WorldTech Blog

IT Compliance for CPA Firms: FTC Safeguards & IRS Pub 4557

Written by WorldTech Team | Aug 7, 2026, 6:51:00 PM

Accounting firms sit on exactly the data criminals want — Social Security numbers, financial records, and tax information for hundreds of clients. That's why the rules governing how you protect it have gotten stricter. If you run a CPA or accounting firm, here's what you need to know about IT compliance, in plain terms.

This is a general overview, not legal advice — confirm your specific obligations with a qualified advisor.

The FTC Safeguards Rule

Under the Gramm-Leach-Bliley Act, tax and accounting professionals are considered "financial institutions" and must comply with the FTC Safeguards Rule. In practice, that means maintaining a written information security program with specific safeguards, including:

  • A designated person responsible for security (a "Qualified Individual")
  • A written risk assessment
  • Access controls and encryption of customer data
  • Multi-factor authentication for anyone accessing sensitive systems
  • Continuous monitoring or regular testing
  • Vendor oversight and an incident response plan
  • Security awareness training for staff

Non-compliance carries real penalties — and, just as important, real risk to your clients and reputation.

IRS Publication 4557 and your WISP

The IRS requires paid tax preparers to have a Written Information Security Plan (WISP), and Publication 4557 ("Safeguarding Taxpayer Data") lays out the expected protections. A WISP documents how your firm secures client data — the administrative, technical, and physical safeguards you have in place. It's not optional, and "we'll write it later" is a common, costly gap.

What this looks like day to day

Meeting these requirements isn't a one-time project — it's an ongoing security posture:

  • Multi-factor authentication everywhere sensitive data lives
  • Encryption of data at rest and in transit
  • Managed, monitored endpoints so threats are caught early
  • Tested backups so you can recover from ransomware or failure
  • Staff training, since phishing is the most common way firms get breached
  • Documentation proving you're doing all of the above

You don't have to navigate it alone

Most accounting firms don't have in-house IT security expertise — and shouldn't have to. An IT partner experienced with financial-sector compliance can implement the technical safeguards, help document your WISP, and keep everything monitored year-round. See how we did this for a real firm in our CPA firm case study, and learn what strong network and system security involves. Contact us for a confidential assessment.