Map the handoffs
Write the client journey from the first inquiry to the end of the retention period. Include the fit check, engagement terms, secure document request, interview, preparation, review, signatures, e-file authorization, payment, delivery, recordkeeping, and follow-up. Assign an owner and a system to every step.
Taxpayer documents should not live in ordinary email threads, text messages, or an unplanned collection of personal devices. Select tools after writing the process and the security requirements. A feature list is not a security program.
Put the written security plan to work
The FTC Safeguards Rule covers tax preparation firms and requires covered firms to maintain a written information security program suited to the business and the information it handles. IRS Publication 4557 and the detailed sample in Publication 5708 give tax professionals security guidance and a WISP starting point. A downloaded template still needs decisions, owners, controls, evidence, training, testing, vendor review, and an incident process.
- Use multi-factor authentication and unique accounts for systems that hold client data.
- Limit access to the people who need it and remove access promptly when roles change.
- Encrypt devices and transmissions, patch systems, maintain protected backups, and test recovery.
- Vet service providers and document which party owns each security task.
- Know whom to call and what to preserve if information may have been exposed.
Review the process with a fictional case
Walk a fictional client through the entire map. Look for duplicated entry, unclear status, unprotected files, missing approvals, and a step that depends on one person remembering what to do. Fix the process before the filing-season rush.
Do this today
- Draw the client journey with one box per handoff.
- Mark every box that stores, sends, or exposes taxpayer information.
- Open the IRS WISP resource and list the decisions that still need an owner or qualified review.
Sources
Next lesson