What Small Businesses Need to Know About the FTC Safeguards Rule
Running a CPA firm in Chicago? We have specialized IT services built for accounting firms.
If your business handles financial information for clients — as a tax preparer, CPA firm, bookkeeper, or financial advisor — the FTC Safeguards Rule applies to you. It requires you to have a written information security program in place, keep it updated, and designate someone responsible for it. The rule has been in effect since 2023, and the FTC has made clear it intends to enforce it. Here is what it requires and what you need to do if you are not already compliant.
Who the rule applies to
The FTC Safeguards Rule applies to financial institutions as defined under the Gramm-Leach-Bliley Act. That definition is broader than most people expect. It includes tax preparers, CPA firms, mortgage brokers, payday lenders, debt collectors, and any business that is significantly engaged in providing financial products or services to consumers.
If you prepare tax returns, file on behalf of clients, or provide accounting and financial advisory services, you are almost certainly covered. The rule applies regardless of the size of your firm.
What the rule requires
- A written information security program (WISP) that is appropriate to the size and complexity of your firm and the sensitivity of the information you handle
- Designation of a qualified individual responsible for overseeing and implementing your security program
- A risk assessment that identifies reasonably foreseeable security risks to client information
- Safeguards to address those risks, including access controls, encryption, and multi-factor authentication
- Regular monitoring and testing of your safeguards
- Oversight of service providers who handle client data on your behalf
- An incident response plan for how you will respond to a security event
- Annual reporting to your board or senior management on the status of your security program
The WISP: what it is and what goes in it
A Written Information Security Plan is a document that describes how your firm protects client information. It does not need to be long, but it does need to be specific to your firm. A generic template downloaded from the internet without customization does not satisfy the requirement.
At a minimum, your WISP should describe what data you collect and where it is stored, who has access to it and how access is controlled, how you handle breaches and incidents, how you train staff on security, and how you evaluate and update your security practices over time.
The IRS also requires tax preparers to have a WISP under its own Publication 5293 guidance, and the requirements overlap significantly with the FTC rule. If you need one document that satisfies both, it is achievable.
The technical requirements
The updated Safeguards Rule added specific technical requirements that did not exist in the original 2003 version. These are not optional for covered firms.
Multi-factor authentication is required for any individual accessing customer information. Encryption is required for customer information in transit and at rest. Access to customer information must be limited to authorized users and to those who need it to do their job. You must have a process for monitoring authorized users and detecting unauthorized activity.
These are not theoretical requirements. They describe controls that your IT setup either has or does not have.
What happens if you are not compliant
The FTC can bring enforcement actions under the Gramm-Leach-Bliley Act. Penalties can include civil monetary fines and mandatory compliance programs. Beyond regulatory penalties, a breach at a non-compliant firm creates significant legal exposure in client litigation.
More practically, your cyber liability insurance policy may require compliance with applicable regulations as a condition of coverage. A breach at a firm that was not compliant with the Safeguards Rule could be grounds for a coverage denial.
Where to start if you have not done this yet
- 1
Designate a qualified individual responsible for your security program. For a small firm, this is often the managing partner working with your IT provider.
- 2
Complete a risk assessment. Document what client data you have, where it lives, who can access it, and what the risks are.
- 3
Check whether your technical controls meet the requirements: MFA on all accounts, encryption in place, access limited appropriately.
- 4
Draft or update your WISP. It should be specific to your firm, reviewed annually, and signed off by leadership.
- 5
Put an incident response plan in writing. It does not need to be long, but it needs to exist.
We help CPA firms and tax preparers in the Chicago area get their security programs in order, including WISP development, risk assessments, and technical controls. We have a free WISP template for accounting firms available on our resources page, and we are happy to walk through what compliance looks like for your specific firm.
Questions about your IT setup?
We work with small businesses and accounting firms across the Chicago area. Schedule a free 30-minute consultation and we will tell you honestly what we see.