The FTC Safeguards Rule in Plain English: What It Actually Requires From Your Firm
The Safeguards Rule has been around since 2003, but the version that matters to your firm took effect on June 9, 2023. That's when the FTC's revised Safeguards Rule moved from vague principles to specific, enforceable requirements. Before the revision, the rule said you needed "appropriate safeguards." Now it tells you exactly what those safeguards are.
This article is the plain-language reference for every requirement in the rule. No legal jargon. No hedge language. Just what each provision means for a CPA firm with 5 to 50 employees, and what you need to do about it.
Who the Rule Covers
The Safeguards Rule applies to "financial institutions" as defined under the Gramm-Leach-Bliley Act (GLBA). That definition includes any business "significantly engaged" in providing financial products or services. CPA firms, tax preparation businesses, bookkeeping services, and enrolled agents all qualify.
If your firm prepares tax returns, provides financial advisory services, or handles client financial data in any capacity, you are a financial institution under this rule. Size doesn't matter. A sole practitioner and a 200-person regional firm are both covered.
The Nine Requirements
The core of the rule lives in Section 314.4, which outlines nine specific elements your information security program must include. Here's each one, translated for a working CPA firm.
1. Designate a Qualified Individual
What the rule says: You must designate a qualified individual responsible for overseeing and implementing your information security program.
What it means for your firm: Someone's name needs to be attached to your security program. That person is responsible for making sure the program runs: that risk assessments happen, training gets delivered, vendors are monitored, and incidents are handled. They're also responsible for the annual report to firm leadership (see Requirement 9).
The qualified individual doesn't need a cybersecurity certification. They need to understand your firm's operations, your data, and the requirements of the rule. For many small firms, this is a managing partner or an office manager.
Can you outsource it? Yes. The rule explicitly allows you to designate a service provider, affiliate, or outside consultant as your qualified individual. But even if you outsource the role, your firm retains responsibility for the program. Outsourcing the work doesn't outsource the accountability.
2. Conduct a Written Risk Assessment
What the rule says: You must base your security program on a written risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information.
What it means for your firm: Sit down and think critically about what could go wrong with your client data. Who could access it without authorization? What happens if an employee falls for a phishing email? What if a laptop is stolen? What if a vendor is breached?
Write it down. For each risk you identify, document what safeguards you have in place to address it and evaluate whether those safeguards are adequate. This doesn't need to be a formal risk matrix with probability scores. It needs to be honest, thorough, and specific to your firm.
The rule requires you to revisit this assessment periodically, especially when your operations change, such as when you add new technology, change vendors, or expand your team.
3. Design and Implement Safeguards
What the rule says: You must design and implement safeguards to control the risks identified in your risk assessment, including access controls, data encryption, and multi-factor authentication.
What it means for your firm: This is the requirement that drives most of the technical work. Three specific controls are called out:
Access controls. Limit who can see client data. Not everyone in the firm needs access to every client file. Implement role-based access so staff members only see what's relevant to their work. Review access regularly and revoke it when people change roles or leave the firm.
Encryption. Client data must be encrypted at rest (when stored on your systems or in the cloud) and in transit (when transmitted via email, file transfer, or client portal). If encryption isn't feasible for a specific situation, the rule allows alternative compensating controls, but those alternatives must be approved in writing by your qualified individual.
Multi-factor authentication. MFA is required for anyone accessing customer information. This applies to your email, your tax software, your document management system, your VPN, and any cloud service that stores client data. A username and password alone are no longer sufficient.
4. Monitor and Test Your Safeguards
What the rule says: You must regularly test or otherwise monitor the effectiveness of your key controls, systems, and procedures.
What it means for your firm: The rule gives you two options.
Option A: Continuous monitoring. Real-time, ongoing monitoring of your information systems for security threats, misconfigurations, and vulnerabilities. This is typically implemented by your IT provider through security monitoring tools.
Option B: Periodic testing. Annual penetration testing combined with vulnerability assessments at least every six months.
Most small firms work with their IT provider to implement one or both of these approaches. The key is documentation. Whatever monitoring or testing is in place, you need records that show it's happening regularly.
The small-firm exemption: If your firm maintains customer information on fewer than 5,000 consumers, you're exempt from this monitoring and testing requirement. However, even exempt firms should implement some level of monitoring as a practical security measure.
5. Train Your Personnel
What the rule says: You must provide security awareness training to all personnel and provide specialized training for employees responsible for carrying out the information security program.
What it means for your firm: Everyone on your team needs to know the basics: how to spot phishing, how to handle client data, and what to do when something looks suspicious. This training must happen regularly, not once.
Your qualified individual and anyone else with hands-on security responsibilities needs deeper training on emerging threats and the specifics of your program. This can come from webinars, industry conferences, vendor training, or self-study, as long as it keeps them current.
Document every session. Attendance lists, topic descriptions, and signed acknowledgments are your proof.
6. Oversee Your Service Providers
What the rule says: You must select and retain service providers capable of maintaining appropriate safeguards, require them by contract to implement those safeguards, and periodically assess their continued adequacy.
What it means for your firm: Every vendor that touches client data needs to be assessed. Your IT provider, your tax software, your cloud storage, your document management system. The assessment doesn't need to be elaborate, but it needs to be documented.
Your contracts with these vendors must include language requiring them to maintain security safeguards and to notify you of incidents. If your current agreements don't include this language, they need to be updated.
Review your vendor relationships at least annually.
7. Keep Your Program Current
What the rule says: You must evaluate and adjust your information security program in light of changes to your operations, the results of testing and monitoring, or any other circumstances that you know or have reason to know may have a material impact on your program.
What it means for your firm: Your security program is a living document, not a one-time project. When you change tax software, add a new office location, start accepting a new type of client data, or learn about a new threat, your program needs to be updated to reflect that change.
In practical terms: review your WISP and risk assessment whenever something significant changes. At minimum, conduct a comprehensive review once a year.
8. Create a Written Incident Response Plan
What the rule says: You must establish a written incident response plan designed to promptly respond to, and recover from, any security event that could materially affect your customer information.
What it means for your firm: Write down what you'll do if something goes wrong. Who discovers the incident? Who do they notify? Who contacts your IT provider? Who handles client communication? Who files the regulatory notifications?
The plan should cover: how to detect and contain an incident, how to investigate and assess its scope, what steps to take to protect client data during the response, how to notify clients and regulators within the required timeframes, and how to preserve evidence for the investigation.
Test the plan periodically through tabletop exercises. A plan that's never been tested is a plan that's likely to fail under pressure.
9. Report to Your Leadership
What the rule says: Your qualified individual must report at least annually to your board of directors, or equivalent governing body, on the overall status of the information security program and the firm's compliance.
What it means for your firm: Once a year, the person responsible for your security program needs to present a status update to the partners or firm leadership. The report should cover: the current state of the program, any incidents that occurred during the year, the results of risk assessments and testing, any identified gaps or areas for improvement, and recommendations for the coming year.
For a small firm, this can be a 30-minute agenda item at an annual partner meeting. Document that the report was delivered, when, and to whom. Keep a copy of whatever was presented.
The small-firm exemption: Firms maintaining customer information on fewer than 5,000 consumers are exempt from this reporting requirement. But even if you're exempt, the exercise is valuable and demonstrates good governance.
The Breach Notification Requirement
In addition to the nine program elements, the FTC added a breach notification requirement effective May 2024. If your firm experiences a security event affecting the information of 500 or more consumers, you must notify the FTC within 30 days of discovery.
The notification must include: the firm's name and contact information, a description of the types of information involved, the date or estimated date range of the event, the approximate number of consumers affected, and a brief description of the event.
This is a federal requirement that operates alongside state breach notification laws, which may have shorter timelines and lower thresholds.
The Penalties
The FTC can assess civil penalties of up to $50,120 per violation per day. Individual officers and directors can face personal fines of up to $10,000 per violation. Beyond the financial penalties, the FTC can impose consent orders that require specific remedial actions, ongoing compliance monitoring, and third-party audits, sometimes for periods of 10 to 20 years.
The penalties are real, but they're not the point. The point is that the FTC has drawn a clear line around what it expects from financial institutions, and CPA firms are squarely within that line. The requirements are specific. The expectations are documented. And the enforcement is active.
What You Can Do Today
-
Read the FTC's own summary. The FTC published a plain-language guide that walks through each requirement. It's the most authoritative source and it's written for business owners, not lawyers.
-
Assess where you stand. Go through the nine requirements above and honestly evaluate which ones your firm has addressed, which ones are partially in place, and which ones haven't been started.
-
Start with the gaps. If you don't have a qualified individual designated, do that today. If you've never done a risk assessment, schedule one this month. If your training program isn't documented, build the documentation process now.
-
Talk to your IT provider. Several of these requirements, particularly monitoring, encryption, and MFA, involve your IT infrastructure. Your IT provider can tell you what's already in place and what gaps need to be closed.
-
Build the documentation habit. The recurring theme across all nine requirements is evidence. The FTC wants to see that your program exists, that it's active, and that it's documented. Every action you take should generate a record.
The Bottom Line
The FTC Safeguards Rule is not a suggestion. It's a binding federal regulation with specific requirements and real penalties. But it's also not unreasonable. The nine elements are logical, proportionate, and designed to protect both your clients and your firm.
The firms that take this rule seriously and build their programs around it are the firms that will weather a regulatory inquiry, survive a breach, and earn their clients' trust. The firms that ignore it are carrying a risk that grows every year.
If you need help building a program that meets all nine requirements without requiring a full-time compliance officer, that's exactly what Kompflow was designed for. We translate the regulatory language into a structured workflow that fits a small firm's operations and budget. But even without a platform, the requirements are clear and the path forward is manageable.
The rule is here. The enforcement is active. The time to act is now.