IRS 4557 & GLBA Safeguards Compliance Checklist for CPA Firms
21 items covering your WISP requirements, client data protection, phishing defenses, and endpoint security — ready before tax season. Free PDF, delivered to your inbox.
What’s InsideThis checklist covers what IRS Publication 4557 and the GLBA Safeguards Rule require of tax preparers and CPA firms — organized around the items most commonly missing when an examiner or state board review is triggered. Written Information Security Plan (WISP) WISP on file and reviewed in the last 12 months · Designated information security coordinator identified · Risk assessment completed and documented · Vendor management section covers your IT provider, cloud software, and tax platforms Client Data Protection Client documents received via encrypted portal, not email · No W-2s, 1099s, or tax returns transmitted as unencrypted email attachments · Client SSNs not stored in unencrypted files or spreadsheets · Completed returns delivered via portal or encrypted method only Phishing & Email Security DMARC/DKIM/SPF configured on firm domain · Annual phishing awareness training completed with records · Staff trained on W-2 theft and tax-season BEC schemes specifically · MFA enforced on all email accounts Endpoint Security Full-disk encryption enabled on all devices that touch client data · Endpoint detection and response deployed on all workstations · Remote wipe capability on laptops used outside the office · No client data on personal devices Incident Response Written incident response plan covering data breaches and identity theft · IRS Data Theft reporting procedure documented (Form 14242) · Maryland PIPA breach notification requirements known and documented · Staff know who to call if they suspect a breach 21 items, yes/no format with gap notes. Designed for your pre-tax-season security review — use it annually to update your WISP and identify new gaps before they become incidents. | Get the Free ChecklistEnter your details and we’ll send the PDF to your inbox immediately.
No spam. No sales calls unless you ask. Want a full WISP and compliance review? |
Related Resources
Case Study How a 12-person CPA firm got audit-ready with a WISP, 100% encrypted portal, and zero phishing incidents since deployment. | Services IT built for CPA firms — encrypted portals, WISP documentation, phishing training, and Drake/Lacerte/QuickBooks support. | Free Assessment 30 minutes before tax season. We identify your compliance gaps and what it takes to close them. |
