Prompt
How do I ensure my tax return preparation workflow with tax software is compliant with client data security rules?
Latest observation
To keep a tax return preparation workflow compliant with client data security rules, build your process around access control, encryption, retention, logging, and vendor oversight. Here’s a practical checklist you can use with tax software:
1) Use only approved, reputable tax software
- Choose software that supports role-based access, audit logs, encryption, and secure file transfer.
- Verify whether the vendor has relevant security attestations/certifications, such as SOC 2, ISO 27001, or equivalent controls.
- Make sure the software vendor’s privacy policy, data processing terms, and security incident procedures fit your obligations.
2) Limit access to client data
- Give staff only the access they need for their job.
- Use unique user accounts for every preparer and reviewer; never share logins.
- Require multi-factor authentication (MFA) for software, email, cloud storage, and remote access.
- Remove access immediately when someone leaves or changes roles.
3) Encrypt data in transit and at rest
- Make sure client documents are encrypted:
- In transit: when uploading, emailing, or transferring files
- At rest: on local devices, servers, and cloud storage
- Avoid sending sensitive tax documents through unsecured email. If you must email, use secure client portals or encrypted attachments/password delivery out-of-band.
4) Secure endpoints and networks
- Use firm-managed devices with:
- full-disk encryption
- screen locks
- antivirus/EDR
- automatic patching
- Avoid preparing returns on public Wi‑Fi or unmanaged personal devices unless explicitly allowed and secured.
- Use a VPN or secure remote access if working offsite.
5) Set document handling rules
- Define how clients submit documents, how staff process them, and how files are stored.
- Prefer a secure client portal for uploads and approvals.
- If scanning paper documents, store them securely and shred them when no longer needed.
- Restrict local downloads; if downloads are necessary, delete them after use and keep only the authoritative copy in approved storage.
6) Implement retention and disposal controls
- Keep client records only as long as required by law, regulation, and firm policy.
- Have a written retention schedule for:
- returns
- source documents
- correspondence
- working papers
- Dispose of data securely:
- shred paper
- securely erase electronic files
- destroy old backup media according to policy
7) Maintain logs and monitoring
- Enable logging for:
- logins
- file access
- changes to returns
- exports/downloads
- admin actions
- Review logs periodically for unusual activity.
- Keep records of who accessed what and when, especially for sensitive client files.
8) Train staff on security and confidentiality
- Train employees on:
- phishing
- handling client PII/financial data
- secure document sharing
- incident reporting
- avoiding unauthorized use of AI tools or consumer apps with client data
- Require annual refresher training and document completion.
9) Control third parties and integrations
- Review any e-signature, OCR, bookkeeping, portal, or AI tools connected to your tax software.
- Confirm whether they receive client data and what they do with it.
- Use only approved integrations and disable anything unnecessary.
- Ensure contracts include confidentiality, breach notification, and data use restrictions.
10) Have an incident response plan
- Define steps for suspected data loss, misdirected email, ransomware, or unauthorized access.
- Include:
- containment
- client notification
- legal/regulatory reporting
- vendor contact procedures
- backup restoration
- Test the plan at least annually.
11) Align with applicable rules
Depending on your jurisdiction and practice type, you may need to comply with:
- tax preparer confidentiality rules
- privacy laws
- breach notification laws
- professional conduct standards
- data security regulations for financial information
If you’re in the U.S., common references include IRS-related safeguards, FTC privacy/security expectations for financial data, and state breach-notification requirements. If you’re in another country, local privacy and tax authority requirements may differ.
12) Document your controls
Keep a written security policy covering:
- access control
- password/MFA requirements
- acceptable use
- device security
- retention/destruction
- incident response
- vendor management
- remote work
Documentation helps prove compliance if you’re ever audited or investigated.
Simple compliant workflow example
- Client uploads documents to a secure portal.
- System stores files encrypted and logs access.
- Preparer accesses files on a managed, MFA-protected device.
- Return is prepared in approved tax software with limited user permissions.
- Reviewer checks changes; all actions are logged.
- Return is delivered via secure portal for signature.
- Final records are archived per retention policy.
- Temporary files are deleted securely.
If you want, I can turn this into a one-page SOP/checklist for your firm or tailor it to a specific tax software platform.
Observation history
Unlock observation history
Create a free Obsurfable account to unlock historical responses, model comparisons, and deeper brand intelligence.
How did Obsurfable measure this prompt?
Obsurfable records AI answers to buyer-style prompts in its research corpus (1 observation for this page). Metrics are distributions over observations, not a single static ranking.
Which AI systems does Obsurfable collect answers from?
OpenAI, ChatGPT, Google, Gemini, Google AI Mode, Anthropic, Claude, Perplexity, Grok, DeepSeek, Mistral, Copilot, and Meta AI.