IRS Publication 4557 is the IRS's guidance explaining how paid tax return preparers must safeguard taxpayer data. It applies to every practice that prepares returns for compensation, regardless of size, including solo practitioners. It points firms to Publication 5708 to build a Written Information Security Plan, or WISP, which is the actual document the FTC Safeguards Rule legally requires every covered firm to have.
What Publication 4557 actually is
Publication 4557 is not itself the law. It is the IRS's outreach document explaining an existing legal requirement, the FTC Safeguards Rule, in terms specific to tax professionals. The rule itself comes from the Gramm Leach Bliley Act and is enforced by the FTC, but because it applies to any business handling consumer financial data, the IRS publishes 4557 to walk preparers through what it means for their specific practice.
Practically, this means two things worth separating. The legal obligation exists whether or not a firm has read Publication 4557. But the publication is the clearest, most specific explanation of what that obligation actually requires a tax practice to do, which is why it is worth reading directly rather than relying on a summary, including this one.
Who has to comply
Every tax professional who prepares returns for compensation is covered, regardless of practice size, client count, or revenue. That includes CPA firms and accounting firms preparing individual or business returns, enrolled agent practices, and solo practitioners, even ones operating entirely virtually with no physical office.
Bookkeeping only practices that never prepare a tax return sit in a narrower position, covered in the FAQ below.
The WISP requirement, explained
A Written Information Security Plan is the document the FTC Safeguards Rule actually requires. Publication 4557 points firms to Publication 5708 specifically for step by step guidance on drafting one. At minimum, a data security plan needs to:
- Designate one or more employees to coordinate the information security program, in a solo practice this is simply the practitioner themselves
- Identify the realistic risks to client information, both external and internal
- Evaluate the current safeguards in place for controlling those risks
- Design and implement a safeguards program addressing the gaps found
- Monitor and adjust the plan over time as the practice's tools and processes change
This is not a one time document filed away and forgotten. Adding a new practice management tool, a new automation vendor, or a new staff member with system access is exactly the kind of change that should trigger a review of the existing plan.
If a practice does not have a WISP today, IRS Publication 5708 is the direct, step by step resource for building one, not a generic security policy template. It is written specifically for this audience and this requirement.
Practical steps a small practice can take this month
For a two or three person practice without a dedicated IT or compliance function, the honest starting point is smaller than it sounds. Encrypt client documents in transit and at rest, this is table stakes for any cloud based practice management tool. Limit system access to only the staff who need it for their specific role. Keep a basic written record of what tools touch client data and who has access to each one. Then work through Publication 5708's structure to formalize this into an actual WISP rather than an informal set of habits.
What this means for AI tools and other vendors
Any tool that touches client financial data, whether it is a practice management platform, a document automation system, or an AI reception and document chasing system, becomes part of a firm's data security picture. A firm remains responsible for vetting any vendor's data handling practices before adopting it, encryption standards, whether data is ever used to train external models, and how access is scoped, are all reasonable questions to ask before connecting a new tool to client data. This is the same standard NeverMiss Pro is built to, see the FAQ for specifics on how client data is handled.
Sources
- IRS Newsroom, "Here's what tax preparers need to know about a data security plan"
- Rightworks, "IRS Publication 4557: Safeguarding Taxpayer Data Guide"
- Verito, "IRS Publication 4557: Data Security Guide for Tax Professionals"
This guide is general information, not legal or compliance advice. Confirm current requirements with the source publications above or a qualified compliance professional before making decisions for your practice.
Your data handling standard should already look like this
See exactly how NeverMiss Pro handles client data, aligned with these same principles.