Knowledge Base

Compliance Glossary

Plain-language definitions of the FTC, IRS, and cybersecurity terms every CPA firm needs to understand. No jargon, no legalese.

Control Register

A structured list of all security controls your firm should have in place, mapped to regulatory requirements, with testing status and evidence.

FTC Safeguards Rule (16 CFR 314.4(d))IRS Publication 4557

Cyber Insurance Compliance

Meeting the documented security requirements that cyber insurance carriers mandate as a condition of coverage and claims payment.

FTC Safeguards RuleState Insurance Regulations

Data Breach Notification

The legal requirement to notify affected individuals, regulators, and sometimes law enforcement when personal data is exposed in a security incident.

State Breach Notification Laws (all 50 states)FTC Safeguards Rule

Data Inventory

A comprehensive record of all systems, applications, and locations where your firm stores, processes, or transmits client data.

FTC Safeguards Rule (16 CFR 314.4(b)(1))IRS Publication 4557

FTC Safeguards Rule

A federal regulation requiring financial institutions, including tax preparers, to develop and maintain a comprehensive information security program.

16 CFR Part 314Gramm-Leach-Bliley Act (GLBA)

Incident Response Plan (IRP)

A documented set of procedures your firm follows when a data breach or security incident occurs.

FTC Safeguards Rule (16 CFR 314.4(h))State Breach Notification Laws (all 50 states)

IRS Publication 4557

IRS guidelines outlining data security requirements and best practices for tax professionals handling taxpayer information.

IRS Publication 4557IRC Section 7216

Qualified Individual (QI)

The person designated to oversee and be accountable for your firm's information security program, as required by the FTC Safeguards Rule.

FTC Safeguards Rule (16 CFR 314.4(a))

Risk Assessment

A systematic process of identifying threats to your firm's data and evaluating the effectiveness of your security controls.

FTC Safeguards Rule (16 CFR 314.4(b))IRS Publication 4557

Written Information Security Program (WISP)

A documented set of policies and procedures describing how your firm protects sensitive client data.

FTC Safeguards Rule (16 CFR 314.4(b))IRS Publication 4557

Ready to Get Compliant?

Plans starting at $99/mo · Billed annually

30-day money-back guarantee
Cancel anytime
No setup fees

We use cookies to measure site performance and improve your experience. No data is sold to third parties. Privacy Policy