Data Security Compliance for Accounting Firms: SOX, GLBA, IRS Pub 4557, and What Owners Should Actually Own

Written by:

TL;DR

  • Only three regimes usually bind a private accounting firm: GLBA and the FTC Safeguards Rule, IRS Publication 4557 and the WISP, and SOC 1 or SOC 2 if the firm handles outsourced financial work for clients.
  • SOX almost never applies to firms serving private clients, but two of its provisions (document retention and whistleblower protection) still apply to private companies.
  • Compliance is a finance function first. The owner signs the risk assessment and owns the evidence, and IT executes the controls underneath it.


Data security compliance for accounting firms is often presented as a daunting, monolithic list of frameworks that an owner must satisfy simultaneously. The FTC’s Safeguards Rule alone exempts firms holding customer information on fewer than 5,000 consumers from several of its toughest requirements. 

That detail changes the entire compliance conversation for a modern tax advisory firm or small accounting practice, and it rarely appears in the articles already ranking for this topic. Most compliance content aimed at accounting firms misses the mark on what owners actually need. It lists every framework it can find, from GLBA to SOX to ISO 27001, and treats them as though they all apply equally, when they don’t. 

A firm serving privately held clients carries real, binding obligations under a short list of regimes. It carries near-zero obligations under several others that keep showing up on generic lists anyway. 

This guide sorts that list and draws the line between the decisions an owner must make personally and the technical work a partner can handle day-to-day.

Why Compliance Is a Finance Problem Before It Is an IT Problem

A control is a technical artifact. Scoping, ownership, attestation, and evidence are core financial operations functions, and no vendor can take them on. An IT provider can deploy encryption and enforce multi-factor authentication. 

Only the firm can decide which regimes actually apply and designate the person accountable for the program. It also has to sign the risk assessment and provide evidence when an insurer or examiner requests it.

Firms that treat compliance as a purchase order eventually hit the same wall. The controls run, but nobody can prove it. A cyber insurance renewal request requires a written risk assessment, but the firm has a folder of vendor invoices instead.

Most owners hand the whole question to their IT provider and assume the box is checked. It isn’t, because the box was never IT’s to check. A provider can run the technical side of a program well. It cannot, on the firm’s behalf, decide that GLBA applies but SOX doesn’t. That judgment carries legal weight, and it sits with the owner.

The Regimes That Actually Bind an Accounting Firm

Three regimes reach most privately held accounting and tax firms directly, and a fourth, SOX, almost never does. 

The table below gives the shape of each, then each gets its own breakdown:

RegimeWho It BindsWhat It Requires in PracticeWho Owns It Inside the Firm
GLBA/FTC Safeguards RuleNearly every accounting and tax practice handling nonpublic personal financial informationA designated Qualified Individual, a written risk assessment, technical controls including MFA and encryption, vendor oversight contracts, an incident response plan, and annual reporting to leadershipOwner or managing partner, with IT executing controls
IRS Publication 4557/WISPEvery firm that prepares or handles federal tax returns, no size exemptionA Written Information Security Plan built from the Publication 5708 template, reviewed and updated at least annuallyOwner or a designated Qualified Individual
SOC 1/SOC 2Firms delivering outsourced accounting, bookkeeping, or payroll that feed a client’s financial statements or hold sensitive client dataClient or auditor-initiated attestation requests, not a self-imposed filingOwner, in response to client or auditor requests
SOXSEC-registered public issuers, foreign private issuers, and wholly owned subsidiaries are material to consolidated reportingInternal control certification and testing under Sections 302 and 404Not the firm’s obligation in nearly all cases, see below

GLBA and the FTC Safeguards Rule

Accounting and tax firms are considered financial institutions under the Gramm-Leach-Bliley Act, which places them under the FTC’s Safeguards Rule. The 2021 amendment turned the rule from general guidance into a specific checklist. 

It requires a designated Qualified Individual, a written risk assessment, and technical controls such as multi-factor authentication and encryption. It also requires regular testing, written vendor oversight contracts, a documented incident response plan, and annual reporting to leadership.

A separate 2023 amendment added a narrower duty to notify the FTC within 30 days if a breach exposes unencrypted information of 500 or more consumers. That is a breach notification rule, not the source of the program requirements above.

Most small firms get relief here. Under an FTC exemption, any firm holding records for “fewer than five thousand consumers,” the rule’s own threshold, is excused from several of the toughest provisions. 

Those include the written risk assessment, the incident response plan, and the annual reporting requirement. A two-person tax planning service with 800 client files is not carrying the same paperwork burden as a 40-person firm, even though both are covered by the rule.

IRS Publication 4557 and the WISP

IRS Publication 4557 is the plain language wrapper around the same GLBA and Safeguards Rule obligations, written for anyone who prepares or handles federal tax returns. It directs firms to Publication 5708 for a Written Information Security Plan (WISP) template, which serves as a starting document rather than a finished plan.

Publication 4557 carries no firm-size exemption. A sole practitioner and a fifty-person regional firm face the identical multi-factor authentication mandate for taxpayer data access, a requirement the IRS states applies “regardless of size.” A WISP that describes controls the firm cannot actually evidence documents the gap instead of closing it.

The Safeguards Rule requires firms to test their program and report results at least annually. A WISP should be reviewed on the same cycle, plus off-cycle after a security incident, a change in vendors, or a new office or service line.

SOC 1 and SOC 2, the Regime Almost Nobody Lists

A firm that delivers outsourced accounting, bookkeeping, or payroll services that feed directly into a client’s financial statements counts as a service organization under the American Institute of Certified Public Accountants (AICPA) attestation standards. 

This critical detail is missing from nearly every article concerning data security compliance for accounting firms. This is the primary factor in determining whether a firm requires a SOC report.

A client’s auditor may request a SOC 1 report from the firm rather than audit the firm’s controls directly. SOC 1 covers controls relevant to a client’s internal control over financial reporting. SOC 2 is a different attestation that addresses the AICPA’s Trust Services Criteria and comes into play when a firm holds sensitive client data.

I have personally received this request on multiple occasions. A client’s auditor asked us for a SOC report, and there’s a common misconception about what these reports actually cover. 

Most requesters do not fully understand the report’s purpose. SOC reports are primarily built for software companies to demonstrate that the data stored on their own platforms is secure. 

We have not undergone a SOC audit ourselves. Our own software vendors have, and we require SOC 2 Type II compliance from each one before trusting it with client data.

A firm that outsources a financially material process, like payroll or automated bank reconciliation, should apply the same logic in reverse. It should request SOC reports from those vendors, just as a client might request one from the firm.

State Breach Notification and Privacy Law

State breach notification law is triggered by the affected individual’s home state, not the firm’s own location, which surprises most owners the first time it comes up. A firm with clients in a dozen states has to track as many as a dozen separate notification timelines, not one. 

There is no need to memorize all fifty statutes. A breach response plan has to account for where clients live, not where the firm’s office sits.

SOX: Almost Certainly Not Yours, and Here Is Why That Matters

SOX governs the integrity of financial reporting at public companies. Mixing it into a general data security list is the most common error in this space. 

Sections 302 and 404 require SEC-registered public issuers, foreign private issuers, and wholly owned subsidiaries material to consolidated reporting to certify and test their internal controls. It is a securities law built around public capital markets disclosure, not a data security framework.

Three paths pull a private company into SOX anyway. A client acceptance conversation is the moment to ask about all three. A public parent can push its own documentation expectations down to a private subsidiary. 

A company preparing for an IPO becomes subject to the full set of SOX obligations on the IPO’s effective date. And a company that registers debt securities with the SEC can trigger the same reporting duties under the Exchange Act, even without ever selling public equity.

Two provisions reach private companies regardless of issuer status. Section 802 covers document retention and prohibits the destruction of records relevant to a federal investigation. Section 1107 protects whistleblowers from retaliation. Both apply broadly, public or private, once a federal inquiry is in play.

Generic roundups list SOX beside GLBA and Publication 4557 as though the three sit at the same level. That habit wastes a firm’s attention. A firm serving private clients gets no protective value from SOX planning. The hours a roundup implies should go to SOX are better spent on the Safeguards Rule instead.

Must Do Versus Nice to Have

Not every item on a compliance checklist carries the same weight. 

The table below sorts what a firm must have from what is genuinely optional, and what happens if a firm skips each one:

ObligationRequired or DiscretionaryConsequence of Skipping It
Written Information Security PlanRequiredNo documented program to show an examiner, an insurer, or a client’s auditor
Designated Qualified IndividualRequiredNo one is accountable for the program, a direct Safeguards Rule violation
Multi-factor authenticationRequiredRegulatory exposure and a common root cause in real breach investigations
Encryption of customer dataRequiredSame exposure, plus a harder breach notification conversation if data is exposed unencrypted
Vendor oversight contractsRequiredNo contractual basis to hold a vendor accountable after an incident
Written incident response planRequiredSlower, costlier response, and a documented gap examiners look for first
Annual program reviewRequiredA stale WISP that documents a gap rather than closing it
ISO 27001 certificationDiscretionaryNo regulatory consequence, though some enterprise clients ask for it
Voluntary SOC 2 attestationDiscretionaryNo consequence unless a client’s own requirements demand it
Formal penetration testing below 5,000 recordsDiscretionaryNo requirement below the threshold, though many insurers now ask for it anyway

Discretionary does not always mean optional in practice. A cyber insurance renewal or an enterprise client’s security questionnaire can turn a nice-to-have into a hard requirement overnight. 

What the Owner Has to Own, and What Can Be Outsourced

Four questions sort every compliance task into a keep-or-delegate decision.

Does this require a signature or an attestation? Keep it. Designating the Qualified Individual, signing the risk assessment, and reporting to leadership cannot move to a vendor, no matter who drafted the document.

Does this require judgment about which regimes apply? Keep it, with advice. Scoping is a finance decision informed by the firm’s actual client base. An IT provider has no basis to make that call.

Is this a control that runs continuously? Delegate it. Encryption enforcement, patch cadence, access provisioning, and monitoring are execution work. A dedicated technology team runs them more reliably than a firm without in-house IT staff.

Is this evidence production? Share it. A vendor generates the logs and test reports. The firm decides what counts as evidence, reviews it, and files it against the WISP. Firms that skip that review tend to discover the gap during a claim, not before one.

The Evidence Problem

The most common gap in a compliance program is a control nobody can prove was running, not one that is missing outright. A firm has multi-factor authentication turned on with no record of when it was enforced. 

A WISP was written three years ago, and nobody has touched it since. A vendor contract has no security terms in it, because nobody added them at signing.

An evidence file that would survive an insurer’s questions looks like a specific, dated set of documents:

  • A risk assessment with a date and the name of the person who conducted it
  • Control test results tied to a testing period
  • An annual program review with a named reviewer and a signature
  • Vendor SOC reports on file, each with a note showing someone actually read it
  • Incident response tabletop records, even if the exercise never turned into a real incident

This is the same discipline a firm already applies to an audit trail on the accounting side. A journal entry without supporting documentation does not hold up under review, and neither does a security control without a record showing it ran.

How Nimbl Tech Approaches Compliance for Distributed Firms

Nimbl Tech provides IT and data security for accounting firms, built around the same Safeguards Rule and Publication 4557 obligations described above. This is possible because Nimbl operates as an accounting firm, with staff and client data distributed across the globe. 

Handling IT compliance for accounting firms from the inside, that experience is the difference between a generic technology vendor and a partner that treats compliance evidence as part of the deliverable.

A generic vendor installs a firewall and calls the job done. A partner that has lived under these obligations builds the dated risk assessments and review records into the relationship from the start. Where remote staffing introduces its own access questions, Nimbl Staffing handles that side of the relationship.

For a firm evaluating managed IT services against building compliance capability in-house, the evidence question usually decides it. Most in-house hires can run the technical controls. Few can also produce the paper trail that proves it.

Start With the Three That Bind You

Strip away the noise, and data security compliance for accounting firms comes down to three regimes. GLBA and the Safeguards Rule apply to nearly every accounting and tax practice handling strategic finance workflows. 

Publication 4557 and the WISP apply the same rules to taxpayer data specifically, with no exemption for a small firm. SOC 1 or SOC 2 applies the moment a firm delivers outsourced strategic finance solutions that a client’s own auditor needs to rely on. 

Everything else is either contingent on a specific fact pattern, such as SOX and a public parent, or genuinely discretionary, such as a voluntary SOC 2 report.

None of that changes who owns the outcome. The owner signs the risk assessment, designates the Qualified Individual, and answers for the program when an insurer or auditor asks. A technology partner can run the controls and produce the evidence underneath that signature. 

Nimbl Tech can review your compliance posture with you and help you decide which of these three regimes actually apply to your firm.

FAQs

Does SOX Apply to My Accounting Firm If None of My Clients Are Publicly Traded?

Almost never. Sections 302 and 404 bind SEC-registered public issuers, foreign private issuers, and their material subsidiaries. A firm serving only private clients falls outside that scope unless a public parent, an approaching IPO, or registered debt securities pull it in. 

Two SOX provisions, document retention and whistleblower protection, still apply regardless of issuer status. In practice, most privately held accounting and tax firms can treat SOX as largely irrelevant to their own compliance program, since the securities-disclosure requirements it is built around only start to matter if one of those three triggers shows up in a specific client relationship.

What Is the Difference Between the FTC Safeguards Rule and IRS Publication 4557?

The Safeguards Rule is the FTC regulation that requires financial institutions, including accounting and tax firms, to maintain a written information security program. Publication 4557 is the IRS’s plain-language version of the same obligations, written for tax preparers and pointing to Publication 5708 for the actual WISP template that firms use. 

Because the two describe the same underlying obligations from different regulators, a firm generally does not need two separate compliance programs. A single WISP built from the Publication 5708 template can satisfy both the FTC’s requirements and the IRS’s expectations for anyone handling federal tax return data.

Do We Need a SOC 1 or SOC 2 Report If We Provide Outsourced Bookkeeping to Clients?

Possibly. A firm that delivers outsourced accounting, bookkeeping, or payroll services that feed a client’s financial statements is a service organization under AICPA standards, and that client’s auditor may request a SOC 1 report instead of auditing the firm directly. 

SOC 2 applies when a firm handles sensitive client data, rather than only to financial reporting. Neither report is something a firm files on its own schedule. Both are attestations produced in response to a specific client or auditor request, so the trigger is usually a client relationship reaching a certain size or a client’s own audit requirements, not a fixed regulatory deadline.

Which Parts of Data Security Compliance Can We Outsource, and Which Must the Owner Hold?

The owner has to hold anything requiring a signature or attestation, including designating the Qualified Individual and signing the risk assessment. A technology partner can run continuous controls like encryption, patching, and access provisioning. Evidence production is shared: the vendor generates records, and the owner reviews and files them. 

The dividing line comes down to judgment versus execution. Deciding which regulations apply and accepting accountability for the program are calls only the owner can make, while the day-to-day work of keeping controls running is where a technology partner adds the most value.

What Happens If We Have a WISP on Paper but no Evidence That the Controls Are Running?

An unevidenced control does not hold up under review any better than an absent one. Insurers, examiners, and client auditors increasingly ask for dated risk assessments, test results, and annual review records, not just a policy document. A WISP without that evidence trail documents a gap instead of closing it. 

The fix is usually procedural rather than technical. Assign a specific person to review and date the program at least once a year, and keep the resulting records in one place that a firm can produce quickly if an insurer or auditor asks for them.

Tap our resource library for
everyday insights from top experts.