Skip to content
Corelink
Menu

FTC Safeguards Rule: what a small accounting or tax firm actually has to do

The Safeguards Rule in plain language for a practice of five to fifty people, including what it requires, what it does not, and where to start.

Written for office and practice managers at accounting, bookkeeping and tax preparation firms 8 minute read Published

Most people at a small accounting practice first heard about the Safeguards Rule in a continuing-education session, in a slide deck full of acronyms, and left with the impression that something had changed and that it was going to be expensive. Both are true in outline and misleading in detail. This guide sets out what the rule is, who it reaches, what it actually asks for, and which parts of it a software purchase can and cannot address.

Corelink is not a law firm and this is not legal advice. We license security software. The rule is routinely explained to small practices in terms of what to buy, which gets the order backwards, so what follows is a plain account of what it actually requires and where software is and is not the answer.

Where the rule comes from

The Safeguards Rule is a Federal Trade Commission regulation made under the Gramm-Leach-Bliley Act. The Act, passed in 1999, required regulators to set standards for how financial institutions protect customer information. The FTC’s version of those standards is the Safeguards Rule.

For its first two decades the rule was written in broad terms: have a written information security programme appropriate to your size and complexity. In 2021 the FTC amended it substantially, replacing much of that generality with a list of specific elements a programme has to contain. Those amended requirements have since come into force.

Does it reach your practice?

The rule applies to businesses that the Gramm-Leach-Bliley Act treats as “financial institutions”. That phrase is much broader than it sounds. It is not limited to banks, and the FTC has stated that professional tax preparers fall within it.

Whether a given accounting or bookkeeping practice is covered depends on what it actually does. A practice that prepares returns is in a different position from one that provides only audit services. This is precisely the kind of question that a firm should put to its own attorney or its professional body rather than resolve from a vendor’s web page, including this one.

One practical point, offered as an observation rather than as advice: for a practice of this size the cost of definitively establishing whether it is covered can exceed the cost of simply behaving as though it is. The programme elements below are, with few exceptions, things a practice holding client financial data would want in place regardless of which regulator is interested.

What the rule asks for

The amended rule describes a programme, not a product. Reduced to plain language, a covered business is expected to do the following.

Put one person in charge. The rule requires a single named individual responsible for the information security programme. They do not have to be a security professional and they can be a service provider, but somebody has to own it, and “the IT company” is not a name.

Base it on a written risk assessment. You cannot design safeguards against risks you have not identified. The assessment is meant to be written down, to cover the information you hold and the systems holding it, and to be revisited rather than done once.

Implement specific safeguards. The amended rule names categories rather than products: controls on who can access what, an inventory of the data and systems you hold, encryption of customer information in transit and at rest, multi-factor authentication for anyone accessing customer information, secure disposal of information you no longer need, change management, and monitoring of what authorised users do.

Test what you implemented. Either continuous monitoring, or a combination of periodic penetration testing and vulnerability assessment.

Train your people. Security awareness training for staff, and appropriate expertise for whoever is running the programme.

Oversee your service providers. Select them on the basis that they can safeguard the information, require it contractually, and keep assessing them. This is the clause that generates the questionnaires that firms send us.

Have a written incident response plan. What happens, who does what, who gets told, in what order.

Report on it. The person in charge reports to the board or equivalent governing body, in writing, at least annually.

There are reduced obligations for businesses below a threshold measured in customer records. A small practice may fall under it, which removes some of the documentation requirements but not the substance of the safeguards.

Where endpoint protection actually fits

Read the list again and notice how little of it is about antivirus software. The rule is mostly about knowing what you hold, deciding who can reach it, proving that decision is enforced, and being able to describe what you did.

Endpoint protection sits inside one part of one element. It contributes to the technical safeguards on the machines that customer information passes through, and — more usefully — a business product with a central console contributes something the rule keeps asking for indirectly: evidence.

That distinction is worth dwelling on. A collection of retail antivirus subscriptions can protect machines perfectly well, but it cannot tell you which machines are protected. When your risk assessment says “all workstations run endpoint protection”, the console is what turns that sentence from an assertion into a record. When a client’s vendor questionnaire asks whether protection is centrally managed, the console is the reason the answer is yes.

What endpoint protection does not do is any of the rest of it. It does not inventory your data. It does not impose multi-factor authentication on your tax software. It does not write your incident response plan, train your staff, or produce your annual report. Any supplier suggesting that a purchase makes a practice compliant is either confused or selling something on a false premise, and it is worth asking them to put the claim in writing.

What a small practice might do first

Not legal advice, and not a compliance plan. This is simply an order that avoids the most common sequencing mistake, which is buying software before anyone has mapped the environment it is meant to cover.

  1. Establish whether you are covered, with someone qualified to answer.
  2. Name the individual who owns the programme, in writing, even if that person is the managing partner.
  3. Write down what client information you hold and where it lives. Most firms discover something during this step.
  4. List every device that touches that information — office desktops, laptops, servers, and home machines used during filing season. The home machines are almost always missing from the first draft.
  5. From that list, work out where protection is currently deployed and where it is not, and close the gap with a licensed business product that reports into one console.
  6. Then carry on with the harder parts: multi-factor authentication, access review, service provider oversight, incident response.

Step five is the part we can help with, and we have put it fifth deliberately. Buying software before steps three and four means buying the wrong number of seats for an environment nobody has mapped.

Three things firms get wrong

Treating it as a one-off. The rule expects the programme to be kept current. A risk assessment written in one year and never revisited is a document, not a programme.

Forgetting seasonal machines. A practice that doubles its effective headcount between January and April frequently licenses for the quiet half of the year. Licences are counted per installed device, so the seasonal machines count.

Assuming the IT provider has it covered. Providers vary enormously in what they consider inside scope. The service provider oversight element exists exactly because this assumption is so common. Ask specifically, and get the answer in writing.

Where we fit

Corelink licenses business endpoint protection and renewals for practices of this size. We will help you arrive at an accurate device count, quote comparable products from more than one publisher, and deliver the licences in your practice’s own name. We will also tell you when the honest answer is that your current arrangement is fine and a renewal quote is all you need.

What we will not do is tell you that buying software makes you compliant with anything. If you want to see how the licensing side works, our endpoint security page describes it, and the accounting and tax page covers the same ground for practices specifically.

The rule itself, and the FTC’s own small-business guidance, are short and readable. Start there, then talk to your attorney. Then talk to us about the software, which is the easy part.

Request a quote

Tell us how many computers you have and what you run today. We reply with options and pricing during business hours — there is no automated checkout and no obligation.

Optional. Useful if a renewal date is close.

An approximate count is fine.

Whatever is installed today, or "not sure".

Renewal date, compliance requirement, or anything else that matters.

We use your details to answer this request. See our privacy policy.