Pre-Tax Season IT Checklist: What Every Arizona CPA Firm Should Do Before January

There is a window between the October extension deadline and the start of filing season when a CPA firm can actually change something. It is roughly ten weeks and it is the only ten weeks that exist. Everything not fixed by January gets carried through to April, usually at the worst possible moment.

This is the list, in the order we would do it.

1. Renew your PTIN and read line 11 properly. Renewal opens in the autumn. While you are in there, line 11 asks you to confirm you are aware that paid preparers are required by law to maintain a written information security plan. Most people tick it without registering what it says. It is worth ten seconds of attention, because it is the requirement everything else on this list supports.

2. Test a restore, not a backup. Every firm has backups. Far fewer have watched someone restore a file from one. The test is not whether the backup ran. It is whether you can get a specific client specific document back, today, in under an hour. Do it once in October and you will sleep better in March.

3. Turn on multi factor authentication everywhere it is missing. Not most places. Everywhere that touches client data. This is the single highest value hour on the list and it is free.

4. Remove access for people who left. Former staff, former contractors, the seasonal preparer from last year. Also check for shared logins, which are the version of this problem nobody writes down.

5. Check what your seasonal staff will be able to reach. If you bring in help for the season, decide now what they need rather than in the first busy week. Temporary staff usually get permanent access because it was quicker.

6. Update anything running an old operating system. Machines that are past support do not get security fixes. February is a bad time to discover this.

7. Look at how returns actually leave your office. Not the policy, the habit. If anyone is emailing returns as plain attachments because the portal is fiddly, the portal is the problem and it is fixable in October and not in February.

8. Ask your software vendors for something in writing. The Safeguards Rule requires you to oversee providers that touch client data. A short email asking how they protect your clients information, and keeping the reply, satisfies more of that obligation than most firms realise.

9. Do a fifteen minute phishing conversation with your staff. Tax season is when your firm becomes a target, because the value of what you hold peaks. The specific thing to cover is the message that appears to come from a client, mid season, asking to change bank details or urgently send a document. Everyone is busy and that is exactly the point.

10. Write down what happens if something goes wrong. Who gets called, in what order, and who can authorise stopping work. Two paragraphs is enough. The version that exists only in your head does not survive the actual day.

The one to do first

If you only do one, do the restore test. Everything else on this list reduces the chance of a bad day. That one determines how bad the day is.

Our free FTC Safeguards checklist covers items one, three, seven and eight in more depth, and takes about ten minutes.

Scroll to Top