IRS Publication 4557
IRS Publication 4557, titled “Safeguarding Taxpayer Data,” is IRS guidance directing tax professionals to protect the taxpayer information they handle. It explains the legal obligation to maintain data security, sets out the safeguards to put in place, and directs every tax firm to create, maintain, and follow a written data security plan.
What Publication 4557 Directs Tax Firms to Do
The publication asks a firm to do four things and then prove it did them: assess the risks to taxpayer data it holds, implement safeguards such as access controls, encryption, and secure disposal, recognize and respond to data theft, and maintain a written data security plan that ties the first three together. It also sets out the reporting steps when a firm experiences a breach or discovers client identity theft, including who to contact at the IRS Stakeholder Liaison and the state.
The Written Information Security Plan
The written plan is the centre of the obligation, and it is where most firms stall. The IRS publishes a companion document, Publication 5708, as a fill-in template built for small practices. A workable plan names a responsible individual, records a risk assessment, lists the safeguards in place against those risks, sets out an incident response procedure, describes how staff are trained, and states when the plan gets reviewed.
Length is not the measure. A twelve-page plan that matches how the firm actually operates is worth more in an examination than forty pages of template text describing controls nobody implemented.
The FTC Safeguards Rule Connection
The written plan is not merely good practice. Tax and accounting firms are financial institutions under the FTC Safeguards Rule (16 CFR Part 314), which legally requires that written program. Publication 4557 is, in effect, the IRS translating that obligation into practical guidance for the tax profession.
The Rule sets out specific elements, and several catch firms by surprise:
- Designate a qualified individual responsible for the program.
- Conduct and document a written risk assessment.
- Multi-factor authentication for anyone accessing information systems — not optional, and not limited to email.
- Encryption of customer information in transit and at rest.
- Service provider oversight, including contractual security obligations.
- A written incident response plan.
- Staff training, plus monitoring and testing of safeguards.
- A written report to the board or equivalent governing body.
Since May 2024 the Rule also requires notifying the FTC of a security event affecting at least 500 consumers, within thirty days of discovery.
The PTIN Renewal Connection
Data security is no longer separable from a preparer’s credentials. The PTIN renewal process requires preparers to confirm their awareness of their data security responsibilities, which means the written plan stops being an internal document and becomes something attached to the individual’s ability to file.
Where Tax Firms Most Often Fall Short
Filing season creates its own risks, and four recur:
- Seasonal staff access. Temporary preparers are granted broad permissions in January and still hold them in September. The plan calls for access on a need-to-know basis; the season rewards whoever can open everything.
- Email as a transfer mechanism. Clients send W-2s and full Social Security numbers by plain email because it is what they have always done. A secure portal exists at most firms; what is missing is the habit and the client-facing instruction to use it.
- Personal devices. Work moves to home laptops and phones in March. Without conditional access, the firm cannot say which devices hold taxpayer data.
- Retention and disposal. Old returns accumulate on file shares and in mailboxes past any retention requirement. Data the firm no longer needs is still data it must protect, and still data it must report on after a breach.
What Clients and Insurers Now Ask For
The written plan has started arriving in places the IRS never intended. Cyber insurance applications ask whether one exists and whether MFA is enforced. Larger clients running vendor diligence ask accounting firms for the same evidence they ask of any other supplier. A firm that can produce a current plan, a recent risk assessment, and training records answers those requests in an afternoon. A firm that cannot will spend weeks assembling them under someone else’s deadline.
Why IRS Publication 4557 Matters for Investment & Professional Firms
For DFW accounting and tax firms, Publication 4557 and its required written plan are a direct, profession-specific obligation with a filing credential attached. DKBinnovative has worked with compliance-intensive firms since 2004 and produces and maintains the written data security plan, implements the safeguards it calls for, and keeps the evidence current between filing seasons — for accounting and tax firms in Frisco, Plano, Irving, and Las Colinas.
Related DKBinnovative Resources
- Managed IT for Investment & Professional Firms
- Cybersecurity Services
- Glossary: Written Information Security Program (WISP)
- Glossary: Multi-Factor Authentication
- Glossary: SEC Regulation S-P
External references: IRS Publication 4557 · IRS Publication 5708 (WISP template) · FTC Safeguards Rule guidance
