Compliance & Certification

Certification services and regulatory updates to help keep your organization audit-ready and ahead of new compliance requirements.

System Certification, Compliance & Alignment

Get audit-ready with hands-on assessments aligned to the frameworks that matter for your industry.

ISO 27001:2013 Gap Analysis

Identify where your current controls fall short of the ISO 27001:2013 standard before you pursue certification.

Learn More →

ISO 27001:2013 External Audit

Independent audit support to help your organization achieve and maintain ISO 27001:2013 certification.

Learn More →

CMMC Pre-Certification Readiness Assessment

Find and close gaps ahead of your official CMMC assessment, so nothing catches you off guard.

Learn More →

Regulatory Updates

Industry-specific compliance changes we’re tracking on behalf of our clients.

For Tax Preparers

The Gramm-Leach-Bliley Act Now Applies to YouNew · Effective 2022

See IRS Publication 4557, “Safeguarding Taxpayer Data”

What Happened

On December 9, 2021, the FTC issued a Final Rule (86 FR 70272) amending the Gramm-Leach-Bliley Act (“GLB” or “GLBA”) of 1999, effective January 10, 2022. The rule introduced five key changes — one of which expanded GLBA’s scope to explicitly include tax preparers and additional financial institutions.[1][5]

How This Affects Your Organization

As with most federal cybersecurity rule changes, this one arrived quietly — easy to miss unless you follow regulatory updates closely. It doesn’t yet carry heavy enforcement teeth, but some institutions are already holding newly covered entities to its requirements. Most tax preparers already handle client PII carefully, but the IRS is now actively verifying compliance with these new rules.

According to the Journal of Accountancy:

“Tax preparers will encounter a checkbox when they obtain or renew their preparer tax identification number (PTIN), requiring them to affirm their awareness that they must have a data security plan and provide data and system security protections for all taxpayer information.”[2]

The IRS has translated GLBA compliance into two practical guides: Publication 4557, “Safeguarding Taxpayer Data,” and its guidance on creating a Written Information Security Plan (WISP). Both are linked in the sources below.[3][4]

What if you just check “Yes” without a real plan?

Enforcement details are still evolving, so exactly how the IRS or FTC will audit compliance isn’t fully clear yet. But GLBA sets fines of up to $100,000 per occurrence for non-compliance.[4]

In practice, it could also leave your firm unable to file returns for clients at all.

Receive exclusive news, alerts, and virtual event invites! Always hand-crafted, never spam.

Contact Us