Does the FTC Safeguards Rule apply to your accounting firm?

A plain-English look at whether the FTC Safeguards Rule applies to your accounting or tax firm, what counts as a financial institution, and what it requires.

Does the FTC Safeguards Rule apply to your accounting firm?

Most accountants we talk to are surprised to learn they fall under a federal data-security rule written for “financial institutions.” You prepare returns and keep books. You’re not a bank. So why would a rule aimed at financial institutions reach a small CPA office or a seasonal tax shop? The answer is that the FTC defines “financial institution” far more broadly than the everyday meaning of the words, and tax and accounting firms are squarely inside that definition. Here’s what that means for your firm, in plain English.

Why an accounting firm counts as a “financial institution”

The FTC Safeguards Rule sits under the Gramm-Leach-Bliley Act, and it applies to “financial institutions” that are subject to the FTC’s jurisdiction. The catch is the definition. Under the rule, a financial institution is any business significantly engaged in providing financial products or services, and the FTC’s own guidance on the Safeguards Rule explicitly lists tax preparation firms and accountants among the businesses it covers.

So if your firm prepares tax returns, keeps books, provides financial planning, or otherwise handles customers’ financial information as part of your service, you are very likely a financial institution for purposes of this rule. Size does not exempt you. A solo tax preparer working from a home office and a fifty-person CPA firm are both covered. There is a narrow break for businesses that maintain information on fewer than 5,000 consumers, which exempts them from a few specific paperwork requirements, but it does not exempt you from the core obligation to protect the data.

The information the rule protects is “customer information,” meaning the nonpublic personal information you collect about the people you serve: Social Security numbers, financial account details, income figures, the contents of a return. For an accounting or tax firm, that is nearly everything in your files.

What the rule actually requires

The heart of the Safeguards Rule is a requirement to develop, implement, and maintain a written information security program, often called a WISP. This is not a binder you buy once and shelve. It is a living program with specific elements the FTC spells out. The practical pieces look like this:

Name a qualified individual. You have to designate someone responsible for running and overseeing your security program. In a small firm that can be an owner or partner, and the day-to-day technical work can be delegated to an IT provider, but the accountability stays with your firm.

Do a written risk assessment. Identify where customer information lives, how it flows, and what could go wrong, then base your safeguards on what you find. This is the same risk-first logic that anchors most modern security rules.

Implement specific safeguards. The rule names them directly: access controls, an inventory of the systems where customer information lives, encryption of customer information at rest and in transit, multi-factor authentication for anyone accessing customer information, secure disposal of data you no longer need, change management, and monitoring of who accesses what.

Test and monitor. You either run continuous monitoring or perform regular penetration testing and vulnerability assessments. For most small firms, the realistic path is ongoing monitoring through their IT provider.

Train your people and oversee your vendors. Staff need security awareness training, and any service provider that touches customer information, including your IT company, must be selected and overseen with security in mind, and held to it by contract.

Have a written incident response plan, and report breaches. You need a plan for responding to a security event. And as of mid-2024, covered firms must notify the FTC within 30 days of discovering a breach involving the unencrypted information of 500 or more consumers, a detail covered in the FTC’s data breach notification guidance.

If that list looks familiar, it should. These are the same layered controls we build and document under our People+ Framework. Access control, encryption, MFA, monitoring, and tested response are good security and Safeguards Rule compliance at the same time.

The WISP, in particular

The written program is where firms most often fall short, usually because they have decent IT but nothing documented. A WISP ties everything together: it records your risk assessment, names your qualified individual, describes your safeguards, and lays out your incident response plan. It is also the first thing anyone will ask to see if your compliance is ever questioned.

You don’t have to start from a blank page. Our WISP template for accounting and tax firms is built around the Safeguards Rule’s required elements, so you can adapt it to your firm rather than guess at the structure. We also go deeper on the document itself in what a WISP is and whether your firm is legally required to have one.

One honest note, the same one we give every regulated business: your IT provider can build and operate most of the technical safeguards and help you draft the WISP, but the responsibility under the rule stays with your firm. The FTC requires you to name the qualified individual and oversee your providers. We explain exactly where that line sits in whether an MSP can make you compliant.

Where to start

If you’re not sure whether your firm is covered, assume you probably are and put the question to rest with a real risk assessment. From there, the work is concrete: a documented WISP, the named safeguards actually running, your staff trained, and a response plan written down. None of it requires a big firm’s budget, just the right setup kept current. You can read more on our compliance hub, or sit down with us. We’re local, we work with accounting and tax firms across Alaska and Hawaii, and we’ll give you a plain read on what the rule requires of you and where your gaps are.

Book a Discovery Call