Security program

The FTC Safeguards Rule and AI in accounting firms.

An AI tool is part of the information system when it handles customer information. Bring it into the same written risk and control process as the rest of the firm.

Published by PrivateStride · Last updated August 11, 2026

Why it belongs in the WISP

AI changes the map, even when it does not change the rule.

The FTC identifies tax preparation firms as an example of a financial institution under the Safeguards Rule.

The Rule requires covered financial institutions to develop, implement, and maintain a written information security program with administrative, technical, and physical safeguards. The program must fit the size and complexity of the business, the nature and scope of its activities, and the sensitivity of the information involved.

Adding an AI system can create a new data store, user interface, access path, vendor relationship, log, or workflow. Even an on-premises system needs an owner, a risk assessment, defined controls, monitoring, change management, and incident-response treatment.

Review PrivateStride security and data boundaries

The AI system record

Give your Qualified Individual a complete picture.

A model name and a vendor security page are not a system inventory. Document the deployed configuration and the human workflow around it.

01 · Inventory

Inventory the real system.

Which AI applications, models, servers, plug-ins, accounts, retrieval systems, and support channels can handle customer information? Include AI features built into software you already license.

02 · Data flow

Data flow the real system.

What enters the system, where is it processed, which copies are stored, who can retrieve them, when are they deleted, and what leaves the environment? Map prompts, files, outputs, logs, backups, and telemetry.

03 · Access

Access the real system.

Which users, administrators, vendors, and support personnel can reach customer information? How are roles approved, reviewed, revoked, and protected with authentication controls?

04 · Change

Change the real system.

What changes when a model, integration, retention setting, vendor, or workflow is updated? Name the person who can approve a material change and the evidence required first.

05 · Testing

Testing the real system.

How will the firm test safeguards, review logs, detect unauthorized access, handle vulnerabilities, and verify that the written process matches the deployed system?

06 · Response

Response the real system.

How does the AI system enter the incident-response plan? Identify records, owners, containment steps, communications, legal review, recovery, and post-incident changes.

WISP update

Connect each control to an identified risk.

Do not paste a generic AI section into the plan. Record why the chosen safeguards fit the information, workflow, and environment.

01

Governance

Name the owner and approval authority.

Record the Qualified Individual’s role, the AI system owner, acceptable uses, prohibited uses, exception process, review cadence, and reporting path to firm leadership.

02

Risk assessment

Assess the intended use and foreseeable misuse.

Consider unauthorized disclosure, excessive access, prompt injection, unreliable output, data persistence, lost audit evidence, unapproved integrations, credential compromise, and staff workarounds. Prioritize the risks using the firm’s established criteria.

03

Safeguards

Describe the deployed controls.

Address access control, multi-factor authentication where required, encryption, data disposal, secure configuration, logging, monitoring, testing, backup, change management, and professional review of outputs. State important limitations.

04

Operations

Prove the control continues to work.

Assign evidence, frequency, and owner for access reviews, patching, vulnerability work, log review, model changes, exceptions, training, incidents, vendor changes, and annual leadership reporting.

Architecture and responsibility

Keeping inference local can narrow exposure. It does not finish the program.

On-premises processing can reduce the number of external systems that receive prompts and files. The firm still needs to govern administrators, network access, updates, backups, logs, physical access, user behavior, and any support channel.

Compare public, hosted, and on-premises AI

Before production use

  1. Confirm the system and data-flow inventory.
  2. Approve the written risk assessment and safeguards.
  3. Review provider contracts and access arrangements.
  4. Test roles, authentication, logging, and recovery.
  5. Train users on approved data and professional review.
  6. Run an incident exercise that includes the AI system.
See the PrivateStride deployment process

Use the primary text

The firm owns the compliance decision.

Vendor material can support your documentation. It cannot certify your complete information security program.

Primary sources: The FTC’s official small-entity compliance guide summarizes coverage questions and the Rule’s program elements. The FTC Safeguards Rule page links to the legal text and amendments. NIST’s Cybersecurity Framework is voluntary risk-management guidance. PrivateStride’s measurable claims are explained in our methodology.

Keep reading

Turn the policy into a working system.

These guides cover the decisions that sit next to this one.

IRC Section 7216 and AI

Separate information-security controls from use and disclosure analysis.

Read the guide

The shadow AI guide

Bring unapproved services and workflows into the inventory.

Read the guide

AI use policy starter

Turn governance decisions into instructions staff can follow.

Read the guide

Capacity & AI risk assessment

Map the risk before you choose the tool.

In 30 minutes, we identify your highest-value workflows, likely shadow-AI exposure, and the controls a private AI program would need. The findings are yours to keep.

Book your audit 30 min · No preparation · Confidential