If you hold a PTIN, federal law already treats your practice as a financial institution — the FTC Safeguards Rule sets what your written security plan has to contain, and the IRS asks whether you have one every time you renew. Texas layers its own requirements on top. Which of these reach your firm, and how, is what the Compliance Readiness Review determines. Briggs IT reviews what you have against what you need to be able to produce, plans what has to change, implements those changes or guides your internal IT team through them, and builds the documentation — steady enough to carry you through your busiest weeks.
Under the Gramm-Leach-Bliley Act, a tax preparation practice that handles customer financial information is defined as a “financial institution,” which places it under the FTC Safeguards Rule. Most preparers never learn this until the moment it counts: the renewal question they can’t answer truthfully, a breach, or an inquiry from a regulator. The obligation has been there the whole time — quietly — whether or not anyone pointed it out.
The IRS makes it explicit. When you renew your PTIN, the W-12 form asks directly whether you maintain a Written Information Security Plan — and answering falsely is a serious federal matter. Between IRS Publication 4557 and the FTC Safeguards Rule, the standard your practice is held to is already set. What most preparers lack isn’t awareness of the rules so much as proof they’ve met them.
Texas adds its own layer on top of the federal rules — the SB 2610 safe harbor against punitive damages, the TITEPA and TDPSA breach and privacy duties, and TRAIGA’s new AI-governance expectations. Which of these reach your practice, and what each one demands, is what the Compliance Readiness Review sorts out.
A defensible program is a set of pieces that work together — and, just as important, the written evidence that each one exists.
For most tax practices, that looks like things such as:
This isn’t something you do once and forget. It’s a program you maintain, update, and re-evidence every year.
With the proof attached, ready for the day the IRS or the FTC asks to see it.
A system failure in your slow season is a bad day. The same failure at the height of filing season is something else entirely — because so much of your year runs through such a narrow window that there’s no room to recover. A breach or an outage you’d shrug off in the off-season can put the whole year’s revenue at risk if it lands at the wrong moment. For a tax practice, this isn’t just a cybersecurity concern. It’s a stay-in-business concern.
That’s why the work belongs in the off-season, and why it runs in order. First we gather what you have and review it against what the IRS and the FTC require — you get a written report of where the practice stands, yours to keep. Then the gaps get closed before any recurring billing begins: if you have internal or outside IT, we guide them through the changes and verify each one — including that backups are tested and recovery is planned, not just assumed; if you don’t, we do the build ourselves in a scoped, defined, and billable remediation and implementation phase, a phase with an end, not us becoming your IT. By the time filing season hits, the program is built, documented, and current, and recurring simply keeps it that way — so you walk into your busiest weeks with nothing hanging over them.
The Compliance Readiness Review is a working session built for tax practices. We gather what you already have and review it against the rules that actually reach your practice — the FTC Safeguards Rule and IRS Publication 4557, plus the Texas statutes on top — then hand you a written report in plain English: what’s in place, what’s missing, and what to fix first. No sales pressure. The report is yours to keep, whether or not you ever hire Briggs IT. The quiet stretch before your next busy season is the ideal time to take it.