Skip to content
Bellator Cyber Guard
Tax21 min readDeep Dive

FTC Safeguards Rule Vendor Oversight for Tax Firms

Learn FTC Safeguards Rule service provider oversight requirements for tax preparers and build a practical vendor review process. Review your gaps.

By Bellator Cyber Guard Security Team
FTC Safeguards Rule Vendor Oversight for Tax Firms - ftc safeguards rule service provider oversight requirements tax preparers

Tax preparers subject to the FTC Safeguards Rule need a documented process for choosing, contracting with, and periodically reviewing service providers that handle or can affect the security of customer information. In practical terms, you should know which vendors can access taxpayer data, evaluate their security before onboarding, require reasonable safeguards in writing, and revisit the decision when risk or the service changes. A one-time software purchase list is not enough.

The Federal Trade Commission rule does not require every small tax firm to perform enterprise-style audits of every vendor. It does require a risk-based approach that you can explain and document. This matters because cloud tax software, document portals, managed IT providers, payroll systems, email platforms, backup vendors, and contractors can all create a path to sensitive client information or firm systems.

Key Takeaway

For a tax practice, vendor oversight means matching the depth of review to the data, access, and business dependence involved. Keep evidence of your selection decision, contractual safeguards, and periodic review in your written information security program.

What the FTC Safeguards Rule requires from tax preparers

The FTC Safeguards Rule implements security requirements under the Gramm-Leach-Bliley Act for covered financial institutions. Many professional tax preparation and accounting firms fall within its scope because they provide tax preparation services involving customer financial information. Whether the rule applies to your particular business is a legal question to review with counsel.

Section 314.4(f) requires covered businesses to periodically assess service providers based on the risk they present and to maintain contractual provisions requiring providers to implement and maintain safeguards for customer information. The rule also calls for a written information security program, a designated Qualified Individual, risk assessment, safeguards, testing or monitoring, incident response planning, and ongoing program evaluation.

The IRS gives tax professionals related practical guidance in irs publication 4557 requirements 2026. IRS Publication 4557 explains that tax professionals should protect taxpayer data and consider the security practices of third parties that may access that information. IRS Publication 5708 provides a guide for creating a Written Information Security Plan, often called a WISP.

Match vendor review to the risk the provider creates

Typical example

Lower-risk provider
Office supply or scheduling tool with no taxpayer data
Higher-risk provider
Tax software, portal, managed IT, backup, or payroll vendor

Access and data review

Lower-risk provider
Confirm no customer information or production-system access
Higher-risk provider
Document data types, access roles, integrations, and subcontractors

Security evidence

Lower-risk provider
Written privacy and security representations may be enough
Higher-risk provider
Review security documentation, incident process, MFA, encryption, backup, and access controls

Contract expectation

Lower-risk provider
Use terms appropriate to the limited exposure
Higher-risk provider
Include safeguards, notification, cooperation, access, and data-return or deletion terms

Which service providers deserve the closest review

Start with providers that store taxpayer data, connect to your network, administer accounts, or can interrupt your ability to serve clients. A service provider is broader than a company that directly hosts returns. A managed service provider with remote access, an email-security vendor with mailbox visibility, or a contractor using a firm-issued laptop may all need to be on your oversight list.

  • Tax workflow vendors: tax preparation software, e-file services, client portals, document collection, e-signature, practice management, and payment processors.
  • Technology providers: managed IT, managed detection and response, cloud storage, backup, email, identity providers, remote support, and internet-connected phone systems.
  • People and professional services: seasonal preparers, outsourced bookkeeping, transcription, scanning, shredding, and marketing vendors that receive client lists.

Do not overlook informal arrangements. A contractor forwarding returns to a personal email address, a partner sharing a consumer cloud-storage folder, or a former IT provider retaining an administrator account can create a documentation gap and an avoidable security exposure. Your inventory should identify the business owner, service provided, information handled, system access, contract location, review date, and next review date.

Vendor oversight also connects directly to the threats tax firms see during filing season. Review phishing attacks on tax professionals with your staff and vendors who administer mailboxes or remote access, because a compromised privileged account can expose far more than one inbox.

A practical service-provider oversight workflow

1

Build and classify your vendor inventory

List every provider and contractor. Mark whether each one stores taxpayer data, processes it, can access it, or can affect the security or availability of a firm system.

2

Set a risk tier before you buy or renew

Consider data sensitivity, access level, integration with your systems, remote administration rights, business dependence, and whether the provider uses subcontractors.

3

Collect evidence that fits the tier

For higher-risk vendors, review security documentation and ask focused questions about identity controls, encryption, incident handling, backups, logging, employee access, and offboarding.

4

Put safeguards into the agreement

Confirm the contract requires appropriate safeguards and addresses incident notification, cooperation, permitted use, access restrictions, and data return or disposal when the relationship ends.

5

Record the approval and review it again

Keep the decision, evidence reviewed, contract link, exceptions, owner, and next review date with your WISP records. Reassess after a material change, a security incident, or a change in the vendor's access.

Questions to ask a vendor before granting taxpayer-data access

Ask questions that produce usable answers, not a generic assurance that security is important. A small firm does not need to demand every provider use the same controls. You do need enough information to decide whether its safeguards are appropriate for the access you plan to provide.

  • What customer information will you store, process, transmit, or be able to access?
  • Which employees, contractors, and subcontractors can access that information, and how is access removed when roles change?
  • Do you require multi-factor authentication for administrative and remote access?
  • How do you encrypt customer information in transit and at rest?
  • What is your process for detecting, containing, and notifying customers about a security incident affecting their information?
  • How are backups protected and tested if your service is needed to restore operations?
  • Will you use subcontractors, and how do you oversee their access and safeguards?
  • At termination, how can our firm retrieve data and confirm return or deletion where appropriate?

Record unanswered questions and compensating controls. For example, if a vendor cannot offer a security document because it is a very small provider, you may decide to limit the data shared, prohibit direct system access, use a separate account with multi-factor authentication, or choose another provider. The point is to make and document a reasoned decision.

According to Verizon's 2025 Data Breach Investigations Report, third-party involvement in breaches reached 30 percent, double the prior year's figure. That statistic does not mean every vendor is unsafe. It does show why a tax practice should treat third-party access as part of its own risk management rather than as someone else's problem.

Service-provider oversight checklist for your WISP

  • Maintain a current vendor and contractor inventory, including taxpayer-data and system-access details.
  • Assign each provider a risk tier based on data, access, integration, and operational dependence.
  • Keep selection evidence and security answers for higher-risk providers.
  • Review contracts for safeguards, incident notification, and data-handling responsibilities.
  • Remove accounts and recover or revoke access when a contract or worker relationship ends.
  • Set a periodic review date and reassess after a material change or security event.

What good documentation looks like for a small tax practice

A defensible vendor file is usually simple and repeatable. It should show that you identified the provider, understood the access involved, reviewed information appropriate to the risk, included reasonable safeguards in the agreement, and set a future review point. Save a dated copy of the agreement, security questionnaire or documentation, approval notes, and any exceptions.

Place the workflow in your WISP so it becomes part of normal purchasing and renewal, rather than a spreadsheet nobody sees until an incident. An irs wisp template can give you the starting structure, but it must reflect your actual vendors, systems, roles, and review process. A copied template that says you conduct reviews when no one owns the task will not help you manage risk.

If you use an outside IT provider, define the boundary clearly. The provider may supply technical evidence and help operate controls, but firm leadership still needs to approve vendors, understand where client data goes, and retain oversight records. This is one reason the distinction between a cybersecurity company vs msp matters when you evaluate support. Ask who monitors endpoints, who can administer identity accounts, what happens after an alert, and what documentation you receive for your WISP.

Important contract limitation

A vendor contract can support your Safeguards Rule program, but it does not transfer all responsibility for your firm’s customer information. Review contracts and any legal interpretation with qualified counsel, especially when a provider processes large volumes of taxpayer data or has privileged access.

When managed endpoint security supports vendor oversight

Vendor oversight cannot compensate for unmanaged computers inside your own firm. If an IT provider, seasonal worker, or remote contractor uses a system that can reach taxpayer records, you need a clear endpoint standard, account controls, and a process for removing access. Endpoint detection and response can improve visibility into suspicious activity and support incident investigation, but it does not guarantee prevention of a breach.

Bellator Cyber Guard offers Bellator Shield managed EDR for $19 per computer per month. It is a managed endpoint detection and response service for firms that need focused endpoint coverage. Bellator Core is $33 per computer per month and adds remote monitoring and Ransomware Rollback®; see protection plan details to compare the scope. These are managed-service offers, so they should not be compared as if they were license-only software prices.

For the policy and documentation side, Bellator provides a custom WISP starting at $749 for up to 5 users. Larger practices receive a custom quote. A tailored WISP can save a firm a reasonable 20 to 40 billable hours compared with assembling and adapting policy materials alone, while still requiring you to validate that the document reflects real operations. For a broader control baseline, use the irs cybersecurity compliance guide alongside your vendor-review process.

Book a Free Tax Cybersecurity Assessment

Get plain-language help identifying vendor oversight gaps, endpoint risks, and the controls that fit your tax practice. No pressure.

Frequently Asked Questions

No. The rule requires periodic, risk-based assessment of service providers and contractual safeguards. The depth of review should reflect the provider’s access to customer information, access to your systems, and the impact if its service is disrupted or compromised.

Include vendors and contractors that store, process, transmit, or can access taxpayer information, as well as providers with administrative or remote access to firm systems. This commonly includes tax software, portals, email, cloud storage, managed IT, backups, payroll, and seasonal personnel.

No. A template can organize your process, but your WISP needs current vendor information, assigned responsibilities, review dates, and records showing how you apply the process. IRS guidance and the FTC rule focus on implementing safeguards, not merely possessing a document.

Set a recurring schedule based on risk, then review sooner when a provider changes ownership, access, data use, subcontractors, contract terms, or incident history. Higher-risk providers generally justify more frequent attention than vendors with no taxpayer-data or system access.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

From requirement to defensible practice

Turn IRS and FTC expectations into a WISP your office can follow

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

People also look for

Keep exploring Tax security & WISP

Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.