FTC Safeguards Rule: the nine required elements, in plain English
What 16 CFR 314.4 actually asks a tax preparer, CPA, RIA, mortgage broker, or dealership to have in place, what the small-firm exemption covers, and how the 30-day breach clock works.
By Ed Wirsing, CISSP · Reviewed September 2026 · Not legal advice
Who this applies to
The Safeguards Rule (16 CFR Part 314) covers "financial institutions" under FTC jurisdiction. That phrase is broader than it sounds. The FTC's own examples include tax preparation firms, accountants, mortgage brokers and lenders, investment advisers not registered with the SEC, auto dealers that arrange financing, collection agencies, and finance companies. If you are a paid tax preparer, the IRS separately expects you to have a written data security plan (Publication 4557) and asks you to attest to it at PTIN renewal.
The nine elements of 314.4
Your written program must include all of these. In the WISP Build, each one becomes a section with an owner.
- A designated Qualified Individual. One person owns the program. It can be an employee or an outside provider, but if it is an outside provider, a senior person in your firm must retain oversight and the provider must report to them.
- A written risk assessment. Specific to your firm: where customer information lives, what could go wrong, how likely it is, and how bad it would be. A downloaded template that does not name your systems does not satisfy this.
- Safeguards designed from that assessment. The Rule names them: access controls and least privilege, an inventory of data and systems, encryption of customer information in transit and at rest, secure development practices for any in-house apps, multi-factor authentication for anyone accessing customer information, secure disposal of customer information no later than two years after last use, change management, and monitoring and logging of authorized user activity.
- Regular testing. Either continuous monitoring, or an annual penetration test plus vulnerability assessments at least every six months.
- Staff training and qualified security personnel. Security awareness training for everyone, and someone qualified (in-house or contracted) to run the program.
- Service provider oversight. Pick vendors that can protect the data, put it in the contract, and periodically check that they do. Your tax software, cloud storage, and IT provider all count.
- Keep the program current. Adjust it when testing finds something, when your business changes, or when something goes wrong.
- A written incident response plan. Goals, roles, internal processes, communication, remediation, documentation, and post-incident review.
- An annual written report to your board or senior officer. Prepared by the Qualified Individual: overall status, compliance, risk assessment results, testing results, incidents, and recommended changes.
The small-firm exemption (314.6)
If you maintain customer information on fewer than 5,000 consumers, you are exempt from four items: the written risk assessment, the continuous monitoring or annual pen test requirement, the written incident response plan, and the annual written report. You still need a Qualified Individual, the safeguards themselves, training, vendor oversight, and a program that is kept current. Most firms I work with build the exempt items anyway, because their insurer asks for them.
The 30-day breach clock (314.5)
Since May 13, 2024, a "notification event" involving unencrypted customer information of 500 or more consumers must be reported to the FTC within 30 days of discovery, through the FTC's online form. This is in addition to any state breach-notification law (Florida's is section 501.171) and any IRS reporting for tax preparers.
What the IRS adds for tax preparers
- Publication 4557 describes the safeguards the IRS expects, and Publication 5708 provides a WISP template and guidance.
- The "Security Six": antivirus, firewall, MFA, backups, drive encryption, and a VPN for remote work.
- Report data theft to your IRS Stakeholder Liaison and, for identity-theft returns, follow the IRS process for preparers.
A quick self-check
Answer honestly. Every "no" is a finding an examiner or insurer could make.
- Is one named person responsible for security, in writing?
- Do you have a risk assessment that names your actual systems and vendors?
- Is MFA on for email, tax software, cloud storage, and remote access?
- Is client data encrypted on laptops and in cloud storage?
- Do you have a list of every vendor that touches client data, with contracts that mention security?
- Has every employee had security training in the last 12 months?
- Do you know what you would do in the first 24 hours after a breach?
- Has ownership received a written security report in the last year?
If you answered "no" to three or more, you need the WISP Build. If you answered "no" only to the last two, you need a Qualified Individual and probably nothing else.
This guide pairs with the program page:
WISP & FTC Safeguards program →