Sourcepass Blog

The GLBA Safeguards Rule Checklist for Accounting Firms | Sourcepass

Written by Robert Villano | Sep 25, 2026

For accounting firms, GLBA compliance is not just a privacy requirement. The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires covered financial institutions to develop, implement, and maintain a written information security program designed to protect customer information.

For accounting firms that handle tax returns, financial records, payroll information, banking details, and other sensitive customer data, that means regulatory requirements need to translate into practical cybersecurity controls.

The key question is not simply whether your firm has a written security policy. It is whether the policies, technologies, processes, and employee behaviors that make up your security program actually address the risks to customer information.

This GLBA Safeguards Rule checklist breaks the requirements into practical areas accounting firms can use to evaluate their cybersecurity program, identify gaps, and establish measurable improvements.

 

What Is the GLBA Safeguards Rule?

The GLBA requires covered financial institutions under the Federal Trade Commission's jurisdiction to safeguard sensitive customer information. The FTC's definition of financial institutions is broader than banks and traditional financial services companies and can include businesses such as tax preparers and accountants depending on the activities they perform.

The Safeguards Rule specifically focuses on information security. Covered organizations must develop, implement, and maintain a comprehensive written information security program with administrative, technical, and physical safeguards appropriate to the organization's size, complexity, activities, and the sensitivity of the information it handles.

The FTC's Safeguards Rule guidance provides the detailed requirements.

For an accounting firm, the practical implication is straightforward: GLBA compliance should be connected to the firm's actual IT environment, customer data, employees, vendors, and security operations.

 

GLBA Safeguards Rule Checklist for Accounting Firms

The following checklist translates the Safeguards Rule into the areas an accounting firm should be able to demonstrate, document, and regularly review.

Area What to evaluate Example measure
Written information security program Is there a documented program covering administrative, technical, and physical safeguards? Program reviewed and approved annually
Risk assessment Has the firm documented foreseeable internal and external risks to customer information? Risk assessment completed and updated periodically
Access controls Is access limited to people with a legitimate business need? Quarterly access review completion
MFA Is multifactor authentication enabled for users accessing customer information? 100% of applicable users protected by MFA
Encryption Is customer information encrypted at rest and in transit? Encryption coverage across identified systems
Secure configuration Are systems configured and maintained using appropriate security controls? Critical configuration gaps remediated within defined timeframe
Monitoring and detection Can the firm identify suspicious activity affecting customer information? Alerts monitored and investigated according to defined procedures
Incident response Does the firm have a documented process for responding to security incidents? Incident response plan tested annually
Security awareness Do employees receive security awareness training appropriate to their roles? Training completion and phishing-test results
Vendor oversight Are service providers evaluated and contractually required to maintain safeguards? High-risk vendors reviewed annually
Data retention and disposal Does the firm know what information it retains and when it should be securely disposed of? Retention schedules and disposal controls documented
Security testing Are safeguards regularly monitored and tested? Vulnerability assessments, penetration testing, or continuous monitoring
Program governance Does leadership receive regular reporting on the security program? Written security program report provided at least annually

 

The checklist is useful as a starting point, but compliance is not achieved by checking boxes once. The Safeguards Rule expects organizations to maintain and adjust their information security program as risks, technology, and business operations change.

 

1. Written Information Security Program

A written information security program is the foundation of GLBA compliance.

The program should describe how the firm protects customer information and how security responsibilities are managed. It should be appropriate to the firm's size and complexity, the nature and scope of its activities, and the sensitivity of its customer information.

A useful program should answer practical questions such as:

  • What customer information does the firm collect and store?
  • Where is that information located?
  • Who can access it?
  • What systems and applications process it?
  • What security controls protect it?
  • Who is responsible for managing the security program?
  • How are security incidents handled?
  • How are vendors evaluated?
  • How is the program tested and updated?

The document should reflect how the firm actually operates. A policy that describes controls the firm does not use creates a documentation gap rather than reducing risk.

 

What to measure

At a minimum, leadership should be able to determine:

  • When the information security program was last reviewed
  • Which executive or qualified individual is responsible for it
  • Which risks and control gaps were identified
  • Which remediation activities remain open
  • When the program will next be reviewed

 

2. Written Risk Assessment

The Safeguards Rule requires the information security program to be based on a written risk assessment.

For an accounting firm, that assessment should identify reasonably foreseeable internal and external risks to customer information and evaluate whether existing safeguards adequately address those risks.

The assessment should consider the firm's actual technology environment rather than relying on a generic cybersecurity template.

That can include:

  • Microsoft 365 and identity infrastructure
  • Email and phishing risks
  • Endpoints and workstations
  • Tax and accounting applications
  • Cloud document management
  • OneDrive and SharePoint
  • Customer portals
  • Remote access
  • Backup systems
  • Third-party applications
  • Managed service providers
  • Employees and contractors
  • Physical records and devices

The goal is to create a connection between risk → control → evidence → remediation.

 

What to measure

A useful risk assessment can track:

  • Number of identified risks
  • Risk severity
  • Existing controls
  • Control gaps
  • Assigned owners
  • Remediation deadlines
  • Residual risk after remediation

This makes the risk assessment a management tool rather than a compliance document that sits unused.

 

3. Access Controls

Accounting firms should be able to demonstrate that access to customer information is limited to people who have a legitimate business need.

This starts with understanding who can access what.

Review access to:

  • Microsoft 365 accounts
  • Email
  • SharePoint and OneDrive
  • Tax and accounting applications
  • Customer portals
  • File servers
  • Backup systems
  • Administrative accounts
  • Security tools
  • Third-party applications

Access should be based on role and business need, not simply on historical permissions.

 

What to measure

Consider tracking:

  • Percentage of users reviewed during access reviews
  • Number of excessive permissions removed
  • Number of inactive accounts disabled
  • Number of privileged accounts
  • Time required to disable access after an employee leaves

For Microsoft 365 environments, identity security should be part of the firm's broader GLBA control strategy rather than treated as a separate IT concern.

 

4. Multifactor Authentication

Multifactor authentication (MFA) is one of the most important identity controls for protecting customer information.

The Safeguards Rule requires MFA for individuals accessing customer information on information systems, unless an equivalent form of secure access control is approved in writing by the Qualified Individual.

For accounting firms, MFA should extend beyond email where applicable. Review access to the systems that store, process, or provide access to customer information.

That can include:

  • Microsoft 365
  • Administrative accounts
  • Tax applications
  • Accounting platforms
  • Remote access systems
  • Customer portals
  • Backup platforms
  • Cloud applications

 

What to measure

A straightforward KPI is:

MFA coverage = users protected by MFA ÷ users requiring access × 100

The objective should be to identify and eliminate exceptions, rather than simply reporting that MFA is "enabled."

 

5. Encryption

The Safeguards Rule requires covered organizations to encrypt customer information on their systems and while it is in transit, unless encryption is not feasible and effective alternative controls are approved in writing by the Qualified Individual.

For accounting firms, encryption should be evaluated across the firm's actual information flow.

Consider:

  • Email
  • Cloud storage
  • Laptops
  • Mobile devices
  • Servers
  • Backups
  • File transfers
  • Customer portals
  • Removable media

Encryption should also be considered alongside identity controls. Encrypting data does not eliminate the need to control who can access it.

 

What to measure

Track encryption coverage across systems containing customer information and document any approved exceptions and compensating controls.

 

6. Secure Configuration and System Protection

GLBA compliance is not limited to policies and identity controls. The firm's systems must also be configured and maintained in a way that protects customer information.

A practical review should address:

  • Endpoint security
  • Operating system patching
  • Application updates
  • Firewall configuration
  • Secure remote access
  • Administrative privileges
  • Mobile device security
  • Cloud configuration
  • Backup protection
  • Security baselines

For firms using Microsoft 365, this can include reviewing identity, device, email, and cloud security configurations rather than assuming that purchasing the platform automatically establishes a compliant security program.

 

What to measure

Useful operational measures include:

  • Critical vulnerabilities outstanding
  • Percentage of supported endpoints
  • Patch compliance
  • Number of high-risk configuration findings
  • Average time to remediate critical findings

 

7. Monitoring and Detection

A security program should not depend entirely on employees reporting suspicious activity after something has already happened.

The Safeguards Rule calls for monitoring and testing the effectiveness of safeguards. For an accounting firm, that means having appropriate visibility into systems that contain or provide access to customer information.

Monitoring can include:

  • Suspicious sign-ins
  • Privileged account activity
  • Endpoint alerts
  • Email security events
  • Unusual data access
  • Malware detections
  • Authentication anomalies
  • Cloud application activity
  • Backup failures

The specific technology will vary by firm, but the underlying question is consistent:

Can the firm identify meaningful security events quickly enough to investigate and respond?

 

What to measure

Consider tracking:

  • Security events detected
  • Alerts investigated
  • Mean time to investigate
  • Mean time to contain
  • Unresolved high-severity alerts
  • Coverage of critical systems

 

8. Incident Response

A written incident response plan is another core component of the Safeguards Rule.

The plan should establish what happens when a security incident affects the confidentiality, integrity, or availability of customer information.

It should define:

  • Who declares an incident
  • Who investigates it
  • Who has authority to make decisions
  • How systems are contained
  • How evidence is preserved
  • How affected parties are identified
  • How legal and regulatory obligations are evaluated
  • How customers and other stakeholders are communicated with
  • How the incident is documented
  • How lessons learned are incorporated into the security program

An incident response plan should be tested, not simply stored in a policy repository.

 

What to measure

Track:

  • Date of most recent incident response exercise
  • Time to identify an incident
  • Time to contain an incident
  • Outstanding remediation items
  • Completion of post-incident reviews

The firm's incident response process should also account for the GLBA notification requirement. Under the Safeguards Rule, certain notification events involving at least 500 consumers' unencrypted customer information must be reported to the FTC as soon as possible and no later than 30 days after discovery.

The specific regulatory threshold and definition matter, so firms should involve appropriate legal or compliance professionals when determining whether an incident is reportable.

 

9. Employee Security Awareness

Technology controls are only one part of an accounting firm's security program.

Employees interact with customer information every day through email, document sharing, tax applications, cloud systems, and customer communications. Security awareness should therefore address the behaviors most relevant to the firm's actual risks.

Training should cover topics such as:

  • Phishing
  • Business email compromise
  • Credential protection
  • MFA
  • Secure document handling
  • Data sharing
  • Suspicious requests
  • Incident reporting
  • Remote work
  • Use of personal devices
  • Social engineering

 

What to measure

Security awareness becomes more useful when behavior can be measured.

Examples include:

  • Training completion rate
  • Phishing simulation reporting rate
  • Phishing click rate
  • Time to report suspicious messages
  • Repeat training requirements

The objective is not simply 100% training completion. It is measurable improvement in security-related behavior.

 

10. Vendor and Service Provider Oversight

Accounting firms frequently rely on third-party providers to store, process, transmit, or protect customer information.

That creates another part of the firm's security program.

The FTC requires covered financial institutions to take reasonable steps to select and retain service providers capable of maintaining appropriate safeguards and to require appropriate safeguards through contracts.

A vendor review should consider:

  • What customer information does the provider handle?
  • Where is it stored?
  • How is access controlled?
  • Is MFA supported?
  • Is data encrypted?
  • How are security incidents reported?
  • What security testing is performed?
  • How are subcontractors managed?
  • What happens to the firm's data when the relationship ends?

 

What to measure

Create a vendor inventory that identifies:

  • Critical vendors
  • Data handled
  • Risk level
  • Contract requirements
  • Security documentation
  • Last review date
  • Next review date
  • Open findings

Not every vendor needs the same level of scrutiny. Prioritize providers with direct access to sensitive customer information or critical systems.

 

11. Data Retention and Secure Disposal

GLBA security responsibilities extend through the information lifecycle.

Accounting firms should understand what customer information they retain, why they retain it, where it resides, and when it should be securely disposed of.

Review:

  • Paper records
  • Email
  • Cloud storage
  • File shares
  • Tax documents
  • Accounting records
  • Backups
  • Retired devices
  • Removable media

A data inventory can help identify information that exists outside the firm's expected systems.

 

What to measure

Consider tracking:

  • Systems containing customer information
  • Data retention periods
  • Records eligible for disposal
  • Completed secure disposal activities
  • Exceptions requiring additional review

The goal is to reduce unnecessary data exposure while preserving information the firm is required to retain.

 

12. Regular Security Testing

A security program should provide evidence that its safeguards are working.

The Safeguards Rule requires covered organizations to regularly monitor and test the effectiveness of their safeguards. Depending on the firm's monitoring capabilities, this can include continuous monitoring, penetration testing, vulnerability assessments, and other forms of security testing.

The important distinction is between having a control and demonstrating that the control works.

For example:

  • MFA is configured, but are exceptions identified?
  • Backups exist, but can the firm restore from them?
  • Endpoint protection is deployed, but are alerts being investigated?
  • Access controls exist, but are permissions reviewed?
  • Security awareness training is assigned, but is employee behavior improving?

 

What to measure

A practical security testing dashboard can include:

  • Critical vulnerabilities
  • Vulnerability remediation time
  • Penetration testing findings
  • Failed controls
  • Open remediation items
  • Backup recovery test results
  • Security exercise results

 

13. Security Program Governance

The Safeguards Rule also establishes governance responsibilities.

A Qualified Individual must oversee and implement the information security program and provide written reporting to the firm's board or governing body, or an appropriate senior officer where there is no board or equivalent.

The report must address the overall status of the information security program and relevant matters such as risk assessments, control decisions, service provider arrangements, testing results, security events, management responses, and recommendations for changes.

For executives and firm leadership, this creates an opportunity to turn cybersecurity from a technical discussion into a business risk discussion.

A useful quarterly or annual security review should answer:

  • What are our highest cybersecurity risks?
  • Which controls are reducing those risks?
  • Where do material gaps remain?
  • What has changed since the previous assessment?
  • What incidents or significant security events occurred?
  • What remediation is underway?
  • What decisions or investments are required?

 

A Practical GLBA Compliance Checklist

An accounting firm evaluating its GLBA cybersecurity program can use the following checklist as a starting point.

 

Governance

  • Qualified Individual designated
  • Written information security program maintained
  • Security responsibilities clearly assigned
  • Leadership reporting established
  • Program reviewed and updated regularly

 

Risk Management

  • Written risk assessment completed
  • Customer information identified
  • Systems and data locations documented
  • Internal and external risks evaluated
  • Control gaps documented
  • Remediation owners and deadlines assigned,

 

Identity and Access

  • Access based on business need
  • Privileged access controlled
  • MFA enabled for applicable users
  • User access reviewed periodically
  • Former employee access removed promptly
  • Third-party access reviewed

 

Data Protection

  • Customer information encrypted
  • Encryption exceptions documented
  • Secure data transmission implemented
  • Data retention requirements documented
  • Secure disposal procedures established

 

Security Operations

  • Endpoint security deployed
  • Security configurations reviewed
  • Vulnerability management established
  • Security events monitored
  • Appropriate logging maintained
  • Security controls tested regularly

 

People

  • Security awareness training completed
  • Role-specific security training provided where appropriate
  • Phishing awareness measured
  • Employees know how to report suspicious activity

 

Third Parties

  • Service provider inventory maintained
  • High-risk vendors assessed
  • Security requirements included in contracts
  • Vendor security reviewed periodically
  • Vendor incident notification requirements documented

 

Incident Response

  • Written incident response plan maintained
  • Roles and responsibilities defined
  • Incident response exercises conducted
  • Regulatory notification requirements documented
  • Post-incident reviews completed
  • Lessons learned incorporated into security controls

 

How to Turn the Checklist Into a Measurable Security Program

The most useful GLBA compliance programs do not stop at documenting whether a control exists.

They establish measurable outcomes.

Instead of:

"We have MFA."

Track:

"99% of applicable user accounts have MFA enabled, with two documented exceptions scheduled for remediation."

Instead of:

"We conduct security awareness training."

Track:

"100% of employees completed training, and phishing simulation reporting improved from 62% to 81%."

Instead of:

"We perform vulnerability management."

Track:

"Critical vulnerabilities are remediated within the firm's defined target timeframe, with exceptions documented and reviewed."

This approach creates a direct connection between the GLBA requirement, the cybersecurity control, and the evidence that the control is working.

 

What GLBA Compliance Looks Like in a Microsoft 365 Environment

For accounting firms using Microsoft 365, many GLBA-related controls intersect directly with identity, endpoint, email, and cloud security.

A practical review should consider:

  • Microsoft 365 identity and authentication
  • MFA coverage
  • Privileged account management
  • Conditional access and access policies
  • Email security
  • SharePoint and OneDrive permissions
  • Endpoint security
  • Device management
  • Data protection and encryption
  • Security monitoring
  • Audit logging
  • Backup and recovery
  • Third-party application access

The objective is not to deploy every available security feature. It is to determine which controls address the firm's documented risks and whether those controls are consistently configured, monitored, and maintained.

For firms without internal security resources, this is also where a managed security or IT provider may support the firm's Qualified Individual and broader security program. The responsibility for the firm's information security program, however, should remain clearly defined within the organization.

 

The GLBA Checklist Is a Starting Point, Not the Program

The Safeguards Rule provides a framework for protecting customer information, but a checklist alone does not establish an effective information security program.

For an accounting firm, the more useful process is:

Identify → Assess → Protect → Monitor → Test → Respond → Improve

Start by identifying the customer information the firm handles and where it exists. Assess the risks surrounding that information. Implement controls that address those risks. Monitor whether the controls are working. Test them regularly. Respond when something goes wrong. Then use what you learn to improve the program.

That creates a security program that is not only easier to demonstrate from a compliance perspective, but also more useful as an ongoing management process.

 

FAQ

What is the GLBA Safeguards Rule for accounting firms?

The GLBA Safeguards Rule requires covered financial institutions under FTC jurisdiction to develop, implement, and maintain a written information security program with administrative, technical, and physical safeguards designed to protect customer information. Accounting firms may be covered depending on the financial activities they perform.

What should an accounting firm's GLBA compliance checklist include?

A GLBA compliance checklist should address the written information security program, risk assessment, access controls, MFA, encryption, secure system configuration, monitoring, incident response, employee security awareness, vendor oversight, data retention and disposal, security testing, and program governance.

Does GLBA require accounting firms to use multifactor authentication?

Yes. The Safeguards Rule requires multifactor authentication for individuals accessing customer information on information systems, unless an equivalent form of secure access control is approved in writing by the Qualified Individual overseeing the information security program.

Does the GLBA Safeguards Rule require encryption?

The Safeguards Rule requires covered organizations to encrypt customer information on their systems and while it is in transit, unless encryption is not feasible and effective alternative controls are approved in writing by the Qualified Individual.

Does GLBA require a written risk assessment?

Yes. A covered firm's information security program must be based on a written risk assessment that identifies reasonably foreseeable internal and external risks to customer information and evaluates the safeguards used to address those risks.

Does GLBA require employee security awareness training?

The Safeguards Rule requires covered organizations to implement policies and procedures to ensure personnel are able to enact the information security program. This includes security awareness training for employees and specialized training for personnel responsible for implementing the program.

Does GLBA require an incident response plan?

Yes. Covered organizations must have a written incident response plan designed to address security incidents affecting the confidentiality, integrity, or availability of customer information.

Does the GLBA Safeguards Rule require breach notification?

Certain security incidents must be reported to the FTC. A covered financial institution must notify the FTC as soon as possible, and no later than 30 days after discovery, when a notification event involves the information of at least 500 consumers. The rule defines a notification event based on unauthorized acquisition of unencrypted customer information, subject to the rule's specific requirements.

How often should an accounting firm review its GLBA security program?

The Safeguards Rule requires covered organizations to keep their information security program current and make adjustments based on monitoring, testing, risk assessments, vulnerabilities, and material changes to the business or its environment. Firms should establish a recurring review cadence rather than treating GLBA compliance as a one-time project.

Can Microsoft 365 help an accounting firm meet GLBA security requirements?

Microsoft 365 can provide security capabilities relevant to GLBA controls, including identity protection, MFA, access management, endpoint security, email security, encryption, and monitoring. However, using Microsoft 365 does not by itself make an accounting firm GLBA compliant. The firm still needs a risk-based information security program, appropriate configurations, documented processes, monitoring, testing, governance, and evidence that its safeguards are operating effectively.

What is the first step for an accounting firm evaluating GLBA compliance?

Start with a written risk assessment and data inventory. Identify what customer information the firm handles, where it is stored or transmitted, who can access it, which third parties process it, and what safeguards currently protect it. That provides the foundation for identifying gaps and prioritizing remediation.