ClearPath IT
Security · IT Support · Web
Back to Blog
IRS Compliance7 min readOctober 10, 2024

IRS Publication 4557: What Tax Preparers Must Do to Stay Compliant

IRS Publication 4557 outlines cybersecurity requirements for all tax professionals. This guide breaks down the Security Six, WISP requirements, and what happens if you're not compliant.

IRS Publication 4557, titled 'Safeguarding Taxpayer Data,' is the IRS's official guide to cybersecurity requirements for tax professionals. It applies to every tax preparer who handles client tax information — from solo practitioners to large multi-partner firms.

Publication 4557 isn't optional guidance. It reflects legal obligations under the Gramm-Leach-Bliley Act (GLBA) and is enforced by both the IRS and the FTC. Failure to comply can result in the IRS revoking your e-filing credentials — which effectively shuts down your practice.

The Security Six

IRS Publication 4557 centers on six foundational security practices that every tax professional must implement. The IRS calls these the 'Security Six':

  • Anti-virus software — installed, active, and up to date on all devices
  • Firewall — between your network and the internet
  • Two-factor authentication (2FA / MFA) — on all software that accesses tax data
  • Backup software and services — with encrypted, tested backups stored separately
  • Drive encryption — for all devices that store taxpayer data
  • VPN — required when accessing client data over public or unsecured Wi-Fi

WISP Requirement for Tax Preparers

Beyond the Security Six, Publication 4557 requires all tax preparers to maintain a Written Information Security Plan (WISP). This document must:

  • Be in writing — not just understood informally
  • Name a designated security coordinator
  • Describe your firm's data environment and the risks to it
  • Document specific safeguards in place for each identified risk
  • Include employee training procedures
  • Outline your response plan for a data breach
  • Be reviewed and updated annually

Identity Theft Protection Plan

IRS Publication 4557 also requires tax professionals to have an Identity Theft Protection Plan — procedures for recognizing and responding to tax-related identity theft affecting your clients. This includes:

  • Procedures for identifying suspicious activity in client accounts
  • Steps to take if you suspect a client's identity has been stolen
  • How to report suspected identity theft to the IRS
  • How to assist clients who are victims of tax identity theft

Data Breach Response Requirements

If your firm experiences a data breach, the IRS expects you to act immediately. Under both Publication 4557 and the FTC Safeguards Rule, you must:

  • Report the breach to the IRS immediately by emailing your local IRS Stakeholder Liaison
  • Notify affected clients
  • File Form 14039-B (Business Identity Theft Affidavit) with the IRS
  • Notify the FTC within 30 days if more than 500 customers were affected
  • Notify affected state tax agencies where required

Employee Training Requirements

Publication 4557 explicitly requires tax preparers to train employees on data security. This includes:

  • Recognizing and avoiding phishing emails (the #1 attack vector for tax firms)
  • Proper password hygiene and MFA use
  • Safe handling and disposal of physical documents with taxpayer data
  • Procedures for working remotely with client data
  • What to do if a device is lost, stolen, or compromised

What If You Don't Comply?

The IRS takes Publication 4557 requirements seriously. Non-compliance can result in:

  • Revocation of your IRS e-services access and e-filing credentials
  • Suspension of your Preparer Tax Identification Number (PTIN)
  • FTC civil penalties of up to $50,120 per violation per day
  • Professional liability exposure if a breach results in client harm
  • Loss of malpractice insurance coverage at renewal

How ClearPath IT Keeps Tax Preparers Compliant

We implement and maintain every Publication 4557 requirement for tax firms. We write your WISP, enforce MFA across your software stack (Drake, ProSeries, UltraTax, TaxDome, and others), deploy and monitor encrypted backups, and manage your incident response if something goes wrong.

IRS 4557 Compliance Assessment — Free

Not sure if your firm meets Publication 4557 requirements? We'll walk through every item with you in a free 30-minute call and tell you exactly where you stand.

Book Free Assessment →
FTC Compliance

FTC Safeguards Rule Checklist for CPA Firms (2024)

A practical checklist covering every FTC Safeguards Rule requirement for CPA firms, bookkeepers, and tax preparers. Understand what you need, why it matters, and how to get compliant.

Read guide
WISP

What Is a WISP and Does My Accounting Firm Need One?

A Written Information Security Plan (WISP) is legally required for CPAs, bookkeepers, and tax preparers. Here's what it is, what it must include, and how to get one.

Read guide