IRS Campaign Highlights Security Requirements, Resources For Tax Professionals

(UCBJ) – The Internal Revenue Service and Security Summit partners are reminding tax and accounting professionals that they are required under federal law to create and maintain a written information security plan to protect client information from identity theft and data breaches.

The reminder is part of the IRS’ five-part “Protect Your Clients; Protect Yourself” summer campaign, which provides tax professionals with information and resources to help safeguard sensitive taxpayer data and their businesses.

The security requirements are also a focus of the IRS Nationwide Tax Forum, which continues this week in New York City before moving to Orlando and San Diego.

What Tax Pros Need to Know

Under the Gramm-Leach-Bliley Act, financial institutions are required to protect customer information. Tax and accounting professionals are considered financial institutions under the law and must maintain a data security plan.

The Federal Trade Commission requires firms to:

  • Designate one or more employees to coordinate the information security program.
  • Identify and assess risks to customer information and evaluate the effectiveness of existing safeguards.
  • Create, implement, regularly monitor and test security safeguards.
  • Select service providers capable of maintaining appropriate safeguards and require compliance through contracts.

The IRS said a WISP should focus on three primary areas: employee management and training, information systems, and detecting and managing system failures.

IRS Offers WISP Resources

The IRS provides several publications to help tax professionals create and maintain their security plans, including Publication 5708, “Creating a Written Information Security Plan for Your Tax & Accounting Practice.”

The publication includes a template designed to help tax professionals, particularly smaller practices, develop a WISP and understand their security compliance requirements and professional responsibilities.

Tax professionals are legally required to have a written and accessible plan and should regularly review, test and update it. Changes to business operations or the results of security testing and monitoring should be reflected in the plan.

The IRS also recommends that tax professionals create a data theft response plan. The plan should include procedures for reporting security incidents to the IRS Stakeholder Liaison and the appropriate state tax agency.

Tax professionals should also understand security event reporting requirements under the FTC’s Safeguards Rule. Covered financial institutions must report certain security events affecting 500 or more people to the FTC, generally within 30 days of discovery.

Additional IRS resources include Publication 5709, “How to Create a Written Information Security Plan for Data Safety,” Publication 5293, “Data Security Resource Guide for Tax Professionals” and Publication 4557, “Safeguarding Taxpayer Data.”

The IRS also directs tax professionals to the National Institute of Standards and Technology’s “Small Business Information Security: The Fundamentals” for additional guidance.

Tax professionals can stay up to date through IRS e-News for tax professionals and the agency’s social media channels.

Image by stefamerpik on Magnific.

Other stories you may want to check out:

ADVERTISEMENT

This site uses Akismet to reduce spam. Learn how your comment data is processed.