
Tax preparers subject to the FTC Safeguards Rule need a documented process for choosing, contracting with, and periodically reviewing service providers that handle or can affect the security of customer information. In practical terms, you should know which vendors can access taxpayer data, evaluate their security before onboarding, require reasonable safeguards in writing, and revisit the decision when risk or the service changes. A one-time software purchase list is not enough.
The Federal Trade Commission rule does not require every small tax firm to perform enterprise-style audits of every vendor. It does require a risk-based approach that you can explain and document. This matters because cloud tax software, document portals, managed IT providers, payroll systems, email platforms, backup vendors, and contractors can all create a path to sensitive client information or firm systems.
Key Takeaway
For a tax practice, vendor oversight means matching the depth of review to the data, access, and business dependence involved. Keep evidence of your selection decision, contractual safeguards, and periodic review in your written information security program.
What the FTC Safeguards Rule requires from tax preparers
The FTC Safeguards Rule implements security requirements under the Gramm-Leach-Bliley Act for covered financial institutions. Many professional tax preparation and accounting firms fall within its scope because they provide tax preparation services involving customer financial information. Whether the rule applies to your particular business is a legal question to review with counsel.
Section 314.4(f) requires covered businesses to periodically assess service providers based on the risk they present and to maintain contractual provisions requiring providers to implement and maintain safeguards for customer information. The rule also calls for a written information security program, a designated Qualified Individual, risk assessment, safeguards, testing or monitoring, incident response planning, and ongoing program evaluation.
The IRS gives tax professionals related practical guidance in irs publication 4557 requirements 2026. IRS Publication 4557 explains that tax professionals should protect taxpayer data and consider the security practices of third parties that may access that information. IRS Publication 5708 provides a guide for creating a Written Information Security Plan, often called a WISP.
Match vendor review to the risk the provider creates
Typical example
- Lower-risk provider
- Office supply or scheduling tool with no taxpayer data
- Higher-risk provider
- Tax software, portal, managed IT, backup, or payroll vendor
Access and data review
- Lower-risk provider
- Confirm no customer information or production-system access
- Higher-risk provider
- Document data types, access roles, integrations, and subcontractors
Security evidence
- Lower-risk provider
- Written privacy and security representations may be enough
- Higher-risk provider
- Review security documentation, incident process, MFA, encryption, backup, and access controls
Contract expectation
- Lower-risk provider
- Use terms appropriate to the limited exposure
- Higher-risk provider
- Include safeguards, notification, cooperation, access, and data-return or deletion terms
| Feature | Lower-risk provider | RecommendedHigher-risk provider |
|---|---|---|
| Typical example | Office supply or scheduling tool with no taxpayer data | Tax software, portal, managed IT, backup, or payroll vendor |
| Access and data review | Confirm no customer information or production-system access | Document data types, access roles, integrations, and subcontractors |
| Security evidence | Written privacy and security representations may be enough | Review security documentation, incident process, MFA, encryption, backup, and access controls |
| Contract expectation | Use terms appropriate to the limited exposure | Include safeguards, notification, cooperation, access, and data-return or deletion terms |
Which service providers deserve the closest review
Start with providers that store taxpayer data, connect to your network, administer accounts, or can interrupt your ability to serve clients. A service provider is broader than a company that directly hosts returns. A managed service provider with remote access, an email-security vendor with mailbox visibility, or a contractor using a firm-issued laptop may all need to be on your oversight list.
- Tax workflow vendors: tax preparation software, e-file services, client portals, document collection, e-signature, practice management, and payment processors.
- Technology providers: managed IT, managed detection and response, cloud storage, backup, email, identity providers, remote support, and internet-connected phone systems.
- People and professional services: seasonal preparers, outsourced bookkeeping, transcription, scanning, shredding, and marketing vendors that receive client lists.
Do not overlook informal arrangements. A contractor forwarding returns to a personal email address, a partner sharing a consumer cloud-storage folder, or a former IT provider retaining an administrator account can create a documentation gap and an avoidable security exposure. Your inventory should identify the business owner, service provided, information handled, system access, contract location, review date, and next review date.
Vendor oversight also connects directly to the threats tax firms see during filing season. Review phishing attacks on tax professionals with your staff and vendors who administer mailboxes or remote access, because a compromised privileged account can expose far more than one inbox.
A practical service-provider oversight workflow
Build and classify your vendor inventory
List every provider and contractor. Mark whether each one stores taxpayer data, processes it, can access it, or can affect the security or availability of a firm system.
Set a risk tier before you buy or renew
Consider data sensitivity, access level, integration with your systems, remote administration rights, business dependence, and whether the provider uses subcontractors.
Collect evidence that fits the tier
For higher-risk vendors, review security documentation and ask focused questions about identity controls, encryption, incident handling, backups, logging, employee access, and offboarding.
Put safeguards into the agreement
Confirm the contract requires appropriate safeguards and addresses incident notification, cooperation, permitted use, access restrictions, and data return or disposal when the relationship ends.
Record the approval and review it again
Keep the decision, evidence reviewed, contract link, exceptions, owner, and next review date with your WISP records. Reassess after a material change, a security incident, or a change in the vendor's access.
Questions to ask a vendor before granting taxpayer-data access
Ask questions that produce usable answers, not a generic assurance that security is important. A small firm does not need to demand every provider use the same controls. You do need enough information to decide whether its safeguards are appropriate for the access you plan to provide.
- What customer information will you store, process, transmit, or be able to access?
- Which employees, contractors, and subcontractors can access that information, and how is access removed when roles change?
- Do you require multi-factor authentication for administrative and remote access?
- How do you encrypt customer information in transit and at rest?
- What is your process for detecting, containing, and notifying customers about a security incident affecting their information?
- How are backups protected and tested if your service is needed to restore operations?
- Will you use subcontractors, and how do you oversee their access and safeguards?
- At termination, how can our firm retrieve data and confirm return or deletion where appropriate?
Record unanswered questions and compensating controls. For example, if a vendor cannot offer a security document because it is a very small provider, you may decide to limit the data shared, prohibit direct system access, use a separate account with multi-factor authentication, or choose another provider. The point is to make and document a reasoned decision.
According to Verizon's 2025 Data Breach Investigations Report, third-party involvement in breaches reached 30 percent, double the prior year's figure. That statistic does not mean every vendor is unsafe. It does show why a tax practice should treat third-party access as part of its own risk management rather than as someone else's problem.
Service-provider oversight checklist for your WISP
- Maintain a current vendor and contractor inventory, including taxpayer-data and system-access details.
- Assign each provider a risk tier based on data, access, integration, and operational dependence.
- Keep selection evidence and security answers for higher-risk providers.
- Review contracts for safeguards, incident notification, and data-handling responsibilities.
- Remove accounts and recover or revoke access when a contract or worker relationship ends.
- Set a periodic review date and reassess after a material change or security event.
What good documentation looks like for a small tax practice
A defensible vendor file is usually simple and repeatable. It should show that you identified the provider, understood the access involved, reviewed information appropriate to the risk, included reasonable safeguards in the agreement, and set a future review point. Save a dated copy of the agreement, security questionnaire or documentation, approval notes, and any exceptions.
Place the workflow in your WISP so it becomes part of normal purchasing and renewal, rather than a spreadsheet nobody sees until an incident. An irs wisp template can give you the starting structure, but it must reflect your actual vendors, systems, roles, and review process. A copied template that says you conduct reviews when no one owns the task will not help you manage risk.
If you use an outside IT provider, define the boundary clearly. The provider may supply technical evidence and help operate controls, but firm leadership still needs to approve vendors, understand where client data goes, and retain oversight records. This is one reason the distinction between a cybersecurity company vs msp matters when you evaluate support. Ask who monitors endpoints, who can administer identity accounts, what happens after an alert, and what documentation you receive for your WISP.
Important contract limitation
A vendor contract can support your Safeguards Rule program, but it does not transfer all responsibility for your firm’s customer information. Review contracts and any legal interpretation with qualified counsel, especially when a provider processes large volumes of taxpayer data or has privileged access.
When managed endpoint security supports vendor oversight
Vendor oversight cannot compensate for unmanaged computers inside your own firm. If an IT provider, seasonal worker, or remote contractor uses a system that can reach taxpayer records, you need a clear endpoint standard, account controls, and a process for removing access. Endpoint detection and response can improve visibility into suspicious activity and support incident investigation, but it does not guarantee prevention of a breach.
Bellator Cyber Guard offers Bellator Shield managed EDR for $19 per computer per month. It is a managed endpoint detection and response service for firms that need focused endpoint coverage. Bellator Core is $33 per computer per month and adds remote monitoring and Ransomware Rollback®; see protection plan details to compare the scope. These are managed-service offers, so they should not be compared as if they were license-only software prices.
For the policy and documentation side, Bellator provides a custom WISP starting at $749 for up to 5 users. Larger practices receive a custom quote. A tailored WISP can save a firm a reasonable 20 to 40 billable hours compared with assembling and adapting policy materials alone, while still requiring you to validate that the document reflects real operations. For a broader control baseline, use the irs cybersecurity compliance guide alongside your vendor-review process.
Book a Free Tax Cybersecurity Assessment
Get plain-language help identifying vendor oversight gaps, endpoint risks, and the controls that fit your tax practice. No pressure.
Frequently Asked Questions
No. The rule requires periodic, risk-based assessment of service providers and contractual safeguards. The depth of review should reflect the provider’s access to customer information, access to your systems, and the impact if its service is disrupted or compromised.
Include vendors and contractors that store, process, transmit, or can access taxpayer information, as well as providers with administrative or remote access to firm systems. This commonly includes tax software, portals, email, cloud storage, managed IT, backups, payroll, and seasonal personnel.
No. A template can organize your process, but your WISP needs current vendor information, assigned responsibilities, review dates, and records showing how you apply the process. IRS guidance and the FTC rule focus on implementing safeguards, not merely possessing a document.
Set a recurring schedule based on risk, then review sooner when a provider changes ownership, access, data use, subcontractors, contract terms, or incident history. Higher-risk providers generally justify more frequent attention than vendors with no taxpayer-data or system access.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.



