Skip to content
IT tips Updated Noah Stegman

Accounting Firm IT Guide: WISP, IRS and FTC Checklist

What the IRS and the FTC Safeguards Rule require from a tax or accounting firm's IT, with a copyable checklist and questions to ask any IT provider.

If your firm prepares tax returns, federal law treats it as a financial institution. The FTC Safeguards Rule requires a written information security plan (WISP), a named person in charge of it, multi-factor authentication (a second proof of identity beyond the password), encryption of client data, and a report to the FTC when a breach affects 500 or more people. The IRS publishes a free WISP template and a security guide that turn those requirements into practical steps.

This guide covers the software accounting firms run, what the rules require in technical terms, the risks that are specific to the profession, and a checklist you can copy. It is IT guidance, not legal advice. For a shorter overview of the services involved, see our law and accounting firms page.

What software does an accounting firm’s IT have to support?

An accounting practice depends on a few specialized products that are sensitive to versions, updates, and the computers they run on.

SystemCommon productsWhat to check
Tax preparationUltraTax CS, Lacerte, ProSeries, ProConnect Tax, Drake Tax, CCH Axcess Tax, CCH ProSystem fx TaxDesktop versions need a supported Windows version, room for each new tax season’s install, and a backup of the data folders. Cloud versions need multi-factor authentication on every user
Client bookkeepingQuickBooks Online, QuickBooks Desktop Enterprise, XeroWhich desktop versions you must keep to open client files, and whether each one is still supported
Document storage and client portalsSmartVault, TaxDome, Canopy, CCH Axcess Document, or SharePoint in Microsoft 365Permissions by client or engagement, a retention policy, and a way for clients to send documents without using email attachments
Email and office appsMicrosoft 365 or Google WorkspaceMulti-factor authentication, blocked auto-forwarding to outside addresses, an encrypted email option
IRS and state accountsIRS e-Services, the PTIN account, state portalsWho holds the logins, and weekly checks of how many returns were filed under your EFIN (electronic filing identification number) and PTIN (preparer tax identification number)

Two QuickBooks Desktop dates matter for planning. Intuit stopped selling Desktop Pro Plus, Premier Plus, and Mac Plus to new US subscribers after September 30, 2024. Existing subscribers can renew, and Desktop Enterprise is still sold. Separately, QuickBooks Desktop 2023 was discontinued on May 31, 2026, so it no longer receives security updates, live support, or connected services such as payroll and bank feeds. If a 2023 copy is still installed for an old client file, plan its replacement.

The same applies to Windows. Windows 10 support ended on October 14, 2025, and our Windows 10 end of life guide explains the options for any remaining machines.

Which rules apply to a tax or accounting practice?

The FTC Safeguards Rule

The Safeguards Rule (16 CFR Part 314) implements the Gramm-Leach-Bliley Act. The FTC’s guide, FTC Safeguards Rule: What Your Business Needs to Know, lists tax preparation firms among its examples of covered financial institutions. The IRS says the same in Publication 5708: tax and accounting professionals are considered financial institutions “regardless of size.”

The rule requires a written information security program with nine elements:

  1. A designated Qualified Individual who runs the program. This can be an employee or an outside provider, but someone at the firm stays responsible for oversight.
  2. A written risk assessment.
  3. Safeguards that address the risks, including access controls, an inventory of data and systems, encryption of customer information at rest and in transit, multi-factor authentication for anyone accessing customer information, secure disposal, change management, and logging of user activity.
  4. Regular testing: either continuous monitoring, or annual penetration testing plus vulnerability scans every six months.
  5. Security awareness training for staff.
  6. Oversight of service providers, including security terms in contracts.
  7. Keeping the program current as the business and the threats change.
  8. A written incident response plan.
  9. A written report from the Qualified Individual to the firm’s leadership at least once a year.

Most of the updated requirements have been in force since June 9, 2023.

What is the small-firm exemption?

Under 16 CFR 314.6, firms that maintain customer information on fewer than 5,000 consumers are exempt from four pieces: the written risk assessment, the continuous monitoring or penetration testing requirement, the written incident response plan, and the annual written report.

Everything else still applies, including the Qualified Individual, encryption, multi-factor authentication, staff training, and vendor oversight. The wording counts consumers whose information you maintain, not returns filed this year, so a firm that keeps many years of files can pass 5,000 sooner than it expects. Even under the threshold, a short risk assessment and incident plan are worth writing, because the IRS template expects both.

The breach reporting requirement

Since May 13, 2024, a covered firm must notify the FTC as soon as possible, and no later than 30 days after discovery, when unencrypted information of at least 500 consumers is acquired without authorization. California has its own breach notification law on top of this. Our guide on what to do after a data breach covers the first steps.

IRS Publication 4557 and Publication 5708

Publication 4557, Safeguarding Taxpayer Data, is the IRS’s plain-language security guide for preparers. Its basic steps are:

  • Anti-malware software on every device, set to update automatically
  • Strong, unique passwords, with a password manager suggested
  • Multi-factor authentication for anyone accessing customer information
  • Encryption of sensitive files and emails, and drive encryption on devices
  • Backups to a secure source that is not connected to the network full time
  • Access to taxpayer data limited to people who need it
  • Wiping or destroying old hard drives and printers
  • Weekly checks of EFIN and PTIN filing totals
  • A VPN (virtual private network, an encrypted connection into the office) plus multi-factor authentication as the minimum for remote access to the office network

Publication 5708 is a 28-page WISP template written for smaller practices. You fill in your firm’s details, name the responsible people, list your hardware and the places client data lives, and adopt policies for remote access, passwords, and incidents. In a July 2025 reminder, the IRS and its Security Summit partners restated that a WISP is required by law, not optional.

The requirement also appears at PTIN renewal. Form W-12 asks preparers to confirm they are aware that paid preparers must have a data security plan.

What are the biggest IT risks for an accounting firm?

  1. Phishing aimed at preparers. Publication 4557 describes emails that pose as the IRS, a software vendor, or a prospective client with an attachment. One stolen password can expose every return the firm holds. Multi-factor authentication limits the damage, and our post on how to spot phishing emails is written for staff.
  2. Fraudulent returns filed with your credentials. This risk is unique to the profession. It is why the IRS asks preparers to check EFIN and PTIN totals every week and to deactivate EFINs they no longer use.
  3. Ransomware on shared drives. QuickBooks company files and desktop tax program data sit in shared folders, which is exactly what ransomware encrypts. The defense is a backup that is kept off the network and has been restored at least once as a test. See our business data backup guide.
  4. Remote access left open. Remote Desktop exposed directly to the internet is a common way in. If staff work from home, put remote access behind a VPN or a secure gateway with multi-factor authentication. Our guide to secure remote access compares the options.
  5. Seasonal staff and old accounts. Temporary preparers need their own logins, the minimum access their work requires, and an end date. Shared logins make it impossible to show who did what.
  6. Documents traveling by email. W-2s, prior-year returns, and bank statements sent as plain attachments stay in mailboxes on both sides for years. A client portal or encrypted email reduces how much sensitive data lives in email.
  7. Updates and changes in the middle of tax season. A Windows feature update or a server migration in March can break a tax program at the worst moment. Schedule large changes outside the filing windows, and keep security patches flowing all year.

An accounting firm IT checklist you can copy

Plan and paperwork

  • A WISP exists, based on Publication 5708, and has been reviewed in the last 12 months.
  • A Qualified Individual is named in writing.
  • There is an inventory of every device and every place client data lives, including cloud services.
  • There is a list of vendors that hold client data, with contracts that address security.
  • An incident plan covers who contacts the IRS Stakeholder Liaison, the state tax agencies, the FTC if 500 or more consumers are affected, the firm’s insurer, and clients.

Accounts

  • Every person has an individual login to every system. No shared passwords.
  • Multi-factor authentication is on for email, tax software, QuickBooks Online, the client portal, remote access, and IRS e-Services.
  • A business password manager holds firm credentials.
  • Seasonal accounts have an expiry date, and departing staff lose access the same day.
  • EFIN and PTIN filing totals are checked weekly during filing season.

Devices and network

  • Full-disk encryption (BitLocker on Windows, FileVault on Mac) is on for every computer.
  • Operating systems, tax programs, and QuickBooks versions are all still supported by their vendors.
  • Anti-malware runs on every device and updates automatically.
  • Office Wi-Fi uses a strong password, and guests use a separate network.
  • Old computers, drives, and copiers are wiped or destroyed, and the disposal is recorded.

Data

  • Backups cover the tax program data folders, QuickBooks company files, and the document system.
  • One backup copy is kept off site and off the network.
  • A test restore is done before tax season, and the date is written down.
  • Clients send and receive documents through a portal or encrypted email.
  • A retention schedule says how long client files are kept and how they are destroyed.

Before each tax season (November and December)

  • Install and test the new tax year’s software.
  • Review who has access to what, and remove what is no longer needed.
  • Run staff phishing training.
  • Review the WISP and note the review date.
  • Hold large changes, such as new servers or major upgrades, until after the April deadline.

What a very small practice can skip

A sole preparer working on cloud tax software and Microsoft 365 does not need an office server, and without a server there may be nothing for a VPN to connect to. A firm under the 5,000-consumer threshold is not required to buy penetration testing or continuous monitoring.

What cannot be skipped at any size: the written plan, multi-factor authentication, encryption, backups, limited access, and training. For a one-person or two-person firm, the Publication 5708 template can be completed in a few focused sessions, and most of the technical items on the checklist are settings in products you already pay for. Our post on the FTC Safeguards Rule for small-business IT goes through the technical requirements in more detail.

Common mistakes

  • Downloading the WISP template and filing it without filling in the inventory, the names, or the review dates.
  • Turning on multi-factor authentication for email but not for the tax software or the client portal.
  • Counting this year’s returns, instead of every consumer on file, when checking the 5,000 threshold.
  • Backing up the file server but not the tax program’s data folders, or never trying a restore.
  • Keeping a discontinued QuickBooks Desktop version on an internet-connected computer for one old client file.
  • Leaving remote access set up for seasonal staff switched on all year.

Questions to ask any IT provider

  1. Have you read IRS Publication 4557 and the Safeguards Rule, and which of the requirements will you handle?
  2. If you act as our Qualified Individual, what will you report to us, and how often?
  3. How do you back up tax software data and QuickBooks files, and how often do you test a restore?
  4. How do you schedule updates and larger changes around filing deadlines?
  5. How is your own access to our systems protected, and is it logged?
  6. Will you sign a contract that includes the security obligations the rule expects of service providers?
  7. What documentation will we receive, and do we own it?
  8. What do you do in the first hours after a suspected breach, and who contacts the IRS and the FTC?

These questions are just as useful for reviewing a current arrangement as for choosing a new one. Specific, written answers are the goal.

Common questions

Does a one-person tax practice really need a WISP?

Yes. The IRS states that tax and accounting professionals are financial institutions under the Gramm-Leach-Bliley Act regardless of size, and that the Safeguards Rule requires a written plan. The plan should fit the size and complexity of the practice, so a sole preparer’s WISP can be short. Publication 5708 is the IRS template built for that purpose.

Is multi-factor authentication required by law for accounting firms?

For firms covered by the Safeguards Rule, yes. The rule requires multi-factor authentication for anyone accessing customer information, unless the Qualified Individual approves an equivalent or stronger control in writing. IRS Publications 4557 and 5708 repeat the requirement. Our post on why multi-factor authentication matters explains the practical options.

What should a preparer do first after a data theft?

Publication 4557 says to report it immediately to the IRS through your local Stakeholder Liaison, so the IRS can act to block fraudulent returns in your clients’ names. Then contact the state tax agencies where you file, your insurer, and a security expert to determine the cause and scope. If 500 or more consumers are affected, the FTC must be notified within 30 days.

Who counts toward the 5,000-consumer threshold?

The exemption in 16 CFR 314.6 applies to firms that maintain customer information concerning fewer than 5,000 consumers. Read plainly, that covers everyone whose information you still maintain, including past customers whose files you have kept, not only the people you served this year. Both spouses on a joint return are individuals whose information you hold. Check the count against your document retention practice, and ask your attorney if you are close to the line.

How Coastal Growth Co. can help

Coastal Growth Co. provides IT support for small businesses across Orange County, including tax and accounting practices. We can set up the technical safeguards in the checklist above (multi-factor authentication, encryption, backups with test restores, access controls, and secure remote access) and help you fill in the technical sections of your WISP. Larger changes can be planned around your filing calendar. Legal questions about the rule stay with your attorney. The scope and price are agreed before any paid work starts. See managed IT support and cloud and email services, or contact us to talk through your setup.

Need a hand with this?

I offer IT support across Orange County, with on-site work in Los Angeles and nearby areas by arrangement.

Let's talk arrow_forward

Get in touch

Talk with Noah

Tell me about your business and what is getting in the way. A recurring problem, an upcoming project, or a setup you would like a second opinion on.

noah@coastalgrowthco.com

Noah Stegman · Coastal Growth Co.

Your message goes to Noah. I will reply by email. Please leave out passwords and sensitive account details.