Many partners first meet IRS Publication 4557 while vetting an outsourcing provider — then realize the obligations it describes apply to their own firm, outsourcing or not. Tax professionals are "financial institutions" under the Gramm-Leach-Bliley Act, which makes the FTC Safeguards Rule mandatory, and Pub 4557 is the IRS's roadmap for meeting it.
What the Safeguards Rule Requires of Every Tax Firm
- A written information security plan (WISP) — required, and requested on the PTIN renewal
- A designated individual responsible for the security program
- A risk assessment covering where client data lives and how it moves
- Access controls, encryption of client data in transit and at rest, and multi-factor authentication
- Monitoring, testing, and an incident-response plan (with data-breach reporting duties)
- Oversight of service providers — contractual safeguards and periodic reassessment
That last item is where outsourcing lives: engaging a preparation provider doesn't outsource your responsibility; it makes provider due-diligence part of your own compliance.
What Pub 4557 Adds
Publication 4557 translates the rule into tax-practice terms: protect EFINs and PTINs, watch for identity-theft indicators, secure email and portals, control remote access, and train staff. It pairs with the IRS "Security Six" basics — firewall, antivirus, MFA, backup, drive encryption, and a VPN for remote work.
Evaluating an Outsourcing Provider Under Your WISP
Your WISP should treat an offshore preparation partner as a named service provider with documented diligence:
- Written security program you've reviewed, ideally evidenced by SOC 2-type audit reports
- Controlled preparation environment: no local downloads, monitored sessions, device restrictions
- Encryption standards and access-revocation procedures in writing
- Contractual confidentiality binding individual staff, consistent with 7216/6713
- Breach-notification commitments with defined timelines
The Counterintuitive Truth
A specialized provider that lives inside these controls daily is often more compliant than the ad-hoc practices inside a busy small firm. Done right, outsourcing forces the security conversation your WISP needed anyway — and gives you audited answers to put in it.
GTPH operates to Pub 4557-aligned controls with GLBA-consistent safeguards and supplies the documentation your WISP file needs: security overview, audit evidence, and contractual protections, before the first document moves.
