Prompt

How do I ensure my tax return preparation workflow with tax software is compliant with client data security rules?

Latest observation

Jul 24, 2026 · OpenAI APIWeb search: off

To keep a tax return preparation workflow compliant with client data security rules, build your process around access control, encryption, retention, logging, and vendor oversight. Here’s a practical checklist you can use with tax software:

1) Use only approved, reputable tax software

  • Choose software that supports role-based access, audit logs, encryption, and secure file transfer.
  • Verify whether the vendor has relevant security attestations/certifications, such as SOC 2, ISO 27001, or equivalent controls.
  • Make sure the software vendor’s privacy policy, data processing terms, and security incident procedures fit your obligations.

2) Limit access to client data

  • Give staff only the access they need for their job.
  • Use unique user accounts for every preparer and reviewer; never share logins.
  • Require multi-factor authentication (MFA) for software, email, cloud storage, and remote access.
  • Remove access immediately when someone leaves or changes roles.

3) Encrypt data in transit and at rest

  • Make sure client documents are encrypted:
    • In transit: when uploading, emailing, or transferring files
    • At rest: on local devices, servers, and cloud storage
  • Avoid sending sensitive tax documents through unsecured email. If you must email, use secure client portals or encrypted attachments/password delivery out-of-band.

4) Secure endpoints and networks

  • Use firm-managed devices with:
    • full-disk encryption
    • screen locks
    • antivirus/EDR
    • automatic patching
  • Avoid preparing returns on public Wi‑Fi or unmanaged personal devices unless explicitly allowed and secured.
  • Use a VPN or secure remote access if working offsite.

5) Set document handling rules

  • Define how clients submit documents, how staff process them, and how files are stored.
  • Prefer a secure client portal for uploads and approvals.
  • If scanning paper documents, store them securely and shred them when no longer needed.
  • Restrict local downloads; if downloads are necessary, delete them after use and keep only the authoritative copy in approved storage.

6) Implement retention and disposal controls

  • Keep client records only as long as required by law, regulation, and firm policy.
  • Have a written retention schedule for:
    • returns
    • source documents
    • correspondence
    • working papers
  • Dispose of data securely:
    • shred paper
    • securely erase electronic files
    • destroy old backup media according to policy

7) Maintain logs and monitoring

  • Enable logging for:
    • logins
    • file access
    • changes to returns
    • exports/downloads
    • admin actions
  • Review logs periodically for unusual activity.
  • Keep records of who accessed what and when, especially for sensitive client files.

8) Train staff on security and confidentiality

  • Train employees on:
    • phishing
    • handling client PII/financial data
    • secure document sharing
    • incident reporting
    • avoiding unauthorized use of AI tools or consumer apps with client data
  • Require annual refresher training and document completion.

9) Control third parties and integrations

  • Review any e-signature, OCR, bookkeeping, portal, or AI tools connected to your tax software.
  • Confirm whether they receive client data and what they do with it.
  • Use only approved integrations and disable anything unnecessary.
  • Ensure contracts include confidentiality, breach notification, and data use restrictions.

10) Have an incident response plan

  • Define steps for suspected data loss, misdirected email, ransomware, or unauthorized access.
  • Include:
    • containment
    • client notification
    • legal/regulatory reporting
    • vendor contact procedures
    • backup restoration
  • Test the plan at least annually.

11) Align with applicable rules

Depending on your jurisdiction and practice type, you may need to comply with:

  • tax preparer confidentiality rules
  • privacy laws
  • breach notification laws
  • professional conduct standards
  • data security regulations for financial information

If you’re in the U.S., common references include IRS-related safeguards, FTC privacy/security expectations for financial data, and state breach-notification requirements. If you’re in another country, local privacy and tax authority requirements may differ.

12) Document your controls

Keep a written security policy covering:

  • access control
  • password/MFA requirements
  • acceptable use
  • device security
  • retention/destruction
  • incident response
  • vendor management
  • remote work

Documentation helps prove compliance if you’re ever audited or investigated.


Simple compliant workflow example

  1. Client uploads documents to a secure portal.
  2. System stores files encrypted and logs access.
  3. Preparer accesses files on a managed, MFA-protected device.
  4. Return is prepared in approved tax software with limited user permissions.
  5. Reviewer checks changes; all actions are logged.
  6. Return is delivered via secure portal for signature.
  7. Final records are archived per retention policy.
  8. Temporary files are deleted securely.

If you want, I can turn this into a one-page SOP/checklist for your firm or tailor it to a specific tax software platform.

Observation history

Unlock observation history

Create a free Obsurfable account to unlock historical responses, model comparisons, and deeper brand intelligence.

How did Obsurfable measure this prompt?

Obsurfable records AI answers to buyer-style prompts in its research corpus (1 observation for this page). Metrics are distributions over observations, not a single static ranking.

Which AI systems does Obsurfable collect answers from?

OpenAI, ChatGPT, Google, Gemini, Google AI Mode, Anthropic, Claude, Perplexity, Grok, DeepSeek, Mistral, Copilot, and Meta AI.