GLBA Compliance for Accounting Firms: What You Need to Know
Sep 25, 2026 Robert Villano Security & Compliance | Governance, Risk & Compliance | Industry - Professional Services 12 min read
Accounting firms handle some of the most sensitive information their clients entrust to them, including tax records, Social Security numbers, financial statements, account information, payroll data, and other nonpublic personal information. For firms covered by the Gramm-Leach-Bliley Act (GLBA), protecting that information is not simply a matter of good IT hygiene. It is a regulatory obligation.
GLBA compliance for accounting firms centers on two related responsibilities: protecting customers' nonpublic personal information and maintaining an information security program designed to address the risks associated with that information.
The Federal Trade Commission (FTC) specifically identifies tax preparers, accountants, and other financial advisers among businesses that may qualify as financial institutions under GLBA. The FTC's GLBA guidance for businesses explains that coverage depends on the activities a business performs, not simply how the business describes itself.
For accounting firms using Microsoft 365, GLBA compliance also has a practical technology dimension. Identity controls, multifactor authentication, endpoint security, email protection, data access, encryption, monitoring, employee training, and incident response all contribute to the safeguards protecting customer information.
What is GLBA?
The Gramm-Leach-Bliley Act is a federal law focused on the privacy and security of consumers' financial information.
GLBA requires covered financial institutions to explain their information-sharing practices to customers and safeguard sensitive customer information. The law is implemented through regulations including the FTC's Privacy Rule and Safeguards Rule.
For accounting firms, the important distinction is that GLBA is not simply a requirement to keep files confidential. It creates expectations around how customer financial information is collected, used, shared, stored, protected, and ultimately disposed of.
Why does GLBA matter to accounting firms?
Accounting firms routinely handle information that can fall within GLBA's definition of nonpublic personal information, particularly when providing services to individuals.
The FTC identifies providing financial, investment, or economic advisory services as financial activities and specifically lists accountants and tax preparers among examples of businesses that may be covered. Whether a particular firm is subject to the rules depends on its activities and applicable regulatory jurisdiction.
That makes GLBA relevant to many accounting and tax practices, including firms that may not think of themselves as financial institutions in the traditional sense.
Who may be covered by GLBA?
GLBA uses a broader definition of "financial institution" than the term might suggest.
Under the FTC's Safeguards Rule, a financial institution is generally an entity engaged in an activity that is financial in nature or incidental to such financial activities, subject to the rule's jurisdiction and other provisions. The FTC specifically identifies tax preparation firms and certain financial advisers among examples of covered businesses.
Coverage is determined by the nature of the firm's activities rather than its industry label alone.
For an accounting firm, the first compliance question should therefore be:
Does our firm perform activities that bring us within the scope of GLBA and the FTC rules?
A qualified legal or compliance professional can help determine the firm's specific obligations, particularly if the firm operates across multiple regulatory jurisdictions.
What customer information does GLBA protect?
The Safeguards Rule protects "customer information," which includes records containing nonpublic personal information about a customer that are handled or maintained by or on behalf of the financial institution or its affiliates.
The Privacy Rule uses the related concept of nonpublic personal information, or NPI.
The FTC explains that NPI can include information an individual provides to obtain a financial product or service, information obtained through a transaction, and information obtained in connection with providing a financial product or service. Examples can include names, addresses, income information, Social Security numbers, account numbers, payment history, balances, and other financial information.
For an accounting firm, that can translate into a broad information environment.
Examples may include:
- Social Security numbers
- Tax returns and tax documents
- Income and employment information
- Bank and investment account information
- Financial statements
- Payment and transaction information
- Payroll records
- Estate and trust information
- Copies of identification documents
- Client correspondence containing financial information
- Information received from other financial institutions
- Data stored in accounting, tax, document-management, and cloud platforms
The important security question is not simply where the firm's "financial files" are stored.
It is:
Where does customer information exist across the firm's entire technology environment, and who can access it?
GLBA compliance for accounting firms: the Privacy Rule
GLBA's Privacy Rule addresses how covered financial institutions disclose and share consumers' nonpublic personal information.
Covered institutions generally must provide privacy notices explaining their information-sharing practices and, in certain circumstances, give consumers the ability to opt out of certain information sharing with nonaffiliated third parties.
The Privacy Rule is therefore broader than cybersecurity.
It addresses questions such as:
- What customer information does the firm collect?
- How is that information used?
- With whom is it shared?
- Under what circumstances can information be disclosed?
- What privacy notices must customers receive?
- When do customers have the right to opt out of certain disclosures?
An accounting firm's privacy obligations should be evaluated alongside, rather than substituted for, its information security program.
The GLBA Safeguards Rule
For accounting firms, the Safeguards Rule is where GLBA becomes particularly relevant to cybersecurity.
The FTC's Safeguards Rule requires covered financial institutions under its jurisdiction to develop, implement, and maintain a written information security program with administrative, technical, and physical safeguards designed to protect customer information.
The program must be appropriate to the firm's size and complexity, the nature and scope of its activities, and the sensitivity of the customer information it handles.
The objective is not to implement every available security technology.
It is to identify reasonably foreseeable risks and establish safeguards appropriate to those risks.
What does the Safeguards Rule require?
The Safeguards Rule establishes specific elements that covered organizations must address in their information security programs. These requirements provide a useful framework for accounting firms evaluating their cybersecurity maturity.
Designate a Qualified Individual
A covered firm must designate a Qualified Individual to implement and supervise its information security program.
That person can be an employee, affiliate, or service provider. However, using an outside IT or security provider does not transfer the firm's responsibility for compliance. The firm must retain responsibility and designate a senior member of its personnel to oversee the relationship.
For a small or midsize accounting firm, this distinction matters.
An outsourced IT provider may operate security tools and perform technical functions, but firm leadership still needs clear ownership of the information security program.
Conduct a written risk assessment
The information security program must be based on a written risk assessment.
The assessment should identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information and establish criteria for evaluating those risks. The firm must also periodically reassess risks as its operations and threat environment change.
A useful accounting-firm risk assessment should answer:
- What customer information do we have?
- Where is it stored?
- How does it move through our environment?
- Who can access it?
- Which applications and vendors have access?
- What happens if an employee account is compromised?
- What happens if a device is lost or stolen?
- What happens if email is compromised?
- What happens if a critical cloud application becomes unavailable?
- How quickly could the firm detect and respond to unauthorized access?
Implement appropriate safeguards
The Safeguards Rule requires organizations to implement safeguards that address the risks identified through their assessment.
The FTC identifies specific controls including access management, data inventory, encryption, application security, multifactor authentication, secure disposal, change management, and monitoring of user activity.
For a Microsoft 365 environment, these requirements can translate into practical controls such as:
- Multifactor authentication for users accessing customer information
- Conditional access and identity-based access controls
- Least-privilege permissions
- Endpoint protection and device management
- Encryption for customer information at rest and in transit
- Email security and phishing protection
- Logging and security monitoring
- Regular access reviews
- Secure configuration management
- Data retention and secure disposal procedures
- Protection of customer information across connected applications
The specific technology should follow the firm's risk assessment rather than the other way around.
Monitor and test security controls
Security controls need to be tested to determine whether they are actually working.
The Safeguards Rule requires covered institutions to regularly monitor and test the effectiveness of their safeguards. The FTC notes that continuous monitoring can satisfy the testing requirement for information systems; otherwise, the rule specifies annual penetration testing and vulnerability assessments, including system-wide scans every six months for publicly known vulnerabilities, along with additional testing in certain circumstances.
This is an important distinction between having security tools and operating a security program.
A firm should be able to demonstrate not only that a control exists, but that it is being monitored, reviewed, and improved.
Train employees
Employees are part of the information security program.
The Safeguards Rule requires security awareness training and specialized training for personnel with hands-on responsibility for implementing the information security program.
For accounting firms, training should address behaviors employees encounter in their normal work, including:
- Phishing and credential theft
- Suspicious attachments and links
- Business email compromise
- Handling tax and financial documents
- Secure file sharing
- Password and authentication practices
- Use of personal devices
- Reporting suspected security incidents
The objective should be measurable behavior change, not simply completion of an annual training module.
Useful measures can include training completion, phishing-reporting behavior, repeat failures, MFA adoption, and time to report suspected incidents.
Written information security program: what should it contain?
A GLBA information security program should not be a policy document that sits untouched in a compliance folder.
It should describe how the firm actually manages information security.
The Safeguards Rule addresses:
- Risk assessment
- Access controls
- Data and system inventories
- Encryption
- Application security
- Multifactor authentication
- Secure disposal
- Change management
- Monitoring and testing
- Employee training
- Service-provider oversight
- Incident response
- Ongoing program updates
- Leadership reporting
The Qualified Individual must also provide a written report to the firm's board or governing body, or an appropriate senior officer if there is no board or equivalent body, at least annually. The report must address the overall status of the program and material matters such as risk assessments, control decisions, service providers, testing, security events, and recommended changes.
For executive leadership, this creates an opportunity to turn cybersecurity from a collection of technical activities into a measurable risk-management program.
GLBA and service providers
Accounting firms rarely operate entirely on their own infrastructure.
Customer information may pass through:
- Cloud accounting platforms
- Tax software
- Document management systems
- Payroll platforms
- Microsoft 365
- Managed IT providers
- Managed security providers
- Backup providers
- File-sharing platforms
- E-signature services
- Other specialized applications
The Safeguards Rule requires covered institutions to select service providers capable of maintaining appropriate safeguards, require appropriate safeguards through contracts, monitor their performance, and periodically reassess their suitability.
This means vendor management is part of GLBA cybersecurity compliance.
What should accounting firms ask technology providers?
A practical service-provider review should consider:
- What customer information does the provider access?
- Why does it need that access?
- How is the information protected?
- Is multifactor authentication required?
- Is information encrypted?
- How is privileged access controlled?
- What security monitoring is performed?
- How are vulnerabilities identified and remediated?
- How are security incidents reported?
- What happens to customer information when the relationship ends?
- What contractual security obligations apply?
- How is the provider's security posture reassessed?
The goal is not to collect security questionnaires for their own sake.
The goal is to understand where responsibility sits across the firm's technology ecosystem.
GLBA incident response and notification
A GLBA information security program must include a written incident response plan.
The plan should establish the firm's response objectives, internal processes, roles and decision-making authority, communication procedures, remediation processes, documentation and reporting requirements, and post-incident review.
That plan should be practical enough to use during an actual security event.
For example, if an employee's Microsoft 365 credentials are compromised, the firm should already know:
- Who receives the initial report.
- Who can disable or secure the account.
- Who investigates the activity.
- Who determines what customer information may have been accessed.
- Who coordinates with the IT or security provider.
- Who determines whether legal or regulatory notification obligations apply.
- How the incident and response will be documented.
- How lessons learned will be incorporated into future controls.
When does the Safeguards Rule require FTC notification?
The Safeguards Rule includes a specific notification requirement for certain security breaches.
Covered financial institutions must notify the FTC as soon as possible and no later than 30 days after discovery of a notification event involving the unauthorized acquisition of unencrypted customer information affecting at least 500 consumers.
This requirement took effect in May 2024.
The FTC's notification requirement is only one part of an incident response process. Accounting firms may also have obligations under other federal, state, contractual, or professional requirements depending on the circumstances.
How to evaluate your accounting firm's current security controls
A GLBA assessment should begin with information and risk, not with a list of security products.
A practical review can be organized into six areas.
| Area | Questions to evaluate | Example measure |
|---|---|---|
| Identity | Who can access customer information? Is MFA enforced? | MFA coverage and privileged-account coverage |
| Data | Where is customer information stored and shared? | Known data repositories and access paths |
| Endpoints | Are devices protected and managed? | Managed-device coverage and unresolved critical findings |
| Monitoring | Can the firm detect suspicious activity? | Alert coverage and response time |
| People | Do employees recognize and report threats? | Training completion, reporting rate, repeat failures |
| Response | Can the firm contain and investigate an incident? | Time to detect, contain, and document incidents |
For Microsoft 365 environments, the review should extend beyond the Microsoft 365 admin center.
Identity, endpoints, email, cloud applications, file storage, third-party integrations, privileged access, and security monitoring should be evaluated as one connected environment.
A practical GLBA cybersecurity checklist for accounting firms
Use the following checklist as a starting point for an internal review:
Governance
- Confirm whether the firm is subject to GLBA and which rules apply.
- Designate a Qualified Individual.
- Establish executive oversight of the information security program.
- Maintain a written information security program.
- Perform and document a risk assessment.
- Establish a process for periodic reassessment.
Identity and access
- Require multifactor authentication for access to customer information.
- Review privileged accounts.
- Apply least-privilege access.
- Regularly review user access.
- Remove access promptly when employees or contractors leave.
Data protection
- Inventory customer information.
- Identify where it is stored and transmitted.
- Encrypt customer information at rest and in transit.
- Establish retention and secure disposal procedures.
- Review external sharing and file-transfer processes.
Microsoft 365 security
- Enforce MFA across relevant Microsoft 365 accounts.
- Review identity and conditional access policies.
- Protect privileged administrator accounts.
- Secure endpoints accessing customer information.
- Monitor sign-ins and other relevant security events.
- Review third-party applications and integrations.
- Establish appropriate email and phishing protections.
Testing and monitoring
- Conduct required vulnerability assessments and testing.
- Monitor security controls.
- Review security findings and remediation status.
- Track unresolved high-risk issues.
- Retest significant vulnerabilities after remediation.
People
- Provide security awareness training.
- Train personnel with security responsibilities.
- Test employee response to common threats.
- Track reporting behavior and repeat failures.
Service providers
- Inventory providers with access to customer information.
- Evaluate their security practices.
- Include appropriate security requirements in contracts.
- Monitor provider performance.
- Periodically reassess provider risk.
Incident response
- Maintain a written incident response plan.
- Define roles and decision-making authority.
- Establish escalation procedures.
- Document security events and response activities.
- Establish a process for determining regulatory notification requirements.
- Conduct post-incident reviews.
What GLBA compliance should look like operationally
A mature GLBA program is not simply a binder of policies or a list of cybersecurity products.
It should create a repeatable operating cycle:
Identify → Assess → Protect → Monitor → Respond → Improve
The firm's risk assessment identifies what needs protection. Security controls address those risks. Monitoring provides evidence that controls are working. Incident response establishes what happens when they are not. Leadership review then drives changes to the program.
That cycle also gives executives something more useful than a generic statement that the firm is "secure."
Leadership can instead track measurable indicators such as:
- Percentage of users protected by MFA
- Percentage of privileged accounts reviewed
- Percentage of endpoints under management
- Number and age of unresolved high-risk vulnerabilities
- Security awareness completion and reporting rates
- Time to detect and contain security incidents
- Percentage of critical service providers reviewed
- Completion of required security testing
- Progress against identified risk-remediation priorities
These measures help connect GLBA compliance to actual changes in security posture.
Start with the gap between policy and practice
For accounting firms, the most useful GLBA assessment is often not a review of whether policies exist.
It is a comparison between what the firm's policies say should happen and what actually happens.
If the policy requires MFA, is MFA enforced for every relevant account?
If the firm says customer information is encrypted, where is that information stored and how is encryption verified?
If an employee leaves, how quickly is access removed?
If a security alert occurs, who investigates it?
If a service provider has access to client information, when was that provider last assessed?
If an incident occurs, can the firm demonstrate what happened, what information was affected, and how the response was managed?
Those questions turn GLBA from a compliance exercise into a practical cybersecurity framework.
For accounting firms using Microsoft 365 and cloud-based applications, that distinction is especially important. Customer information can move across identities, devices, email, applications, and external providers every day. Effective GLBA compliance therefore depends on understanding the entire information environment and continuously improving the controls that protect it.
FAQ
Does GLBA apply to accounting firms?
GLBA can apply to accounting firms because the FTC identifies accountants and tax preparers among businesses that may qualify as financial institutions based on their financial activities. Whether a specific firm is covered depends on its activities, applicable jurisdiction, and other circumstances.
What is GLBA compliance for accounting firms?
GLBA compliance for accounting firms involves protecting covered customer financial information and meeting applicable privacy and information security requirements. For firms subject to the FTC's Safeguards Rule, this includes maintaining a written information security program based on a risk assessment and implementing appropriate administrative, technical, and physical safeguards.
What information does GLBA protect?
GLBA protects nonpublic personal information and, under the Safeguards Rule, customer information containing such information. Examples can include Social Security numbers, income information, account numbers, payment information, financial statements, and other information collected or maintained in connection with financial services.
What is the GLBA Safeguards Rule?
The GLBA Safeguards Rule requires covered financial institutions under FTC jurisdiction to develop, implement, and maintain a written information security program designed to protect customer information. The program must address risks appropriate to the organization's size, complexity, activities, and the sensitivity of its information.
Does GLBA require multifactor authentication?
Yes. The FTC Safeguards Rule requires multifactor authentication for individuals accessing customer information on the organization's information system, unless the Qualified Individual has approved in writing an equivalent form of secure access control.
Does GLBA require a written information security program?
Yes. Covered organizations under the Safeguards Rule must maintain a written information security program appropriate to their size and complexity, activities, and the sensitivity of customer information.
Does GLBA require an incident response plan?
Yes. The Safeguards Rule requires a written incident response plan covering areas such as response processes, roles and responsibilities, communications, remediation, documentation, reporting, and post-incident review.
Does GLBA require accounting firms to notify the FTC after a data breach?
Certain breaches trigger an FTC notification requirement. Covered financial institutions must notify the FTC as soon as possible and no later than 30 days after discovery of a qualifying notification event involving unauthorized acquisition of unencrypted customer information affecting at least 500 consumers.
Are accounting firm's IT service providers subject to GLBA requirements?
Covered accounting firms remain responsible for overseeing service providers that handle customer information. The Safeguards Rule requires firms to select providers capable of maintaining appropriate safeguards, address security requirements contractually, monitor provider performance, and periodically reassess provider suitability.
Does Microsoft 365 help with GLBA compliance?
Microsoft 365 can provide security capabilities that support a GLBA information security program, including identity controls, multifactor authentication, access management, encryption, endpoint management, and security monitoring. However, using Microsoft 365 does not by itself make an accounting firm GLBA compliant. The firm must evaluate its overall information security program, controls, processes, people, applications, and service providers against its risks and applicable requirements.
How can an accounting firm assess GLBA cybersecurity compliance?
Start by identifying customer information and where it resides, conducting a documented risk assessment, reviewing identity and access controls, evaluating encryption and endpoint protection, testing security controls, reviewing service providers, assessing employee security behavior, and validating the firm's incident response capabilities. The assessment should result in prioritized remediation actions with measurable owners and deadlines.
Subscribe To
Sourcepass Insights
Sourcepass Insights
Stay in the loop and never miss out on the latest updates by subscribing to our newsletter today!