The Written Plan Most Small Firms Do Not Have: FTC Safeguards Before Filing Season

There is a 5 person accounting practice in Santa Clarita that has been preparing returns since before the software moved to the cloud. The partners are careful people. The passwords are not written on anything, the office is locked, and nobody has ever lost a client file. Ask them for their written information security plan and you will get a pause, and then a reasonable question: what plan.

Under federal law that firm is a financial institution, and the plan is not a best practice or a maturity goal. It is the thing the rule actually asks for. The good news is the part almost nobody leads with: the requirement is a document rather than a purchase, the template is free and published by the IRS, and the 4 months between now and filing season is the last quiet stretch of the year in which to write it.

Overview

The sentence that catches people is not complicated, it is just counterintuitive. The Safeguards Rule defines a financial institution as any institution whose business is an activity that is financial in nature, and the Federal Trade Commission's own guidance names tax preparation firms in the list of covered businesses, alongside mortgage brokers, collection agencies and credit counselors. The guidance says as much about itself: the rule defines the phrase in a way that is broader than how people use it in conversation.


If that still sounds like a stretch, the IRS closes it in its own words. Publication 5708 states that under the Gramm-Leach-Bliley Act and the Safeguards Rule, tax and accounting professionals are considered financial institutions, regardless of size, and that implementing and maintaining a written information security plan is a requirement of the rule. Publication 4557 says the same thing more briefly: the financial institutions definition includes professional tax preparers.


Two agencies, 3 documents, no ambiguity, and yet this is close to unknown in small practices. The reason is worth naming, because it explains the shape of everything you will be told next. There was no announcement aimed at a 5 person office. The obligation arrived through a definition rather than through a letter, and the people who did notice it were mostly people with something to sell, which means the first version of this most firms hear is a sales version.


The line this piece holds is the one that separates the obligation from the upsell. The rule asks for a program and a document. It does not ask for a product, it does not ask for a certificate, and there is no agency that approves what you write. That leaves a genuinely useful question in the middle: what does a small firm actually have to do.

The Challenge

The rule asks for 9 things, and most of them are already true in your office. The FTC's guidance lays out the elements of the program: designate a qualified individual to run it, base it on a risk assessment, design and implement safeguards, monitor and test them, train staff, oversee service providers, keep the program current, maintain a written incident response plan, and have the qualified individual report to the board. Inside the safeguards element sit the specifics people recognize: access controls reviewed regularly, an inventory of where customer information lives, encryption at rest and in transit, multi factor authentication, secure disposal within 2 years, change management and logging.


Read that list as an accountant rather than as an engineer and the character of it changes. A firm that already restricts who opens which client folder, already turns on the second factor in its tax package, already shreds paper on a schedule and already knows which cloud vendors hold client data is doing 6 of those things. What it does not have is the sentence that says so, written down, with a name at the top.


The qualified individual is a role, not a hire. This is the element that most often gets sold as a reason to buy something. The FTC's own language is deliberately plain: the person does not need a particular degree or title, and what matters is real world know how suited to your circumstances. It can be a partner. It can be the office manager. It can be an outside provider under contract, which is a legitimate arrangement and is how many small firms handle it, but it is an option rather than the requirement.


The small firm exception is real, and it removes 4 provisions rather than the program. Here is where the market's version and the text diverge most sharply, so it is worth quoting. Section 314.6 of the rule says in a single sentence that 4 provisions do not apply to financial institutions maintaining customer information concerning fewer than 5,000 consumers. Those 4 are the requirement that the risk assessment be written and meet stated criteria, the penetration testing and vulnerability assessment schedule, the written incident response plan, and the annual written report to the board.


Now read what is left, because it is the greater part of the rule. The qualified individual still stands. The risk assessment itself still stands, since the exception removes the requirement that it be written rather than the requirement that you do it. Access controls, the data inventory, encryption, multi factor authentication, disposal, change management, logging, staff training, service provider oversight and keeping the program current all still stand, as does the obligation to notify the FTC of a qualifying security event. A great many firms under the threshold have been told they are exempt. What they are is excepted from 4 provisions, and 2 of those 4 are documents most of them would benefit from having anyway.


There is a clock on the notification piece, and it is short. The notification provision took effect on 13 May 2024. Where an event involves the unauthorized acquisition of unencrypted customer information affecting at least 500 consumers, the FTC has to be notified as soon as possible and no later than 30 days after discovery. Two details in that sentence do real work: unauthorized access to unencrypted information counts as acquisition unless there is evidence it was not acquired, and the 30 days run from discovery rather than from the incident. A firm without an incident response plan discovers on day 1 that it is also writing the plan on day 1, which is the wrong week for it.


The IRS wants to hear about it too, and by a different route. Publication 4557 tells practitioners to report data losses or thefts immediately so precautions can be taken against fraudulent returns filed in clients' names, and it names the local stakeholder liaison as the contact. That is a separate path from the FTC notification, with a separate purpose, and neither one substitutes for the other.

Why It Matters

5 reasons this belongs in the quiet part of the calendar:

The document is the only evidence the program existed. This is the whole argument compressed. A careful firm and a negligent firm look identical in the aftermath of an incident, because the thing being examined is not how careful anyone felt. It is what was decided, when, by whom, and whether it was reviewed. A plan written in September is a record. The same facts recalled in March are a story.


This page will not print a penalty figure, and the reason is the point. Numbers circulate in this market, usually a per violation amount and a personal amount for officers, and they are used to move small firms to a decision. We went to check them, which is the only responsible thing to do with a number that scares somebody into buying. The enforcement section of the statute assigns enforcement to the Federal Trade Commission and the other named regulators and carries no dollar amounts at all. The rule itself carries none. Enforcement runs through the Federal Trade Commission Act, and what any specific matter costs is not a figure available to a vendor in advance. So the number does not go on this page. The obligation is real without it, and a firm that acts on a figure nobody can source has learned the wrong lesson about which claims to check, which is the habit our piece on reading a vendor's fine print is really about.


Nobody certifies this, and the market says otherwise. Nothing in the rule creates an approval process, a certificate or a registry, so a plan sold as agency approved, IRS approved or Safeguards certified is describing something that does not exist. The pattern is the one we hold ourselves to elsewhere and it is the same either way: no provider is a certifying body, ours included. A firm can be helped to build a defensible program. It cannot be handed a certificate that means anything to anyone.


The same questions arrive from a second direction anyway. The cyber insurance application asks about multi factor authentication, encryption, training and incident response in almost the same order, and the answers on that form are representations a carrier reads again at claim time, which our piece on the application you already signed works through. A firm that writes the plan is answering the insurance questionnaire honestly as a side effect. A firm that does neither is answering it from memory, under time pressure, in a document that has consequences.


The service provider element is the one small firms consistently miss. The rule asks you to select providers capable of maintaining appropriate safeguards and to require those safeguards by contract. In a small practice the client data lives in a handful of hosted products, and the obligation follows it there. That makes the contract the control, which is the same argument our piece on aligned software and extraction software makes from the business model side, and the same dependency our piece on third party vendor risk traces through the rest of the building.

What Organizations Should Watch For

  • A plan that exists as a purchased PDF nobody in the office has read. A template completed by a vendor, filed, and never revisited names controls the firm does not actually run. That is worse than having nothing, because it is a written record of a program you were not operating.
  • The exemption sentence. If someone tells you a firm under 5,000 consumers is exempt from the Safeguards Rule, they have read a summary rather than the section. It is an exception covering 4 provisions, and the difference is most of the rule.
  • No named qualified individual. Not a title on an org chart, a person who knows the role is theirs. When the answer to who owns this is everyone, the answer in practice is nobody, and the rule asks for a name.
  • Client data in a product nobody wrote down. The portal a client was invited to once, the storage account from a prior tax package, the personal drive used during a busy March. The inventory element exists because this is universal, and the accounts that get missed are the ones nobody chose.
  • Multi factor turned on for some things. Partial coverage is the common state, and the gap is usually the oldest and most privileged account. Our piece on why multi factor is not enough on its own covers where it stops helping.
  • Seasonal staff who still have access in July. Filing season brings people in and the offboarding rarely matches the onboarding, which our piece on offboarding as a security event takes apart. An account that outlives its purpose is the cheapest way into a firm.
  • Retention with no disposal. The rule asks for secure disposal of customer information within 2 years of the last use unless there is a legitimate reason to keep it. Practices tend to keep everything forever by default, and every extra year of returns held is another year of exposure with no offsetting benefit.
  • A provider who cannot show you the rule. Ask which section requires what they are recommending. Any answer that cannot point at the text is a preference being sold as an obligation.

Recommended Actions

  • Read Publication 5708 before you buy anything. The IRS wrote a template specifically for small tax and accounting practices, it is free, and it is written for a reader who is not an engineer. Start there, and let it tell you what you already have rather than letting a quote tell you what you lack.
  • Name the qualified individual this week. It costs nothing and it is the element everything else hangs from. Write the name in the document and tell the person.
  • Do the risk assessment in writing even if you are under the threshold. The exception removes the requirement, not the value. It is the document that makes every other decision in the plan explicable later, and a small firm can complete a first honest version in an afternoon.
  • List every place client data actually lives, including the ones nobody approved. Software, storage, email, portals, paper, backups, and the machines under the desks. The inventory is the hardest part of the whole exercise and it is the part that cannot be delegated to a product.
  • Write the incident response steps down even if the provision does not apply to you. Who is called first, who talks to clients, who notifies the FTC inside 30 days, and who contacts the IRS stakeholder liaison. 1 page is enough, and the value is entirely in having decided it before the day you need it.
  • Put a review date on the plan and treat it as an appointment. An annual reread after filing season, with what changed written into it, is the difference between a living program and a file. It is also what makes the document credible to anyone reading it later.
  • If you do bring in help, ask what it costs and what it does not include, in writing. A firm that publishes what it charges and what it excludes can be compared. Ours is on the pricing page with the number attached, and the terms are in the published agreements rather than promised on a page.

The SecureLynx Perspective

Observe:

The pattern in accounting practices is not carelessness, it is that the obligation never announced itself. These are firms that already handle client money and client identity with discipline, and the security program is usually running informally at a decent standard with nothing written to prove it. So the first pass is almost always an inventory rather than a purchase: what is already true, where the client data genuinely lives, and which of the elements are met in practice and simply unrecorded. Most of what a small firm needs turns out to be transcription. The gaps that remain are then real gaps, and there are fewer of them than a sales conversation suggests.


Adapt:

Where we help, the plan is the firm's document rather than ours. It is written in language a partner can defend without us in the room, it names their qualified individual rather than installing us as one by default, and the whole of it is exportable from the client portal with the primary copy theirs. Controls that need building get built to the rule's own elements rather than to a product catalogue, which is what our compliance and risk work is scoped around, and the technical layer underneath it is ordinary access control, encryption, logging and training rather than anything exotic. What we charge for it is published, and the agreement is readable before you ever call.


Protect:

Then the limits, plainly, because on this subject they are the load bearing part. We cannot certify your compliance and no provider can, because there is no certificate in the rule to issue. We are not your attorney, and whether a particular practice or a particular line of work falls inside the definition is a question for counsel rather than for us. A firm that reads Publication 5708 and writes its own plan has done a real and sufficient thing, and we would rather say so than pretend the document requires us. The honest recommendation on this page costs us the smallest engagement in it. Point every question here at us first, and start with the agreements.

Common questions

We are a 4 person tax office in Santa Clarita. Are we really covered by a federal security rule written for banks?

Yes, and the IRS says so in its own publication rather than leaving you to infer it. Under the Gramm-Leach-Bliley Act the phrase financial institution is defined by activity rather than by signage, and preparing returns for compensation is an activity that is financial in nature. The IRS states plainly that tax and accounting professionals are considered financial institutions regardless of size. There is no headcount floor and no revenue floor. What size does change is the shape of the obligation rather than its existence: a firm holding information on fewer than 5,000 consumers is excepted from 4 specific provisions of the rule, which is a real and useful exception, and it is a long way from being exempt.

What does the plan actually have to contain, and do we have to buy something to get one?

You have to name a qualified individual to run the program, base the program on a risk assessment, implement a defined set of safeguards including access controls, a data inventory, encryption, multi factor authentication, secure disposal and logging, train your staff, oversee your service providers by contract, keep the program current, and be able to notify the FTC of a qualifying security event. Almost all of that is writing down decisions you have already made about how the office runs. The IRS publishes a free template built specifically for a small tax practice, and a competent firm can complete a defensible first version of it without buying anything at all. Anyone who tells you the plan requires a particular product is selling the product rather than reading the rule.

A vendor quoted us a penalty number to make the case. Should that change what we do?

It should make you ask where the number comes from, because we went looking and could not source the figures that circulate in this market. The enforcement section of the statute the rule sits under carries no dollar amounts, and the rule itself carries none either. Enforcement runs through the Federal Trade Commission Act, and what any particular matter costs is not something a vendor can quote you in advance. There is a second claim worth the same treatment: nothing in the rule creates an approval, a certificate or a registry, so a plan advertised as agency approved or Safeguards certified is describing something that does not exist. The reason to write the plan is that the obligation is real and the document is the only evidence you were meeting it. That case does not need a number attached to hold.