IRS Publication 4557: what it asks a tax practice to do

Sources checked 8 October 2026

Short answer

Publication 4557, Safeguarding Taxpayer Data (Rev. 6-2024), is the IRS's security guide for tax professionals. It sets out basic security steps, how to spot and report data theft, and how to comply with the FTC Safeguards Rule — under which, it says, tax return preparers must create and enact security plans to protect client data. The written plan itself is covered by its companion, Publication 5708. When your firm outsources, the rule requires you to pick providers that can keep safeguards, require them by contract, and oversee them.

What Publication 4557 is

A 21-page IRS guide, current revision 6-2024. It is addressed to every tax professional, whether a partner in a large firm or a sole practitioner, and every Authorized IRS e-File Provider. The guide states four aims: basic security steps, recognising and reporting data theft, responding to and recovering from a data loss, and understanding and complying with the FTC Safeguards Rule.

Where the legal duty comes from

The publication is guidance; the obligation behind it is federal law. Publication 4557 puts it this way: Protecting taxpayer data is the law. The Gramm-Leach-Bliley Act requires financial institutions to protect customer information, and the IRS notes that the definition includes professional tax preparers. The FTC's rule, 16 CFR Part 314, lists tax preparation firms among the institutions it covers (§314.1(b)). Publication 4557 adds that failing to create a security plan may result in an FTC investigation.

How the three documents fit together
DocumentWhat it isUse it for
16 CFR Part 314 — FTC Safeguards RuleFederal regulationWhat your information security program must contain
IRS Publication 4557 (Rev. 6-2024)IRS guide and checklistDay-to-day security steps, theft warning signs, reporting a data loss, a plan checklist
IRS Publication 5708 (Rev. 8-2024)IRS guide with a sample templateWriting the Written Information Security Plan (WISP) itself

What it asks a practice to do

Its "Take Basic Security Steps" list includes, in the IRS's words:

  • Implement multi-factor authentication for anyone accessing customer information on your system.
  • Encrypt all sensitive files/emails, especially those with the taxpayer's personally identifiable information
  • Back up sensitive data to a safe and secure external source not connected fulltime to a network.
  • Limit access to taxpayer data to individuals who need to know.
  • Check e-File Applications and PTIN accounts weekly for total returns filed using EFINs and PTINs
  • Implement audit trails (audit logs) that records all activities that occur.

It then covers security software, passwords (a minimum of eight characters; 16 suggested for an administrator), wireless networks and remote access (multi-factor authentication … and a secure Virtual Private Network (VPN) should be minimum standards), stored client data, the warning signs of data theft, and who to report a loss to — the IRS stakeholder liaison, the states where you file, and, for ransomware, the FBI and CISA.

The Safeguards Rule section

Publication 4557 summarises what the FTC requires each company's plan to do:

Plan requirements as summarised in Publication 4557, with the rule section
Publication 4557 says each company must…16 CFR 314.4
Designate a qualified individual to oversee, implement and enforce the program(a)
Implement multi-factor authentication — required for all companies regardless of size(c)(5)
Identify and assess the risks to customer information and evaluate current safeguards(b)
Design and implement a safeguards program, and regularly monitor and test it(c), (d)
Select service providers that can maintain appropriate safeguards, require it by contract, and oversee them(f)
Evaluate and adjust the program as the business changes(g)
Provide security awareness training and regular refreshers(e)

The rule also requires notice to the FTC, no later than 30 days after discovery, of a notification event involving the information of at least 500 consumers (§314.4(j)). The checklist pages that follow in Publication 4557 group further practices under three headings: employee management and training, information systems, and detecting and managing system failures.

What changes when you outsource

A firm that sends client files to an outside bookkeeper or preparer is using a service provider. Section 314.4(f) requires your firm to:

  1. Select providers capable of maintaining appropriate safeguards for the customer information at issue;
  2. Require those safeguards by contract; and
  3. Periodically assess each provider based on the risk they present and the continued adequacy of their safeguards.

The rule reaches the provider's side too: Part 314 applies to all customer information in your possession, regardless of whether such information … pertains to the customers of other financial institutions that have provided such information to you. In practice, ask each outsourcing partner for its own written plan, its multi-factor and encryption practices, and the contract clause that commits it to them — and record the provider in your own WISP. If the provider is outside the United States and will prepare returns, the client's §7216 consent comes first.

Sources

  1. IRS Publication 4557, Safeguarding Taxpayer Data (Rev. 6-2024) — Introduction; Take Basic Security Steps; Create Strong Passwords; Secure Wireless Networks; Report Data Loss; Comply with the FTC Safeguards Rule (p. 13)
  2. IRS Publication 5708, Creating a Written Information Security Plan (Rev. 8-2024) — Requirements; Getting Started
  3. 16 CFR Part 314 — Standards for Safeguarding Customer Information (eCFR, current) — §314.1(b), §314.4(a)–(j)

This page explains published rules. For advice on your firm's own arrangement, ask your counsel.

Send one real return. Judge us on that.

Book a 20-minute scoping call