The FTC Safeguards Rule (16 CFR Part 314), the Federal Trade Commission regulation that sets data security requirements for non-banking financial institutions under the Gramm-Leach-Bliley Act, requires every covered business to designate one Qualified Individual to oversee, implement, and enforce its information security program. Tax preparation businesses fall under this rule because the IRS treats tax return preparers as financial institutions for GLBA purposes, a point the IRS reinforces in IRS Publication 4557 requirements 2026. The designation requirement took effect on June 9, 2023, and it remains in force today.
The rule does not require a specific certification, degree, or job title. What it requires is a named person, inside the firm or outsourced, with the knowledge and authority to run the security program day to day.
Quick Answer
The FTC Safeguards Rule (16 CFR 314.4(a)) requires covered businesses, including most tax preparation firms, to designate a Qualified Individual responsible for their information security program. This person can be an employee, an affiliate, or a contracted service provider such as a managed security firm. The rule sets no required certification; it requires demonstrated ability to design, implement, and oversee safeguards appropriate to the size and complexity of the business, and to report on the program's status at least annually.
Who Can Serve as the Qualified Individual
The FTC's own guidance is explicit that the Qualified Individual does not need a particular license, degree, or years of security experience. According to the FTC's Safeguards Rule business guidance, the qualification standard is functional: the person must have the knowledge and ability needed to implement and oversee an information security program that fits your firm's size, complexity, and the sensitivity of the data you handle.
For a five-person tax practice, that could reasonably be the owner or office manager who takes on the role alongside their other duties, provided they can actually run the program: tracking risk assessments, verifying that safeguards like CPA and accounting firm cybersecurity controls are in place, and documenting decisions. For a firm without that internal capacity, the rule expressly permits outsourcing the role to a qualified outside individual or firm, such as a managed security provider retained under contract.
Outsourcing Doesn't Remove Your Obligation
If you outsource the Qualified Individual function, 16 CFR 314.4(a) still requires you to designate a senior member of your own staff to direct and oversee the outside party's work. You cannot hand the role to a vendor and walk away from it. The contracted Qualified Individual reports to that internal senior staff member, who in turn is accountable for the program overall.
What the Qualified Individual Must Actually Do
- Oversee a written risk assessment covering the firm's systems, vendors, and client data flows
- Design and implement the safeguards documented in the firm's written information security plan (WISP)
- Oversee service providers, including IT vendors and cloud tools, that touch client data
- Evaluate and adjust the program as the firm's risks, staffing, or technology change
- Report in writing at least annually to the owner, partners, or governing body on the program's status, including incidents and material changes
Why This Comes Up for Tax Practices Specifically
Tax preparers, accountants, and bookkeepers who prepare returns or handle client financial data are treated as "financial institutions" under GLBA and the Safeguards Rule, which is why the requirement shows up alongside IRS IRS WISP template guidance rather than being limited to banks and lenders. The IRS's Security Six framework, described in the IRS Security Six checklist for tax professionals, and the broader IRS cybersecurity compliance guide, both assume a firm already has a designated person accountable for security decisions. Without that designation, a firm's written plan has no clear owner, which becomes a documentation gap during an audit, an insurance renewal, or after an incident.
Compliance Deadline Has Already Passed
The Qualified Individual designation requirement took effect on June 9, 2023, after the FTC extended the original deadline by six months. If your firm has not formally named a Qualified Individual and documented that decision in your written information security plan, that gap can complicate a regulatory inquiry or a data breach response. See the consequences of tax practice non-compliance for what an unaddressed gap can mean.
Documenting the Designation
The designation itself needs to be in writing, not just understood internally. Most firms record it inside their written information security plan, naming the Qualified Individual, describing their reporting line, and outlining how the annual report to leadership will be handled. If you're building this from scratch, a WISP template for tax preparers gives you a starting structure rather than a blank page.
Firms that lack the internal staff time to fill this role often outsource it to a firm already handling their penetration testing or managed detection needs, since that provider is already positioned to track risk and report on it. If you're deciding between building this in-house versus outsourcing, the tradeoffs are similar to choosing between a cybersecurity company vs MSP for ongoing security operations generally.
Get Your WISP and Qualified Individual Documentation in Order
Bellator Cyber Guard builds a custom written information security plan starting at $749 for firms with up to 5 users, with larger practices quoted separately. It documents your Qualified Individual designation, risk assessment, and safeguards in the format examiners and cyber insurers expect. Book a free consultation to see what your firm needs.
Frequently Asked Questions
No. The FTC Safeguards Rule does not require any specific certification, degree, or credential. It requires that the person have sufficient knowledge and authority to design, implement, and oversee the firm's information security program, a standard the FTC scales to the size and complexity of the business.
Yes, provided they can meet the functional requirements: overseeing a risk assessment, maintaining safeguards, and documenting an annual review of the program. Many sole proprietors serve in this role themselves, though some choose to outsource oversight to a managed security provider to reduce their own workload.
The Safeguards Rule doesn't specify a fixed fine for a missing designation on its own, but the gap becomes a liability if a breach or examination occurs, since it signals the security program lacks documented ownership. See non-compliance consequences for tax practices for how gaps like this typically surface.
They're related but not identical. The FTC Safeguards Rule sets the underlying legal requirement for a designated Qualified Individual under 16 CFR 314.4(a). The IRS references this requirement in Publication 4557 and expects tax preparers' written information security plans to reflect it, but the WISP itself is the document where firms typically record the designation and the individual's responsibilities.
Yes. The rule allows the role to be filled by an employee, an affiliate, or a contracted outside party. If outsourced, the firm must still designate a senior internal staff member to direct and oversee that outside party's work, so accountability doesn't leave the business entirely.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.

