Sourcepass Blog

Does GLBA Apply to Your Accounting Firm? Guide to the Safeguards Rule

Written by Robert Villano | Sep 25, 2026

If you run an accounting firm, you may already have a basic cybersecurity program, but a more specific question may be harder to answer: Does GLBA apply to our firm?

For many accounting and tax preparation businesses, the answer may be yes.

The Gramm-Leach-Bliley Act (GLBA) applies beyond traditional banks and financial institutions. The Federal Trade Commission (FTC) identifies tax preparers, accountants, and other financial advisers among businesses that may qualify as financial institutions based on the activities they perform. For firms subject to the FTC's jurisdiction, the GLBA Safeguards Rule requires a written information security program designed to protect customer information.

That makes GLBA compliance for accounting firms more than a privacy policy exercise. It can affect how your firm manages customer information, controls access, secures Microsoft 365 and other cloud systems, evaluates service providers, trains employees, tests security controls, and responds to incidents.

The first step is determining whether GLBA applies to your firm. The second is understanding what the Safeguards Rule actually requires. The third is comparing those requirements with how your firm operates today.

 

Does GLBA apply to your accounting firm?

GLBA applies to certain businesses that are significantly engaged in financial activities and fall within the jurisdiction of the applicable regulator.

For firms regulated by the FTC, the FTC's guidance specifically identifies tax preparers and accountants as examples of businesses that may qualify as financial institutions because they provide financial, investment, or economic advisory services. The definition is broader than the organizations people typically associate with the term "financial institution."

However, being an accounting firm does not automatically answer every question about GLBA coverage. The nature of the services your firm provides, who receives those services, and which regulator has jurisdiction can affect the analysis.

 

Start with these questions

Your firm should establish:

  • What financial services does the firm provide?
  • Are those services provided to individuals for personal, family, or household purposes?
  • What nonpublic personal information does the firm collect or receive?
  • Which GLBA requirements and regulatory authority apply to the firm?
  • Does the firm fall under the FTC's Safeguards Rule?

If there is uncertainty about whether the law applies to your specific business model, have qualified legal or compliance counsel make the determination. Your IT provider can help assess security controls, but determining the firm's legal obligations is a separate question.

 

What information does GLBA protect?

Once you determine that GLBA applies, the next question is what information needs to be protected.

The Safeguards Rule focuses on customer information, including records containing nonpublic personal information that are handled or maintained by or on behalf of the financial institution or its affiliates.

For an accounting firm, that information can exist across much more than a tax or accounting application.

It may include:

  • Social Security numbers
  • Tax returns and supporting documents
  • Income information
  • Bank and investment account information
  • Financial statements
  • Payment information
  • Payroll records
  • Estate and trust information
  • Copies of identification documents
  • Client correspondence
  • Information received from other financial institutions
  • Documents stored in cloud file platforms
  • Data contained in email and collaboration systems

The practical question is not simply, "Where are our client files?"

It is:

Where does customer information exist, how does it move through the firm, and who can access it?

 

Map the information, not just the applications

An accounting firm may have customer information distributed across:

  • Microsoft 365
  • Email
  • SharePoint and OneDrive
  • Tax and accounting applications
  • Document management systems
  • Payroll platforms
  • CRM systems
  • Backup systems
  • Client portals
  • File-transfer services
  • Local workstations
  • Mobile devices
  • Third-party applications and integrations

A GLBA risk assessment should account for this broader information ecosystem.

 

What does the GLBA Safeguards Rule require?

For covered financial institutions under FTC jurisdiction, the Safeguards Rule requires a written information security program with administrative, technical, and physical safeguards designed to protect customer information. The program must be appropriate to the firm's size and complexity, the nature and scope of its activities, and the sensitivity of the information it handles.

The rule is risk-based. It does not mean every accounting firm needs the same technology stack.

It means the firm needs to identify reasonably foreseeable risks and implement safeguards appropriate to those risks.

The FTC's Safeguards Rule identifies specific elements that covered organizations must address.

 

1. Designate a Qualified Individual

The firm must designate a Qualified Individual to implement and supervise its information security program.

That individual can be an employee, affiliate, or service provider. However, outsourcing the technical work does not outsource the firm's responsibility. The FTC specifically states that when a service provider performs this role, the company still needs a senior employee to supervise that person.

For a smaller accounting firm, this distinction is important.

An MSP or managed security provider may operate security tools, monitor systems, perform assessments, and help maintain the program. Firm leadership still needs clear ownership of the overall information security program.

 

2. Conduct a written risk assessment

The information security program must be based on a written risk assessment.

The assessment should identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information and establish criteria for evaluating those risks. The firm must also periodically reassess those risks as its business and threat environment change.

A useful assessment should answer:

  • What customer information do we have?
  • Where is it stored?
  • How is it transmitted?
  • Who can access it?
  • Which vendors can access it?
  • What happens if an employee account is compromised?
  • What happens if a device is lost?
  • What happens if email is compromised?
  • What happens if a critical application is unavailable?
  • How quickly can we detect and respond to unauthorized access?

The output should be more than a risk score. It should establish a prioritized list of risks and the controls needed to reduce them.

 

3. Implement safeguards based on identified risks

The firm must design and implement safeguards that address the risks identified in the assessment.

The FTC identifies controls including access management, data inventory, encryption, application security, multifactor authentication, secure disposal, change management, and monitoring.

For an accounting firm operating primarily in Microsoft 365, that can translate into controls such as:

  • Multifactor authentication
  • Conditional access
  • Privileged identity controls
  • Least-privilege access
  • Endpoint protection and management
  • Email security
  • Encryption
  • Security logging and monitoring
  • Regular access reviews
  • Secure configuration management
  • Data retention and disposal procedures
  • Third-party application controls

The technology should follow the risk assessment.

Buying another security product does not demonstrate that the underlying risk has been addressed.

 

What cybersecurity controls should an accounting firm have?

The Safeguards Rule provides the regulatory framework. The firm's risk assessment should determine how those requirements translate into specific controls.

For most Microsoft 365 accounting environments, several areas deserve particular attention.

 

Identity and access security

Identity is a critical control point because compromised credentials can provide access to email, documents, applications, and customer information.

Review:

  • MFA coverage
  • Privileged administrator accounts
  • Conditional access policies
  • Dormant accounts
  • Former employee access
  • Guest accounts
  • Third-party application permissions
  • Excessive user privileges
  • Regular access reviews

A useful measurement is not "MFA is enabled."

It is what percentage of relevant accounts are actually protected by MFA, including privileged accounts?

 

Endpoint security

Customer information may be accessed from laptops, desktops, mobile devices, and other endpoints.

Evaluate whether:

  • Devices are centrally managed
  • Endpoint protection is deployed
  • Security updates are applied
  • Disk encryption is enabled
  • Local administrator privileges are controlled
  • Lost or stolen devices can be secured
  • Unmanaged devices can access sensitive information

 

Email and phishing protection

Email remains a major pathway into an organization's information environment.

A practical assessment should examine:

  • Email authentication
  • Anti-phishing controls
  • Malicious attachment and link protection
  • Suspicious sign-in detection
  • External forwarding
  • Mailbox rules
  • Business email compromise controls
  • Employee reporting processes

For Microsoft 365 users, these controls should be evaluated as part of the firm's broader identity and security architecture rather than as isolated email settings.

 

Data protection

The firm should know where customer information is stored and how it is protected.

Review:

  • Encryption
  • Access permissions
  • External sharing
  • File-transfer methods
  • Data retention
  • Secure disposal
  • Backup protection
  • Third-party access
  • Data stored outside approved systems

 

Monitoring and detection

Security controls are more useful when the firm can determine whether they are working.

Review whether the firm can:

  • Monitor relevant security events
  • Detect suspicious authentication activity
  • Identify compromised accounts
  • Investigate security alerts
  • Escalate high-risk events
  • Track remediation
  • Document incidents

The goal is to reduce the time between a security event occurring and the firm identifying and responding to it.

 

What documentation should an accounting firm maintain?

GLBA compliance should be supported by evidence.

A firm should be able to demonstrate not only that it has security policies, but that it operates the controls those policies describe.

The FTC's Safeguards Rule requires covered organizations to maintain a written information security program and documentation around key elements of that program.

Depending on the firm's environment, documentation may include:

  • Written information security program
  • Written risk assessment
  • Data and system inventory
  • Access-control procedures
  • Encryption standards
  • Multifactor authentication standards
  • Security awareness training records
  • Security testing results
  • Vulnerability assessments
  • Penetration testing results where applicable
  • Incident response plan
  • Incident records
  • Service-provider assessments
  • Security provisions in vendor contracts
  • Access reviews
  • Remediation plans
  • Leadership reporting

 

Document decisions, not just policies

One of the most useful practices is to document why a security decision was made.

For example:

Risk: Former employees may retain access to cloud applications after termination.

Control: Automated identity deprovisioning and termination checklist.

Measure: Percentage of terminated users whose access is disabled within the firm's defined target.

Owner: IT or security administrator.

Review: Monthly.

That creates a direct connection between the risk assessment, the control, and measurable risk reduction.

 

How should accounting firms manage service providers?

An accounting firm's security program extends beyond systems it owns directly.

Cloud applications, managed IT providers, security providers, tax platforms, payroll systems, document management platforms, and other vendors may have access to customer information.

The Safeguards Rule requires covered institutions to select service providers capable of maintaining appropriate safeguards, require appropriate safeguards through contractual provisions, monitor providers, and periodically reassess their ability to meet security obligations.

 

Build a service-provider inventory

For each provider with access to customer information, document:

  • What information the provider can access
  • Why access is required
  • What security controls the provider maintains
  • How privileged access is controlled
  • How incidents are reported
  • What contractual requirements apply
  • How the relationship is monitored
  • What happens to information when the relationship ends

This turns vendor management into an active part of the firm's security program rather than an annual questionnaire exercise.

 

What happens if an accounting firm has a security incident?

The Safeguards Rule requires a written incident response plan.

The plan should establish how the firm identifies, responds to, and recovers from security events, including roles, responsibilities, communication, remediation, documentation, reporting, and post-incident review.

For an accounting firm, consider a compromised Microsoft 365 account.

The incident response process should establish:

  1. Who receives the initial report.
  2. Who can secure the account.
  3. Who investigates suspicious activity.
  4. How potentially affected customer information is identified.
  5. When outside security or legal resources are engaged.
  6. Who determines whether notification obligations apply.
  7. How the incident is documented.
  8. How lessons learned become changes to the security program.

 

Does GLBA require FTC breach notification?

Certain security incidents trigger a specific FTC notification requirement.

Under the Safeguards Rule, covered financial institutions must notify the FTC as soon as possible and no later than 30 days after discovering a notification event involving unauthorized acquisition of unencrypted customer information affecting at least 500 consumers.

The FTC describes a notification event as the unauthorized acquisition of unencrypted customer information. The rule also addresses circumstances involving access to an encryption key.

This is not the only notification requirement an accounting firm may face. State breach-notification laws, contractual requirements, professional obligations, and other regulations may also apply depending on the circumstances.

 

How to determine whether your firm is GLBA-ready

The most useful assessment is not simply a list of yes-or-no compliance questions.

It should connect requirements → current controls → gaps → actions → measurable outcomes.

A practical assessment can use the following framework:

Area What to evaluate Example measure
GLBA scope Whether the firm and relevant activities are covered Documented coverage determination
Governance Qualified Individual and program ownership Named owner and annual reporting
Risk Written risk assessment and reassessment Open high-risk items and remediation status
Identity MFA, privileged access, account lifecycle MFA and privileged-account coverage
Data Customer information inventory and protection Known repositories and access paths
Endpoints Device management and protection Managed-device coverage
Monitoring Detection and investigation capabilities Alert coverage and response time
People Training and security behavior Completion and reporting rates
Vendors Third-party access and oversight Critical providers reviewed
Response Incident response readiness Time to detect, contain, and document

 

This gives leadership a way to see whether the firm's security program is improving rather than simply whether a policy exists.

 

A practical GLBA compliance checklist for accounting firms

Use this as a starting point for evaluating your current program.

 

Determine whether GLBA applies

  • Confirm which GLBA requirements apply to the firm.
  • Identify the firm's applicable regulatory jurisdiction.
  • Document the firm's coverage determination.
  • Identify the customer information subject to the applicable requirements.

 

Establish governance

  • Designate a Qualified Individual.
  • Define executive oversight.
  • Maintain a written information security program.
  • Establish a regular review cadence.
  • Provide required leadership reporting.

 

Assess risk

  • Identify customer information.
  • Map where information is stored and transmitted.
  • Identify internal and external threats.
  • Evaluate current safeguards.
  • Document gaps and remediation priorities.
  • Periodically reassess the risks.

 

Secure identities and systems

  • Enforce MFA.
  • Review privileged accounts.
  • Apply least-privilege access.
  • Secure endpoints.
  • Protect email.
  • Monitor relevant security events.
  • Review third-party application access.

 

Protect data

  • Encrypt customer information.
  • Control external sharing.
  • Establish retention requirements.
  • Securely dispose of information when appropriate.
  • Protect backups and recovery systems.

 

Manage people and vendors

  • Provide security awareness training.
  • Measure employee security behavior.
  • Review service providers with access to customer information.
  • Establish appropriate contractual safeguards.
  • Periodically reassess critical providers.

 

Prepare for incidents

  • Maintain a written incident response plan.
  • Define roles and escalation paths.
  • Test the response process.
  • Establish a process for determining notification obligations.
  • Document incidents and corrective actions.

 

What should you do if your firm is not meeting every requirement?

A gap does not have to become an all-or-nothing compliance exercise.

Start with the risks that could have the greatest impact on customer information and the controls that can materially reduce those risks.

For many firms, that means establishing a reliable baseline around identity, privileged access, endpoint security, email, data protection, vulnerability management, monitoring, employee behavior, and incident response.

Then establish measurable remediation targets.

For example:

Instead of: "Improve Microsoft 365 security."

Use: "Reach 100% MFA coverage for all users with access to customer information, review privileged accounts monthly, and remediate identified high-risk identity findings within the defined target."

Instead of: "Improve employee security awareness."

Use: "Complete required training for all personnel and increase the percentage of employees who report simulated phishing messages over the next two quarters."

Instead of: "Improve incident response."

Use: "Document and test the incident response process, assign response owners, and establish target times for detection, containment, investigation, and escalation."

The difference is measurable behavior and control effectiveness rather than simply having a policy on file.

 

The real GLBA question is whether your security program works

For an accounting firm, determining whether GLBA applies is the starting point, not the finish line.

If the firm is covered, the Safeguards Rule provides a framework for building an information security program around the information the firm handles and the risks it faces.

That means knowing what customer information exists, controlling who can access it, protecting the systems that process it, evaluating third-party providers, training employees, monitoring security controls, and maintaining an incident response process.

For firms operating in Microsoft 365, identity is often a particularly important part of that environment. But Microsoft 365 security controls are only one component of the broader program. Customer information can move through tax applications, document platforms, endpoints, email, cloud services, and external providers.

The practical test is therefore not whether the firm owns the right security tools.

It is whether the firm can demonstrate:

What information do we need to protect?

What risks have we identified?

What safeguards address those risks?

How do we know those safeguards are working?

Who is responsible for fixing gaps?

What happens when something goes wrong?

That is the foundation of a GLBA information security program that can be managed, measured, and improved over time.

 

FAQ

Does GLBA apply to accounting firms?

GLBA can apply to accounting firms, particularly firms providing services that qualify as financial activities under the law. The FTC specifically identifies accountants and tax preparers among businesses that may qualify as financial institutions. Whether a specific firm is covered depends on its activities and applicable regulatory jurisdiction.

How do I know if my accounting firm needs to comply with GLBA?

Start by determining whether the firm's activities fall within GLBA's definition of financial activities and which regulator has jurisdiction. The FTC identifies tax preparation firms and accountants among businesses that may fall within the scope of the rules it enforces. Firms with uncertainty about their legal coverage should consult qualified legal or compliance counsel.

What is the GLBA Safeguards Rule?

The GLBA Safeguards Rule requires covered financial institutions under FTC jurisdiction to develop, implement, and maintain a written information security program with administrative, technical, and physical safeguards designed to protect customer information.

What does the GLBA Safeguards Rule require from accounting firms?

Requirements include designating a Qualified Individual, conducting a written risk assessment, implementing appropriate safeguards, monitoring and testing controls, training employees, overseeing service providers, maintaining an incident response plan, and providing required leadership reporting.

Does GLBA require multifactor authentication for accounting firms?

The FTC Safeguards Rule requires covered organizations to implement multifactor authentication for individuals accessing customer information on their information systems, unless an equivalent form of secure access control is approved in writing by the Qualified Individual.

What information does GLBA protect at an accounting firm?

The Safeguards Rule protects customer information, including records containing nonpublic personal information handled or maintained by or on behalf of a covered financial institution. For accounting firms, this can include tax information, Social Security numbers, financial statements, account information, and other sensitive client financial information.

Does GLBA require a written information security program?

Yes. Covered organizations subject to the FTC Safeguards Rule must develop, implement, and maintain a written information security program appropriate to their size and complexity, activities, and the sensitivity of customer information.

Does GLBA require a risk assessment?

Yes. The Safeguards Rule requires a written risk assessment that identifies reasonably foreseeable internal and external risks to customer information and evaluates the safeguards used to address those risks. The assessment must be periodically reassessed as circumstances change.

Does GLBA require accounting firms to have an incident response plan?

Yes. Covered organizations must maintain a written incident response plan addressing how the organization will respond to security events, including roles, communications, remediation, documentation, and reporting.

Does GLBA require an accounting firm to report a data breach to the FTC?

Certain security incidents require notification to the FTC. A covered financial institution must notify the FTC as soon as possible and no later than 30 days after discovering a qualifying notification event involving unauthorized acquisition of unencrypted customer information affecting at least 500 consumers.

Does using Microsoft 365 make an accounting firm GLBA compliant?

No. Microsoft 365 can provide security capabilities that support GLBA safeguards, including identity protection, multifactor authentication, access controls, encryption, endpoint management, and monitoring. However, GLBA compliance depends on the firm's overall information security program, including its people, processes, applications, service providers, risk assessment, and incident response capabilities.

What should an accounting firm do first if it has not assessed GLBA compliance?

First determine whether the firm is covered and identify the customer information subject to the applicable requirements. Then conduct a written risk assessment, document existing safeguards, identify gaps, and prioritize remediation based on the risks to customer information. A legal or compliance professional can help establish the firm's regulatory obligations, while IT and security professionals can assess the technical and operational controls.