Compliance & Certification
Certification services and regulatory updates to help keep your organization audit-ready and ahead of new compliance requirements.
System Certification, Compliance & Alignment
Get audit-ready with hands-on assessments aligned to the frameworks that matter for your industry.
ISO 27001:2013 Gap Analysis
Identify where your current controls fall short of the ISO 27001:2013 standard before you pursue certification.
Learn More →ISO 27001:2013 External Audit
Independent audit support to help your organization achieve and maintain ISO 27001:2013 certification.
Learn More →CMMC Pre-Certification Readiness Assessment
Find and close gaps ahead of your official CMMC assessment, so nothing catches you off guard.
Learn More →Regulatory Updates
Industry-specific compliance changes we’re tracking on behalf of our clients.
The Gramm-Leach-Bliley Act Now Applies to YouNew · Effective 2022
See IRS Publication 4557, “Safeguarding Taxpayer Data”
What Happened
On December 9, 2021, the FTC issued a Final Rule (86 FR 70272) amending the Gramm-Leach-Bliley Act (“GLB” or “GLBA”) of 1999, effective January 10, 2022. The rule introduced five key changes — one of which expanded GLBA’s scope to explicitly include tax preparers and additional financial institutions.[1][5]
How This Affects Your Organization
As with most federal cybersecurity rule changes, this one arrived quietly — easy to miss unless you follow regulatory updates closely. It doesn’t yet carry heavy enforcement teeth, but some institutions are already holding newly covered entities to its requirements. Most tax preparers already handle client PII carefully, but the IRS is now actively verifying compliance with these new rules.
According to the Journal of Accountancy:
The IRS has translated GLBA compliance into two practical guides: Publication 4557, “Safeguarding Taxpayer Data,” and its guidance on creating a Written Information Security Plan (WISP). Both are linked in the sources below.[3][4]
What if you just check “Yes” without a real plan?
Enforcement details are still evolving, so exactly how the IRS or FTC will audit compliance isn’t fully clear yet. But GLBA sets fines of up to $100,000 per occurrence for non-compliance.[4]
In practice, it could also leave your firm unable to file returns for clients at all.
Sources
- Federal Register – Standards for Safeguarding Customer Information
- Journal of Accountancy – Guide released for tax pros’ information security plan
- IRS – Publication 4557, Safeguarding Taxpayer Data
- IRS – Creating a Written Information Security Plan (WISP)
- Gramm-Leach-Bliley Act – Public Law 106-102