Tax Firm Data Security Checklist for Busy Season

Tax Firm Data Security Checklist for Busy Season
Table of Contents
Share This Article

Every year, the IRS and its Security Summit partners remind tax professionals to protect client data and review their security plans. Most firm owners intend to act. Then extensions, staffing decisions, and client work take over.

By filing season, the Written Information Security Plan may still describe last year’s systems. A new employee may have missed security training. Nobody may be certain whether a contractor’s access was documented or removed.

Security is easier to review before the pressure begins. The framework is clear: verify the technical controls, update the written plan, train the people, test the response process, and account for every third party that can reach client data.

As of August 24, 2026, current IRS material does not establish a new version of the Security Six or a new WISP mandate specific to 2026. The priority is testing the requirements already in force against the firm’s current systems, staff, vendors, and threats.

What is the IRS Security Summit?

The IRS Security Summit is a partnership among the IRS, state tax agencies, the tax industry, and tax professionals. It was formed to combat tax-related identity theft and strengthen protections around taxpayer information.

Its recurring guidance applies to firms of every size. It covers baseline technical safeguards, a Written Information Security Plan, phishing awareness, signs of data theft, and incident recovery.

The requirements are not limited to large firms. A solo tax preparer may hold the same sensitive taxpayer information as a larger practice, even if the systems used to process it are simpler.

What are the IRS Security Six controls?

The IRS Security Six are six baseline safeguards the Security Summit recommends for tax professionals.

Security control

What your firm should verify

Anti-virus and anti-malware

Protection is active, updated automatically, and installed on every device handling client data.

Firewalls

Network and device firewalls are enabled, configured, and not bypassed by remote staff.

Multi-factor authentication

MFA protects tax software, email, portals, cloud storage, remote access, and administrator accounts.

Backups

Critical information is backed up separately, and the firm has tested whether it can be restored.

Drive encryption

Laptops, desktops, and portable media containing taxpayer information are encrypted.

Virtual private network

Remote users connect through an approved VPN when accessing firm systems over an untrusted network.

These controls are a starting point, not a complete information security program. The IRS Security Six guidance also emphasizes security planning, phishing awareness, signs of data theft, and recovery preparation.

Is your Written Information Security Plan current?

Federal law requires professional tax preparers to create and maintain a Written Information Security Plan, commonly called a WISP, for protecting client data.

Tax Firm Data Security Checklist

The IRS provides a sample WISP for tax and accounting practices, but downloading the template is not enough. The plan must describe the firm as it operates today.

Review the WISP whenever the firm changes software, devices, office locations, staffing arrangements, access methods, or service providers. A documented review should also be included in the annual pre-busy-season process.

At minimum, confirm that the plan addresses:

  • Who owns the information security program
  • What client data the firm collects and stores
  • Where that information resides
  • Who can access each system
  • Employee training, onboarding, and offboarding
  • Authentication, encryption, backups, and remote access
  • Service-provider selection and monitoring
  • Incident detection, response, recovery, and reporting
  • How the plan will be updated when risks or operations change

Primary IRS references include Publication 4557, Safeguarding Taxpayer Data, Publication 5708, and Publication 5709.

What deserves particular attention in 2026?

The 2026 review should focus on whether existing safeguards still work.

Start with phishing and impersonation. Staff should independently verify unexpected requests involving passwords, portal invitations, bank details, Electronic Filing Identification Numbers, or documents from a supposed new client.

Next, test ransomware resilience. A backup is useful only when it can be restored. Confirm that backups are separated from ordinary user access and that the firm can continue essential work if a device or shared system becomes unavailable.

Finally, review access. Remove dormant accounts, reduce unnecessary administrator privileges, verify MFA coverage, and check whether temporary staff or vendors can access more information than their responsibilities require.

The goal is not to add controls simply to appear current. It is to prove that the safeguards described in the WISP work within the firm’s present environment.

Does the FTC Safeguards Rule apply to accounting firms?

Yes, when a tax or accounting firm meets the rule’s definition of a financial institution. The FTC expressly identifies tax-preparation firms as an example.

The FTC Safeguards Rule requires covered firms to maintain a written information security program with appropriate administrative, technical, and physical safeguards.

The rule addresses:

  • Risk assessment
  • Access controls
  • Encryption
  • Multi-factor authentication
  • Employee training
  • System monitoring
  • Incident response
  • Service-provider oversight

Covered financial institutions must also report certain security events affecting at least 500 consumers to the FTC. Firms should confirm their reporting responsibilities with qualified legal and cybersecurity advisers.

The frameworks work together. The Security Six provides a practical technical baseline. The WISP and FTC Safeguards Rule turn security into a managed program with documented responsibility, oversight, testing, and improvement.

Must your WISP cover vendors and offshore teams?

Your security responsibilities include every service provider that receives, maintains, processes, or can access customer information.

This can include cloud platforms, IT providers, document-management vendors, outsourced bookkeepers, and offshore tax-preparation teams.

The FTC requires covered firms to select providers capable of maintaining appropriate safeguards, include security expectations in contracts, and periodically assess their providers.

Before granting access, review the provider’s:

  • Multi-factor authentication
  • Role-based access controls
  • Encryption
  • Audit logs
  • Confidentiality agreements
  • Incident-notification procedures
  • Staff access and offboarding controls
  • Independent security reports

A security badge or website claim is not enough. Firms should request evidence and confirm that the controls cover the services, systems, staff, and locations involved in the engagement.

CPA firms can use an offshore accounting provider evaluation guide to structure the broader due-diligence process.

For offshore tax preparation, firms must also evaluate consent requirements under Internal Revenue Code Section 7216. SafeBooks’ Section 7216 checklist for offshore tax preparation explains the separate, affirmative, signed, and dated consent process that may apply before Form 1040 information is disclosed outside the United States.

Outsourcing is not automatically a security weakness. The provider should be included in the firm’s WISP, restricted to the information needed for its role, and assessed before client data is shared.

SafeBooks welcomes that review and can explain its secure remote tax-preparation controls during due diligence.

Pre-busy-season tax firm data security checklist

Before busy season, confirm that your firm has completed these actions:

  • Activate all six Security Six controls on every relevant system.
  • Review the WISP against current staff, software, devices, and vendors.
  • Assign clear ownership for the information security program.
  • Require MFA across tax software, email, portals, storage, and remote access.
  • Train staff on phishing, impersonation, and file-sharing risks.
  • Remove dormant accounts and unnecessary administrator privileges.
  • Test backup restoration and record the result.
  • Confirm IRS, state, insurer, legal, and FTC incident-reporting steps.
  • Identify every third party with access to client information.
  • Review evidence of each provider’s security controls.
  • Address Section 7216 consent where required.
  • Record outstanding fixes, responsible owners, and completion dates.

Data security is a before-busy-season task. Confirm the Security Six, bring the WISP in line with current operations, test the recovery process, and hold everyone with access to client data to a documented standard.

Then busy season can begin with one less unresolved risk.

FAQS

Is a WISP required for tax preparers?

Yes. Federal law requires professional tax preparers to create and maintain a written information security plan for protecting client data. The plan should reflect the firm’s size, activities, systems, vendors, and information risks.

The Security Six are anti-virus and anti-malware protection, firewalls, multi-factor authentication, backups, drive encryption, and a VPN for remote access. They are baseline controls, not a complete security program.
It applies when a tax or accounting firm meets the rule’s definition of a covered financial institution. The FTC expressly identifies tax-preparation firms as an example.
Yes, when those teams can access customer information. The WISP should address provider selection, contractual safeguards, access restrictions, monitoring, incident procedures, and offboarding.
Include a documented WISP review in the annual pre-busy-season process. Update it whenever material changes affect risk, including new systems, employees, locations, access methods, or service providers.
  • Director (CA, CPA (USA))

    Shivangi is a U.S.-certified CPA and Chartered Accountant with deep expertise in U.S. tax, financial reporting, and audit compliance. She has supported CPA and EA firms across sectors like real estate, SaaS, and healthcare. At SafeBooks, she leads global delivery, ensuring every remote accounting team meets U.S. standards with accuracy, discipline, and client-first execution.

Related Blogs

Ready to Build a Smarter Accounting Team?

Let’s simplify your operations with secure, scalable, and U.S.-aligned remote staffing.