01
Who is the tax return preparer?
Identify the firm and people involved, then determine which rules apply to the preparer and the proposed activity. Do not assume every accounting workflow has the same analysis.
Tax return information
An AI workflow can raise questions about both the use and disclosure of tax return information. Data location matters, but location alone is not the legal test.
Published by PrivateStride · Last updated August 11, 2026
Important context
Section 7216 and related rules are fact-specific and carry serious consequences. This guide is an issue-spotting tool only. It does not decide whether a use, disclosure, exception, or consent is lawful for your firm.
The core distinction
A system can be well secured and still require a separate use or disclosure analysis.
Section 7216 and its regulations address certain knowing or reckless disclosures and uses of tax return information by tax return preparers. Related provisions and guidance include exceptions, consent rules, definitions, and civil penalties. Your advisers need the actual people, data, purpose, systems, and contracts to analyze a proposed workflow.
An on-premises system may reduce external data flows. That can make the architecture easier to explain and control. It does not establish that every use inside the firm is permitted, and it does not remove every possible disclosure.
See how PrivateStride documents data flowsThe review record
Write the answers before the pilot. Revisit them when the model, vendor, purpose, or data path changes.
01
Identify the firm and people involved, then determine which rules apply to the preparer and the proposed activity. Do not assume every accounting workflow has the same analysis.
02
List the fields, documents, facts, prompts, derived text, and outputs involved. Masking a name may not remove the sensitivity or legal character of the remaining information.
03
Describe what the firm will do with the information and every person or system outside the relevant boundary that may receive it. A workflow label such as “summarization” is not enough detail.
04
Tie the activity to a specific preparation, assistance, administrative, legal, security, product-improvement, or other purpose. The purpose can affect the analysis.
05
Have qualified advisers analyze current statutes, regulations, revenue procedures, guidance, and facts. If consent is considered, confirm its required form, timing, content, and delivery.
06
Document where data goes, who can access it, retention, deletion, subprocessors, model training, support, audit evidence, and the firm’s instructions. Controls support the analysis; they do not replace it.
Example issue map
This is an illustration of the questions to document. It is not a conclusion about whether a workflow is permitted.
| Step | Record | Question | Evidence |
|---|---|---|---|
| Input | Tax organizer and source documents | What information enters, and for what exact purpose? | Data inventory and approved use case |
| Processing | Prompt, retrieval context, and model operation | Who or what can receive or access the information? | Architecture and access diagram |
| Output | Draft summary or client question list | How will the output be used and professionally reviewed? | Workflow procedure and reviewer record |
| After use | Logs, backups, exports, and support records | What persists, where, for how long, and under whose control? | Retention settings and contract terms |
A controlled launch
Start technical validation with synthetic or approved test data. Use the pilot to verify roles, logging, output review, deletion, and failure handling. Move to production information only after the responsible business, legal, privacy, tax, and security owners have approved the written workflow.
Put the approval path into policyProduction gate
Start with IRS material
Do not rely on a vendor summary, an old consent form, or a general statement about where a server sits.
Primary sources: The IRS maintains the Section 7216 Information Center with regulations, revenue procedures, revenue rulings, and related material. The FTC’s Safeguards Rule guide addresses information-security program questions that may sit next to the Section 7216 analysis. PrivateStride’s evidence and claim definitions appear in our methodology.
Keep reading
These guides cover the decisions that sit next to this one.
Review the exact product, data, purpose, and workflow before approval.
Read the guideBring AI systems into the written risk and control program.
Read the guideUnderstand what local processing changes and what it does not.
Read the guideCapacity & AI risk assessment
In 30 minutes, we identify your highest-value workflows, likely shadow-AI exposure, and the controls a private AI program would need. The findings are yours to keep.