The rule requires a written information security program and, unless exempt, specific written risk-assessment, testing, incident-response, and reporting records. Citation: 16 CFR 314.4 and 314.6.
Primary source: 16 CFR 314.2(h)(2)(viii)
What documents does the Safeguards Rule actually require for a tax preparer?
Details
Policywright splits the operating record into a WISP, incident response plan, acceptable use policy, and access control policy. For a tax preparer, those documents should map to Client information moves through organizers, tax software, portals, email, e-signature tools, e-file records, and retained workpapers. The WISP must match where taxpayer data actually lives, not just the tax software named on the invoice.
Primary source: 16 CFR 314.2(h)(2)(viii).
FAQ
What documents does the Safeguards Rule actually require for a tax preparer?
The rule requires a written information security program and, unless exempt, specific written risk-assessment, testing, incident-response, and reporting records. Citation: 16 CFR 314.4 and 314.6.
What is the data-flow issue for a tax preparer?
Client information moves through organizers, tax software, portals, email, e-signature tools, e-file records, and retained workpapers. The WISP must match where taxpayer data actually lives, not just the tax software named on the invoice.
Is this legal advice?
No. It is source-cited educational content for a template product, not legal advice.