If you prepare returns for a fee in Arizona, the FTC considers your firm a financial institution. Not in a figurative sense. The Safeguards Rule names accountants and tax preparation services directly, and it applies whether you have forty staff in Scottsdale or work alone out of Queen Creek.
This is the version of the rule with the marketing stripped out, organised as things you can check.
First, confirm you are covered
You are covered if you collect, store or process customer financial information in connection with providing a financial service. That includes Social Security numbers, income data, bank details and any other nonpublic personal information about an individual client.
Two things that do not get you out of it. Firm size is irrelevant, there is no small business exemption. And using cloud software does not transfer the obligation to your vendor. Your firm remains responsible.
The checklist
1. Have you named a Qualified Individual? One specific person responsible for the information security program. No certification required. It can be the managing partner, an internal person, or an outside provider. Write the name down. An unnamed role is not a designation.
2. Do you have a written risk assessment? Not a feeling that things are probably fine. A document that lists where client data sits, what could compromise it and how serious that would be. This is the foundation of everything else, because the rule expects your safeguards to answer risks you identified rather than a generic list.
3. Is client data encrypted, at rest and in transit? Laptops, servers, backups, and anything moving between you and a client. The most common gap here is not the main system, it is email. Sending a return as an unprotected attachment is the habit that survives every other improvement.
4. Is multi factor authentication on everything that reaches client data? Email, practice management, document portal, remote access, and the cloud accounts underneath them. Partial coverage is where firms usually sit. One account without it is the one that gets used.
5. Do you control and review access? Who can see what, and does that still match who works there. Departed staff accounts are the classic finding. So is everyone having access to everything because it was simpler when the firm was smaller.
6. Are your safeguards tested, not just installed? The rule asks for regular monitoring and testing. In a small firm that can be modest, but it has to happen and it has to be recorded.
7. Have you addressed service providers? Select vendors capable of maintaining appropriate safeguards, require it in the contract, and oversee them. If you have never asked your software vendors or your IT provider for anything in writing about how they protect your clients data, this element is unmet. It is also the one almost nobody does.
8. Is there a written incident response plan? What happens, who is called, in what order. Since 2023 there is also an obligation to notify the FTC of a security event involving unauthorised acquisition of unencrypted information for 500 or more consumers.
9. Do you train your staff? Including yourself. The rule expects security awareness to be part of the program, and in a small firm the humans are the whole attack surface.
10. Is the program reviewed and updated? When you change software, add staff, or change how you work. A plan written once and never touched is evidence you have a document, not a program.
Where Arizona firms tend to fall down
Three patterns come up repeatedly in this market.
Sole practitioners assume the rule is for larger firms. It is not, and a solo practice is the most exposed because there is nobody whose job this is.
Firms that moved to the cloud during 2020 and 2021 assume the platform handles compliance. The platform handles its own security. Your obligations about access, training, vendor oversight and documentation are still yours.
And firms with genuinely good practices have no documentation of them, so the answer to any question is a verbal one. That works until the moment it needs to be written.
If you would rather not work through this from scratch, our free Safeguards checklist covers the same ground in a one page format you can fill in with a partner.
