(844) 777-6544
Industries → Accounting

IRS, FTC, State CPA Board — Every Requirement Met. Every Audit Passed.

The IRS requires a Written Information Security Plan. The FTC Safeguards Rule mandates nine specific controls. State CPA boards add their own requirements. Missing any of them risks your PTIN, your license, and your reputation. GCS implements and documents every control so your firm is always audit-ready.

Regulatory Compliance — All Frameworks

Compliant
IRS Publication 4557
Compliant
FTC Safeguards Rule
All 9 Elements
WISP Document
Current
State CPA Board Reqs
Met
Data Retention Policies
Active
IRS Publication 4557 Compliance

Every IRS Security Requirement — Implemented and Documented

IRS Publication 4557 is the definitive guide for tax professionals protecting client data. It outlines specific technical controls, employee training, incident response procedures, and documentation requirements. We implement every recommendation and maintain the documentation the IRS expects during a review.

Pub 4557

Security Awareness Training

Annual training for all staff covering phishing recognition, social engineering, data handling procedures, and breach reporting obligations.

GCS delivers: annual training + monthly phishing sims
Pub 4557

Access Controls & Authentication

MFA on all systems, unique user accounts, automatic screen locks, and principle of least privilege access to client tax data.

GCS delivers: 100% MFA, role-based access, conditional access
Pub 4557

Data Protection & Encryption

Encryption of all client data at rest and in transit, secure disposal of records, and DLP policies preventing unauthorized data transfer.

GCS delivers: AES-256, TLS 1.2+, BitLocker, DLP rules
IRS Pub 4557 — Implementation Status
Security Awareness TrainingComplete
MFA / Authentication100% Enforced
Data EncryptionAES-256
Firewall / IDSFortiGate Active
Anti-MalwareSentinelOne
Backup / RecoveryAutomated
Incident Response PlanTested
WISP DocumentCurrent
FTC Safeguards Rule Compliance

All Nine Elements of the Updated Safeguards Rule — Covered

The FTC updated the Safeguards Rule in 2023 with specific technical requirements for financial institutions — including accounting firms and tax preparers. These are not guidelines. They are legally enforceable requirements with real penalties for non-compliance.

Qualified Individual

GCS serves as your designated qualified individual responsible for overseeing and implementing your information security program

Risk Assessment

Written risk assessment identifying internal and external threats, evaluating controls, and documenting remediation — updated annually

Encryption & MFA

Multi-factor authentication on all systems plus encryption of customer information both in transit and at rest

Incident Response

Written incident response plan that is tested and updated — covering containment, notification, and recovery procedures

FTC Safeguards Rule — All 9 Elements
1. Qualified IndividualGCS Designated
2. Written Risk AssessmentComplete
3. Safeguards ImplementationAll Controls
4. Regular TestingContinuous
5. Staff TrainingAnnual
6. Service Provider OversightDocumented
7. Program UpdatesAnnual Review
8. Incident Response PlanTested
9. Board ReportingQuarterly

State CPA Board IT Requirements

State boards of accountancy are increasingly requiring cybersecurity measures as conditions of CPA licensure. We track requirements for every state where your firm is licensed and ensure your IT environment meets the strictest standard across all jurisdictions.

Alaska Board

Alaska CPA board requires compliance with AICPA professional standards including data protection and confidentiality for client financial records.

  • AICPA standards compliance
  • Confidentiality safeguards
  • CPE cybersecurity credits

Washington Board

Washington requires adherence to AICPA professional conduct rules including reasonable measures to protect client financial data and tax information.

  • Data protection standards
  • Cloud storage guidelines
  • Breach notification rules

Multi-State Firms

Firms licensed in multiple states must meet the most stringent requirement across all jurisdictions. We track and apply the highest bar for every control.

  • Highest-standard approach
  • Multi-jurisdiction tracking
  • Proactive regulatory updates
All 50 states require CPA firms to protect client data under AICPA professional standards. GCS tracks regulatory changes across all jurisdictions and adjusts your compliance posture proactively.
Data Retention Policies

Retain What the IRS Requires. Destroy What Creates Risk.

Tax records, work papers, client correspondence, and financial documents all have specific retention requirements. We implement automated policies that keep data for the required period and securely destroy it when obligations expire — reducing breach exposure and storage costs.

Tax Return Records

IRS requires preparers to retain copies of returns and related records. We enforce automated retention with secure storage and access logging.

Minimum 3 years (IRS) / 7 years recommended

Email & Correspondence

Client communications containing financial data retained per your policy with automatic archiving and litigation hold capability.

Configurable: 5-7 years

Work Papers & Audit Docs

Engagement work papers, audit documentation, and supporting schedules retained with version control and access restrictions.

7 years (AICPA recommended)

Secure Destruction

DOD-standard data wiping for retired devices and expired records — with certificates of destruction for your compliance files.

Documented + certified
Compliance Documentation Support

Audit-Ready Documentation — Always Current, Always Complete

Compliance is not just about having the right controls — it is about proving you have them. When the IRS, FTC, or a state board asks for documentation, you need to produce it immediately. We create, maintain, and update every compliance document your firm needs.

Written Information Security Plan (WISP)

Custom WISP document covering your firm's specific environment, policies, and controls — not a generic template

Risk Assessment Reports

Annual risk assessment with threat analysis, vulnerability identification, and scored remediation roadmap

Incident Response Plan

Written IRP with IRS breach notification procedures, FTC reporting obligations, and client communication templates

Training Records

Documented proof of employee security training completion, quiz scores, and phishing simulation results

Documentation — Status

All Current
WISP DocumentCurrent
Risk AssessmentAnnual — Complete
Incident Response PlanTested Q1 2026
Security Policies12 Documented
Training Records100% Complete
Vendor AgreementsAll Current
Data Retention ScheduleDocumented
Last Full ReviewQ1 2026

Could your firm pass an IRS or FTC review today?

Our free compliance audit evaluates your WISP, FTC Safeguards Rule implementation, state board requirements, data retention policies, and documentation completeness — and delivers a clear gap analysis showing exactly where you are compliant and where you are exposed.

100% client audit pass rate. IRS, FTC, and state board compliant.