For accounting firms, GLBA compliance is not just a privacy requirement. The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires covered financial institutions to develop, implement, and maintain a written information security program designed to protect customer information.
For accounting firms that handle tax returns, financial records, payroll information, banking details, and other sensitive customer data, that means regulatory requirements need to translate into practical cybersecurity controls.
The key question is not simply whether your firm has a written security policy. It is whether the policies, technologies, processes, and employee behaviors that make up your security program actually address the risks to customer information.
This GLBA Safeguards Rule checklist breaks the requirements into practical areas accounting firms can use to evaluate their cybersecurity program, identify gaps, and establish measurable improvements.
The GLBA requires covered financial institutions under the Federal Trade Commission's jurisdiction to safeguard sensitive customer information. The FTC's definition of financial institutions is broader than banks and traditional financial services companies and can include businesses such as tax preparers and accountants depending on the activities they perform.
The Safeguards Rule specifically focuses on information security. Covered organizations must develop, implement, and maintain a comprehensive written information security program with administrative, technical, and physical safeguards appropriate to the organization's size, complexity, activities, and the sensitivity of the information it handles.
The FTC's Safeguards Rule guidance provides the detailed requirements.
For an accounting firm, the practical implication is straightforward: GLBA compliance should be connected to the firm's actual IT environment, customer data, employees, vendors, and security operations.
The following checklist translates the Safeguards Rule into the areas an accounting firm should be able to demonstrate, document, and regularly review.
| Area | What to evaluate | Example measure |
|---|---|---|
| Written information security program | Is there a documented program covering administrative, technical, and physical safeguards? | Program reviewed and approved annually |
| Risk assessment | Has the firm documented foreseeable internal and external risks to customer information? | Risk assessment completed and updated periodically |
| Access controls | Is access limited to people with a legitimate business need? | Quarterly access review completion |
| MFA | Is multifactor authentication enabled for users accessing customer information? | 100% of applicable users protected by MFA |
| Encryption | Is customer information encrypted at rest and in transit? | Encryption coverage across identified systems |
| Secure configuration | Are systems configured and maintained using appropriate security controls? | Critical configuration gaps remediated within defined timeframe |
| Monitoring and detection | Can the firm identify suspicious activity affecting customer information? | Alerts monitored and investigated according to defined procedures |
| Incident response | Does the firm have a documented process for responding to security incidents? | Incident response plan tested annually |
| Security awareness | Do employees receive security awareness training appropriate to their roles? | Training completion and phishing-test results |
| Vendor oversight | Are service providers evaluated and contractually required to maintain safeguards? | High-risk vendors reviewed annually |
| Data retention and disposal | Does the firm know what information it retains and when it should be securely disposed of? | Retention schedules and disposal controls documented |
| Security testing | Are safeguards regularly monitored and tested? | Vulnerability assessments, penetration testing, or continuous monitoring |
| Program governance | Does leadership receive regular reporting on the security program? | Written security program report provided at least annually |
The checklist is useful as a starting point, but compliance is not achieved by checking boxes once. The Safeguards Rule expects organizations to maintain and adjust their information security program as risks, technology, and business operations change.
A written information security program is the foundation of GLBA compliance.
The program should describe how the firm protects customer information and how security responsibilities are managed. It should be appropriate to the firm's size and complexity, the nature and scope of its activities, and the sensitivity of its customer information.
A useful program should answer practical questions such as:
The document should reflect how the firm actually operates. A policy that describes controls the firm does not use creates a documentation gap rather than reducing risk.
At a minimum, leadership should be able to determine:
The Safeguards Rule requires the information security program to be based on a written risk assessment.
For an accounting firm, that assessment should identify reasonably foreseeable internal and external risks to customer information and evaluate whether existing safeguards adequately address those risks.
The assessment should consider the firm's actual technology environment rather than relying on a generic cybersecurity template.
That can include:
The goal is to create a connection between risk → control → evidence → remediation.
A useful risk assessment can track:
This makes the risk assessment a management tool rather than a compliance document that sits unused.
Accounting firms should be able to demonstrate that access to customer information is limited to people who have a legitimate business need.
This starts with understanding who can access what.
Review access to:
Access should be based on role and business need, not simply on historical permissions.
Consider tracking:
For Microsoft 365 environments, identity security should be part of the firm's broader GLBA control strategy rather than treated as a separate IT concern.
Multifactor authentication (MFA) is one of the most important identity controls for protecting customer information.
The Safeguards Rule requires MFA for individuals accessing customer information on information systems, unless an equivalent form of secure access control is approved in writing by the Qualified Individual.
For accounting firms, MFA should extend beyond email where applicable. Review access to the systems that store, process, or provide access to customer information.
That can include:
A straightforward KPI is:
MFA coverage = users protected by MFA ÷ users requiring access × 100
The objective should be to identify and eliminate exceptions, rather than simply reporting that MFA is "enabled."
The Safeguards Rule requires covered organizations to encrypt customer information on their systems and while it is in transit, unless encryption is not feasible and effective alternative controls are approved in writing by the Qualified Individual.
For accounting firms, encryption should be evaluated across the firm's actual information flow.
Consider:
Encryption should also be considered alongside identity controls. Encrypting data does not eliminate the need to control who can access it.
Track encryption coverage across systems containing customer information and document any approved exceptions and compensating controls.
GLBA compliance is not limited to policies and identity controls. The firm's systems must also be configured and maintained in a way that protects customer information.
A practical review should address:
For firms using Microsoft 365, this can include reviewing identity, device, email, and cloud security configurations rather than assuming that purchasing the platform automatically establishes a compliant security program.
Useful operational measures include:
A security program should not depend entirely on employees reporting suspicious activity after something has already happened.
The Safeguards Rule calls for monitoring and testing the effectiveness of safeguards. For an accounting firm, that means having appropriate visibility into systems that contain or provide access to customer information.
Monitoring can include:
The specific technology will vary by firm, but the underlying question is consistent:
Can the firm identify meaningful security events quickly enough to investigate and respond?
Consider tracking:
A written incident response plan is another core component of the Safeguards Rule.
The plan should establish what happens when a security incident affects the confidentiality, integrity, or availability of customer information.
It should define:
An incident response plan should be tested, not simply stored in a policy repository.
Track:
The firm's incident response process should also account for the GLBA notification requirement. Under the Safeguards Rule, certain notification events involving at least 500 consumers' unencrypted customer information must be reported to the FTC as soon as possible and no later than 30 days after discovery.
The specific regulatory threshold and definition matter, so firms should involve appropriate legal or compliance professionals when determining whether an incident is reportable.
Technology controls are only one part of an accounting firm's security program.
Employees interact with customer information every day through email, document sharing, tax applications, cloud systems, and customer communications. Security awareness should therefore address the behaviors most relevant to the firm's actual risks.
Training should cover topics such as:
Security awareness becomes more useful when behavior can be measured.
Examples include:
The objective is not simply 100% training completion. It is measurable improvement in security-related behavior.
Accounting firms frequently rely on third-party providers to store, process, transmit, or protect customer information.
That creates another part of the firm's security program.
The FTC requires covered financial institutions to take reasonable steps to select and retain service providers capable of maintaining appropriate safeguards and to require appropriate safeguards through contracts.
A vendor review should consider:
Create a vendor inventory that identifies:
Not every vendor needs the same level of scrutiny. Prioritize providers with direct access to sensitive customer information or critical systems.
GLBA security responsibilities extend through the information lifecycle.
Accounting firms should understand what customer information they retain, why they retain it, where it resides, and when it should be securely disposed of.
Review:
A data inventory can help identify information that exists outside the firm's expected systems.
Consider tracking:
The goal is to reduce unnecessary data exposure while preserving information the firm is required to retain.
A security program should provide evidence that its safeguards are working.
The Safeguards Rule requires covered organizations to regularly monitor and test the effectiveness of their safeguards. Depending on the firm's monitoring capabilities, this can include continuous monitoring, penetration testing, vulnerability assessments, and other forms of security testing.
The important distinction is between having a control and demonstrating that the control works.
For example:
A practical security testing dashboard can include:
The Safeguards Rule also establishes governance responsibilities.
A Qualified Individual must oversee and implement the information security program and provide written reporting to the firm's board or governing body, or an appropriate senior officer where there is no board or equivalent.
The report must address the overall status of the information security program and relevant matters such as risk assessments, control decisions, service provider arrangements, testing results, security events, management responses, and recommendations for changes.
For executives and firm leadership, this creates an opportunity to turn cybersecurity from a technical discussion into a business risk discussion.
A useful quarterly or annual security review should answer:
An accounting firm evaluating its GLBA cybersecurity program can use the following checklist as a starting point.
The most useful GLBA compliance programs do not stop at documenting whether a control exists.
They establish measurable outcomes.
Instead of:
"We have MFA."
Track:
"99% of applicable user accounts have MFA enabled, with two documented exceptions scheduled for remediation."
Instead of:
"We conduct security awareness training."
Track:
"100% of employees completed training, and phishing simulation reporting improved from 62% to 81%."
Instead of:
"We perform vulnerability management."
Track:
"Critical vulnerabilities are remediated within the firm's defined target timeframe, with exceptions documented and reviewed."
This approach creates a direct connection between the GLBA requirement, the cybersecurity control, and the evidence that the control is working.
For accounting firms using Microsoft 365, many GLBA-related controls intersect directly with identity, endpoint, email, and cloud security.
A practical review should consider:
The objective is not to deploy every available security feature. It is to determine which controls address the firm's documented risks and whether those controls are consistently configured, monitored, and maintained.
For firms without internal security resources, this is also where a managed security or IT provider may support the firm's Qualified Individual and broader security program. The responsibility for the firm's information security program, however, should remain clearly defined within the organization.
The Safeguards Rule provides a framework for protecting customer information, but a checklist alone does not establish an effective information security program.
For an accounting firm, the more useful process is:
Identify → Assess → Protect → Monitor → Test → Respond → Improve
Start by identifying the customer information the firm handles and where it exists. Assess the risks surrounding that information. Implement controls that address those risks. Monitor whether the controls are working. Test them regularly. Respond when something goes wrong. Then use what you learn to improve the program.
That creates a security program that is not only easier to demonstrate from a compliance perspective, but also more useful as an ongoing management process.
The GLBA Safeguards Rule requires covered financial institutions under FTC jurisdiction to develop, implement, and maintain a written information security program with administrative, technical, and physical safeguards designed to protect customer information. Accounting firms may be covered depending on the financial activities they perform.
A GLBA compliance checklist should address the written information security program, risk assessment, access controls, MFA, encryption, secure system configuration, monitoring, incident response, employee security awareness, vendor oversight, data retention and disposal, security testing, and program governance.
Yes. The Safeguards Rule requires multifactor authentication for individuals accessing customer information on information systems, unless an equivalent form of secure access control is approved in writing by the Qualified Individual overseeing the information security program.
The Safeguards Rule requires covered organizations to encrypt customer information on their systems and while it is in transit, unless encryption is not feasible and effective alternative controls are approved in writing by the Qualified Individual.
Yes. A covered firm's information security program must be based on a written risk assessment that identifies reasonably foreseeable internal and external risks to customer information and evaluates the safeguards used to address those risks.
The Safeguards Rule requires covered organizations to implement policies and procedures to ensure personnel are able to enact the information security program. This includes security awareness training for employees and specialized training for personnel responsible for implementing the program.
Yes. Covered organizations must have a written incident response plan designed to address security incidents affecting the confidentiality, integrity, or availability of customer information.
Certain security incidents must be reported to the FTC. A covered financial institution must notify the FTC as soon as possible, and no later than 30 days after discovery, when a notification event involves the information of at least 500 consumers. The rule defines a notification event based on unauthorized acquisition of unencrypted customer information, subject to the rule's specific requirements.
The Safeguards Rule requires covered organizations to keep their information security program current and make adjustments based on monitoring, testing, risk assessments, vulnerabilities, and material changes to the business or its environment. Firms should establish a recurring review cadence rather than treating GLBA compliance as a one-time project.
Microsoft 365 can provide security capabilities relevant to GLBA controls, including identity protection, MFA, access management, endpoint security, email security, encryption, and monitoring. However, using Microsoft 365 does not by itself make an accounting firm GLBA compliant. The firm still needs a risk-based information security program, appropriate configurations, documented processes, monitoring, testing, governance, and evidence that its safeguards are operating effectively.
Start with a written risk assessment and data inventory. Identify what customer information the firm handles, where it is stored or transmitted, who can access it, which third parties process it, and what safeguards currently protect it. That provides the foundation for identifying gaps and prioritizing remediation.