Every Tax Preparer Is a Financial Institution Under Federal Law. Many Have No Written Security Plan.

Every Tax Preparer Is a Financial Institution Under Federal Law. Many Have No Written Security Plan.

The IRS is in the final week of its summer campaign telling tax professionals to write one. Industry data says the firms it applies to are mostly two-person shops.

KANSAS CITY, Mo., Aug 07, 2026, ZEX PR WIREIf you prepare tax returns for a living, federal law counts you as a financial institution. Same category as a bank. That classification carries an obligation most small firm owners have never heard of: a written information security plan (WISP), on paper, kept current.

The Gramm-Leach-Bliley Act is what does it. Under GLBA, tax and accounting professionals are considered financial institutions and must implement a data security plan, which puts them under the Federal Trade Commission’s Safeguards Rule. The IRS said it plainly in July 2025: tax professionals are legally required to have a written, accessible plan, and should review, test and update it regularly.

The agency is in the middle of saying it again. On July 7 the IRS and its Security Summit partners launched “Protect Your Clients; Protect Yourself,” a five-week campaign for tax professionals now in its final week. The same guidance is being delivered in person at the 2026 IRS Nationwide Tax Forums, which continue in New York City Aug. 18-20, Orlando Sept. 1-3, and San Diego Sept. 15-17.

“Most preparers I talk to have no idea this applies to them, and I don’t blame them one bit. Nobody ever told them,” said Sam Sapp of Lockbaud. “Many of these smaller firms would be lucky to have a cybersecurity plan at all, let alone a written one.”

The size of the gap follows from the shape of the profession. Research published in The CPA Journal in January, drawn from IRS preparer and e-filing datasets for the 2024 tax year, found 89% of all e-filers handle fewer than 1,000 filings a year, and 48% of preparers matched to a firm are solo practitioners. Intuit, H&R Block, and TaxHawk together account for only about a third of e-filing submissions. Most of the rest of the profession is small businesses.

Those firms hold exactly what an attacker wants. Social Security numbers, bank account details, income records, and dependent information for every client on the list, usually going back years.

The Safeguards Rule doesn’t ask for a security operations center. The FTC asks firms to designate someone to coordinate the program, identify and assess risks to customer information, and create, implement and regularly test safeguards. The IRS publishes Publication 5708, a 28-page template built for smaller practices, and Publication 4557 covers safeguarding taxpayer data more broadly. Both are free.

A plan on paper isn’t really the point either. The protections have to actually be in place, and that’s where a lot of firms get caught. They assume somebody else has it handled, usually the tax software vendor or whoever set the office up. Those companies secure their own platform. They don’t secure your email, your laptops, your backups, or the person who clicks the wrong link.

Somebody has to own that, and in a two-person office nobody has room for one more job. That’s why these plans get started in February and forgotten by March. A lot of firms hand it off instead, which is a good chunk of what IT support for accounting firms means in practice. And it’s not just tax firms. Any small business sitting on customer data runs into the same thing, which is most of why outsourced IT for small businesses is a category at all.

Two things any tax or accounting firm can check this week:

  • Find out whether your firm has a written plan at all, and who is named in it as responsible. If nobody is named, you don’t have one.
  • Ask your tax software vendor and your IT provider, in writing, exactly what each one secures. The gap between those two answers is yours to cover.

“That’s what we try to help with, and honestly what we want to make a push to help more with,” Sapp said. “If a firm gets one page written and puts a name on it, that’s a real win. We’ll take it.”

Through Oct. 31, Lockbaud is offering a free written information security plan review to tax and accounting firms. Lockbaud will read an existing plan against Publication 5708 and the Safeguards Rule and say plainly what’s missing, or confirm a firm doesn’t have one yet. Requests go to connect@lockbaud.com or 816-208-2888.

About Lockbaud

Lockbaud is a managed IT and cybersecurity provider based in Kansas City, Missouri, serving small and mid-sized businesses across the United States. Lockbaud works most often with accounting firms, law firms, and chambers of commerce, and backs its work with same-day support, zero-downtime onboarding, and a money-back guarantee. Founded and owned by Sam Sapp. More at lockbaud.com.

Media Contact

Sam Sapp, Lockbaud

lockbaud.com

Full release with sources: https://lockbaud.com/newsroom/tax-preparer-security-plan-requirement/

You may also like...