Secure information handling Current
Storing client identity evidence securely
Safeguarding client data is a legal requirement for tax practitioners, not just good practice.
Once your firm collects identity documents, taxpayer numbers, or beneficial ownership details, protecting them isn't optional. This guide sets out the IRS's own expectations for a practitioner data security plan. It is general information, not a substitute for your firm's own cyber security policy or advice.
Action plan
1 Know that safeguarding client data is a legal requirement for tax practitioners This isn't just best practice; the IRS frames it as a legal obligation under FTC regulation.
The IRS states directly that protecting client data is the law, because Federal Trade Commission regulations require professional tax preparers to create and put in place security plans to protect client data. Treat identity documents, taxpayer numbers, and beneficial ownership details your firm holds as covered by that same obligation.
- Treat client data protection as a legal requirement, not a discretionary practice
- Cover identity documents, taxpayer numbers, and beneficial ownership evidence under the same standard
- Confirm your firm's current security plan actually covers this category of client data
Done when: Your firm recognises client identity and taxpayer data protection as a legal requirement, and its current plan covers it
IRS: protect your clients, protect yourself2 Put a written security plan in place The IRS points practitioners to its own guide for building one.
The IRS directs tax professionals to Publication 4557, Safeguarding Taxpayer Data, for a step-by-step approach to building and maintaining a written data security plan covering a firm's digital network and office. If your firm doesn't have a current written plan, use this as the starting reference rather than building one from scratch with no structure.
- Confirm whether your firm has a current written data security plan
- Use IRS Publication 4557 as the reference for what that plan should cover
- Assign clear ownership for keeping the plan current
Done when: A written data security plan, built against IRS Publication 4557's structure, is in place and owned by someone specific
IRS: Publication 4557, Safeguarding Taxpayer Data3 Restrict who can access stored identity evidence Limiting access is a core control in both the IRS's own guidance and broader trust-services security practice.
Restrict access to stored identity documents, taxpayer numbers, and beneficial ownership records to staff who genuinely need them for the engagement. Where your firm's broader systems are assessed against a security framework such as the AICPA's Trust Services Criteria, keep client identity evidence within the same access-control boundary rather than treating it as a separate, less-controlled category.
- Limit access to stored identity evidence to staff who need it for the specific engagement
- Keep client identity evidence inside your firm's existing access-control boundary, not a separate unmanaged store
- Review who has access after any staff change
Done when: Access to stored client identity evidence is limited to staff who need it and reviewed after staff changes
4 Review the plan periodically, and after any change A written plan or an access list is only current until something changes.
Review your firm's written security plan and access arrangements on a regular schedule, and specifically after any change in staff, systems, or how identity evidence is collected. Treat this as an ongoing responsibility rather than a one-time document.
- Set a regular review schedule for the security plan and access arrangements
- Trigger an additional review after any staff or system change
- Document when each review took place and what changed as a result
Done when: The security plan and access arrangements were reviewed on schedule and after any relevant change
See setting a record retention schedule for tax records