The FTC Safeguards Rule binds the US firm, not you, but section 314.4(f) forces it into your contract. Here is what an offshore firm must actually prove

FTC Safeguards Rule & WISP: Offshore Compliance in 2026

Last verified: 2026-07-29

A US accounting firm cannot legally send you a tax return until it has put security terms in your contract. That is not the client being difficult. It is a federal rule called the FTC Safeguards Rule, and it makes the US firm responsible for how you handle their clients’ data.

The rule does not apply to your company in India. It applies to theirs. But it reaches you anyway, through the contract you sign and the questions you have to answer before you sign it.


The FTC Safeguards Rule, 16 CFR Part 314, does not apply to a firm in India directly. It applies to the US firm that sends you the work. Section 314.4(f) requires that firm to select service providers capable of maintaining appropriate safeguards, to require those safeguards by contract, and to reassess those providers periodically. Section 314.2(r) defines a service provider as anyone who receives, maintains, processes, or is otherwise permitted access to customer information. That is you. The Safeguards Rule reaches you through the contract rather than through the regulator, though other US rules do land on an offshore provider directly.

This article sets out who the FTC Safeguards Rule covers, what it makes your US client demand from you, what goes in a WISP, what the contract clauses mean, what proof you need to hand over, and where India’s own DPDP Act fits.

Almost everything written on this subject is addressed to the US firm. It tells American accountants how to vet a vendor. Ten of the top-ranking guides on this topic were read while preparing this article. Not one of them is written for the vendor.

That is a strange gap, because the vendor is the one doing the work. You are the one who has to answer the security questionnaire, produce the evidence, encrypt the files, and call the client at 2am when something goes wrong. This article is written from your side of the contract.



Who the FTC Safeguards Rule applies to

The FTC Safeguards Rule applies to businesses the rule calls financial institutions, and that category is much wider than banks. It covers the US accounting and tax firms that send work offshore. It does not cover your Indian company as a matter of US law. Understanding that split is the whole foundation, so it is worth getting exactly right.

Why a tax preparer counts as a financial institution

A tax preparer counts as a financial institution because the rule says so in plain words. Section 314.2(h) of 16 CFR Part 314 lists thirteen examples, and example (viii) reads: “An accountant or other tax preparation service that is in the business of completing income tax returns is a financial institution because tax preparation services is a financial activity.”

There is no size threshold in that definition. IRS Publication 5708 says the same thing from the other direction: “Under the GLBA and Safeguards Rule, tax and accounting professionals are considered financial institutions, regardless of size.”

So a solo preparer in Ohio with forty clients is a financial institution. So is a 300-person CPA firm. Both carry the same duty toward you.

Bookkeeping is a harder case. If the firm does not prepare returns, its status depends on what else it does. Many bookkeeping firms also prepare returns or handle payroll, which brings them inside. The safe assumption when you are the vendor is that your client is covered, because you gain nothing by guessing they are not.

Where an offshore firm sits in the rule

An offshore firm sits in the rule as a service provider, which is a defined term rather than a loose description. Section 314.2(r) defines it as “any person or entity that receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a financial institution that is subject to this part.”

Read that against what you actually do. You receive client files. You process them. You are permitted access to a US firm’s systems.

You provide services directly to that firm. So you are a service provider under the rule, without any argument being needed.

The rule itself applies to “financial institutions over which the Commission has jurisdiction”. A company registered in Pune is not one of those. So the Federal Trade Commission is not going to write to you. Your client is the regulated party.

Advertisement

That does not leave you free. It changes the mechanism. Your obligations arrive as contract terms rather than as regulation, and a contract term is enforceable in a way that matters just as much to your business.

How many US firms this affects

Roughly a quarter of US accounting firms already send work offshore. The AICPA’s 2023 National Management of an Accounting Practice survey, reported by the Journal of Accountancy in November 2024, covered more than 1,100 firms. About 25% outsourced offshore, around 30% outsourced domestically, and 12% said they planned to start.

Every one of those offshore relationships carries a section 314.4(f) duty on the US side. That is the size of the population you are competing in, and the size of the population that has to run a vendor check before hiring anyone new.

This pattern is not unique to data security. The same structure shows up in 1099 filing, where the forms go out under the client’s employer identification number and the client stays the filer of record whatever software you use. The duty sits with the US party, and your exposure comes through the engagement.

If you want the wider market picture, see why US and UK firms send accounting work to India.

What the rule replaced

The Safeguards Rule is not new, but the version you are dealing with is. Congress passed the Gramm-Leach-Bliley Act in 1999, and the FTC issued the original Safeguards Rule in 2002. That first version was short and general. It told firms to have a security program and said little about what was in it.

The 2021 amendments changed that. They added specific requirements: a named Qualified Individual, a written risk assessment, encryption, multi-factor authentication, penetration testing, and the service-provider duties that now shape your contracts.

Firms were originally given until 9 December 2022 to comply. In November 2022 the FTC extended that by six months to 9 June 2023, and that is the date the current requirements took effect.

One more piece arrived later. The breach-notification requirement at section 314.4(j) took effect on 13 May 2024. That one matters to you more than any other, and it gets its own section below.

What the FTC Safeguards Rule makes your client demand

The FTC Safeguards Rule makes your client do three things about you, and those three things explain almost every awkward request you get during onboarding. They all sit in section 314.4(f), which is short. Here it is in full.

(f) Oversee service providers, by: (1) Taking reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue; (2) Requiring your service providers by contract to implement and maintain such safeguards; and (3) Periodically assessing your service providers based on the risk they present and the continued adequacy of their safeguards.

The FTC puts it more plainly in its plain-English guidance on the rule: “Your contracts must spell out your security expectations, build in ways to monitor your service provider’s work, and provide for periodic reassessments of their suitability for the job.”

The three duties, in order

Duty one is selection. Before hiring you, the firm has to take reasonable steps to check you can actually protect the data. That is where the security questionnaire comes from.

Duty two is the contract. The firm cannot rely on your good intentions. It has to require the safeguards in writing. That is where the data protection addendum comes from.

Duty three is reassessment. This is the one people forget. The check is not a one-time gate at onboarding. It repeats, and it repeats based on risk.

Work through the sequence in this order:

  1. The firm scopes what data you will touch and how sensitive it is.
  2. The firm assesses whether you can protect it, usually by questionnaire and evidence review.
  3. The firm decides whether to engage you at all.
  4. The firm puts the required safeguards into a signed contract.
  5. You implement them, and you keep evidence that you did.
  6. The firm reassesses you on a stated cadence.
  7. The firm records the result, because a reassessment nobody wrote down is hard to prove later.

Stopping early is the common failure. Many firms do steps one to four and then never do step six.

How much of the rule flows down to you

Not all of it, and this is the point most vendors get wrong in the other direction. You are not required to run your client’s entire compliance program.

The FTC addressed this directly in its June 2025 staff FAQ for auto dealers, which is the agency’s most detailed public guidance on service-provider oversight. Per the FTC’s June 2025 staff FAQ, the obligation “does not mean that you have to get the service provider to agree to meet all of the Safeguards Rule requirements that apply to you as a financial institution”. The FAQ adds that the rule “gives you the flexibility to select service providers whose safeguards are appropriate for the customer information they will be using”.

So the flow-down is scoped to what you actually handle. A vendor that only receives redacted trial balances is not asked for the same controls as a vendor with live access to the tax software.

Two controls do flow down concretely, and the FAQ names both:

  • Multi-factor authentication. If you get direct access to the client’s network, you should be required to use MFA. That comes from section 314.4(c)(5).
  • Encryption. If you store or process customer information for the client, you should be required to encrypt it. That comes from section 314.4(c)(3), which requires protection of customer information “both in transit over external networks and at rest”.

Treat those two as non-negotiable. Everything else is a conversation about scope.

One caution on this source. The dealer FAQ is staff guidance, and the FTC states it is not binding on the Commission. It is the clearest thing the agency has published on the subject, but it is not the rule itself.

The one case where the whole program lands on you

There is a single situation where the full information security program becomes your problem. It happens when the client’s Qualified Individual works for you.

Section 314.4(a) requires every covered firm to designate a Qualified Individual to oversee its security program. That person “may be employed by you, an affiliate, or a service provider”. Small US firms often do exactly this, because they have no security lead of their own.

If your firm supplies that person, section 314.4(a)(3) requires the client to “require the service provider or affiliate to maintain an information security program that protects you in accordance with the requirements of this part”.

Read that carefully. The scoped flow-down disappears. You now have to run a program meeting the requirements of the whole part. If a client asks your team to act as their Qualified Individual, price it accordingly and understand what you are taking on.

“Periodically” has no interval, so set one

Section 314.4(f)(3) says “periodically” and names no number. There is no annual deadline in the text, no 90-day cycle, nothing. That vacuum causes real problems, because your client cannot prove a cadence they never defined.

Fill it yourself. Hand the client a reassessment register at onboarding and keep it current. Something like this:

Control Evidence Issuer Last reviewed Next due Status
Information security program ISO 27001 certificate + Statement of Applicability BSI 2026-03-14 2027-03-14 Current
Independent assurance SOC 2 Type II, 12-month window Audit firm 2026-05-02 2027-05-02 Current
Network testing External penetration test report VAPT vendor 2026-06-20 2026-12-20 Current
Vulnerability scanning Quarterly scan summary Internal 2026-07-01 2026-10-01 Current
Cyber liability cover Certificate of insurance, US jurisdiction Insurer 2026-01-10 2027-01-10 Current
Staff background checks Verification policy + sample records Internal HR 2026-02-28 2027-02-28 Current
Cloud subprocessor Sub-processor SOC 2 + DPA Cloud provider 2026-04-11 2027-04-11 Expiring

Add a row for every subprocessor, not just your own controls. Add an effective-date column if a status changes mid-year, so the history is visible rather than overwritten.

Two practical notes. Set the cadence in the contract rather than leaving it open, because an undefined cadence tends to become no cadence. And send the register to the client before they ask for it. A vendor who arrives with the evidence already organised is a vendor who is easy to keep.

Who owns each element of 16 CFR 314.4

The duty sits with the US firm. This is how each part reaches an offshore vendor.

ElementSectionUS firmOffshore vendorHow it reaches the vendor
Qualified Individual314.4(a)OwnsOnly if it supplies the person314.4(a)(3) pushes the whole programme onto the provider in that case
Risk assessment314.4(b)OwnsSupplies inputsYou answer the questionnaire that feeds the assessment
Encryption314.4(c)(3)OwnsSharedRequired by contract where you store or process customer information
Multi-factor authentication314.4(c)(5)OwnsSharedRequired where you have direct network access
Secure disposal314.4(c)(6)OwnsSharedReturn or certified destruction clause on termination
Testing and monitoring314.4(d)OwnsSupplies evidencePenetration test and vulnerability scan summaries handed over
Training314.4(e)OwnsOwn staffYou train your delivery team and can evidence it
Service provider oversight314.4(f)OwnsIs the subjectSelection, contract, and periodic reassessment. Never waived at any firm size.
Incident response plan314.4(h)OwnsFeeds itYour contractual notification window sits inside their plan
FTC breach notification314.4(j)OwnsTriggers the clockDiscovery is imputed through agents under 314.4(j)(2)
The flow-down is scoped, not total. FTC staff guidance states a firm does not have to make a service provider meet every requirement that applies to the firm itself, and that the rule allows the firm to select providers whose safeguards suit the customer information they will use. Two controls are named concretely: multi-factor authentication where the provider has direct network access, and encryption where the provider stores or processes customer information. Sources: 16 CFR Part 314 via eCFR; FTC staff FAQ for automobile dealers, June 2025 (staff views, not binding on the Commission).

The FTC Safeguards Rule exemption for small firms

The FTC Safeguards Rule exemption for small firms is far narrower than almost everyone thinks, and the misunderstanding runs in your client’s favour in a way that can hurt you. Many small US firms believe they are exempt because they hold information on fewer than 5,000 consumers.

They are not. Four specific sub-provisions are switched off. Everything else still applies.

The count is worth getting right, because the wrong version of it circulates widely.

The four provisions that are waived

Section 314.6 is one sentence long. Here it is complete:

§ 314.6 Exceptions. Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers.

That is the entire exemption. Four cross-references. The FTC describes it on its own guidance page as being “exempted from certain provisions of the Rule”, not from the rule.

Those four are:

  • 314.4(b)(1) the requirement that the risk assessment be written
  • 314.4(d)(2) annual penetration testing and six-monthly vulnerability assessments
  • 314.4(h) the written incident response plan
  • 314.4(i) the annual written report to the board or a senior officer

What still applies below the threshold

Requirement Section Under 5,000 consumers
Written information security program 314.3(a) Still required
Qualified Individual 314.4(a) Still required
Risk assessment (just not written) 314.4(b) Still required
Access controls 314.4(c)(1) Still required
Asset inventory 314.4(c)(2) Still required
Encryption in transit and at rest 314.4(c)(3) Still required
Secure development practices 314.4(c)(4) Still required
Multi-factor authentication 314.4(c)(5) Still required
Secure disposal 314.4(c)(6) Still required
Change management 314.4(c)(7) Still required
Activity monitoring and logging 314.4(c)(8) Still required
Testing and monitoring generally 314.4(d)(1) Still required
Staff training 314.4(e) Still required
Service provider oversight 314.4(f) Still required
Program adjustment 314.4(g) Still required
FTC breach notification 314.4(j) Still required
Written risk assessment 314.4(b)(1) Waived
Pen testing and vulnerability scans 314.4(d)(2) Waived
Written incident response plan 314.4(h) Waived
Annual written report 314.4(i) Waived

Note the two most important rows. The requirement to have a written security program comes from section 314.3(a), not from 314.4(b)(1), so a small firm still needs the document. What gets waived is the written risk assessment, which is a different thing. And section 314.4(f), the one that governs you, is not on the waived list at any firm size.

Why this matters when it is your client’s threshold

A small client is still fully bound on the parts that touch you. That is the practical takeaway.

If a US firm tells you the Safeguards Rule does not apply to them because they are small, and therefore they do not need a data protection addendum, they are wrong. The contract duty at 314.4(f)(2) does not scale with client count.

Be careful how you say this. You are not their compliance adviser and you should not pretend to be. But you can reasonably say your own policy is to sign a data protection addendum on every engagement, which gets to the same place without arguing about their obligations.

What the 5,000-consumer exemption actually waives

16 CFR 314.6 is one sentence and names four cross-references

Waived below five thousand consumers

4 sub-provisions
  • The requirement that the risk assessment be written 314.4(b)(1)
  • Annual penetration testing and six-monthly vulnerability assessments 314.4(d)(2)
  • The written incident response plan 314.4(h)
  • The annual written report to the board or a senior officer 314.4(i)

Still applies at any size

Everything else
  • The written information security programme itself 314.3(a)
  • Qualified Individual 314.4(a)
  • Risk assessment, just not written 314.4(b)
  • All eight safeguards, including encryption and MFA 314.4(c)(1)-(8)
  • Testing and monitoring generally 314.4(d)(1)
  • Staff training 314.4(e)
  • Service provider oversight 314.4(f)
  • Programme adjustment 314.4(g)
  • FTC breach notification 314.4(j)
Two rows people get wrong. The duty to have a written security programme comes from 314.3(a), not 314.4(b)(1), so a small firm still needs the document. What is waived is the written risk assessment, which is a different thing. And 314.4(f), the section that governs an offshore vendor, is not on the waived list at any firm size.
Section 314.6, quoted in full: “Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers.” The FTC’s own guidance describes this as being exempted from certain provisions of the Rule, not from the Rule. Source: 16 CFR 314.6 via eCFR; FTC, “Safeguards Rule: What Your Business Needs to Know”.

What a WISP is, and which parts name you

A WISP is the written information security plan a US tax or accounting firm has to maintain, and one section of it will describe your company by name. Knowing what that section says lets you supply the content instead of guessing at it.

The document the IRS expects

The Safeguards Rule itself never uses the word WISP. Section 314.3(a) requires “a comprehensive information security program that is written in one or more readily accessible parts”. The industry name for that document is the WISP, and the IRS adopted the term.

Two IRS publications set the expectation:

  • IRS Publication 4557, Safeguarding Taxpayer Data, revision 6-2024, 21 pages. It explains the Safeguards Rule and gives a checklist for building a plan.
  • Publication 5708, Creating a Written Information Security Plan for your Tax and Accounting Practice, revision 8-2024, 29 pages. This is the sample WISP most small US firms start from.

Pub 5708 states the position plainly: “A requirement of the Safeguards Rule is implementing and maintaining a WISP. Your WISP must be written and accessible.”

Worth knowing: Pub 5708 is the 8-2024 revision, not the 2022 original that many blog posts still cite. If a client sends you a template, check which version it came from.

The service-provider oversight section, filled in

Most WISP templates leave the service-provider section nearly blank, because the template author does not know who the vendors are. Your client has to fill it in. You can hand them the text.

Here is what a completed section looks like. This is the artifact almost no competitor publishes, and it is the single most useful thing you can send a nervous prospect.

Section 9. Oversight of Service Providers

9.1 Scope. This section covers all third parties that receive, maintain, process, or are permitted access to customer information, in satisfaction of 16 CFR 314.4(f).

9.2 Current service providers.

Provider Service Data accessed Location
[Vendor name] Pvt Ltd Tax return preparation support 1040 and 1120 workpapers, redacted SSNs Bengaluru, India

9.3 Selection. Before engagement, the Qualified Individual reviewed the provider’s ISO 27001 certificate and Statement of Applicability, its most recent SOC 2 Type II report including the exceptions table, its penetration test summary dated within twelve months, its background verification policy, and its certificate of cyber liability insurance. The review is recorded in the vendor file dated [date].

9.4 Contractual safeguards. The Master Services Agreement dated [date] incorporates a Data Protection Addendum requiring: encryption of customer information in transit and at rest; multi-factor authentication for all access to firm systems; prohibition on local download or removable media; written approval before engaging any subprocessor; notification to the firm within 24 hours of a suspected security event; return or certified destruction of customer information within 30 days of termination; and use of customer information solely to perform the services.

9.5 Reassessment. The Qualified Individual reassesses this provider annually, and on any material change to the services or after any security event. The reassessment covers the current SOC 2 report, the penetration test, insurance renewal, and the subprocessor list. The outcome is recorded in the vendor file.

9.6 Last reassessment. [Date]. Next due. [Date]. Reviewer. [Name of Qualified Individual].

Change the details to match your actual controls. Do not send a client language describing safeguards you do not have, because section 9.3 asks them to inspect the evidence.

The PTIN attestation your client signs

Once a year, your client signs a statement about the WISP under penalty of perjury. That is why the topic gets tense in October and November.

Anyone who is paid to prepare US federal returns needs a Preparer Tax Identification Number, renewed annually on Form W-12. Line 11 of that form carries a data-security attestation.

The wording has hardened over time. Through the 2024 season it read: “I am aware that paid tax return preparers must have a data security plan.” The October 2024 revision changed it to: “I am aware that paid tax return preparers are required by law to create and maintain a written information security plan that provides data and system security protections for all taxpayer information,” and added a pointer to Publications 5708 and 4557.

The October 2025 revision went further and made the checkbox mandatory.

A version of this attestation has existed at least since the October 2019 revision, so it is not new. What is new is the “required by law” language and the compulsory tick. That is why more clients are asking harder questions than they did three years ago.

The IRS is also pushing the topic seasonally. Its Security Summit launched a five-week campaign on 7 July 2026, in the programme’s eleventh year, and week three was dedicated entirely to the written information security plan.

The contract clauses that arrive with the work

The contract clauses arrive because section 314.4(f)(2) gives your client no choice: safeguards have to be required “by contract”. A US firm that hands you work on a handshake is in breach of a federal rule, whatever they think of your competence.

Knowing what the clauses are for makes negotiating them much easier.

What your client’s lawyer is trying to achieve

The lawyer has four goals, and none of them is to make your life difficult.

They need the safeguards to be a binding promise rather than a description. They need to find out about a breach fast enough to meet their own 30-day federal deadline. They need the right to check, because 314.4(f)(3) requires periodic reassessment and you cannot reassess what you cannot inspect. And they need the data to come back or be destroyed when the relationship ends, because section 314.4(c)(6) requires secure disposal.

Every clause below maps to one of those four goals.

Drafted clause text

This is a working example of a Safeguards flow-down addendum. It is written to be readable rather than exhaustive, and a lawyer should review anything you actually sign.

Data Protection Addendum

1. Definitions. “Customer Information” has the meaning given in 16 CFR 314.2(d). “Security Event” has the meaning given in 16 CFR 314.2(q). “Provider” means [vendor]. “Firm” means [client].

2. Security standard. Provider shall implement and maintain administrative, technical and physical safeguards for Customer Information that are at least as protective as those required of the Firm under 16 CFR 314.4, appropriate to the Customer Information Provider accesses.

3. Encryption. Provider shall encrypt all Customer Information in transit over external networks and at rest, using industry-standard algorithms. Where encryption is infeasible, Provider shall obtain the Firm’s prior written approval of compensating controls.

4. Access control. Provider shall require multi-factor authentication for all access to Customer Information and to any Firm system. Provider shall limit access to personnel who need it to perform the Services, and shall revoke access within 24 hours of a person ceasing to require it.

5. Data handling. Provider shall prohibit local download, removable media, printing, and transmission of Customer Information outside the controlled environment, except as the Firm approves in writing.

6. Subprocessors. Provider shall not permit any third party to access Customer Information without the Firm’s prior written consent, and shall impose on any approved subprocessor obligations no less protective than this Addendum.

7. Security event notification. Provider shall notify the Firm without undue delay and in any event within 24 hours of becoming aware of any Security Event affecting Customer Information, and shall provide the Firm with the information the Firm reasonably requires to meet its own notification obligations, including those under 16 CFR 314.4(j).

8. Audit and assessment. Provider shall, once per contract year and following any Security Event, provide its current independent assurance report, penetration test summary, and subprocessor list, and shall respond to the Firm’s reasonable security questionnaire within 30 days.

9. Return and destruction. On termination, Provider shall return or securely destroy all Customer Information within 30 days and shall certify destruction in writing.

10. Use limitation. Provider shall use Customer Information solely to perform the Services and for no other purpose.

11. Survival. Clauses 9 and 10 survive termination.

Clause 7 deserves attention. Twenty-four hours looks aggressive next to the client’s own 30-day deadline, and that gap is deliberate. The client’s clock starts when you find out, not when they do. The reasoning is set out in the breach section below.

If you want to understand how these obligations are structured under Indian law, LawSikho has a clause-by-clause guide to how a data processing agreement is drafted under the DPDP Act.

What to negotiate and what to accept

Some of this is genuinely negotiable. Some is not, and pushing on the wrong item makes you look like a poor security risk.

Accept without argument: encryption, multi-factor authentication, use limitation, return and destruction, and the subprocessor consent requirement. These come more or less straight from the regulation. Resisting them signals that you cannot meet them.

Negotiate the mechanics. Three items are usually movable. The notification window: 24 hours is common and 48 is defensible, while “immediately” is unworkable. The audit format: a report plus a questionnaire is reasonable, unlimited on-site inspection at your cost is not. The liability cap: uncapped liability on a small engagement is a real business risk, and most clients will accept a multiple of fees with a carve-out for wilful misconduct.

Read carefully: any clause requiring you to comply with “all applicable laws” without limit, and any clause making you responsible for the client’s own regulatory filings. Those are drafting habits rather than Safeguards requirements.

The addendum normally sits underneath a master services agreement that covers the commercial terms, and the two documents need to point at each other properly.

Proving it: SOC 2, ISO 27001 and the evidence pack

Proving your safeguards means handing over documents, not making promises. The client’s Qualified Individual has to record what they inspected, so what they want is paper with someone else’s name on it. This section covers what that paper is, how to read it, and what to do when you do not have the headline certificate yet.

How to read a SOC 2 report instead of waving it

A SOC 2 report is not a certificate and it is not a pass mark. It is an auditor’s opinion about a set of controls over a period of time, and the useful information is in the parts nobody reads.

Five things decide whether a report actually helps your client:

  • Scope. Which systems, which entities, which locations. A report covering your Mumbai office does not cover your Coimbatore delivery centre.
  • Trust services criteria. Security is the only mandatory one. Availability, confidentiality, processing integrity and privacy are optional. A report covering Security alone says nothing about confidentiality.
  • The exceptions table. This lists the controls that did not operate as described. It is the most informative page in the document and the one most often skipped.
  • Complementary user entity controls. These are things the report assumes your client does. They shift work back across the contract, and a client who has not read them will be surprised later.
  • The observation period. A Type II covering three months tells you far less than one covering twelve.

Type I versus Type II gets discussed as though Type II always wins. Usually it does, because Type I is a point-in-time design opinion while Type II tests operating effectiveness over a period. But a Type II over a three-month window with five unresolved exceptions is not obviously stronger than a clean Type I. Read the contents, not the label.

The evidence pack when you do not have SOC 2 yet

Most Indian firms under about fifty people do not have SOC 2 Type II, and the guides that treat it as mandatory are describing a commercial norm rather than a legal one. You can still pass a vendor review. You need a pack of smaller documents that together answer the same questions.

Artifact What it proves Who issues it
ISO 27001 certificate An information security management system exists and was audited Accredited certification body
Statement of Applicability Which controls you applied and which you excluded, with reasons You, reviewed by the auditor
Penetration test report summary Someone independent tried to break in and you fixed what they found External security firm
Vulnerability scan summary Regular scanning happens on a stated cadence Internal or vendor tool
Access control policy plus sample logs Least privilege is real, not aspirational You
MDM and DLP configuration attestation Devices are managed, data cannot leave You, with screenshots
Background verification policy Staff are checked before they touch client data You or a screening vendor
Physical security description Controlled floor, no phones, no removable media You, with photographs
Data protection addendum, signed Contractual safeguards are in place Both parties
Cyber liability certificate Insurance responds, and covers US jurisdiction Insurer
Subprocessor list with their reports The chain does not break below you You plus each subprocessor

Assemble this once and keep it current. A prospect who receives it in the first week of conversation is a prospect who stops worrying about you.

One control matters more than its size suggests. If your team works in a virtual desktop with local download disabled, clipboard blocked, printing off and no removable media, you have removed most of the ways client data leaks. Say so early and show the configuration.

The six safeguards US tax law actually names

There is one list of acceptable data-protection frameworks written into US tax rules, and SOC 2 is not on it. This surprises almost everyone, because SOC 2 is treated across the industry as the answer.

Revenue Procedure 2013-14, section 5.07, defines an “adequate data protection safeguard” as a management-approved and implemented security program, policy and practice that includes administrative, technical and physical safeguards, and that “meets or conforms to one of the following privacy or data security frameworks”. Then it lists six.

# Framework named in section 5.07 What it means for an Indian firm today
1 US Department of Commerce “safe harbor” framework, or a successor program The original safe harbour was invalidated in 2015. The clause survives only through “or a successor program”.
2 A foreign law data protection safeguard that includes a security component The most direct route. India’s DPDP Act with its security-safeguards duty is a candidate here.
3 A financial or industry-specific standard generally accepted as best practice The reg gives the Financial Institution Shared Assessment Program as its example. ISO 27001 arguably fits.
4 The AICPA/CICA Privacy Framework AICPA replaced this with its Privacy Management Framework in 2020, and CICA has not co-authored since merging into CPA Canada.
5 The most recent version of IRS Publication 1075 A real, current, freely available standard. Demanding, but nothing stops you mapping to it.
6 Any other framework giving the same level of privacy protection as (1) to (5) The catch-all. This is where a SOC 2 or ISO 27001 programme actually lands.

Two conclusions follow, and both are useful in a sales conversation.

First, when a US client asks whether you have “an adequate data protection safeguard”, they are using a term with a legal definition, and the definition points at frameworks rather than at a specific audit report. Item (6) is broad enough that a well-run ISO 27001 or SOC 2 programme qualifies, but you should describe it as conforming to the framework rather than as being the requirement.

Second, be careful with the bigger claims here. Anyone telling you SOC 2 is legally required for offshore tax work is overstating it. It is a commercial expectation, and a strong one, but the legal standard is this list.

Note that this list belongs to the section 7216 consent rules, not to the Safeguards Rule. The two regimes are separate, which is the subject of a later section.

The questionnaire, with model answers

The vendor security questionnaire is where deals slow down. Firms send between thirty and eighty questions, and a vendor answering them from scratch takes weeks. Prepare the answers once.

Here is a representative extract with the kind of answer that ends the exchange rather than extending it.

Q. Where is customer data stored, and in which country? All customer information remains in the client’s own environment. Our team accesses it through a virtual desktop hosted in [region]. No customer information is stored on Indian infrastructure or on local devices.

Q. Is data encrypted in transit and at rest? Yes. TLS 1.2 or higher in transit, AES-256 at rest. Key management is handled by [provider]. This satisfies 16 CFR 314.4(c)(3).

Q. Do you enforce multi-factor authentication? Yes, for all staff, on all systems that touch customer information, with no exceptions and no shared accounts. This satisfies 16 CFR 314.4(c)(5).

Q. Can staff download, copy, print or photograph client data? No. Local download is disabled in the virtual desktop, clipboard redirection is off, printing is disabled, USB and other removable media are blocked at the endpoint, and mobile phones are not permitted on the delivery floor. Screenshots of the enforcing policy are available.

Q. Who can access our data, and how is that controlled? Access is role-based and limited to the named engagement team. Access is granted by the engagement lead, reviewed quarterly, and revoked within 24 hours of a person leaving the engagement. Access logs are retained for [period] and available on request.

Q. Do you run background checks on staff? Yes. Identity, address, education and employment history are verified before joining, plus a criminal record check where local law permits. Policy available on request.

Q. Do you use subcontractors or offshore any part of the work further? No work is subcontracted without your prior written consent. Our current subprocessors are [list], each covered by a data protection agreement with terms no less protective than ours.

Q. Do you use AI tools on client data? Only tools approved in writing by you, under business or enterprise terms that contractually exclude your data from model training. No consumer-tier assistants are permitted on client work, and this is enforced by policy and by endpoint controls.

Q. How quickly will you notify us of a security incident? Within 24 hours of becoming aware, with the details you need for your own reporting under 16 CFR 314.4(j).

Q. What insurance do you carry? Cyber liability of [amount] with coverage valid for claims brought in US jurisdiction. Certificate available.

Answer in this register. Short, specific, and citing the rule where a rule exists. Vague answers create follow-up questions, and follow-up questions delay contracts.

Why this is a pricing lever, not a cost

Compliance capability changes what you can charge, and this is the part most Indian firms miss while treating it as overhead.

The cost of building the evidence pack is mostly fixed. An ISO 27001 programme, a penetration test, an MDM rollout and a set of written policies cost roughly the same whether you have twelve staff or ninety. That means the cost per engagement falls as you grow, and it means small firms carry the heaviest relative burden.

Two consequences follow. Firms that build this early can take work that firms without it cannot even bid for, because a US client with a documented vendor process cannot legally engage a vendor who fails the check. And the compliance-ready vendor shortens the client’s own work, which is worth real money to a firm whose Qualified Individual is also its managing partner.

Expect consolidation. Fixed compliance costs favour scale, so the smallest Indian shops will either invest, specialise into work that never touches customer information, or become subcontractors to larger vendors who already hold the certifications.

There is a career effect too. The people who can run a vendor security programme, read a SOC 2 report critically and answer a questionnaire without help are doing work adjacent to building a career in data privacy consulting from India, and the skills transfer directly.

What the DPDP Act adds and what it removes

India’s Digital Personal Data Protection Act, 2023 changes less about your US work than most people expect, and the reason is an exemption almost nobody writes about. The short version: you owe no consent notices to American taxpayers, but you do owe a security duty, and that duty lines up neatly with what your US client has to demand anyway.

The exemption nobody has written about

Section 17(1)(d) of the Digital Personal Data Protection Act, 2023 disapplies most of the Act for exactly the fact pattern you are in. The provision switches off Chapter II, except sub-sections (1) and (5) of section 8, along with all of Chapter III and section 16, where:

“personal data of Data Principals not within the territory of India is processed pursuant to any contract entered into with any person outside the territory of India by any person based in India”

Read that against a typical engagement. The data belongs to US taxpayers, who are not in India. You process it under a contract with a US firm, which is outside India.

You are based in India. All three limbs are satisfied.

What that removes is substantial. Chapter III contains the rights of Data Principals, including access, correction and erasure. Section 16 restricts transfers outside India, and most of Chapter II covers notice and consent.

None of that applies to the US taxpayer data you handle for a US client.

So an American client’s customer cannot serve you a DPDP erasure request, and you do not have to issue a consent notice to people whose returns you prepare. This also resolves what would otherwise be a genuine conflict, because a DPDP erasure duty would collide badly with US record-retention requirements.

The duty that survives

Two things survive the exemption, and they are deliberately chosen.

Section 8(1) keeps overall responsibility in place “irrespective of any agreement to the contrary”, so you cannot contract out of it. Section 8(5) requires reasonable security safeguards to prevent a personal data breach.

Rule 6 of the DPDP Rules, 2025 sets out what those safeguards are. It requires protection of personal data “including in respect of any processing undertaken by it or on its behalf by a Data Processor”. The minimum list is:

  • encryption, obfuscation, masking or virtual tokens
  • access control on computer resources
  • logs, monitoring and review
  • backups and business continuity
  • retention of logs for one year
  • appropriate contractual provision where a Data Processor is engaged
  • appropriate technical and organisational measures

That list should look familiar. It is close enough to 16 CFR 314.4(c) that a single control set satisfies both.

Rule 7 handles breaches. A Data Fiduciary must inform each affected Data Principal without delay, inform the Data Protection Board without delay with an initial description, and give the Board detailed information within 72 hours.

iPleaders has a practical walkthrough of the operational compliance work the DPDP Rules create for Indian businesses, which is worth reading if your firm also handles Indian client data, where the full Act does apply.

The two rules side by side

Obligation FTC Safeguards Rule DPDP Act and Rules Gap for an India-based vendor
Written security programme 314.3(a), on the US firm Rule 6 measures, on the Data Fiduciary Neither binds you directly. Both reach you by contract.
Encryption 314.4(c)(3), transit and at rest Rule 6(a), encryption, obfuscation, masking or tokens Effectively the same control
Access control 314.4(c)(1) Rule 6(b) Same
Logging and monitoring 314.4(c)(8) Rule 6(c), plus one-year log retention DPDP names a retention period; the FTC rule does not
Multi-factor authentication 314.4(c)(5), explicit Not named explicitly The US rule is more specific
Processor contract 314.4(f)(2), required by contract Rule 6(f), appropriate contract provision Both point to the same addendum
Breach notification 314.4(j), FTC, 500+ consumers, 30 days Rule 7, Data Protection Board, 72 hours Different regulators, different clocks
Data principal rights Not applicable Chapter III, disapplied by s.17(1)(d) No erasure exposure on US taxpayer data
Cross-border transfer Not applicable Section 16, disapplied by s.17(1)(d) No restriction on this work
Consent Handled by IRC section 7216, on the US preparer Chapter II, mostly disapplied Consent lives in US tax law, not DPDP

The overlap is high enough that one control set covers both. The differences are worth noting in your own policy so an auditor can see you understood them.

The clock

The substantive DPDP obligations are not in force yet, and the date takes a little arithmetic. Do not just diary a number someone quotes at you.

The DPDP Rules, 2025 were made by notification G.S.R. 846(E), dated 13 November 2025, and published in the Official Gazette on 14 November 2025. Rule 1 sets three commencement tranches:

  • Rules 1, 2 and 17 to 21 came into force on publication.
  • Rule 4 comes into force one year after publication.
  • Rules 3, 5 to 16, 22 and 23 come into force eighteen months after publication.

Rule 6, the security safeguards rule, and Rule 7, the breach rule, both sit in that third tranche. Eighteen months from 14 November 2025 lands in mid-May 2027.

Confirm that against the notification before you diary it, because commencement provisions get amended and a date taken from a blog post is not a date you should rely on.

The practical reading is that you have a runway, and it ends. Firms that build the Rule 6 control set now are also building the control set their US clients demand today, so there is no reason to wait for the Indian deadline.

FTC Safeguards Rule next to the DPDP Act

Where the two rulebooks overlap, and where India’s law steps back

ObligationFTC Safeguards RuleDPDP Act and RulesWhat it means for you
Written security programmeOn the US firm 314.3(a)Rule 6 measures, on the Data FiduciaryNeither binds you directly. Both reach you by contract.
EncryptionIn transit and at rest 314.4(c)(3)Encryption, obfuscation, masking or tokens Rule 6Effectively the same control
Access control314.4(c)(1)Rule 6Same
Logging and monitoring314.4(c)(8)Logs, monitoring and review, plus one-year retention Rule 6DPDP names a retention period. The FTC rule does not.
Multi-factor authenticationExplicit 314.4(c)(5)Not named explicitlyThe US rule is more specific
Processor contractSafeguards required by contract 314.4(f)(2)Appropriate contractual provision Rule 6Both point at the same addendum
Breach notificationFTC, 500 or more consumers, 30 days 314.4(j)Data Protection Board, 72 hours Rule 7Different regulators, different clocks
Data principal rightsNot applicableChapter III, disapplied for this workNo erasure exposure on US taxpayer data
Cross-border transferNot applicableSection 16, disapplied for this workNo restriction on this work
ConsentSits in IRC section 7216, on the US preparerChapter II, mostly disappliedConsent lives in US tax law, not DPDP
The exemption, and the duty that survives it. Section 17 of the DPDP Act disapplies Chapter II (except sub-sections (1) and (5) of section 8), all of Chapter III and section 16, where personal data of Data Principals not within India is processed under a contract with a person outside India by a person based in India. That is the offshore fact pattern exactly. What survives is section 8(1), responsibility irrespective of any agreement to the contrary, and section 8(5), reasonable security safeguards, which Rule 6 operationalises. So you owe no consent notice to a US taxpayer, but you do owe the security duty.
Timing. The DPDP Rules, 2025 were notified in November 2025. Rule 1 sets three commencement tranches, and the security-safeguards and breach-reporting rules sit in the eighteen-month tranche, which lands around mid-May 2027. Confirm the tranche list and dates against the Gazette notification before diarising them. Sources: Digital Personal Data Protection Act, 2023, sections 8 and 17; Digital Personal Data Protection Rules, 2025, Rules 1, 6 and 7.

Consent is a separate layer from security

Consent and security are two different rules, and doing one perfectly does nothing for the other. A flawless WISP does not cure a missing consent. A signed consent does not cure a missing safeguard. Firms mix these up constantly.

Why the SSN usually arrives redacted

Where a US preparer sends individual tax return data offshore, section 301.7216-3(b)(4)(i) generally bars them from disclosing the taxpayer’s social security number. Per 26 CFR 301.7216-3(b)(4), the preparer “must redact or otherwise mask the taxpayer’s SSN before the tax return information is disclosed outside of the United States”.

There is a route around it. Under (b)(4)(ii) the SSN can go if both preparers maintain an adequate data protection safeguard and the US preparer verifies that in the consent request. Those are the six frameworks listed earlier.

The consent rules themselves are covered in detail in our article on the consent rules that govern offshore 1040 data, so this section stays on how consent and security interact rather than repeating the mechanics.

Both sides, both moments

The safeguard requirement is symmetrical, and that is where the two layers touch. Revenue Procedure 2013-14 section 5.07 requires that both the disclosing US preparer and the receiving offshore preparer maintain an adequate data protection safeguard, and that they maintain it both at the time consent is obtained and when the disclosure is made.

So your security posture is not just your own commercial problem. It is a precondition for your client lawfully sending you an unredacted return. If your safeguard lapses between the consent and the disclosure, the basis for that disclosure lapses with it.

The prescribed consent wording is blunt about the underlying risk. It tells the taxpayer that if they consent, “federal agencies may not be able to enforce United States laws that protect the privacy of your tax return information” against a preparer outside the United States. That sentence is the US government describing the trust gap you are working to close.

Direct engagement changes the analysis

Who hired you decides which consent rules apply, and this distinction is rarely stated. Under section 301.7216-2(c)(3), where the taxpayer furnished the information to your firm directly, your own internal use of it does not require consent.

So an Indian firm engaged directly by the US business or individual sits in a different position from an Indian firm receiving work from a US CPA firm. In the second case the US firm is making a disclosure and needs the consent. In the first case there was no disclosure to make.

This matters commercially as well as legally. It is one of the reasons some Indian firms move toward direct engagements over subcontracting rather than staying in the second tier.

The breach clock on both sides

If client data is exposed, three different clocks start, and they are easy to confuse. One belongs to your client and runs to a US regulator. One is yours and runs to your client. One may run to the Indian Data Protection Board.

Getting the order right is most of incident response.

Your client’s federal clock

Section 314.4(j) requires the US firm to notify the FTC when a notification event involves at least 500 consumers, “as soon as possible, and no later than 30 days after discovery of the event”. The notice goes in electronically and has to state the firm’s details, the types of information involved, the dates, the number of consumers affected, a description of the event, and whether law enforcement has asked for a delay.

This requirement took effect on 13 May 2024 under section 314.5, which is why older guides do not mention it.

Two definitions make it bite harder than it looks. A “notification event” under section 314.2(m) is acquisition of unencrypted customer information without authorisation. And the rule presumes the worst: “Unauthorized acquisition will be presumed to include unauthorized access to unencrypted customer information unless you have reliable evidence showing that there has not been, or could not reasonably have been, unauthorized acquisition.”

Read that as a burden of proof. Your client does not have to be shown that data was taken. They have to show it was not. Good logging is what makes that possible, which is a practical reason to keep the logs your addendum promises.

Note also that encryption changes the analysis entirely. Encrypted information is outside the definition unless the key was also accessed.

Your clock sits inside theirs

Your notification duty is tighter than your client’s, and section 314.4(j)(2) explains why. It says a notification event is treated as discovered “as of the first day on which such event is known to you”, and the firm is “deemed to have knowledge of a notification event if such event is known to any person, other than the person committing the breach, who is your employee, officer, or other agent“.

You are acting as their agent. So when your team learns of an event, the client’s 30-day clock may already be running, whether or not anyone has told them.

Work the arithmetic. If your staff discover a problem on day 1 and you tell the client on day 20, the client does not have 30 days from day 20. They may have 10 days left. That is why a 24-hour or 48-hour contractual window is normal, and why arguing it down to a week is a bad trade for a few hours of drafting comfort.

What enforcement has actually looked like

Enforcement history is short, and it does not look the way vendor marketing suggests.

The first Safeguards Rule cases came from a compliance sweep, not a breach. In November 2004 the FTC checked a set of auto dealers and mortgage companies. Most passed.

Two did not. The failures cited were the absence of a risk assessment, safeguards, employee training and oversight of staff handling customer information. Nobody had to be hacked first.

The one tax-preparation case is FTC v. TaxSlayer. Attackers ran a credential-stuffing attack between October and December 2015, reaching 8,882 accounts, and the stolen data was used to file fraudulent returns. The FTC alleged there was no written information security program until November 2015.

Final approval came on 8 November 2017. The outcome was no monetary penalty, a 20-year prohibition on further violations, and ten years of biennial third-party assessments.

Breaches at tax firms are common even though enforcement is rare. In IR-2025-88 on 26 August 2025 the IRS reported: “In the first half of the year there were nearly 300 data breaches reported impacting as many as 250,000 clients.”

What the penalty figure actually is

Most articles on this topic quote a penalty of $46,517 per violation per day. That figure is out of date, and the “per day” framing is doing work it cannot support.

Claim in circulation What the source says
$46,517 per violation This was the 2022 figure, set by the adjustment published on 10 January 2022, which raised it from $43,792. It has been superseded three times since.
$51,744 per violation The 2024 figure, and the one immediately before the current amount.
$53,088 per violation Operative. The adjustment published on 17 January 2025 raised section 5(m)(1)(A) from $51,744 to $53,088. No further adjustment has been published since.
“$100,000 per violation under GLBA” A different statutory provision, not the Safeguards Rule penalty.
“Per violation, per day, automatically” Not supported. No official source states that a standalone Safeguards Rule breach carries automatic daily civil penalties.

For the penalty figure, the regulation is the source to use rather than a vendor blog. The published amount sits in 16 CFR 1.98, and the current text records it as applying to “penalties assessed after January 17, 2025”.

One detail is worth noticing in the wording. The Federal Register notice describes section 5(m)(1)(A) as covering a “knowing violation of rule respecting unfair or deceptive acts or practices”. The Safeguards Rule is issued under the Gramm-Leach-Bliley Act rather than as a trade regulation rule on unfair or deceptive practices, which is exactly why the automatic per-violation framing does not transfer cleanly.

Be careful with the bigger claims here. Civil penalties under the FTC Act attach in defined circumstances, and the enforcement record for the Safeguards Rule consists of orders, prohibitions and mandated assessment programmes rather than headline fines. A vendor telling you that a missing WISP triggers an automatic five-figure daily penalty is selling something.

The realistic exposure for your client is a consent order with years of third-party assessments attached, plus breach costs, plus the client relationships they lose. The realistic exposure for you is losing the contract, which is the one that should focus attention.

Where an offshore provider is directly exposed

The Safeguards Rule reaches you through the contract. Not every US rule works that way, and it is worth knowing the counter-example before someone else raises it.

Under the FinCEN beneficial ownership regime, an individual who wilfully files a false or fraudulent beneficial ownership report on a company’s behalf may face the same civil and criminal penalties as the reporting company and its senior officers. FinCEN does not require a third-party filer to keep records proving it was authorised to file, though it says a filer may want to consider keeping documentary records relevant to the reports it files.

So the general principle is not that offshore providers are always shielded by the contract. It is that this particular rule works that way. Check the specific regime before assuming.

Common mistakes offshore firms make

Treating the certificate as the finish line. A SOC 2 report or an ISO certificate is the start of the conversation. Section 314.4(f)(3) requires your client to reassess you periodically, so the certificate that closed the deal has to be replaced, renewed and re-sent. Firms that let a certificate lapse quietly usually discover it during a client’s audit.

Answering the questionnaire reactively. Waiting for the questionnaire, then spending three weeks drafting answers, adds a month to every sales cycle. Prepare the answers once, keep them in a maintained document, and send the pack before it is requested.

Forgetting the fourth party. Your own cloud provider, your own subcontractors and your own tooling all sit below you in the chain, and the flow-down is recursive. Tax law makes the same point: under section 301.7216-2(d)(2) a contractor who receives tax return information becomes a tax return preparer in its own right and must be given written notice of sections 7216 and 6713. If you cannot name your subprocessors and produce their reports, your evidence pack has a hole in it.

Confusing the two consent positions. Firms often assume every engagement needs the same paperwork. Whether the taxpayer gave you the data directly or your US client disclosed it to you changes which rules apply, as set out above.

Putting client data into AI tools without a policy. Your client’s WISP now very likely has an AI section, and that section becomes a contract term the moment the addendum incorporates their security standard. A delivery team pasting client figures into a consumer-tier assistant breaches that term regardless of whether any tax rule was broken, because the consumer tiers of the major products may use submitted content to train the model. Get the approved tool list in writing, enforce it at the endpoint, and read our detailed guide on using AI on client data without breaching the contract before you write your policy.

Assuming a small client has no obligations. The 5,000-consumer exemption waives four sub-provisions. Service-provider oversight is not one of them.

Frequently asked questions

Does the FTC Safeguards Rule apply to a company based in India? Not directly. The rule applies to financial institutions the Federal Trade Commission has jurisdiction over, and an Indian company is not one. It reaches you through section 314.4(f), which makes your US client impose safeguards on you by contract. Your obligations are contractual, not regulatory.

What is a WISP, and does an offshore firm need its own? A WISP is the written information security plan a US tax or accounting firm must maintain under 16 CFR 314.3(a). You are not legally required to have one. In practice most serious vendors keep their own policy set, because clients ask for it and it makes the questionnaire easier to answer.

What is a Qualified Individual under the FTC Safeguards Rule? The person designated under section 314.4(a) to oversee and implement the firm’s information security program. They may work for the firm, an affiliate, or a service provider. If your firm supplies that person, section 314.4(a)(3) makes you maintain a program meeting the whole rule.

Does the FTC Safeguards Rule apply to bookkeepers who do not prepare tax returns? It depends on the activities, not the job title. The rule covers businesses significantly engaged in financial activities, and tax preparation is named at section 314.2(h)(2)(viii). A bookkeeping firm that also prepares returns or runs payroll is likely covered. As a vendor, assume your client is.

Are small firms exempt from the FTC Safeguards Rule? No. Section 314.6 switches off four sub-provisions below five thousand consumers: the written risk assessment, penetration testing and vulnerability scans, the written incident response plan, and the annual written report. Everything else applies, including service-provider oversight.

Does the rule require multi-factor authentication for an offshore team? Section 314.4(c)(5) requires MFA for any individual accessing any information system, unless the Qualified Individual approves equivalent controls in writing. FTC staff guidance states that a service provider given direct network access should be required to use it. Treat MFA as mandatory.

How often should an offshore provider be reassessed? Section 314.4(f)(3) says “periodically” and sets no interval. Annual reassessment is the common practice, with an additional review after any material change to the services or any security event. Setting the cadence in the contract avoids arguments later.

How long does it take to get SOC 2 Type II from a standing start? It depends on your existing controls and the observation window you choose, so any firm quoting a fixed timeline without seeing your environment is guessing. The sequence is a readiness assessment, then remediation, then an observation period the auditor tests across.

What should an offshore firm do in the first 48 hours after a suspected breach? Contain first, preserve logs, and notify the client inside the window your contract specifies. Do not wait for certainty. Your client’s federal clock may already be running from the moment your staff knew, so an early notification with incomplete facts is better than a late one with complete facts.

Is a SOC 2 report required to work with a US CPA firm? Not as a matter of law. It is a strong commercial expectation, and many firms will not proceed without one. The legal standard for offshore tax data is the framework list in Revenue Procedure 2013-14 section 5.07, which does not name SOC 2.

SOC 2 or ISO 27001: which do US firms actually ask for? US firms usually ask for SOC 2 because it is the familiar North American report. ISO 27001 is more common among Indian providers and is recognised internationally. Holding ISO 27001 with a clear Statement of Applicability is a reasonable answer, and many firms eventually hold both.

How does the FTC Safeguards Rule differ from IRS Publication 4557? The Safeguards Rule is binding law at 16 CFR Part 314. Publication 4557 is IRS guidance explaining it and giving a checklist. Publication 5708 adds a sample WISP. The publications help you comply; the rule is what you comply with.

Can a US firm outsource to India and stay FTC compliant? Yes. Nothing in the Safeguards Rule prohibits offshore service providers. The firm must select a provider capable of maintaining appropriate safeguards, impose them by contract, and reassess periodically. Separate rules under IRC section 7216 govern consent.

Who is liable if the offshore provider has the breach? The US firm remains responsible for its own compliance and for its notification obligations, and cannot transfer that by contract. That does not leave you untouched. Your liability to the client runs through the addendum you signed, and commercially you would expect to lose the engagement.

Does DPDP Act compliance satisfy a US client’s Safeguards Rule requirement? Not on its own. They are separate regimes with separate regulators. The control sets overlap heavily, so one well-built security programme can satisfy both, but your client still needs the contractual safeguards and evidence that 16 CFR 314.4(f) requires.

References

All sources were live-checked on 29 July 2026.

Official guidance and regulations

  1. 16 CFR Part 314, Standards for Safeguarding Customer Information – Federal Trade Commission, via eCFR. Source for the financial-institution and service-provider definitions, the section 314.4 elements, the 314.6 exception and the 314.4(j) breach requirement, used throughout.
  2. FTC Safeguards Rule: What Your Business Needs to Know – Federal Trade Commission. Source for the plain-English statement of contract expectations in the service-provider section.
  3. Automobile Dealers and the FTC’s Safeguards Rule: Frequently Asked Questions – Federal Trade Commission staff, June 2025. Source for the scoped flow-down position and the MFA and encryption points.
  4. 16 CFR 1.98, Adjustment of civil monetary penalty amounts – Federal Trade Commission. Source for the $53,088 figure in the penalty table.
  5. IRS Publication 4557, Safeguarding Taxpayer Data – Internal Revenue Service, revision 6-2024. Cited in the WISP section.
  6. IRS Publication 5708, Creating a Written Information Security Plan – Internal Revenue Service, revision 8-2024. Source for the “regardless of size” statement and the WISP requirement.
  7. Form W-12, IRS Paid Preparer Tax Identification Number Application and Renewal – Internal Revenue Service. Source for the Line 11 data-security attestation.
  8. Revenue Procedure 2013-14 – Internal Revenue Service. Source for the section 5.07 definition of an adequate data protection safeguard and the six frameworks table.
  9. IRS Security Summit – Internal Revenue Service. Source for the 2026 summer campaign and the WISP-focused week.
  10. ISO/IEC 27001 – International Organization for Standardization. Referenced in the evidence pack.
  11. Digital Personal Data Protection Act, 2023 – Ministry of Electronics and Information Technology, Government of India. Source for section 17(1)(d), the exemption for processing data of Data Principals outside India, and sections 8(1), 8(2) and 8(5).
  12. Digital Personal Data Protection Rules, 2025, G.S.R. 846(E) – Ministry of Electronics and Information Technology, Government of India. Source for the Rule 1 commencement tranches, the Rule 6 security safeguards and the Rule 7 breach-intimation deadline.

Data and research

  1. Offshoring for CPA firms: the hows and whys – Journal of Accountancy, November 2024, reporting the AICPA 2023 National Management of an Accounting Practice survey. Source for the 25% offshore-outsourcing figure.
  2. Security Summit: IRS reminds tax pros to guard against identity theft – Internal Revenue Service, IR-2025-88, 26 August 2025. Source for the breach count in the enforcement section.

Secondary sources

  1. FTC gives final approval to settlement with online tax preparation service – Federal Trade Commission, November 2017. Source for the TaxSlayer outcome.
  2. FTC enforces Gramm-Leach-Bliley Act’s Safeguards Rule against mortgage companies – Federal Trade Commission, November 2004. Source for the compliance-sweep point.

This article is for educational purposes only and does not constitute professional, financial, legal, or immigration advice. For guidance specific to your situation, consult a qualified professional.

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *