The Dangerous Assumption
Your firm serves 200 business clients. You've been in practice for decades, built a reputation for excellence, and take client confidentiality seriously. When you hear about the FTC Safeguards Rule and its requirements for firms handling more than 5,000 consumer records, you do the math: 200 clients, well under the threshold. You assume certain requirements don't apply to you.
You're almost certainly wrong.
The 5,000 threshold doesn't count clients—it counts individual consumer records. And that distinction changes everything for CPA firms. A firm with 200 business clients routinely maintains tax records, W-2s, and financial data for thousands of individual employees, shareholders, and beneficiaries. What looks like a modest client roster often translates to 10,000, 15,000, or more individual consumer records.
This misunderstanding isn't just common—it's pervasive. And it leaves accounting firms exposed to regulatory enforcement, cyber insurance gaps, and the kind of data breach liability that can end a practice.
Why CPA Firms Are 'Financial Institutions'
The FTC Safeguards Rule exists under the Gramm-Leach-Bliley Act (GLBA), which requires "financial institutions" to protect consumer financial information. When most people hear "financial institution," they think of banks. But the GLBA definition is far broader.
The FTC explicitly identifies tax preparers and accounting firms as covered financial institutions. If your firm prepares tax returns, provides financial planning services, or handles client financial data in any capacity, the Safeguards Rule applies to you. There's no revenue threshold, no employee minimum, no exemption for professional services firms.
The revised Safeguards Rule (16 CFR Part 314) took full effect on June 9, 2023, introducing specific technical requirements that go well beyond the original "reasonable safeguards" standard. As of May 13, 2024, covered institutions must also notify the FTC within 30 days of discovering a breach affecting 500 or more consumers.
This isn't a gray area. The FTC has published guidance specifically addressing tax preparers and has pursued enforcement actions in the financial services sector. CPA firms are squarely within scope.
The 5,000 Consumer Threshold: What It Actually Means
The Safeguards Rule includes a provision that exempts certain firms from two specific requirements—maintaining a written incident response plan and providing annual reports to the board—if they maintain information on fewer than 5,000 consumers. This limited exemption has created widespread confusion about who must comply with what.
The critical distinction: The threshold counts individual consumer records, not client relationships.
A "consumer" under GLBA is any individual whose personal information you maintain. For a CPA firm, this includes:
- Individual taxpayers whose returns you prepare
- Employees of business clients (from payroll processing, W-2s, benefits administration)
- Shareholders and partners of business entities
- Beneficiaries named in trusts and estates
- Dependents listed on tax returns
- Historical records from prior years that you retain
A worked example:
Consider a regional CPA firm with 200 business clients. If those businesses average 50 employees each, the firm maintains W-2 data alone for 10,000 individuals. Add individual tax clients, shareholder information, trust beneficiaries, and five years of historical records, and the actual consumer count often reaches 15,000 to 25,000—five times what the firm assumed.
What this means for compliance: Firms under the 5,000 threshold are exempt from Elements 8 and 9 only (written incident response plan and board reporting). They must still comply fully with Elements 1 through 7, which include designating a Qualified Individual, conducting risk assessments, implementing technical safeguards, and maintaining an ongoing security program.
Most mid-sized CPA firms, once they count correctly, find they exceed the threshold. And even firms that genuinely fall below 5,000 records face the same core compliance requirements that drive the majority of implementation effort.
The 9 Required Elements: A CPA Firm Perspective
The FTC Safeguards Rule mandates nine specific elements for an information security program. Here's what each means for accounting practices.
Element 1: Designate a Qualified Individual
Your firm must appoint someone responsible for implementing and overseeing the security program. This can be an employee, someone at an affiliate, or a third-party service provider such as a virtual CISO (vCISO). The firm retains ultimate responsibility regardless of who fills the role. For most mid-sized CPA firms without dedicated IT security staff, a vCISO arrangement provides the required expertise without the overhead of a full-time hire.
Element 2: Conduct Written Risk Assessments
You must document a risk assessment identifying where consumer information is collected, stored, and transmitted. For CPA firms, this means mapping data flows through tax software, client portals, email systems, cloud storage, and any other systems touching client financial data. The assessment must be updated as your technology environment changes.
Element 3: Design and Implement Safeguards
Based on your risk assessment, implement controls addressing access management, data encryption, and multi-factor authentication (MFA). The rule specifically requires MFA for anyone accessing customer information. For CPA firms, this extends to tax software, document management systems, client portals, and remote access. You must also implement secure disposal procedures for data no longer needed and conduct access reviews when staff members change roles or leave the firm.
Element 4: Monitor and Test Systems
The rule requires continuous monitoring or periodic testing of your safeguards. This typically means annual penetration testing, semi-annual vulnerability assessments, and ongoing system monitoring. Many cyber insurance policies now require penetration testing as a condition of coverage, so this element often aligns with existing insurance obligations.
Element 5: Provide Security Training
All personnel must receive security awareness training upon hire and at least annually thereafter. Given that accountants are high-value targets—especially during tax season—training should emphasize phishing recognition, social engineering tactics, and secure handling of client data. Key security personnel need additional specialized training on current threats and countermeasures.
Element 6: Oversee Service Providers
You must evaluate the security capabilities of vendors with access to customer data, require contractual security commitments, and periodically assess their compliance. For CPA firms, this includes tax software vendors, cloud hosting providers, IT support companies, and any other third parties handling client information.
Element 7: Maintain the Program
Your security program must be reviewed and updated at least annually, with adjustments for new threats, technology changes, and business developments. Opening a new office, adopting new software, or expanding remote work capabilities all trigger the need for program updates.
Element 8: Create a Written Incident Response Plan
Required for 5,000+ recordsDocument roles, responsibilities, and procedures for responding to security incidents. The plan must address FTC notification requirements (30 days for breaches affecting 500+ consumers) and applicable state breach notification laws, which vary significantly in their timing and disclosure requirements.
Element 9: Report to Board/Leadership
Required for 5,000+ recordsThe Qualified Individual must provide written reports to the board of directors or equivalent governing body at least annually. For partnerships, this means formal reporting to partners on the firm's security posture, risk assessment findings, and any security incidents.
The Cyber Insurance Connection
FTC Safeguards compliance increasingly intersects with cyber insurance requirements. Insurers have tightened underwriting standards significantly over the past three years, and many now require specific security controls as conditions of coverage.
Common cyber insurance requirements that align with the Safeguards Rule include MFA implementation, employee security training, incident response planning, and—critically—having a designated individual responsible for security governance. Some carriers specifically ask whether the firm has a CISO or equivalent role.
Firms that exceed the 5,000 consumer threshold often face additional underwriting scrutiny. The logic is straightforward: more consumer records means more exposure in a breach, which means higher potential claims. Demonstrating robust compliance with all nine Safeguards elements can improve both insurability and premium rates.
Perhaps more importantly, non-compliance can void coverage. If a breach occurs and the subsequent investigation reveals that the firm misrepresented its security posture or failed to implement required controls, the carrier may deny the claim entirely.
Assessing Your Firm's Position
If you haven't evaluated your firm's FTC Safeguards compliance recently, start with two fundamental questions.
First, count your actual consumer records. Not clients—individuals. Include employees of business clients, individual taxpayers, beneficiaries, dependents, and historical records you retain. Most firms find this number is significantly higher than expected.
Second, evaluate your current compliance against all applicable elements. Even firms below the 5,000 threshold must comply with Elements 1 through 7. Do you have a designated Qualified Individual? A documented risk assessment completed within the past year? MFA on all systems accessing customer data?
We've developed a free FTC Safeguards Compliance Checklist specifically for CPA firms. The interactive assessment walks through all nine required elements and provides a gap analysis based on your firm's size and current practices. Most firms complete it in under ten minutes.
For firms that need expert guidance—particularly those requiring a Qualified Individual to satisfy Element 1—our vCISO services provide ongoing compliance support tailored to accounting practices. But whether you work with us or tackle compliance internally, the first step is understanding where you stand today.