The IRS requires a Written Information Security Plan. The FTC Safeguards Rule mandates nine specific controls. State CPA boards add their own requirements. Missing any of them risks your PTIN, your license, and your reputation. GCS implements and documents every control so your firm is always audit-ready.
IRS Publication 4557 is the definitive guide for tax professionals protecting client data. It outlines specific technical controls, employee training, incident response procedures, and documentation requirements. We implement every recommendation and maintain the documentation the IRS expects during a review.
Annual training for all staff covering phishing recognition, social engineering, data handling procedures, and breach reporting obligations.
GCS delivers: annual training + monthly phishing simsMFA on all systems, unique user accounts, automatic screen locks, and principle of least privilege access to client tax data.
GCS delivers: 100% MFA, role-based access, conditional accessEncryption of all client data at rest and in transit, secure disposal of records, and DLP policies preventing unauthorized data transfer.
GCS delivers: AES-256, TLS 1.2+, BitLocker, DLP rulesThe FTC updated the Safeguards Rule in 2023 with specific technical requirements for financial institutions — including accounting firms and tax preparers. These are not guidelines. They are legally enforceable requirements with real penalties for non-compliance.
GCS serves as your designated qualified individual responsible for overseeing and implementing your information security program
Written risk assessment identifying internal and external threats, evaluating controls, and documenting remediation — updated annually
Multi-factor authentication on all systems plus encryption of customer information both in transit and at rest
Written incident response plan that is tested and updated — covering containment, notification, and recovery procedures
State boards of accountancy are increasingly requiring cybersecurity measures as conditions of CPA licensure. We track requirements for every state where your firm is licensed and ensure your IT environment meets the strictest standard across all jurisdictions.
Alaska CPA board requires compliance with AICPA professional standards including data protection and confidentiality for client financial records.
Washington requires adherence to AICPA professional conduct rules including reasonable measures to protect client financial data and tax information.
Firms licensed in multiple states must meet the most stringent requirement across all jurisdictions. We track and apply the highest bar for every control.
Tax records, work papers, client correspondence, and financial documents all have specific retention requirements. We implement automated policies that keep data for the required period and securely destroy it when obligations expire — reducing breach exposure and storage costs.
IRS requires preparers to retain copies of returns and related records. We enforce automated retention with secure storage and access logging.
Minimum 3 years (IRS) / 7 years recommendedClient communications containing financial data retained per your policy with automatic archiving and litigation hold capability.
Configurable: 5-7 yearsEngagement work papers, audit documentation, and supporting schedules retained with version control and access restrictions.
7 years (AICPA recommended)DOD-standard data wiping for retired devices and expired records — with certificates of destruction for your compliance files.
Documented + certifiedCompliance is not just about having the right controls — it is about proving you have them. When the IRS, FTC, or a state board asks for documentation, you need to produce it immediately. We create, maintain, and update every compliance document your firm needs.
Custom WISP document covering your firm's specific environment, policies, and controls — not a generic template
Annual risk assessment with threat analysis, vulnerability identification, and scored remediation roadmap
Written IRP with IRS breach notification procedures, FTC reporting obligations, and client communication templates
Documented proof of employee security training completion, quiz scores, and phishing simulation results
Our free compliance audit evaluates your WISP, FTC Safeguards Rule implementation, state board requirements, data retention policies, and documentation completeness — and delivers a clear gap analysis showing exactly where you are compliant and where you are exposed.