Under federal law your firm is a financial institution, so a written information security program isn’t optional — the IRS asks whether you have one every time you renew, and the FTC Safeguards Rule sets what it has to contain. On top of that sits the Texas State Board of Public Accountancy, with its own rules on confidentiality, breach notice, and returning client records. Which of these reach your firm, and how, is what the Compliance Readiness Review determines. Briggs IT reviews what you have against what you need to be able to produce, plans what has to change, implements those changes or guides your internal IT team through them, and builds the documentation that stands when someone asks to see it.
Under the Gramm-Leach-Bliley Act, a CPA or accounting practice that handles customer financial information is a “financial institution” — which puts your firm squarely under the FTC Safeguards Rule. The IRS adds its own layer: at PTIN renewal the W-12 form asks directly whether you maintain a Written Information Security Plan, and IRS Publication 4557 is the guide to meeting the Safeguards requirement. Most practitioners have no idea any of this applies to them — right up until a renewal question they can’t answer truthfully, a breach, or a regulator’s inquiry.
On top of anything federal sits the Texas State Board of Public Accountancy. You must take all reasonable measures to keep client records confidential and, immediately on learning of a breach or loss of control over them, notify the affected client in writing with the date and time. Client information cannot go to any contractor, subcontractor, subsidiary, or affiliate — inside or outside the United States — without the client’s written permission. Original client records must be returned within 10 business days of a request, at no charge, regardless of the client’s account status — and those records expressly include software files and the passwords needed to open them. Attest documentation must be kept at least five years, and your firm answers for the conduct of its non-CPA owners and employees exactly as it answers for its licensees.
Texas layers its statutes over all of it. SB 2610, in effect since September 1, 2025, is an opt-in safe harbor: a qualifying program in place at the time of a breach shields your firm from punitive damages. TITEPA requires reasonable procedures to protect sensitive personal information, notice to affected Texans no later than the 60th day, and notice to the Texas Attorney General no later than the 30th day when a breach involves at least 250 Texas residents; the TDPSA adds data-privacy duties but exempts firms and data covered by Gramm-Leach-Bliley. And TRAIGA, in effect since January 1, 2026, sets AI governance expectations if your firm uses AI tools.
A defensible program is a set of pieces that work together — and, just as important, the written evidence that each one exists.
For most accounting firms, that looks like things such as:
This isn’t a checklist you complete once and file away. It’s a program you maintain, update, and re-evidence every year.
Because that’s what both the IRS and the FTC actually expect.
For an accounting firm, timing isn’t a small detail — it’s everything. A security gap that’s an inconvenience in your slow months is a five-alarm fire at the peak of filing season, when a huge share of your year runs through a short window and there’s no slack to absorb a breach or a system failure. That’s exactly why the off-season is the right time to get your program in order: the pressure is low, the calendar is open, and the work gets done properly instead of in a panic.
That’s why the work belongs in the off-season, and why it runs in order. First we gather what you have and review it against what the IRS, the FTC, and the Texas Board require — you get a written report of where the firm stands, yours to keep. Then the gaps get closed before any recurring billing begins: if you have internal or outside IT, we guide them through the changes and verify each one; if you don’t, we do the build ourselves in a scoped, defined, and billable remediation and implementation phase — a phase with an end, not us becoming your IT. By the time filing season hits, the program is built, documented, and current, and recurring simply keeps it that way. You walk into your busy season with nothing hanging over it.
The Compliance Readiness Review is a working session built for accounting firms. We gather what you already have and review it against the rules that actually reach your firm — the FTC Safeguards Rule and IRS Publication 4557, the Texas State Board of Public Accountancy, and the Texas statutes on top — then hand you a written report in plain English: what’s in place, what’s missing, and what to address first. No sales pressure. The report is yours to keep, whether or not you ever hire Briggs IT.