Secure information handling Current

Storing client identity evidence securely

Safeguarding client data is a legal requirement for tax practitioners, not just good practice.

Once your firm collects identity documents, taxpayer numbers, or beneficial ownership details, protecting them isn't optional. This guide sets out the IRS's own expectations for a practitioner data security plan. It is general information, not a substitute for your firm's own cyber security policy or advice.

Action plan

2 Put a written security plan in place The IRS points practitioners to its own guide for building one.

The IRS directs tax professionals to Publication 4557, Safeguarding Taxpayer Data, for a step-by-step approach to building and maintaining a written data security plan covering a firm's digital network and office. If your firm doesn't have a current written plan, use this as the starting reference rather than building one from scratch with no structure.

  • Confirm whether your firm has a current written data security plan
  • Use IRS Publication 4557 as the reference for what that plan should cover
  • Assign clear ownership for keeping the plan current

Done when: A written data security plan, built against IRS Publication 4557's structure, is in place and owned by someone specific

IRS: Publication 4557, Safeguarding Taxpayer Data
3 Restrict who can access stored identity evidence Limiting access is a core control in both the IRS's own guidance and broader trust-services security practice.

Restrict access to stored identity documents, taxpayer numbers, and beneficial ownership records to staff who genuinely need them for the engagement. Where your firm's broader systems are assessed against a security framework such as the AICPA's Trust Services Criteria, keep client identity evidence within the same access-control boundary rather than treating it as a separate, less-controlled category.

  • Limit access to stored identity evidence to staff who need it for the specific engagement
  • Keep client identity evidence inside your firm's existing access-control boundary, not a separate unmanaged store
  • Review who has access after any staff change

Done when: Access to stored client identity evidence is limited to staff who need it and reviewed after staff changes

4 Review the plan periodically, and after any change A written plan or an access list is only current until something changes.

Review your firm's written security plan and access arrangements on a regular schedule, and specifically after any change in staff, systems, or how identity evidence is collected. Treat this as an ongoing responsibility rather than a one-time document.

  • Set a regular review schedule for the security plan and access arrangements
  • Trigger an additional review after any staff or system change
  • Document when each review took place and what changed as a result

Done when: The security plan and access arrangements were reviewed on schedule and after any relevant change

See setting a record retention schedule for tax records