James R. Evans, CEO, American Frontier
2026
What Most CPA Firms Get Wrong About the FTC Safeguards Rule — and What Compliance Actually Looks Like
I want to tell you about a conversation I have had more than once.
A CPA firm partner — smart, experienced, running a successful practice — is sitting across from me. I ask about the FTC Safeguards Rule. They nod. "We've got that covered," they say. "We paid someone to put together a WISP for us."
I ask if I can see it.
It is twelve pages long, cleanly formatted, and nearly useless. It describes security practices the firm does not actually follow. It names a "Qualified Individual" who had no idea they had been designated. It references an incident response process that has never been tested. It arrived, got filed, and no one has looked at it since.
"This is going to be a problem," I tell them.
They look surprised. They did what they were told. They have the document. Why is that not enough?
Here is the answer: because the FTC Safeguards Rule is not asking you for a document. It is asking you to run your firm differently.
What Is the FTC Safeguards Rule — and Does It Apply to CPA Firms?
Yes, it applies to your firm. The FTC Safeguards Rule (formally 16 CFR Part 314), enacted under the Gramm-Leach-Bliley Act, defines "financial institution" broadly. Tax preparers and accounting firms are explicitly named as covered entities. The FTC updated the Rule significantly in 2021 and added breach notification requirements that took effect in May 2024.
Violations can carry fines starting at $100,000 per incident. This is not a large-firm exemption. A solo CPA practice in Apex is covered the same as a national accounting firm.
The W-12 Problem: You Already Told the IRS You Know
Here is the detail that surprises most CPA firm partners when I share it.
Every year, when you renew your IRS e-filing credentials, you complete Form W-12. Box 11 of that form contains a certification you sign: that you are "aware that paid tax return preparers are required by law to create and maintain a written information security plan that provides data and system security protections for all taxpayer information."
You have signed that statement. Probably multiple times. You told the IRS, in writing, that you understand this obligation exists.
That creates a very specific problem if something goes wrong and you do not have a real program in place. You cannot claim you did not know. You signed a form saying you did.
This is not meant to alarm you. It is meant to reframe what compliance actually requires of you — and why a generic template does not clear the bar.
What the Safeguards Rule Actually Requires: The 9 Elements
The Rule mandates nine specific elements in your information security program. Here are the ones that most often catch CPA firms off guard:
1. Designate a Qualified Individual. Someone must own your security program — actively supervise it, understand what is in it, and report on it in writing at least annually to your firm's leadership. The FTC is clear: this person can be an employee, or they can be outsourced to a qualified service provider. But the buck still stops with you. Outsourcing the role does not outsource the accountability. If you use an outside firm to fill this seat, a senior person inside your firm must still supervise that relationship and understand what the program covers.
2. Conduct a written risk assessment — and keep it current. Not a one-time exercise. Whenever operations change — new staff, new software, new client workflows — the assessment must be revisited. It must be written, and it must identify real risks, not just confirm that you have antivirus software.
3. Implement multi-factor authentication (MFA) on every system that accesses customer information. This is a mandate. Email. Tax software. Client portals. Cloud storage. Every point of access. A username and password alone does not meet the standard.
4. Encrypt customer information in transit and at rest. That unprotected PDF you emailed to a client? The laptop a staff member takes home with twelve years of client records on it? Both represent real exposure — to your clients and to your firm's legal liability.
5. Train your staff — regularly. The FTC's own language is pointed: "A financial institution's information security program is only as effective as its least vigilant staff member." One-time training does not meet the standard. Neither does a login to a compliance module from three years ago.
6. Create a written incident response plan — and test it. The plan must include clear roles, decision-making authority, communication protocols, a process to document and report events, and a post-mortem requirement. "Contact IT if something goes wrong" is not a plan.
7. Notify the FTC within 30 days of a qualifying breach. If unauthorized access involves 500 or more consumers' unencrypted data, you have 30 days from discovery to file a report with the FTC. Most small CPA firms have never heard this requirement exists.
8. Monitor and test your safeguards. This means either continuous monitoring or annual penetration testing plus vulnerability scans every six months. Not a firewall that no one has checked since it was installed.
9. Require your Qualified Individual to report to firm leadership in writing, at least annually. That report must cover your program's status, risk assessment findings, test results, security incidents, and recommendations for improvement. This is an active governance requirement, not a passive one.
The WISP: Required, But Routinely Misunderstood
A Written Information Security Plan is required — by the IRS, by the FTC Safeguards Rule, and by IRS Publications 5708, 5709, 4457, and 5417. There is no ambiguity here.
What is misunderstood is what the WISP is supposed to be.
A WISP is not a compliance certificate. It is a description of how your firm actually operates — what systems you have, who has access to what, how you protect client data, how you train your team, how you respond to incidents, and how you verify the program is working.
The FTC is explicit: your program "must be appropriate to the size and complexity of your business, the nature and scope of your activities, and the sensitivity of the information at issue."
That sentence rules out a generic template. It demands something specific to your firm.
A WISP that does not reflect how your firm actually operates is not an asset. It is a liability. When a regulator or a plaintiff's attorney asks to see your security program after an incident, a document describing practices your firm never implemented becomes evidence of negligence — proof that you knew what was expected and chose not to do it.
The Real Question: What Can You Actually Show an Auditor or Attorney?
I want to spend a moment on this because it is the part that matters most.
After a security incident, there are four groups who will want to see evidence of your security program. Insurance carriers reviewing your cyber claim. Attorneys retained by affected clients. IRS examiners. FTC enforcement staff. They all ask the same question: Can you prove it?
Not "do you have a document?" — but can you demonstrate, with evidence, that your firm actually operates the way your WISP says it does?
That evidence looks like this:
- Signed security acknowledgments — your Acceptable Use Policy, signed by every employee
- A current, acknowledged Incident Response Plan — signed off by firm leadership, not just filed
- Security awareness training records — dates, who attended, what was covered, when it was last updated
- Signed risk acceptances — formal documentation for any recommendation your firm reviewed and declined, shifting the liability appropriately
- A current security posture report — showing your controls, their status, and your remediation roadmap
- Access control logs — showing who has access to what, and that you review it periodically
- Backup and recovery test records — confirming your backups have actually been restored and validated
If a breach occurred tonight and litigation followed six months from now, the question would not be whether you had good intentions. It would be whether you can produce this paper trail. The firms that survive that question are the ones who built their program around documentation and evidence from the start — not the ones who filed a WISP template and hoped for the best.
What I See in the Field
In my conversations with CPA firms across the Triangle, I encounter three situations.
The first: They have never heard of the FTC Safeguards Rule at all. They are genuinely surprised to learn it applies to them — and unsettled when they understand what they hold. Complete financial pictures of hundreds of clients. Social Security numbers. Bank account details. Business financials going back years. All of it potentially sitting behind nothing more than a username and password.
The second: They have heard of the Rule and have done something about it. Someone sold them a WISP. They feel covered. The gap between that sense of security and the actual requirements — especially the evidence and documentation requirements — is where the exposure lives.
The third: They know exactly what they need to do but have not gotten around to it. Tax season. Extension season. Year-end planning. There is always a more urgent priority. I understand this deeply. But the clock on these requirements does not stop because you are busy.
None of these positions represent carelessness. CPAs are extraordinary professionals. This simply is not what you trained for. And when the guidance you received was incomplete, a different outcome was not realistic.
The part I cannot soften: lack of intent does not change the outcome when something goes wrong.
How a Real Program Differs From a Template
Building a real information security program for a CPA firm starts with an honest assessment of your actual environment — not a checkbox exercise. It answers operational questions:
- Who in this firm has access to which client data, and how do we know?
- How do we verify that someone requesting a password reset is actually who they say they are?
- When did we last confirm that every employee has MFA active on every system they use?
- When did we last test a full restore from our backups?
- What do we do in the first 24 hours if we suspect a breach?
- When did we last review and update our incident response plan?
From that assessment, you build the program. You designate the right Qualified Individual — whether internal or outsourced — and make sure someone senior inside the firm is actively supervising that role. You implement the technical controls. You document every step, every recommendation, every decision. And you keep the evidence.
A WISP that describes the firm that actually exists, rather than an idealized version of it, becomes a genuine asset when it is time to prove your program works.
How American Frontier Helps CPA Firms Close This Gap
Most IT providers install tools and move on. Antivirus. A firewall. Maybe MFA. They hand you a bill and call it security.
That is not what the FTC Safeguards Rule requires, and it is not what we do.
At American Frontier, we have a service specifically designed for firms facing this compliance challenge: Cyber Liability Guard. It is built around the principle that protection and defensibility are two different jobs — and both need to be done.
The protection work — the tools, monitoring, MFA, encryption, endpoint security — is the technical side. Cyber Liability Guard handles the other side: building and maintaining the documented, evidenced security program that holds up under scrutiny.
That means we work with your firm to:
- Conduct the written risk assessment the Rule requires
- Designate and document your Qualified Individual (and serve in that role if appropriate, with your senior oversight)
- Build a real, firm-specific WISP — not a template
- Create and maintain your Incident Response Plan, acknowledged by firm leadership
- Establish Acceptable Use Policies and get them signed by your team
- Maintain your security awareness training records
- Document every security recommendation, and capture formal signed acknowledgments for anything your firm declines
- Produce the written annual report to firm leadership that the Rule requires
- Build and maintain the evidence file — the paper trail that protects you with insurers, regulators, and attorneys
This is the work that a generic WISP template was never going to do for you. And it is the work that actually puts you in a defensible position.
A Question Worth Sitting With
The IRS has your signature on Form W-12 certifying that you understand this obligation.
So here is the honest question: if a regulator or an attorney retained by an affected client asked to see your information security program tomorrow — not your WISP template, but evidence of how your firm actually operates — what would you be able to show them?
If the honest answer is "not much," that is your starting point. Not a reason for panic. A reason to act.
I have helped CPA firms across the Triangle build programs that meet the actual requirements — that hold up to scrutiny, that their teams actually follow, and that protect what those teams have spent careers building.
If you want to know where your firm stands, I am glad to have that conversation. No jargon. No pressure. Just an honest look at the gap between where you are and where you need to be.
James R. Evans is the Founder and CEO of American Frontier, LLC, a cybersecurity and managed IT services company headquartered in Apex, North Carolina. He is a two-time bestselling author and co-authored Empathy and Understanding in Business with former FBI hostage negotiator Chris Voss. He holds 37 issued US patents and has been protecting the technology and livelihoods of businesses in the Triangle and beyond for over 30 years. To schedule a free 15-minute discovery call, visit amfrontier.net or call 919-741-5468.
