1 Your practice2 Contact3 Calendar

About your practice

Which products are you interested in? Select all that apply
What software does your firm use? Select all that apply
Select your software

AI review and controls

AI Tax Preparation Security Checklist for CPA and Tax Firms

Evaluate AI tax-preparation security across governance, data flows, access, encryption, vendors, retention, monitoring, incident response, and recovery.

Tax Automate Editorial Team Published September 28, 2026 4 min read
Tax-firm leaders reviewing an information-security checklist beside a laptop and organized client binder
Editorial illustration of a tax-firm security review. No taxpayer data or software interface is shown.

Govern the use case before selecting controls

Define the business purpose, authorized users, taxpayer-data categories, return types, systems, decision owners, prohibited uses, professional-review boundary, and acceptable fallback. A broad approval to 'use AI' is not a security design; each workflow needs a named scope and accountable owner.

The IRS Tax Security 2.0 checklist points professional tax preparers to an information security plan, while the FTC Safeguards Rule guidance specifically includes tax preparation firms among covered financial institutions. Fit the AI use case into the firm's current program and obtain qualified legal, security, insurance, and professional advice where needed.

Map every taxpayer-data flow

Inventory what enters the tool, where it travels, where it is stored, which people and services can reach it, what outputs are produced, and where copies remain. Include prompts, documents, extracted fields, chat history, logs, support access, backups, exports, browser extensions, connectors, and temporary processing locations.

Use the minimum data needed for the approved task. Separate production, testing, support, and demonstration access. A vendor saying that data is encrypted does not answer who holds access, how keys and sessions are managed, whether data reaches subprocessors, or what happens after termination.

  • Data categories and purpose
  • Storage and processing locations
  • Users, service accounts, and subprocessors
  • Model-training and product-improvement terms
  • Retention, export, deletion, and backup behavior

Protect identities, devices, applications, and data

Require unique identities, least privilege, prompt removal of seasonal and departed users, multifactor authentication, secure configuration, encryption, managed devices, supported software, and controlled administrator and support access. Review how the AI workflow authenticates to tax software, portals, email, storage, and practice systems.

The FTC Safeguards Rule guidance describes multifactor authentication, encryption or approved alternatives, app assessment, secure disposal, and service-provider oversight among its requirements. IRS Publication 4557 provides tax-practice-oriented building blocks for a security plan. Apply current guidance to the firm's actual risk and environment rather than copying a generic checklist unchanged.

Detect misuse and unreliable system behavior

Log authentication, privileged actions, document access, exports, connector activity, configuration changes, support sessions, overrides, and material AI workflow events. Assign who reviews alerts and how suspicious use, unexpected data movement, compromised accounts, and unusual automation behavior are investigated.

Security monitoring and quality monitoring overlap but are not identical. A wrong field mapping may be a product issue; bulk document access or an unexplained export may be a security event. Route each condition to the correct owner while preserving evidence and protecting taxpayer information in the logs themselves.

Prepare incident response and recovery before launch

Document who can disable users, connectors, API keys, browser sessions, and vendor access; how the firm preserves evidence; who evaluates affected data and clients; which contractual, regulatory, insurer, professional, and law-enforcement notifications may apply; and how approved communications are coordinated.

Test restoration from backups and the manual path for deadline work. NIST Cybersecurity Framework 2.0 organizes cybersecurity outcomes around Govern, Identify, Protect, Detect, Respond, and Recover. Use those functions as a lifecycle check, not as a claim that the firm or vendor is NIST-certified.

Run a bounded vendor and pilot review

Review current security documentation, contract language, subprocessors, independent assessments where available, incident terms, change notification, insurance, support access, data-use terms, retention, deletion, export, and termination assistance. Convert important promises into contract or implementation requirements rather than relying on a sales conversation.

Pilot with representative but minimized data and defined acceptance criteria. Include unauthorized-access attempts, incorrect permissions, a lost session, a terminated user, an unavailable integration, a corrected source document, export and deletion tests, and recovery from an interruption. Record limitations and a scheduled re-evaluation date.

Review TaxAutomate against your security requirements

Bring your written security program, data-flow questions, access model, and vendor checklist to a workflow and security review.

Discuss security and workflow

Frequently asked questions

Questions tax firms ask before choosing

Do tax preparation firms need a written information security plan?

The IRS Tax Security 2.0 checklist says federal law requires professional tax preparers to create and maintain an information security plan for client data. Firms should use current IRS and FTC guidance and obtain qualified advice for their specific obligations.

What should a tax firm ask an AI vendor about client data?

Ask what data is collected, where it is stored, who can access it, which subprocessors receive it, whether it is used for model training or product improvement, how long it is retained, how it is deleted or exported, and how incidents and material changes are reported.

Is multifactor authentication enough to secure AI tax preparation?

No. Multifactor authentication is one control. A complete program also addresses governance, asset and data inventory, least privilege, encryption, secure configuration, monitoring, vendor oversight, retention, incident response, recovery, training, and tested operational fallback.

Should a firm upload real taxpayer data during an AI pilot?

Begin with synthetic, sanitized, or otherwise authorized representative data whenever practical. Before using taxpayer information, approve the data flow, access, contract, retention, model-use terms, incident process, and the minimum data required for the defined test.

Does using an AI tax tool transfer the firm's security responsibility?

No. Vendor controls matter, but the firm still needs to evaluate the service, configure access, manage users, train staff, monitor use, handle incidents, and fit the tool into its broader information-security program.

Sources and limitations

  1. Tax Security 2.0 checklist — Internal Revenue Service; reviewed September 28, 2026.
  2. Publication 4557: Safeguarding Taxpayer Data — Internal Revenue Service; reviewed September 28, 2026.
  3. FTC Safeguards Rule: What Your Business Needs to Know — Federal Trade Commission; reviewed September 28, 2026.
  4. NIST Cybersecurity Framework 2.0 — National Institute of Standards and Technology; reviewed September 28, 2026.

This article is educational and is not tax, legal, accounting, security, or investment advice. Product capabilities and tax requirements can change. Confirm current vendor scope and authoritative guidance for the relevant facts, tax year, and jurisdiction.

How this article was prepared

We separate current sourced facts from operational recommendations, avoid invented performance claims, and show the primary sources and review date used.

Read the editorial methodology