background, and the role can be delegated to a service provider — but if you outsource it, your business retains responsibility and must designate someone internally to oversee that provider.
A written risk assessment
Identifying reasonably foreseeable internal and external risks to customer information, evaluating their likelihood and impact, and describing how they will be addressed. It must be written, and it must be periodically reassessed.
Specific required safeguards
- Access controls limiting information to those who need it
- An inventory of what data you hold, where it is, and who can reach it
- Encryption of customer information both at rest and in transit
- Multi-factor authentication for anyone accessing information systems — this one is explicit and non-negotiable
- Secure development practices for any customer-facing applications
- Secure disposal of customer information no longer needed, generally within two years of last use
- Change management procedures
- Monitoring and logging of authorised user activity
Testing
Either continuous monitoring, or annual penetration testing combined with vulnerability assessments at least every six months. Whichever route, it must be documented.
Training and service provider oversight
Security awareness training for staff, and due diligence on service providers who touch customer information — including contractual requirements that they maintain appropriate safeguards.
An incident response plan
Written, covering roles, internal processes, communication, remediation, and post-incident review.
An annual report
The Qualified Individual reports at least annually to the board or equivalent governing body on the programme's status, risks, and any incidents.
Breach notification
Since May 2024, non-banking financial institutions covered by the rule must notify the FTC of a security event involving the unencrypted information of 500 or more consumers, no later than 30 days after discovery.
The notification is filed through the FTC's online portal and the FTC may make it public. That possibility is a meaningful consequence in its own right, particularly for firms whose business depends on trust.
State breach notification laws apply in addition. New York and Connecticut both impose their own requirements, and New York's SHIELD Act carries data security obligations that apply independently of the federal rule.
The tax preparer angle specifically
For tax professionals there is an additional layer. IRS Publication 4557 sets out the expectation, and PTIN renewal now includes an acknowledgement that you are required by law to have a written information security plan.
That acknowledgement is the part worth pausing on. False statements on that form are a criminal offence, and once you have formally acknowledged the requirement, a missing plan is a known compliance gap rather than an oversight — something considerably more serious.
The IRS also expects tax professionals to report data theft to their local IRS Stakeholder Liaison promptly — a separate obligation from the FTC notification, with a different recipient and purpose.
| Who you notify | When | Who it applies to |
|---|---|---|
| FTC, via its online portal | Event involving unencrypted information of 500 or more consumers; no later than 30 days after discovery | Non-bank financial institutions covered by the Safeguards Rule |
| Your local IRS Stakeholder Liaison | Promptly after client data theft | Tax professionals |
| Affected individuals and state authorities | As each state's breach notification law requires (e.g. New York, Connecticut) | Businesses holding those states' residents' information |
Where firms usually fall short
- A downloaded template that was never customised to the actual environment. A WISP describing safeguards you do not have is worse than none — it documents the gap.
- No MFA, or MFA on email only. The rule says information systems, which includes remote access, line-of-business applications, and administrative accounts.
- No data inventory. You cannot protect data whose location you have not established, and this is usually the hardest item to complete honestly.
- Retention with no disposal. The rule expects information to be disposed of within two years of last use unless there is a legitimate business or legal reason to keep it. Most firms keep everything indefinitely.
- No service provider due diligence. Your cloud tax software, your document portal, your IT provider all handle customer information.
- Nothing documented. The rule is largely about documented process. Doing the work without recording it does not demonstrate compliance.
The recurring theme is that this is a programme rather than a document. The written plan is evidence of the programme, not a substitute for it — and that distinction is what an examiner will focus on.
Sources
- Federal Trade Commission — FTC Safeguards Rule: What Your Business Needs to Know
- Legal Information Institute, Cornell Law School (text of the Code of Federal Regulations) — 16 CFR 314.4 - Elements
- Legal Information Institute, Cornell Law School (text of the Code of Federal Regulations) — 16 CFR 314.6 - Exceptions
- Internal Revenue Service — Publication 4557, Safeguarding Taxpayer Data: A Guide for Your Business
- Internal Revenue Service — Instructions for Form W-12, IRS Paid Preparer Tax Identification Number (PTIN) Application and Renewal
- Internal Revenue Service — Data theft information for tax professionals


