If you run a CPA firm, bookkeeping practice, or tax preparation business, the FTC Safeguards Rule applies to you — whether your IT vendor has told you so or not. CPAs, tax preparers, bookkeepers, and credit professionals are classified as 'financial institutions' under the Gramm-Leach-Bliley Act (GLBA). That means you're legally required to implement a comprehensive information security program.
The FTC can fine you up to $50,120 per violation per day. This checklist covers every requirement from the 2023 updated rule.
1. Written Information Security Plan (WISP)
A WISP is the foundation of your compliance program. It must be a written document that describes your safeguards, who's responsible for them, and how risks are assessed and managed.
- Assign a Qualified Individual to oversee the program
- Document the scope of customer information your firm handles
- Describe each safeguard and who is responsible for it
- Include a vendor oversight section
- Review and update the WISP at least annually
2. Risk Assessment
Before implementing safeguards, you must conduct and document a risk assessment of your firm's data environment.
- Identify where customer information is stored and who has access
- Evaluate internal and external threats
- Assess the likelihood and potential damage of each identified threat
- Document the assessment in writing
- Repeat the assessment whenever there are material changes to your environment
3. Access Controls
You must implement the principle of least privilege — employees should only have access to the data they need to do their jobs.
- Enforce Multi-Factor Authentication (MFA) on all systems that access customer data
- Implement role-based access controls
- Document onboarding and offboarding procedures
- Review access rights at least annually
- Immediately revoke access when an employee leaves
4. Encryption
Customer financial data must be encrypted both in transit and at rest.
- Encrypt all customer data stored on laptops, desktops, and servers
- Encrypt data transmitted over networks (use TLS 1.2 or higher)
- Encrypt email attachments containing customer financial information
- Verify your cloud storage providers encrypt data at rest
5. Secure Development & Change Management
If your firm uses any custom software or has IT systems managed internally, you must have a change management process.
- Evaluate new software before deployment
- Apply security patches within a reasonable timeframe (typically 30 days for critical patches)
- Test changes before rolling them out firm-wide
6. Monitoring & Testing
You can't set it and forget it. The rule requires ongoing monitoring of your security controls.
- Monitor all authorized users accessing customer information
- Conduct penetration testing at least annually
- Conduct vulnerability assessments at least every 6 months
- Review audit logs regularly
7. Vendor Oversight
Third-party software vendors (QuickBooks, TaxDome, Drake, Intuit) and cloud providers that handle your client data must be evaluated and monitored.
- Identify all vendors that access or store customer information
- Review each vendor's security practices before engaging
- Include security requirements in vendor contracts
- Periodically re-evaluate vendors
8. Incident Response Plan
The updated Safeguards Rule requires a written incident response plan. If you have a breach, you have 30 days to notify the FTC.
- Define what constitutes a security incident at your firm
- Designate a response team and chain of command
- Document how you'll contain, eradicate, and recover from an incident
- Address the FTC's 30-day breach notification requirement
- Test your incident response plan annually
9. Staff Training
Your team is your biggest vulnerability. The rule requires ongoing security awareness training.
- Train all staff on phishing and social engineering
- Cover password hygiene and MFA use
- Train staff on how to handle and transmit customer data
- Document all training with dates and attendees
- Conduct training at least annually — more often when threats change
10. Annual Program Review
Your security program must be reviewed and approved at the senior level at least once a year.
- Prepare a written report to your firm's leadership or board
- Summarize the risk assessment findings
- Document changes made to the program
- Get documented approval from a senior officer or managing partner
What Happens If You Don't Comply?
The FTC can pursue civil penalties of up to $50,120 per violation per day. More practically: your malpractice insurer may deny a claim if a breach occurs and you had no security program. Clients and referral partners are increasingly asking for proof of compliance before engaging.
How ClearPath IT Handles This For You
We build and maintain every item on this checklist for financial professionals across Ohio, Texas, Florida, and beyond. That includes writing your WISP from scratch, enforcing MFA across your firm, managing encrypted backups with verified restores, and running your incident response if something goes wrong.
Free Compliance Assessment
Not sure where your firm stands? We'll review your setup against this checklist in a free 30-minute call and give you a clear gap report — no obligation.
Book Free Assessment →