Accounting and tax firms are 'financial institutions' under the Gramm-Leach-Bliley Act and its FTC Safeguards Rule - a fact many firms don't realize until a client or the IRS asks. Combined with the IRS's WISP requirement for anyone holding a PTIN, that means a real, evidenced security program, not just a policy on file.
Book a 15-minute review →Why CPA firms are covered: GLBA and the FTC Safeguards Rule apply to businesses that handle customer financial information, which squarely includes tax preparation and accounting. The IRS reinforces this through Publication 4557 and the WISP requirement tied to holding a PTIN - so the obligation reaches solo practitioners and small firms.
What you must do: maintain a written information security program with a qualified individual, risk assessment, access controls, encryption, MFA, monitoring, and an incident response plan - and keep it operating. During tax season, when firms handle SSNs, bank details, and returns at volume, business email compromise attacks spike, making real monitoring more than a formality.
The evidence gap: firms often have a WISP template but can't show the safeguards operate. That's the exposure - both to regulators and to the increasingly common client security questionnaires that ask CPA firms to prove their controls.
MDRwatchdog monitors where client financial data moves - workstations, email, cloud - and produces evidence your safeguards are operating, with heightened email and business-email-compromise monitoring for the tax-season months attackers target hardest. Readiness and evidence, not legal or tax advice; confirm your obligations with your own advisors.
Yes. Accounting and tax firms handling customer financial information are 'financial institutions' under GLBA and the FTC Safeguards Rule. The IRS also requires a WISP for anyone holding a PTIN.
Through Publication 4557 and the WISP requirement, the IRS expects tax professionals to maintain a written, operating information security plan protecting client data - reinforcing the FTC Safeguards Rule.
Firms handle SSNs, bank details, and returns at volume, and business email compromise attacks spike. Real monitoring during those months protects both clients and the firm.
MDRwatchdog provides security monitoring and compliance evidence to support readiness. It is not a certification and not legal advice. Certification and formal audits are performed by the appropriate authorized bodies (a C3PAO for CMMC, a licensed CPA firm for SOC 2, an accredited body for ISO 27001).