IRS Publication 4557: What Changed, What Stayed, and What You Need to Do About It
Last week we published a plain-English breakdown of the FTC Safeguards Rule. If you read that article, you know the nine requirements the FTC imposes on every CPA firm. But the FTC isn't the only federal agency with expectations for your firm's security posture.
The IRS has its own guidance, and it lives in Publication 4557: Safeguarding Taxpayer Data. This document is the IRS's security blueprint for tax professionals, and it covers territory that overlaps with the FTC rule but also adds requirements specific to the tax preparation environment.
If you're a CPA firm, you're subject to both. The good news is that most of the work overlaps. The less-good news is that the areas where they differ can create compliance gaps if you're only paying attention to one framework.
What Publication 4557 Is (and Isn't)
Publication 4557 is IRS guidance for tax professionals on how to protect taxpayer data. It was developed through the IRS Security Summit, a partnership between the IRS, state tax agencies, and the tax industry that launched in 2015 in response to a surge in tax-related identity theft.
The publication is updated periodically to reflect evolving threats and regulatory changes. The current version incorporates references to the FTC Safeguards Rule and aligns many of its recommendations with the FTC's specific requirements.
Here's the distinction that matters: the FTC Safeguards Rule is a regulation. It's legally binding, with enforcement authority and penalties. Publication 4557 is guidance. It describes what the IRS expects from tax professionals, and it forms the basis for the security attestation you make during your PTIN renewal. It's not optional in a practical sense, even if its enforcement mechanism is different from the FTC's.
The Core Requirements
Publication 4557 structures its guidance around the concept of a Written Information Security Plan, which the IRS requires every tax professional to maintain. The WISP is the central document that describes your firm's approach to protecting client data.
The publication covers six major areas:
1. The Written Information Security Plan (WISP)
Every tax preparer must have a WISP. The IRS provides a template through Publication 5708 that outlines the basic structure, but the expectation is that you customize it to reflect your specific firm.
The WISP must document your administrative, technical, and physical safeguards. It must name the person responsible for your security program. It must describe how you protect client data from collection through disposal. And it must be a living document that's reviewed and updated regularly.
The IRS recommends reviewing your WISP at minimum quarterly. That's a more frequent cadence than the FTC's annual minimum, and it reflects the IRS's recognition that tax professionals face rapidly evolving threats.
2. Employee Management and Training
Publication 4557 requires that all employees who handle taxpayer data receive security training. The training must cover phishing awareness, social engineering recognition, safe email and file sharing practices, and how to report suspicious activity.
Training must be logged with dates and signed attendance records. The IRS uses a strict standard for documentation: if it isn't written and timestamped, it doesn't exist.
The publication also addresses employee onboarding and offboarding. New employees should receive security training before they access client data. Departing employees should have their access revoked immediately, and any firm-issued devices should be recovered and wiped.
3. Information Systems and Data Protection
The publication addresses technical controls that tax professionals should implement:
Firewalls and network security for your office network. Antivirus and anti-malware software on all devices. Encryption of client data in storage and during transmission. Strong password policies with multi-factor authentication. Automatic screen locks on workstations. Secure Wi-Fi configurations (WPA2 or WPA3, not open networks).
It also addresses mobile devices, requiring that any smartphone, tablet, or laptop used to access client data be protected with the same controls as office workstations, including encryption, strong authentication, and remote wipe capabilities.
4. Physical Security
Publication 4557 requires physical safeguards for taxpayer data. This includes locked offices, locked filing cabinets for paper records, visitor sign-in procedures, and secure document disposal through cross-cut shredding or a certified shredding service.
The publication specifically addresses the end-of-day routine: computers should be shut down or locked, paper files should be secured, and office doors should be locked. For firms that allow remote work, the guidance extends to the home office environment.
5. Recognizing and Responding to Data Theft
The publication includes a detailed section on how to recognize that a data breach may have occurred: unexpected changes to client records, clients reporting that returns were filed in their name that they didn't authorize, unusual network activity, or employees receiving phishing emails that appear to come from firm leadership.
When a breach is suspected, the IRS requires you to contact the IRS Identity Protection Specialized Unit and your state tax agency. You must also file a complaint with the FBI's Internet Crime Complaint Center and notify local law enforcement.
The publication provides a data theft response checklist that walks through each step of the response process. This checklist is specific to tax-related breaches and supplements the broader incident response plan required by the FTC.
6. PTIN Renewal and Security Attestation
During the annual PTIN renewal process, tax professionals are required to attest that they have a data security plan in place. This attestation means you're certifying to the IRS that you've implemented the security measures described in Publication 4557.
Some firms have certified compliance without actually having a WISP. The IRS has begun cross-referencing PTIN attestations against reported security incidents, and firms that certified compliance but couldn't produce documentation during investigations have faced credential challenges. The attestation isn't a formality. It's a commitment that the IRS is increasingly willing to verify.
Where 4557 Overlaps With the FTC Safeguards Rule
The overlap is substantial. Both frameworks require:
A written security plan (WISP for IRS, information security program for FTC). A designated person responsible for the program. A risk assessment. Access controls and authentication including MFA. Encryption of client data. Employee security training. Incident response procedures. Vendor/service provider oversight.
If you build a comprehensive program that meets the FTC Safeguards Rule requirements, you'll satisfy most of Publication 4557's expectations as well. The FTC rule is generally the more prescriptive of the two, so using it as your primary framework and then checking against 4557 is an efficient approach.
Where They Differ
There are several areas where Publication 4557 adds requirements or emphasis beyond the FTC rule.
IRS-specific breach reporting. The FTC requires notification to the FTC for breaches affecting 500+ consumers within 30 days. The IRS has its own reporting process that runs in parallel. If client tax data is compromised, you need to contact the IRS Identity Protection Specialized Unit and your state tax agency in addition to any FTC notifications. These are separate reporting obligations with different contact points.
The Taxes-Security-Together checklist. The IRS Security Summit publishes a set of security recommendations specifically for the tax preparation community. These include guidance on securing online accounts, recognizing tax-specific phishing schemes (fake IRS emails, fraudulent e-file confirmations), and protecting electronic filing identification numbers (EFINs).
PTIN attestation. The FTC doesn't require you to certify your compliance to anyone. The IRS does, annually, through the PTIN renewal. This creates a documented record of your compliance claim that can be checked against your actual practices.
Quarterly WISP reviews. The IRS recommends quarterly reviews of your WISP, with immediate updates when you change technology, modify business processes, add or remove staff, experience a security event, or receive updated guidance. The FTC requires "periodic" review but doesn't specify quarterly.
Tax-specific technical guidance. Publication 4557 includes recommendations specific to the tax preparation environment: securing e-filing systems, protecting EFINs, managing client portal access, and handling the specific data types that tax professionals collect (Social Security numbers, bank routing numbers, employer identification numbers).
IRS breach-specific response procedures. When a tax-related breach occurs, the IRS has a specific response sequence that includes contacting the IRS stakeholder liaison, state attorney general, and state tax agency. This is in addition to the FTC's notification requirements and any applicable state breach notification laws.
How to Cover Both Without Doubling the Work
The most efficient approach is to build one integrated program that satisfies both frameworks. Here's how:
Use the FTC Safeguards Rule as your primary structure. The FTC's nine requirements provide a comprehensive framework that covers most of what Publication 4557 expects.
Layer in IRS-specific elements. Add the following to your program: IRS breach reporting procedures alongside your FTC notification process, EFIN and PTIN protection measures, tax-specific phishing recognition in your training program, and quarterly WISP review cadence.
Maintain one WISP that satisfies both. Your WISP doesn't need to be two documents. It needs to be one document that addresses both sets of requirements. Include a section on tax-specific data protection and reference both the FTC Safeguards Rule and IRS Publication 4557 in your purpose statement.
Use a single training program. Your security training should cover both general security topics (FTC) and tax-specific threats (IRS). Phishing recognition, data handling, and incident reporting satisfy both frameworks when they include tax-relevant scenarios.
Document for the stricter standard. Where the two frameworks differ in documentation expectations, follow the stricter one. If the IRS recommends quarterly WISP reviews and the FTC requires annual at minimum, review quarterly. If the IRS requires signed and dated training logs, keep signed and dated training logs. Over-documenting never creates a compliance problem. Under-documenting does.
What You Can Do Today
-
Download the current Publication 4557. Read it. It's less than 50 pages, and it's written in reasonably plain language. Understand what the IRS expects beyond the FTC requirements.
-
Check your PTIN attestation. When you renewed your PTIN, you attested that you have a security plan. Make sure you can back that attestation up with an actual, documented plan.
-
Compare your current program against both frameworks. Use the FTC's nine requirements and Publication 4557's six areas to create a gap analysis. Where do you meet requirements? Where are you short?
-
Add IRS-specific procedures to your incident response plan. If your plan only covers FTC notification, add the IRS reporting steps: contact the IRS Identity Protection Specialized Unit, your state tax agency, the FBI IC3, and local law enforcement.
-
Adopt the quarterly review cadence. Even if the FTC only requires annual review, the IRS recommendation of quarterly reviews is a better standard. Put four dates on your calendar for the year.
The Bottom Line
Publication 4557 and the FTC Safeguards Rule are two sides of the same coin. They both want the same outcome: a CPA firm that protects client data through documented, active security practices. The FTC provides the legal framework with enforcement teeth. The IRS provides the tax-specific guidance with an annual attestation requirement.
Your firm is subject to both. The work is mostly the same. The documentation is mostly the same. The key is to build one program, review it against both standards, and maintain the documentation that proves compliance under each.
If coordinating across both frameworks feels like it's pulling you in two directions, that's one of the problems Kompflow solves. Our platform maps your firm's security program against both the FTC and IRS requirements, identifies gaps, and tracks your compliance activities in one place. One program. Two frameworks. No duplication.
Your clients trust you with their most sensitive financial data. The IRS and the FTC both expect you to earn that trust, every year, with evidence.